Salta al contenuto principale

Practical guide

Data security measures in the condominium manager's office

A condominium manager's office holds the data of many condominiums and hundreds of people: registers, accounts, documents, communications and sometimes sensitive information. Article 32 of the GDPR requires the adoption of technical and organisational measures appropriate to the risk, to ensure the confidentiality, integrity and availability of data. There is no fixed list valid for everyone: the measures must be proportionate to the quantity and nature of the data processed. Some steps, however, are effectively indispensable in any office, from access control to backups, and must be documented to be demonstrable in the event of an incident or a check.

Basic technical measures

Technical measures concern the tools with which data is stored and processed. The starting point is access control: every collaborator must have personal credentials, with strong passwords and, where possible, multi-factor authentication, so it is always clear who did what. Devices must be protected with up-to-date systems and antivirus, avoiding obsolete and unsupported software.

Equally important are the encryption of mobile devices and media that leave the office, periodic saving of data with verified backups kept in a separate location, and network protection. A backup that is never tested is not a real security measure: its effectiveness is proven only through test restores.

  • Personal credentials and strong passwords for every collaborator
  • Multi-factor authentication where possible
  • Up-to-date systems and antivirus, no unsupported software
  • Periodic backups, verified and kept in a separate location
  • Encryption of mobile devices and removable media

Organisational measures

Technology alone is not enough: internal rules and behaviour matter. You must define who can access which data based on their role, train collaborators on correct processing, and formally appoint them as persons authorised to process, with written instructions. Handling paper documents requires lockable cabinets and the clean-desk rule, so as not to leave data exposed.

Procedures for critical cases must also be in place: what to do in the event of a data breach, how to handle data subjects' requests, how to securely dispose of devices and erase data no longer needed. Regulating relations with technology providers through an agreement appointing them as processors completes the organisational picture.

The cloud and external providers

Many offices use cloud services for management software, mail and storage. These providers process data on behalf of the office and must be framed as processors, with an agreement defining purposes, security measures and obligations. It is advisable to check where the data resides, what guarantees the provider offers and how it ensures service continuity.

Relying on a reputable provider does not release the office from its own responsibilities, but it can significantly raise the level of security compared with an improvised setup on individual computers. The choice of provider is itself an organisational measure, to be assessed and documented.

Documenting and maintaining over time

The measures adopted must be put in writing and reviewed periodically, because risk changes as data and threats evolve. A register of measures, with the review date, makes the office's commitment demonstrable and eases updates. Security is not a goal reached once, but a continuous process.

A platform such as AmministraPro, with role-based access, operation logs, cloud data and tools for communications and documents, offers a solid base on which to build the office's security measures. The features are described on the /funzioni page and the plans on the /prezzi page.

Frequently asked questions

What security measures must the manager's office adopt?

The GDPR does not set a single list, but requires technical and organisational measures appropriate to the risk. In practice you need access control with personal credentials, up-to-date systems, verified backups, encryption of mobile devices, internal rules on roles, and procedures for breaches and data subjects' requests, all documented and reviewed over time.

Is a backup really a mandatory measure?

Periodic saving of data is essential to ensure its availability, one of the three objectives of Article 32 of the GDPR. A backup, however, is only worth it if verified: without test restores there is no certainty the data can be recovered. It must also be kept in a location separate from the original data.

Does using a cloud service make the office safe?

The cloud can raise the level of security compared with a setup on individual computers, but it does not release the office from its own responsibilities. The provider must be framed as a processor through an agreement defining measures and obligations, checking where data resides and what guarantees are offered.

Must collaborators be authorised to process data?

Yes. Anyone accessing data on behalf of the office must be formally appointed as a person authorised to process and instructed with written guidance on what they may do and how. Access must be assigned by role, so each person sees only the data needed for their tasks, reducing the risk of improper use.

Try AmministraPro

Accounting, thousandths-based cost splitting, meetings, communications and artificial intelligence in a single Italian software, compliant with UNI 10801 and GDPR.