Salta al contenuto principale

Practical guide

How to appoint authorised persons in your management firm

In a condominium management firm, every employee, collaborator or trainee who accesses owners' records, accounts and documents acts under the authority of the controller or the processor. The GDPR and the Italian privacy code call these people authorised persons: they must be identified, authorised in writing and instructed. This is not a mere formality, but the foundation for demonstrating that access to data is limited, traceable and informed. This guide explains who to appoint, how to draft the authorisation act and what instructions to provide, with a practical checklist.

Checklist for appointing an authorised person

  1. List the roles that access data: front office, accounting, technical staff, trainees, occasional external collaborators.
  2. Draft a written authorisation letter for each one, setting out the permitted scope of processing.
  3. Attach operating instructions on confidentiality, credentials, document handling and behaviour in case of anomalies.
  4. Have the act signed and keep a copy in the firm's privacy file.
  5. Assign each authorised person only the minimum permissions needed in the software.
  6. Update the list whenever someone joins, changes role or leaves.

Who is an authorised person and why the appointment matters

The condominium is the controller of its participants' data, and the administrator processes that data to carry out the mandate granted by the owners' meeting under Articles 1129 and 1130 of the Italian Civil Code. Inside the firm, however, the administrator does not handle information alone: front office staff, accountants, technicians and trainees do too. Article 29 of the GDPR and Article 2-quaterdecies of the Italian privacy code state that anyone acting under the authority of the controller or processor may process data only if authorised and instructed.

Appointing authorised persons is not red tape: it serves to limit access to those who genuinely need it and to make each person aware of their obligations. If the Italian supervisory authority carries out a check or an owner raises a complaint, the written act shows that the firm organised data access in a controlled way and does not leave information available to anyone passing by the desk.

What the authorisation act must contain

The act must be in writing and tailored to the role. It should identify the person, indicate who authorises them (the condominium as controller through the administrator, or the firm as processor), and define the scope: which categories of data they may process and for which purposes. An accountant will process financial and identifying data, a technician data on systems and maintenance, the front office communications.

Operating instructions should be attached to the text. There is no need for an encyclopaedic manual: clear rules are enough on how to keep credentials safe, how to handle paper and digital documents, the prohibition on disclosing data to unauthorised third parties, and the duty to report any anomaly or suspected breach immediately to the firm's privacy contact.

  • Identifying details of the authorised person and their role.
  • Scope of processing: permitted categories of data and purposes.
  • Instructions on credentials, confidentiality and document retention.
  • Duty to report anomalies promptly.
  • Duration of the authorisation and reference to the mandate or employment contract.

Minimum permissions in the software

The authorisation on paper must be translated into concrete permissions in the software. The principle is data minimisation: each person sees and edits only what they need. A trainee does not need to export all records in bulk, and a collaborator handling a single building must not access the data of the other condominiums managed by the firm.

Good software lets you assign differentiated roles and access profiles and record who does what. This way the appointment document and the technical configuration coincide, and the firm can demonstrate consistency between what it authorised and what the system actually allows.

Keeping the list current and linking it to training

The list of authorised persons is a living document. It must be updated whenever someone is hired, changes role or leaves: when a collaborator leaves the firm, their credentials must be revoked the same day and the authorisation archived with the closing date. Access left active for a departed employee is one of the most frequent and easily avoidable vulnerabilities.

The appointment must also be accompanied by training: an authorised person who does not know the instructions is not really instructed. It helps to have receipt of the instructions signed and to schedule a short periodic refresher. With AmministraPro the firm manages roles, access profiles and operation tracking in a single environment; the features are described on the /funzioni page and the plans on the /prezzi page.

Frequently asked questions

What is the difference between an authorised person and a processor?

The authorised person is a natural person operating inside the controller's or processor's organisation, such as an employee of the firm, acting under their authority under Article 29 of the GDPR. The processor is instead an external party, for example the software vendor, that processes data on behalf of the controller under a dedicated contract.

Must the authorisation act be in writing?

Yes. The Italian privacy code requires authorised persons to operate under instructions, and written form is how the firm demonstrates that it has identified the people and defined the scope of processing. Written form makes the authorisation enforceable and verifiable in case of a check or dispute.

Does a trainee or intern need to be authorised?

Yes, if they access owners' personal data. Even a temporary or training relationship involves processing information, so the person must be authorised in writing, instructed and given minimum permissions, with credentials revoked immediately at the end of the period.

How often should the list of authorised persons be updated?

There is no fixed legal deadline, but the list must be updated whenever something changes: a new collaborator, a change of role, the end of a relationship. A full review at least once a year helps verify that permissions and authorisations still match the real organisation.

Try AmministraPro

Accounting, thousandths-based cost splitting, meetings, communications and artificial intelligence in a single Italian software, compliant with UNI 10801 and GDPR.