Salta al contenuto principale

Regulation

Appointing a data processor in a condominium

A condominium manager is the data controller for the personal data of unit owners, tenants and suppliers: names and addresses, ownership share tables, payment data and, in some cases, CCTV footage of common areas. To carry out these tasks, the manager often relies on external parties, from the accountant to the provider of an online portal, who process that same data on the manager's behalf. When this happens, Article 28 of the GDPR requires a formal appointment as data processor, with an agreement setting out tasks, guarantees and limits. This guide explains which suppliers need to be appointed, what the appointment document must contain, and how a management platform such as AmministraPro can help keep track of appointments and ongoing processing activities.

Who is the controller and who can become a processor

In a condominium, the data controller is the condominium itself, represented by the acting manager: the manager decides the purposes and means of processing, for example which data to collect for managing service charges or access to an online portal. The data processor, instead, is the third party that processes that data on the controller's behalf, following documented instructions rather than pursuing its own purposes.

Not every supplier needs to be appointed as a processor: only those who actually process personal data of unit owners or tenants while carrying out their service become processors. A plumber who fixes a leak and happens to see a resident list posted on a notice board is not a data processor; someone who systematically processes personal data on behalf of the condominium is.

  • The accountant or consultant preparing the budget and residents' financial records
  • The provider of the software or online portal used for communications and payments
  • The company managing the CCTV system covering the common areas
  • The payroll consultant handling the doorman or other condominium staff
  • The provider sending certified email, registered letters or bulk communications to residents

What the appointment agreement must contain

Article 28 of the GDPR does not leave the form open: the contract or legal act appointing a processor must be in writing, including electronic form, and must specifically govern the relationship between controller and processor. A generic reference to privacy rules inside the service contract is not enough: precise clauses are required.

As the controller, the manager remains responsible for verifying, before signing the appointment, that the supplier offers sufficient guarantees in terms of appropriate technical and organizational measures. This is not a purely formal step: the choice of supplier must be justified.

  • Subject matter, duration, nature and purpose of the processing entrusted
  • Type of personal data and categories of data subjects involved (owners, tenants, employees)
  • Obligation to process data only on the controller's documented instructions
  • Confidentiality obligations for anyone accessing data on the processor's behalf
  • Conditions for engaging sub-processors, subject to the controller's authorization
  • Assistance to the controller in responding to data subject requests and security obligations
  • Arrangements for deleting or returning data at the end of the engagement
  • Availability to provide the information needed to demonstrate compliance

The case of CCTV and the online portal

Two recurring situations deserve specific attention. For CCTV covering common areas, if installation and maintenance require the contractor to access recorded footage, that contractor must be appointed as data processor, with clauses governing who can view recordings and for how long they are retained, in line with the controller's instructions.

For management software and online portals used to communicate with residents, collect service charge payments or publish assembly minutes, the service provider processes personal data on behalf of the condominium and must be appointed as processor. AmministraPro, as a platform residents can use for these activities, gives the manager clear reference information about the processing carried out as part of the service, useful for correctly drafting the appointment.

Keeping track of appointments over time

Processor appointments are not a one time exercise: they need to be reviewed when a supplier changes, when the service provided changes, or when the underlying contract expires. An up to date list of suppliers appointed as processors, with the date of the agreement and the purpose of the processing entrusted, is a useful tool in case of a check or a request from a data subject.

Even a simple paper register or a shared spreadsheet with the board, where the condominium provides for one, helps keep track of who processes what and since when, reducing the risk of forgetting an appointment when a recurring supplier such as the accountant or the maintenance company changes.

Frequently asked questions

Does the manager need to appoint every single condominium supplier as a data processor?

No. The appointment is only needed for suppliers who actually process personal data of unit owners, tenants or employees on behalf of the condominium, following the controller's instructions, such as the accountant, the online portal provider or the CCTV maintenance company. A supplier who carries out physical work without accessing structured personal data, such as a stairwell cleaning company, normally does not require this appointment, unless it also processes specific data while performing the service.

Does the processor appointment replace the service or works contract with the supplier?

No, it sits alongside it. The service or works contract governs the commercial subject matter of the relationship, for example bookkeeping or CCTV system maintenance. The Article 28 GDPR appointment specifically governs the processing of personal data connected to that service, with the clauses required by the regulation. These can be two separate documents or a single contract with a dedicated privacy section or annex.

Who checks whether the supplier actually follows the instructions given in the appointment?

The responsibility for verification remains with the data controller, meaning the manager acting on behalf of the condominium. Article 28 GDPR provides that the controller may request from the processor the information needed to demonstrate compliance and may contribute to audits and inspections. In practice, for a condominium, this often means asking the supplier for a written summary of the measures adopted, rather than a formal inspection, unless there are particularly significant circumstances or reports of irregularities.

What happens if a supplier who should have been appointed as a processor was not?

The missing appointment exposes the data controller, meaning the condominium represented by the manager, to the risk of being considered responsible for processing personal data without an adequate contractual basis under Article 28 GDPR, with possible consequences in the event of a check or a data subject complaint. It is therefore advisable to regularize the position as soon as the gap is noticed, preparing the appointment document even for relationships already underway.

Can a platform like AmministraPro help the manager with this obligation?

Yes, in a practical way: a condominium management platform such as AmministraPro centralizes the data processed for managing the condominium and gives the manager clear reference information about the processing carried out as part of the service itself, useful for correctly drafting the software provider's appointment as processor. Evaluating the condominium's other suppliers and drafting their respective appointments remains the manager's responsibility, based on the specific characteristics of each relationship.

Try AmministraPro

Accounting, thousandths-based cost splitting, meetings, communications and artificial intelligence in a single Italian software, compliant with UNI 10801 and GDPR.