Practical guide
Privacy by design when configuring condominium software
Data protection does not end with documents: it takes shape in how the firm configures the tools it uses every day. The GDPR introduces the principles of privacy by design and by default, which require integrating protection from the design stage and, by default, processing only the data that is necessary. Applied to condominium management software, these principles translate into concrete choices about permissions, visibility, retention times and data minimisation. This guide explains how to turn the two principles into operational settings, with a checklist to leave nothing to chance.
Privacy-by-default configuration checklist
- Enable differentiated access profiles: each role sees only the data it needs.
- By default, limit the visibility of sensitive data such as arrears.
- Configure retention times and deletion rules for data no longer needed.
- Reduce the fields collected to those actually useful for management.
- Enable operation tracking to know who accesses what.
- Set up encryption and backups according to the available options.
- Verify that the owners' reserved area shows only the data relevant to them.
What privacy by design and by default say
Article 25 of the GDPR requires the controller to put in place appropriate technical and organisational measures from the moment of designing the processing, and to ensure that, by default, only the data necessary for each purpose is processed. In other words, protection must be the starting point, not an adjustment added later.
For a management firm this means that choosing and configuring the software are themselves data protection measures. It is not enough to write in a policy that access is limited: you must configure the software so that it really is. Privacy-oriented default settings make the difference, because most users never change them.
Differentiated permissions and visibility
The first area of application is permissions. Well-configured software assigns each role a profile that exposes only the necessary data: the front office sees communications, accounting sees financial movements, a collaborator assigned to one building sees only that building. Bulk exports and the most sensitive functions should be reserved for a few authorised profiles.
Particular attention should go to data that can harm people's reputation or financial situation, such as arrears. Their visibility should be limited by default and governed according to the guidance on processing arrears data, avoiding confidential information being exposed more than necessary, even within the firm.
- Access profiles by role, following the least-privilege principle.
- Restriction of bulk exports to authorised profiles only.
- Reduced default visibility of financial data and arrears.
- Separation of data between the different condominiums managed by the firm.
Minimisation, retention and tracking
Minimisation concerns the data you collect: the software should be configured to acquire only the information useful for management, avoiding superfluous fields that increase risk without adding value. Every extra piece of data is one more thing to protect, keep and eventually delete.
Retention should be set according to purposes: data no longer needed should be deleted or made non-identifiable following a defined policy. Finally, operation tracking lets you know who did what and when, a valuable element both for preventing internal abuse and for reconstructing any incident. These are all settings to decide at configuration time, not improvised afterwards.
Reviewing the configuration over time
The initial configuration is not final. The firm's organisation changes, new collaborators join, condominiums are added, needs evolve. It helps to periodically review permissions, visibility and retention rules, checking that they still reflect reality and recording the changes in the compliance file.
Choosing software that offers granular access profiles, operation tracking and retention settings greatly eases the application of privacy by design and by default. AmministraPro's features designed for these purposes are described on the /funzioni page and the available plans on the /prezzi page.
Frequently asked questions
What does privacy by default mean in practice?
It means the software's default settings must be the most protective: by default only the necessary data is processed and visibility is limited. The user may consciously broaden it, but the starting point must protect the data, because most people never change the initial settings.
Does privacy by design concern only software developers?
No. The principle also concerns those who choose and configure the tool. A management firm applies privacy by design when it selects software that allows adequate controls and sets it up protectively, with permissions, visibility and retention consistent with the purposes of the processing.
How do I limit the visibility of arrears to internal users?
By configuring access profiles that reserve sensitive financial data to the roles that need it and by reducing, by default, its exposure in records and printouts. This prevents confidential information from being visible to anyone accessing the system without a genuine need.
How often should the software's privacy configuration be reviewed?
There is no fixed deadline, but a periodic review, at least annual, is advisable, together with extraordinary checks when the organisation, staff or software functions change. Each change should be documented, to show that the settings are consistent with the firm's real activity.
Try AmministraPro
Accounting, thousandths-based cost splitting, meetings, communications and artificial intelligence in a single Italian software, compliant with UNI 10801 and GDPR.
