Regulatory guide
The condominium data processing register
A condominium processes personal data every day: owner and tenant details, unit shares used for cost allocation, bank details for direct debits, meeting minutes, and often footage from cameras covering common areas. Regulation EU 2016/679 (GDPR), at Article 30, requires a record of processing activities documenting purposes, categories of data, parties involved, and security measures. In a condominium this obligation falls on the administrator, who acts as data controller on behalf of the community of owners. This guide explains who must keep the register, what it must contain, which typical processing activities need to be mapped, and how management software can make keeping the document up to date considerably easier.
Who is the data controller in a condominium
In a condominium the data controller is the administrator, not the individual owners and not the condominium itself, which under Italian law has no autonomous legal personality. It is the administrator who determines the purposes and means of processing: convening meetings, managing accounting, communicating with suppliers and banks, and maintaining the owners' register required under Article 1130 of the Italian Civil Code. That register, which collects ownership and other real or personal rights over the units, is itself personal data processing and must be included in the record.
The controller may rely on external processors, such as the tax consultancy firm, the provider of the management software, or the maintenance company that accesses owners' data, with whom an agreement under Article 28 of the GDPR must be signed. These parties should be listed in the record as recipients of the data.
What the record must contain under Article 30
Article 30 of the GDPR lists the minimum elements the record must document for each processing activity.
- Name and contact details of the controller (the administrator or the management firm)
- Purposes of processing, such as accounting management, convening meetings, handling arrears, or maintaining plant and equipment safety
- Categories of data subjects involved: owners, tenants, suppliers, employees or collaborators
- Categories of personal data processed: identity and contact details, banking details for SEPA direct debits, and any footage from CCTV covering common areas
- Categories of recipients the data is disclosed to, including external processors
- Envisaged time limits for erasure of the different categories of data, where it is possible to set them
- A general description of the technical and organisational security measures adopted
Typical processing activities to map in a condominium
In day to day condominium management the recurring processing activities to include in the record are: keeping the owners' register, managing accounting and cost allocation based on unit shares, handling reminders and actions for unpaid charges, convening and minuting meetings, corresponding with owners and suppliers, and, where present, operating CCTV systems covering common areas, which also requires the specific notice foreseen by the Italian data protection authority and visible signage.
Each processing activity should be matched by a privacy notice given to data subjects under Articles 13 and 14 of the GDPR: when an owner joins the condominium or the administrator takes on the mandate is the natural moment to deliver it. The record and the notice are not the same document, but they must be consistent: the purposes described in the notice should also appear in the record.
Keeping the record updated with management tools
The record is not something to compile once and archive: it needs updating whenever processing activities change, for example when new CCTV equipment is installed, a new collection method is adopted, or a new supplier begins accessing owners' data. For a firm managing several condominiums, keeping a consistent record for each one means avoiding starting from scratch at every review or inspection.
Management software such as AmministraPro helps concretely on this front: it centralises the owners' register, accounting, and communication with owners and suppliers in a single environment, giving the administrator clear visibility over which data is processed, for which purposes, and with which external parties, all of which makes compiling and updating the record of processing activities considerably easier.
Frequently asked questions
Is a condominium administrator required to keep the record of processing activities?
Article 30 of the GDPR sets a general obligation for controllers and processors, with an exemption for organisations with fewer than 250 employees that does not apply when the processing is likely to result in a risk to data subjects' rights, is not occasional, or involves special categories of data. Condominium administration involves systematic and non occasional processing of owners', tenants' and suppliers' data, so in practice, and following guidance from the Italian data protection authority, administrators are expected to keep the record.
Does the record of processing activities replace the privacy notice given to owners?
No, they are two distinct documents with different functions. The record of processing activities, required under Article 30 of the GDPR, is an internal accountability tool documenting the controller's activities and can be shown to the supervisory authority on request. The privacy notice, required under Articles 13 and 14, is instead addressed to data subjects (owners, tenants, suppliers) and explains what data is collected and for what purposes. The content of the two documents must be consistent with each other.
Who is liable if a data protection breach occurs in a condominium?
Primary liability falls on the administrator as data controller, since it is the administrator who decides the purposes and methods of processing owners' data. Where processing is partly entrusted to external parties, such as the tax consultancy firm or the management software provider, they are liable as processors within the limits of the agreement signed under Article 28 of the GDPR, but the controller remains responsible for overseeing their work.
Should CCTV covering common areas be included in the record of processing activities?
Yes, CCTV systems installed in common areas of a condominium, such as entrances, courtyards or shared spaces, constitute personal data processing in every respect and must be documented in the record together with their purposes, typically the protection of the safety and property of the condominium. Installing such systems also requires a resolution passed at a meeting, a specific notice to data subjects, and visible signage placed before the monitored areas, consistent with guidance from the Italian data protection authority.
Does management software like AmministraPro help keep the record of processing activities?
Management software does not compile the record on its own, since it remains a document the administrator is responsible for, but it can make keeping it considerably easier by giving clear visibility over the data actually processed. AmministraPro, by centralising the owners' register, accounting, and communications with owners and suppliers, helps the administrator pinpoint the categories of data, purposes, and recipients to record, and keep the register updated whenever ongoing processing activities change.
Try AmministraPro
Accounting, thousandths-based cost splitting, meetings, communications and artificial intelligence in a single Italian software, compliant with UNI 10801 and GDPR.
