Salta al contenuto principale

Features & tools

Security and privacy of the owner's private area

The owner's private area contains personal data and financial information: names, ownership shares, balances, building documents. Putting them online means taking on a precise responsibility, which EU Regulation 2016/679 assigns to the administrator as the controller of the condominium's data. The security of the private area is therefore not just a technical matter of the software, but a legal obligation that translates into concrete measures: how you log in, how the data is stored and who can see what. This guide explains the elements that genuinely make a private area secure, what the administrator should demand from their software and which precautions fall to the individual owner.

Access: the first line of defence

A private area is secure first of all in the way you enter it. Access must take place with personal credentials, a password stored only in encrypted form and not visible to whoever manages the condominium. The administrator enables access, but must not be able to enter the owner's area on their behalf nor know their password.

The second authentication factor, where available, raises the level considerably: even if a password were discovered, access would require an additional temporary code. It is not a specific legal obligation, but it is among the technical measures appropriate to the risk that the GDPR requires when processing personal data, especially when accompanied by financial information.

  • Personal, nominal credentials, never shared
  • Password stored only in encrypted form
  • Second authentication factor where available
  • Sessions that expire and time-limited activation links

Everyone sees only what belongs to them

Security is not only about keeping strangers out, but also about preventing a legitimate owner from seeing data that does not concern them. The private area must separate information by unit: the owner of flat 3 sees their own accounting position, the documents of the common parts and what concerns their property, not the balances of other owners.

This principle of minimisation, a cornerstone of the GDPR, has a precise technical translation: the data requests the app sends to the server must be filtered on the server side according to who is authenticated, not merely hidden in the interface. Data hidden on screen but still downloadable would be a flaw. Communications addressed to the whole condominium remain visible to all, but the individual financial position stays reserved to the unit's owner.

Encryption and data retention

Data must travel encrypted between the app and the server, typically over a protected connection, and the most sensitive information, such as access credentials or any integration keys, must be stored encrypted at rest as well. This reduces the impact of any unauthorised access to the systems.

Retention over time is also part of security. The GDPR requires that data not be kept longer than necessary for the purposes for which it is processed. In the condominium context this must be balanced against the administrator's obligations to keep documentation, but the principle remains that an access no longer current, such as that of a former owner after a sale, must be deactivated without leaving orphaned positions.

The responsibilities of the administrator and the owner

The administrator is the controller of the condominium's data and is accountable for its protection. They must choose tools that offer adequate security measures, inform owners about how the data is processed and manage access correctly, deactivating what is no longer justified. If they rely on a software provider, that provider normally acts as processor, under an agreement defining its obligations and guarantees.

The owner is responsible for looking after their own credentials: a strong, non-reused password, activating the second factor when offered, wariness towards data requests made by phone or suspicious emails. In AmministraPro the private area separates data by unit with server-side controls, keeps credentials in encrypted form and lets the administrator enable and revoke access from the register; the security measures and plans can be explored on the software's features and pricing pages.

Frequently asked questions

Who is responsible for data protection in the owner's private area?

The administrator is the controller of the condominium's personal data under EU Regulation 2016/679, so they are accountable for its protection: they must adopt security measures appropriate to the risk, inform owners about the processing and manage access correctly. The software provider normally acts as processor, on the basis of an agreement establishing its obligations and guarantees.

Can another owner see my balance or my data?

In a well-designed private area, no. The GDPR principle of minimisation requires that each person see only the data that concerns them: the individual accounting position remains visible only to the unit's owner. Communications and documents addressed to the whole condominium are instead shared with everyone. The separation must be guaranteed on the server side, not just by hiding data in the interface.

Is the second authentication factor really necessary?

It is not a specific legal obligation, but it is a very effective technical measure and consistent with the GDPR requirement to adopt measures appropriate to the risk. The private area contains personal and financial data, so a second factor, which requires a temporary code in addition to the password, protects access even if the password alone is discovered. Where it is offered, it is worth activating.

What happens to my access when I sell the property unit?

The former owner's access must be deactivated and the new owner's enabled. This is a step the administrator governs from the condominium register, consistent with the GDPR principle of not keeping data and access longer than necessary. Well-built software makes this transition immediate without leaving orphaned accounts that would keep showing data to someone who no longer owns the property.

How can I contribute to the security of my private area?

By choosing a strong password not reused on other services, activating the second authentication factor when available and never sharing the activation link, which is personal. It is also important to be wary of credential requests made by phone or through suspicious emails: a serious administrator never asks for the owner's password, because they must neither know nor store it.

Try AmministraPro

Accounting, thousandths-based cost splitting, meetings, communications and artificial intelligence in a single Italian software, compliant with UNI 10801 and GDPR.