Comparison
Condominium data security: cloud or on-premise
The condominium registry required by Article 1130, paragraph 6 of the Italian Civil Code contains owners' personal data, from tax codes to cadastral details and the safety conditions of common areas. Safeguarding it is an obligation that falls on the administrator as the data controller under the GDPR. The practical question is where to keep it: in the cloud, on infrastructure managed by a provider, or on-premise, meaning on a server or computer in the office. The difference is not ideological but operational, and it concerns who handles backups, encryption and updates, and how responsibilities are shared. This guide compares the two models concretely, without slogans, to help you choose with awareness.
Compared
| Criterion | On-premise data (in the office) | Cloud data |
|---|---|---|
| Who manages backups and redundancy | The administrator, with their own procedures and media | The provider, with automatic backups and redundant infrastructure |
| Security updates | To be applied manually to the operating system and software | Managed centrally and distributed continuously |
| GDPR roles | The administrator is the controller and manages everything alone | Administrator is controller, provider is processor (Article 28) |
| Protection from failures and physical theft | Depends on the measures adopted in the office | Data centres with dedicated physical and environmental measures |
| Direct control over the infrastructure | Total, but requires dedicated skills and time | Delegated to the provider, to be verified by contract and guarantees |
What the GDPR actually says
The GDPR, EU Regulation 2016/679, does not require keeping data in one place rather than another: it requires protecting it with technical and organizational measures adequate to the risk. The administrator is the data controller and answers for protecting the owners' data, whether it is kept on an office computer or on a cloud platform.
When data is processed through a cloud provider, that provider takes on the role of data processor under Article 28 of the GDPR, and the relationship must be governed by a written agreement defining guarantees and instructions. So it is not true that the cloud releases the administrator from their responsibilities: it keeps them, but shares them with a party that must offer documented guarantees.
On-premise: total control, total burden
Keeping data on an office server or computer gives the administrator direct control over the infrastructure, which may seem safer. In practice that control translates into burdens: configuring and maintaining technical safeguards, applying security updates to the operating system and software, managing backups and keeping them in a separate location, protecting the device from failures, theft, fire and flooding.
If these activities are carried out competently and continuously, on-premise can be secure. The real risk is that, in small practices without dedicated technical staff, many of these measures remain incomplete: a computer that is not updated, without regular backups and without encryption, is more exposed than one might think, and a single failure can cause data loss.
Cloud: managed infrastructure, delegated control
A cloud platform shifts much of the operational burden onto the provider: automatic backups, data redundancy, continuous security updates, data centres with dedicated physical and environmental measures. For a practice without in-house IT skills, this raises the level of protection compared with what it could achieve alone.
The trade-off is that direct control over the infrastructure is delegated: the administrator must trust the provider's guarantees, which need to be verified. It is essential to check the contract terms, the presence of data encryption, where the data centres are located and which security certifications the provider declares. The cloud is not secure by definition, it is secure to the extent that the provider makes it so and documents it.
What to verify before choosing
Beyond the cloud or on-premise label, security is judged on the facts. Before deciding, it helps to verify some concrete elements, the same for both models, adapted to whoever is responsible for them:
- Regular, verified backups kept separately from the primary data
- Data encryption, both in transit and at rest
- Security updates applied continuously
- Permission management by role, so each person accesses only what concerns them
- In the cloud, a written agreement with the provider as data processor
- On-premise, physical protection of the device from theft, failure and environmental damage
How to orient yourself
A practice with in-house IT skills, able to maintain the infrastructure with the necessary continuity, can manage data on-premise. Most practices, however, have no staff dedicated to these activities, and for them a professionally managed cloud platform generally offers a higher and more consistent level of protection, provided you choose a provider that is transparent about its guarantees.
AmministraPro uses the cloud model with centralized data, managed backups and encryption, operating as data processor for the administrator as controller. The features page covers aspects related to security and the owners' reserved area, while the plans section clarifies what is included in the service.
Frequently asked questions
Is cloud data less secure because it leaves the office?
Security does not depend on the physical location of the data but on the measures adopted. A professionally managed data centre, with automatic backups, encryption and redundancy, generally offers stronger guarantees than a single, unupdated office computer. What matters is verifying the cloud provider's guarantees and governing the relationship with an agreement under Article 28 of the GDPR, not the fact that the data does not sit in the office.
With the cloud does the administrator stop being responsible for the data?
No. The administrator remains the data controller and continues to answer for protecting the owners' data. The cloud provider becomes the data processor under Article 28 of the GDPR and must offer documented guarantees, but responsibility toward the owners and the supervisory authority is not transferred: it is shared with a party acting on the controller's instructions.
Does on-premise mean backups are not needed?
On the contrary: on-premise, backups are entirely the administrator's responsibility, who must run them regularly, verify their integrity and keep them in a location separate from the primary data. A local archive without backups is among the riskiest situations, because a single failure, theft or damage can cause the permanent loss of the owners' data, with consequences under the GDPR as well.
Where is the data kept with a cloud platform?
It depends on the provider, and it is something to verify before choosing. It is advisable to ask where the data centres are located, whether the data stays within the European Union and which security certifications the provider declares. This information, together with the processing agreement, lets the administrator judge whether the guarantees are adequate to the risk of the condominium data being handled.
How do I prove I protected the data in case of an audit?
In both models it helps to keep a record of the measures adopted: backup procedures, permission management, updates applied. In the cloud, the agreement with the provider and its documented guarantees are part of this proof. On-premise, documenting the measures falls entirely on the administrator. Being able to show a coherent set of adequate measures is what the GDPR asks of the data controller.
Try AmministraPro
Accounting, thousandths-based cost splitting, meetings, communications and artificial intelligence in a single Italian software, compliant with UNI 10801 and GDPR.
