Salta al contenuto principale

Security & privacy

Security of condominium data in the cloud

The data a property manager handles, resident records, budgets, meeting minutes, tax documents, are sensitive personal and financial information, and under GDPR the manager acts as data controller. For years the common practice was to keep everything in a spreadsheet or software installed on a single office computer: a fragile setup, tied to one device, without automatic backups and without any record of who accessed what. Moving to cloud based management software changes these conditions, but not automatically: security depends on how the provider designed encryption, access profiling, backups and service continuity. This guide explains what to actually check, with reference to the obligations of Italian civil law and GDPR that apply to property managers.

The risk of the local file: why the old model is not enough

A condominium archive kept on an office PC or a USB drive carries structural risks that well designed cloud software removes at the root. The first is loss: hardware failure, theft or human error can wipe out years of documentation with no way to recover it, directly affecting the manager's duty to retain accounting records and meeting minutes for the period required by law.

The second risk is undifferentiated access: on a local file shared across an office, everyone often sees everything, with no way to limit visibility to only the staff actually handling a given building. This conflicts with the GDPR principle of data minimization, under which personal data should be accessible only to those who genuinely need it to perform their duties.

Encryption of data: at rest and in transit

Serious cloud management software encrypts data at two distinct moments. In transit, meaning while data moves between the manager's device and the servers, through protected connections that prevent interception while data travels across the network. At rest, meaning when data is stored on the servers, so that even in the event of unauthorized access to the infrastructure the information is not readable without the correct keys.

For a property manager, checking this means asking the provider for a clear statement on how data is protected at these two stages: there is no need to understand implementation details, only to know that a defined and documentable policy exists, which is also useful when drafting the record of processing activities required by GDPR.

Role based access: who sees what, and why it matters for a condominium

Access profiling allows distinct roles to be defined: the managing agent, office staff, external consultants, and even individual residents through a personal area where each one sees only their own data, their own installments, their own account position, and not the data of other residents.

This aligns with Article 1130 bis of the Italian Civil Code, which governs the condominium financial statement and residents' right to review accounting documents: a properly profiled personal area makes this right exercisable independently, without the manager having to physically extract and hand over copies, and without exposing other residents' personal data in one indiscriminately shared file.

Backups and continuity: what happens if the office closes or the manager changes

Article 1129 of the Italian Civil Code requires an outgoing manager to hand over all condominium documentation to the incoming one. With a local archive, this handover depends on the diligence, and availability, of the outgoing manager. With a cloud archive structured per building, documentation remains accessible and transferable regardless of which individual happens to be running the office at that moment, reducing the risk of disputes over missing records.

Continuity is also measured by the frequency and reliability of backups: a cloud provider should guarantee regular backup copies of data, something a single office PC normally does not offer in a structured way. It is worth asking the provider how backups are handled and what happens in case of a server side failure.

What to actually ask before choosing management software

Software such as AmministraPro was built to address exactly these points in a structured way: role based access profiling, a personal area for residents, automatic backups and orderly document retention for every building managed. Anyone evaluating the move from a local file to the cloud can review the available features on the features page and compare plans on the pricing page.

  • Who is the data controller and who is the data processor, and whether a processing agreement exists as required by Article 28 of GDPR.
  • Whether data is encrypted both in transit and at rest, with a documentable policy.
  • Whether access for each staff member can be limited to only the buildings they actually manage.
  • Whether there is a personal area for residents with access limited to their own data, consistent with Article 1130 bis of the Italian Civil Code.
  • How backups work and how frequently they run.
  • What happens to the data if the manager changes or the relationship with the provider ends.
  • How compliance with the UNI 10801 standard on condominium management service requirements is handled, where applicable.

Frequently asked questions

Is the cloud safer than a spreadsheet on the manager's PC?

In most cases yes, provided the cloud provider applies data encryption, regular backups and role based access. A local file offers none of these protections by default: it depends entirely on individual diligence, it is not encrypted, it has no automatic backups, and it is often accessible to anyone with access to the office PC or network.

Is the manager still responsible for the data even when using cloud software?

Yes. The property manager is the data controller under GDPR regardless of the tool used. When processing is delegated to a cloud provider, the provider acts as data processor under Article 28 of GDPR, and an agreement should exist governing that relationship. Responsibility toward residents still rests with the manager.

Can individual residents see other residents' data in the software?

In software with correctly profiled access, no: each resident, through their personal area, sees only their own account position and the documents concerning them, not those of other residents in the same building. This is consistent with both the GDPR minimization principle and the right of access to documents under Article 1130 bis of the Italian Civil Code, which covers one's own data, not that of others.

What happens to the condominium's data if the manager changes?

Article 1129 of the Italian Civil Code requires the outgoing manager to hand over all documentation to the incoming one. With cloud software organized per building, such as AmministraPro, documentation remains attached to the building itself and the handover is more orderly, since it does not depend on manually recovering files scattered across different devices.

Do residents need to give consent for the manager to use cloud management software?

Processing of residents' data by the manager is typically based on the performance of the management mandate, not on individual consent. However, the manager must inform residents about the processing through a privacy notice and must choose providers that offer adequate security guarantees, consistent with the accountability obligations under GDPR.

Try AmministraPro

Accounting, thousandths-based cost splitting, meetings, communications and artificial intelligence in a single Italian software, compliant with UNI 10801 and GDPR.