Salta al contenuto principale

Choosing software

Sub-processors behind condominium software: what to ask

A condominium platform rarely works alone. Behind it there are often other suppliers: the one that hosts the infrastructure, the one that sends emails, the one that handles notifications, the one that provides support. Each of these parties may process the condominium's personal data and, in GDPR terms, becomes a sub-processor. Before choosing the software it is worth asking for the list of these parties, because the supply chain is an integral part of data security. A transparent vendor provides it without difficulty. This guide explains what to ask and how to read the answer.

What to check about the supply chain

  1. Is there an up-to-date list of sub-processors?
  2. For each one, is the activity performed and the location indicated?
  3. Does the vendor give advance notice when a new sub-processor is added?
  4. Are sub-processors bound by the same obligations as the vendor?
  5. Can the controller object to a new sub-processor?

Why the supply chain matters

The condominium's data does not necessarily stay with a single party. The infrastructure may belong to a cloud provider, the sending of communications to a mail service, the support to an external company. Each of these links is a point where data is processed and potentially exposed. Knowing the chain means understanding how many parties actually see the condominium's information.

Article 28 of the GDPR establishes that a processor may not engage another processor without the controller's authorization and must impose on it, by contract, the same protection obligations. In practice the vendor is answerable for its own chain. The manager therefore has the right to know who is behind it and on what basis they operate.

What answer to expect

A mature vendor keeps a list of sub-processors that is current and accessible, often published or attached to the data processing agreement. For each party it states the activity performed, for example hosting or email delivery, and the location. This transparency lets the manager reconstruct the data trail and assess its risks.

The weak answer comes from a vendor that cannot say who processes the data beyond itself or treats the information as confidential. If the vendor cannot name its sub-processors, it has probably not imposed adequate contractual obligations on them. This is a sign that security governance stops at the surface.

  • Public or attached list, with activity and country for each sub-processor.
  • Commitment to give advance notice when a sub-processor is added or replaced.
  • The controller's right to object to a new sub-processor on reasonable grounds.
  • Contractual obligation extending the same protection duties to sub-processors.

The questions to ask when choosing

First ask for the complete and up-to-date list. Then check how changes are handled: a proper vendor notifies the controller before introducing a new sub-processor, leaving room to object. Also ask whether the sub-processors are in the European Union or elsewhere, because a non-EU location triggers additional safeguards.

Finally, look into oversight. The vendor should state how it monitors its sub-processors and how it ensures they respect the security measures. A detailed audit of each party is not needed, but a vendor that exercises no control over its own chain shifts the risk downstream, onto the manager.

Keeping track of changes over time

The supply chain is not static. Over time a vendor may change infrastructure provider or add new services. That is why it is important for the list to be kept current and for updates to be communicated. Keep the version you received together with the data processing agreement, so you have a reference in case of an inspection.

AmministraPro makes the list of sub-processors, with their respective activities, available to managers and communicates its updates. You can explore the data management framework on the /funzioni page and compare the plans on /prezzi before choosing.

Frequently asked questions

What is a sub-processor?

It is a supplier to which the processor, meaning the software company, entrusts part of the data processing. Typical examples are the cloud infrastructure provider or the email delivery service. Under Article 28 of the GDPR the sub-processor must be bound by the same protection obligations.

Do I have the right to know my platform's sub-processors?

Yes. Since the condominium is the data controller, the manager has the right to know who processes the data along the supply chain. The vendor should provide an up-to-date list of sub-processors indicating the activity performed and the location.

Can I object to the addition of a new sub-processor?

It depends on how the agreement is worded. Many contracts provide that the vendor gives advance notice of a new sub-processor and that the controller may object on reasonable grounds. Check this clause before signing, because it protects your ability to control the data.

Why does the location of sub-processors matter?

Because if a sub-processor is based outside the European Economic Area, the data transfer requires additional safeguards such as standard contractual clauses. Knowing the location lets the manager understand which obligations fall on the condominium and assess the risks.

Try AmministraPro

Accounting, thousandths-based cost splitting, meetings, communications and artificial intelligence in a single Italian software, compliant with UNI 10801 and GDPR.