Salta al contenuto principale

Practical guide

Data protection impact assessment: when a condominium needs one

The data protection impact assessment, often called DPIA, is the analysis the controller must carry out when a processing activity may present a high risk to people's rights and freedoms. It does not concern every activity of a management firm, but some condominium processing may require it, in particular video surveillance of common areas and access control systems. This guide explains when the assessment is needed, how it is structured and how to document it, so as to avoid both omission and wasting resources on processing that does not require it.

When to assess whether a DPIA is needed

  1. The processing involves systematic monitoring of publicly accessible areas, such as video surveillance.
  2. Data is processed on a large scale or involves special categories, for example health or biometric data.
  3. New technologies or access control solutions using biometric data are used.
  4. The processing combines several data sets or evaluates personal aspects of data subjects.
  5. When in doubt, document at least a preliminary risk assessment.
  6. If an unmitigable high risk emerges, consult the supervisory authority before starting.

What a DPIA is and where the duty comes from

Article 35 of the GDPR provides that, where a type of processing is likely to result in a high risk to the rights and freedoms of natural persons, the controller must carry out an impact assessment first. It is a prevention tool: it serves to identify risks and decide on measures to reduce them before starting the processing, not after the fact.

In a condominium the controller is the body of participants and the administrator organises the processing on its behalf. The DPIA is therefore not an abstract task but a concrete responsibility of whoever decides to install, for example, a video surveillance system filming entrances, courtyards or common areas used daily by owners and third parties.

The condominium cases where it may be needed

The most typical case is video surveillance of common areas. A system that systematically monitors accessible areas is among the processing activities that may require an impact assessment, especially when cameras cover wide zones or continuously film people passing by. The same applies to access control systems that use biometric data.

Not all condominium processing requires a DPIA. Ordinary management of records, accounting and communications does not usually present a high risk. The key is to distinguish: the assessment should be concentrated where the risk is truly significant, not applied indiscriminately to every spreadsheet.

  • Systematic video surveillance of common areas.
  • Access control using biometric data.
  • Processing that combines data from different sources on a large scale.
  • The introduction of new technologies whose effects are not yet known.

How the assessment is structured

A well-made impact assessment first describes the processing: what data, for what purposes, for how long and with what tools. It then evaluates necessity and proportionality, that is whether the purpose can be achieved with less invasive means, and analyses the risks to data subjects, indicating the measures planned to reduce them, such as limiting the areas filmed, short retention times and control of access to the footage.

If, despite the measures, an unmitigable high risk remains, the controller must consult the supervisory authority in advance. In condominium practice the assessment should be kept together with the owners' resolution authorising the system and the notice on display, so as to have a coherent documentary picture.

Documenting and reviewing the assessment

The impact assessment is not a document to file and forget. It must be reviewed when the elements of the processing change: new cameras, different coverage, a change of purpose or retention time. Each update must be dated and kept in the compliance file, together with the original assessment.

Software that keeps documents, resolutions, deadlines and notices together helps maintain the entire documentary set of the processing in order, including impact assessments and the measures adopted. AmministraPro's features are described on the /funzioni page and the plans on the /prezzi page.

Frequently asked questions

Does condominium video surveillance always require a DPIA?

Not automatically, but systematic video surveillance of accessible areas is among the processing activities that may present a high risk and therefore require an impact assessment. The decision depends on the extent, purpose and methods of the system. When in doubt it is advisable to carry out and document at least a preliminary risk assessment.

Who must carry out the impact assessment in a condominium?

The duty lies with the controller, that is the condominium, but in practice it is the administrator who organises it on its behalf, involving a consultant if needed. The assessment should be approved together with the decision to install the system and kept as evidence of compliance.

What happens if a high risk emerges?

If, after planning the mitigation measures, a high risk remains that cannot be reduced, the controller must consult the supervisory authority in advance before starting the processing. This consultation is a step provided by Article 36 of the GDPR and must be documented in the file.

Does ordinary management of records require a DPIA?

Usually not. Keeping records, accounting and ordinary communications does not present a high risk to data subjects' rights and does not require an impact assessment. The DPIA should be concentrated on genuinely risky processing, not applied to every activity of the firm.

Try AmministraPro

Accounting, thousandths-based cost splitting, meetings, communications and artificial intelligence in a single Italian software, compliant with UNI 10801 and GDPR.