What personal data does a building actually hold?
More than most committees realise. Walk through a typical building's records and you will find:
- Owners: names, postal and email addresses, phone numbers, unit and share, IBAN if the building pays anything back, ID or passport details collected for the register or a transfer.
- Financial: each owner's charges, payments, balance and arrears history; payment plans; correspondence about debt.
- Tenants: names and contact details where the regulations or a manager's practice collect them; sometimes lease dates.
- Governance: attendance lists, proxies, minutes that record who said and voted what, complaints between neighbours.
- Operational: access codes, key holders, CCTV footage where installed, contractor contacts, incident reports.
Little of this is "special category" data under the GDPR, but a balance, a debt or a dispute is sensitive in the everyday sense: the harm from a leaked arrears list is the neighbour who now knows you are three months behind.
Who is the controller — the committee, the manager or the software?
The GDPR distinguishes the controller, who decides why and how data is processed, from the processor, who processes it on the controller's instructions. In a co-owned building the community of owners — acting through its committee or equivalent organ — is typically the controller of the building's data. A professional managing agent may be a processor under the committee's mandate, a controller for its own client and staff records, or both; the management contract should say which, and a data protection lawyer can advise where it is unclear.
Software is a processor. Whoever hosts your ledger processes owners' data on your behalf and must be bound by a written contract meeting Article 28 — what the vendor may do with the data, confidentiality, security, sub-processors, deletion at the end. The supervisory authority you answer to is the one in your country: in Cyprus the Commissioner for Personal Data Protection; in the UK the Information Commissioner's Office under the UK GDPR and the Data Protection Act 2018; each EU member state has its own. Domera's privacy notice sets out its own role and commitments.
What is the lawful basis for processing owners' data?
Every processing activity needs a basis under Article 6, and for a building the usual candidates are three. Where the law or the regulations oblige the committee to keep a register of owners, collect contributions and keep accounts, processing that data is necessary for a legal obligation (Article 6(1)(c)). Where processing is necessary to run the building in the owners' collective interest — sending statements, chasing arrears, holding meetings — the committee typically relies on legitimate interests (Article 6(1)(f)), balanced against the owners' rights. A managing agent performing its contract with the community often cites the contract basis (Article 6(1)(b)).
Consent is the wrong basis for the core work: an owner cannot withdraw consent to being charged their share. Reserve it for the optional extras — publishing a phone number in an owners' directory, a newsletter, a photo from the summer party. This is general orientation; confirm your bases with a data protection adviser and write them down. Article 13 also requires you to tell owners, in plain terms, what you hold and why — a one-page notice with the welcome statement does it.
Who may see what? Minimisation in practice
Two GDPR principles do most of the work in a building: data minimisation — collect only what the purpose needs — and integrity and confidentiality — let only the people who need it see it. Applied to a building's records the rules are short.
- Each owner sees their own charges, payments and balance, and the building's totals — never another owner's balance.
- The committee sees names and balances, because it collects; the whole body of owners sees totals and counts.
- A managing agent's staff see the buildings they are assigned to, not the firm's entire portfolio.
- Tenants' data is collected only where a real purpose exists, and is not shared with other owners.
- Minutes record decisions and counted votes; they do not need to record which neighbour complained about which.
- Contractors get the access codes and contacts they need for the job, for the duration of the job.
The hard case is arrears. Owners are entitled to know that the building is owed €6,420.00 and that four owners are behind; not which four. Name an owner only where a decision requires it — a vote to take legal action — and then in the minutes of that item, not on a list in the lobby or a screenshot in the WhatsApp group. Software helps only if it enforces the rule technically: Domera's owner portal shows each owner their own account and the building's totals, a manager sees only the buildings they serve, and every change is logged in the audit trail.
How long should records be kept?
The storage limitation principle (Article 5(1)(e)) says: no longer than necessary for the purpose. For a building, the purpose is often defined by other law. Accounting records — invoices, allocations, payments, statements — must typically be kept for a period set by national tax and company law, commonly somewhere between six and ten years; confirm the figure for your country with an accountant. Minutes and resolutions are the building's governance record and are usually kept for as long as the building exists, because a resolution from 2009 can still bind owners today.
The data that should go is the data with no continuing purpose: a former owner's phone number and email once the final statement is settled; a tenant's details once the tenancy ends; a losing contractor's quotation once the tender is closed. Write a short retention schedule — dataset, purpose, period, what happens at the end — and review it yearly with the accounts. A former owner should still see the statements for their own period; they should not still receive the AGM notice.
What do you do when something goes wrong?
A personal data breach is any accidental or unlawful loss, disclosure or alteration of personal data: the balances spreadsheet emailed to the whole building instead of the treasurer, the manager's unencrypted laptop left on a bus, a portal account that showed one owner another's statement. Article 33 requires the controller to notify the supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware, unless the breach is unlikely to result in a risk to the people concerned. Article 34 requires you to tell the affected people themselves when the risk is high.
The 72 hours pass quickly, so decide the procedure before you need it: who is told first, who assesses the risk, who drafts the notification, and where the breach log lives — every breach is recorded, including those you decide not to report. The other routine request is access: under Article 15 an owner may ask for a copy of the data you hold about them, and you have one month to answer. A building whose records sit in one ledger with an owner-scoped portal answers that in minutes; one with six spreadsheets and a shoebox does not.
What should you ask a software vendor?
Choosing software is a data protection decision, because the vendor becomes your processor. Ask for demonstrations, not descriptions:
- Where is the data hosted, under which law, and who are the sub-processors?
- Is there a written processing agreement meeting Article 28, and what does it say about deletion when we leave?
- Show me what an owner sees when they sign in, and prove they cannot see another owner's balance.
- Show me how a manager's access is limited to the buildings they serve.
- Show me the audit trail for a change to an owner's share or a payment — who, when, what before and after.
- Is multi-factor authentication available, and how are staff who leave removed?
- How and how quickly will you tell us about a breach on your side?
- Can we export everything — owners, ledger, documents — in a format we can open?
Domera's technical answers are on the audit trail and security page: each company's data is isolated at the database level with row-level security, access is limited by role and building assignment, and financial and compliance records carry a log of who changed what and when. Ask us the contractual questions too — hosting location, sub-processors, the processing agreement — and file the answers with your retention schedule.
Checklist
- List every dataset the building holds, its purpose and its lawful basis, on one page.
- Give owners a plain notice of what is held and why, with the welcome statement.
- Enforce the rule that each owner sees only their own account; report arrears to the body of owners as totals.
- Write a retention schedule tied to your country's accounting retention period, and review it yearly.
- Agree a breach procedure now — who is told, who assesses, who notifies within 72 hours — and keep a breach log.
- Sign an Article 28 processing agreement with every vendor that touches owners' data, and check their access controls live.
- Delete what has no purpose: former owners' contact details, ended tenancies, closed tenders.
Frequently asked questions
- Does the GDPR apply to a small self-managed building?
- Yes. The regulation applies to any organisation processing personal data, and a committee keeping an owners' register and accounts is doing so. Some administrative obligations are lighter for small organisations, but the principles — lawful basis, minimisation, security, breach notification — apply regardless of size.
- Can we post the arrears list in the lobby to encourage payment?
- No. Disclosing named owners' debts to their neighbours is hard to justify under any lawful basis and is the kind of disclosure that draws complaints to the supervisory authority. Report totals to owners; pursue individuals privately and through the process the regulations allow.
- Can an owner demand to see another owner's data?
- Not as a rule. The right of access under Article 15 is to one's own data. Owners are generally entitled to inspect the building's accounts and records, but the committee should provide those in a form that does not disclose other owners' personal balances unless the law in your country specifically requires it.
- Is it acceptable to run the building on a WhatsApp group?
- For notices and general discussion, many buildings do. For anything involving an individual's data — balances, disputes, complaints about a named neighbour — it is not the place: everyone sees everything, nothing can be retracted, and the committee has no control over who saves what.
- Do we need a data protection officer?
- Generally not for an ordinary residential building, as we understand Article 37: the mandatory DPO applies to public authorities and to organisations whose core activities involve large-scale or systematic monitoring or special-category data. A large managing agent should check its own position. Naming one responsible person is good practice either way.