GDPR Checklist for Spanish Property Managers: 15 Points to Meet
Updated: August 2026 · Reading time: 8 min
Knowing that GDPR applies to you doesn't help much if you don't know exactly what to check on Monday morning. This checklist turns the obligations of Regulation (EU) 2016/679 and Spain's LOPDGDD (Organic Law 3/2018) into 15 concrete audit points, built for the daily reality of a Spanish property management firm (administrador de fincas). Use it as an internal verification list, not as a substitute for advice from your DPO or lawyer.
Before you start: in most owners' communities, the data controller is the community itself (represented by its board) and the property manager acts as data processor (Art. 4(8) GDPR). This checklist covers the obligations that fall on the firm as processor, plus the ones it should verify the community meets as controller.
Block 1 · Legal basis and transparency (points 1-4)
Identify the legal basis for each processing activity
Fees and routine management → contract performance (Art. 6(1)(b) GDPR). CCTV → legitimate interest (Art. 6(1)(f)) plus a notice sign. Marketing communications from the firm → consent (Art. 6(1)(a)). If you cannot state the legal basis for a processing activity in one sentence, it is not properly justified.
Keep your privacy notice ready (Arts. 13-14 GDPR)
Every owner must know, at the point their data is collected, who processes it, for what purpose, for how long, and how to exercise their rights. Check that the management contract and onboarding forms include it, not just the firm's website.
Keep the Record of Processing Activities (RoPA) up to date
Art. 30 GDPR requires documenting each processing activity: purpose, categories of data and data subjects, recipients, retention periods and security measures. A firm managing several communities is almost always required to keep this record, regardless of any single community's size.
Never post arrears information on notice boards or general-access minutes
Debt is personal data of an economic nature. The AEPD repeatedly fines this practice. It can appear in internal board documentation, but never be displayed in communal areas.
Block 2 · Retention periods (points 5-7)
CCTV footage: 30-day maximum
Art. 22 LOPDGDD sets a maximum 30-day retention period for footage from communal-area cameras, unless it must be kept as evidence of an offence or criminal act. Check the actual recorder configuration, not just what the installer's contract states.
Minutes and accounts: 5-10 years
Minutes and accounts must be kept for at least 5 years under Spanish tax and accounting obligations (General Tax Law). GDPR also requires that personal data not be kept longer than necessary for the original purpose: define your firm's criterion in writing (typically 5-10 years) and apply it consistently.
Departing owners (property sold)
Do not delete their data immediately: outstanding debts or open claims may justify keeping it for the applicable statute-of-limitations period. Document the blocking/erasure criterion your firm applies so it is not left to each staff member's own judgement.
Block 3 · Data processing agreements with suppliers (points 8-10)
Inventory every supplier with access to data
Property management software, cloud accounting, resident communication platforms, payroll services for caretakers, SMS/email providers — any company that accesses personal data from the communities you manage is, under GDPR, a data processor (Art. 28 GDPR).
Confirm a signed DPA exists with each of them
Art. 28(3) GDPR requires the contract with each processor (or sub-processor) to specify: subject matter and duration of processing, nature and purpose, type of data and categories of data subjects, and the controller's obligations and rights. If a supplier cannot provide its DPA, treat that as a red flag.
Confirm where the data is hosted
If any supplier transfers data outside the EU/EEA, an adequate safeguard must be in place (standard contractual clauses, an adequacy decision) under Chapter V GDPR. Ask explicitly about server location — do not assume it is within the EU.
Block 4 · Security breaches (points 11-12)
72 hours
Maximum time to notify a security breach to the AEPD from the moment you become aware of it, if it may pose a risk to owners' rights (Art. 33 GDPR). Missing the deadline is an aggravating factor that can increase the fine.
Have a written breach notification procedure
Don't improvise on the day of the incident. Define: who detects and escalates a breach internally, who decides whether owners are at risk, who drafts and submits the notification to the AEPD (Art. 33 GDPR) through its electronic office, and when affected owners must also be notified directly (Art. 34 GDPR, when the risk is high).
Keep a breach register, whether notified or not
Art. 33(5) GDPR requires documenting every security breach, its effects and the remedial measures taken, even if you concluded it did not need to be notified to the AEPD. That register is the first thing an inspector will ask for during an audit.
Block 5 · Owners' rights and special category data (points 13-15)
Respond to access, rectification and erasure requests within one month
Arts. 12-22 GDPR set a one-month deadline (extendable by two further months for complex requests, with the reason notified). An owner's arrears status is never a valid reason to deny them access to their own data. Keep a response template and a clear intake channel for these requests.
Treat health data as special category data (Art. 9 GDPR)
When an owner requests an accessibility adaptation (a ramp, an adapted lift, a reserved parking space) due to reduced mobility or a disability, that request can carry information about their health. Health data falls within Art. 9 GDPR special categories, whose processing is prohibited by default except for specific exemptions — including the data subject's explicit consent (Art. 9(2)(a)) or where processing is necessary to comply with accessibility-related obligations. In practice: collect only the minimum data needed (a justification of the need, not a full diagnosis), restrict who within the firm can see it, and do not merge it with the owner's general arrears or complaints file.
Train the team and review this checklist yearly
Staff turnover and regulatory changes make a two-year-old checklist stale. Schedule an annual review of these 15 points, especially after onboarding a new SaaS supplier or changing your CCTV system.
IgeraFincas helps meet several of these points by design
DPA included in all plans, EU-only servers, full multi-tenant isolation, AES-256 encryption, conversation retention capped at 30 days. 14-day free trial.
Try free for 14 daysFrequently asked questions
Does this checklist replace a formal GDPR audit?
No. It is a quick self-assessment guide to spot the most common compliance gaps in the sector. For a full audit with risk analysis and legally binding documentation, consult a data-protection lawyer or your DPO.
What if I find gaps in several of these 15 points?
Prioritise by risk: start with points 11-12 (breach procedure) and point 14 (health data), since they carry the most serious sanctions and involve the most sensitive data. Then review supplier DPAs (points 8-10), which are usually a quick administrative fix.
Does a request for an adapted parking space always involve health data?
Not necessarily, but when the justification rests on a medical condition or disability, that information does fall under the Art. 9 GDPR special categories. A disability certificate or medical report submitted with the request must be handled with the same care as any health data: restricted access and retention limited to the purpose.
Do I need to repeat the whole checklist for every community I manage?
The points about SaaS suppliers and the breach procedure (8-12) apply firm-wide and only need reviewing once. The points about CCTV, the privacy notice and special category data (1-2, 5, 14) can vary community by community, depending on whether they have cameras, their access setup, or any active accessibility requests.
Article produced by the Igera Solutions editorial team. Based on Regulation (EU) 2016/679 (GDPR) and Organic Law 3/2018 (LOPDGDD), updated August 2026. Does not constitute legal advice.