GDPR for Spanish Property Managers: Obligations and Risks 2026
Spanish property managers (administradores de fincas) process personal data every day: owners' names and national ID numbers, IBANs for fee direct debits, debt and arrears records, CCTV footage from communal areas. All of this falls under the GDPR (Regulation (EU) 2016/679) and Spain's LOPDGDD (Organic Law 3/2018). Non-compliance is actively sanctioned by the AEPD (Spanish Data Protection Agency) with fines reaching €20M or 4% of global turnover — and the property management sector has been a recurring target.
Data processor (GDPR Art. 4): An entity that processes personal data on behalf of a data controller. In a Spanish owners' community, the data controller is the community itself (represented by the board of owners). The property manager acts as the data processor — not the controller. This distinction determines who signs the DPA and who is primarily liable to the AEPD.
72h
"Maximum time to notify a data breach to the AEPD if it may pose a risk to owners (Art. 33 GDPR). Missing this deadline can double the base fine."
— Regulation (EU) 2016/679, Art. 33
What personal data does a property manager process?
The volume and variety of personal data handled by a property management firm is larger than it first appears:
- Owner identification data: full name, national ID (DNI/NIF), address, phone number, email
- Bank data for fee direct debits: IBAN (sensitive data with fraud risk)
- Debt and arrears data: amounts owed, claims history (sensitive economic data)
- CCTV footage from communal areas: entrance hall, car park, swimming pool
- Tenant data in communities that formally register them
- Community employee data: caretakers, concierges (full employment relationship)
- Health data in special cases: residents with disabilities or accessibility needs
What specific GDPR obligations apply to a property manager?
- Data Processing Agreement (DPA): a signed DPA must exist between the property manager and each community they manage, defining what data is processed, for what purpose, for how long and with what security measures.
- Record of Processing Activities (RoPA): document all data processing activities with purpose, legal basis, recipients and retention periods (Art. 30 GDPR).
- Privacy information clause for owners: when collecting data (management contract, forms) owners must be informed of who processes their data, for what purpose and for how long (Arts. 13-14 GDPR).
- Legal basis for each processing activity: fees are covered by contract performance (Art. 6.1.b); CCTV by legitimate interest (Art. 6.1.f) plus a mandatory notice sign.
- Data subject rights: access, rectification and erasure requests must be answered within one month (Arts. 12-22 GDPR). Arrears status does not justify denying a data access request.
- Data breach notification: within 72 hours to the AEPD if the breach may pose a risk to owners' rights (Art. 33 GDPR).
- DPA contracts with suppliers: any SaaS company (property management software, cloud services) that accesses personal data is a data processor. A signed DPA with each one is mandatory.