RegTech

GDPR for Spanish Property Managers: Obligations and Risks 2026

Gerard Maymó
June 17, 2026
7 min read
GDPR for Spanish Property Managers: Obligations and Risks 2026
GDPR · Property Managers · 2026

GDPR for Spanish Property Managers: Obligations and Risks 2026

Spanish property managers (administradores de fincas) process personal data every day: owners' names and national ID numbers, IBANs for fee direct debits, debt and arrears records, CCTV footage from communal areas. All of this falls under the GDPR (Regulation (EU) 2016/679) and Spain's LOPDGDD (Organic Law 3/2018). Non-compliance is actively sanctioned by the AEPD (Spanish Data Protection Agency) with fines reaching €20M or 4% of global turnover — and the property management sector has been a recurring target.

Data processor (GDPR Art. 4): An entity that processes personal data on behalf of a data controller. In a Spanish owners' community, the data controller is the community itself (represented by the board of owners). The property manager acts as the data processor — not the controller. This distinction determines who signs the DPA and who is primarily liable to the AEPD.

72h

"Maximum time to notify a data breach to the AEPD if it may pose a risk to owners (Art. 33 GDPR). Missing this deadline can double the base fine."

— Regulation (EU) 2016/679, Art. 33

What personal data does a property manager process?

The volume and variety of personal data handled by a property management firm is larger than it first appears:

  • Owner identification data: full name, national ID (DNI/NIF), address, phone number, email
  • Bank data for fee direct debits: IBAN (sensitive data with fraud risk)
  • Debt and arrears data: amounts owed, claims history (sensitive economic data)
  • CCTV footage from communal areas: entrance hall, car park, swimming pool
  • Tenant data in communities that formally register them
  • Community employee data: caretakers, concierges (full employment relationship)
  • Health data in special cases: residents with disabilities or accessibility needs

What specific GDPR obligations apply to a property manager?

  1. Data Processing Agreement (DPA): a signed DPA must exist between the property manager and each community they manage, defining what data is processed, for what purpose, for how long and with what security measures.
  2. Record of Processing Activities (RoPA): document all data processing activities with purpose, legal basis, recipients and retention periods (Art. 30 GDPR).
  3. Privacy information clause for owners: when collecting data (management contract, forms) owners must be informed of who processes their data, for what purpose and for how long (Arts. 13-14 GDPR).
  4. Legal basis for each processing activity: fees are covered by contract performance (Art. 6.1.b); CCTV by legitimate interest (Art. 6.1.f) plus a mandatory notice sign.
  5. Data subject rights: access, rectification and erasure requests must be answered within one month (Arts. 12-22 GDPR). Arrears status does not justify denying a data access request.
  6. Data breach notification: within 72 hours to the AEPD if the breach may pose a risk to owners' rights (Art. 33 GDPR).
  7. DPA contracts with suppliers: any SaaS company (property management software, cloud services) that accesses personal data is a data processor. A signed DPA with each one is mandatory.

What specific rules apply to CCTV in communal areas?

Security cameras in entrance halls, car parks and communal areas require specific measures under GDPR and Spain's LOPDGDD:

  1. Mandatory notice sign in the monitored area, clearly visible and showing the data controller's identity (the community, not the manager).
  2. Maximum 30-day retention period (Art. 22 LOPDGDD), except where the footage proves an offence or criminal act.
  3. Prior assembly approval required to install or extend the CCTV system. It cannot be installed unilaterally by the property manager.
  4. Restricted access: only the authorised property manager and the community president may access recordings.

What concrete risks exist if you do not comply with GDPR?

The AEPD actively inspects owners' communities. The most commonly sanctioned violations in the property management sector:

  • Posting debtor lists on community notice boards (public exposure of financial data): typical fines €3,000-€15,000
  • CCTV without notice signs or with retention exceeding 30 days: fines €5,000-€20,000
  • Sharing owners' data with third parties (debt collection agencies, suppliers) without a DPA or prior notification: fines €10,000-€50,000
  • Failing to respond to access or erasure requests within one month: warning or fine depending on recidivism
  • Data breach not notified to the AEPD within 72 hours: aggravating factor that can double the base fine

How does IgeraFincas implement privacy by design?

IgeraFincas acts as a data processor for the property manager and has been built with privacy by default:

  • DPA included in all plans at no extra cost
  • EU-only servers with no data transfers to third countries
  • Full multi-tenant isolation: each community's data is completely separated from all others
  • AES-256 encryption at rest and TLS 1.3 in transit
  • The AI model is never trained on individual community residents' data
  • Limited retention: owner conversations are not stored for more than 30 days
GDPR obligationResponsible partyIgeraFincas covers it
DPA contract with the communityProperty managerDPA included
Record of Processing Activities (RoPA)Property managerTemplate available
Privacy clause for ownersProperty managerModel available
Encryption at rest and in transitSaaS providerAES-256 + TLS 1.3
EU-only data storageSaaS providerEU servers only
Isolation between communitiesSaaS providerFull multi-tenant
AI not trained on client dataSaaS providerGuaranteed

How IgeraFincas resolves it

Resident question:

"I have the right to see the car park camera footage from 12 November — can I request it?"

IgeraFincas answers:

"Under Art. 22 LOPDGDD, CCTV footage is retained for a maximum of 30 days. If fewer than 30 days have passed since 12 November, you can exercise your right of access by submitting a written request to the community's property manager (the data controller). If more than 30 days have passed, the footage must have been deleted."

⏱ 3 seconds🕐 24/7📄 Source cited

IgeraFincas — GDPR compliant by design

DPA included, EU-only servers, full multi-tenant isolation, AES-256 encryption. 14-day free trial.

Try free for 14 days

Summary: GDPR for Spanish property managers

  • The property manager acts as data processor; the data controller is the owners' community.
  • Key obligations: DPA with each community, RoPA, privacy clause, legal basis per processing activity, breach notification within 72h, DPA with SaaS providers.
  • CCTV: mandatory notice sign + maximum 30-day retention + prior assembly approval.
  • Main risks: fines for publishing debtor lists, CCTV without signs, and data sharing without a DPA.

Frequently asked questions

Can I post a list of owners in arrears on the community notice board?

No. The AEPD has repeatedly fined communities that post debtor lists in communal spaces. Debt information is personal data of an economic nature. You may include it in assembly documentation (minutes) for attending owners, but not expose it publicly.

Does the community need a Data Protection Officer (DPO)?

Generally no. GDPR requires a DPO for organisations that carry out large-scale processing or process special category data. A standard owners' community does not reach that threshold. However, a property management firm managing many communities may need a DPO if it exceeds the thresholds across its combined processing activities.

How long must I keep community accounts and minutes?

Community accounts and minutes must be kept for at least 5 years to meet fiscal and accounting obligations (Spanish General Tax Law). GDPR requires that personal data not be retained longer than necessary for the purpose they were collected. For community management, the standard criterion is 5-10 years.

Does IgeraFincas have access to owners' bank details?

No. IgeraFincas does not process or store IBANs or bank data. The platform indexes documents (bylaws, minutes, regulations) and answers residents' text queries. Financial data is handled exclusively in the firm's accounting software (Adminplus, A3, etc.).

How does IgeraFincas demonstrate GDPR compliance?

IgeraFincas provides: (1) a signed DPA included in all plans, (2) data hosted exclusively on EU servers, (3) full multi-tenant isolation between communities, (4) AES-256 encryption at rest and TLS 1.3 in transit, (5) the AI model is never trained on individual community residents' data.

What must I do if I suffer a data breach involving owners' data?

You must notify the AEPD within 72 hours of becoming aware of the breach if there is a risk for owners' rights (Art. 33 GDPR). If the risk is high, you must also notify the affected owners directly (Art. 34 GDPR). Document the incident in your breach register even if it does not meet the notification threshold.

Article produced by the Igera Solutions editorial team. Based on Regulation (EU) 2016/679 (GDPR) and Organic Law 3/2018 (LOPDGDD), updated June 2026. Does not constitute legal advice.

#RGPD administradores fincas#proteccion datos comunidad propietarios#GDPR administrador fincas#lopd fincas#rgpd datos propietarios comunidad#brecha seguridad administrador fincas

COMPARTIR

Comparte el conocimiento con tu red