GDPR Compliance for Property Managers: What You Need to Know About Resident Data
If you manage residential buildings in the EU, you handle personal data. Names, phone numbers, email addresses, payment history, meter readings, maintenance requests — all of it is personal data under GDPR. And if you're still managing buildings on spreadsheets and shared drives, you're probably not compliant.
GDPR isn't a one-time checklist. It's an ongoing obligation. But the good news is that once you understand the requirements and use the right tools, compliance becomes a natural part of your workflow rather than a monthly panic.
What personal data do property managers process?
More than you think. Here's what counts as personal data in a property management context:
- Identity data — name, personal ID number, date of birth
- Contact data — email, phone number, mailing address
- Financial data — bank account numbers, payment history, invoice records, debt status
- Consumption data — utility meter readings, electricity usage, water consumption
- Behavioral data — maintenance request history, portal login activity, communication preferences
- Special categories — if you collect health information for accessibility accommodations or biometric data for building access, this triggers additional protections under Article 9
If you're processing any of this without a clear legal basis and retention policy, you have a compliance gap.
The six lawful bases for processing
Under GDPR Article 6, you need a lawful basis for every type of personal data you process. For property managers, the relevant bases are:
- Contract (6(b)) — processing is necessary to fulfill the lease or service agreement. This covers invoicing, payment processing, and utility billing.
- Legal obligation (6(c)) — you're required by law to keep certain records (tax records, safety inspections). This covers mandatory retention periods.
- Legitimate interest (6(f)) — processing is necessary for your legitimate business operations, such as sending payment reminders or maintenance notifications. This must be balanced against the resident's privacy rights.
- Consent (6(a)) — the resident has explicitly agreed to specific processing, such as receiving marketing emails or using biometric building access. Consent must be freely given, specific, and withdrawable.
The key is documentation. You should be able to point to the legal basis for every type of data you process. If you can't, that's a gap.
The retention problem most managers ignore
This is the one that catches people off guard. GDPR requires that personal data not be kept longer than necessary. But most property managers either keep everything forever or delete things randomly without a policy.
Here's a practical retention schedule for property management:
- Active resident data — keep for the duration of the lease plus one year for dispute resolution
- Invoice and payment records — keep for 5 years (tax law requirement in most EU countries, including Latvia)
- Meter reading data — keep for 3 years for billing dispute resolution
- Maintenance request records — keep for 2 years after resolution
- Communication logs — keep for 1 year
- Access logs — keep for 1 year (required for audit trail)
After the retention period expires, data should be deleted or anonymized. A good property management platform does this automatically based on configurable retention rules. If you're on spreadsheets, you need a manual deletion calendar — and you probably don't have one.
The Article 30 record of processing activities
If your organization has more than 250 employees, or if your processing is not occasional, or if you process special categories of data, you must maintain a Record of Processing Activities (ROPA) under Article 30. This document describes:
- What data you process <
- Why you process it (purpose)
- What legal basis you rely on
- Who you share it with (recipients)
- How long you keep it (retention)
- Where it's stored (transfer mechanisms, if applicable)
Even if you're below the 250-employee threshold, maintaining a ROPA is best practice. If a data subject requests access to their data (Article 15), or if the supervisory authority audits you, having a ROPA makes the process straightforward instead of a scramble.
Access controls: who can see what, and when
GDPR Article 32 requires appropriate technical and organizational measures to protect personal data. For property managers, this means:
- Role-based access — not everyone needs to see everything. A maintenance worker doesn't need access to payment history. A billing clerk doesn't need to see maintenance request photos. Define roles and restrict access accordingly.
- Audit logging — every time someone views or edits personal data, the system should log who, what, and when. This is your evidence that you're protecting data properly.
- Encryption — data should be encrypted in transit (HTTPS) and at rest (database encryption). If you're storing resident data in a shared Google Drive with no access controls, you're not meeting this requirement.
- Secure deletion — when the retention period expires, data should be permanently deleted, not just moved to a trash folder.
Resident rights you need to handle
GDPR gives residents (data subjects) specific rights. As a property manager, you need a process for each:
- Right of access (Article 15) — a resident can request a copy of all personal data you hold about them. You have one month to respond. A good platform can export this data in one click.
- Right to rectification (Article 16) — a resident can request correction of inaccurate data. You must respond within one month.
- Right to erasure (Article 17) — also known as the right to be forgotten. A resident can request deletion of their data, unless you have a legal obligation to keep it (e.g., tax records). You must respond within one month.
- Right to data portability (Article 20) — a resident can request their data in a structured, machine-readable format (JSON, CSV). This is where having an open API helps — you can export the data directly.
- Right to object (Article 21) — a resident can object to processing based on legitimate interest. You must stop unless you have compelling legitimate grounds.
If you receive one of these requests and you're on spreadsheets, responding within one month means manually searching every file, email, and record. With a proper platform, it's a few clicks.
Data breaches: what to do when something goes wrong
If personal data is accidentally deleted, exposed, or stolen, you have 72 hours to notify the supervisory authority (in Latvia, the Data State Inspectorate — DVI). You must also notify affected residents if the breach is likely to result in high risk to their rights and freedoms.
This is where audit logging saves you. If you can show exactly what data was accessed, by whom, and when, the notification is precise and the damage is contained. Without logs, you're reporting a vague breach and hoping for the best.
Practical steps to get compliant
- Audit your data. Make a list of what personal data you collect, where it's stored, and who has access. This is the foundation of your ROPA.
- Define retention periods. Create a schedule for each data type. Set calendar reminders if you're manual, or configure automatic deletion if your platform supports it.
- Implement access controls. Restrict who can view sensitive data. If your current system doesn't support roles, it's time to switch.
- Enable audit logging. If your platform doesn't log access to personal data, you can't demonstrate compliance. This is a dealbreaker.
- Set up data export. Test your ability to produce an Article 15 response. If it takes more than an hour, you need better tooling.
- Create a breach response plan. Know who to notify, how, and within what timeframe. Practice it once a year.
- Review annually. GDPR compliance is not a one-time project. Review your ROPA, retention schedule, and access controls every year.
How a property management platform helps
The right platform handles most of GDPR compliance automatically:
- Role-based access control — define who sees what, enforced by the system
- Audit logging — every action on personal data is logged automatically
- Configurable retention — set retention periods per data type; the platform deletes automatically
- Data export — one-click export for Article 15 requests
- Secure deletion — permanent deletion that can't be recovered
- Encryption — data encrypted in transit and at rest
- ROPA maintenance — the platform's processing records feed directly into your Article 30 documentation
If your current tool is a spreadsheet, you're doing all of this manually. And if you're doing it manually, you're probably cutting corners. GDPR enforcement is increasing across the EU. The cost of non-compliance — fines up to EUR 20 million or 4% of annual turnover — is far higher than the cost of a compliant platform.
The bottom line
GDPR compliance for property managers is not about hiring a lawyer or filling out forms. It's about having systems that respect data subjects' rights by default. If your tools make compliance automatic, you can focus on managing buildings instead of managing legal risk.
If you're not sure whether your current setup is compliant, start with the audit in step 1 above. If you can't answer basic questions about who accesses resident data and how long you keep it, you have work to do. The good news is that the right platform makes this work straightforward — and permanent.