Data Protection and Governance in Condominium Assemblies

Data Protection and Governance in Condominium Assemblies

Data Protection and Governance in Condominium Assemblies

Dicas para Síndicos e PMES

Calendar icon04/03/2026
Clock icon5 min

The entry into force of the General Data Protection Law (LGPD), consolidated by Law No. 13,709/2018, established an indispensable regulatory framework for the processing of personal information across Brazilian territory, directly affecting the administration of residential and commercial condominiums. Although condominiums are legally classified as unincorporated entities, their day-to-day operations involve the collection, storage, and processing of a substantial volume of data belonging to residents, employees, visitors, and service providers. Within the condominium ecosystem, the condominium assembly stands out as the moment of greatest informational density, where deliberations on the agenda require the disclosure of financial and behavioural data and, at times, sensitive data, which are subsequently preserved in the minutes for record-keeping and internal publicity purposes.

Compliance with the legislation is not merely a formal requirement but a strategic necessity to mitigate legal and administrative risks, given that the National Data Protection Authority (ANPD) already identifies the condominium sector as one of the most prone to reported irregularities. The building manager, in their capacity as legal representative and risk manager, must understand that the condominium assembly extends far beyond a simple gathering of residents, constituting complex data processing operations that require a well-structured agenda and minutes drafted under the principle of data minimisation.

Fundamentals of the General Data Protection Law in the Context of Condominium Management

The genesis of the LGPD in Brazil was strongly influenced by the European Union's General Data Protection Regulation (GDPR), seeking to guarantee privacy and the free development of the personality of the natural person. For the building manager and management companies, a basic understanding of the law begins with identifying the data processing agents: the condominium acts as controller, defining the purposes and legal bases for the use of data, while outsourced companies and management firms operate as processors, carrying out the processing in accordance with the controller's guidelines. The relationship between these entities must be guided by transparency, ensuring that the data subject knows exactly why their information is being collected before any assembly takes place.

The application of the law to condominiums is comprehensive, regardless of the size or the residential or commercial purpose of the development. However, ANPD Resolution CD/ANPD No. 2/2022 introduced important flexibilities for small-scale agents, a category into which most condominiums fall as unincorporated private entities. This resolution allows for a simplified record of processing operations and removes the obligation to appoint a full-time Data Protection Officer (DPO), although maintaining a communication channel with data subjects remains mandatory.

Data processing at a condominium assembly must always be anchored in one of the ten legal bases set out in Article 7 of the LGPD. For most routine activities, such as convening the assembly based on the agenda and recording decisions in the minutes, the most common legal bases are compliance with a legal or regulatory obligation (such as those required by the Civil Code), contract performance, and the controller's legitimate interest. Consent, although frequently cited, should be reserved for situations where no other legal justification exists, such as recording images and voices during the assembly for purposes beyond the mere drafting of the minutes.

Structuring a privacy programme requires the building manager to carry out a data flow mapping exercise, identifying every point at which an assembly agenda might expose unnecessary data. This inventory process makes it possible to understand the information lifecycle, from registration at the front desk to the secure disposal of physical and digital documents. Risk analysis, fundamental to governance, can be expressed through the need for protection proportional to the volume of sensitive data processed, such as biometrics and employees' health information.

The Building Manager's Role as Controller and Civil Liability in the Handling of Information

The building manager occupies a central position in applying the LGPD, acting as the condominium's risk manager. Although they need not be an information technology specialist, the building manager must ensure that internal processes, from drafting the agenda to signing the minutes, comply with good data protection practices. The building manager's responsibility is broad, encompassing the guidance of employees and oversight of service providers, such as the management company, which handles the data required to hold the condominium assembly.

Legally, the condominium bears strict liability for damages arising from the inadequate processing of personal data, and the building manager may be held liable in a subsequent claim for indemnity should it be proven that they acted with intent or negligence in implementing security measures. This liability extends to the careful selection of processors. If a remote concierge company leaks biometric data collected for building security, the condominium, as controller, is the first to be held accountable by the data subject. It is therefore vital that the building manager review contracts to include clauses on liability and confidentiality specific to data protection.

The duty of accountability, inherent to the building manager under Article 1,348 of the Civil Code, takes on new dimensions under the LGPD. When presenting the financial position at an assembly, the building manager must balance residents' right to know about arrears with the debtors' right to privacy. The humiliating exposure of a resident at a condominium assembly, whether through aggressive comments included in the agenda or unnecessary disclosures recorded in the minutes, can result in awards for moral damages.

On the administrative front, ANPD enforcement already shows that condominiums are on the regulatory radar. The agency's 2023 report placed the sector in 4th place in the ranking of reported irregularities, even surpassing banking institutions in the volume of incidents during certain periods. This often occurs due to the lack of formal processes for responding to data subject requests, such as when a resident demands to know what data the management company holds about them ahead of a condominium assembly. The building manager must therefore establish a response process that guarantees replies within 15 days, under penalty of a complaint being lodged with the national authority.

Managing Sensitive Data and Protecting Biometrics and Images in Everyday Building Life

102333

The LGPD classifies as sensitive any information with a high potential to give rise to discrimination, including racial origin, religious beliefs, political opinions, health data and, crucially for condominiums, biometric and genetic data. The processing of sensitive data demands a higher degree of technical rigour, generally grounded in consent or in ensuring fraud prevention and the data subject's safety..

Biometric data, being immutable, poses a critical risk. If a condominium's fingerprint database is compromised, the harm to data subjects is permanent. For this reason, the building manager should require technology providers to use encryption or "hashing" techniques, whereby the fingerprint image itself is not stored, but rather a mathematical code derived from it. These technical specifications should be discussed whenever the topic appears on an assembly agenda, so that residents can vote with full awareness of the risks involved.

Images captured by CCTV systems are also considered personal data and, in certain contexts, may reveal sensitive data (such as attendance at religious services or visible health conditions). The building manager must ensure that access to such images is restricted and that the retention period is kept to the minimum necessary, generally between 30 and 60 days, except in cases of criminal investigation. Providing footage to residents who wish to "spy" on neighbours, or for sharing in messaging groups, is strictly prohibited and constitutes a serious infringement.

With regard to employees, the processing of health data must be handled with absolute confidentiality. Information about medical leave or occupational examination results must not be shared with the council or disclosed at a condominium assembly, unless strictly necessary for a specific administrative decision, and even then only in pseudonymised form in the minutes. The disposal of such data must also follow strict protocols, preventing health records from being discarded in general waste, which could lead to leaks and ANPD sanctions.

Structuring the Agenda from the Perspective of Privacy and Data Minimisation

The agenda of an assembly is the document that defines the scope of discussions and guarantees residents' right to information. Under the LGPD, the drafting of the agenda must follow the principle of data minimisation, avoiding the disclosure of personal data that is not essential to understanding the matter to be decided.

A well-structured agenda prevents what legal scholars call "purpose diversion". If the agenda lists "general matters" but the building manager uses that space to expose the moral conduct of a specific resident, this constitutes a breach of the duty of transparency and of proper data handling. Clarity in the agenda allows the data subject to exercise their right of defence or to prepare for the disclosure of their information in a controlled setting, as is the case at a condominium assembly.

Distribution of the agenda must take place through means that ensure interested parties are informed without exposing the data to third parties unconnected to the condominium relationship. The use of restricted management apps or individual emails is preferable to posting detailed notices in lifts, where visitors might read sensitive information about financial management or internal conflicts. When the agenda involves high-risk matters, such as amending internal regulations affecting the collection of biometric data, the building manager should make supporting materials available (such as the Data Protection Impact Assessment (DPIA)) for prior consultation, but always under access control.

Recording and Consent Dynamics in the Condominium Assembly Setting

146906

Recording a condominium assembly has become a common practice to ensure the accuracy of the minutes and allow absent residents to follow the deliberations. However, voices and images are personal data protected under the LGPD, and their capture requires ethical and legal care. There is no legal prohibition on recording, but the practice should be preceded by a clear notice in the agenda and in the notice of meeting, explaining the purpose (generally to support the drafting of the minutes) and the retention period for the file.

Consent for the recording should preferably be obtained at the start of the condominium assembly. The chair of the meeting should announce that the meeting will be recorded and ask that any objection be raised immediately. It is essential to record in the minutes that the notice was given and that participants consented, freely and with full knowledge, to the processing of their image and voice for that specific purpose. In virtual assemblies, access logs and express agreement via chat or the voting tool serve as proof of unhindered consent.

The use of recordings must be strictly limited to the stated purpose. The building manager or management company is prohibited from sharing excerpts of the condominium assembly on social media or WhatsApp groups for the purpose of ridiculing or exposing residents. Once the minutes have been drawn up, recorded, and approved, the purpose of the recording ceases, and the file should be deleted or stored in an ultra-secure manner, with access restricted solely for purposes of legal evidence. Storage for years without a plausible justification constitutes a breach of the storage limitation principle.

In cases where the assembly discusses sensitive matters, such as allegations of harassment or mistreatment of minors, it is recommended that the recording be paused or that the audio be pseudonymised, ensuring that details that could identify victims are not recorded in digital media that is easily shared. The building manager should instruct the secretary to ensure that the minutes reflect the legal conclusion of the debate without exposing the raw, emotional content that the recording may have captured.

Drafting the Minutes: Balancing Transparency with the Confidentiality of Personal Data

The minutes of the condominium assembly are the official document proving that the events occurred and the decisions taken. Their drafting should be an exercise in objective synthesis, steering clear of a literal transcript of heated debates or offensive remarks that contribute nothing to the validity of the resolutions. From an LGPD perspective, the minutes should contain the minimum amount of personal data necessary. Stating that "the resident of Unit 202 spoke against the agenda item" is legally sufficient and far more protective than listing the resident's full name, national ID number (CPF), and marital status in the body of the text.

Pseudonymisation is one of the most effective tools available to whoever drafts the minutes. By using codes or unit numbers instead of names, the condominium guarantees the transparency of its accountability — allowing any resident to verify who voted for what — without exposing data subjects' identities to third parties unconnected to the building who might have access to the minute book. If the minutes are registered with a public registry office, they become public, which reinforces the need to avoid including sensitive data or detailed financial information about specific individuals.

Beyond content, the way the minutes are distributed must also be controlled. Copies sent to all residents should be delivered through channels that ensure confidentiality, such as sealed envelopes or password-protected access on electronic portals. Posting the full minutes on the building notice board or in the lift, where any service provider or visitor could photograph the document, is considered a high risk of data leakage. The building manager must ensure that the version of the minutes distributed respects privacy, keeping the full version available only for consultation in the condominium's physical archive by those who demonstrate a legitimate interest.

In the case of virtual assemblies, voting logs and reports from digital platforms should be attached to the minutes but treated as restricted-access documents. The secretary must take care not to include, in the publicly distributed attachments to the minutes, information such as voters' IP addresses or private email addresses — data that is not necessary to validate the quorum before the condominium as a whole, but which is valuable to cybercriminals.

Implementing Confidentiality Agreements for Staff and Third Parties

148

Data protection at a condominium assembly does not end when the minutes are closed; it depends on the discretion of everyone involved in the process. For this reason, applying confidentiality agreements is an essential preventive measure that the building manager should adopt to safeguard the management. These agreements should be signed by all in-house staff, such as caretakers and doorkeepers, and by members of the meeting's board (chair and secretary) who have access to sensitive information during the meeting.

An effective confidentiality agreement should clearly define what constitutes confidential information: attendance lists, financial data from the agenda, discussions held during the condominium assembly, and the preliminary content of the minutes. The document should establish that the information may only be used in the performance of professional duties and that any leak, whether through gossip or digital sharing, will subject the offender to disciplinary sanctions and civil liability. For the building manager, having these agreements signed demonstrates compliance with the LGPD's principle of accountability.

In dealings with third parties, the building manager should require processing companies, such as the management company and the security firm, to present their own data protection protocols. Service contracts must contain clauses obliging the company to train its employees and to notify the condominium immediately in the event of any security incident that could compromise data from the assembly or the minutes. Failure to include such contractual safeguards can shift sole blame onto the condominium in the event of legal proceedings.

Below is a suggested structure for managing confidentiality documents:

  1. Functional Confidentiality Agreement: Applied to doorkeepers and caretakers, focused on not disclosing residents' movement data captured by cameras or entry logs.

  2. Privacy Clause in Contracts: Applied to management companies, setting limits on sharing the agenda and minutes with third parties without the building manager's authorisation.

  3. Board Confidentiality Commitment: A simple document signed at the start of the condominium assembly by the chair and secretary, ensuring that meeting notes will not be improperly disclosed.

  4. Internal Privacy Policy: A general condominium document, approved at an assembly, setting out the rules for how each type of data will be handled by all representatives.

Legal Risks and the Disclosure of Defaulters in Internal Communication Channels

Managing arrears is one of the greatest challenges for the building manager and frequently tops the agenda of any condominium assembly. The tension between the duty of financial transparency and the debtor's right to privacy is ever-present. Brazilian case law and the LGPD establish that the condominium has the right to inform other residents about who is not contributing to the shared costs, since non-payment affects the collective assets. However, the manner in which this information is conveyed in the agenda and recorded in the minutes is what determines the lawfulness of the act.

Humiliating exposure occurs when the building manager uses disproportionate means to coerce the debtor, such as posting lists with names and amounts owed in highly visible locations (lifts, entrances, external notice boards). Such practices give rise to proven moral damages, exposing the condominium to compensation claims that can exceed the value of the debt itself.

During the assembly, barring the defaulter's vote (Article 1,335, III of the Civil Code) should be handled discreetly by the chair of the meeting. There is no need to announce out loud the reason for refusing the vote; it is enough to state that the unit does not meet the eligibility requirements for that particular agenda item, in accordance with the management company's records. The entry in the minutes should likewise be discreet, noting only that "units in arrears did not vote", without any need to name residents in an irregular situation in the document that will be distributed.

ANPD Sanctions and the Evolution of Case Law in Data Protection Disputes

The sanctions provided for under the LGPD came into force in August 2021 and range from simple warnings to severe financial penalties. In addition to fines, the ANPD can order the suspension of data processing, which in practice would paralyse the management of a condominium, preventing it from holding an assembly or processing employee payments. The ANPD's first sanction, applied in 2023, although against a small business, served as a warning to all small-scale agents about the obligation to have a Data Protection Officer or communication channel and to demonstrate the purpose of processing.

Case law in state courts has been quick to apply LGPD principles to condominium disputes. Cases involving the leaking of security camera footage to social media or resident groups have resulted in significant awards for invasion of privacy and moral damages. Similarly, residents whose sensitive data was disclosed in a set of minutes without legal justification have succeeded in claims for rectification and compensation.

The courts have shown that the "risk theory" applies fully to condominiums. If the building manager neglects the management company's cybersecurity and the data from a condominium assembly's agenda is captured by hackers, the condominium is liable to residents for the failure in its duty of custody. On the other hand, courts also protect condominiums when they deny third parties access to data on the basis of the LGPD, such as when a resident demands to see footage of everyone who entered the building in order to investigate a personal matter without a court order.

Practical Governance Guidelines for Ongoing Condominium Compliance

Ongoing compliance with the LGPD requires the building manager to establish a governance routine that goes beyond a single assembly. The first step is a "Preliminary Diagnosis", identifying which areas of the condominium handle the most data (front desk, finance, human resources). Next, creating a clear "Privacy Policy", approved at a condominium assembly, will serve as the building's informational constitution, dictating how each agenda item is drafted and how each set of minutes is stored.

Staff training is one of the most neglected pillars. Doorkeepers must know that they cannot give out a resident's phone number to another person, even under insistence, and that camera footage only leaves the condominium with the building manager's authorisation or a court order. This training drastically reduces the likelihood of incidents that would otherwise generate conflict at the condominium assembly and negative entries in the minutes.

Successful LGPD compliance depends on the building manager's proactivity in bringing the topic up for discussion. By professionalising the agenda and the minutes, the condominium not only protects itself from fines but also builds a relationship of trust and transparency with its residents, raising the standard of communal living and the development's value in the property market. Data protection is, ultimately, the protection of the people who live in and build the condominium community.

Share this article:

You may also like

banner

Stop paying more for your energy bill

Find out in less than 1 minute how much you could save with clean energy every month — no works and no bureaucracy.

Join the energy revolution

Subscribe to our newsletter and receive exclusive content

Data Protection and Governance in Condominium Assemblies