The Incident (The Homeowners' Association Silence): A property owner submitted a formal data access request to their Homeowners' Association (Comunidad de Propietarios) on 10 September 2025, exercising their right under Article 15 GDPR to obtain personal data held by the community. In Spain, homeowners' associations are legal entities that manage communal properties, collect maintenance fees, and maintain records about residents including payment histories, correspondence, voting records at community meetings, and complaints or disputes. Despite the clear legal obligation to respond within 30 days under Article 12.3 GDPR, the Homeowners' Association completely ignored the resident's request.
The Complaint: After receiving no acknowledgment or response whatsoever from the community's administrator or governing board, the frustrated homeowner filed a formal complaint with the AEPD. The complainant provided documentation proving they had properly submitted the access request through appropriate channels and had received absolutely no communication from the Homeowners' Association within the mandatory one-month response period.
The AEPD Investigation: Following standard procedure under Article 65.4 LOPDGDD, the AEPD transferred the complaint to the Homeowners' Association, giving them an opportunity to explain the non-response and provide the requested information. When the association's initial response failed to satisfy the complainant's legitimate rights, the AEPD formally admitted the case for full investigation on 10 December 2025, opening an official rights procedure against the community.
The Belated Compliance: Only after the AEPD initiated formal proceedings did the Homeowners' Association finally respond to the resident's access request. The association belatedly provided the requested personal data—but this response came months after the original 30-day legal deadline had expired. The pattern is clear: the community ignored the resident's direct request entirely and only complied when facing regulatory enforcement action.
The Core Ruling (Formal Estimation Without Further Action): The AEPD ruled in favour of the complainant, formally confirming that the Homeowners' Association violated Article 15 GDPR and Article 12.3 GDPR by failing to respond within the mandatory timeframe. However, because the association had eventually provided the requested data during the AEPD investigation (though significantly late), the regulator determined that no additional remedial action was required. This is a "formal estimation"—the AEPD officially recognises the violation occurred and validates the resident's complaint, creating a permanent regulatory record against the Homeowners' Association, but does not order the community to issue a new response since the substantive right has now been satisfied (albeit tardily and only under regulatory pressure).
Based on Resolution EXP202517310, here is the compliance protocol for homeowners' associations, community organisations, and small-scale data controllers:
Many community boards mistakenly believe GDPR only applies to large companies or government agencies. This is false.
Legal Reality: If your Homeowners' Association collects and stores residents' names, addresses, phone numbers, email addresses, payment records, or any other personal information, you are a data controller under GDPR with the same legal obligations as any business or public authority.
Action: Homeowners' associations must designate a person responsible for GDPR compliance (this could be the community president, administrator, or secretary). This person must understand basic data protection obligations including responding to access requests within 30 days.
Residents may request access to any of the following data categories:
Financial Records:
Administrative Records:
Property Information:
Action: When a resident requests access, compile all of these records into a single organised response document.
Many homeowners' associations are managed by unpaid volunteer residents or small property management companies with limited staff. This does not exempt them from GDPR deadlines.
No Excuses for:
Action: If your community is entirely volunteer-run, establish a simple email monitoring system where at least one board member checks the community's email address weekly and forwards any GDPR requests to the designated compliance person immediately.
You don't need expensive legal counsel or compliance software. A simple, organised response is sufficient.
Step-by-Step Protocol:
Some residents may submit very broad requests like "send me all information you have about me."
Proportionate Response: You are not required to spend weeks manually searching through decades of paper archives. Article 12.5 GDPR allows you to request clarification if a request is "manifestly unfounded or excessive."
Action: If a request seems overly broad, respond within 7 days asking: "To help us locate the specific information you need, could you please clarify whether you are primarily interested in: (a) financial records, (b) meeting minutes, (c) correspondence, or (d) all of the above? Additionally, what time period should we cover?"
GDPR's data minimisation principle (Article 5.1(e)) requires that personal data should not be kept longer than necessary.
Recommended Retention Periods:
Action: Implement an annual data review process where old records are securely deleted, reducing the volume of data you need to search when responding to access requests.
Many communities hire professional property management companies to handle administration. However, the Homeowners' Association remains the data controller.
Joint Responsibility: If you use a property manager, the management company is a "data processor" acting on your behalf. You must have a written contract (Article 28 GDPR) specifying:
Action: Review your property management contract to ensure GDPR obligations are clearly defined. If the manager receives an access request, they must forward it to the community board immediately.
Homeowners' associations often violate GDPR due to misunderstandings rather than malice. Avoid these common errors:
Mistake 1: "We don't have to respond because the resident owes community fees"
Mistake 2: "The request is vague, so we'll ignore it"
Mistake 3: "We'll discuss this at the next community meeting in 3 months"
Mistake 4: "Only the administrator has access to the files, and they're unavailable"
Many access requests stem from residents' distrust or suspicion about how their data is being used.
Proactive Measures:
Result: Residents who feel informed and respected are less likely to file GDPR complaints.
If your Homeowners' Association receives a formal communication from the AEPD about a resident's complaint:
Immediate Actions (Within 48 Hours):
Medium-Term Actions (Within 30 Days):
This case confirms that homeowners' associations, despite often being small, volunteer-run organisations, are subject to exactly the same GDPR obligations as commercial businesses and public authorities. Ignoring residents' access requests triggers formal AEPD investigations, creates permanent regulatory records against the community, and can result in enforcement orders or sanctions. The AEPD's ruling sends a clear message: community organisations must designate responsible individuals, implement basic compliance procedures, and respond to residents' data rights requests within 30 days—there are no exemptions for small-scale or volunteer-managed entities.
Informational Purposes Only: The content provided by ANRO DIGITAL SOLUTIONS S.L.U. (including resolution summaries, infographics, and case analyses) is for educational and informational purposes only.
No Legal Advice: This information does not constitute legal advice, a formal legal opinion, or a substitute for professional legal counsel. The interpretation of data protection laws (including the GDPR, LOPDGDD, and AEPD resolutions) is subject to change and can vary based on specific facts and circumstances.
No Liability: ANRO DIGITAL SOLUTIONS S.L.U. assumes no responsibility or liability for any actions taken, or not taken, based on the information provided on this website. While we strive for accuracy, we make no guarantees regarding the completeness or timeliness of the information.
Consult a Professional: Data protection compliance is a complex legal requirement. You should not act upon this information without seeking advice from a qualified Data Protection Officer (DPO) or a specialist data protection lawyer licensed to practice in your jurisdiction.
Third-Party Links: Links to official AEPD documents are provided for convenience. We are not responsible for the content or availability of these external government portals.
Este resumen tiene carácter meramente informativo. Para más información, consulte nuestro Aviso Legal.