Back to blog

Sunday 27 September · Part of Building associations & residents

Is sharing a parking spot GDPR-compliant?

The moment residents share something that records names, times or contact details, someone is processing personal data. And GDPR applies, whether that happens through a chat group or an app built specifically for it. For a board that's never had to think about this before, the obvious question is: who's actually responsible, and what should they watch for?

The answer sits in two roles the GDPR distinguishes, which determine exactly who's liable for what.

Controller and processor: who is who

In cases like this, the building association is usually the data controller: it decides that shared parking will happen and for what purpose data gets recorded. A software provider delivering the app is then the processor: processing data on the association's behalf, according to its instructions. That's the same relationship that's existed for years between an association and its property manager, who also processes owners' personal data on the association's behalf.

Article 28 of the GDPR requires a data processing agreement between those two parties the moment a supplier has access to personal data, not only once that data is actually used. A board choosing a supplier may, and should, ask: is there a processing agreement, and what does it say about retention, access and what happens in a data breach?

What that means in practice for the choice

The less data a system records, the smaller the risk. And that's exactly where a chat group and a purpose-built app diverge. A WhatsApp group shares phone numbers and names with everyone in it by default, with no distinction and no expiry. A system that only records what's needed to make a booking work (who, which spot, what time) and that handles login through a one-time email link instead of a password database, simply has less that can go wrong.

That's called data minimisation, one of the GDPR's core principles: don't record more than the purpose requires. It's not a legal cure-all (a processing agreement is still needed, and a board remains ultimately responsible) but it's the difference between a supplier where GDPR compliance is a paperwork exercise, and one where it's already built into the design.

For a board considering a building-wide approach, the question isn't just "does this work in practice" but also "what would we need to record to offer this." Both questions have the same answer: choose something that records as little as possible, and handle the rest (the processing agreement, the retention terms) the same way you would with any other supplier.

Curious what this could mean for your VvE or complex?

Get in touch