Is your housing company violating the GDPR?
Can shareholders communicate with each other using both email and social media platforms such as Facebook or the board's WhatsApp group?
Official housing company matters should be handled through a separate communication channel. Personal data should never be shared via social media applications or groups.
Official board decisions must be made outside social media platforms. Anyone publishing information through social media should be aware that, under the platform's terms of service, certain rights to the published content are generally granted to the provider of that social media platform. This is based on the platform's terms and conditions.
Is email considered a secure way to transmit personal data?
Can a housing manager's certificate still be sent by email to the shareholder who requested it or to the shareholder's bank?
When transmitting personal data, great care must always be taken. In practice, organisations must assess the risks involved in the processing, including whether the technical solution used provides an adequate level of security. If unencrypted email is used to transfer personal data, the recipient must be informed in advance of the risks associated with this method. The Data Protection Ombudsman recommends that secure email should always be used when transmitting personal data.
What happens if a housing company does not adapt its operations to comply with the GDPR?
Failure to comply with the GDPR may, in the worst case, result in a housing company being required to pay significant administrative fines and compensation for damages. Both the data controller and the data processor must be able to demonstrate that they comply with the GDPR.
Source: Office of the Data Protection Ombudsman
www.luottoposti.fi

