Knowledge — security and privacy

Housing community data security: ten questions to ask a software vendor

A housing community system brings together owner data, financial records, documents, payment information, resolutions and technical cases. Security therefore needs to be more specific than “the data is in the cloud”.

1. In which country or region is persistent data stored?

Ask for a concrete location and whether the answer differs for backups, documents or supporting services.

2. How are separate communities isolated?

A management firm needs one tool for multiple customers, but each housing community should remain a distinct data and permission context.

3. How do roles and least privilege work?

Accounting staff, board members, administrators and technical-case handlers do not necessarily need identical access. The vendor should demonstrate how access is limited to real need.

4. Is MFA available and when is fresh confirmation required?

A password alone is a weak boundary for highly privileged accounts. Ask about MFA and additional confirmation for higher-risk operations.

5. How is vendor administrative access controlled?

Do not assume the answer. Ask who on the vendor side can gain operational access, in which situations, how that access is approved and how it is recorded.

6. What actions are written to the audit trail?

The audit trail should help reconstruct an important change: who, when, in which context and what changed. It does not need to duplicate sensitive data into logs.

7. How do backup and restore work?

Ask about backup scope, frequency, retention and how restore capability is tested. “We make backups” has limited value without restore verification.

8. Can the community export a complete data set?

Export is a business-security control. It preserves independence from a vendor and supports controlled handover when the administrator changes.

9. Who are the subprocessors and where is the current list?

The list should be public or easy to obtain and remain consistent with the privacy policy and processing agreement.

10. How is a vulnerability or incident reported?

The vendor should provide a clear contact route and response process. Customers need to know who communicates an issue and how they receive information needed for their own obligations.

What WM Administrator currently communicates publicly

WM Administrator states EU jurisdiction for persistent data, separate housing community contexts, individual roles and MFA for privileged roles, a history of significant operations, complete export and controlled offboarding. Processing details and the current subprocessor list are available in the public legal package.

Do not reduce this to “GDPR compliant by default”. Compliance also depends on the organisation’s own purposes, legal bases, permissions, procedures and use of the system.

See the security page

Sources and scope

For information only. This is not legal, tax or accounting advice; adapt the procedure to the documents and circumstances of the specific housing community.

Related articles