It's 2026. Why are we still emailing meter readings?
Here's a scene that plays out in every Riga courtyard, at least once a year. The house elder, a retired engineer with a folder of printed Excel sheets, wants to photograph everyone's water meters. A younger tenant refuses. He's seen the data protection trainings at work and now suspects that his grandmother's neighbour collecting consumption data violates something. Both sides are wrong. And both are partially right.
GDPR doesn't actually forbid anyone from photographing water meters. The law's starting position is this: if you need data for a legitimate purpose and collect no more of it than the purpose requires, you are generally allowed. The house elder really does need the readings — without them, the association cannot bill for water at all. That's not surveillance, that's housekeeping.
But it's the word "housekeeping" where people's imagination tends to run wild. So let me walk you through where apartment associations genuinely make mistakes — and, importantly, where they panic for no reason. I'll be leaning on Latvia's rules (since that's where I've seen most of the paperwork), with the occasional glance at Estonia, which does a few things differently.
Who is the controller? (Spoiler: it's you)
This is the first question worth settling, because it decides who carries the obligations. The moment an apartment association starts collecting tenants' data — names, consumption figures, payment records, arrears lists — it becomes a data controller within the meaning of GDPR Article 4(7). Not the management company. Not the software vendor. The association itself.
I've sat in management company meetings where the manager insists "that's the IT firm's problem." No. The IT firm is a processor. The person who decides why data is collected and what happens to it — that's the association. Latvia's Law on Residential Property Management (Dzīvojamās mājas pārvaldīšanas likums) obliges the manager to keep consumption records; it doesn't move GDPR responsibility onto anyone's shoulders.
And yes, associations in Riga already got fined. In 2023–2024, the data state inspectorate (Datu valsts inspekcija, DVI) issued fines for publishing tenant names with arrears amounts in building common areas, for circulating full payment details to all residents, and for leaving tenants' personal data exposed in public areas. I've personally seen an arrears list taped up in a stairwell on Mēness iela, names and euro amounts visible from the street through the window. The inspectorate's news feed reads like a catalogue of exactly these mistakes.
The classic mistakes (from actual DVI decisions)
DVI publishes decisions, and there are a few that come up over and over.
1. Arrears lists on the notice board. A DVI decision in case G30-746 (2021) concerned exactly this: an association posted full names and debt amounts on the house notice board. The ruling: full names plus amounts is excessive disclosure. The data subject can be identified by anyone in the building. The inspectorate didn't say "never publish debtors" — it said the disclosure must be proportionate. Initials or apartment numbers can be fine; full names with euro amounts is where it tips over.
2. Payment details circulated to the whole house. There was also a decision about an association distributing all residents' payment and consumption data to everyone. The association argued legitimate interest. The inspectorate disagreed: distributing data not related to the recipient, in a form where individuals remain identifiable, isn't justified by interest alone.
3. CCTV without signs. Not the camera itself — the missing warning. If an association has installed a camera over the entrance "for safety," it needs signage, retention rules, and a documented basis. A camera silently recording a public sidewalk is a different kind of problem: that's public-space surveillance, and in Latvia it needs grounding in law, not just a board decision.
Where people panic for no reason
Now, the reassuring part. The data protection authority's decisions show that associations regularly get away with things that tenants fear.
Water meter photos. Consumption data collection for utility billing is a textbook case of legitimate interest. The authority's own practice confirms: an association can process meter readings without consent, because it's necessary for billing. You don't need to beg for consent from every resident.
Debt collection letters. Also fine. Sending a payment reminder to the apartment owner whose data you hold, based on the contract between them and the association — no separate GDPR consent required.
Management company data flows. If the association has outsourced billing to a management company, you don't need to file a GDPR Article 30-style processor agreement with a notary. A written processor agreement is enough, and the management company's obligations are further defined by the property management law. The practical takeaway: check that such an agreement exists. If there's nothing in writing, that's the real problem — not the absence of a notarised document.
A pattern emerges from all of this. Regulators don't object to the data processing itself. They object when a house's internal data travels beyond the group of people who need it. Data collected by the house for the house, processed by the house for the house — rarely a problem. The moment data leaves that circle, you need a reason.
The rules of the house: what a basic privacy policy should cover
GDPR Article 13 requires you to inform people about data processing. Practically, for an association this means one page: how to access it, what's collected, why, how long it's kept, who to contact. If your association already has a website, a single static page is enough to satisfy this.
What should be on that page:
- what categories of data the association processes (identity data, contact details, consumption data, payment history, correspondence);
- for what purposes (billing, debt collection, house maintenance, safety);
- the legal basis for each purpose (contract performance or legitimate interest);
- retention periods (more on these below);
- who to contact for questions or to exercise your data subject rights.
If your association has no website at all, put the notice on the house notice board and make sure the board minutes record that it was approved. A stairwell wall is not the most convenient place to fit retention periods, I'll admit. But the obligation exists, and one page is genuinely all it takes.
How long can you keep tenant data?
The storage limitation principle says: as long as the purpose exists, and no longer. Sounds vague. In practice, the tax records retention obligation is the practical anchor.
An association processes member data and issues invoices — that means accounting documents. Under Latvia's accounting rules, documents must be kept for 5 years (for some document types, longer). The association can therefore justify keeping consumption and payment records for 5 years. Beyond that, there's no purpose, and the storage limitation principle starts to pull in the other direction.
Estonia does this slightly differently. Accounting acts are kept for 7 years, so consumption and payment records sit in the archive longer — 7 years is the safe number there. One legal system, two retention periods, and a house in Valmiera whose sister building in Tartu keeps the same kind of paper for a different amount of time. Not ideal. But that's cross-border apartment life for you.
"I want to know what you have on me" — handling data subject requests
A tenant writes to the board: please give me a copy of all my data, my payment history, and a record of who you shared it with. This is a GDPR Article 15 request. It must be answered. Within a month, extendable by another two months if it's genuinely complex.
In practice, most associations' first response is panic. There is no need for panic. The tenant's data sits in two or three systems: the billing ledger, maybe an email thread, maybe a paper folder in the house elder's drawer. Compile it, review it, and send it on. The deadline runs from receipt, so the date the request arrives in the board's inbox matters — date-stamp it and note it in the minutes.
The trickier scenario is the reverse: the tenant demands you delete their data. A board member replies: we can't, we have a legal obligation to keep accounting records. And that is the correct answer. GDPR never gives anyone a right to erase records that the law requires you to keep. You can delete marketing data, photos from the summer party, the newsletter list. You cannot delete the invoice archive. Explaining the difference takes one paragraph in a reply letter. What you cannot do is ignore the request.
The board's 45 minutes: a checklist
Nobody expects board members to become lawyers. But an evening with coffee and this checklist covers the essentials. I've seen an association get through the entire list in under an hour — the main cost was finding a person who was willing to type the privacy notice.
1. Find your documents. You need three papers: the privacy notice, the processor agreements (with the management company, billing provider, accountant), and — this one surprises people — a written authorisation for anyone who handles data on the board's behalf. That last item matters more than people think: whoever handles data on the association's behalf should hold a written authorisation, so it's clear who is entitled to do what. It doesn't need to be fancy; half a page stating what the person may access and what they must do with it is plenty.
2. Do the walk-through. Physically look at the house. Cameras over entrances? Notices on doors? Arrears lists taped up? Email distribution lists with 40 recipients in one "to" field? The stairwell itself is part of your data audit. Take a notepad.
3. Set retention rules. Agree in minutes: consumption and payment records — 5 years (LV) or 7 years (EE); applications and correspondence — while the tenancy lasts plus a reasonable period; camera footage — 30 days is a common default.
4. Assign a contact. Not necessarily a DPO — most associations don't need a formal Data Protection Officer. But one named person whom tenants can write to. A name and email on the notice. That's it.
5. Answer requests in writing. When someone asks for their data, date-stamp the request, respond within the deadline, and keep the reply. Not because lawyers will come — but because a board member who leaves after two years should leave behind a traceable history instead of a mystery.
Most of this is just housekeeping with legal names attached. The law itself isn't unreasonable: collect only what you need, tell people what you're doing, don't show their data to the whole building. That's it. That's the whole philosophy.
And the house elder with the Excel folder?
He can keep it. Meter readings in a folder, billing once a month, arrears handled with individual letters rather than a notice-board list — that's a fully GDPR-compliant operation. Whether it's stored in Excel or in purpose-built software makes no difference to the law. What matters is that access is limited, the retention period is defined, and the neighbour can find out what the house knows about them if they ask.
What does get people into trouble is improvising disclosure. The arrears list taped in the stairwell. The all-residents email with everyone's payment details. The camera without a sign. Those aren't law problems; they're habit problems. And habits, unlike software, are free to fix.
GDPR in an apartment house isn't about legal machinery — it's about a handful of habits. Collect less, share narrowly, keep records for as long as the tax authority wants them, tell people what the house knows. Board members spend forty-five minutes, write half a page, and after that the topic can sleep quietly in the minutes folder. Which, honestly, is where it belongs.