PoPIA turns its attention to gated access

May 2026 News & Events, Security Services & Risk Management

The Information Regulator has gazetted its proposed Code of Conduct for the processing of personal information at gated access points. At 65 pages long, the code signals a significant shift in how housing estates, office parks, and other secure access buildings will be expected to manage personal information collected at entry points.


Ahmore Burger Smidt.

The Code follows growing public complaints about the excessive collection and retention of personal information in gated environments. According to the draft, the Regulator received concerns that information being collected at access points was often “excessive, not relevant and not limited to what is necessary” for security purposes. These concerns included the use of facial recognition technology, biometric systems, CCTV surveillance, and extensive visitor registers, without clear communication about how information would be stored, shared, or retained.

Importantly, the proposed Code applies broadly across both the public and private sectors. This includes residential estates and sectional title schemes, social housing and RDP developments, commercial buildings and office parks, healthcare establishments, schools, universities and government facilities.

Proportionality and accountability

At the heart of the Code are two key requirements: proportionality and accountability. The first means organisations will need to justify why each category of personal information is collected and demonstrate that it is relevant and not excessive for the stated security purpose. The Code specifically flags as potentially excessive the collection of multiple forms of information, such as full names, ID numbers, vehicle registration details, photographs and fingerprints, for a single access-control purpose where less intrusive alternatives exist.

The second major requirement is governance and record-keeping. Responsible parties will need to appoint Information Officers, conduct privacy and proportionality assessments, maintain retention schedules and implement formal PoPIA compliance frameworks. The Code also makes it clear that personal information cannot be kept indefinitely. Records must only be retained for as long as necessary for the purpose for which they were collected, after which they must be securely deleted, destroyed or de-identified.

For businesses and property managers, this marks a move away from informal security practices toward far more structured and defensible data governance. The days of open visitor books, permanent ID scans and unclear retention practices are rapidly coming to an end.

In practice, this means organisations will need to justify why each data point is collected, limit retention periods, and ensure that access controls and storage practices meet reasonable security safeguards. Importantly, “because it has always been done this way” will not suffice as a lawful basis. Businesses operating gated environments should begin auditing their practices now, as over-collection at entry points is both highly visible and increasingly difficult to defend.




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Woolworths attack raises bomb preparedness questions
News & Events
Two explosions have been reported at Woolworths stores in South Africa over the past week. SMART Security Solutions asked Jimmy Roodt, an experienced and accredited explosive ordnance disposal specialist from Gauntlet Security Solutions, for his insight into the events.

Read more...
Growing adoption of AI at work
News & Events AI & Data Analytics
AI adoption accelerates worldwide, with South Africa making gains amid uneven diffusion. Locally, South Africa ranks 46th of 147 economies measured, and its AI usage increased to 23,1% in Q1 2026.

Read more...
Enterprise AI hits the wall
News & Events AI & Data Analytics
Demands for AI privacy and sovereignty expose the limits of architectures built for centralised and borderless data flows. Organisations that redesign early are gaining a measurable edge in AI readiness and scale.

Read more...
71% of organisations suffered an identity breach
News & Events Information Security
The State of Identity Security 2026 report from Sophos finds human error and poor non-human identity management are the root causes of most attacks, as agentic AI accelerates the risk.

Read more...
From the Editor's desk: Security goes mainstream
Technews Publishing News & Events
      Welcome to SMART Security’s SMART Mining & Industrial Security Handbook 2026. While the world is focused on cybersecurity and AI, physical security has become a board-level concern across South Africa’s ...

Read more...
Global security in 2026
Editor's Choice News & Events Security Services & Risk Management Industrial (Industry) Mining (Industry)
The World Security Report 2026 states: “In a world of increasing volatility, physical security has evolved. It is no longer just a defensive measure; it is a critical driver of corporate value.”

Read more...
Who is to blame for autonomous mistakes?
Editor's Choice Security Services & Risk Management Industrial (Industry) Mining (Industry)
Most supply agreements for AI-integrated equipment still closely resemble plant hire contracts from ten years ago: bilateral, human-focused, and silent on who bears the risk when a machine makes a decision on its own.

Read more...
Industry perspective on industrial cybersecurity
Technews Publishing News & Events Infrastructure Industrial (Industry)
The Industrial Security Harmonization Group has released a joint industry perspective highlighting a critical truth in industrial cybersecurity: secure communication is not determined by protocols alone, but by how they are deployed and managed in real-world environments.

Read more...
The post-Q1 security checklist
Asset Management Security Services & Risk Management
By this time of year, employees have changed jobs or roles, suppliers may have changed, and devices have moved between offices, homes, and sites. This is the right time for businesses to run a practical post-Q1 security check.

Read more...
Aerial firefighter training revolution
Fire & Safety News & Events
Sophisticated new flight simulation software capable of accurately modelling the performance of firefighting helicopters could help train pilots to tackle wildfires more effectively and safely in the future.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.