PoPIA turns its attention to gated access

May 2026 News & Events, Security Services & Risk Management

The Information Regulator has gazetted its proposed Code of Conduct for the processing of personal information at gated access points. At 65 pages long, the code signals a significant shift in how housing estates, office parks, and other secure access buildings will be expected to manage personal information collected at entry points.


Ahmore Burger Smidt.

The Code follows growing public complaints about the excessive collection and retention of personal information in gated environments. According to the draft, the Regulator received concerns that information being collected at access points was often “excessive, not relevant and not limited to what is necessary” for security purposes. These concerns included the use of facial recognition technology, biometric systems, CCTV surveillance, and extensive visitor registers, without clear communication about how information would be stored, shared, or retained.

Importantly, the proposed Code applies broadly across both the public and private sectors. This includes residential estates and sectional title schemes, social housing and RDP developments, commercial buildings and office parks, healthcare establishments, schools, universities and government facilities.

Proportionality and accountability

At the heart of the Code are two key requirements: proportionality and accountability. The first means organisations will need to justify why each category of personal information is collected and demonstrate that it is relevant and not excessive for the stated security purpose. The Code specifically flags as potentially excessive the collection of multiple forms of information, such as full names, ID numbers, vehicle registration details, photographs and fingerprints, for a single access-control purpose where less intrusive alternatives exist.

The second major requirement is governance and record-keeping. Responsible parties will need to appoint Information Officers, conduct privacy and proportionality assessments, maintain retention schedules and implement formal PoPIA compliance frameworks. The Code also makes it clear that personal information cannot be kept indefinitely. Records must only be retained for as long as necessary for the purpose for which they were collected, after which they must be securely deleted, destroyed or de-identified.

For businesses and property managers, this marks a move away from informal security practices toward far more structured and defensible data governance. The days of open visitor books, permanent ID scans and unclear retention practices are rapidly coming to an end.

In practice, this means organisations will need to justify why each data point is collected, limit retention periods, and ensure that access controls and storage practices meet reasonable security safeguards. Importantly, “because it has always been done this way” will not suffice as a lawful basis. Businesses operating gated environments should begin auditing their practices now, as over-collection at entry points is both highly visible and increasingly difficult to defend.




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Fire safety in South Africa
Technoswitch Fire Detection & Suppression Technews Publishing SMART Security Solutions Fire & Safety Security Services & Risk Management Editor's Choice
Fire safety is sometimes ignored, sometimes relegated to whatever is cheapest, and sometimes treated with the seriousness it deserves, given that it focuses on protecting life and assets. SMART Security Solutions asked Brett Birch, MD of Technoswitch, for some insights into the realities of fire safety in South Africa.

Read more...
From the editor's desk: The high price of cheap
Technews Publishing News & Events
Bringing fire and safety, along with intrusion and perimeter protection, into the same publication is an interesting exercise. At their core, all these systems exist for one reason: to warn people ...

Read more...
A risk-based approach to fire safety
Fire & Safety Security Services & Risk Management Industrial (Industry) Agriculture (Industry)
A report by fire engineering consultancy ASP Fire is challenging blanket assumptions around combustible-core sandwich panels, arguing instead for a rational, risk-based approach that balances fire safety requirements with commercial realities in sectors such as agriculture, manufacturing and industrial processing.

Read more...
Preventing and suppressing lithium fires
SMART Security Solutions Technews Publishing Editor's Choice Fire & Safety Security Services & Risk Management Smart Home Automation
SMART Security Solutions asked Clyde Becker, director of Pyro Brand, for some insight into the mechanics of lithium-ion battery fire risks, especially thermal runaway, and to define a comprehensive, layered approach to fire detection and suppression.

Read more...
Southern Africa’s security leaders honoured at the 2026 OSPAs
News & Events
The winners of the 2026 Southern Africa Outstanding Security Performance Awards (OSPAs) were announced at a virtual ceremony on 23 June 2026. The winners in seven categories will progress to the third Global OSPAs in 2027.

Read more...
MPT unveils R50m customer experience centre
News & Events Power Management
Master Power Technologies has unveiled its new Customer Experience Centre, also home to its new regional headquarters in Midrand, Gauteng. The facility spans 6 000 m2 and houses approximately 200 employees.

Read more...
Duxbury Cybersecurity sharpens reseller offering
Duxbury Networking Information Security News & Events
Duxbury Networking has strengthened its Duxbury Cybersecurity business unit by adding WatchGuard and Cynet, giving South African resellers broader, more integrated coverage for the security risks customers are now asking them to address.

Read more...
Disconnect between confidence in identity security and operational reality
Access Control & Identity Management News & Events
New FIDO Alliance and HID study reveals gap between identity security confidence and reality; 94% of enterprises claim they can revoke employee access within 24 hours, yet 35% experienced delays or failures in the past two years.

Read more...
Paxton Solo training available to security installers
Paxton Access Control & Identity Management News & Events
Following the launch of Solo, Paxton’s brand-new access control system, the security manufacturer is rolling out dedicated Solo training sessions across South Africa to support security installers working with the system.

Read more...
Echoes of 2018? Follow-up on Woolworths explosions
Technews Publishing News & Events Security Services & Risk Management Retail (Industry) Facilities & Building Management
SMART Security Solutions follows up with Jimmy Roodt to find out more about an old connection to the Woolworths bombings from 2018. The investigation remains ongoing.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.