On 30 April 2026, the Information Regulator published the draft Gated Access Code of Conduct under POPIA. It applies to owners, managers, and their security and technology service providers at any gated premises, including residential estates and office parks. The code requires them to process personal information lawfully and responsibly, in line with POPIA. It will affect many properties and people, and will require action to comply. Interested parties may submit comments on the draft Code of Conduct to the Regulator on or before 14 May 2026.
This is not a guidance note but a code of conduct which carries more weight.
The main purpose of this code
The overarching purpose is to ensure that owners and managers process personal information collected through gated access systems lawfully, responsibly, and in line with POPIA.
It essentially turns POPIA’s broad legal principles into clear, workable standards for the gated access sector.
Actions you can take
- Get a better understanding of what this Code of Conduct entails by reading our page on the POPIA Code of Conduct for Gated Access.
- Have your say in the final Code of Conduct on Gated Access by instructing Michalsons to draft comments on your behalf for submission to the Regulator.
- Read the draft code and consider its impact on you by accessing it on the Information Regulator’s website.
- Be alerted to future developments by subscribing to the Michalsons newsletter or on LinkedIn.
- If this Code of Conduct on Gated Access affects you, influence its development by asking for our assistance
- Comply with the code by asking for our assistance.
- Take steps to comply with data protection laws by joining our programme and working through the lens for data protection for community schemes, or a module on controlling physical access to premises.