If your estate, complex, office park, or gated community controls access at its gates, you need to understand how you collect and use personal information.
The Information Regulator has published a draft code of conduct for processing personal information at gated access points. Although the code is not yet final, it shows what the regulator expects from gated communities and service providers that collect, store, or use personal information for access control.
Gated communities already need to comply with POPIA and PAIA. The new code places greater focus on gate and visitor management practices and signals that organisations should review their current processes.
Complying with these requirements usually involves both legal and technical measures. We can help you with the legal component and recommend a service provider for the technical.
Once this code is finalised and published it will be enforceable and binding.
Overall objectives of the POPIA Code of Conduct for Gated Access
- Provide clear direction on how owners and managers must apply and comply with the conditions for lawful processing of personal information.
- Provide procedures for dealing with complaints.
- Establish a sector-specific framework for the responsible processing of personal information.
- Align gated access practices with POPIA requirements.
- Provide clarity and consistency
- Promote privacy-protective access control to premises.
The Code requires responsible parties operating gated access premises to comply with all eight conditions for lawful processing under POPIA.
Who must comply with the POPIA Code of Conduct on Gated Access?
It will apply to both residential and commercial premises with access control.
The code will apply to any premises with gated access or controlled access. Premises include “a house or building, together with its land and outbuildings, occupied by residents, business or considered in an official context, such as residential estate or commercial/complex/office park etc”. Gated access “means restricted entry to a specific area, requiring authorisation or credentials for access.”
- Residential estates.
- Sectional title schemes.
- Gated communities and housing complexes.
- Business parks, commercial premises or office parks.
- Public (Government) buildings.
The following kinds of people will have to comply.
- Private and public bodies that own or manage premises with gated access.
- Trustees of the body corporate.
- Managing agents
- Home Owners’ Associations (HOAs).
- Executive estate managers in the private and public sectors.
- Facilities manager of many corporates in South Africa.
- Security service providers (acting as operators on a need-to-know basis).
- Technology and access control system suppliers (acting as operators on a need-to-know basis).
If you collect people’s personal information to control entry to premises, this applies to you.
Different role players will have different obligations?
Estate owners and community bodies
Estate owners, body corporates, and homeowners’ associations typically act as responsible parties under POPIA. They decide why they collect access-control information and how they use it.
Your organisation will already have a default Information Officer under POPIA. The draft code highlights the additional compliance measures your deputy IO will have to do.
Security and access-control service providers
Service providers may manage visitor systems, biometric access, CCTV monitoring, and access records. Therefore, choose a reputable service provider that meets regulatory requirements and supports your organisation’s technical compliance obligations.
What the code of conduct expects you to do
The draft code highlights practical steps that gated communities and access-control providers should take. It does not cover every POPIA compliance requirement, but it identifies the additional areas you need to focus on.
Start by understanding what you collect
Many estates and access-control systems collect more personal information than they realise. For example, scanning a South African driving licence barcode can expose:
- full names and initials
- South African ID numbers
- date of birth
- licence issue and expiry dates
- vehicle codes
- restriction codes that may reveal sensitive medical information
- biometrics
- CCTV footages
Before deciding whether to collect this information, organisations must first understand what data they process and why.
One practical starting point is mapping activities and producing a Record of Processing Activities (ROPA). A ROPA helps organisations identify:
- What personal information is being collected.
- Why is it being processed.
- Who has access to it.
- How long is it retained for.
- Whether the processing is necessary to achieve its goals.
If your organisation does not yet have a ROPA, now is the time to create one.
Identify and document your lawful basis
Under POPIA, organisations must have a lawful basis for processing personal information. In gated access environments, many operators may rely on legitimate interest, particularly where they process information for safety and security purposes.
But relying on legitimate interest is not enough on its own. You must be able to explain:
- What the legitimate interest is.
- Why the processing is necessary.
- Why the processing does not unfairly impact the rights of data subjects.
For example, where an estate scans and stores driving licence barcode information for security purposes, it should clearly document why it processes that information, such as maintaining safety and security at the premises.
Notify people about what you are doing
Transparency remains one of the core principles of POPIA.
People entering gated environments should know:
- What information is being collected.
- Why it is being collected.
- Whether providing it is mandatory or voluntary.
- How long it will be stored.
- Who it may be shared with.
This can be done through notice boards or estate manuals and policies.
Minimise the data you collect
One of the biggest themes emerging from the draft POPIA Code of Conduct for Gated Access is data minimisation. This aligns with sections 10 and 14 of the Protection of Personal Information Act, which require organisations to retain personal information only as long as necessary to fulfil the purpose for which they originally collected or processed it.
One of the biggest themes emerging from the draft code is data minimisation. This aligns with sections 10 and 14 of the Protection of Personal Information Act. This requires organisations to retain personal information only for as long as necessary to fulfil the purpose for which they originally collected or processed it.
Just because a system can collect certain information does not mean it should.
Estates and service providers should consider whether their systems can be configured to:
- avoid storing unnecessary information;
- mask sensitive fields;
- limit retention periods; and
- restrict access to personal information.
Data collection needs to be designed and tailored to minimise the risk such processing will create. Organisations must design and tailor data collection to minimise the risk that processing creates.
Collect Minimum, Retain Minimum
Train frontline staff at gated accesses
Security guards and gate personnel are often the first people residents and visitors speak to about privacy concerns.
- The organisation should explain what information is collected.
- The organisation should explain why the information is collected.
- The organisation should explain who people can contact regarding more detailed questions or complaints.
- Staff should know how to respond to POPIA-related questions.
- Staff should know what to do when someone objects to processing or requests access to information.
Training is particularly important where service providers operate access-control systems on behalf of estates or property managers.
Preparation before the regulator finalises the POPIA Code of Conduct for Gated Access
Although the code of conduct is still in draft form, it provides useful insight into the regulator’s expectations. Organisations do not necessarily need to wait for the final version before improving their privacy practices.
If an organisation follows the Code of Conduct, it should be safe for 90% of data protection.
When will the Information Regulator Code of Conduct on the processing of personal information at gated accesses in South Africa be finalised?
We don’t know. The Regulator must follow the process in Chapter 7 of POPIA. Once the Regulator has received and processed public input, it will publish the code of conduct in the government gazette. The code will come into effect 28 days after the Regulator issues the code and publishes a notice in the government gazette.
We will monitor these developments and will update this post with further developments.
Timeline of the process
- During a consult session held on 18 February 2026, the Regulator went through the draft proposed Gated Access Code of Conduct.
- On 30 April 2026, the Regulator published the draft Code of Conduct.
- Submit your comments on the Code of Conduct to the Regulator within 14 days of publication, on or before 29 May 2026. The Regulator will still consider comments submitted after 13 May 2026 until 29 May 2026.
- According to the Regulator, there has been a public outcry on this issue, and therefore, the Information Regulator will respond by publishing a code of conduct on its own initiative.
Actions you can take
We know that this is probably the last compliance burden you need. We can help you deal with the legal side in a practical way.
You can take action in two ways.
Option 1: Do it yourself through our Information Officer Programme
Join our Information Officer Programme and use our guidance, resources and templates to take action yourself.
For residential gated communities, we can offer a discounted option so that you can work through the key POPIA and PAIA compliance steps at a reduced cost.
This is a good option if you want to manage compliance internally but need a clear path, practical tools and ongoing support.
Option 2: Outsource the legal compliance work to us
If you do not want to do it yourself, you can outsource the legal component to us.
We can help you understand your obligations, document your lawful basis, prepare or update your privacy notices, review your access-control arrangements, advise on contracts with service providers, and help you decide what steps to prioritise.
Speak to us and we will give you a quote.
Technical solutions
You may also need to make technical changes to your access-control systems. We can recommend service providers who can help you implement technical components that align with the code.
