South Africa’s Information Regulator has published a draft Code of Conduct that will reshape how gated communities, residential estates, commercial buildings and government offices handle the personal information of visitors, residents and employees.
If you have ever handed over your driver’s licence at a boom gate, signed a visitor register that the next person in the queue could read, or had your fingerprints scanned just to enter an office park, you have experienced the practices that South Africa’s Information Regulator is now moving to regulate. The proposed Own-Initiative Code of Conduct on the Processing of Personal Information at Gated Accesses, gazetted on 30 April 2026 under Section 60(1) of POPIA, will be legally binding once finalised. Finalisation is expected during the 2026/27 financial year, according to Moonstone Information Refinery.
The Code emerged from a wave of public complaints about intrusive access-control practices. As IOL Business Report noted, gated environments are no longer just security systems. They are now regulated data systems.
Who Does This Apply To?
The Code covers any premises where access is controlled, and personal information is collected in the process. As published in Government Gazette 54594, it includes residential estates, body corporates, HOAs, social housing schemes, commercial office parks, retail centres, hotels, government buildings, healthcare facilities and schools. As ITLawCo puts it: “If your security team controls who enters and leaves, and you process personal information to do that, this Code is aimed squarely at you.”
What Is Changing?
1. Collect only what you actually need
The Code sets a strict minimality standard. As IOL reports, collecting full names, ID numbers, vehicle details, photographs and fingerprints all for a single access purpose will likely be treated as excessive, especially where simpler alternatives exist. BusinessTech confirms that estates can still collect a name, vehicle registration, entry time and host details but the Regulator will take a harder line on anything beyond that.
| Category | Allowed | Excessive |
| Employees | Name, access card number, entry/exit time | Full ID number, home address, next-of-kin, unjustified biometrics |
| Visitors | Name, visit purpose, vehicle registration, entry/exit time | Home address, email, personal phone, employer details |
| Contractors | Name, company, work order reference, entry/exit time | Full ID number, bank details, residential address |
2. Biometrics need proper justification
Fingerprints, facial images and facial recognition data are classified as special personal information under POPIA section 26. As Recording Law explains, processing this category requires explicit consent or another specific legal basis. Before installing biometric systems, responsible parties must run a proportionality assessment showing the system is necessary (not just convenient), likely to be effective, and that the security benefit genuinely outweighs the privacy cost to visitors. Faster entry at a boom gate is unlikely to pass that test.
3. Consent must be genuine
Signing a visitor register is not consent. Under the Code, consent must be informed, voluntary, and formally recorded in a way that mirrors Form 4 from the Information Regulator. Visitors must also be able to object to processing without being turned away at the gate. Estates will need alternative identity verification methods in place.
4. Data must be deleted on schedule
Every responsible party needs a written retention policy. As IT-Online reported, the era of clipboard security is over. The Code sets clear outer limits: visitor registers should be kept for 30 to 90 days, CCTV footage for 7 to 30 days, and incident reports for 3 to 5 years. Keeping data indefinitely is non-compliance, full stop.
5. Automated decisions must be explainable
Number plate recognition, AI-flagging systems and biometric gates that automatically deny access are all under scrutiny. Where automated systems make access decisions, visitors must be able to challenge those decisions and understand the logic behind them.
Who Is on the Hook?
The HOA, body corporate, or property owner is the responsible party. As ATG Digital’s guide makes clear, hiring a security company does not transfer that responsibility. You remain accountable for how your operator handles personal information.
Every responsible party must:
- Register an Information Officer with the Regulator (it is free, takes 30 minutes, and is one of the most overlooked POPIA obligations in South Africa)
- Build a compliance framework covering privacy notices, a retention schedule, and an incident response plan
- Sign operator agreements with security providers that include data protection obligations
- Run a Personal Information Impact Assessment (PIIA) before rolling out biometrics or facial recognition
- Train all staff who handle visitor data
Werksmans Attorneys director Ahmore Burger-Smidt puts it plainly: “Property, retail, education, healthcare and corporate campus operators should undertake pre-emptive reviews of entry-point collection practices, minimising collection to what is strictly necessary, securing storage, shortening retention and eliminating bulk ID scans and open visitor logs.”
What Happens If You Do Not Comply?
Once approved, the Code is enforceable by the Information Regulator. POPIA already allows for administrative fines of up to R10 million per offence plus imprisonment of up to 10 years for directors and registered Information Officers, as Synthro notes. Both the organisation and the individual can be held liable at the same time.
Visitors who believe their data has been mishandled can complain to the responsible party, escalate to an independent adjudicator (in the residential sector, that could be the Community Schemes Ombud Services (CSOS) or NAMA), or go straight to the Information Regulator using Form 5 at POPIAcomplaints@inforegulator.org.za.
What Should You Do Right Now?
Michalsons advises not to wait for formal adoption. Here is where to start:
- Audit what you collect at each access point and cut anything you cannot justify
- Check your CCTV and biometric setups against the proportionality test
- Write a retention policy and actually follow it
- Replace open visitor books with a secure digital system
- Put up a clear privacy notice at your entrance
- Register your Information Officer via the eServices Portal if you have not done so yet
- Update your contracts with security providers to include data protection clauses
If you need assistance with implementing POPIA and PAIA legislation for your business, HOA, estate, body corporate or property ownership, get in touch with us or book a free consultation to assess your risk.