17 August 2026

Picture a Saturday morning at a busy Cape Town estate. A steady queue of visitors, contractors and delivery drivers hands over identity documents, has a licence disc scanned, presses a finger to a reader and waits for the boom to lift. By lunchtime the gatehouse has quietly gathered hundreds of pieces of personal information. The security question most committees ask is "did we let the right people in?" The question fewer ask is "what did we just collect, and where does it all go?"
That second question now carries real weight. The Protection of Personal Information Act already applies to personal information gathered at access points, and the Information Regulator has signalled where it wants the sector to head.
What is settled law, and what is still a proposal
POPIA is existing law and applies to estates, body corporates and commercial properties today. Separately, on 30 April 2026 the Information Regulator published a proposed Own Initiative Code of Conduct on the processing of personal information at gated accesses. It was issued for public comment, and it is not final or binding at the time of writing. Treat it as a strong indication of direction rather than a rule you must already meet.
The proposed code speaks to residential estates, commercial buildings, CCTV, physical guards and electronic access-control systems, and it specifically flags high-risk technologies such as CCTV and biometric systems. Even before any code is finalised, its themes are a sensible checklist because they flow from POPIA principles that already bind you.
Useful information versus excessive collection
POPIA does not stop an estate from keeping people safe. It asks you to collect information for a specific, legitimate purpose and to avoid gathering more than that purpose needs.
A name, the person being visited and a time-stamped entry record usually serve a genuine security purpose. Photographing every visitor's full identity document "just in case", or capturing fingerprints from short-term visitors when a simpler method would do, is where collection can tip into excessive. The test is not "could this ever be useful?" — almost anything could be. The test is "does this specific purpose actually require it?"
Biometrics deserve particular care. Fingerprints and facial images are sensitive personal information, and the bar for collecting and safeguarding them is higher than for a name on a visitor slip.
Different people, different expectations
An estate processes very different groups. Residents have an ongoing relationship and may reasonably be enrolled on an access system. Visitors and delivery drivers are transient and rarely need the same depth of data. Contractors sit somewhere in between, often on site for weeks. Employees — guards, cleaners, gardeners — have their own information held by their employers.
Designing one blunt collection process for everyone tends to over-collect from the people you interact with most briefly. Matching what you gather to each group is both better privacy practice and a smoother experience at the gate.
Know your data: collected, stored, accessed, deleted
For every category of information at your access points, your committee or managing agent should be able to answer four plain questions:
- What is collected — visitor records, licence-disc scans, biometrics, CCTV footage?
- Where is it stored, and is that storage secured?
- Who can access it, and is that access logged?
- When is it deleted?
CCTV is where this bites hardest. Retention periods should be defined rather than "keep everything forever". Footage tied to a specific incident may be preserved for a legitimate reason, while routine footage should age out on a set schedule. The same discipline applies to visitor logs and to access permissions that are never revoked after a contractor leaves.
A five-point access-control privacy audit
- Purpose: for each item collected at the gate, write down the specific security purpose. If you cannot, stop collecting it.
- Minimisation: identify one thing you currently collect that the purpose does not require, and remove it.
- Retention: set and document a retention period for CCTV footage, visitor records and incident files.
- Access: list who can view gate data and camera footage, and confirm that access is limited and logged.
- Deletion and revocation: check that departed residents, staff and contractors are removed from access systems and that old records are deleted on schedule.
Run this once a year and keep the notes with your governance records.
Roles at the gate — without overstating the law
Responsibility under POPIA turns on who decides the purpose and means of processing. In practice that is often the HOA or body corporate, sometimes shared with a managing agent, and supported by the security company that operates the system day to day. Exactly how those roles fall for your scheme is a legal question that depends on your structure and contracts, and you should obtain advice on your own circumstances rather than rely on a general description.
Training guards to handle privacy questions
Your officers are the human face of all this. A resident or visitor may object to a scan, ask why information is needed, or request that footage be reviewed. Guards should be able to explain, in plain terms, what is collected and why, and know when to escalate a request to the estate office or managing agent rather than improvise. That training is where privacy compliance and everyday security actually meet — and it is a core part of our estate and residential security and commercial and industrial-park security work across the Western Cape and Gauteng.
Effective security and POPIA compliance are not opposing goals. An access process that collects less, stores it responsibly and deletes it on time is usually easier to run — and easier to defend — than one that hoards everything.
If your estate or commercial property would like to review its current access-control procedures against POPIA principles and the direction of the proposed code, speak to JBA Security. We can walk through your gatehouse process, CCTV handling and access permissions with your trustees or managing agent.
This article is general guidance and not legal advice; your scheme should obtain advice based on its own facts.
Frequently asked questions
Is the gated-access code of conduct law yet?
No. The Information Regulator published it as a proposed code on 30 April 2026 for public comment, and it is not yet in force. POPIA itself, however, already applies.
Are fingerprints treated differently from a name?
Yes. Biometric information such as fingerprints and facial images is sensitive and generally calls for stronger safeguards.
Who is responsible for POPIA at an estate?
It depends on who determines the purpose and means of processing — often the body corporate or HOA, sometimes with the managing agent and security provider. Obtain advice on your own structure.
Sources consulted
- Notice regarding the proposed Own Initiative Code of Conduct on the processing of personal information at gated accesses — Information Regulator (South Africa), Department of Justice and Constitutional Development. Government Gazette No. 54594, Notice 7415 of 2026, published 30 April 2026; written comments invited within 14 days (on or before 14 May 2026). inforegulator.org.za
- Protection of Personal Information Act 4 of 2013 (POPIA) — existing law governing the processing of personal information in South Africa.
More Insights
New PSiRA Reporting Rules: Why Your Security Provider's Payroll Records Matter to Your Estate
Since 1 April 2026, PSiRA-registered security businesses must submit detailed monthly workforce, deployment and payroll information. We explain what changed, why it matters to your property, and the compliance documents an HOA or procurement team should request from any guarding provider.
Read More →Security Wage Changes Are Coming—Is Your Guarding Contract Ready?
South Africa's National Minimum Wage Commission opened its 2026 review in August, with submissions due by 4 September. No new rate is in force yet. We explain how labour costs shape guarding prices and what procurement managers should ask before signing.
Read More →Why PSIRA Registration Matters When Choosing A Security Provider
PSIRA registration isn't just a formality — here's what it actually protects you from, and how to verify a provider's number before you sign.
Read More →Is Your Current Security Provider Truly Accountable?
Book a no-obligation site security assessment with JBA Security.
