Overview of POPIA and the Gated Access Code of Conduct for Access Control Information Processing
Guidance for residential estates, bodies corporate, homeowners’ associations, commercial property owners, and Access Track as operator.
Last updated: 1 August 2026
1. Executive summary
The Protection of Personal Information Act, 4 of 2013 (POPIA), applies whenever a public or private body processes personal information in South Africa, including at access control points. The proposed Information Regulator Code of Conduct for gated accesses translates POPIA’s general requirements into practical rules for estates, office parks, schools, mines, solar farms, industrial sites, government premises and other controlled-access environments.
The central message is simple: a secure scanning solution is important, but it does not by itself make the property owner or estate compliant. Compliance depends on lawful purpose, minimality, transparency, retention, data-subject rights, governance, operator controls and documented decision-making. Access Track can provide secure tools and operator safeguards, but the responsible party must still decide what is collected, why it is collected, how long it is kept, who may access it and how data subjects are informed.
2. Who is responsible for what?
Under POPIA, the responsible party is the person or body that determines the purpose of and means for processing personal information. In gated-access environments this will usually be the homeowners’ association, body corporate, trustees, estate management entity, commercial landlord, managing company, school, mine operator, solar-farm owner, office-park owner or public body that controls the premises.
Access Track, when providing licence scanning, visitor management, equipment, software, hosting or related support services on behalf of a property owner, is generally an operator. The operator processes personal information for the responsible party and must do so only with the responsible party’s knowledge or authorisation, under a written operator agreement, and with appropriate confidentiality and security measures.
|
Topic |
Responsible party |
Access Track as operator |
|
Purpose and lawful basis |
Decides why visitor information is collected and identifies the POPIA justification. |
Processes only for the agreed purposes and does not decide independent uses. |
|
Minimality |
Decides what fields are necessary for the site’s risk profile. |
Configures systems to capture only the approved fields where technically possible. |
|
Privacy notices |
Provides clear notices at gates, reception points, websites and onboarding documents. |
May supply template wording or system functionality, but the owner must approve and issue the notice. |
|
Retention |
Sets retention periods and lawful exceptions for incidents or investigations. |
Applies configured deletion, archiving or restriction processes as agreed. |
|
Security |
Must ensure appropriate technical and organisational safeguards and monitor operators. |
Must maintain agreed safeguards, confidentiality, access controls, audit logs and breach reporting. |
|
Data-subject rights |
Responds to access, correction, deletion, objection and complaint requests. |
Assists the responsible party to retrieve, correct, restrict or delete records where instructed. |
3. Practical POPIA principles for access control
3.1 Accountability
The responsible party must appoint and register an Information Officer and, where appropriate, Deputy Information Officers. It must maintain a POPIA compliance framework covering access control, privacy notices, retention, incident response, security safeguards, operator management, complaints and staff training. The proposed Code expects the responsible party to demonstrate compliance, not merely assert it.
3.2 Processing limitation and minimality
Personal information may only be collected lawfully, reasonably and in a way that is adequate, relevant and not excessive. For a normal visitor-access purpose, the proposed Code treats basic information such as name, purpose of visit, vehicle registration where relevant, host or destination, and time of entry or exit as more likely to be proportionate. Full ID numbers, copies of identity documents, full driver’s licence scans, home addresses, photographs, biometric data and unrelated contact details require a stronger justification and may be excessive where less intrusive alternatives are available.
3.3 Purpose specification
Each category of information must be linked to a specific, explicitly defined and lawful purpose. “Security” should be broken down into practical purposes, such as verifying identity, confirming authorisation to enter, recording entry and exit for incident investigation, managing contractor access, or supporting emergency response. If a field is not needed for that purpose, it should not be collected.
3.4 Openness and privacy notices
Visitors, residents, employees, contractors and service providers must be told who is collecting their information, what is collected, why it is collected, whether provision is voluntary or mandatory, who may access it, how long it is kept, what rights they have, and how to complain. Notices should be visible at the access point, easy to understand, and supported by a fuller privacy notice online or on request.
3.5 Retention and deletion
Access control records must not be kept indefinitely. The proposed Code suggests purpose-based retention, commonly 30 to 90 days for visitor registers or access logs, shorter cycles for CCTV unless footage is linked to an incident, and longer retention only where justified by contract, law, audit, dispute, insurance, investigation or litigation needs. Deletion must be secure and capable of preventing reconstruction in readable form.
3.6 Security safeguards
The responsible party and operator must apply appropriate technical and organisational measures. Examples include role-based access, audit logs, encryption where appropriate, secure devices, secure hosting, staff confidentiality commitments, privacy training, documented incident response, vulnerability testing, penetration testing where justified, and immediate escalation of suspected compromises.
3.7 Data-subject participation
Data subjects have rights to request confirmation of whether their information is held, access to their information, correction of inaccurate or misleading information, deletion or destruction where appropriate, objection to certain processing, and complaint handling through the responsible party and the Information Regulator. The responsible party should have a practical process to verify identity, retrieve relevant access records, redact third-party information where necessary, and respond within applicable timeframes.
4. Licence scanning: when it is useful and when it becomes risky
Licence scanning can be an efficient and secure way to reduce false entries, verify a visitor’s identity and create a reliable audit trail. However, a South African driver’s licence barcode may expose more information than is needed for ordinary access control. For that reason, the decision to scan must be supported by a documented assessment of necessity, proportionality, lawful basis, retention and safeguards.
For lower-risk residential visits, it may be sufficient to capture limited visitor details and verify them visually against an identity document without storing a copy or full document dataset. For higher-risk premises such as mines, critical infrastructure, solar farms, high-value commercial sites or locations with documented security incidents, more robust verification may be justified, provided the responsible party can show why lesser measures are inadequate.
5. Why secure collection is not the same as POPIA compliance
A property owner does not become POPIA-compliant simply by using a secure scanner, encrypted device or reputable service provider. Security is only one of POPIA’s eight conditions. The responsible party must still prove that the collection is lawful, minimal, transparent, purpose-specific, accurate, retained only for as long as necessary, protected against misuse, and supported by mechanisms for access, correction, objection and complaints.
In practice, this means that Access Track may help the responsible party comply by providing secure technology, configurable collection fields, auditability, deletion capabilities, support processes and operator commitments. But the responsible party must still make and document the legal and operational decisions. The operator cannot decide the estate’s lawful basis, approve excessive collection, issue the estate’s privacy notice, appoint the estate’s Information Officer, or replace the estate’s compliance framework.
6. Practical compliance checklist
-
Identify the responsible party for each site and register the Information Officer.
-
Document each access control purpose and the lawful basis relied on.
-
Map every field collected and remove fields that are not necessary for the stated purpose.
-
Complete a proportionality assessment for licence scanning, biometrics, facial recognition, CCTV and automated access decisions.
-
Conduct a Personal Information Impact Assessment for high-risk processing.
-
Implement clear gate notices and a fuller privacy notice.
-
Set site-specific retention periods and configure deletion or restriction controls.
-
Conclude a written operator agreement with Access Track and any security provider, hosting provider or managing agent.
-
Limit access to personal information to authorised personnel only and keep audit logs.
-
Train guards, reception staff, estate managers and administrators on POPIA and the Code.
-
Create processes for data-subject access, correction, deletion, objection and complaints.
-
Maintain an incident response plan and notify Access Track, the estate, the Regulator and affected data subjects where required.
-
Review the access control process regularly, especially when introducing new technology or expanding collected fields.
7. Access Track or property owner - who is responsible?
Access Track provides secure licence scanning and visitor information processing services as an operator for the property owner or estate. The property owner, homeowners’ association, body corporate, trustees, commercial landlord or other site controller remains the responsible party under POPIA. The responsible party must determine the lawful purpose, categories of information collected, lawful basis, retention period, privacy notice, access permissions, complaint process and ongoing compliance framework. Access Track supports those decisions through secure systems and agreed operator safeguards, but the responsible party remains accountable for POPIA and Code compliance.
8. Important note
This overview is intended as practical operational guidance and not as formal legal advice. Because the referenced Code of Conduct is not yet finalised, property owners should monitor the Information Regulator’s final publication and update policies, contracts and notices when the final Code is issued or amended.
9. References
-
Protection of Personal Information Act (POPI Act), available at https://popia.co.za
-
Own Initiative Code of Conduct of the Information Regulator on the processing of personal information at gated accesses in South Africa (Code of Conduct), available to download here.
