POPIA & Gated Access Compliance Checklist
Guidance for residential estates, bodies corporate, homeowners’ associations, commercial property owners.
Last updated: 1 August 2026
-
Governance and accountability
-
Identify the responsible party, such as the body corporate, HOA, trustees or estate legal entity.
-
Appoint and register the Information Officer.
-
Appoint a Deputy Information Officer where the estate manager, security manager or managing agent handles day-to-day access-control information.
-
Allocate clear responsibility for POPIA, access-control records, complaints and security incidents.
-
Keep a written POPIA compliance file for the estate.
-
Purpose and lawful basis
-
Document why visitor, contractor, resident and employee access information is collected.
-
Separate purposes clearly, including visitor verification, entry and exit recording, security incident investigation, contractor access control and resident access administration.
-
Identify the lawful basis relied on for each purpose.
-
Avoid relying on consent where access will be refused if the visitor declines, because that may not be a voluntary choice.
-
Minimal information collection
-
List every field collected at the gate or through the access-control system.
-
Confirm that each field is necessary for the stated access-control purpose.
-
Avoid excessive collection such as full ID numbers, ID copies, full driver’s licence scans, home addresses, unnecessary phone numbers, photographs and biometric information unless properly justified.
-
Use less intrusive methods where they meet the estate’s security need.
-
Licence scanning assessment
-
Document why licence scanning is necessary for the estate.
-
Assess whether a less intrusive method would be adequate.
-
Decide which fields from the scan are actually required.
-
Configure the system to store only necessary information where possible.
-
Apply stricter justification for higher-risk estates or estates with documented security concerns.
-
Privacy notices
-
Display a short privacy notice at the gate or access point.
-
Make a fuller privacy notice available online, at the security office or on request.
-
Explain who is collecting the information, what is collected, why it is collected, whether provision is voluntary or mandatory, who may access it, how long it is kept, what rights the visitor has and how to complain.
-
Operator agreements
-
Have a written operator agreement with Access Track.
-
Also have appropriate agreements with security companies, managing agents, hosting providers or other service providers with access to the information.
-
Cover authorised processing, confidentiality, security safeguards, breach reporting, deletion and retention support, access controls, audit rights and assistance with data-subject requests.
-
Retention and deletion
-
Create a retention schedule for each record type.
-
Avoid indefinite retention of visitor and access records.
-
Consider practical retention periods such as 30 to 90 days for visitor records and access logs, 7 to 30 days for CCTV unless linked to an incident, and longer periods only where justified by investigation, insurance, legal claims or audit needs.
-
Securely delete, destroy or de-identify records when no longer needed.
-
Security safeguards
-
Restrict system access to authorised personnel only.
-
Use unique user accounts rather than shared logins.
-
Keep audit logs of access to personal information.
-
Secure gate devices, scanners and computers.
-
Train guards and estate staff on confidentiality and POPIA duties.
-
Review access rights when staff, guards, contractors or managing agents change.
-
Data-subject rights and complaints
-
Have a process for residents, visitors and contractors to request access, correction, deletion, objection or confirmation that their information is held.
-
Verify the requester’s identity before releasing information.
-
Redact third-party information where required.
-
Publish a simple complaint process and state who receives complaints.
-
Record complaint outcomes and corrective actions.
-
Incident response and high-risk processing
-
Keep a written incident response plan.
-
Require guards, managing agents and Access Track to report suspected breaches immediately.
-
Assess whether the Information Regulator and affected data subjects must be notified.
-
Conduct a Personal Information Impact Assessment for biometric access, facial recognition, automated number plate recognition, CCTV analytics, automated denial of access, large-scale visitor profiling or licence scanning that stores more than minimal information.
-
Review access-control practices at least annually and whenever technology, vendors or data fields change.
