{"id":3724,"date":"2026-05-29T09:00:21","date_gmt":"2026-05-29T09:00:21","guid":{"rendered":"https:\/\/itlawco.com\/?p=3724"},"modified":"2026-05-29T09:10:23","modified_gmt":"2026-05-29T09:10:23","slug":"popia-code-of-conduct-gated-access-south-africa","status":"publish","type":"post","link":"https:\/\/itlawco.com\/fr\/popia-code-of-conduct-gated-access-south-africa\/","title":{"rendered":"The POPIA Code of Conduct for Gated Access"},"content":{"rendered":"\n\t\t<div id=\"fws_6a60ed06be7ce\"  data-column-margin=\"default\" data-midnight=\"dark\"  class=\"wpb_row vc_row-fluid vc_row\"  style=\"padding-top: 0px; padding-bottom: 0px; \"><div class=\"row-bg-wrap\" data-bg-animation=\"none\" data-bg-animation-delay=\"\" data-bg-overlay=\"false\"><div class=\"inner-wrap row-bg-layer\" ><div class=\"row-bg viewport-desktop\"  style=\"\"><\/div><\/div><\/div><div class=\"row_col_wrap_12 col span_12 dark left\">\n\t<div  class=\"vc_col-sm-12 wpb_column column_container vc_column_container col no-extra-padding inherit_tablet inherit_phone \"  data-padding-pos=\"all\" data-has-bg-color=\"false\" data-bg-color=\"\" data-bg-opacity=\"1\" data-animation=\"\" data-delay=\"0\" >\n\t\t<div class=\"vc_column-inner\" >\n\t\t\t<div class=\"wpb_wrapper\">\n\t\t\t\t\n<div class=\"wpb_text_column wpb_content_element \" >\n\t<h2 class=\"text-text-100 mt-3 -mb-1 text-&#091;1.125rem&#093; font-bold\">Why security gates are becoming regulated data systems<\/h2>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-&#091;1.7&#093;\">Security gates used to control movement. Today, they control personal information.<\/p>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-&#091;1.7&#093;\">Every visitor log, licence scan, CCTV recording, biometric reader, and access tag is a form of regulated data processing. The Information Regulator\u2019s draft Code of Conduct for Gated Access\u2014published for comment on 30 April 2026\u2014formalises a major shift: gated environments are no longer just security systems; they are regulated data systems.<\/p>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-&#091;1.7&#093;\">This article explains what the draft Code means, who it affects, the legal risks, how it now stands, and how estates and controlled-access environments should prepare.<\/p>\n<h2 class=\"text-text-100 mt-3 -mb-1 text-&#091;1.125rem&#093; font-bold\">Where the draft Code stands now<\/h2>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-&#091;1.7&#093;\">On 30 April 2026, the Information Regulator published the draft <a href=\"https:\/\/pmg.org.za\/call-for-comment\/1717\/\"><em>Own Initiative Code of Conduct on the Processing of Personal Information at Gated Accesses in South Africa<\/em><\/a> in Government Gazette No. 54594 (Government Notice No. 7415). It was issued on the Regulator\u2019s own initiative under section 60(1) of POPIA, with the comment notice given under section 61(2).<\/p>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-&#091;1.7&#093;\">The draft is 65 pages. The comment period\u2014initially fourteen days, <a href=\"https:\/\/inforegulator.org.za\/wp-content\/uploads\/2026\/05\/Media-Alert-invitation-for-public-comment-on-POPIA-code-of-conduct-for-Gated-Access.pdf\">later extended<\/a>\u2014closed on 29 May 2026. The draft is now with the Regulator, which will consider stakeholder comments before deciding whether to revise the draft and, in due course, issue a final Code.<\/p>\n<blockquote>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-&#091;1.7&#093;\">An important distinction: the Code has been published as a draft. It is not yet binding. A Code of Conduct issued under section 60 of POPIA becomes binding and enforceable once it is finalised and issued, but this version is a consultation draft, and its content may change before then.<\/p>\n<\/blockquote>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-&#091;1.7&#093;\"><strong>ITLawCo filed comments on the draft.<\/strong> Our submission supports the Regulator\u2019s underlying objective (there are real privacy harms at access points, and they are worth addressing) while identifying areas where the draft needs refinement before it is issued. We summarise the three that matter most to controlled-access operators below.<\/p>\n<h2 class=\"text-text-100 mt-3 -mb-1 text-&#091;1.125rem&#093; font-bold\">What is the POPIA Code of Conduct for Gated Access?<\/h2>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-&#091;1.7&#093;\">The Code is a sector-specific regulatory instrument under section 60 of POPIA. It translates the Act&#8217;s general principles into operational rules for environments where access is controlled, including:<\/p>\n<ul class=\"&#091;li_&amp;&#093;:mb-0 &#091;li_&amp;&#093;:mt-1 &#091;li_&amp;&#093;:gap-1 &#091;&amp;:not(:last-child)_ul&#093;:pb-1 &#091;&amp;:not(:last-child)_ol&#093;:pb-1 list-disc flex flex-col gap-1 pl-8 mb-3\">\n<li class=\"font-claude-response-body whitespace-normal break-words pl-2\">Residential estates and sectional title schemes<\/li>\n<li class=\"font-claude-response-body whitespace-normal break-words pl-2\">HOAs and bodies corporate<\/li>\n<li class=\"font-claude-response-body whitespace-normal break-words pl-2\">Office parks and commercial complexes<\/li>\n<li class=\"font-claude-response-body whitespace-normal break-words pl-2\">Industrial and controlled-access facilities<\/li>\n<\/ul>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-&#091;1.7&#093;\">Once finalised and issued, the Code will be binding and enforceable, not guidance. Until then, it is a draft that signals the Regulator&#8217;s direction of travel.<\/p>\n<h2 class=\"text-text-100 mt-3 -mb-1 text-&#091;1.125rem&#093; font-bold\">Why the Information Regulator introduced this Code<\/h2>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-&#091;1.7&#093;\">The Regulator has identified systemic patterns across gated environments:<\/p>\n<ul class=\"&#091;li_&amp;&#093;:mb-0 &#091;li_&amp;&#093;:mt-1 &#091;li_&amp;&#093;:gap-1 &#091;&amp;:not(:last-child)_ul&#093;:pb-1 &#091;&amp;:not(:last-child)_ol&#093;:pb-1 list-disc flex flex-col gap-1 pl-8 mb-3\">\n<li class=\"font-claude-response-body whitespace-normal break-words pl-2\">Excessive visitor data collection<\/li>\n<li class=\"font-claude-response-body whitespace-normal break-words pl-2\">Weak surveillance governance<\/li>\n<li class=\"font-claude-response-body whitespace-normal break-words pl-2\">Unlawful or unclear biometric processing<\/li>\n<li class=\"font-claude-response-body whitespace-normal break-words pl-2\">Poor transparency to residents and visitors<\/li>\n<li class=\"font-claude-response-body whitespace-normal break-words pl-2\">Heavy reliance on third-party security operators<\/li>\n<\/ul>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-&#091;1.7&#093;\">The Code aims to standardise how POPIA&#8217;s lawful processing conditions apply in real-world gatehouse environments.<\/p>\n<h2 class=\"text-text-100 mt-3 -mb-1 text-&#091;1.125rem&#093; font-bold\">The gatehouse as a regulated data processing environment<\/h2>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-&#091;1.7&#093;\">Under POPIA, &#8220;processing&#8221; includes the collection, recording, storage, use, and deletion of personal information. This means everyday gatehouse activity is regulated:<\/p>\n<ul class=\"&#091;li_&amp;&#093;:mb-0 &#091;li_&amp;&#093;:mt-1 &#091;li_&amp;&#093;:gap-1 &#091;&amp;:not(:last-child)_ul&#093;:pb-1 &#091;&amp;:not(:last-child)_ol&#093;:pb-1 list-disc flex flex-col gap-1 pl-8 mb-3\">\n<li class=\"font-claude-response-body whitespace-normal break-words pl-2\">Logging visitors<\/li>\n<li class=\"font-claude-response-body whitespace-normal break-words pl-2\">Scanning driver&#8217;s licences or IDs<\/li>\n<li class=\"font-claude-response-body whitespace-normal break-words pl-2\">Recording vehicle information<\/li>\n<li class=\"font-claude-response-body whitespace-normal break-words pl-2\">Operating CCTV and surveillance<\/li>\n<li class=\"font-claude-response-body whitespace-normal break-words pl-2\">Managing biometric or tag-based access<\/li>\n<\/ul>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-&#091;1.7&#093;\">What was once informal security practice is now legally accountable data governance.<\/p>\n<h2 class=\"text-text-100 mt-3 -mb-1 text-&#091;1.125rem&#093; font-bold\">Three areas the draft still needs to get right<\/h2>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-&#091;1.7&#093;\">Our submission addresses several dozen points. Three are worth flagging for any organisation that operates a controlled-access environment, because they shape how workable the final Code will be.<\/p>\n<ol>\n<li class=\"font-claude-response-body break-words whitespace-normal leading-&#091;1.7&#093;\"><strong>Lawful basis beyond consent.<\/strong> The draft leans heavily on consent as the route to lawful processing. But consent given at a gate, where the practical choice is to comply or be turned away, is rarely the freely given consent POPIA contemplates. POPIA offers six grounds for lawful processing, not one. The final Code should make clear how the other lawful bases (contract, legal obligation, public-law duty, legitimate interest) apply in different settings, rather than defaulting to consent.<\/li>\n<li class=\"font-claude-response-body break-words whitespace-normal leading-&#091;1.7&#093;\"><strong>One size does not fit every gate.<\/strong> The draft applies in largely identical terms across very different environments: residential estates, hotels, hospitals, schools, office parks, government buildings, and critical infrastructure. Each of these already sits under its own statutory regime (immigration law, labour law, community-scheme law, education law, and others). A hotel is legally required to keep a guest register; a workplace&#8217;s monitoring is governed by labour law; a body corporate operates under registered conduct rules. The final Code will work better as a two-layer instrument: common rules that apply at every gate, plus sector-specific calibration for the settings that differ.<\/li>\n<li class=\"font-claude-response-body break-words whitespace-normal leading-&#091;1.7&#093;\"><strong>Where biometric data lives.<\/strong> Biometric information is special personal information under POPIA and carries elevated risk: a fingerprint or face, unlike a password, cannot be reset if it leaks. The single most consequential omission in the draft is a clear rule on where biometric templates are stored and who holds the key. International regulators have converged on the principle that the least intrusive architecture\u2014template held on a device the data subject controls, or encrypted with a key the data subject holds\u2014should be the default. The final Code should say so.<\/li>\n<\/ol>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-&#091;1.7&#093;\">These are constructive points. None is fatal to the Code; all are addressable in the next draft.<\/p>\n<h2 class=\"text-text-100 mt-3 -mb-1 text-&#091;1.125rem&#093; font-bold\">The biggest compliance risks for estates and controlled-access environments<\/h2>\n<ul>\n<li class=\"font-claude-response-body break-words whitespace-normal leading-&#091;1.7&#093;\"><strong>Visitor data and minimality.<\/strong> POPIA requires that personal information be relevant, adequate, and not excessive. Many estates collect more data than security requires, particularly through full licence or ID scanning.<\/li>\n<li class=\"font-claude-response-body break-words whitespace-normal leading-&#091;1.7&#093;\"><strong>Surveillance and proportionality.<\/strong> CCTV must serve a legitimate purpose, be proportionate, and be supported by transparency (signage and notices). Retention must be justified and limited. South African courts are increasingly applying this proportionality requirement to private surveillance.<\/li>\n<li class=\"font-claude-response-body break-words whitespace-normal leading-&#091;1.7&#093;\"><strong>Biometric processing.<\/strong> Biometric data is special personal information under POPIA and carries elevated legal risk. Lawful justification, safeguards, and in some cases regulatory authorisation are required.<\/li>\n<li class=\"font-claude-response-body break-words whitespace-normal leading-&#091;1.7&#093;\"><strong>Vendor and operator liability.<\/strong> Outsourcing does not transfer responsibility. The estate or governing body remains the responsible party under POPIA.<\/li>\n<\/ul>\n<h2 class=\"text-text-100 mt-3 -mb-1 text-&#091;1.125rem&#093; font-bold\">The eight POPIA conditions in gated environments<\/h2>\n<ol class=\"&#091;li_&amp;&#093;:mb-0 &#091;li_&amp;&#093;:mt-1 &#091;li_&amp;&#093;:gap-1 &#091;&amp;:not(:last-child)_ul&#093;:pb-1 &#091;&amp;:not(:last-child)_ol&#093;:pb-1 list-decimal flex flex-col gap-1 pl-8 mb-3\">\n<li class=\"font-claude-response-body whitespace-normal break-words pl-2\"><strong>Accountability<\/strong> \u2014 The estate remains responsible for all processing.<\/li>\n<li class=\"font-claude-response-body whitespace-normal break-words pl-2\"><strong>Processing limitation<\/strong> \u2014 Data must be lawful, reasonable, and minimal.<\/li>\n<li class=\"font-claude-response-body whitespace-normal break-words pl-2\"><strong>Purpose specification<\/strong> \u2014 Information must be collected for defined security purposes.<\/li>\n<li class=\"font-claude-response-body whitespace-normal break-words pl-2\"><strong>Further processing limitation<\/strong> \u2014 Data cannot be repurposed without a lawful basis.<\/li>\n<li class=\"font-claude-response-body whitespace-normal break-words pl-2\"><strong>Information quality<\/strong> \u2014 Records must be accurate and reliable.<\/li>\n<li class=\"font-claude-response-body whitespace-normal break-words pl-2\"><strong>Openness<\/strong> \u2014 Visitors and residents must understand how their data is used.<\/li>\n<li class=\"font-claude-response-body whitespace-normal break-words pl-2\"><strong>Security safeguards<\/strong> \u2014 Systems must prevent breaches and unauthorised access.<\/li>\n<li class=\"font-claude-response-body whitespace-normal break-words pl-2\"><strong>Data subject participation<\/strong> \u2014 Individuals retain rights over their information.<\/li>\n<\/ol>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-&#091;1.7&#093;\">The Code converts these from principles into operational obligations.<\/p>\n<h2 class=\"text-text-100 mt-3 -mb-1 text-&#091;1.125rem&#093; font-bold\">Enforcement is increasing<\/h2>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-&#091;1.7&#093;\">The Information Regulator has strengthened its complaint mechanisms, compliance assessments, and breach reporting processes.<\/p>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-&#091;1.7&#093;\">Non-compliance with POPIA may result in:<\/p>\n<ul class=\"&#091;li_&amp;&#093;:mb-0 &#091;li_&amp;&#093;:mt-1 &#091;li_&amp;&#093;:gap-1 &#091;&amp;:not(:last-child)_ul&#093;:pb-1 &#091;&amp;:not(:last-child)_ol&#093;:pb-1 list-disc flex flex-col gap-1 pl-8 mb-3\">\n<li class=\"font-claude-response-body whitespace-normal break-words pl-2\">Enforcement notices<\/li>\n<li class=\"font-claude-response-body whitespace-normal break-words pl-2\">Administrative fines of up to R10 million<\/li>\n<li class=\"font-claude-response-body whitespace-normal break-words pl-2\">Governance and reputational damage<\/li>\n<\/ul>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-&#091;1.7&#093;\">The informal era of gatehouse data processing is ending.<\/p>\n<h2 class=\"text-text-100 mt-3 -mb-1 text-&#091;1.125rem&#093; font-bold\">How to prepare<\/h2>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-&#091;1.7&#093;\">Organisations operating controlled-access environments should:<\/p>\n<ul class=\"&#091;li_&amp;&#093;:mb-0 &#091;li_&amp;&#093;:mt-1 &#091;li_&amp;&#093;:gap-1 &#091;&amp;:not(:last-child)_ul&#093;:pb-1 &#091;&amp;:not(:last-child)_ol&#093;:pb-1 list-disc flex flex-col gap-1 pl-8 mb-3\">\n<li class=\"font-claude-response-body whitespace-normal break-words pl-2\">Conduct a <a href=\"https:\/\/itlawco.com\/piias-under-popia\/\">personal information impact assessment (PIIA)<\/a><\/li>\n<li class=\"font-claude-response-body whitespace-normal break-words pl-2\">Audit gatehouse data collection and retention<\/li>\n<li class=\"font-claude-response-body whitespace-normal break-words pl-2\">Review biometric and surveillance legality<\/li>\n<li class=\"font-claude-response-body whitespace-normal break-words pl-2\">Strengthen vendor and operator governance<\/li>\n<li class=\"font-claude-response-body whitespace-normal break-words pl-2\">Improve transparency and privacy notices<\/li>\n<li class=\"font-claude-response-body whitespace-normal break-words pl-2\">Train security and operational staff<\/li>\n<li class=\"font-claude-response-body whitespace-normal break-words pl-2\">Ensure information officer compliance<\/li>\n<\/ul>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-&#091;1.7&#093;\">Acting now, while the Code is still a draft, gives organisations time to align before the final version is issued.<\/p>\n<h2 class=\"text-text-100 mt-3 -mb-1 text-&#091;1.125rem&#093; font-bold\">How ITLawCo assists gated and controlled-access environments<\/h2>\n<div class=\"overflow-x-auto w-full px-2 mb-6\">\n<table class=\"min-w-full border-collapse text-sm leading-&#091;1.7&#093; whitespace-normal\">\n<thead class=\"text-left\">\n<tr>\n<th class=\"text-text-100 border-b-0.5 border-border-300\/60 py-2 pr-4 align-top font-bold\" scope=\"col\">Service area<\/th>\n<th class=\"text-text-100 border-b-0.5 border-border-300\/60 py-2 pr-4 align-top font-bold\" scope=\"col\">How ITLawCo helps<\/th>\n<th class=\"text-text-100 border-b-0.5 border-border-300\/60 py-2 pr-4 align-top font-bold\" scope=\"col\">Outcome for your organisation<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td class=\"border-b-0.5 border-border-300\/30 py-2 pr-4 align-top\">POPIA compliance assessment<\/td>\n<td class=\"border-b-0.5 border-border-300\/30 py-2 pr-4 align-top\">Legal and operational review of gatehouse data processing and systems.<\/td>\n<td class=\"border-b-0.5 border-border-300\/30 py-2 pr-4 align-top\">Clear view of compliance exposure.<\/td>\n<\/tr>\n<tr>\n<td class=\"border-b-0.5 border-border-300\/30 py-2 pr-4 align-top\">Personal information impact assessment<\/td>\n<td class=\"border-b-0.5 border-border-300\/30 py-2 pr-4 align-top\">Risk and proportionality analysis of data processing.<\/td>\n<td class=\"border-b-0.5 border-border-300\/30 py-2 pr-4 align-top\">Defensible compliance position.<\/td>\n<\/tr>\n<tr>\n<td class=\"border-b-0.5 border-border-300\/30 py-2 pr-4 align-top\">Visitor and surveillance governance<\/td>\n<td class=\"border-b-0.5 border-border-300\/30 py-2 pr-4 align-top\">POPIA-aligned governance frameworks.<\/td>\n<td class=\"border-b-0.5 border-border-300\/30 py-2 pr-4 align-top\">Lawful, auditable data processing.<\/td>\n<\/tr>\n<tr>\n<td class=\"border-b-0.5 border-border-300\/30 py-2 pr-4 align-top\">Biometric compliance<\/td>\n<td class=\"border-b-0.5 border-border-300\/30 py-2 pr-4 align-top\">Legal review of biometric systems.<\/td>\n<td class=\"border-b-0.5 border-border-300\/30 py-2 pr-4 align-top\">Reduced high-risk exposure.<\/td>\n<\/tr>\n<tr>\n<td class=\"border-b-0.5 border-border-300\/30 py-2 pr-4 align-top\">Vendor and operator governance<\/td>\n<td class=\"border-b-0.5 border-border-300\/30 py-2 pr-4 align-top\">POPIA-aligned contracts and due diligence.<\/td>\n<td class=\"border-b-0.5 border-border-300\/30 py-2 pr-4 align-top\">Reduced third-party liability.<\/td>\n<\/tr>\n<tr>\n<td class=\"border-b-0.5 border-border-300\/30 py-2 pr-4 align-top\">Data lifecycle and retention<\/td>\n<td class=\"border-b-0.5 border-border-300\/30 py-2 pr-4 align-top\">Lawful retention and destruction model.<\/td>\n<td class=\"border-b-0.5 border-border-300\/30 py-2 pr-4 align-top\">Controlled data environment.<\/td>\n<\/tr>\n<tr>\n<td class=\"border-b-0.5 border-border-300\/30 py-2 pr-4 align-top\">Governance and information officer support<\/td>\n<td class=\"border-b-0.5 border-border-300\/30 py-2 pr-4 align-top\">Compliance framework and regulatory readiness.<\/td>\n<td class=\"border-b-0.5 border-border-300\/30 py-2 pr-4 align-top\">Strong governance posture.<\/td>\n<\/tr>\n<tr>\n<td class=\"border-b-0.5 border-border-300\/30 py-2 pr-4 align-top\">POPIA audit and enforcement readiness<\/td>\n<td class=\"border-b-0.5 border-border-300\/30 py-2 pr-4 align-top\">Preparation for investigations and complaints.<\/td>\n<td class=\"border-b-0.5 border-border-300\/30 py-2 pr-4 align-top\">Confidence under regulatory scrutiny.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<h2 class=\"text-text-100 mt-3 -mb-1 text-&#091;1.125rem&#093; font-bold\">Frequently asked questions<\/h2>\n<\/div>\n\n\n\n<div class=\"toggles \" data-br=\"none\" data-starting=\"default\" data-style=\"default\"><div class=\"toggle default\" data-inner-wrap=\"true\"><h3 class=\"toggle-title\"><a href=\"#\" id=\"toggle-button-6a60ed06c07d4\" role=\"button\" aria-expanded=\"false\" aria-controls=\"toggle-panel-6a60ed06c07d4\" class=\"toggle-heading\"><i role=\"presentation\" class=\"fa fa-plus\"><\/i>Does the code apply only to residential estates?<\/a><\/h3><div id=\"toggle-panel-6a60ed06c07d4\" role=\"region\" aria-labelledby=\"toggle-button-6a60ed06c07d4\"><div class=\"inner-toggle-wrap\">\n<div class=\"wpb_text_column wpb_content_element \" >\n\t<p>No. The draft applies broadly to controlled-access environments, including commercial, industrial, and institutional properties.<\/p>\n<\/div>\n\n\n\n<\/div><\/div><\/div><div class=\"toggle default\" data-inner-wrap=\"true\"><h3 class=\"toggle-title\"><a href=\"#\" id=\"toggle-button-6a60ed06c0cb6\" role=\"button\" aria-expanded=\"false\" aria-controls=\"toggle-panel-6a60ed06c0cb6\" class=\"toggle-heading\"><i role=\"presentation\" class=\"fa fa-plus\"><\/i>Is scanning driver\u2019s licences illegal under POPIA?<\/a><\/h3><div id=\"toggle-panel-6a60ed06c0cb6\" role=\"region\" aria-labelledby=\"toggle-button-6a60ed06c0cb6\"><div class=\"inner-toggle-wrap\">\n<div class=\"wpb_text_column wpb_content_element \" >\n\t<p data-start=\"6373\" data-end=\"6497\">Not in itself. The question is whether the data collected is relevant and not excessive for the security purpose, and whether it is stored and retained lawfully. Routine full-licence scanning, retained indefinitely, is hard to justify; a more limited, purpose-specific approach is more defensible.<\/p>\n<\/div>\n\n\n\n<\/div><\/div><\/div><div class=\"toggle default\" data-inner-wrap=\"true\"><h3 class=\"toggle-title\"><a href=\"#\" id=\"toggle-button-6a60ed06c1153\" role=\"button\" aria-expanded=\"false\" aria-controls=\"toggle-panel-6a60ed06c1153\" class=\"toggle-heading\"><i role=\"presentation\" class=\"fa fa-plus\"><\/i>Are biometric systems allowed?<\/a><\/h3><div id=\"toggle-panel-6a60ed06c1153\" role=\"region\" aria-labelledby=\"toggle-button-6a60ed06c1153\"><div class=\"inner-toggle-wrap\">\n<div class=\"wpb_text_column wpb_content_element \" >\n\t<p>Yes, but biometric data is special personal information under POPIA and attracts heightened safeguards. Lawfulness depends on necessity, proportionality, the availability of less intrusive alternatives, and\u2014critically\u2014where the biometric data is stored and who controls it.<\/p>\n<\/div>\n\n\n\n<\/div><\/div><\/div><div class=\"toggle default\" data-inner-wrap=\"true\"><h3 class=\"toggle-title\"><a href=\"#\" id=\"toggle-button-6a60ed06c15bb\" role=\"button\" aria-expanded=\"false\" aria-controls=\"toggle-panel-6a60ed06c15bb\" class=\"toggle-heading\"><i role=\"presentation\" class=\"fa fa-plus\"><\/i>Who is responsible: the estate or the security company?<\/a><\/h3><div id=\"toggle-panel-6a60ed06c15bb\" role=\"region\" aria-labelledby=\"toggle-button-6a60ed06c15bb\"><div class=\"inner-toggle-wrap\">\n<div class=\"wpb_text_column wpb_content_element \" >\n\t<p data-start=\"6700\" data-end=\"6810\">The estate or governing body. It remains the responsible party under POPIA. A security company or technology vendor typically acts as an operator, but outsourcing does not transfer accountability.<\/p>\n<\/div>\n\n\n\n<\/div><\/div><\/div><div class=\"toggle default\" data-inner-wrap=\"true\"><h3 class=\"toggle-title\"><a href=\"#\" id=\"toggle-button-6a60ed06c1a0a\" role=\"button\" aria-expanded=\"false\" aria-controls=\"toggle-panel-6a60ed06c1a0a\" class=\"toggle-heading\"><i role=\"presentation\" class=\"fa fa-plus\"><\/i>Is the Code in effect yet?<\/a><\/h3><div id=\"toggle-panel-6a60ed06c1a0a\" role=\"region\" aria-labelledby=\"toggle-button-6a60ed06c1a0a\"><div class=\"inner-toggle-wrap\">\n<div class=\"wpb_text_column wpb_content_element \" >\n\t<p>No. The draft was published for comment on 30 April 2026 (Government Gazette No. 54594). The comment period closed on 29 May 2026. The Regulator will consider comments before deciding whether to revise the draft and issue a final Code. There is no confirmed date for the final Code; organisations should prepare now rather than wait.<\/p>\n<\/div>\n\n\n\n<\/div><\/div><\/div><\/div>\n<div class=\"wpb_text_column wpb_content_element \" >\n\t<h2 data-start=\"6977\" data-end=\"6996\">The deeper shift<\/h2>\n<p data-start=\"6998\" data-end=\"7180\">Security environments are becoming data environments. Organisations that embed minimality, transparency, and governance early will reduce risk and build institutional resilience.<\/p>\n<h2 data-start=\"7187\" data-end=\"7204\">Contact ITLawCo<\/h2>\n<p data-start=\"7206\" data-end=\"7329\">If your organisation operates a gated or controlled-access environment, early alignment with the Code is critical. And the draft stage is the moment to get ahead of it.<\/p>\n<p data-start=\"7331\" data-end=\"7426\"><a href=\"https:\/\/itlawco.com\/contact-us\/\">Contact ITLawCo<\/a> to assess your exposure and prepare for the next phase of POPIA compliance.<\/p>\n<\/div>\n\n\n\n\n\t\t\t<\/div> \n\t\t<\/div>\n\t<\/div> \n<\/div><\/div>\n\t\t<div id=\"fws_6a60ed06c217f\"  data-column-margin=\"default\" data-midnight=\"dark\"  class=\"wpb_row vc_row-fluid vc_row\"  style=\"padding-top: 0px; padding-bottom: 0px; \"><div class=\"row-bg-wrap\" data-bg-animation=\"none\" data-bg-animation-delay=\"\" data-bg-overlay=\"false\"><div class=\"inner-wrap row-bg-layer\" ><div class=\"row-bg viewport-desktop\"  style=\"\"><\/div><\/div><\/div><div class=\"row_col_wrap_12 col span_12 dark left\">\n\t<div  class=\"vc_col-sm-12 wpb_column column_container vc_column_container col no-extra-padding inherit_tablet inherit_phone \"  data-padding-pos=\"all\" data-has-bg-color=\"false\" data-bg-color=\"\" data-bg-opacity=\"1\" data-animation=\"\" data-delay=\"0\" >\n\t\t<div class=\"vc_column-inner\" >\n\t\t\t<div class=\"wpb_wrapper\">\n\t\t\t\t\n\t<div class=\"wpb_raw_code wpb_raw_html wpb_content_element\" >\n\t\t<div class=\"wpb_wrapper\">\n\t\t\t<!-- Full Article JSON-LD GEO schema (Article + FAQPage + LegalService) -->\n<script type=\"application\/ld+json\">\n{\n  \"@context\": \"https:\/\/schema.org\",\n  \"@graph\": [\n    {\n      \"@type\": \"Organization\",\n      \"@id\": \"https:\/\/itlawco.com\/#organization\",\n      \"name\": \"ITLawCo\",\n      \"url\": \"https:\/\/itlawco.com\",\n      \"logo\": {\n        \"@type\": \"ImageObject\",\n        \"@id\": \"https:\/\/itlawco.com\/#logo\",\n        \"url\": \"https:\/\/itlawco.com\/images\/itlawco-logo.png\",\n        \"contentUrl\": \"https:\/\/itlawco.com\/images\/itlawco-logo.png\",\n        \"caption\": \"ITLawCo\"\n      },\n      \"sameAs\": [\n        \"https:\/\/www.linkedin.com\/company\/itlawco\/\"\n      ],\n      \"address\": {\n        \"@type\": \"PostalAddress\",\n        \"addressCountry\": \"ZA\"\n      }\n    },\n    {\n      \"@type\": \"Person\",\n      \"@id\": \"https:\/\/itlawco.com\/#nathan-ross-adams\",\n      \"name\": \"Nathan-Ross Adams\",\n      \"jobTitle\": \"Managing Director\",\n      \"worksFor\": {\n        \"@id\": \"https:\/\/itlawco.com\/#organization\"\n      },\n      \"url\": \"https:\/\/itlawco.com\"\n    },\n    {\n      \"@type\": \"WebSite\",\n      \"@id\": \"https:\/\/itlawco.com\/#website\",\n      \"url\": \"https:\/\/itlawco.com\",\n      \"name\": \"ITLawCo\",\n      \"publisher\": {\n        \"@id\": \"https:\/\/itlawco.com\/#organization\"\n      },\n      \"inLanguage\": \"en-ZA\"\n    },\n    {\n      \"@type\": \"WebPage\",\n      \"@id\": \"https:\/\/itlawco.com\/popia-code-of-conduct-gated-access-south-africa\/#webpage\",\n      \"url\": \"https:\/\/itlawco.com\/popia-code-of-conduct-gated-access-south-africa\/\",\n      \"name\": \"The POPIA Code of Conduct for Gated Access\",\n      \"isPartOf\": {\n        \"@id\": \"https:\/\/itlawco.com\/#website\"\n      },\n      \"about\": [\n        { \"@id\": \"https:\/\/itlawco.com\/#popia\" },\n        { \"@id\": \"https:\/\/itlawco.com\/#information-regulator\" }\n      ],\n      \"inLanguage\": \"en-ZA\",\n      \"primaryImageOfPage\": {\n        \"@id\": \"https:\/\/itlawco.com\/images\/popia-code-of-conduct-gated-access-security-gate-data-processing-south-africa-hero-image.jpg#image\"\n      }\n    },\n    {\n      \"@type\": \"ImageObject\",\n      \"@id\": \"https:\/\/itlawco.com\/images\/popia-code-of-conduct-gated-access-security-gate-data-processing-south-africa-hero-image.jpg#image\",\n      \"name\": \"POPIA Code of Conduct for Gated Access Security Gate Data Processing\",\n      \"caption\": \"Controlled access security environments are becoming regulated data processing systems under South Africa\u2019s POPIA Code of Conduct for Gated Access.\",\n      \"description\": \"Conceptual hero image illustrating a modern gated access security entrance with biometric authentication, surveillance, and a digital data overlay. The image represents the transition from physical security to regulated personal information processing under POPIA and the draft Code of Conduct for Gated Access in South Africa.\",\n      \"contentUrl\": \"https:\/\/itlawco.com\/images\/popia-code-of-conduct-gated-access-security-gate-data-processing-south-africa-hero-image.jpg\",\n      \"url\": \"https:\/\/itlawco.com\/images\/popia-code-of-conduct-gated-access-security-gate-data-processing-south-africa-hero-image.jpg\",\n      \"inLanguage\": \"en-ZA\",\n      \"keywords\": [\n        \"POPIA gated access\",\n        \"Gated community POPIA compliance\",\n        \"Security gate data processing\",\n        \"Biometric access POPIA South Africa\",\n        \"CCTV POPIA estates\",\n        \"Controlled access data governance\"\n      ],\n      \"copyrightHolder\": {\n        \"@id\": \"https:\/\/itlawco.com\/#organization\"\n      }\n    },\n    {\n      \"@type\": \"Article\",\n      \"@id\": \"https:\/\/itlawco.com\/popia-code-of-conduct-gated-access-south-africa\/#article\",\n      \"mainEntityOfPage\": {\n        \"@id\": \"https:\/\/itlawco.com\/popia-code-of-conduct-gated-access-south-africa\/#webpage\"\n      },\n      \"headline\": \"The POPIA Code of Conduct for Gated Access\",\n      \"alternativeHeadline\": \"Why security gates are becoming regulated data systems\",\n      \"description\": \"The Information Regulator published the draft POPIA Code of Conduct for Gated Access in Government Gazette No. 54594 on 30 April 2026. This article explains what the draft means for estates and controlled-access environments, where it now stands, the key compliance risks, the areas still being refined, and how to prepare.\",\n      \"image\": {\n        \"@id\": \"https:\/\/itlawco.com\/images\/popia-code-of-conduct-gated-access-security-gate-data-processing-south-africa-hero-image.jpg#image\"\n      },\n      \"author\": {\n        \"@id\": \"https:\/\/itlawco.com\/#nathan-ross-adams\"\n      },\n      \"publisher\": {\n        \"@id\": \"https:\/\/itlawco.com\/#organization\"\n      },\n      \"datePublished\": \"2026-02-12\",\n      \"dateModified\": \"2026-05-28\",\n      \"inLanguage\": \"en-ZA\",\n      \"articleSection\": [\n        \"POPIA\",\n        \"Data protection\",\n        \"Gated access\",\n        \"Security and surveillance governance\"\n      ],\n      \"keywords\": [\n        \"POPIA code of conduct for gated access South Africa\",\n        \"POPIA for estates South Africa\",\n        \"Gated community POPIA compliance\",\n        \"Visitor data POPIA estates\",\n        \"Biometric compliance South Africa estates\",\n        \"CCTV POPIA gated communities\"\n      ],\n      \"about\": [\n        {\n          \"@type\": \"Thing\",\n          \"@id\": \"https:\/\/itlawco.com\/#popia\",\n          \"name\": \"Protection of Personal Information Act (POPIA)\"\n        },\n        {\n          \"@type\": \"GovernmentOrganization\",\n          \"@id\": \"https:\/\/itlawco.com\/#information-regulator\",\n          \"name\": \"Information Regulator (South Africa)\"\n        },\n        {\n          \"@type\": \"Thing\",\n          \"name\": \"Code of conduct for gated access\"\n        }\n      ],\n      \"mentions\": [\n        {\n          \"@type\": \"Country\",\n          \"name\": \"South Africa\"\n        },\n        {\n          \"@type\": \"Legislation\",\n          \"name\": \"Protection of Personal Information Act 4 of 2013 (POPIA), section 60(1) and section 61(2)\"\n        },\n        {\n          \"@type\": \"CreativeWork\",\n          \"name\": \"Draft Own Initiative Code of Conduct on the Processing of Personal Information at Gated Accesses in South Africa\",\n          \"datePublished\": \"2026-04-30\",\n          \"publisher\": {\n            \"@id\": \"https:\/\/itlawco.com\/#information-regulator\"\n          },\n          \"isPartOf\": \"Government Gazette No. 54594, Government Notice No. 7415\"\n        }\n      ],\n      \"isAccessibleForFree\": true,\n      \"audience\": {\n        \"@type\": \"Audience\",\n        \"audienceType\": [\n          \"Homeowners\u2019 associations\",\n          \"Bodies corporate\",\n          \"Property managers\",\n          \"Security operators\",\n          \"Facilities managers\",\n          \"Estate trustees\"\n        ],\n        \"geographicArea\": {\n          \"@type\": \"Country\",\n          \"name\": \"South Africa\"\n        }\n      },\n      \"speakable\": {\n        \"@type\": \"SpeakableSpecification\",\n        \"xpath\": [\n          \"\/html\/head\/title\",\n          \"\/html\/body\/\/h1\",\n          \"\/html\/body\/\/h2[1]\",\n          \"\/html\/body\/\/p[1]\"\n        ]\n      }\n    },\n    {\n      \"@type\": \"FAQPage\",\n      \"@id\": \"https:\/\/itlawco.com\/popia-code-of-conduct-gated-access-south-africa\/#faq\",\n      \"mainEntity\": [\n        {\n          \"@type\": \"Question\",\n          \"name\": \"Does the Code apply only to residential estates?\",\n          \"acceptedAnswer\": {\n            \"@type\": \"Answer\",\n            \"text\": \"No. The draft applies broadly to controlled-access environments, including residential, commercial, industrial and institutional properties where personal information is processed for access control and security.\"\n          }\n        },\n        {\n          \"@type\": \"Question\",\n          \"name\": \"Is scanning driver\u2019s licences illegal under POPIA?\",\n          \"acceptedAnswer\": {\n            \"@type\": \"Answer\",\n            \"text\": \"Not in itself. Legality depends on whether the data collected is relevant and not excessive for the security purpose, and whether it is stored and retained lawfully. Routine full-licence scanning retained indefinitely is hard to justify; a more limited, purpose-specific approach is more defensible.\"\n          }\n        },\n        {\n          \"@type\": \"Question\",\n          \"name\": \"Are biometric systems allowed?\",\n          \"acceptedAnswer\": {\n            \"@type\": \"Answer\",\n            \"text\": \"Yes, but biometric data is special personal information under POPIA and attracts heightened safeguards. Lawfulness depends on necessity, proportionality, the availability of less intrusive alternatives, and\u2014critically\u2014where the biometric data is stored and who controls it. Some processing designs may require regulatory authorisation.\"\n          }\n        },\n        {\n          \"@type\": \"Question\",\n          \"name\": \"Who is responsible: the estate or the security company?\",\n          \"acceptedAnswer\": {\n            \"@type\": \"Answer\",\n            \"text\": \"The estate, HOA or governing body that determines the purpose and means of processing remains the responsible party under POPIA, even when security or visitor management is outsourced. The security company or technology vendor typically acts as an operator, but outsourcing does not transfer accountability.\"\n          }\n        },\n        {\n          \"@type\": \"Question\",\n          \"name\": \"Is the Code in effect yet?\",\n          \"acceptedAnswer\": {\n            \"@type\": \"Answer\",\n            \"text\": \"No. The draft was published for comment on 30 April 2026 in Government Gazette No. 54594. The comment period closed on 29 May 2026. The Information Regulator will consider stakeholder comments before deciding whether to revise the draft and issue a final Code. There is no confirmed date for the final Code, so organisations should prepare now rather than wait.\"\n          }\n        }\n      ]\n    },\n    {\n      \"@type\": \"LegalService\",\n      \"@id\": \"https:\/\/itlawco.com\/#legalservice-gated-access-popia\",\n      \"name\": \"POPIA compliance for gated and controlled-access environments\",\n      \"provider\": {\n        \"@id\": \"https:\/\/itlawco.com\/#organization\"\n      },\n      \"url\": \"https:\/\/itlawco.com\/services\/popia-gated-access\/\",\n      \"areaServed\": {\n        \"@type\": \"Country\",\n        \"name\": \"South Africa\"\n      },\n      \"serviceType\": [\n        \"POPIA compliance assessment\",\n        \"Personal information impact assessment (PIIA)\",\n        \"Biometric compliance advisory\",\n        \"Visitor management and surveillance governance\",\n        \"Vendor and operator agreements\",\n        \"Retention and data lifecycle design\",\n        \"Audit and enforcement readiness\"\n      ],\n      \"hasOfferCatalog\": {\n        \"@type\": \"OfferCatalog\",\n        \"name\": \"Gated access POPIA services\",\n        \"itemListElement\": [\n          {\n            \"@type\": \"Offer\",\n            \"name\": \"POPIA compliance assessment\",\n            \"description\": \"Legal and operational review of gatehouse processing, visitor systems, CCTV and access controls.\"\n          },\n          {\n            \"@type\": \"Offer\",\n            \"name\": \"Personal information impact assessment (PIIA)\",\n            \"description\": \"Evaluation of processing necessity, proportionality and risk in controlled-access environments.\"\n          },\n          {\n            \"@type\": \"Offer\",\n            \"name\": \"Biometric compliance\",\n            \"description\": \"Legal review of fingerprint and facial recognition processing and safeguard requirements.\"\n          },\n          {\n            \"@type\": \"Offer\",\n            \"name\": \"Vendor and operator governance\",\n            \"description\": \"POPIA-aligned contracts and due diligence for security and technology providers.\"\n          }\n        ]\n      }\n    }\n  ]\n}\n<\/script>\n\t\t<\/div>\n\t<\/div>\n\n\t\t\t<\/div> \n\t\t<\/div>\n\t<\/div> \n<\/div><\/div>\n","protected":false},"excerpt":{"rendered":"Why security gates are becoming regulated data systems Security gates used to control movement. Today, they control personal information. Every visitor log, licence scan, CCTV recording, biometric reader, and access...","protected":false},"author":1,"featured_media":3725,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"footnotes":""},"categories":[15],"tags":[],"class_list":["post-3724","post","type-post","status-publish","format-standard","has-post-thumbnail","category-data-protection-and-privacy"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>The POPIA Code of Conduct for Gated Access - ITLawCo<\/title>\n<meta name=\"description\" content=\"The Information Regulator\u2019s POPIA Code of Conduct for Gated Access will transform how estates and controlled-access environments process personal information. Learn the risks, legal duties, and how to prepare.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/itlawco.com\/fr\/popia-code-of-conduct-gated-access-south-africa\/\" \/>\n<meta property=\"og:locale\" content=\"fr_FR\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"The POPIA Code of Conduct for Gated Access - ITLawCo\" \/>\n<meta property=\"og:description\" content=\"The Information Regulator\u2019s POPIA Code of Conduct for Gated Access will transform how estates and controlled-access environments process personal information. Learn the risks, legal duties, and how to prepare.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/itlawco.com\/fr\/popia-code-of-conduct-gated-access-south-africa\/\" \/>\n<meta property=\"og:site_name\" content=\"ITLawCo\" \/>\n<meta property=\"article:published_time\" content=\"2026-05-29T09:00:21+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-05-29T09:10:23+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/itlawco.com\/wp-content\/uploads\/2026\/02\/popia-code-of-conduct-gated-access-security-gate-data-processing-south-africa-hero-image.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1536\" \/>\n\t<meta property=\"og:image:height\" content=\"1024\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Nathan-Ross Adams\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"\u00c9crit par\" \/>\n\t<meta name=\"twitter:data1\" content=\"Nathan-Ross Adams\" \/>\n\t<meta name=\"twitter:label2\" content=\"Dur\u00e9e de lecture estim\u00e9e\" \/>\n\t<meta name=\"twitter:data2\" content=\"8 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/itlawco.com\\\/popia-code-of-conduct-gated-access-south-africa\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/itlawco.com\\\/popia-code-of-conduct-gated-access-south-africa\\\/\"},\"author\":{\"name\":\"Nathan-Ross Adams\",\"@id\":\"https:\\\/\\\/itlawco.com\\\/#\\\/schema\\\/person\\\/180a104e03a6d73faeb2de9137a2a995\"},\"headline\":\"The POPIA Code of Conduct for Gated Access\",\"datePublished\":\"2026-05-29T09:00:21+00:00\",\"dateModified\":\"2026-05-29T09:10:23+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/itlawco.com\\\/popia-code-of-conduct-gated-access-south-africa\\\/\"},\"wordCount\":3298,\"publisher\":{\"@id\":\"https:\\\/\\\/itlawco.com\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/itlawco.com\\\/popia-code-of-conduct-gated-access-south-africa\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/itlawco.com\\\/wp-content\\\/uploads\\\/2026\\\/02\\\/popia-code-of-conduct-gated-access-security-gate-data-processing-south-africa-hero-image.jpg\",\"articleSection\":[\"Data protection and privacy\"],\"inLanguage\":\"fr-FR\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/itlawco.com\\\/popia-code-of-conduct-gated-access-south-africa\\\/\",\"url\":\"https:\\\/\\\/itlawco.com\\\/popia-code-of-conduct-gated-access-south-africa\\\/\",\"name\":\"The POPIA Code of Conduct for Gated Access - ITLawCo\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/itlawco.com\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/itlawco.com\\\/popia-code-of-conduct-gated-access-south-africa\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/itlawco.com\\\/popia-code-of-conduct-gated-access-south-africa\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/itlawco.com\\\/wp-content\\\/uploads\\\/2026\\\/02\\\/popia-code-of-conduct-gated-access-security-gate-data-processing-south-africa-hero-image.jpg\",\"datePublished\":\"2026-05-29T09:00:21+00:00\",\"dateModified\":\"2026-05-29T09:10:23+00:00\",\"description\":\"The Information Regulator\u2019s POPIA Code of Conduct for Gated Access will transform how estates and controlled-access environments process personal information. Learn the risks, legal duties, and how to prepare.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/itlawco.com\\\/popia-code-of-conduct-gated-access-south-africa\\\/#breadcrumb\"},\"inLanguage\":\"fr-FR\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/itlawco.com\\\/popia-code-of-conduct-gated-access-south-africa\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"fr-FR\",\"@id\":\"https:\\\/\\\/itlawco.com\\\/popia-code-of-conduct-gated-access-south-africa\\\/#primaryimage\",\"url\":\"https:\\\/\\\/itlawco.com\\\/wp-content\\\/uploads\\\/2026\\\/02\\\/popia-code-of-conduct-gated-access-security-gate-data-processing-south-africa-hero-image.jpg\",\"contentUrl\":\"https:\\\/\\\/itlawco.com\\\/wp-content\\\/uploads\\\/2026\\\/02\\\/popia-code-of-conduct-gated-access-security-gate-data-processing-south-africa-hero-image.jpg\",\"width\":1536,\"height\":1024,\"caption\":\"Controlled access security environments are becoming regulated data processing systems under South Africa\u2019s POPIA Code of Conduct for Gated Access.\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/itlawco.com\\\/popia-code-of-conduct-gated-access-south-africa\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/itlawco.com\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"The POPIA Code of Conduct for Gated Access\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/itlawco.com\\\/#website\",\"url\":\"https:\\\/\\\/itlawco.com\\\/\",\"name\":\"ITLawCo\",\"description\":\"Fast, fearless legal\",\"publisher\":{\"@id\":\"https:\\\/\\\/itlawco.com\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/itlawco.com\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"fr-FR\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/itlawco.com\\\/#organization\",\"name\":\"ITLawCo\",\"url\":\"https:\\\/\\\/itlawco.com\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"fr-FR\",\"@id\":\"https:\\\/\\\/itlawco.com\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/itlawco.com\\\/wp-content\\\/uploads\\\/2024\\\/06\\\/Logo-prsm@4x.png\",\"contentUrl\":\"https:\\\/\\\/itlawco.com\\\/wp-content\\\/uploads\\\/2024\\\/06\\\/Logo-prsm@4x.png\",\"width\":2854,\"height\":2883,\"caption\":\"ITLawCo\"},\"image\":{\"@id\":\"https:\\\/\\\/itlawco.com\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.linkedin.com\\\/company\\\/itlawco\\\/\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/itlawco.com\\\/#\\\/schema\\\/person\\\/180a104e03a6d73faeb2de9137a2a995\",\"name\":\"Nathan-Ross Adams\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"fr-FR\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/25dc8945a16b2092572617ca3935624f6c0c2b8e7f90f89e9dd3ce6611085fcb?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/25dc8945a16b2092572617ca3935624f6c0c2b8e7f90f89e9dd3ce6611085fcb?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/25dc8945a16b2092572617ca3935624f6c0c2b8e7f90f89e9dd3ce6611085fcb?s=96&d=mm&r=g\",\"caption\":\"Nathan-Ross Adams\"},\"sameAs\":[\"https:\\\/\\\/itlawco.com\",\"https:\\\/\\\/www.linkedin.com\\\/in\\\/nathan-ross-adams-a5760b9a\\\/\"],\"url\":\"https:\\\/\\\/itlawco.com\\\/fr\\\/author\\\/itadmin\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"The POPIA Code of Conduct for Gated Access - ITLawCo","description":"The Information Regulator\u2019s POPIA Code of Conduct for Gated Access will transform how estates and controlled-access environments process personal information. Learn the risks, legal duties, and how to prepare.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/itlawco.com\/fr\/popia-code-of-conduct-gated-access-south-africa\/","og_locale":"fr_FR","og_type":"article","og_title":"The POPIA Code of Conduct for Gated Access - ITLawCo","og_description":"The Information Regulator\u2019s POPIA Code of Conduct for Gated Access will transform how estates and controlled-access environments process personal information. Learn the risks, legal duties, and how to prepare.","og_url":"https:\/\/itlawco.com\/fr\/popia-code-of-conduct-gated-access-south-africa\/","og_site_name":"ITLawCo","article_published_time":"2026-05-29T09:00:21+00:00","article_modified_time":"2026-05-29T09:10:23+00:00","og_image":[{"width":1536,"height":1024,"url":"https:\/\/itlawco.com\/wp-content\/uploads\/2026\/02\/popia-code-of-conduct-gated-access-security-gate-data-processing-south-africa-hero-image.jpg","type":"image\/jpeg"}],"author":"Nathan-Ross Adams","twitter_card":"summary_large_image","twitter_misc":{"\u00c9crit par":"Nathan-Ross Adams","Dur\u00e9e de lecture estim\u00e9e":"8 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/itlawco.com\/popia-code-of-conduct-gated-access-south-africa\/#article","isPartOf":{"@id":"https:\/\/itlawco.com\/popia-code-of-conduct-gated-access-south-africa\/"},"author":{"name":"Nathan-Ross Adams","@id":"https:\/\/itlawco.com\/#\/schema\/person\/180a104e03a6d73faeb2de9137a2a995"},"headline":"The POPIA Code of Conduct for Gated Access","datePublished":"2026-05-29T09:00:21+00:00","dateModified":"2026-05-29T09:10:23+00:00","mainEntityOfPage":{"@id":"https:\/\/itlawco.com\/popia-code-of-conduct-gated-access-south-africa\/"},"wordCount":3298,"publisher":{"@id":"https:\/\/itlawco.com\/#organization"},"image":{"@id":"https:\/\/itlawco.com\/popia-code-of-conduct-gated-access-south-africa\/#primaryimage"},"thumbnailUrl":"https:\/\/itlawco.com\/wp-content\/uploads\/2026\/02\/popia-code-of-conduct-gated-access-security-gate-data-processing-south-africa-hero-image.jpg","articleSection":["Data protection and privacy"],"inLanguage":"fr-FR"},{"@type":"WebPage","@id":"https:\/\/itlawco.com\/popia-code-of-conduct-gated-access-south-africa\/","url":"https:\/\/itlawco.com\/popia-code-of-conduct-gated-access-south-africa\/","name":"The POPIA Code of Conduct for Gated Access - ITLawCo","isPartOf":{"@id":"https:\/\/itlawco.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/itlawco.com\/popia-code-of-conduct-gated-access-south-africa\/#primaryimage"},"image":{"@id":"https:\/\/itlawco.com\/popia-code-of-conduct-gated-access-south-africa\/#primaryimage"},"thumbnailUrl":"https:\/\/itlawco.com\/wp-content\/uploads\/2026\/02\/popia-code-of-conduct-gated-access-security-gate-data-processing-south-africa-hero-image.jpg","datePublished":"2026-05-29T09:00:21+00:00","dateModified":"2026-05-29T09:10:23+00:00","description":"The Information Regulator\u2019s POPIA Code of Conduct for Gated Access will transform how estates and controlled-access environments process personal information. Learn the risks, legal duties, and how to prepare.","breadcrumb":{"@id":"https:\/\/itlawco.com\/popia-code-of-conduct-gated-access-south-africa\/#breadcrumb"},"inLanguage":"fr-FR","potentialAction":[{"@type":"ReadAction","target":["https:\/\/itlawco.com\/popia-code-of-conduct-gated-access-south-africa\/"]}]},{"@type":"ImageObject","inLanguage":"fr-FR","@id":"https:\/\/itlawco.com\/popia-code-of-conduct-gated-access-south-africa\/#primaryimage","url":"https:\/\/itlawco.com\/wp-content\/uploads\/2026\/02\/popia-code-of-conduct-gated-access-security-gate-data-processing-south-africa-hero-image.jpg","contentUrl":"https:\/\/itlawco.com\/wp-content\/uploads\/2026\/02\/popia-code-of-conduct-gated-access-security-gate-data-processing-south-africa-hero-image.jpg","width":1536,"height":1024,"caption":"Controlled access security environments are becoming regulated data processing systems under South Africa\u2019s POPIA Code of Conduct for Gated Access."},{"@type":"BreadcrumbList","@id":"https:\/\/itlawco.com\/popia-code-of-conduct-gated-access-south-africa\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/itlawco.com\/"},{"@type":"ListItem","position":2,"name":"The POPIA Code of Conduct for Gated Access"}]},{"@type":"WebSite","@id":"https:\/\/itlawco.com\/#website","url":"https:\/\/itlawco.com\/","name":"ITLawCo","description":"Rapide, sans peur, juridique","publisher":{"@id":"https:\/\/itlawco.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/itlawco.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"fr-FR"},{"@type":"Organization","@id":"https:\/\/itlawco.com\/#organization","name":"ITLawCo","url":"https:\/\/itlawco.com\/","logo":{"@type":"ImageObject","inLanguage":"fr-FR","@id":"https:\/\/itlawco.com\/#\/schema\/logo\/image\/","url":"https:\/\/itlawco.com\/wp-content\/uploads\/2024\/06\/Logo-prsm@4x.png","contentUrl":"https:\/\/itlawco.com\/wp-content\/uploads\/2024\/06\/Logo-prsm@4x.png","width":2854,"height":2883,"caption":"ITLawCo"},"image":{"@id":"https:\/\/itlawco.com\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.linkedin.com\/company\/itlawco\/"]},{"@type":"Person","@id":"https:\/\/itlawco.com\/#\/schema\/person\/180a104e03a6d73faeb2de9137a2a995","name":"Nathan-Ross Adams","image":{"@type":"ImageObject","inLanguage":"fr-FR","@id":"https:\/\/secure.gravatar.com\/avatar\/25dc8945a16b2092572617ca3935624f6c0c2b8e7f90f89e9dd3ce6611085fcb?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/25dc8945a16b2092572617ca3935624f6c0c2b8e7f90f89e9dd3ce6611085fcb?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/25dc8945a16b2092572617ca3935624f6c0c2b8e7f90f89e9dd3ce6611085fcb?s=96&d=mm&r=g","caption":"Nathan-Ross Adams"},"sameAs":["https:\/\/itlawco.com","https:\/\/www.linkedin.com\/in\/nathan-ross-adams-a5760b9a\/"],"url":"https:\/\/itlawco.com\/fr\/author\/itadmin\/"}]}},"_links":{"self":[{"href":"https:\/\/itlawco.com\/fr\/wp-json\/wp\/v2\/posts\/3724","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/itlawco.com\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/itlawco.com\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/itlawco.com\/fr\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/itlawco.com\/fr\/wp-json\/wp\/v2\/comments?post=3724"}],"version-history":[{"count":5,"href":"https:\/\/itlawco.com\/fr\/wp-json\/wp\/v2\/posts\/3724\/revisions"}],"predecessor-version":[{"id":3728,"href":"https:\/\/itlawco.com\/fr\/wp-json\/wp\/v2\/posts\/3724\/revisions\/3728"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/itlawco.com\/fr\/wp-json\/wp\/v2\/media\/3725"}],"wp:attachment":[{"href":"https:\/\/itlawco.com\/fr\/wp-json\/wp\/v2\/media?parent=3724"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/itlawco.com\/fr\/wp-json\/wp\/v2\/categories?post=3724"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/itlawco.com\/fr\/wp-json\/wp\/v2\/tags?post=3724"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}