Why security gates are becoming regulated data systems
Security gates used to control movement. Today, they control personal information.
Every visitor log, licence scan, CCTV recording, biometric reader, and access tag is a form of regulated data processing. The Information Regulator’s draft Code of Conduct for Gated Access—published for comment on 30 April 2026—formalises a major shift: gated environments are no longer just security systems; they are regulated data systems.
This article explains what the draft Code means, who it affects, the legal risks, how it now stands, and how estates and controlled-access environments should prepare.
Where the draft Code stands now
On 30 April 2026, the Information Regulator published the draft Own Initiative Code of Conduct on the Processing of Personal Information at Gated Accesses in South Africa in Government Gazette No. 54594 (Government Notice No. 7415). It was issued on the Regulator’s own initiative under section 60(1) of POPIA, with the comment notice given under section 61(2).
The draft is 65 pages. The comment period—initially fourteen days, later extended—closed on 29 May 2026. The draft is now with the Regulator, which will consider stakeholder comments before deciding whether to revise the draft and, in due course, issue a final Code.
An important distinction: the Code has been published as a draft. It is not yet binding. A Code of Conduct issued under section 60 of POPIA becomes binding and enforceable once it is finalised and issued, but this version is a consultation draft, and its content may change before then.
ITLawCo filed comments on the draft. Our submission supports the Regulator’s underlying objective (there are real privacy harms at access points, and they are worth addressing) while identifying areas where the draft needs refinement before it is issued. We summarise the three that matter most to controlled-access operators below.
What is the POPIA Code of Conduct for Gated Access?
The Code is a sector-specific regulatory instrument under section 60 of POPIA. It translates the Act’s general principles into operational rules for environments where access is controlled, including:
- Residential estates and sectional title schemes
- HOAs and bodies corporate
- Office parks and commercial complexes
- Industrial and controlled-access facilities
Once finalised and issued, the Code will be binding and enforceable, not guidance. Until then, it is a draft that signals the Regulator’s direction of travel.
Why the Information Regulator introduced this Code
The Regulator has identified systemic patterns across gated environments:
- Excessive visitor data collection
- Weak surveillance governance
- Unlawful or unclear biometric processing
- Poor transparency to residents and visitors
- Heavy reliance on third-party security operators
The Code aims to standardise how POPIA’s lawful processing conditions apply in real-world gatehouse environments.
The gatehouse as a regulated data processing environment
Under POPIA, “processing” includes the collection, recording, storage, use, and deletion of personal information. This means everyday gatehouse activity is regulated:
- Logging visitors
- Scanning driver’s licences or IDs
- Recording vehicle information
- Operating CCTV and surveillance
- Managing biometric or tag-based access
What was once informal security practice is now legally accountable data governance.
Three areas the draft still needs to get right
Our submission addresses several dozen points. Three are worth flagging for any organisation that operates a controlled-access environment, because they shape how workable the final Code will be.
- Lawful basis beyond consent. The draft leans heavily on consent as the route to lawful processing. But consent given at a gate, where the practical choice is to comply or be turned away, is rarely the freely given consent POPIA contemplates. POPIA offers six grounds for lawful processing, not one. The final Code should make clear how the other lawful bases (contract, legal obligation, public-law duty, legitimate interest) apply in different settings, rather than defaulting to consent.
- One size does not fit every gate. The draft applies in largely identical terms across very different environments: residential estates, hotels, hospitals, schools, office parks, government buildings, and critical infrastructure. Each of these already sits under its own statutory regime (immigration law, labour law, community-scheme law, education law, and others). A hotel is legally required to keep a guest register; a workplace’s monitoring is governed by labour law; a body corporate operates under registered conduct rules. The final Code will work better as a two-layer instrument: common rules that apply at every gate, plus sector-specific calibration for the settings that differ.
- Where biometric data lives. Biometric information is special personal information under POPIA and carries elevated risk: a fingerprint or face, unlike a password, cannot be reset if it leaks. The single most consequential omission in the draft is a clear rule on where biometric templates are stored and who holds the key. International regulators have converged on the principle that the least intrusive architecture—template held on a device the data subject controls, or encrypted with a key the data subject holds—should be the default. The final Code should say so.
These are constructive points. None is fatal to the Code; all are addressable in the next draft.
The biggest compliance risks for estates and controlled-access environments
- Visitor data and minimality. POPIA requires that personal information be relevant, adequate, and not excessive. Many estates collect more data than security requires, particularly through full licence or ID scanning.
- Surveillance and proportionality. CCTV must serve a legitimate purpose, be proportionate, and be supported by transparency (signage and notices). Retention must be justified and limited. South African courts are increasingly applying this proportionality requirement to private surveillance.
- Biometric processing. Biometric data is special personal information under POPIA and carries elevated legal risk. Lawful justification, safeguards, and in some cases regulatory authorisation are required.
- Vendor and operator liability. Outsourcing does not transfer responsibility. The estate or governing body remains the responsible party under POPIA.
The eight POPIA conditions in gated environments
- Accountability — The estate remains responsible for all processing.
- Processing limitation — Data must be lawful, reasonable, and minimal.
- Purpose specification — Information must be collected for defined security purposes.
- Further processing limitation — Data cannot be repurposed without a lawful basis.
- Information quality — Records must be accurate and reliable.
- Openness — Visitors and residents must understand how their data is used.
- Security safeguards — Systems must prevent breaches and unauthorised access.
- Data subject participation — Individuals retain rights over their information.
The Code converts these from principles into operational obligations.
Enforcement is increasing
The Information Regulator has strengthened its complaint mechanisms, compliance assessments, and breach reporting processes.
Non-compliance with POPIA may result in:
- Enforcement notices
- Administrative fines of up to R10 million
- Governance and reputational damage
The informal era of gatehouse data processing is ending.
How to prepare
Organisations operating controlled-access environments should:
- Conduct a personal information impact assessment (PIIA)
- Audit gatehouse data collection and retention
- Review biometric and surveillance legality
- Strengthen vendor and operator governance
- Improve transparency and privacy notices
- Train security and operational staff
- Ensure information officer compliance
Acting now, while the Code is still a draft, gives organisations time to align before the final version is issued.
How ITLawCo assists gated and controlled-access environments
| Service area | How ITLawCo helps | Outcome for your organisation |
|---|---|---|
| POPIA compliance assessment | Legal and operational review of gatehouse data processing and systems. | Clear view of compliance exposure. |
| Personal information impact assessment | Risk and proportionality analysis of data processing. | Defensible compliance position. |
| Visitor and surveillance governance | POPIA-aligned governance frameworks. | Lawful, auditable data processing. |
| Biometric compliance | Legal review of biometric systems. | Reduced high-risk exposure. |
| Vendor and operator governance | POPIA-aligned contracts and due diligence. | Reduced third-party liability. |
| Data lifecycle and retention | Lawful retention and destruction model. | Controlled data environment. |
| Governance and information officer support | Compliance framework and regulatory readiness. | Strong governance posture. |
| POPIA audit and enforcement readiness | Preparation for investigations and complaints. | Confidence under regulatory scrutiny. |
Frequently asked questions
Does the code apply only to residential estates?
No. The draft applies broadly to controlled-access environments, including commercial, industrial, and institutional properties.
Is scanning driver’s licences illegal under POPIA?
Not in itself. The question is whether the data collected is relevant and not excessive for the security purpose, and whether it is stored and retained lawfully. Routine full-licence scanning, retained indefinitely, is hard to justify; a more limited, purpose-specific approach is more defensible.
Are biometric systems allowed?
Yes, but biometric data is special personal information under POPIA and attracts heightened safeguards. Lawfulness depends on necessity, proportionality, the availability of less intrusive alternatives, and—critically—where the biometric data is stored and who controls it.
Who is responsible: the estate or the security company?
The estate or governing body. It remains the responsible party under POPIA. A security company or technology vendor typically acts as an operator, but outsourcing does not transfer accountability.
Is the Code in effect yet?
No. The draft was published for comment on 30 April 2026 (Government Gazette No. 54594). The comment period closed on 29 May 2026. The Regulator will consider comments before deciding whether to revise the draft and issue a final Code. There is no confirmed date for the final Code; organisations should prepare now rather than wait.
The deeper shift
Security environments are becoming data environments. Organisations that embed minimality, transparency, and governance early will reduce risk and build institutional resilience.
Contact ITLawCo
If your organisation operates a gated or controlled-access environment, early alignment with the Code is critical. And the draft stage is the moment to get ahead of it.
Contact ITLawCo to assess your exposure and prepare for the next phase of POPIA compliance.




