IO Responsibilities

Just scanning your license and taking your photo, sir…”

What information you can collect at the gate under the Protection of Personal Information Act (POPIA) and the draft Code of Conduct comes down to a strict legal test rather than a fixed “shopping list.”

POPIA — Need an Information Officer?

What does the actual POPI Act say?

Section 10 of POPIA does not give you a list of what you can collect, which would be nice and simple. It sets a test instead: personal information must be adequate, relevant and not excessive, given the purpose for which it is processed.

What the draft Code of Conduct adds

The draft Code of Conduct sets out how the Regulator proposes to apply that standard at gated access points. It remains in draft and the comment period has closed, so the final wording may still change. It asks estates to record why each type of information is collected, and to keep the outcome of the proportionality assessment with their risk records. That assessment has three parts

The Three-Part Proportionality Test

For any of the data categories above, the estate’s collection method and fields must pass three checks:

  • Is it necessary? It must be strictly essential for the security purpose.
  • Is it likely to be effective? It must actively and successfully meet the identified security need
  • Does the benefit outweigh the loss of privacy? If the benefit is minor or based purely on administrative convenience, the intrusion on privacy is deemed inappropriate.

Where an assessment is required:

More than one unique identifier

Capturing both an ID number and a driver’s license for a single person.

Special personal information

Biometrics, health information, or criminal records.

Children’s information

Any personal information relating to anyone under 18.

Vehicle details

Registration numbers, car color, and car make.

Wherever one of these is being collected, an assessment is required. Is it necessary? Is it likely to be effective? Does the benefit outweigh the loss of privacy? The assessment is specific to your premises, and should be revisited when access patterns, technology or threats change.

Has your estate assessed and documented its purpose for collecting all its personal information, and substantiated why?

There is no single right answer, every property is different, and working through this is going to be “fun” for every estate. But the draft Code of Conduct sets a demanding standard, and if it is published in anything like its current form, this substantiating documentation will be required

Four questions worth putting on an agenda.

To ensure compliance, estate management and boards should address these four operational questions:

  • What is collected at the gate, by category of person, and what is the documented purpose of each field?
  • Where more than one unique identifier is collected, has a proportionality assessment been conducted and recorded?
  • Where a field cannot be tied to a documented access purpose, on what basis is it being retained?
  • When was the current collection practice last reviewed against the estate’s own risk profile?

Important Documents