IO Responsibilities
“Just scanning your license and taking your photo, sir…”
What information you can collect at the gate under the Protection of Personal Information Act (POPIA) and the draft Code of Conduct comes down to a strict legal test rather than a fixed “shopping list.”
What does the actual POPI Act say?
Section 10 of POPIA does not give you a list of what you can collect, which would be nice and simple. It sets a test instead: personal information must be adequate, relevant and not excessive, given the purpose for which it is processed.

What the draft Code of Conduct adds
The draft Code of Conduct sets out how the Regulator proposes to apply that standard at gated access points. It remains in draft and the comment period has closed, so the final wording may still change. It asks estates to record why each type of information is collected, and to keep the outcome of the proportionality assessment with their risk records. That assessment has three parts
The Three-Part Proportionality Test
For any of the data categories above, the estate’s collection method and fields must pass three checks:
- Is it necessary? It must be strictly essential for the security purpose.
- Is it likely to be effective? It must actively and successfully meet the identified security need
- Does the benefit outweigh the loss of privacy? If the benefit is minor or based purely on administrative convenience, the intrusion on privacy is deemed inappropriate.
Where an assessment is required:

More than one unique identifier
Capturing both an ID number and a driver’s license for a single person.

Special personal information
Biometrics, health information, or criminal records.

Children’s information
Any personal information relating to anyone under 18.

Vehicle details
Registration numbers, car color, and car make.
Wherever one of these is being collected, an assessment is required. Is it necessary? Is it likely to be effective? Does the benefit outweigh the loss of privacy? The assessment is specific to your premises, and should be revisited when access patterns, technology or threats change.
Four questions worth putting on an agenda.
To ensure compliance, estate management and boards should address these four operational questions:
- What is collected at the gate, by category of person, and what is the documented purpose of each field?
- Where more than one unique identifier is collected, has a proportionality assessment been conducted and recorded?
- Where a field cannot be tied to a documented access purpose, on what basis is it being retained?
- When was the current collection practice last reviewed against the estate’s own risk profile?






