Practical requirements under POPIA and the emerging Gated Access Code of Conduct
Gated communities, residential estates, sectional title schemes, homeowners' associations (HOAs), and similar controlled-access environments in South Africa increasingly rely on artificial intelligence (AI) as part of their security and access-control systems. These tools range from facial recognition and licence-plate recognition (LPR) to behavioural analytics, automated visitor verification, predictive risk flagging, and AI-enhanced CCTV. While such technologies can improve efficiency and safety, they process personal information and therefore fall squarely under the Protection of Personal Information Act 4 of 2013 (POPIA).
The Information Regulator has reinforced this reality through its draft Own Initiative Code of Conduct on the Processing of Personal Information at Gated Accesses (gazetted for comment in April/May 2026). The Code, still progressing toward finalisation as of mid-2026, aims to give practical effect to POPIA's eight conditions for lawful processing in gated environments and specifically addresses high-risk technologies such as biometrics and CCTV. Once finalised and in force, compliance with the Code will become the primary sector-specific standard; non-compliance will constitute an interference with the protection of personal information.
Below is a practical overview of what POPIA (and the emerging Code) require when AI forms part of gated-community control systems.
The body corporate, HOA, trustees, or property owner is typically the responsible party - the entity that determines the purpose and means of processing. Security companies, technology vendors, and managing agents that process data on their behalf are operators. POPIA requires a written operator agreement that imposes appropriate security safeguards and instructions. The responsible party remains accountable even when AI systems are outsourced.
An Information Officer (and any Deputy Information Officers) must be designated and registered with the Information Regulator. This person oversees compliance, including AI-related processing.
All processing of personal information through AI systems must rest on a lawful basis under section 11 of POPIA (consent, legitimate interests, contractual necessity, legal obligation, etc.). Security is commonly framed as a legitimate interest, but this must be balanced against data subjects' rights and documented.
The purpose must be specific, explicitly defined, and lawful - typically limited to access control, safety, and security. AI systems that repurpose data collected at the gate for secondary uses (marketing, profiling beyond security, sharing with third parties, or linking across unrelated databases) will breach purpose limitation unless a new lawful basis and, where applicable, further processing justifications are established.
POPIA's processing limitation condition requires that personal information be adequate, relevant, and not excessive. The draft Gated Access Code strongly emphasises this. Collecting multiple categories of data (full name + ID number + driver's licence + vehicle registration + photograph + biometrics + contact details) solely for routine access control is frequently flagged as excessive when less intrusive alternatives exist (temporary visitor permits, access codes, resident confirmation, or simple name verification against an ID without recording full details).
AI systems that ingest or generate rich multi-modal datasets must be designed and configured for necessity. Over-collection "just in case" is not compliant.
Biometric data (fingerprints, facial images, iris scans, etc.) and health-related inferences are special personal information. Processing is generally prohibited unless an exception under sections 26-33 applies (explicit consent, or specific authorisations such as for security purposes with appropriate safeguards). Facial recognition systems used for positive identification have been highlighted by the Regulator as particularly intrusive.
AI systems relying on biometrics require heightened justification, technical and organisational safeguards, and careful assessment of necessity and proportionality.
Section 71 restricts decisions that produce legal consequences or substantially affect a data subject when based solely on the automated processing of personal information intended to profile the person (including reliability, location, conduct, or preferences).
Automated access decisions (denying entry based on AI analysis of biometrics, LPR, behavioural patterns, or risk scores) can engage this provision. Where the exception for contractual or legitimate-interest measures applies, the responsible party must:
Purely "black-box" AI decisions without human oversight or explainability risk non-compliance. Basic biometric template matching is sometimes treated broadly in the draft Code as automated decision-making; estates should ensure human review pathways exist for contested or significant outcomes.
Section 57 requires prior authorisation from the Information Regulator for certain high-risk processing, including the use of unique identifiers for purposes other than those for which they were collected and with the aim of linking information across responsible parties, processing criminal or objectionable conduct data on behalf of third parties, credit reporting, or certain cross-border transfers of special or children's information.
Once the Gated Access Code is finalised and in force, section 57(3) generally disapplies the prior-authorisation requirement for processing that falls within the Code's scope and complies with it. Processing that goes beyond the Code's authorised practices (for example, extensive data linking or secondary uses) may still require prior authorisation. Until the Code is binding, responsible parties should carefully assess whether their AI systems trigger section 57 and apply where necessary.
Data subjects (residents, visitors, contractors) must be informed about the processing - including the use of AI, purposes, retention periods, and their rights - through clear notices at access points and privacy policies. Implied consent from signing a visitor register is insufficient.
Personal information impact assessments (or equivalent risk assessments) are expected for high-risk AI and biometric systems. These should document the nature of processing, risks to data subjects, and mitigating measures.
Data subjects retain rights of access, correction, deletion (where applicable), objection, and complaint to the Information Regulator. AI systems must be designed to support the exercise of these rights.
Appropriate technical and organisational measures must protect against unauthorised access, loss, or destruction. Digital visitor management and AI systems should encrypt data. CCTV and access logs generally require short retention periods (the draft Code contemplates ranges such as 7-30 days for routine CCTV footage on an overwrite cycle, with longer holds only for incidents or justified risk). Indefinite storage is not permitted.
Breach of POPIA can result in administrative fines (up to R10 million), enforcement notices, civil claims for damages, and, in serious cases, criminal liability. Reputational harm and loss of resident trust are additional consequences. The Regulator has already received complaints about intrusive gated-access practices, including facial recognition and excessive data collection, making this sector a focus area.
AI can enhance security in gated communities, but it does not operate outside POPIA. Responsible parties must treat AI-enabled access and surveillance systems as personal-information processing activities subject to the full suite of POPIA conditions, with particular attention to minimality, special personal information rules, automated decision-making safeguards, and the emerging Gated Access Code of Conduct. Proactive governance - rather than reactive compliance - is the most effective way to balance legitimate security needs with the privacy rights of residents and visitors.
Back to Insights