If your estate still scans driver’s licences at the gate, 2026 is the year that practice comes under real scrutiny. On 30 April 2026, South Africa’s Information Regulator gazetted an own-initiative Code of Conduct on Processing Personal Information at Gated Accesses — a sector-specific application of POPIA aimed squarely at residential estates, homeowners’ associations, commercial parks and any property with a controlled entry point.

What changed

POPIA itself has applied since 2021, but enforcement at gates was patchy and the rules generic. The new code makes them concrete. The heart of it is minimality: an estate may collect only what is strictly necessary for the stated security purpose — and the code takes the position that demanding a full name, contact number, vehicle registration, identity number and a photograph or biometric for a single visit is too much.

The driver’s-licence barcode scan, the fixture of South African gate security for a decade, is the clearest casualty. That barcode doesn’t just carry a name — it exposes the full identity number, licence codes and restrictions, and vehicle authorisation data. Scanning it for a pizza delivery is exactly the kind of over-collection the code was written to end.

What the code requires

Reporting on the code highlights four obligations for anyone running a gated access:

  • Collect the minimum. Identify the visitor to the degree the security purpose actually requires — verified name-level identification rather than harvesting full licence data.
  • Store it properly. Whatever is collected must sit in encrypted, access-controlled storage — not a paper visitor book anyone at the gate can page through, and not a spreadsheet on the guard-house PC.
  • Delete it on schedule. Retention must be defined and defensible; for CCTV footage the code points to windows in the range of 7–30 days, not indefinite archives.
  • Be transparent. Visitors and residents must know what is collected, why, and by which surveillance technologies — with consent handled properly where it’s required.

Enforcement is not theoretical. The Information Regulator has been conducting own-initiative assessments, naming non-compliant operators publicly, and can impose administrative fines of up to R10 million, with civil liability under POPIA on top of that. For a body corporate, that is not a risk to leave with the incumbent gate-book process.

What estates should do now

  1. Audit what your gate collects today. Every field on the visitor slip, every scan, every camera. If you can’t tie a field to a specific security purpose, it goes.
  2. Retire the licence scanner as an identity harvester. Verify who someone is without copying everything the barcode holds.
  3. Put retention in writing. How long does visitor data live, where, and who can read it? “Forever, in a drawer” is now a liability.
  4. Check your access-control vendor’s posture. Where does the data sit, who operates it, and can they show you what they hold about your visitors?

Where QRXS stands

We designed QRXS on the assumption that the least defensible data is data you never collected. A visitor scanning a QRXS plate records a timestamp and which access point was scanned — no visitor personal data is collected by default. Contact happens by relaying a call to the resident without exposing anyone’s phone number. Passes are time-windowed and revocable, access events land in an audit trail carrying minimal data, and the platform runs on our own infrastructure rather than a third party that trades in data.

Minimality wasn’t a compliance retrofit for us; it was the starting design constraint. The new code has simply made that the industry’s standard too.


Sources: TTK Surveillance — The new rules for access control to residential and business estates (19 May 2026); Information Regulator (South Africa); Protection of Personal Information Act, 2013.

This article is general information, not legal advice. For a compliance opinion on your estate’s specific setup, consult your attorney.