South Africa

New surveillance laws for estates and shopping malls in South Africa

A proposed new law will require estates, malls, schools, hospitals and other controlled-access sites to comply with stricter POPIA rules governing CCTV, biometrics and visitor data.

The recent publication of the draft Code of Conduct on the Processing of Personal Information at Gated Access signals that South Africa is about to regulate one of its largest workforces.

According to the Private Security Industry Regulatory Authority (PSiRA), the country has more than 580,000 registered private security officers and 11,000 security businesses.

This makes it one of the largest private security sectors in the world. However, Van Deventer Dowlath & Marx Director Cor van Deventer pointed out that it has never been formally integrated into POPIA compliance.

This is despite the fact that it manages personal information at thousands of access points every day. The draft has exposed a national blind spot, he said.

“Guards, receptionists, boom operators, parking attendants and contractor access teams will now be treated as data processors under POPIA (Protection of Personal Information Act).”

On a daily basis, hundreds of thousands of access control workers process visitor registers, ID verification, licence‑plate recognition, biometric scanners and CCTV systems.

It is important to note, van Deventer added, that PSiRA’s training standards do not currently require any POPIA modules.

This means that despite the sensitive nature of what access control workers handle, they have never had proportionality, retention rules, deletion protocols, or privacy notice training.

Van Deventer also stressed the sheer magnitude of South Africa’s private security sector. Industry mapping by Estate Living estimates there are between 7,000 and 8,500 residential estates.

Meanwhile, the Community Schemes Ombud Service said the country has approximately 70,000 sectional title schemes.

The South African Council of Shopping Centres lists around 2,000 shopping centres nationwide, and the Department of Basic Education said South Africa has about 26,000 public and independent schools.

Health Systems Trust and Department of Health data show there are between 400 and 450 hospitals and major medical facilities.

SAPOA and commercial real estate mapping also confirm there are thousands of office parks, industrial precincts and government facilities across the country, van Deventer said.

South Africa also has a very significant surveillance footprint. “Industry estimates suggest the country has over 1.2 million CCTV cameras in commercial and residential environments, many positioned at access points.”

Biometric adoption is just as widespread. Approximately 60% of large estates use fingerprint or facial recognition, and 40% of office parks rely on biometric or licence plate recognition.

Van Deventer also noted that around 70% of new access control installations include some form of biometric component.

What has changed

POPIA itself hasn’t changed, van Deventer stressed. “The law has always required proportionality, necessity, security safeguards and responsible governance.”

He explained that what is changing is the level of accountability that the Regulator will now demand at access points.

“The Code isn’t a new law. It is a new enforcement framework for environments that have long overlooked their data handling duties.”

The draft Code is a response to years of public complaints, he said. According to the Information Regulator, it receives a number of common POPIA complaints about intrusive gate practices.

These include excessive data collection, unclear retention periods, unregulated CCTV capture and the use of biometrics without proper justification, to name a few.

The Code requires that only information necessary for access control be collected, and that any use of biometrics or high‑risk technologies be justified through a Personal Information Impact Assessment.

Now, for the first time, van Deventer said that access control is going to be a regulated compliance function in South Africa.

This means that trustees, directors, homeowner associations, landlords, property managers and heads of public bodies will need to implement some major changes to their access control systems.

They will all need to appoint information officers, implement compliance frameworks, and maintain retention and deletion schedules.

They will also be required to provide privacy notices, document all processing operations, and train staff who handle personal information.

“And this is very important to note – governance structures will carry the legal risk for non‑compliant data handling at the gate, not the guard.”

Van Deventer said the Code is also going to influence the way security companies contract with estates, malls, office parks and public bodies, with service level agreements now needing to include:

  • POPIA‑aligned data‑handling duties
  • training obligations for frontline staff
  • retention and deletion rules
  • breach‑reporting procedures
  • liability clauses
  • documented processing instructions

“Security companies can no longer rely on generic SLAs,” he warned. “If their staff collect personal information, their contracts will need to prove that those staff were properly trained and are legally governed.”

What businesses should do

While the compliance costs will vary widely depending on existing systems, van Deventer offered the following budget starting point:

  • POPIA training for frontline staff: R350 – R1,200 per person
  • Compliance framework development: R20,000 – R150,000
  • Access‑control system upgrades: R50,000 – R500,000-plus
  • Biometric replacements: R80,000 – R1.2 million
  • CCTV compliance upgrades: R15,000 – R200,000

Once approved, he said the Code will probably allow a transitional period to implement training, update systems, revise contracts and align procedures, although the Regulator hasn’t confirmed the duration.

“It’s not going to happen overnight, but it is going to happen, so organisations need to use the transitional period wisely.”

Van Deventer recommended that, in the meantime, trustees, landlords and operators begin preparing immediately by:

  • establishing a budget
  • auditing current access control practices
  • identifying excessive data collection
  • reviewing CCTV and biometric systems
  • preparing training plans for frontline staff
  • updating privacy notices at access points
  • revising contracts with security providers
  • establishing retention and deletion schedules
  • documenting all processing operations

Van Deventer clarified that the code’s central focus is proportionality – parties may collect only the information strictly necessary for access control.

Excessive collection, such as taking multiple identifiers for a single entry, will be prohibited. Any use of biometrics or high‑risk technologies must be justified through a Personal Information Impact Assessment.

Van Deventer cautioned that access control is no longer an operational issue – “it’s now a serious governance risk.”

“Organisations that wait for final enforcement before acting could find themselves exposed, underprepared and unable to prove compliance when the time comes.”

Newsletter

Top JSE indices

1D
1M
6M
1Y
5Y
MAX
 
 
 
 
 
 
 
 
 
 
 
 

Comments