
WHY THIS GUIDE MATTERS
Access-controlled environments collect and process a lot of personal information every day. POPIA and the draft Code of Conduct set the rules for how that information must be handled. This eBook translates those rules into practical steps you can take - so you can protect people’s privacy, reduce risk, and build trust at every gate.
WHO SHOULD READ THIS?
This eBook is written for the people who actually run access-controlled environments in South Africa. Whether you’re making decisions, managing operations, or providing services, this guide will help you understand your responsibilities and take practical steps toward POPIA compliance.
WHAT'S INSIDE?
What the draft Code is trying to achieve
Responsible parties vs operators
Accountability is non-negotiable
What information may be collected at gate access
Why data mapping is necessary
Basic training expectations
Privacy notices and transparency
Retention, access control and security safeguards
Operator agreement requirements
Impact assessments for high-risk processing
Common misconceptions and practical FAQs
Immediate next steps

