Estates, gated communities and office parks face sweeping changes to security procedures as the Information Regulator calls for access-controlled areas to collect minimal visitor information and protect privacy. The regulator has now published the “Own-Initiative Code of Conduct for Gated Access Areas” that will govern how gated-access environments handle personal information to conform to the prescripts of the Protection of Personal Information Act (Popia). The code applies to residential and commercial premises with access control. It is not a guidance note but a code of conduct, which carries much heftier weight than the former. The regulator in the code of conduct says members of the public have raised concerns that the collection of personal information at gated access entry points is excessive. “The regulator undertook research into the utilisation of closed-circuit camera (CCTV) surveillance and, in addition, considered complaints received in this regard. These collectively revealed certain access control practices of an intrusive nature, including the processing of biometric information such as the use of facial recognition systems for the purpose of positive identification of data subjects,” the draft code of conduct reads. “Furthermore, the deployment of CCTV surveillance at access control points results in the capture of facial images without the consent of data subjects and, at times, without their knowledge or awareness. “Such processing may constitute excessive collection and processing of personal information in so far as it is not relevant and limited to what is necessary for the legitimate purpose for which it is collected and accordingly warrants the imposition of appropriate regulatory measures to ensure compliance with provisions of Popia.” Under the proposed code of conduct, visitor books must not be visible to others in a queue, and digital visitor management systems must encrypt data. The code also prohibits indiscriminate copying of IDs and driver’s licences