Estates · Bodies Corporate · Managing Agents
What your gate collects is personal information.
Every ID number scanned, licence disc read, fingerprint captured and hour of footage kept at your access points is personal information under POPIA — and the responsible party is almost always the homeowners association or body corporate, not the guarding company at the boom.
We map how that information actually moves through your estate, prove where it is exposed, and make the requirements operational — technically, not on paper.
Why now
The Regulator has turned its attention to the boom gate.
On 30 April 2026 the Information Regulator gazetted a draft own-initiative Code of Conduct dealing with the processing of personal information at gated accesses. Its stated concerns are the ones you see at almost every gate: excessive collection of identity and licence details, images and biometrics; cameras capturing faces without people being aware; and facial recognition used for identification.
Public comment closed on 29 May 2026. A code of conduct carries materially more weight than a guidance note, and it applies beyond residential estates — office parks, shopping centres, schools and hospitals sit in the same scope.
Status, stated honestly: the code was still in draft when this page was written, and we do not quote clauses from a draft as though they were final. What is already true today, code or no code, is that POPIA governs everything your gate collects.
We track the Gazette and the Regulator's publications, and our checklist follows the final wording when it lands. An estate that has mapped its data first adapts; one that waits does a retrofit under pressure.
Who this is for
The person who answers when the question is asked.
Managing agents
One estate is one problem. A portfolio is the same problem repeated, and it lands on your desk rather than the guarding contractor's. Portfolio rates apply across a book.
Estate managers & HOA chairs
You are usually the responsible party. That means the register at the gate, the footage retention and the biometric reader are yours to justify.
Bodies corporate
Sectional title schemes collect the same data with less administrative capacity behind it, and trustees carry the accountability personally.
Guarding companies
Your estate clients will push the operational burden down to you: SOPs, training records, what a guard may write down. Contractors who can show a documented process keep contracts at renewal.
What we actually look at
We watch a real shift, not a policy document.
Ninety minutes at a working access point, including a delivery vehicle and a visitor who is not on the list — because that is where the process actually breaks.
Collection — what is taken, by what means
- ID book, card or licence: inspected, scanned, photographed, or written down?
- Licence disc scanners and ANPR — what the device stores, and for how long
- Biometrics: fingerprint or facial recognition, for visitors, contractors, residents or staff
- The paper register left open on the counter where the next visitor can read it
- Contractors and domestic workers — usually more data, kept longer, with no stated basis
- Visitor apps and pre-authorisation platforms, and who operates them
Notices, and what happens when someone says no
- Is there a notice at the point of collection, and does it say who, why, how long and who to contact?
- Is the Information Officer reachable by a visitor who asks?
- What actually happens to a visitor who declines to hand over an identity document
Storage, access and retention
- Where each field lands: device, guardhouse PC, vendor cloud, or a drawer
- Who can retrieve it — guards, supervisors, the estate manager, vendor support, head office
- Whether access is logged, and whether an export can be traced to a person
- Retention per stream, and whether destruction is happening or merely stated
- Backups: where they are, who holds the keys, and whether a restore has ever been tested
CCTV
- Coverage map, including any public road or neighbouring property in frame
- Retention, and whether the system enforces it or just overwrites when full
- Who can view live, who can export, and how exports are recorded
People and process — the part that decays
- Has any guard been trained on visitor data? We ask a guard, not the supervisor.
- Guard turnover in the last twelve months — the real threat to any SOP
- The paper fallback when the system is down, and what happens to that paper
- Incidents already survived: a lost register, a stolen device, footage in a WhatsApp group
Breach radius — our signature analysis
- For each store: how many data subjects, which categories, and whether special personal information is present
- The worst realistic compromise — stolen guardhouse PC, vendor breach, insider export
- Whether it would trigger notification to the Regulator and to the people affected
- The three changes that shrink the radius most, ranked by cost
What it costs
Fixed fees, written scope, named exclusions.
Never hourly. Every engagement is quoted against a defined scope after a short call, and the exclusions are written on the proposal so there is no argument later.
Gate Data Audit
R18,000 – R28,000The first engagement, deliberately small and specific. One access point and the systems behind it.
- A data flow map for the gate — drawn, not described
- A necessity and proportionality test for every field collected, with particular attention to biometrics
- Retention and destruction findings
- A breach-radius note
- A prioritised remediation list, costed in three bands
- A one-page board summary your chair can read in five minutes
Excludes: remediation work, manuals, staff training and legal opinion.
Estate Readiness Pack
R45,000 – R75,000- Gate Data Audit across every access point
- Operator agreement gap list for the guarding and access-control vendors
- Access control and CCTV configuration review — retention, access rights, export logging
- A visitor data SOP written for guards, not for lawyers, plus on-shift training
- Signage and notice pack
- PAIA manual and POPIA policy set for the HOA or body corporate
- Information Officer designation and registration support
- Incident and breach runbook for the estate manager
Managed Compliance
R6,500 – R12,000 / month- Quarterly re-test against the published code once it is final
- Register and log upkeep, and review of every new vendor
- Refresher training on guard turnover — the real failure mode
- Annual board report and breach on-call
Where we stop
Three things we will not sell you.
Each of these is a boundary, not modesty. A provider who offers them either misunderstands the law or is hoping you do.
Common questions
Straight answers.
Who is responsible for the personal information collected at an estate gate?
In most estates the responsible party is the homeowners association or body corporate, not the guarding company. The guarding company is usually an operator processing the information on the estate's instruction, which is why an operator agreement is required. That distinction decides who answers to the Information Regulator, and it is the first thing we establish in writing.
Can our estate use fingerprint or facial recognition at the gate?
Biometric information carries a higher bar under POPIA. The test is necessity and proportionality: whether a less intrusive means would achieve the same access control, and whether the collection is justified for the purpose. We run that test field by field, document the reasoning, and tell you plainly where a reader is difficult to justify. Whether to keep it is your board's decision and, where liability is in question, one for your attorney.
What is a breach radius?
For every place personal information sits, it is the answer to one question: if this were compromised tomorrow, how many people are affected, what categories are exposed, and would you have to notify the Information Regulator and the data subjects? It turns a vague worry into a number your board can act on, and it ranks what to fix first.
Can ASi Imperium act as our Information Officer?
No, and nobody outside your organisation can. Under POPIA the head of the body is the Information Officer by default, and where someone else acts, that person must be authorised from within the body. We prepare the designation and delegation, the PAIA manual particulars, and the registration on the Regulator's eServices portal, and we train and support the person appointed. Any provider offering to be your outsourced Information Officer is selling something the Regulator's guidance does not allow.
Do you give legal advice or advise on cyber insurance?
Neither. Our reports state findings of fact and technical recommendations. Legal opinions, operator agreements and regulator correspondence go to a data protection law firm. On insurance, we produce the technical evidence an underwriter asks for — control inventory, access and backup evidence, incident history — and hand it to your own licensed broker. ASi Imperium is not an authorised financial services provider and does not recommend, compare or place cover.
What does a Gate Data Audit cost?
A Gate Data Audit for one access point is R18,000 to R28,000, depending on the systems behind the gate. A whole-estate Estate Readiness Pack is R45,000 to R75,000, and ongoing Managed Compliance is R6,500 to R12,000 a month on a twelve-month term. Every engagement is a fixed fee against a written scope with a named exclusion list — never hourly.
General information, not legal advice. This page describes technical assessment work and summarises publicly gazetted material. It is not a legal opinion on your obligations, and the draft code referred to was not final when this page was written — confirm the current text before relying on it. On insurance: ASi Imperium (PTY) LTD is not an authorised financial services provider; we do not recommend, compare or place cover, and insurance decisions require a licensed broker.
Who does this work. An engineering-led practice, certified in cybersecurity, cloud and networking, working to named standards rather than adjectives. Every engagement is scoped and authorised in writing before it starts. See our credentials — verification documents are provided to clients and procurement teams at onboarding. Our own PAIA manual is published.