South Africa's Information Regulator has extended the public comment window on its draft Code of Conduct on the Processing of Personal Information at Gated Accesses, after property owners, security contractors, and privacy advocates flagged that the rules — and the time to respond to them — needed more room. The draft, published in Government Gazette No. 54594 on 30 April 2026, was accompanied by an unusually tight 14-day comment period; the Regulator subsequently pushed the deadline to 29 May 2026 after stakeholders objected that a rulemaking touching every residential estate, office park, shopping centre, hospital, and university in the country deserved more than two weeks of scrutiny (ITLawCo).
What the Code Actually Does
The Own-Initiative Code — issued under Sections 60 and 61 of the Protection of Personal Information Act, 4 of 2013, which empower the Regulator to draft sector-specific rules and require it to gazette them for public comment before finalisation (POPIA s.60; POPIA s.61) — targets a genuinely common South African experience: handing over a driver's licence, a fingerprint scan, or a full facial photograph just to visit a friend's estate or attend a meeting in an office park. The draft treats fingerprint and facial-recognition data as "special personal information" under POPIA, requiring heightened justification, and gives concrete examples of what counts as excessive collection — full names, phone numbers, vehicle registration, ID or licence numbers, photographs, and biometrics gathered simultaneously "where alternative means are available" (Moonstone). It also sets indicative retention ceilings — visitor registers for 30 to 90 days, CCTV footage on a 7-to-30-day overwrite cycle, access logs up to a year for high-risk sites — and bans indefinite footage storage and visitor books left visible in a queue.
The Case For the Code
The Regulator did not invent this problem. Its own chairperson, Pansy Tlakula, has pointed to a steep rise in security-compromise reports — 1,727 in the 2024/25 financial year, with an internal projection of roughly 2,500 for 2025/26 — as the backdrop against which estates and complexes have quietly built biometric databases with little oversight (BusinessDay). That is a fair starting point for regulation. Biometric identifiers are unlike passwords: they cannot be reset once leaked, and a facial-recognition database built by a homeowners' association has none of the security engineering, breach-notification discipline, or independent oversight that a bank or telco is expected to maintain. A visitor who hands a security guard a photocopied ID and thumbprint at a boom gate has no visibility into who holds that data next, how long it is kept, or who it might be shared with. Treating that as a POPIA compliance gap, rather than an unregulated grey zone, is a defensible starting position — and the code's proportionality language, requiring data collected to be "relevant, adequate and not excessive" for the stated security purpose, tracks POPIA's existing minimality principle rather than inventing a new standard.
Where the Draft Still Falls Short
The extension itself is the right call, and the Regulator deserves credit for responding to the objection rather than steamrolling a two-week window past a rulemaking of this scope — a genuinely proportionate response to proportionate criticism. But the underlying draft still has a design gap that a longer comment period, not a different one, is supposed to fix: it identifies biometric templates as high-risk without specifying the storage architecture that would make them low-risk. As the compliance bar analysis at ITLawCo notes, the code would be markedly stronger if it defaulted to on-device or subject-held-key storage for biometric templates, rather than leaving architecture to each estate's IT vendor. Without that specificity, a compliant-on-paper estate can still run a centralised facial-recognition database as long as its retention schedule and consent notices check the right boxes — precisely the intrusive outcome the code claims to be preventing.
The other risk is compliance cost falling hardest on smaller bodies corporate and sectional-title schemes that cannot afford dedicated Information Officers or encrypted visitor-management software, while well-resourced commercial landlords absorb the cost easily. A code that is proportionate in its privacy analysis but blunt in its compliance timeline risks pushing small estates toward the crudest possible fix — turning away digital logging altogether and reverting to paper — which serves neither security nor privacy.
The Bigger Picture
What makes this episode notable for South African tech policy isn't the code's substance so much as its process discipline. The Regulator gazetted a draft, took criticism about an unreasonably short comment window seriously, and extended it by two weeks rather than either ignoring the objection or restarting the process from scratch. That is the standard evidence-based regulators should be held to everywhere: engage the sector being regulated, particularly where a rule reaches into every gated estate and office park in the country, before locking in binding obligations that take effect 28 days after final gazettal and run for up to five years. The final text — expected once the Regulator has, per Section 61, considered the extended round of submissions — will be the real test of whether "proportionate" survives contact with a national biometric-access rulebook, or whether it collapses into another paperwork exercise that leaves the actual facial-recognition architecture untouched.