POPIA Compliance

Introduction

Section 14 of the Constitution of the Republic of South Africa, 1996, provides that everyone has the right to privacy. This right includes protection against the unlawful collection, retention, dissemination, and use of personal information. Many public liability insurance policies require organisations to implement appropriate access control measures as a condition of cover. While visitor management remains an important security requirement, organisations must now ensure that their access control procedures also comply with the Protection of Personal Information Act (POPIA). The purpose of POPIA is to give effect to every individual’s constitutional right to privacy by safeguarding personal information when it is processed by a responsible party. The Act seeks to balance the right to privacy with other important rights and interests, including access to information and the free flow of information within South Africa and across international borders. POPIA regulates how personal information may be processed by establishing conditions that align with international standards. These conditions prescribe the minimum requirements for the lawful processing of personal information and provide individuals with rights and legal remedies where their personal information is processed unlawfully.

Visitor Access Control

Security personnel, including guards, receptionists, boom operators, parking attendants, and contractor access personnel, routinely process visitors’ personal information as part of their daily duties. Organisations are therefore responsible for ensuring that these employees understand their obligations under POPIA and process personal information lawfully. POPIA requires organisations to have a lawful basis for collecting and processing personal information. This includes any collection of identity document details, driver’s licence information, photographs, or biometric information. Unless there is a lawful justification, organisations should avoid collecting more personal information than is reasonably necessary for security purposes. Although POPIA does not prohibit the scanning of identity documents, organisations must be able to justify why scanning is necessary instead of simply inspecting the document. In many situations, visually verifying an identity document may be sufficient. Where legislation requires identity verification, such as under FICA or RICA, or where another lawful basis exists under POPIA, scanning may be appropriate.

Rights of Visitors

Individuals whose personal information has been collected have several rights under POPIA. These include the right to:

  • Know whether an organisation holds their personal information.
  • Request access to their personal information.
  • Request information about how their personal information has been processed.
  • Know who has had access to their personal information.
  • Know whether their personal information has been shared with third parties.
  • Request the correction or deletion of inaccurate or unlawfully held personal information where appropriate.

Where an organisation fails to comply with POPIA, an individual may lodge a complaint with the Information Regulator and, where applicable, pursue legal remedies available under the Act.

Training Requirements

Organisations are responsible for ensuring that employees who process personal information receive appropriate POPIA training and that internal procedures comply with the requirements of the Act. Upon completion of the training, each site receives a certificate confirming that its personnel have been trained, together with a record of the topics and compliance requirements covered. VERIFRAUD can assist organisations in meeting these obligations by developing customised POPIA training manuals tailored to each company and each site. The training addresses the specific personal information processing activities performed at each location.

Proposed Changes Affecting Gated Communities ,Business office blocks and warehouses

The Information Regulator has proposed a Code of Conduct that would place stricter limits on how gated communities, office parks, and similar organisations collect and process visitors’ personal information. Under the proposed Code, organisations should:

  • Collect only the minimum personal information necessary for security purposes.
  • Protect visitor information against unauthorised access.
  • Securely store any personal information that is retained.
  • Destroy or delete personal information when it is no longer required.
  • Ensure that visitor registers are not openly visible to other visitors.

These measures are intended to strengthen compliance with POPIA while maintaining effective security procedures.

CCTV Signage Requirements

POPIA’s principle of openness requires that individuals be informed when their personal information is being collected. Where CCTV surveillance is used, organisations should ensure that clear and visible signage is displayed before a person enters the monitored area.

The signage should include:

  • A statement that CCTV surveillance is in operation.
  • The name of the responsible party operating the surveillance system.
  • The purpose of the surveillance (for example, “For the safety and security of persons and property”).
  • Contact details for enquiries or requests relating to personal information.

Signs should be positioned at all entrances to monitored areas, including vehicle entrances, pedestrian gates, reception areas, building entrances, and parking areas. They should be clearly visible before a visitor enters the camera’s field of view.

How VERIFRAUD Can Assist

VERIFRAUD provides practical POPIA compliance solutions for organisations that operate visitor access control systems. Our services include:

  • POPIA compliance assessments for visitor management procedures.
  • Site-specific visitor access control policies.
  • Customised POPIA training manuals.
  • Staff training for security personnel and reception staff.
  • Compliance certificates confirming completed training.
  • Guidance on lawful collection and processing of visitor information.
  • Advice on CCTV signage and visitor privacy requirements.

By implementing compliant visitor management procedures, organisations can continue to meet their security and insurance requirements while respecting the privacy rights of employees, contractors, and visitors under POPIA.