The practice of scanning visitors’ driver’s licences at residential estates, gated communities, and office parks has sparked concerns about compliance with South Africa’s Protection of Personal Information Act (POPIA).
Advocate Pansy Tlakula, chair of the Information Regulator, has
highlighted
issues of “overprocessing,” where entities collect far more data than necessary for security, including names, home addresses, ID numbers, and even photographs.
According to POPIA, businesses should only gather minimal, lawful information—typically a visitor’s name, vehicle registration, and car colour for security purposes.
The overcollection of data, such as scanning driver’s licences and vehicle discs, poses significant risks, particularly with growing cybercrime threats.
Questions about how this information is stored and secured remain critical, as these practices expose individuals to potential fraud and misuse.
To address these concerns, the Information Regulator is considering a code of conduct to ensure compliance with POPIA. Advocates like Ariel Flax from access system provider ATG Digital support limiting data collection to essentials and incorporating measures like data redaction, encryption, and secure cloud storage.
While digitised visitor management systems may enhance security compared to outdated handwritten logs, they must respect privacy rights and adhere to legal standards.
Excessive data collection not only undermines POPIA but also erodes public trust. Striking a balance between effective security and protecting personal information is vital to building a safer, privacy-conscious environment.