ISRAEL · PRIVACY PROTECTION LAW · AMENDMENT 13

A Data Protection Officer for Israel.
Because your EU one does not count.

Amendment 13 requires many organizations to appoint a DPO, and it reaches foreign companies that process the data of Israeli residents. The regulator has stated plainly that knowing a foreign privacy framework is not a substitute for Israeli-law expertise. I take the appointment, and the responsibility that comes with it.

Certified Data Protection Officer, Bar-Ilan University

WHERE THIS STANDS TODAY

14 Aug 2025

The appointment obligation became legally enforceable.

31 Oct 2025

The regulator's initial grace period expired. There is nothing left to wait for.

15 Jul 2026

Final guidance on the appointment obligation published. DPO compliance is a stated enforcement priority.

WHO HAS TO APPOINT ONE

Does this apply to your organization?

Four categories carry the obligation. The Authority has deliberately refused to publish clean numeric thresholds, assessing instead the totality of the circumstances: how many people, how much data, how sensitive, how often. Small volume is not automatically safe.

Public bodies

Government ministries, local authorities, health funds, hospitals, universities and statutory corporations. The obligation here is unconditional.

Data brokers and marketing databases

Controllers whose core business involves transferring personal data to others, where the database covers 10,000 people or more.

Systematic large-scale monitoring

Search engines, profiling and location apps, wearables and IoT, ad tech, and surveillance operations. If tracking behaviour is how the product works, you are likely in scope.

Highly sensitive data at volume

Health, biometric, genetic, financial, political and similar categories. Relevant to health tech, fintech, insurance and any platform holding medical or payment histories.

The trap for processors and service providers

If you process data on behalf of many separate clients, your exposure to highly sensitive data is assessed in aggregate across all of them, not client by client. A processor handling a thousand small databases of a hundred people each is assessed at a hundred thousand people. No single contract would have triggered it on its own, and it still applies.

Not sure which category you fall into? A short scoping call will give you a clear answer.

FOR COMPANIES OUTSIDE ISRAEL

Why your existing DPO probably does not cover Israel

What companies assume

  • “We have a DPO in Dublin, so the group is covered everywhere.”
  • “No Israeli entity, so no Israeli obligation.”
  • “Our GDPR documentation set can be relabelled for Israel.”

What the guidance says

  • Familiarity with foreign privacy frameworks does not substitute for in-depth practical knowledge of Israeli privacy law, and the Authority calls this out specifically for multinational groups.
  • There is no citizenship or residency requirement, but the DPO must be physically available in Israel to the extent required.
  • The Authority intends to use its enforcement powers to verify that appointees genuinely hold the requisite expertise.

The practical answer for a foreign group is usually not to replace anyone. It is to add a named Israeli appointment that sits alongside the existing privacy function, works to your established reporting lines, and closes the specific gap the regulator has said it will be looking for.

WHAT THE ENGAGEMENT COVERS

From the first assessment to ongoing compliance

01

Scope assessment and data mapping

Whether the obligation actually applies to you, then a full map of personal data flows: what you hold, where it sits, who touches it, whether a registration or notification duty is triggered, and where you sit against the law.

02

Named DPO appointment

I serve as your organization's named Data Protection Officer before the Privacy Protection Authority. The law requires a specific natural person, not a firm, and that person is me.

03

Policies, procedures and contracts

Privacy policy, data processing agreements, access and retention procedures, database definition documents and an information security plan, drafted against Amendment 13 rather than translated from a GDPR template.

04

Breach response readiness

A rehearsed protocol for a security incident: detection, containment, and notification to the Authority and to data subjects inside the window the law allows. Written before you need it, not during.

05

Training and internal adoption

Management and team training that turns regulation into working procedure. Compliance that lives only in a document is the kind that fails an inspection.

06

Ongoing supervision and reporting

Monthly oversight, handling of data subject requests, tracking of regulatory change, and a periodic compliance report your board can actually use. Note that appointing a DPO does not discharge the board's own supervisory duty, so that report matters.

WHY ME

I do not just write the policy. I can implement it.

Most privacy consultants stop at the document. I build production software for a living, which means privacy by design is something I apply in the schema, the permission model and the retention job, not something I recommend to your engineers and hope they implement. When the Authority asks how a deletion request is actually executed, the answer is a query, not a paragraph.

  • Certified Data Protection Officer, Bar-Ilan University
  • Hands-on experience building systems that process personal and sensitive data
  • A single point of accountability, from assessment to technical implementation
  • Plain business language, in Hebrew or English, for boards and for engineers

TWO WAYS TO ENGAGE

Standalone, or built into the product itself

Standalone DPO

The full officer function for your existing organization: assessment, appointment, documentation, training and ongoing supervision. Independent of whatever technology you are running.

Onboarding project, then a monthly retainer

DPO plus product build

Building something new? Compliance gets designed in at architecture stage, so the product is born conformant instead of being retrofitted at audit. The officer and the engineer are the same person, so there is nobody in the middle translating between them.

See how I build →

QUESTIONS

What organizations ask before appointing

Our company has no office in Israel. Does Amendment 13 apply to us?+

It can. The law reaches foreign entities that process the personal data of Israeli residents, and a local office is not what triggers it. If you run a SaaS product, a store, an app or an ad platform with Israeli users, you should assume you are in scope until an assessment says otherwise.

We already have a DPO for GDPR. Doesn't that cover Israel?+

Generally no. The Privacy Protection Authority's final guidance is explicit that familiarity with foreign privacy frameworks does not substitute for in-depth practical knowledge of Israeli privacy law, and it flags this specifically for multinational groups trying to designate a foreign DPO to cover an Israeli entity. The guidance also expects the DPO to be physically available in Israel to the extent required. An EU appointment on its own does not meet either test.

Can the DPO be an external service provider rather than an employee?+

Yes. Outsourcing is explicitly permitted. The one firm requirement is that the appointment names a specific natural person, so engaging a consultancy without naming the individual does not satisfy the law. You must also give that person sufficient time, resources and access to information to do the job.

Is there still a grace period?+

No. The obligation became legally enforceable on 14 August 2025. The Authority exercised enforcement discretion during an initial grace period, which expired on 31 October 2025. Final guidance on the appointment obligation was published on 15 July 2026, and DPO compliance is a stated enforcement priority.

What happens if we do not appoint one?+

The Authority has substantially broader investigative powers under Amendment 13 and can impose administrative fines that scale with the size of the organization and the severity of the breach, reaching into the millions of shekels in serious cases. There is also a direct incentive in the other direction: organizations that have appointed a DPO receive a 10% reduction in financial sanctions imposed for statutory violations.

We are a processor serving many small clients. Are we below the threshold?+

Probably not, and this catches people out. For a processor servicing multiple controllers, exposure to highly sensitive data is assessed in aggregate across all clients rather than per client. A processor handling a thousand databases of a hundred people each is assessed at a hundred thousand, even though no single client relationship would trigger the obligation on its own.

Do we still have to register our database?+

In most cases no, and this is one of the most common errors in the material still circulating online. Amendment 13 abolished the general registration requirement and kept it for only two kinds of database: one whose main business is transferring personal data to others and which holds information on more than 10,000 people, and one belonging to a public body. A notification duty replaced it: an organization holding specially sensitive information on more than 100,000 people that is not required to register must notify the Authority within 30 days. Note how the two connect: if you are required to register, you are also required to appoint a DPO.

Can our CTO, CISO or general counsel take the role?+

The DPO must act independently and free from conflicts of interest, and cannot simultaneously hold a role that determines the purposes of processing. The Authority names Head of Marketing, Head of Customer Success, CFO, IT Manager and CTO as incompatible. Pairing with the CISO is not prohibited outright but requires a documented conflict analysis, and in practice a CISO often lacks the legal privacy expertise the role demands. In-house or external counsel can work where no conflict arises.

Who should the DPO report to?+

Directly to the CEO, or to a senior executive who reports to the CEO. A DPO buried inside IT or marketing fails the independence test regardless of how capable the individual is.

How is Amendment 13 different from GDPR in practice?+

The direction of travel is similar and the mechanics are not. Israel keeps its own database registration regime, its own definitions of sensitive data, its own notification timelines, and its own regulator with its own guidance and enforcement priorities. Mapping a GDPR programme onto Israel gets you most of the way on principles and leaves you exposed on specifics, which is exactly where an inspection looks.

What does it cost?+

It depends on the number of databases, the sensitivity of the data and the complexity of the organization. The usual shape is a one-off onboarding project covering the assessment and the foundation documents, then a monthly retainer for the ongoing role. I will quote after a short scoping call, at no charge.

What are your qualifications?+

I hold a Data Protection Officer certification from Bar-Ilan University. I am also a full-stack product builder, which means I implement privacy by design at the level of the database schema, the permission model and the code, rather than only describing it in a policy document.

NEXT STEP

A free scoping call

Twenty minutes to establish whether the obligation applies to you, where the material gaps are, and what the right first move is. No obligation, and no charge.

This page describes a professional compliance service and is general information about Israeli regulation. It is not legal advice, and it does not create a professional relationship. Regulatory guidance changes, so confirm current requirements for your specific circumstances before acting.

לעמוד בעברית: שירות ממונה הגנת פרטיות