Solutions /  The situation

Amendment 13 is in force. The roles it requires are probably empty in your company.

Israel's Privacy Protection Law now obliges many organisations to appoint a Data Protection Officer and an information security officer: real, named, qualified roles with duties, not a line in a policy. Most Israeli mid-market companies have neither, have not noticed, and are non-compliant on that point alone before anyone even looks at their databases. The law created two jobs; the question is who is doing them at your company today.

Get your free exposure assessment

The amendment is already in effect and it moved privacy from a paper obligation to a supervised one, with administrative enforcement powers that did not exist before. It applies based on what you do with personal data, not on how large you are, which is exactly why so many companies assumed it was somebody else's problem.

What it is costing you

  • A statutory role sits vacant, which is a finding any regulator, customer or insurer can establish in a single question.
  • Enterprise customers and cyber insurers now ask for the DPO's name in writing; "we do not have one" ends the conversation.
  • Database registration, processing records, data subject rights and retention obligations all assume an owner. With no owner, none of them are running.
  • Administrative enforcement is now available to the regulator, and exposure grows with every month the gap is documented and unaddressed.

What we do

01

We tell you whether the roles apply to you

The obligation turns on what personal data you process and how. We give you a straight answer, in writing, on whether you are required to appoint a DPO, a security officer, or both.

02

We fill the role

A named, qualified DPO and information security officer, appointed formally and reachable, an external appointment that satisfies the requirement without you hiring two people you do not have budget for.

03

We build the record

Processing inventory, database registration where required, retention rules, data subject request handling, breach notification procedure. This is the evidence that turns an appointment into compliance.

04

We run it continuously

Privacy obligations drift the moment you add a system, a vendor or a market. The ROC keeps the register, the records and the notifications live, not refreshed once a year.

How long it takes. The appointment itself can be in place within weeks. Building the processing records and data subject machinery behind it typically takes two to four months, depending on how many systems hold personal data.

Who must appoint a Data Protection Officer under Amendment 13 to the Israeli Privacy Protection Law?

Amendment 13 requires a Data Protection Officer for organisations whose core activity involves large-scale or systematic processing of personal data (including public bodies, data brokers, and companies whose main business involves processing sensitive personal data) and separately requires an information security officer for certain database holders. The obligation depends on the nature and scale of the processing, not on company size, which is why many mid-market Israeli companies are within scope without realising it. The DPO may be an external appointment.

Can an external provider serve as our DPO under Amendment 13?

Yes. The law requires that the role be filled by someone qualified, independent and reachable, and reporting to management. It does not require an employee. An external DPO is a standard and accepted arrangement, and for a 50-500 person company it is usually the only realistic one, because the role demands specific expertise and independence that an internal generalist cannot provide.

What happens if we have not appointed a DPO and we are required to?

You are non-compliant from the day the obligation applies, and it is the easiest possible finding to establish: there is either a named, appointed officer or there is not. Amendment 13 gives the Israeli Privacy Protection Authority administrative enforcement powers, and the missing appointment also surfaces in customer due diligence and cyber insurance underwriting. The remediation is fast compared with the exposure: the appointment can be made in weeks.

Find out how far you have drifted.

A free exposure assessment. We connect to what you already have, and show you what your dashboards are not showing you.

No obligation. Results in 10 business days.