Privacy Protection: Practical Highlights for Amendment 13 to the Law
What are the critical practical highlights to maintain?
Much has been discussed regarding Amendment No. 13 to the Privacy Protection Law, which comes into effect on August 14, 2025. Following the amendment, the Privacy Protection Authority (PPA) published a practical guide. This guide is intended for anyone for whom privacy protection is a priority and includes highlights and practical examples for implementing the law’s requirements, including: updating material definitions in the law; reducing the obligation to register databases; the mandatory notification of large databases containing highly sensitive information; the mandatory appointment of a Data Protection Officer (DPO), and more.
We have compiled several practical highlights from the guide, representing the “20% of actions that cover 80%” of the requirements for compliance with the law.
Does the organization hold “Personal Information” or “Highly Sensitive Information”?
Check whether the status of information held by the organization has changed following the amendment, as the definition of personal information has been significantly broadened. Today, personal information is any data that identifies a person—directly or indirectly (name, ID number, location, medical information, etc.). Check if the information status falls under the category of “Highly Sensitive Information,” which includes data such as: medical information, biometric data, financial information, political opinions, sexual orientation, and more.
What to do: Map all data held in the organization’s databases and classify it according to the legal definitions.
Important: Remember to update the Database Definition Document and the Information Security Procedure accordingly.
Is the organization still required to register databases?
If, based on the mapping above, the organization holds databases containing personal information or highly sensitive information, check if you are required to register or report them. While the obligation to register databases has been reduced, the obligation to notify the Authority regarding large or sensitive databases remains. If the organization is a public body or a commercial entity that trades in data, database registration remains mandatory.
What to do: Map all database in the organization and decide whether it is mandatory to register them or notify the Privacy Protection Authority.
Important: It is also possible to delete a database from the Registry of Databases.
Who are the “Four Musketeers”? Three of them: Collection, Authorization, Purpose.
Ensure that the information in the organization’s databases was collected lawfully, with authorization, and for the purpose for which it was gathered. To do this, verify whether the information was collected by virtue of legal authorization or through the informed consent of employees/customers/consumers/suppliers (the “Data Subjects”). Ensure the organization uses the information solely for the purpose for which it was collected, as presented to the data subjects.
What to do: Map the information lifecycles in the organization, from the moment of collection to disposal. Then, verify that each lifecycle complies with legal provisions regarding collection, authorization, and purpose.
Important: Retain the data subject’s consent for information collection as documentation.
And one more: Rights
Uphold the rights of data subjects, ensuring you address and respond to requests from individuals who wish to know what information has been collected about them, to review that information, or to correct inaccurate data. A Data Protection Officer (DPO) will handle such requests.
What to do: Appoint a Privacy Protection Officer (DPO) and task them with managing data subject rights.
Important: An organization that fails to protect data subject rights may be required to pay financial compensation to the data subject.
The Data Protection Officer (DPO) is a vital asset to the organization (and the State)
An organization that is a public body, an organization that processes sensitive information on a large scale, or an organization that performs systematic monitoring of individuals must appoint a Privacy Protection Officer. The DPO will ensure the rights of data subjects are upheld and reduce the organization’s exposure to, among other things, financial damage.
What to do: Appoint a Privacy Protection Officer.
Important: The Law and the Privacy Protection Authority attach great importance to the appointment of a DPO.
Summary: Do not “turn a blind eye”
The Privacy Protection Authority has been granted broader powers. An organization that does not comply with the Law and uses information without authorization exposes itself to high fines (up to millions of NIS), the possibility of orders to cease the use of data or to delete it, and investigation and enforcement measures—including criminal proceedings—by the Privacy Protection Authority.
What to do: Perform the actions mentioned above.
Important: The Authority has received independent status and extensive powers for investigation and enforcement, including criminal authority.
Interested in a gap analysis against the requirements of the Privacy Protection Law in general, and Amendment 13 in particular? Contact the experts at IPV Security!
For professional consultation, you can reach us at info@ipvsecurity.com or by phone at 077-4447130. IPV Security has specialized for 20 years in information security, cyber, risk assessments, and standards and regulations regarding data security and more.