א.מ. דויטש - משרד עו"ד וגישור
Privacy and Data Protection

Privacy is not measured by a document. It is measured by what the organization can operate and evidence.

Privacy regulation reaches systems, vendors, employees, customers, information security and everyday workflows. The objective is to translate legal requirements into an operating system the organization can manage, maintain and demonstrate when needed.

The website has no inquiry form and does not ask you to enter sensitive personal or business information.

Amendment 13

The framework changed. Organizational accountability became more concrete.

Amendment 13 to the Israeli Privacy Protection Law entered into force in August 2025. Among other changes, it broadened the definition of personal information, changed the database registration regime and introduced a DPO appointment obligation for public bodies and certain organizations that meet the statutory criteria.

01

Are we required to appoint a DPO?

Not every organization is in the same position. The statutory conditions and the nature of the activity need to be examined rather than relying on a general label.

02

Does a database require registration or notice?

Amendment 13 changed the registration regime, and certain databases containing significant volumes of specially sensitive personal information can be subject to a notice requirement.

03

Do the documents reflect operational reality?

A policy disconnected from systems, vendors and permissions does not create a reliable picture of accountability.

Scope of support

Privacy support built around the actual need.

The firm supports organizations on focused issues and ongoing programs in Israel and, where relevant, in matters involving the GDPR and international operations.

01

Amendment 13 and Security Regulations

Mapping obligations and gaps, database definition documents, policies, permissions and action plans.

02

DPO as a Service

An ongoing privacy function covering advice, work planning, training, monitoring and interaction with management and relevant stakeholders.

03

GDPR and international data transfers

Applicability, roles, vendors, transfers, agreements and relevant processes for the organization's activity.

04

DPIA, DPA and vendors

Impact assessments where appropriate, data processing agreements, vendor review and coordination between legal, security and operations.

05

Data subject rights

Processes for intake, assessment, documentation and response under the applicable framework.

06

Security incidents and regulator matters

Legal support during incidents, assessment of reporting obligations and representation before the Israeli Privacy Protection Authority.

Method

No more documents for the sake of documents.

The goal is a proportionate, operable and demonstrable system that prioritizes material risks and fits the way the organization actually works.

01

Map

Map data, systems, vendors, processes, stakeholders and relevant requirements.

02

Prioritize

Separate what needs attention now from what can be planned in phases.

03

Build

Create policies, documents, processes, RACI, controls and training as needed.

04

Evidence

Define how execution, follow-up, decisions and continuous improvement are documented.

Privacy, technology and systems

Adv. Modi Deutsch

Modi Deutsch brings more than 20 years of experience in software development and systems engineering. The combination of law and technology helps translate regulatory requirements into solutions that can operate within real systems and workflows.

Professional difference

Regulation does not stop at the legal department.

A privacy obligation can affect system architecture, access rights, vendors, logs, retention, product, HR and operating processes. Implementing it properly requires understanding both the law and the system in which the law must work.

Translate legal requirements into controls and operating processes
Work directly with Legal, DPO, CISO, IT, HR, Risk and Product
Connect governance, evidence, vendors, data and technology
Accountability

What should an organization be able to show?

Not every organization needs the same program. A healthy privacy framework, however, creates ownership, documentation and processes that make it possible to explain what was done and why.

Who owns each area and who makes decisions
Which databases, systems and vendors process personal information
How data subject requests are handled
Which security, access and retention controls are required
How new projects, changes and vendors are reviewed
How training, assessments, decisions and remediation are evidenced
FAQ

Three questions that arise in almost every organization.

The precise answer depends on the activity, data, systems and role of the organization. These are starting points for review, not automatic conclusions.

Does every company have to appoint a DPO?

No. Amendment 13 imposes the appointment obligation on specified bodies and types of activity. The statutory conditions and the organization's characteristics need to be reviewed before reaching a conclusion.

If we have a privacy policy, are we covered?

A policy is only one component. The documentation needs to match systems, permissions, vendors, retention, rights handling, security and evidence of execution.

Can the DPO function be external?

Yes. The firm offers DPO as a Service as part of its privacy and governance services, subject to the organization's needs and structure.

Contact

Want to understand what should be checked next?

A short conversation can be enough to map the issue. There is no need to send documents or sensitive medical, personal or business information with the initial inquiry.

The information on this page is general and does not replace legal advice based on the specific circumstances.