Are we required to appoint a DPO?
Not every organization is in the same position. The statutory conditions and the nature of the activity need to be examined rather than relying on a general label.
Privacy regulation reaches systems, vendors, employees, customers, information security and everyday workflows. The objective is to translate legal requirements into an operating system the organization can manage, maintain and demonstrate when needed.
The website has no inquiry form and does not ask you to enter sensitive personal or business information.
Amendment 13 to the Israeli Privacy Protection Law entered into force in August 2025. Among other changes, it broadened the definition of personal information, changed the database registration regime and introduced a DPO appointment obligation for public bodies and certain organizations that meet the statutory criteria.
Not every organization is in the same position. The statutory conditions and the nature of the activity need to be examined rather than relying on a general label.
Amendment 13 changed the registration regime, and certain databases containing significant volumes of specially sensitive personal information can be subject to a notice requirement.
A policy disconnected from systems, vendors and permissions does not create a reliable picture of accountability.
The firm supports organizations on focused issues and ongoing programs in Israel and, where relevant, in matters involving the GDPR and international operations.
Mapping obligations and gaps, database definition documents, policies, permissions and action plans.
An ongoing privacy function covering advice, work planning, training, monitoring and interaction with management and relevant stakeholders.
Applicability, roles, vendors, transfers, agreements and relevant processes for the organization's activity.
Impact assessments where appropriate, data processing agreements, vendor review and coordination between legal, security and operations.
Processes for intake, assessment, documentation and response under the applicable framework.
Legal support during incidents, assessment of reporting obligations and representation before the Israeli Privacy Protection Authority.
The goal is a proportionate, operable and demonstrable system that prioritizes material risks and fits the way the organization actually works.
Map data, systems, vendors, processes, stakeholders and relevant requirements.
Separate what needs attention now from what can be planned in phases.
Create policies, documents, processes, RACI, controls and training as needed.
Define how execution, follow-up, decisions and continuous improvement are documented.
Modi Deutsch brings more than 20 years of experience in software development and systems engineering. The combination of law and technology helps translate regulatory requirements into solutions that can operate within real systems and workflows.
A privacy obligation can affect system architecture, access rights, vendors, logs, retention, product, HR and operating processes. Implementing it properly requires understanding both the law and the system in which the law must work.
Not every organization needs the same program. A healthy privacy framework, however, creates ownership, documentation and processes that make it possible to explain what was done and why.
The precise answer depends on the activity, data, systems and role of the organization. These are starting points for review, not automatic conclusions.
No. Amendment 13 imposes the appointment obligation on specified bodies and types of activity. The statutory conditions and the organization's characteristics need to be reviewed before reaching a conclusion.
A policy is only one component. The documentation needs to match systems, permissions, vendors, retention, rights handling, security and evidence of execution.
Yes. The firm offers DPO as a Service as part of its privacy and governance services, subject to the organization's needs and structure.
A short conversation can be enough to map the issue. There is no need to send documents or sensitive medical, personal or business information with the initial inquiry.
The information on this page is general and does not replace legal advice based on the specific circumstances.