Corporate Law

Does an Israeli company have to appoint a data protection officer?

Only some companies do. Amendment 13 to the Protection of Privacy Law 5741-1981, which came into force in August 2025, requires a designated data protection officer for public bodies, for data brokers whose business is trading in personal information, and for controllers or processors whose core activity involves large-scale processing of highly sensitive data or systematic monitoring of individuals. A company outside those categories has no appointment duty, but it still carries the substantive obligations of lawful purpose, database security, and responding to subject access requests. The officer must have suitable expertise, report to the most senior level of management, and hold no other role that conflicts with the function.

Amendment 13 rebuilt Israeli privacy enforcement rather than simply adding a new post. It narrowed the old database registration regime, redefined sensitive information, and gave the Privacy Protection Authority administrative fining powers calculated by reference to the size of the database and the seriousness of the breach. The data protection officer sits at the centre of that structure. The statutory role covers advising the organisation on its obligations, monitoring compliance and training, preparing the internal data map, and acting as the contact point for both data subjects and the regulator. It is distinct from the information security officer required under Section 17B of the Law, and one person can hold both roles only where doing so creates no conflict of interest, as Israeli data protection compliance increasingly treats independence as central.

Foreign groups are frequently caught even without an Israeli office, because the Law reaches processing that relates to Israeli residents. The officer does not have to be an employee. Israeli practice accepts an external service provider, and a single officer can serve several companies in the same group, provided they remain reachable by Israeli data subjects and free of conflicting commercial duties. A group that already has a GDPR data protection officer will usually extend that person's mandate, but the Israeli appointment needs its own documentation, its own published contact details, and familiarity with Israeli notification and breach requirements. Record the board decision appointing the officer; regulators ask for it first.

⚖ In Practice
  • Governing law: Amendment 13 to the Protection of Privacy Law 5741-1981, in force from August 2025; information security officer duty under Section 17B
  • Competent authority: Privacy Protection Authority (HaRashut LeHaganat HaPratiyut), Ministry of Justice
  • Who must appoint: public bodies; data brokers; and controllers or processors whose core activity is large-scale processing of highly sensitive data or systematic monitoring of individuals
  • Enforcement: administrative fines are calculated by reference to the number of data subjects and the nature of the breach, and can reach several million shekels for large databases
  • Structure: the officer may be an external contractor and may serve multiple group companies, but must report to senior management and avoid conflicting roles such as head of marketing or IT procurement
  • Extraterritorial reach: a foreign company with no Israeli office can still fall within the Law where its processing relates to individuals in Israel

From the full guide: Data Protection Law in Israel for Businesses and Foreign Companies


Related Questions

Related Guides

Need legal help with this topic?
Get a Free Consultation with Adv. Eli ShimonyPrepared under the direction of Adv. Eli Shimony, Eli Shimony Law Office · Editorial policy

← Browse all Q&A