Israel Israel Privacy Protection Law amendment

Israel's Final DPO Guidance Closes a Real Loophole, But Its Aggregation Rule May Snare Small Vendors

The Privacy Protection Authority's July 2026 guidance forces genuine DPO independence and counts processor exposure across all clients combined.

Israel's DPO Mandate, By The Numbers People of Internet Research · Israel 10,000+ people Broker DPO Threshold Data brokers or commercial databas… 100,000 records Processor Aggregation Trigger 1,000 client contracts of 100 reco… 5 roles Roles Barred From DPO Post Marketing, customer success, finan… Aug 14, 2025 DPO Duty Enforceable Since Amendment 13's DPO mandate took le… peopleofinternet.com
Israel's DPO Mandate, By The Numbers People of Internet Research · Israel 10,000+ people Broker DPO Threshold 100,000 records Processor Aggregation Trig… 5 roles Roles Barred From DPO Post Aug 14, 2025 DPO Duty Enforceable Since peopleofinternet.com

Key Takeaways

What The Authority Published

On July 15, 2026, Israel's Privacy Protection Authority (PPA) published its final guidance on the Data Protection Officer (DPO) appointment obligation under Amendment 13 to the Protection of Privacy Law, 5741-1981 — the country's first statutory DPO mandate, in force since August 14, 2025. The final text supersedes a July 2025 draft and arrives after the PPA's enforcement-forbearance window has lapsed; the Authority has signaled DPO compliance as a 2026 enforcement priority.

The guidance clarifies who must appoint a DPO: public bodies and database holders, data brokers or commercial database operators covering 10,000 or more individuals, organizations conducting ongoing systematic monitoring, and controllers or processors whose core activity involves large-scale processing of sensitive data — banks, insurers, hospitals, and health funds among them.

Two Substantive Changes From The Draft

Two elements distinguish the final version from last year's draft. First, independence: a DPO cannot simultaneously serve as Head of Marketing, Head of Customer Success, CFO, IT Manager (or that manager's subordinates), or CTO — roles the PPA views as inherently conflicted because they set the very processing purposes a DPO is meant to police. Pairing the DPO role with a CISO or in-house counsel position remains permissible "in principle," but only with documented, case-specific analysis showing no conflict.

Second, and more consequential for the market: processor exposure to sensitive data is now aggregated across all clients served, not assessed contract-by-contract. A payroll or SaaS vendor running 1,000 client databases of 100 records each — none individually triggering the threshold — now counts as handling 100,000 records in aggregate, and must appoint a DPO.

The Case For This Design

The strongest argument for both changes is straightforward. GDPR's Article 37 DPO mandate, on which Amendment 13 is loosely modeled, has been undermined in parts of Europe by "DPO-in-name-only" arrangements — marketing or IT leads nominally wearing the DPO hat while continuing to set the processing policies they're supposed to check. Barring that overlap outright, rather than trusting internal self-assessment, is a defensible response to a documented failure mode elsewhere.

The aggregation rule closes a similarly real loophole. A processor that structures its business around thousands of small client contracts, each individually below a size threshold, can amass a far larger and more sensitive dataset in practice than a single large controller — while claiming none of its contracts trigger DPO obligations. Assessing exposure cumulatively matches the rule to the underlying privacy risk rather than to how a company happens to have carved up its client base.

Where The Rule Overshoots

The aggregation rule, however, doesn't distinguish between a data broker deliberately amassing profiles and a mid-size Israeli SaaS or payroll processor whose 1,000 small-business clients each hold fragmented, low-sensitivity records for unrelated purposes. Both now clear the same numeric bar and face the same governance obligation — a full-time-equivalent, independently reporting DPO — designed with consumer-data brokers in mind, not back-office vendors serving Israel's dense small-business and startup ecosystem.

That matters because Israel's tech sector runs on exactly this kind of outsourced infrastructure: HR platforms, billing processors, and cloud-adjacent SaaS tools serving hundreds of small clients apiece. A mechanical headcount-of-records test, applied without a materiality or risk-weighting filter, risks pulling a meaningful slice of that vendor layer into a compliance regime built for banks and health funds. Smaller processors without spare senior headcount face a choice between diverting scarce budget to a standalone DPO function, outsourcing the role at real cost, or exiting sensitive-data-adjacent business lines — a dynamic that tends to consolidate markets toward larger incumbents who can absorb the overhead, an odd outcome for a reform partly meant to modernize a startup-dependent economy.

The independence rule's escape valve — "documented case-by-case analysis" for DPO/CISO or DPO/counsel dual-hatting — has a similar problem at smaller scale. It's the right instinct, since blanket bans on sensible dual roles would be its own overreach. But leaving the standard undefined means every smaller, compliance-conscious firm must commission its own bespoke legal opinion to rely on an exception the PPA itself has already endorsed in principle. That's a cost the guidance could remove with a short list of presumptively acceptable configurations, reserving case-by-case review for genuine edge cases.

The Better Calibration

None of this argues against a DPO mandate, genuine independence, or an aggregation principle — all are proportionate responses to real risks the draft guidance left open. What the final text lacks is a materiality threshold that scales the aggregation rule to actual sensitivity and purpose, not just cumulative record counts, plus a phased runway or size-based carve-out for smaller processors who are the collateral catch rather than the intended target. The PPA has a full enforcement cycle ahead of it in 2026 to calibrate that in practice; how it treats the first mid-size vendor caught by aggregation, rather than a bank or broker, will show whether the rule is being applied with the proportionality Amendment 13's drafters intended.

Sources & Citations

  1. PPA Final DPO Guidance Summary — Arnon, Tadmor-Levy
  2. law.co.il: PPA Publishes Final DPO Appointment Opinion
  3. Protection of Privacy Law, 5741-1981 (WIPO Lex)
  4. Amendment 13 to the Privacy Protection Law (gov.il)
  5. IAPP: Israel Marks a New Era in Privacy Law