DPO DPO Israel

DPO as a Service (DPOaaS) in Israel

A named Data Protection Officer for your organisation, appointed in writing and working with you every month under Amendment 13 and, where it applies, GDPR.

DPO as a Service (DPOaaS) is a formally appointed, outsourced Data Protection Officer, provided to your organisation as an ongoing service. You get a named DPO on the appointment letter who carries the Amendment 13 duties month after month, without opening an internal position.

We usually start with a short project phase for gap work and database mapping, then move to a monthly retainer. We work alongside your CISO, or bring GRC support if you don't have one. When the organisation needs someone physically in the building, we add on-site days.

Led by Ofir Srusi, DPO (Bar-Ilan University certification). A boutique firm covering privacy counsel, CISO/GRC support and Authority-facing work under one roof.

Boutique privacy compliance work session with documents, laptop and risk planning
Premium Privacy Practice

What is DPO as a Service (DPOaaS)?

DPO as a Service (DPOaaS) is an outsourced Data Protection Officer appointment run as a continuing service. An external privacy specialist is formally named as your DPO, reports to management and carries the legal duties of the role: advice, training, compliance monitoring, making sure data subject requests are handled, and acting as contact person with the Privacy Protection Authority.

Both laws that matter to Israeli companies allow this. Section 17B3 of the Privacy Protection Law says the DPO can be someone who isn't an employee of the organisation, and GDPR Article 37(6) allows a DPO to work under a service contract. So when people search for the DPOaaS meaning, the short version is an outside DPO with the full legal role, paid as a service.

What our DPOaaS includes

Signing the appointment letter takes a day. Most of the work comes after it, and this is what the retainer covers.

Ongoing oversight. We build a plan for checking compliance across your databases, test it against what really happens in the organisation, and report findings and fixes to management. This is the heart of the DPO duties in section 17B2, and it's usually the first thing to disappear when the role exists only on paper.

Records and data mapping. Every database needs a database definition document under regulation 2 of the 2017 Security Regulations, and the DPO has to make sure it exists, together with the security procedure, and that management has approved both. We map the systems, the vendors with access and the data flows, then write or fix those documents. Where GDPR applies we also help you maintain the Article 30 records of processing, a duty that sits with the company as controller or processor. Our guide to the database definition document shows what goes into one.

DPIA. Before a new product, AI feature or major system goes live. The Authority recommends a DPIA, especially before new projects or technologies that involve personal data, and publishes a methodology for it, but Israeli law doesn't require one. Under GDPR Article 35 it's required when processing is likely to result in high risk. You can see how we run one in the DPIA guide.

Work with the Israeli Privacy Protection Authority. By law the DPO is your contact person with the Authority. We're copied on correspondence and attend meetings, and we prepare the answers with you.

Data subject requests. Access, correction and deletion requests, logged and answered on time. The DPO's contact details have to be published, so people will write to us directly.

Breach and incident response. A leaked file, or a vendor writing to say it was breached. We help you work out fast whether it's a severe security incident that has to be reported under the Security Regulations, and we stay with it through notification, communications and the post-mortem. More on our incident response service.

Training. A yearly training plan, with short sessions by role. Managers, HR and the support team each get the parts that apply to them.

Vendors. Questionnaires and processing agreements (DPAs) for suppliers who touch personal data, and transfer checks when data leaves Israel.

Behind the appointment there is a signed professional bench: privacy counsel, CISO/GRC, a DPIA analyst and a PMO. NDAs and conflict-of-interest declarations are ready from day one.

Our Services

Services around the DPO role

01

Formal DPO appointment under Amendment 13, in tiers that match your size.

02

Risk analysis for new products and AI systems that process personal data.

03

Gap assessment and alignment with the 2017 Security Regulations.

04

Real-time support, Authority notification when a severe incident requires it, communications, post-mortem.

05

Mapping, GDPR Article 30-style records where relevant, and database definition documents under the 2017 Regulations.

06

Vendor questionnaires, processing agreements, transfer impact assessments for cross-border vendors.

07

Combined CISO and DPO support, ISO 27001/27701 readiness, SOC 2 support. See GRC + privacy.

08

Ready packet: CV, SLA, conflict declarations for municipalities, CHE, regional clusters. See public tender response.

DPOaaS vs an in-house DPO

Start with the workload. A mid-sized company with an HR system, a CRM, a few databases and a list of vendors has real DPO work, but rarely enough to fill the week of a senior privacy specialist who also understands technology. Hiring one means a full senior salary, a long search for a profile that is still hard to find in Israel, and starting over when that person leaves. With DPOaaS you pay for the scope you actually have, and the documents and history stay with the service.

Independence is the second reason, and the law is specific here. The DPO reports directly to the CEO, or to someone who reports directly to the CEO. The DPO also can't hold another role, or report to an officer, in a way that could create a conflict of interest. The Authority's final opinion says the DPO can't hold, or report to, a role that sets policy on processing personal data. It names marketing, customer, finance and CTO roles as frequent conflicts, and says the head of information systems (IT) is conflicted as a rule, along with anyone who reports to them. An outside DPO has no budget or roadmap of their own to defend, so it's easier to raise the awkward point in a management meeting.

Then the CISO question, which comes up in a lot of first calls. Israeli law doesn't ban the CISO from also being the DPO. The Authority's final opinion says the two roles are different in substance, that combining them raises real questions, and that an organisation that does it needs a case-by-case assessment with documented reasoning. It points to three issues: the DPO needs deep knowledge of privacy law, which a security officer doesn't necessarily have; in large organisations the security role alone demands full attention; and the DPO must report to the CEO or someone directly under the CEO, which a CISO often doesn't. Our usual setup is your CISO on security and us on privacy, working from the same risk list. There's a longer comparison in DPO vs CISO.

To be fair to the other side, the Authority's final opinion says there is usually an advantage in a full-time in-house DPO, and that the employment model and scope should be decided for each organisation. Where you process a lot of data across many databases, an internal DPO may be the right call, and we'll tell you. We can also support that person instead of replacing them.

DPOaaS vs an in-house DPO
Topic DPOaaSIn-house DPO
Scope and cost You pay for the scope you actually have.A full senior salary, and a long search for a profile that is still hard to find in Israel.
When someone leaves The documents and history stay with the service.You start over when that person leaves.
Independence An outside DPO has no budget or roadmap of their own to defend.The DPO can't hold another role, or report to an officer, in a way that could create a conflict of interest. The Authority names marketing, customer, finance and CTO roles as frequent conflicts, and says the head of information systems (IT) is conflicted as a rule.
Workload A mid-sized company rarely has enough DPO work to fill the week of a senior privacy specialist.Where you process a lot of data across many databases, an internal DPO may be the right call.
What the Authority says The employment model and scope should be decided for each organisation.There is usually an advantage in a full-time in-house DPO.

Who must appoint a DPO in Israel, and when GDPR adds one

Amendment 13 to the Privacy Protection Law came into force on 14 August 2025. Section 17B1 makes a DPO mandatory for four groups:

  • Public bodies, and anyone who holds a database for a public body. That second part catches the IT, SaaS or outsourcing vendor running the system. Security bodies are excluded and have their own regime, with an internal privacy supervisor.
  • A controller of a database whose main purpose is collecting personal data in order to pass it to others as a business or for payment, direct mail services included, when the database holds personal data on more than 10,000 people. This category covers controllers, not holders.
  • Controllers or holders whose main activities require ongoing, systematic monitoring of people at large scale, for example tracking behaviour, location or actions. Mobile operators and search engines are the examples the law gives.
  • Controllers or holders whose main activity includes large-scale processing of specially sensitive data. The law names banks, insurers, general hospitals and HMOs as examples.

"Large scale" has no fixed number. The law points to how many people are involved (or their share of a given population), the amount and types of data, how long and how often it's processed, how long it's kept, and the geographic reach. The Authority's final opinion on DPO appointment, published in July 2026, is the document it says it will rely on in enforcement, so read it if you're close to the line.

Outside these groups, appointing a DPO is voluntary. Some organisations appoint one anyway because a customer, a tender or an investor asks for it. Our guide on who must appoint a DPO goes through each category with examples, or tick the boxes in the check below.

Israeli companies that fall under GDPR

GDPR reaches Israeli companies with no EU office when they offer goods or services to people in the EU, or monitor their behaviour there (Article 3(2)). That alone doesn't mean you need a DPO. Article 37(1) requires one only for public authorities, for organisations whose core activities involve regular and systematic monitoring of people on a large scale, and for those whose core activities involve large-scale processing of special categories of data or data about criminal convictions. A B2B SaaS company can be fully under GDPR and still meet none of those tests.

When a DPO is required, Articles 37 to 39 let you use an external one on a service contract, as long as the DPO has expert knowledge, is involved early, gets the resources needed, takes no instructions on how to do the tasks, and reports to the highest management level. The DPO's contact details are published and sent to the supervisory authority.

A separate role often gets mixed up with this. Under Article 27, a company covered by Article 3(2) usually has to appoint an EU representative, established in an EU member state where its data subjects are. The exemption is narrow: it covers processing that is occasional, does not include large-scale processing of special-category or criminal-offence data, and is unlikely to result in a risk to people's rights and freedoms. The representative and the DPO are two different appointments.

Smart Check

Do you need a DPO?
30-second check

Tick what applies. The answer updates from Amendment 13 categories. No form, no email.

Want more depth? The full calculator (2 min) or the who must appoint a DPO guide.

Tick what applies. The answer will appear here.

Initial indication only, not a legal opinion.

What drives DPO as a Service cost

We don't publish a single price for DPOaaS, because two organisations with the same headcount can need very different amounts of work. These are the things that move it:

  • How many databases you have, and how sensitive they are. Health, financial, biometric data and data about minors sit at the top.
  • Public body or private company. Public bodies bring tender terms, more reporting and more people around the table.
  • The number and depth of DPIAs in a typical year, especially if you ship AI features.
  • Vendor load, meaning how many suppliers touch personal data and need questionnaires or DPAs.
  • On-site days, if someone has to be there in person.
  • Whether GRC or CISO support is bundled with the DPO role.

Our outsourced DPO packages show how these usually group together, from a small organisation with a few main databases up to a local authority or a healthcare body. After the first call we send a written proposal for your actual scope.

How to choose a DPOaaS provider

I'd ask these questions before signing with anyone, us included.

Who is actually named? The appointment letter should carry one person's name, and that person should be the one who shows up to your management meetings. Ask what happens when they're on holiday, and what happens if they leave the firm.

Ask to see real output. A redacted quarterly report, a database definition document, a DPIA. If all you're shown is a slide deck, that's probably what you'll get each quarter.

Check the Israeli depth. Many DPO offerings are built on GDPR templates. Amendment 13, the 2017 Security Regulations and the way the Authority works day to day (in Hebrew) are different, and your documents have to match them.

Look for conflicts. A provider that also sells you the security tools, or audits the controls it built for you, is checking its own work. We prepare clients for ISO and SOC 2 audits and leave the audit itself to someone independent.

Ask how they would handle a letter from the Authority arriving tomorrow morning. You'll hear quickly whether they have done it before.

And check the exit. The documents, logs and database map are yours, and they should be handed over cleanly if you move on.

Sectors

Who this is for

Outsourced DPO work for organisations that process personal data under Amendment 13, across sectors with different pressure points:

Current updates and opinions of the Privacy Protection Authority

Privacy Authority Q&A on using voter registry data

Israel’s Privacy Protection Authority published a Q&A on using personal data from the voter registry, written for parties and factions and for the public. The data may be used only to run in the elections and to contact voters. Any other use, or passing it on, is prohibited, and once the permitted period ends the data has to be deleted so it can’t be recovered. Direct mail must say who sent it and where the data came from, and give recipients a way to ask to be removed. Complaints go to the Authority. If you advise a party or a campaign vendor ahead of the elections, check now what the data is actually used for, who receives it and how it’s secured, and when and how it gets deleted. Removal requests need a working process too.

ILS 64,000 fine on Beit Shemesh municipality after GIS data exposure

Israel’s Privacy Protection Authority imposed a final ILS 64,000 administrative fine on Beit Shemesh municipality after welfare and medical data of about 4,600 residents was exposed through the municipal website (GIS; incident reported 20 August 2025). The Authority found Security Regulations breaches: a support vendor with ongoing access was not listed as a holder in the database definitions document, and the security procedure did not cover contracting with external parties that have database access. The amount was cut 20% from ILS 80,000 under the Fifth Schedule (no prior fines on the same provisions in the previous five years). For municipalities and any org with IT vendors on live databases: holders need to be documented, and the vendor relationship needs to sit in the security procedure.

CPAs tendered as assisting parties for horizontal supervision

The Authority tendered CPA firms as assisting parties in horizontal supervision (s. 23yz), under its instructions and with confidentiality and data-protection duties. A horizontal review can come from an external accountant, not only from an Authority official.

Final opinion: DPO appointment under Amendment 13

The final opinion on appointing a DPO under Amendment 13 replaces the 2025 draft: duty scope, qualifications, status and roles — and the Authority will rely on it in enforcement. This is the document that now defines section 17b1 in practice.

Methodology

Three steps

01

Diagnostic call and gap assessment

Initial mapping of personal-data assets and organisation-specific regulatory needs. 30 minutes, free, no commitment.

02

Formal appointment and foundation

Appointment documentation, core policies, SLA for ongoing response. Typically within about 30 days, depending on the organisation's pace.

03

Ongoing management and periodic review

Audits, employee training, support on incidents and regulatory contact. Quarterly and annual reporting as agreed.

FAQ

Frequently asked questions

What does DPOaaS mean?

DPOaaS stands for DPO as a Service, short for Data Protection Officer as a Service. It means a formally appointed outside DPO who does the role for your organisation on an ongoing basis, under a service agreement. In Israel that covers the Amendment 13 duties, and the GDPR duties too where GDPR applies.

Can the CISO also be the DPO?

Israeli law doesn't forbid it outright. The Privacy Protection Authority's final opinion says combining the roles raises serious questions and needs a documented, case-by-case assessment. The DPO needs deep knowledge of privacy law, must report to the CEO or someone directly under the CEO, and can't hold a role that creates a conflict of interest. In large organisations the security role usually needs a person's full attention. GDPR also allows a DPO to take on other tasks only when they don't create a conflict of interest (Article 38(6)).

Does a DPO need to be certified?

No certificate is required by law, in Israel or under GDPR. Section 17B3 asks for the knowledge and skills the job needs, including deep knowledge of privacy law, a fair understanding of technology and information security, and knowledge of the organisation's field. GDPR Article 37(5) talks about professional qualities and expert knowledge of data protection law and practice. A recognised course helps you show that knowledge to management, a tender committee or the Authority. Ofir holds the Bar-Ilan University DPO certification.

What are the key DPO responsibilities?

Under section 17B2 of the Israeli law, the DPO:
  • advises management and employees, and prepares and oversees a training plan
  • builds a plan for ongoing compliance checks, follows up that it's carried out, and reports findings and suggested fixes to management
  • makes sure the security procedure and the database definition documents exist and have been approved by management
  • makes sure requests from data subjects are handled, including access and correction
  • acts as the organisation's contact person with the Privacy Protection Authority.
GDPR Article 39 has a similar list, and adds advice on DPIAs where requested and monitoring how they're carried out.

Is DPOaaS enough for GDPR?

For the DPO duty itself, yes, provided the external DPO has the expertise and independence that Articles 37 and 38 require. GDPR expressly allows a DPO on a service contract. Three things to keep in mind. The company stays responsible for compliance, and the DPO advises and monitors. If you fall under Article 3(2), you will probably also need an EU representative under Article 27, which is a separate role based in the EU. We coordinate that through partners there. And GDPR has its own paperwork (Article 30 records, lawful basis, transfer terms), even where it overlaps with the Israeli documents.

How much does DPO as a Service cost?

It depends on scope: the number and sensitivity of your databases, public or private sector, DPIAs, vendors, on-site days, and whether GRC support is bundled. You can see what each tier covers on our DPO packages and tiers page. Every proposal is written within 48 hours of the first call.

What is the difference between a DPO and a CISO?

The DPO handles privacy: Amendment 13, GDPR, DPAs, DPIAs and data subject rights. The CISO handles security, such as penetration tests, secure coding, encryption and access management. The roles overlap in places and work best side by side. In most mid-sized organisations we see an internal CISO with an outsourced DPO. In combined public tenders we often run one GRC and privacy engagement that covers both.

Do you have public tender experience?

Yes. We are tender-ready from day one, with framework response documents, CVs for the chief DPO and the bench, a bilingual company profile, a sample SLA, conflict-of-interest declarations, active professional liability and cyber insurance, and bookkeeping and tax certificates. More on our public tender response.

How long is the commitment?

An annual contract with a monthly exit option. There are no exit penalties. If the service stops being useful to you, you can leave.

How do we start?

Book a free 30-minute intro call by Zoom or phone. I'll tell you where the organisation stands against Amendment 13 and, if it makes sense, send a written proposal within 48 hours. If you'd like a quick self-check first, try the DPO obligation calculator.

What does a DPO appointment include?

A named individual (only a person can be appointed DPO, even when the contract runs through a company, and they must be available in person as the role requires), a direct reporting line to the CEO (or to someone who reports directly to the CEO), published contact details, and the duties listed in section 17B2. The law allows the DPO to be an outside provider. There's a practical example in our guide to the DPO appointment letter.
Contact

Get in touch.
Intro call.

Intro call. Tell us what the organisation does with personal data; we will say whether a DPO appointment is on the table and what a sensible first step looks like.

Book a free 30-minute intro call
Phone
054-871-9609

+972 54-871-9609

Location

Kibbutz Gevaram Israel

Sun-Thu 09:00-18:00
Hebrew and English
Free 30-minute intro call