Signing the appointment letter takes a day. Most of the work comes after it, and this is what the retainer covers.
Ongoing oversight. We build a plan for checking compliance across your databases, test it against what really happens in the organisation, and report findings and fixes to management. This is the heart of the DPO duties in section 17B2, and it's usually the first thing to disappear when the role exists only on paper.
Records and data mapping. Every database needs a database definition document under regulation 2 of the 2017 Security Regulations, and the DPO has to make sure it exists, together with the security procedure, and that management has approved both. We map the systems, the vendors with access and the data flows, then write or fix those documents. Where GDPR applies we also help you maintain the Article 30 records of processing, a duty that sits with the company as controller or processor. Our guide to the database definition document shows what goes into one.
DPIA. Before a new product, AI feature or major system goes live. The Authority recommends a DPIA, especially before new projects or technologies that involve personal data, and publishes a methodology for it, but Israeli law doesn't require one. Under GDPR Article 35 it's required when processing is likely to result in high risk. You can see how we run one in the DPIA guide.
Work with the Israeli Privacy Protection Authority. By law the DPO is your contact person with the Authority. We're copied on correspondence and attend meetings, and we prepare the answers with you.
Data subject requests. Access, correction and deletion requests, logged and answered on time. The DPO's contact details have to be published, so people will write to us directly.
Breach and incident response. A leaked file, or a vendor writing to say it was breached. We help you work out fast whether it's a severe security incident that has to be reported under the Security Regulations, and we stay with it through notification, communications and the post-mortem. More on our incident response service.
Training. A yearly training plan, with short sessions by role. Managers, HR and the support team each get the parts that apply to them.
Vendors. Questionnaires and processing agreements (DPAs) for suppliers who touch personal data, and transfer checks when data leaves Israel.
Behind the appointment there is a signed professional bench: privacy counsel, CISO/GRC, a DPIA analyst and a PMO. NDAs and conflict-of-interest declarations are ready from day one.