A Database Definitions Document describes what the organization collects, why, where the information is stored, who uses it, to which suppliers it is transferred, and what the main risks are. The obligation to prepare it is set out in Regulation 2 of the Privacy Protection (Data Security) Regulations. It is not a registration form and it is not a website privacy policy. It is an internal document that must reflect the actual reality.
If the document states that the information is stored in Israel, but the cloud system stores backups abroad; if it indicates that there is no medical information, but employees write such information in a notes field; or if three suppliers appear in it when in practice ten suppliers have access — the document is not in order. Elegant legal drafting does not fix incorrect facts.
Who is required to prepare a Database Definitions Document?
The obligation applies to the owner of a database. Following Amendment 13, it is also appropriate to examine the responsibility of the “controller of the database” — the person who determines the purposes of processing the information or is authorized by law to process it. Before preparing a document, it is necessary to check whether the collection of information is a “database” according to the updated definition in the law.
According to the explanation of the Privacy Protection Authority regarding the duties of a database owner, it generally means a collection of personal information items processed by digital means, subject to limited exceptions. The exceptions include a collection for personal use that is not for business purposes and a certain collection that includes only name, address and contact details. Most businesses hold much more than that: purchase history, service inquiries, employee data, recordings, financial information, browsing data, photographs or evaluations. Therefore, one must not assume that the exception applies without examining the content of the database and its use.
Database registration and a Definitions Document are not the same thing
Amendment 13 to the Privacy Protection Law, which entered into force in August 2025, significantly narrowed the obligation to register databases. It did not abolish the obligation to prepare a Database Definitions Document. An organization may be exempt from registration and still be required to prepare a document, maintain data security, control suppliers and respect the rights of data subjects.
The notification obligation to the Authority is also a separate track. A database that includes information of special sensitivity regarding more than 100,000 individuals is subject, inter alia, to the obligation to notify the Privacy Protection Authority. An up-to-date copy of the Database Definitions Document is attached to the notification. The fact that a database does not reach the notification threshold does not exempt it from Regulation 2.
What must appear in the document according to Regulation 2?
The regulation requires at least seven components. The Authority publishes an official template for a Database Definitions Document, but the template is only a skeleton. Every answer must be based on an examination of systems, forms, agreements and work processes.
1. Collection activities and use of the information
It is necessary to describe how the information arrives at the organization and what is done with it. For example: information is submitted in a website form, entered into a CRM system, reviewed by a representative, transferred to the finance department and also stored in backup. Material activities such as collection, verification, cross-checking, recording, ranking, analysis, sharing, mailing, deletion or anonymization must be indicated.
The wording “the organization collects information for the purposes of its activity” is not sufficient. It does not explain what is collected, who uses it or what happens to it after collection. If an artificial intelligence system is used for transcription, classification, recommendation or decision-making, this must be stated.
2. Purposes of use of the information
Defined purposes must be formulated: provision of service, management of a customer account, billing and collection, handling of inquiries, prevention of fraud, employee management, compliance with a legal requirement or marketing. “Business needs” and “service improvement” are formulations that are too broad if it is not explained what use is made of the information.
The purposes in the document must match the collection forms, privacy notices, consents and agreements. If a form is intended for a return call to the customer and the information automatically enters a mailing list, there is a problem. The solution is not to broaden the purpose of the database after the fact, but to check whether the use is lawful and to update the process.
3. Types of information included in the database
Clear groups of information must be detailed: identification details, contact details, address, employment data, salary, financial information, medical information, location data, photographs, recordings, purchase history, IP addresses, correspondence and evaluations. Information of special sensitivity must be expressly identified, because the classification affects the level of risk, the notification obligation, the obligation to appoint a DPO and the scope of exposure in the event of a breach.
One does not examine only the structured fields in the system. Notes fields, attached documents, mailboxes, chats, recordings and local files must be examined. Sensitive information that was not planned in advance is sometimes stored in these places.
4. Transfer or use of information outside Israel
It must be indicated whether the information is stored, backed up or accessible outside Israel. A cloud service is not a geographic location. The storage region, location of backups, access by support teams, sub-processors and transfers between group companies must be examined.
When there is a transfer abroad, its purpose, destination countries, identity or type of the recipient and the legal basis for the transfer must be documented. The examination is performed against the terms of service, the data processing agreement and the actual service structure — not according to a general promise by a salesperson.
5. Processing of information by means of a holder or external supplier
Suppliers who receive access to the information must be mapped: cloud services, payroll, CRM, payment processing, mailing, support, backup, digital signature, analytics, service center and development. For each supplier it is necessary to indicate what it does, to which information it is exposed, where it processes it and whether it uses sub-processors.
Regulation 15 requires examining the risks of the engagement and regulating the supplier’s obligations in writing. The list of suppliers in the document must match data processing agreements, DP