DPO DPO Israel
Open as Markdown

Database Definition Document — Full Guide

Published: May 26, 2026 · Updated: August 20, 2026

A Database Definitions Document describes what the organization collects, why, where the information is stored, who uses it, to which suppliers it is transferred, and what the main risks are. The obligation to prepare it is set out in Regulation 2 of the Privacy Protection (Data Security) Regulations. It is not a registration form and it is not a website privacy policy. It is an internal document that must reflect the actual reality.

If the document states that the information is stored in Israel, but the cloud system stores backups abroad; if it indicates that there is no medical information, but employees write such information in a notes field; or if three suppliers appear in it when in practice ten suppliers have access — the document is not in order. Elegant legal drafting does not fix incorrect facts.

Who is required to prepare a Database Definitions Document?

The obligation applies to the owner of a database. Following Amendment 13, it is also appropriate to examine the responsibility of the “controller of the database” — the person who determines the purposes of processing the information or is authorized by law to process it. Before preparing a document, it is necessary to check whether the collection of information is a “database” according to the updated definition in the law.

According to the explanation of the Privacy Protection Authority regarding the duties of a database owner, it generally means a collection of personal information items processed by digital means, subject to limited exceptions. The exceptions include a collection for personal use that is not for business purposes and a certain collection that includes only name, address and contact details. Most businesses hold much more than that: purchase history, service inquiries, employee data, recordings, financial information, browsing data, photographs or evaluations. Therefore, one must not assume that the exception applies without examining the content of the database and its use.

Database registration and a Definitions Document are not the same thing

Amendment 13 to the Privacy Protection Law, which entered into force in August 2025, significantly narrowed the obligation to register databases. It did not abolish the obligation to prepare a Database Definitions Document. An organization may be exempt from registration and still be required to prepare a document, maintain data security, control suppliers and respect the rights of data subjects.

The notification obligation to the Authority is also a separate track. A database that includes information of special sensitivity regarding more than 100,000 individuals is subject, inter alia, to the obligation to notify the Privacy Protection Authority. An up-to-date copy of the Database Definitions Document is attached to the notification. The fact that a database does not reach the notification threshold does not exempt it from Regulation 2.

What must appear in the document according to Regulation 2?

The regulation requires at least seven components. The Authority publishes an official template for a Database Definitions Document, but the template is only a skeleton. Every answer must be based on an examination of systems, forms, agreements and work processes.

1. Collection activities and use of the information

It is necessary to describe how the information arrives at the organization and what is done with it. For example: information is submitted in a website form, entered into a CRM system, reviewed by a representative, transferred to the finance department and also stored in backup. Material activities such as collection, verification, cross-checking, recording, ranking, analysis, sharing, mailing, deletion or anonymization must be indicated.

The wording “the organization collects information for the purposes of its activity” is not sufficient. It does not explain what is collected, who uses it or what happens to it after collection. If an artificial intelligence system is used for transcription, classification, recommendation or decision-making, this must be stated.

2. Purposes of use of the information

Defined purposes must be formulated: provision of service, management of a customer account, billing and collection, handling of inquiries, prevention of fraud, employee management, compliance with a legal requirement or marketing. “Business needs” and “service improvement” are formulations that are too broad if it is not explained what use is made of the information.

The purposes in the document must match the collection forms, privacy notices, consents and agreements. If a form is intended for a return call to the customer and the information automatically enters a mailing list, there is a problem. The solution is not to broaden the purpose of the database after the fact, but to check whether the use is lawful and to update the process.

3. Types of information included in the database

Clear groups of information must be detailed: identification details, contact details, address, employment data, salary, financial information, medical information, location data, photographs, recordings, purchase history, IP addresses, correspondence and evaluations. Information of special sensitivity must be expressly identified, because the classification affects the level of risk, the notification obligation, the obligation to appoint a DPO and the scope of exposure in the event of a breach.

One does not examine only the structured fields in the system. Notes fields, attached documents, mailboxes, chats, recordings and local files must be examined. Sensitive information that was not planned in advance is sometimes stored in these places.

4. Transfer or use of information outside Israel

It must be indicated whether the information is stored, backed up or accessible outside Israel. A cloud service is not a geographic location. The storage region, location of backups, access by support teams, sub-processors and transfers between group companies must be examined.

When there is a transfer abroad, its purpose, destination countries, identity or type of the recipient and the legal basis for the transfer must be documented. The examination is performed against the terms of service, the data processing agreement and the actual service structure — not according to a general promise by a salesperson.

5. Processing of information by means of a holder or external supplier

Suppliers who receive access to the information must be mapped: cloud services, payroll, CRM, payment processing, mailing, support, backup, digital signature, analytics, service center and development. For each supplier it is necessary to indicate what it does, to which information it is exposed, where it processes it and whether it uses sub-processors.

Regulation 15 requires examining the risks of the engagement and regulating the supplier’s obligations in writing. The list of suppliers in the document must match data processing agreements, DP

Frequently asked questions

What is a Database Definitions Document?

A Database Definitions Document is an internal document that describes the database and the manner of its use: what information is collected, for what purposes, who uses it, whether it is transferred to suppliers or abroad, what the security risks are, and who the responsible office holders are. The obligation to prepare the document is set out in Regulation 2 of the Privacy Protection (Data Security) Regulations, 5777–2017. It is not a registration form and it is not a website privacy policy. The document must reflect the actual activity and be accurate enough to enable control over the database.

Who is required to prepare a Database Definitions Document?

Every owner of a database is required to prepare a Database Definitions Document according to Regulation 2. The obligation applies both to a database at a basic security level and to a database managed by an individual. A database managed by an individual enjoys reliefs in some of the security requirements, but is not exempt from a Database Definitions Document. The obligation is also not dependent on registration of the database or on the appointment of a DPO. Therefore, before deciding that there is no need for a document, it is necessary to check whether the organization’s collection of information is considered a “database” according to the updated definition in the law.

What must a Database Definitions Document include according to Regulation 2?

Regulation 2 requires including at least seven subjects: the activities of collecting the information and using it; the purposes of use; the types of information in the database; transfer of information or use of it outside Israel; processing of information by means of a holder or external supplier; the main risks of harm to the security of the information and the manner of dealing with them; and the names of the manager of the database, the holder, and the information security officer, if appointed. In practice it is desirable also to document the systems of the database, the groups of data subjects, the number of permission holders, the retention periods, the security level, and the responsible business factor.

Is there an official template for a Database Definitions Document?

Yes. The Privacy Protection Authority published an official template for a Database Definitions Document. The template is a starting point, not a document that is filled in automatically. Before filling it in, it is necessary to map the systems, the forms, the suppliers, the information flows, the transfers abroad, and the actual risks. General answers such as “use for the needs of the business” or “the information is secured in the cloud” are not sufficient. A DPO or privacy consultant can manage the mapping and review the result, but the process owners and management must provide accurate information and make the required decisions.

How often must a Database Definitions Document be updated?

The document must be updated every time a significant change is made in the database, for example addition of a type of information, change of purpose of use, transition to a new system, engagement with a new supplier, transfer of information abroad, or a security incident. In addition, it is necessary to examine every year, by 31 December, whether an update is required following technological, organizational, or security incident changes. Once a year it is also necessary to check whether more information than required for its purposes is retained in the database. It is recommended to document the date of the examination and the conclusions even when no change was made in the document.

Did Amendment 13 abolish the obligation to prepare a Database Definitions Document?

No. Amendment 13 significantly narrowed the obligation to register databases, but did not abolish the obligation to prepare and maintain a Database Definitions Document. Even a database that is not required to be registered may be subject to Regulation 2 and to the other data security requirements. The amendment also established a notification obligation regarding certain databases that include information of special sensitivity regarding more than 100,000 individuals, as well as an obligation to appoint a DPO for certain types of organizations. Registration, notification to the Authority, appointment of a DPO, and a Database Definitions Document are separate obligations that must each be examined on its own.