A DPIA (Data Protection Impact Assessment) checks a project, system, or processing activity before it starts: what data moves, who is affected, what can go wrong for people, and what you will change. This guide covers when it is required, what Israeli law actually mandates, how to run one, what the report includes, and when to consult the Authority, with notes on AI, cameras, health data, and profiling. In Israel the Privacy Protection Authority recommends a documented privacy impact review for high-risk processing. Under GDPR Article 35, when that law applies, a DPIA can be a real duty.
DPIA at a glance
- What it is: privacy impact assessment (DPIA / PIA)
- When it matters: high-risk processing for data subjects
- Legal status in Israel: Authority recommendation (no general statutory duty in Amendment 13); under GDPR Art. 35: duty when in scope and the high-risk test is met
- Focused assessment: about 3-5 weeks
- Complex assessment: about 8-12 weeks
- Typical price range: 6,000-35,000 ILS (see FAQ)
- Who runs it: DPO, external advisor, or an internal team independent of the project sponsor
- Authority consultation: if residual risk stays high (recommendation in Israel; Art. 36 duty where GDPR applies)
What a DPIA is
A DPIA is a structured process that assesses how a project, system, or processing activity affects the privacy of data subjects. It finds risks early, proposes mitigations, and records decisions. PIA (Privacy Impact Assessment) is an older parallel term. In practice it is the same job.
Do not confuse it with a database definition document under Security Regulations reg. 2, or a security risk survey under reg. 5. Those documents can feed a DPIA. They are not a DPIA.
When it is required, and what the law actually mandates
Precision matters. Israeli law has no general, explicit duty to run a DPIA, including after Amendment 13. The Authority recommends a DPIA as a central privacy risk-management tool, and in practice expects documented risk management for high-risk processing: specially sensitive data at scale; systematic monitoring of public space; automated decisions with real impact on a person (including AI); significant third-party sharing; new technologies. Sector rules or special circumstances can still require an assessment. Under GDPR, by contrast, Art. 35 is a real duty when it applies.
Watch out for online checklists that claim Amendment 13 made a DPIA mandatory for every new personal-data project. That is not what the statute says.
Amendment 13 professional guide (appointment, databases, security duties, not a DPIA mandate): https://www.gov.il/he/pages/guide_tikon13_professional
Methodological materials: https://www.gov.il/he/pages/tool_box_first_page
Authority digital privacy-risk form (screening aid, not a finished DPIA): https://mojforms.justice.gov.il/mojaemprivacyprotectionauthority/dpiaform.html
Link to GDPR
GDPR Article 35 imposes a real DPIA duty, with EDPB guidance on when high risk is presumed. An Israeli organisation that falls under GDPR should treat Art. 35 as mandatory for those processings. The same assessment can also answer the Authority’s recommended practice in Israel, so one careful document can serve both frames. In both frames, do the assessment before processing starts.
Where residual risk stays high after mitigations, GDPR Art. 36 can require prior consultation with the supervisory authority. Israel has no general statutory consultation duty of that kind; consulting the Authority remains recommended practice when residual risk is still high.
GDPR text: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679
The stages in practice
- Scope: which project, which databases, who the users are.
- Map data and flows: where from, where to, which vendors, cross-border?
- Identify risks: what can go wrong for people, at what likelihood and severity.
- Mitigations: pseudonymisation, minimisation, encryption, access control, short retention, contractual controls.
- Residual risk: after all that, is the risk acceptable? If not, plan Authority consultation where appropriate.
- Document and decide: formal report, sign-off, update date.
After mitigations are named, PETs guides are useful follow-ons for technical options: https://www.gov.il/BlobFolder/reports/guide_enhancing_technologies/en/PETs-Mongash-en.pdf
What the report includes
A solid DPIA report is often in the 20-40 page range and usually covers: system and processing description; purpose and legal basis; data-flow diagram; risk matrix; mitigations per risk; residual risk assessment; decision (proceed, change, consult); sign-off by the relevant owners; and an update date.
Consulting the Authority
When residual risk after mitigations is still high, recommended practice in Israel is to consider consulting the Privacy Protection Authority before processing starts. That is practice, not a general statutory DPIA consultation duty. Under GDPR, Article 36 can require prior consultation with the competent EU supervisory authority when residual high risk remains. Do not assume a fixed Israeli reply clock. The DPO typically prepares the pack and files through the Authority’s channels.
DPIA for AI systems
AI usually needs a deeper assessment. Beyond the usual issues, ask: explainability (can the system explain decisions?); bias (is training data representative?); human in the loop (does a person review consequential decisions?); transfers to foundation models (where is data processed, is it used for training?); prompt and log retention. Especially relevant for SaaS teams shipping AI features. PETs for AI (EN): https://www.gov.il/BlobFolder/generalpage/pets_ai/en/PETs_AI_english_accessable.pdf
DPIA for monitoring (cameras, location)
Public-space CCTV, employee monitoring, location apps, in-store behaviour analytics: these usually need a privacy impact write-up. Ask who the data subjects are, whether there is signage, whether the purpose is proportionate, retention, access control, and automated recognition (faces, plates). Each "yes" raises risk. Health organisations often need a tighter write-up for medical data at scale.
Smart-city companion from the Authority: https://www.gov.il/BlobFolder/generalpage/smart_city_guide/he/smart%20city%20guide%202020.pdf
Who should run it
With an internal DPO, they lead. Without one, an external advisor. In a small organisation, a privacy working group (project, IT, counsel) can work if the assessor is independent of the project sponsor. The project owner should not be the only reviewer. DPO vs security roles: https://dpoisrael.com/en/learn/dpo-vs-ciso/
Soft CTA
Have a project that may need a DPIA? A 30-minute call, written proposal within 48 hours when relevant.
For a standing appointment, see DPO as a Service Israel.
Book via https://dpoisrael.com/en/services/dpia/ or https://dpoisrael.com/en/contact/
If you still need to decide whether a DPO appointment is on the table: https://dpoisrael.com/en/learn/who-needs-dpo/