DPO DPO Israel
Open as Markdown

DPO appointment letter in Israel

Published: May 26, 2026 · Updated: September 5, 2026

DPO appointment letter in Israel

Under Amendment 13, some organisations must appoint a Privacy Protection Officer (DPO). The statute does not dictate a form titled "appointment letter," but a signed appointment writing — or an engagement agreement for an external DPO — is how you document the role, the reporting line, and the contact channel you will publish. This page walks through what that document should reflect, how it ties to sections 17B1–17B3, and when the Authority needs DPO details on a filing.

Who must appoint

Appointment is mandatory only in the categories in section 17B1: a public body (or a holder of its database); a business whose main purpose is collecting personal data to transfer to others or for direct mailing, with data on more than 10,000 people; core activities of large-scale systematic monitoring of people; or core activity of processing specially sensitive data on a large scale (the law expressly includes banks, insurers, general hospitals, and HMOs). Security bodies have a separate internal supervisor track. If you are outside those categories, appointment is still common as good practice — it is not a universal duty for every Israeli company.

The Authority's Amendment 13 guide summarises the same map: https://www.gov.il/he/pages/guide_tikon13_professional

What the role is (so the letter matches the law)

Sections 17B2–17B3 set the job: advise leadership; build and oversee a training plan; run ongoing compliance monitoring and propose fixes; make sure a security procedure and database definition document exist and reach management for approval; handle data-subject requests; publish contact channels in an accessible, simple way; and act as the Authority liaison. The DPO needs deep privacy-law knowledge, enough tech/security understanding to do the work, and familiarity with the organisation. They may be an employee or an external provider. They report to the CEO or someone directly under the CEO. The organisation must give resources and real involvement. Conflict of interest is barred — including when one external DPO serves several bodies. This is not the same role as the information-security officer under section 17B.

The detailed appointment opinion is here: https://www.gov.il/he/pages/amendment-13-26-07-26

Statute text (17B1–17B3): https://he.wikisource.org/wiki/חוק_הגנת_הפרטיות

What to put in the appointment writing

Useful contents for an internal letter or external service agreement:

  • Who is appointing (controller/holder) and who is appointed (named person, and firm if external).
  • Effective date; internal vs external; which databases or units are covered.
  • Duties that track 17B2(a) — advise, train, monitor, definitions/security docs, data-subject requests, Authority contact.
  • Reporting line to the CEO or a direct report; access to information and resources; involvement in privacy matters.
  • Independence / conflict-of-interest language; for an external DPO, time and availability expectations.
  • The contact channel that will be published to the public (17B2(a)(4) requires accessible contact channels; it does not require publishing the DPO's personal name).
  • A clear line that the organisation remains responsible; the DPO advises and oversees and does not replace legal counsel or the security function.

A conflict-of-interest declaration is often signed alongside the appointment, especially for tenders. External DPOs sometimes carry professional liability insurance — that is practice, not a statutory duty.

Tools and older organisational kits sit in the DPO toolbox; treat the Amendment-13 opinion and guide as the primary post-amendment sources: https://www.gov.il/he/pages/tool_box_first_page

Publishing inside the organisation

Publish how to reach the DPO in a way people can actually use — intranet, email, notice board, and the public privacy policy where data subjects look. Keep a record of what you published and when. If the DPO changes, issue a new appointment, republish, update the privacy policy and vendor contact points, and record the previous DPO's end date.

When the Authority sees DPO details

Amendment 13 does not turn every appointment into an automatic standalone "we hired a DPO" notice to the public register. Where database registration (s. 9) or notice (s. 8A) applies, filings include DPO identity, contact details, and appointment date, and changes should be updated within 30 days. The public register omits the DPO's name (s. 12(b)).

Notice form: https://mojforms.justice.gov.il/mojaemprivacyprotectionauthority/noticeobligation.html

Registration form: https://mojforms.justice.gov.il/mojaemprivacyprotectionauthority/DBregistrationForm.html

A temporary non-enforcement policy, if one is still live, does not erase the statutory duty to appoint when 17B1 applies.

FAQ

Is a written letter mandatory? The law requires appointing a DPO (when 17B1 applies) and publishing accessible contact channels. A signed appointment writing or service agreement is the practical way to prove the appointment in an audit or tender — an oral "you're the DPO" usually is not.

Who signs? Typically the controller's senior authorised signatory (often CEO / chair / secretary in public or kibbutz settings). The DPO usually signs acceptance; a separate conflict declaration is common.

Can the CEO or CISO also be the DPO? Conflict and skills rules make that a bad default. The security officer role under 17B is different; personal liability patterns there do not simply copy onto the privacy DPO.

Does downloading a sample appoint us? No. Appointment is an organisational act — documentation, reporting line, resources, and publication — not a website form.

If you use a sample letter, treat it as an educational starting point, not an Authority-approved form.