People mix these up because both sit near data and both talk to regulators. Under Amendment 13 they are different statutory tracks: the privacy officer (DPO) in sections 17B1–17B3, and the information-security officer in section 17B. Job titles like "CISO" often cover the security side — they are not automatic proof that the statutory 17B appointment is filled, and they do not replace a DPO.
This page is for Israeli organisations trying to staff both roles without inventing a hybrid that the law never designed.
Two different jobs
The DPO's mandate in section 17B2 is privacy compliance for personal data: advise leadership; build and oversee training; monitor compliance and propose fixes; make sure a security procedure and database definition documents reach management for approval; see that data-subject requests get handled; publish an accessible contact channel; and act as the Authority liaison. The centre of gravity is data subjects and the Privacy Protection Law.
The statutory security officer in section 17B is responsible for securing information in the body's databases. Focus: confidentiality, integrity, availability — for personal data and for other organisational information. Day-to-day that often looks like what a CISO does: controls, incidents, vendors on the tech side, testing. The overlap with the DPO is real. So is the tension — a security control that is "good cyber" can still be a privacy problem (broad employee monitoring is the classic example).
The DPO still needs enough technology to follow personal data through systems, APIs, vendors, logs, and backups — without becoming the person who runs the security stack. Fluency is required; owning infosec is not. A system can be tightly locked down and still collect too much. Processing can look fine on paper and still be poorly secured. Those two failure modes are why the roles sit in the same meetings and why collapsing them into one job title is a weak default.
Who must appoint which role
DPO — section 17B1(a). Mandatory for: a public body (or a holder of its database); a business whose main purpose is collecting personal data to transfer to others or for direct mailing, with personal data on more than 10,000 people; core activities of large-scale systematic monitoring of people; or core activity of processing specially sensitive data on a large scale (banks, insurers, general hospitals, and HMOs are named). External appointment is allowed (17B3(b)). Report to the CEO or someone directly under the CEO (17B2(c)). Resources and real involvement are required (17B2(b)). Conflict of interest is barred — for the role itself and for the reporting line (17B3(c)).
Security officer — section 17B(a). A different list: controller of five databases subject to registration or notice under 8A (or holder of five such / five for different controllers); public body; bank; insurer; credit-rating company. Section 17B(b) puts personal liability on that officer for securing those databases. That personal-liability pattern is not copied onto the DPO.
So: needing a DPO does not mean you automatically need a 17B security officer, and the reverse is also false. One appointment does not satisfy the other.
The Authority's Amendment 13 professional guide maps the privacy side here: https://www.gov.il/he/pages/guide_tikon13_professional
Statute text (including 17B and 17B1–17B3): https://he.wikisource.org/wiki/חוק_הגנת_הפרטיות
Can the same person be both?
There is no express statutory ban on combining DPO with the security officer / CISO role. The Authority's Amendment 13 materials still treat the combination as usually a poor fit: skills (deep privacy law vs deep infosec), conflict risk (the DPO is meant to oversee privacy aspects of security choices), liability asymmetry (17B(b) sits on the security officer), reporting line (DPO must reach the CEO), and capacity in large organisations.
Write the decision the way an auditor will read it: not "always illegal," not "always fine." Where section 17B already forces a security appointment, combining gets harder, not easier. If you still combine, document why, how conflicts are managed, and that both mandates can actually be performed.
The detailed appointment opinion (skills, status, conflicts) is here: https://www.gov.il/he/pages/amendment-13-26-07-26
Older organisational kits and tools live in the DPO toolbox; treat post-amendment sources as primary: https://www.gov.il/he/pages/tool_box_first_page
CEO, general counsel, CIO, and marketing leadership raise the same conflict questions the Authority flags for other dual roles — separate from the CISO question, and usually a bad default for the DPO seat.
How the work splits in practice
A mid-size org with both roles filled (often internal security + external DPO) tends to look like this:
- Mapping personal data / processing purposes → DPO leads; security consulted on systems and access.
- Security programme, patching, pen-tests → security leads; DPO consulted when controls touch people or monitoring.
- Vendor DPA / processing terms → DPO leads; security on technical annexes.
- Incident: technical containment and forensics → security; Authority notification assessment, data-subject angles, regulatory drafting → DPO, with management accountable for the organisational decision.
- Employee privacy training vs cyber training → different owners, sometimes one calendar.
- DPIA-style privacy review for a new project → DPO leads; security inputs threat and control reality.
ISO 27001 sits mainly with security. ISO 27701 (privacy extension) needs the privacy function in the room — titles alone do not finish the paperwork.
GDPR in one breath
GDPR Arts. 37–39 define the DPO. Security measures are a separate duty (Art. 32 and the organisation's infosec leadership). The Israeli split via 17B vs 17B1–17B3 is the local parallel — useful if you already run European compliance, not a copy-paste of EU titles onto Israeli filings.
After you decide who wears which hat
Document the DPO appointment (letter or external engagement), reporting line, and the public contact channel. A practical walkthrough is here: https://dpoisrael.com/en/learn/dpo-appointment-letter/
If you need an external privacy officer rather than a combined GRC fantasy title, start with DPOaaS
FAQ
Can a CISO also be the DPO? Sometimes on paper — the statute does not say "never." In most organisations that already have a real security mandate, it is a weak design. Skills, conflict, 17B(b) liability, and CEO access all pull against a casual dual hat.
Does appointing a CISO satisfy section 17B1? No. Different section, different duty list, different conflict and reporting rules.
Does the DPO carry 17B(b) personal liability for securing databases? No. That personal liability attaches to the statutory security officer under 17B(b).
Who owns a security incident? Both, on different rails. Security runs the technical response. The DPO runs the privacy/regulatory track (including whether Authority notification is required). Management owns the organisational call.
We are a small company — do we need both? Only if you fall into the statutory lists above. Many small businesses need neither as a hard duty; some need one and not the other. Guessing from headcount alone is how bad appointments happen.