DPO DPO Israel
Open as Markdown

ISO 27701 privacy management standard for organisations in Israel

Published: May 26, 2026 · Updated: September 23, 2026

ISO 27701 privacy management standard for organisations in Israel

ISO/IEC 27701 is the international standard for a Privacy Information Management System (PIMS). It gives you a structured way to run privacy work for personal data: roles, records, risk assessment, controller and processor controls, suppliers, data-subject requests, incidents, internal audit. There is also a certificate path when you want third-party attestation. It is not Israeli law, not a Privacy Protection Authority licence, and not a substitute for Amendment 13 or a DPO appointment where section 17B1 applies.

Catalogue entry: https://www.iso.org/standard/85819.html

What a PIMS actually is

A PIMS is the management system for how the organisation handles personally identifiable information as a controller, a processor, or both. In practice that means documented ownership, processing records that match reality, privacy risk assessment, controls for your own processing and for processors you use, workflows for access/correction/deletion requests, incident handling that includes the privacy track, and a cycle of internal audit and improvement.

Security work under ISO/IEC 27001 still matters. It answers confidentiality, integrity, and availability. Privacy governance answers whether processing is organised, accountable, and aligned with the roles the standard expects for controllers and processors. You can look strong on 27001 and still be thin on privacy process. Under the 2025 edition, the reverse is possible too.

2019 vs 2025: say the edition out loud

ISO/IEC 27701:2019 was written as an extension to ISO/IEC 27001/27002. Certification programmes treated an ISMS as the base; you added privacy controls on top.

ISO/IEC 27701:2025 (published around October 2025) is a standalone privacy management system standard. Certification without ISO 27001 is possible. Integration with 27001 (and other management system standards) is still common and often sensible. It is no longer framed as "you must finish 27001 first" for every programme.

A lot of Israeli vendor copy still describes only the 2019 add-on model. When you read a proposal or an RFP, check which edition they mean. Transition rules for existing 2019 certificates are set by accreditation bodies and certification schemes. Treat timelines as programme-specific, not as something this page invents.

What the certificate attests

A scoped ISO 27701 certificate is third-party evidence that, within the stated scope, the PIMS meets the standard. Enterprise buyers and tender questionnaires often ask for that shared language. It can shorten due diligence when the scope matches what the customer cares about.

It does not prove compliance with the Israeli Privacy Protection Law after Amendment 13. It does not appoint a DPO under sections 17B1-17B3. It does not satisfy GDPR Articles 37-39 where EU law applies, and it does not replace a DPIA under Article 35 when that duty is triggered. It does not block Privacy Protection Authority enforcement. Anything outside the certificate scope stays outside the certificate.

Israeli legal map for the duties that still sit next to any PIMS: the Authority's Amendment 13 guide at https://www.gov.il/he/pages/guide_tikon13_professional and the appointment opinion at https://www.gov.il/he/pages/amendment-13-26-07-26. Statute text: https://he.wikisource.org/wiki/חוק_הגנת_הפרטיות. GDPR text: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679. Older organisational kits also sit in the DPO toolbox: https://www.gov.il/he/pages/tool_box_first_page

When Israeli organisations chase it anyway

Typical reasons are commercial, not statutory: SaaS and other processors selling to enterprise; questionnaires that list ISO 27701 next to SOC 2; public or regulated buyers who want management-system evidence; EU or UK customers who want privacy-management attestation alongside local-law work.

Use it as supporting management evidence, next to data mapping, policies, a DPO where 17B1 applies, a statutory security officer where section 17B applies, and DPIA-style reviews where the risk warrants them. The certificate does not swallow those jobs.

DPO, security officer, and PIMS roles

Keep the Israeli split clear. Section 17B is the statutory information-security officer track (with personal responsibility for securing databases under 17B(b) when that appointment applies). That is often the CISO function. Sections 17B1-17B3 are the privacy officer (DPO): advise leadership, training, monitoring, ensuring definition and security procedure documents, data-subject contact channel, Authority liaison, independence and conflict rules.

A PIMS needs privacy ownership and security ownership in the room. ISO titles on an org chart do not merge those statutory roles. Holding a 27701 certificate does not appoint a DPO and does not satisfy 17B. Dual-hat questions still run through 17B3(c) and the Authority's appointment guidance. Same analysis as on the DPO vs CISO page: https://dpoisrael.com/en/learn/dpo-vs-ciso/

Where a DPO helps a 27701 programme: defining scope honestly, mapping Israeli and EU duties into the control set, owning the data-subject and Authority interface, and flagging gaps between certificate scope and what the law still requires. That is oversight and translation, not a claim that the cert closes those gaps.

If you are appointing or documenting the DPO role itself, start from the appointment writing guide: https://dpoisrael.com/en/learn/dpo-appointment-letter/

Practical path (without a branded framework)

Most programmes still look like this: decide controller vs processor scope; map processing and suppliers; set privacy risk assessment; build the procedures the standard expects for requests, retention, processors, and incidents; run internal audit; then engage an accredited certification body. Builders and auditors should be separate. Conflict of interest is real if the same shop writes the system and issues the certificate.

Costs and timelines vary by size, sites, whether 27001 is already live, and which edition you target. Treat published price ranges on marketing pages as rough orientation only; get a written quote against your scope.

For ongoing privacy officer capacity rather than a certification project alone, see DPO as a Service

FAQ

Does ISO 27701 replace Amendment 13 compliance? No. The law still governs processing, notice and registration where they apply, security regulations, and DPO duties where 17B1 applies. The standard is a management system and optional attestation.

Do we still need ISO 27001 first? Under the 2019 edition, certification was built as an extension to 27001. Under 2025, standalone PIMS certification is possible. Many organisations still run both together because security and privacy programmes share suppliers, incidents, and audit calendars.

If we are certified, do we still need a DPO? If section 17B1 applies, yes. The statute does not waive appointment because you hold a certificate. The certificate also does not create the appointment by itself.

Does the Privacy Protection Authority treat ISO 27701 as proof of compliance? There is no published Authority rule that equates the certificate with compliance. Keep it as buyer/auditor evidence, not as a fine shield.

Who issues the certificate? An accredited certification body after audit. Advisory work that builds the PIMS should stay separate from the body that certifies it.

How does this relate to SOC 2? Different market languages. US enterprise often leads with SOC 2; many EU buyers recognise ISO management system certificates. Some organisations carry both. Neither replaces Israeli statutory duties.