Under Amendment 13 to the Israeli Privacy Protection Law (section 17B1 of the Law), the obligation to appoint a Data Protection Officer (DPO) applies to five categories of organizations. If you fall into one — required. If not — recommended. Here is the full breakdown — and if external fits, see DPO as a Service.
Five mandatory DPO categories — quick answer
- 1. Public bodies: Ministries, municipalities, regional councils, health funds, public hospitals
- 2. Holders: Anyone processing data on behalf of a public body (SaaS, outsourcing)
- 3. Data brokers: Principal occupation = data trading + over 10,000 records
- 4. Systematic monitoring: At large scale — profiling, location tracking, AI decisioning
- 5. Large-scale sensitive data: Medical, financial, minors, biometric, genetic, beliefs
Source: Israeli Privacy Protection Authority guidance on DPO appointment, July 2025
01
Public bodies
Government ministriesLocal authoritiesRegional and local councilsMunicipal corporationsHealth funds (kupot cholim)Public hospitalsTax AuthorityNational Insurance Institute
Note: The full list is in the schedule to the law. A public body must appoint a DPO regardless of size.
02
Holders of personal data on behalf of public bodies
SaaS vendors serving municipalitiesOutsourcing providers to ministriesSoftware suppliers to health fundsExternal call centers for citiesTax advisors processing data for public bodies
Note: Even if the company is privately owned — the moment it processes data on behalf of a public body, it is in scope.
03
Data brokers
Data brokerage companiesDirect-mail systems that sell listsMarketing data aggregators selling to commercial clientsData-driven advertising platforms
Note: Two conditions: principal occupation is data brokerage, and more than 10,000 records held.
04
Systematic large-scale monitoring
Profiling and advertising platformsTransport and location appsSmart-IoT companiesLarge-scale employee monitoringCity-scale CCTV systemsAI for automated decisions about people
Note: Test: systematic + large scale. Spot-monitoring does not qualify.
05
Large-scale processing of sensitive personal data
Banks and credit companiesInsurance companiesLarge private healthcare systems (clinic chains, labs)Large educational institutionsHR systems at large organizationsFintech platforms
Note: "Special-sensitive data": health, mental, genetics, biometrics, religion, sexual orientation, criminal record, salary. "Large scale" — typically hundreds of thousands of records and up, but judgment applies.
After you confirm the obligation — next steps
If your organization falls into one of the categories, formalize the appointment with a DPO appointment letter, then start with an Amendment 13 gap analysis. Sector-specific paths: DPO for local authorities and DPO for nonprofits.
Not sure? Use the calculator.
5 questions, under 3 minutes, and you’ll know whether you need a DPO. No email required.