Any organization, Israeli or foreign, that collects, stores or processes personal data belonging to individuals in Israel, regardless of where the organization itself is based.
Data breach notification to the Privacy Protection Authority, expanded data-subject rights, database registration updates, and materially increased penalties for non-compliance.
Security controls must now be demonstrably mapped to specific data classes, with evidence trails the regulator can request directly, not just an internal policy document.
Data-flow mapping, database classification review, breach-response readiness test, and a gap analysis against the Authority's current enforcement guidance.
Map data flows and databases; identify regulated personal data.
Close control gaps; update breach-response and notification procedures.
Document controls and maintain an audit-ready evidence trail.
Database registration records, data-processing agreements, breach-response logs, and documented data-subject request handling, all reviewable on demand by the Privacy Protection Authority.
Treating this as a one-time compliance project rather than an ongoing obligation; assuming GDPR compliance automatically satisfies Amendment 13 (the two regimes overlap but are not identical); under-scoping which databases count as "regulated."
See exactly where your data handling stands against Amendment 13 before a regulator asks.
Request a Gap Assessment →