Israel’s Privacy Protection (Data Security) Regulations 2017 take effect today, setting detailed information security requirements for personal databases.
Key points
- Tiered security levels depending on database sensitivity and size.
- Security procedures, access control and logging.
- Periodic audits and penetration testing for higher security levels.
- Reporting of severe security incidents to the Privacy Protection Authority.
UK organisations with Israeli operations, or processing data for Israeli clients, should check security controls against these tiered requirements. The regulations apply to database owners and holders, including service providers processing data on their behalf, so outsourcing contracts need to reflect the required security measures and audit rights.
Source: Protection of Privacy Regulations (Data Security) 5777-2017 (Privacy Protection Authority)
Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.