Israeli Legislation.com

Credit Data Rules (Information Security), 5779-2018

כללי נתוני אשראי (אבטחת מידע), תשע"ט-2018

Published: 2018-11-25Consolidated Hebrew text as of 2026-09-15 · Last amended 2021-08-30
Premium
Unofficial English translation — for reference only. It may contain errors or omissions and cannot be relied on as a legal text. Only the Hebrew text published in Reshumot is legally binding.More

This English text was translated from the official Hebrew using a range of translation tools, and it undergoes ongoing checks and updates. It is not a certified translation.

Despite these checks, it may contain errors, omissions, or imprecise renderings of legal terminology and cross-references, and it may not yet reflect the latest amendments. It cannot be relied upon as a legal text.

The Hebrew text as published in Reshumot (ספר החוקים) and on the Knesset website is the sole authoritative and legally binding version. In any discrepancy, the Hebrew text prevails.

This translation is provided for informational purposes only and does not constitute legal advice. For use in legal proceedings, request a certified Expert Legal Opinion.

By virtue of my authority under section 60(c) of the Credit Data Law, 5776-2016 (hereinafter – the Law), and with the consent of the Minister of Justice, I hereby prescribe these Rules:

Manner of Collection and Recording of Information by an Information Source for the Purpose of its Transfer to the Database§

1.
(a)An information source shall appoint a professional person who shall be responsible for the collection, recording and reporting of information to be transferred to the database in accordance with the directions of the Commissioner; such a professional person –
(1)shall be a senior employee in the organisation;
(2)shall possess qualifications in the field of information collection and recording in a manner that enables personal responsibility to be imposed upon that person;
(3)shall be subject to rules for the preservation of that person's professional independence and for the prevention of conflicts of interest, which shall be determined by the information source;
(4)shall act in coordination with the person responsible for information security of the information source in all matters relating to information security aspects, as well as with other persons within the information source who are relevant to the performance of that person's role.
(b)An information source shall operate a system for the collection of information to be transferred to the database in a manner that ensures the preservation of its integrity, reliability, currency and availability, including, inter alia, through the implementation of access permissions, accepted security measures that will ensure the protection of the organisation's information systems, and appropriate controls and audits.
(c)The information systems used by the information source for the purpose of transferring information to the database shall be reliable and shall enable the preservation of business continuity such that the quality of the information and the ability to report to the database are not materially impaired.
(d)An information source shall examine, from time to time, and upon the occurrence of technological, business, organisational and regulatory changes or information security incidents, the need to update the level of security of the information systems used by the information source for the purpose of transferring information to the database.
(e)The information source shall verify, once a year, that the information it transfers to the database does not contain information that it is not required to transfer to the database under the Law.
(f)Where an information source discovers a defect or malfunction that has a material impact on the credit data sharing system, it shall report thereon to the Commissioner immediately and shall also report on the steps it took following the incident, including in accordance with the directions of the Commissioner.

Manner of Transfer of Information to the Database§

2.
(a)The database manager shall identify the reporting information source as an information source that is obligated or permitted to report to the database under the Law.
(b)The transfer of information from the information source to the database shall be carried out in a manner that prevents harm to the reliability and integrity of the data, or their exposure to the knowledge or use of an unauthorised party, and shall be encrypted in a manner to be defined by the database manager; the database manager shall maintain control over the process of transferring information to the database and shall verify that it is transferred to the database, all in accordance with the directions of the Commissioner.
(c)The database manager shall maintain control over the quality of input and the integrity of information transferred to the database and shall notify the reporting information source of erroneous or defective information discovered during the input process or of any other malfunction identified.
(d)The database manager shall report to the Commissioner on defects as referred to in subsections (b) and (c); the Commissioner shall act to clarify the defects with the information source and to provide directions to the information source for their rectification.

Manner of Storing Information in the Database, Using It and Securing It§

3.
(a)For the purpose of storing information in the database, using it and securing it, the database manager shall take, inter alia, steps as set out below:
(1)shall establish an information security procedure that shall include, inter alia, provisions concerning the following matters:
(a)the definition of means in respect of physical security intended to protect the computing systems and infrastructure and the manner of their operation for that purpose, provided that such means shall include, at a minimum, a dedicated isolated and monitored compound, means to ensure identification of entry to sites where the computing systems and infrastructures are located, locking of rooms and cabinets in the compound and security cameras;
(b)access permissions to information in the database, including for the purpose of using information in the database, to computing infrastructure systems and to communications and information security systems, including the allocation of access permissions on the basis of role and responsibility, prohibition of access to information other than for the purpose of performing a role, centralised management of permissions, granting of access to advanced users (administrators) only by means of PAS (Privileged Accounts Security), revocation of permissions upon termination of an employee's employment and periodic review of permissions; access permission to information in the database shall be granted only to holders of the appropriate security clearance applied in the Bank of Israel in respect of authorised accessors to information databases in the Bank of Israel;
(c)conduct of training for authorised accessors to information in the database, for authorised accessors to computing infrastructure systems and to communications and information security systems and for authorised users of information; such training shall include guidance and updates in the fields of information security and privacy protection;
(d)conduct of a risk survey that shall include, inter alia, reference to risks to which the information in the database is exposed in the course of ongoing activity, including risks arising from the structure of the database systems, hardware and software, from the uses of the information, and from the users and interfaces; the said survey shall include a risk mitigation plan, shall be conducted at a frequency of at least once every 18 months, and its results shall be transmitted to the Commissioner;
(e)the manner of handling information for the purpose of making it accessible as unidentified information to credit bureaux and to the Bank of Israel for the purpose of performing their roles and in accordance with the policy to be determined on the matter, provided that the making accessible of information shall be carried out by means of the operation of a private computing hosting service and the work processes shall include restrictions on the manner of the input and output of information, management of permissions for a limited number of users, control over information that is approved for output from the database, physical security of activity compounds, having users sign a usage agreement, conduct of training and determination of sanctions;
(f)coping with information security incidents according to the severity of the incident and the degree of sensitivity of the information, as well as monitoring of systems throughout all hours of the day by a dedicated team and dedicated tools for this purpose, determination of an alerts protocol and reporting procedures, definition of minimum service targets upon the occurrence of information security incidents and definition of required response steps;
(g)rules for the use of portable devices, including the determination of the types of devices permitted for use, blocking of the possibility of connecting such means to system components except in exceptional cases such as dedicated stations for the input and output of information, all subject to access permissions;
(h)information security aspects relating to information backup, provided that the backup processes shall be detailed according to their various types, their frequency, the manner of their storage and the manner of their use for the purpose of restoration;
(i)a description of additional means whose purpose is the protection of the database systems and the manner of their operation for that purpose;
(2)shall conduct periodic tests including penetration tests at a frequency of at least once every 18 months, in order to verify the existence and proper functioning of the various security measures, including the security measures determined pursuant to paragraph (1);
(3)shall issue instructions regarding the manner of performing development operations in the database and their documentation, including the access of development personnel to data in the database, such as the maintenance of a separate development environment, working in accordance with a secure development methodology and the use of synthetic data only;
(4)shall examine, once every 18 months, the need to update information security procedures; if a technological, organisational or work-process change that is a material change is made, or upon the occurrence of information security incidents, the need to update the information security procedures shall be examined immediately.
(b)The information security procedure and any material amendment thereto shall be brought for the approval of the Governor.

Manner of Access to Identified Information in the Database§

4.
(a)Access to identified information in the database shall be permitted only to the Commissioner, to the database manager, or to a person expressly authorised by either of them on their behalf for a specific matter, for the purpose of performing their functions and subject to the access permissions to be determined.
(b)The database manager shall ensure that measures are taken to control and document entry to and exit from the site in which the information systems are located and the bringing in and taking out of equipment to and from the site.
(c)The database manager shall maintain an updated register of those authorised to access identified information and unidentified information held in the database, their roles and their access permissions as determined pursuant to section 3(a)(1)(b); access permissions shall be determined on the basis of role definitions and to the extent required for the performance of the role.
(d)The database manager shall maintain defined and controlled access channels for the purpose of access to information in the database and shall ensure that any attempt to access by an unauthorised channel is blocked, monitored and documented.

Identification Means Required from a Credit Bureau for the Purpose of Using the Technological System of the Database§

5.

The identification means of a credit bureau for the purpose of using the technological system serving the database shall be an electronic message issued by the Bank of Israel, certifying that the signature authentication means belongs to an authorised employee of the bureau (in this section – electronic certificate); the electronic certificate shall be renewed from time to time at a frequency to be determined by the database manager, and at least once every 24 months.

Control over the Technological System of the Database and Access Documentation§

6.
(a)The database manager shall establish a control mechanism over the technological system serving the database and access thereto, in which the following conditions shall be met:
(1)the mechanism shall enable the documentation of access to information systems and shall include the data required for the purpose of monitoring access to the systems, including data regarding the identity of the user, the date and time of the access attempt, the system component to which the access attempt was made, the type of access, its scope, and whether the access was approved or rejected (hereinafter – access data); access data shall be retained for at least 24 months;
(2)only authorised persons who have been expressly designated for that purpose by the database manager shall be permitted to exceptionally modify or cancel the operation of the mechanism referred to in paragraph (1), in accordance with a procedure to be determined by the database manager for the modification or cancellation of the mechanism and subject to an approval track to be determined therein.
(b)The database manager shall maintain systems for the monitoring and management of information security incidents that shall relate to all information in defined control channels; the systems shall operate on a continuous basis and in real time and shall alert to breaches defined in the alert policy pursuant to section 3(a)(1)(f); use shall be made of systems such as: SIEM (Security Information and Event Management) and UEBA (User and Entity Behavior Analytics).
(c)The database manager shall maintain a routine inspection procedure of control channel data and monitoring reports, shall direct a timetable for the rectification of a defect discovered according to its severity, and shall verify its rectification.
(d)The information security incident monitoring and management system shall receive reports from the various information systems included in the database concerning a suspicion of exceptional events relating to threats to the information.

Manner of Transfer of Identified Information to a Credit Bureau§

7.
(a)Identified credit data concerning a customer shall be transferred from the database to a credit bureau only after an explicit request has been received from the credit bureau, which meets the conditions determined under the Law and in the fields determined by the Commissioner for the transfer of information concerning the customer.
(b)Information shall be transferred from the database to the credit bureau through controlled and monitored communication channels, and in the fields to be determined by the Commissioner.
(c)The transfer of information shall be carried out in a secure manner through the implementation of accepted information protection processes, including the use of accepted encryption methods, verification that data reaches its destination, and restriction of access to data taking into account the needs for use of the information and the restrictions determined under the Law.
(d)The database manager shall implement accepted protection and encryption techniques and shall validate their currency from time to time, relying on recognised international standards.
(e)The database manager shall define and implement a procedure for managing encryption keys, which shall include provisions for the entire life cycle of the encryption keys, including generation, distribution, storage, updating and revocation.
(f)Access to information held in the database shall not be granted to an unauthorised party or for uses not permitted under the Law; the database manager shall document and report to the Commissioner any case in which use was made without authorisation or in excess of authorisation and of permitted uses.

Storage, Use, Security and Deletion of Information in the Information Systems of a Credit Bureau§

8.
(a)Where a serious security incident, as defined in the Privacy Protection (Information Security) Regulations, 5777-2017, occurs, the bureau shall notify the Commissioner thereof immediately and shall also report on the steps it took following the incident, including in accordance with the directions of the Commissioner.
(b)A credit bureau shall act to delete the identified credit data transferred to it from the database in accordance with that prescribed in the Credit Data Regulations, 5778-2017, and in accordance with the directions of the Commissioner.
(c)The deletion of data shall be carried out in a manner that does not enable their reading by technological applications, including the operating systems serving the information systems of the credit bureau, except for their reading by relying on backups or log files.
(d)A credit bureau shall establish a work procedure for the process of deleting the identified data received from the database, which shall include, inter alia, provisions concerning the matters detailed below, and shall bring it for the approval of the Commissioner:
(1)the party responsible for the process;
(2)the frequency and timing of deletion;
(3)identification of the systems in which deletion is required to be performed;
(4)deletion means;
(5)ongoing control processes.

Savings of Laws§

9.

The provisions of these Rules are intended to add to the provisions of any law concerning information security and not to derogate therefrom.

5 Kislev 5779 (13 November 2018) Karnit Flug

Governor of the Bank of Israel

Need to cite this law in a foreign court?

Eli Shimony Israeli Attorneys-at-Law provides certified Expert Legal Opinions on Israeli law within 24–48 hours, accepted by courts worldwide.

Contact Us →
RegulationsAdministrative Law

כללי נתוני אשראי (אבטחת מידע), תשע"ט-2018

credit data rules

credit data law

information security rules

information security law

5779-2018

2018 credit data

credit information security

data security credit

personal credit data

credit file security