Israeli Legislation.com
RegulationsCivil Law

Privacy Protection (Information Security) Regulations, 5777-2017

תקנות הגנת הפרטיות (אבטחת מידע), תשע"ז-2017

Published: 2023-09-18Last amended 2023-09-18✓ Amendment status checked against the Knesset legislation record on 2026-09-04
Premium
Unofficial English translation — for reference only. It may contain errors or omissions and cannot be relied on as a legal text. Only the Hebrew text published in Reshumot is legally binding.More

This English text was translated from the official Hebrew using a range of translation tools, and it undergoes ongoing checks and updates. It is not a certified translation.

Despite these checks, it may contain errors, omissions, or imprecise renderings of legal terminology and cross-references, and it may not yet reflect the latest amendments. It cannot be relied upon as a legal text.

The Hebrew text as published in Reshumot (ספר החוקים) and on the Knesset website is the sole authoritative and legally binding version. In any discrepancy, the Hebrew text prevails.

This translation is provided for informational purposes only and does not constitute legal advice. For use in legal proceedings, request a certified Expert Legal Opinion.

By virtue of my authority under section 36 of the Privacy Protection Law, 5741-1981 (hereinafter – the Law or the Privacy Protection Law), and with the approval of the Constitution, Law and Justice Committee of the Knesset, I hereby promulgate these Regulations:

Definitions§

1.

In these Regulations –

"serious security incident" – any of the following:

(1)in a database to which the high security level applies – an incident in which information from the database was used without authorisation or in excess of authorisation, or in which the integrity of the information was compromised;
(2)in a database to which the medium security level applies – an incident in which a substantial part of the database was used without authorisation or in excess of authorisation, or in which the integrity of the information was compromised in respect of a substantial part of the database;

"authorised person" – an individual who has access to any of the following pursuant to the authorisation of the database owner or the holder:

(1)information from the database;
(2)the database systems;
(3)information or a component required for the purpose of operating the database or for the purpose of accessing it.

Notwithstanding the foregoing, a holder who is not an individual, or an individual who received access pursuant to the authorisation of a holder, shall not be regarded as an authorised person of the database owner;

"mobile device" – any of the following:

(1)a computer intended for mobile use, including a computer that is wireless terminal equipment as defined in the Wireless Telegraph Ordinance [New Version], 5732-1972;
(2)any other medium used for storing computer material;

"computer material" and "computer" – as defined in the Computer Law, 5755-1995;

"database managed by an individual" – a database managed by an individual or by a corporation owned by an individual, in which only the individual and at most two additional authorised persons are entitled to make use of it and are capable of making use of it, excluding the following databases:

(1)a database whose primary purpose is the collection of information for the purpose of transferring it to another person in the ordinary course of business, including direct mailing services;
(2)a database containing information about 10,000 persons or more;
(3)a database that includes information in respect of which the database owner is subject to an obligation of professional confidentiality under law or under the principles of professional ethics;

"databases to which the basic security level applies" – databases that are not of the types listed in the First or Second Schedule and are not a database managed by an individual;

"databases to which the medium security level applies" – databases of the types listed in the First Schedule that are not a database managed by an individual;

"databases to which the high security level applies" – databases of the types listed in the Second Schedule;

"biometric information" – information used to identify a person, being a physiological, unique human characteristic susceptible to computerised measurement;

"security officer" – as that term is used in section 17b of the Law;

"database systems" – systems serving the database that are of importance from an information security perspective;

"data subject" – the person about whom information exists in the database;

"Israel National Cyber Directorate" – the Israel National Cyber Directorate whose purpose is the protection of cyberspace, established pursuant to a Government decision and operating in accordance with its decisions;

"public network" – a communications network that enables use also by a person who is not an authorised person.

Database Definition Document§

2.
(a)A database owner shall define in a database definition document (hereinafter – the database definition document) at least all of the following matters:
(1)a general description of the collection and use of information;
(2)a description of the purposes for which the information is used;
(3)the various types of information contained in the database, having regard to the list of types of information in item 1(3) of the First Schedule;
(4)particulars of the transfer of the database, or a substantial part thereof, outside the borders of the State, or of the use of information outside the borders of the State, the purpose of the transfer, the destination country, the manner of transfer and the identity of the transferee;
(5)information processing operations by means of a holder;
(6)the principal risks of a breach of information security and the manner of addressing them;
(7)the name of the database manager, of the database holder and of the information security officer appointed for it, if one has been appointed.
(b)A database owner shall update the database definition document whenever a material change is made to the matters listed in sub-regulation (a), and shall examine the need for such an update due to technological or organisational changes or security incidents as referred to in regulation 11, annually by 31 December.
(c)A database owner shall examine, once a year, whether the information retained in the database does not exceed what is required for the purposes of the database.

Information Security Officer§

3.

Where there is an obligation to appoint an information security officer, or where an information security officer has been appointed for a database, the following provisions shall apply:

(1)a security officer shall be directly subordinate to the database manager or to an active manager of the database owner or the holder, as the case may be, or to another senior office holder who is directly subordinate to the database manager;
(2)the security officer shall prepare an information security procedure and bring it for the approval of the database owner;
(3)the security officer shall prepare a plan for ongoing monitoring of compliance with the requirements of these Regulations, shall implement it, and shall notify the database owner and the database manager of his findings;
(4)the security officer shall not fulfil an additional role that may place him in a situation of apprehension of a conflict of interests in the performance of his functions under these Regulations;
(5)where the database owner has assigned to the security officer tasks additional to the duties listed in paragraphs (2) and (3) for the purpose of implementing these Regulations, the database owner shall define them clearly;
(6)the database owner shall allocate to the security officer the resources required for the performance of his functions.

Security Procedure§

4.
(a)A database owner shall set out in a document an information security procedure (hereinafter – the security procedure), in accordance with the database definition document and these Regulations, which shall be binding on every authorised person in accordance with the details of the procedure to which that person is exposed pursuant to sub-regulation (b).
(b)A database owner shall keep the security procedure in such a manner that details thereof are disclosed to authorised persons only to the extent required for the performance of their functions.
(c)The security procedure shall include, inter alia, all of the following:
(1)provisions concerning the physical and environmental security of the database sites as referred to in regulation 6;
(2)access authorisations to the database and to the database systems in accordance with regulation 8;
(3)a description of the measures designed to protect the database systems and the manner of their operation for that purpose;
(4)instructions for persons authorised to access the database and the database systems for the purpose of protecting the information in the database;
(5)the risks to which the information in the database is exposed in the course of the ordinary activity of the database owner, including those arising from the structure of the database systems as set out in regulation 5(a), the manner of determining such risks and the manner of addressing them, including by means of accepted encryption mechanisms for the protection of information stored in the database or in the database systems;
(6)the manner of dealing with information security incidents as referred to in regulation 11, according to the severity of the incident and the degree of sensitivity of the information;
(7)provisions concerning the management and use of mobile devices as referred to in regulation 12.
(d)In a database to which the medium or high security level applies, the security procedure shall include, in addition to what is set out in sub-regulation (c), reference to all of the following:
(1)the means of identification and authentication for access to the database and to the database systems, in accordance with regulation 9;
(2)the manner of monitoring the use of the database, including the logging of access to the database systems as referred to in regulation 10;
(3)provisions concerning the conduct of periodic audits to verify the existence and proper functioning of the security measures pursuant to the security procedure and pursuant to these Regulations, as referred to in regulation 16;
(4)provisions concerning the backup of the data referred to in regulation 18(a)(1);
(5)provisions concerning the manner of performing and documenting development operations in the database, including the manner of access by development personnel to data in the database.
(e)A database owner shall examine, once a year, the need to update the procedure, and without derogating from the foregoing, shall examine whether there is a need to update the procedure in the following cases:
(1)material changes are made to the database systems or to information processing procedures;
(2)new technological risks relevant to the database systems become known.
(f)An organisation that owns several databases may set out a security procedure as referred to in this regulation in a single document in respect of all the databases in its possession that are at the same security level.

Mapping of Database Systems and Conducting a Risk Survey§

5.
(a)A database owner shall maintain an updated document of the structure of the database and an updated inventory list of the database systems, including:
(1)infrastructure and hardware systems, types of communications and information security components;
(2)software systems used for the operation of the database, for its management and maintenance, for support of its activities, for its monitoring and for its security;
(3)software and interfaces used for communications to and from the database systems;
(4)a network diagram in which the database operates, including a description of the interconnections among the various system components and the physical location of those components;
(5)the date of the last update of the document and of the inventory list.
(b)The updated document of the structure of the database and the inventory list shall be kept in such a manner that details thereof are disclosed to authorised persons only to the extent required for the performance of their functions.
(c)In a database to which the high security level applies, the database owner is responsible for ensuring that a survey is conducted to identify information security risks (hereinafter – risk survey); the database owner shall discuss the results of the risk survey transmitted to him, shall examine the need to update the database definition document or the security procedure in consequence thereof, and shall act to remedy the deficiencies discovered in the course of the survey, to the extent any were discovered; a risk survey as aforesaid shall be conducted at least once every eighteen months.
(d)In a database to which the high security level applies, the database owner is responsible for ensuring that penetration tests are conducted on the database systems to examine their resilience against internal and external risks, at least once every eighteen months; the database owner shall discuss the results of the penetration tests and shall act to remedy the deficiencies discovered, to the extent any were discovered.
(e)An organisation that owns several databases may set out the inventory list referred to in sub-regulation (a) in a single document in respect of all the databases in its possession that are at the same security level, and may also fulfil the obligations set out in sub-regulations (c) and (d) by means of a single risk survey or penetration test, as the case may be, in respect of all the databases in its possession that are at the same security level.

Physical and Environmental Security§

6.
(a)A database owner shall ensure that the systems listed in regulation 5(a)(1) are kept in a protected location that prevents unauthorised intrusion and entry and that is consistent with the nature of the database's activity and the sensitivity of the information therein.
(b)A database owner to whom the medium or high security level applies shall take measures to monitor and document entry into and exit from sites at which the systems listed in regulation 5(a)(1) are located, and the introduction and removal of equipment to and from the database systems.

Information Security in Human Resources Management§

7.
(a)A database owner shall not grant access to information contained in a database, nor shall the database owner alter the scope of an authorisation that has been granted, unless the database owner has taken reasonable measures, of the kind accepted in employee screening and placement procedures, to ascertain that there is no apprehension that the authorised person is unsuitable to receive access to the information in the database; such measures shall be taken having regard to the sensitivity of the information in the database and to the scope of the access authorisations for the position for which the person concerned is designated, as referred to in regulation 8.
(b)Before authorised persons receive access to information from the database or before a change in the scope of their authorisations, the database owner shall conduct training sessions for authorised persons on the obligations under the Law and these Regulations, and shall provide them with information about their obligations under the Law and the security procedure.
(c)In a database to which the medium or high security level applies, the database owner shall conduct periodic training activities for its authorised persons concerning the database definition document, the security procedure and the information security provisions under the Law and these Regulations, to the extent required for the performance of their functions, and concerning the obligations of authorised persons thereunder; such training shall be conducted at least once every two years, and in respect of the authorisation of an authorised person to a new position – as close as possible to the date on which the authorisation takes effect.

Management of Access Authorisations§

8.
(a)A database owner shall determine the access authorisations of authorised persons to the database and to the database systems, in accordance with position definitions; the access authorisation for each position shall be limited to what is required for the performance of that position.
(b)A database owner shall maintain an updated register of positions, the access authorisations granted to them, and the authorised persons filling those positions (hereinafter – the valid authorisations list).

Identification and Authentication§

9.
(a)A database owner shall take measures that are accepted in the circumstances of the matter and in accordance with the nature and character of the database, in order to verify that access to the database and to the database systems is carried out only by an authorised person who is permitted to do so according to the valid authorisations list.
(b)In a database to which the medium or high security level applies –
(1)the method of identification shall, to the extent possible, be based on a physical means under the exclusive control of the authorised person;
(2)the security procedure shall also set out provisions concerning sub-regulation (a), including in respect of the following matters:
(a)the method of identification; where the method of identification is based on passwords, the procedure shall also address the strength of the password, the number of failed attempts, and the frequency of password changes, which shall be carried out in accordance with the role of the authorised person and in any event for a period not exceeding six months;
(b)automatic disconnection after a period of inactivity;
(c)the manner of dealing with malfunctions relating to identity authentication.
(c)A database owner shall ensure the revocation of the authorisations of an authorised person who has completed his role and, to the extent possible, the changing of passwords to the database and to the database systems that the authorised person may have known, immediately upon the completion of the authorised person's role.

Access Monitoring and Logging§

10.
(a)In the systems of a database to which the medium or high security level applies, an automatic logging mechanism shall be maintained that enables auditing of access to the database systems (in this regulation – the monitoring mechanism), including the following data: the identity of the user, the date and time of the access attempt, the system component to which access was attempted, the type and scope of the access, and whether the access was approved or denied.
(b)The monitoring mechanism shall, to the best of its ability, not permit the cancellation or alteration of its operation; the monitoring mechanism shall detect changes or cancellations in its operation and shall disseminate alerts to those responsible.
(c)A database owner shall establish a routine procedure for examining the log data of the monitoring mechanism, and shall prepare a report of the problems discovered and the steps taken in consequence thereof.
(d)The log data of the monitoring mechanism shall be retained for at least 24 months.
(e)A database owner shall inform the authorised persons in the database of the existence of the monitoring mechanism for the database systems.

Documentation of Security Incidents§

11.
(a)A database owner is responsible for documenting every instance in which an incident was discovered that raises an apprehension of a breach of the integrity of the information, of its use without authorisation, or of a deviation from authorisation (hereinafter – security incidents); to the extent possible, such documentation shall be based on automatic recording.
(b)In the security procedure, the database owner shall also set out provisions concerning the handling of information security incidents, according to the severity of the incident and the degree of sensitivity of the information, including concerning the revocation of authorisations and other immediate steps required, and also concerning the reporting to the database owner of security incidents and of the actions taken in consequence thereof.
(c)In a database to which the medium security level applies, the database owner shall conduct a discussion at least once a year on the security incidents and shall examine the need to update the security procedure; in a database to which the high security level applies, such a discussion shall be held at least once a quarter.
(d)Where a serious security incident has occurred –
(1)the database owner shall notify the Registrar thereof immediately, and shall also report to the Registrar on the steps taken in consequence of the incident;
(2)the Registrar may, after consulting with the head of the Israel National Cyber Directorate, instruct the database owner, except a database owner among those listed in section 13(e) of the Law, to notify the data subject who may be affected by the incident of the security incident.

Mobile Devices§

12.

A database owner shall restrict or prevent the possibility of connecting mobile devices to the database systems in a manner consistent with the information security level applicable to the database, the sensitivity of the information, the particular risks to the database systems or to the information arising from the connection of the mobile device, and the existence of appropriate protective measures against such risks; a database owner who permits the use of information from the database on a mobile device or its copying to a mobile device shall take protective measures having regard to the particular risks associated with the use of a mobile device in connection with that database; for this purpose, the use of accepted encryption methods shall be regarded as the taking of reasonable measures to protect information that has been copied to the mobile device.

Secure and Updated Management of Database Systems§

13.
(a)A database owner shall ensure the proper management and operation of the database systems, in accordance with what is accepted in the operation of such systems.
(b)A database owner shall separate, to the reasonable and practicable extent, the database systems from which information can be accessed from other computing systems used by the database owner.
(c)A database owner shall ensure that ongoing updates are made to the database systems, including the computer material required for their operation; systems that are no longer supported by the manufacturer in respect of security aspects shall not be used unless an appropriate security response has been provided.

Communications Security§

14.
(a)A database owner shall not connect the database systems to the Internet or to any other public network without installing appropriate protective measures against unauthorised intrusion or against software capable of causing damage or disruption to a computer or to computer material.
(b)The transfer of information from the database over a public network or the Internet shall be carried out using accepted encryption methods.
(c)In a database that can be accessed remotely via the Internet or another public network, means shall be used, in addition to the security measures referred to in sub-regulations (a) and (b), that are designed to identify the person connecting and to authenticate that person's authorisation to carry out the remote activity and its scope; for the purpose of access by an authorised person to a database at the medium or high security level, a physical means under the exclusive control of the authorised person shall be used.

Outsourcing§

15.
(a)A database owner who enters into an agreement with an external party for the purpose of receiving a service that involves granting access to the database shall —
(1)examine, before entering into the agreement with that particular external party, the information security risks involved in the agreement;
(2)expressly stipulate in the agreement with the external party (in this regulation — the agreement) all of the following, having regard to the risks under paragraph (1):
(a)the information that the external party is permitted to process and the permitted purposes of its use for the purposes of the agreement;
(b)the database systems to which the external party is permitted to have access;
(c)the type of processing or operation that the external party is permitted to carry out;
(d)the duration of the agreement, the manner of returning the information to the owner upon termination of the agreement, its destruction from the possession of the external party, and reporting thereof to the database owner;
(e)the manner of implementing the information security obligations to which the holder is subject under these Regulations, as well as any additional instructions regarding information security measures determined by the database owner, if any were determined;
(f)the obligation of the external party to have its authorised persons sign an undertaking to maintain the confidentiality of the information, to use the information only as stated in the agreement, and to implement the security measures set out in the agreement as referred to in sub-paragraph (e);
(g)where a database owner has permitted the external party to provide the service by means of an additional party — the obligation of the external party to include in the agreement with the additional party all the matters specified in this regulation;
(h)the obligation of the external party to report, at least once a year, to the database owner regarding the manner in which it fulfils its obligations under these Regulations and the agreement, and to notify the database owner in the event of a security incident;
(3)set out in the security procedure of the database also the matters enumerated in paragraph (2)(a) to (e), and expressly refer therein to the agreement with the external party and to its security procedure;
(4)take control and oversight measures to ensure the external party's compliance with the provisions of the agreement and with the provisions of these Regulations, to the extent required having regard to the risks referred to in paragraph (1).
(b)An organisation that is the owner of several databases and that enters into an agreement with an external party for the purpose of providing a service involving access thereto by the external party may fulfil the requirements of sub-regulation (a)(2) in a single agreement in respect of all the databases, provided that they are at the same security level.
(c)This regulation shall not apply to an agreement between a database owner and an individual.

Periodic Audits§

16.
(a)In respect of a database to which the medium or high security level applies, the database owner is responsible for ensuring that an internal or external audit is conducted at least once every 24 months, by a person with appropriate training in information security auditing who is not the security officer of the database, in order to verify compliance with the provisions of these Regulations.
(b)In the audit report, the auditor shall report on the conformity of the security measures with the security procedure and with these Regulations, shall identify deficiencies, and shall propose measures necessary to remedy the situation.
(c)The database owner shall discuss the audit reports transmitted to it and shall examine the need to update the database definition document or the security procedure in consequence thereof.
(d)A database owner to whom the high security level applies may fulfil the obligation set out in this regulation within the framework of conducting a risk survey that satisfies the requirements of sub-regulation (b).
(e)An organisation that is the owner of several databases may fulfil the obligation set out in this regulation within the framework of a single audit in respect of all the databases in its possession that are at the same security level.

Retention of Security Data§

17.
(a)A database owner shall retain the data accumulated in the course of implementing the provisions of regulations 6(b), 8 to 11, 14, 15(a)(4) and 16, to the extent that those regulations apply to it, in a secure manner for a period of 24 months.
(b)In respect of a database to which the medium or high security level applies, the database owner shall back up the data retained as referred to in sub-regulation (a), in a manner that ensures that it is possible, at any time, to restore the said data to its original state.

Backup and Recovery of Security Data§

18.
(a)In respect of a database to which the medium or high security level applies, the database owner shall set out in a document —
(1)procedures for performing backup as referred to in regulation 17(b), on a routine periodic basis;
(2)procedures to ensure the recovery of data as referred to in regulation 17(b), provided that the performance of the recovery shall require the approval of the database manager;
(3)that within the framework of documenting security incidents as referred to in regulation 11, data recovery procedures shall also be documented, including the identity of the person who carried out the recovery procedures and the particulars of the information recovered.
(b)In respect of a database to which the high security level applies, the database owner is responsible for ensuring that a backup copy of the data referred to in sub-regulation (a)(1) and of the procedures referred to in sub-regulation (a)(2) is retained in a manner that ensures the integrity of the information and the possibility of recovering the information in the event of loss or destruction.

Obligations of Database Owner Apply to Database Manager and Holder, and Documentation of Performance of an Action§

19.
(a)The obligations imposed under these Regulations on a database owner shall also apply to the database manager, and — except for the obligations set out in regulations 2 and 15(a) — shall also apply to the database holder, with the necessary modifications and as appropriate.
(b)A person upon whom an obligation or responsibility to perform an action that does not constitute the creation of a document is imposed under these Regulations is required to document, in a reasonable manner, the way in which the action was performed, as appropriate; the Registrar may give instructions regarding the manner of documentation as aforesaid.

Powers of the Registrar§

20.
(a)
(1)The Registrar may, if satisfied that there are reasons justifying it, exempt a particular database from information security obligations under these Regulations, or apply to a particular database obligations under these Regulations, in whole or in part, according to the circumstances of the matter, including by taking into account the size of the database, the type of information contained in it, the scope of activity of the database, or the number of authorised persons in it.
(2)An exemption from obligations or the application of obligations under paragraph (1) shall be effected by written notice to the database owner; in such notice the Registrar shall determine the date of commencement of the exemption or application, as the case may be, and may determine different dates in respect of different regulations.
(b)The Registrar may direct that a person who complies with the provisions of a guidance document on information security or with the instructions of a competent authority on information security that apply to that person shall be regarded as complying with the provisions of these Regulations, in whole or in part, if satisfied that compliance with the provisions of the guidance document on information security or with the instructions of the competent authority, as the case may be, in the manner directed under these Regulations, ensures the security level prescribed in these Regulations for that database; for this purpose —

"competent authority" – a public body empowered under law to issue instructions on information security;

"guidance document on information security" – an official standard, an Israeli standard or an international standard as those terms are defined in the Standards Law, 5713-1953, or a reference document approved by the Registrar for this purpose.

Application and Exceptions to Application§

21.

In these Regulations —

(1)to databases to which the high security level applies — regulations 1 to 20 shall apply;
(2)to databases to which the medium security level applies — regulations 1 to 4, 5(a), (b) and (e), 6 to 15, 16(a), (b), (c) and (e), 17, 18(a), 19 and 20 shall apply;
(3)to databases to which the basic security level applies — regulations 1 to 3, 4(a), (b), (c), (e) and (f), 5(a), (b) and (e), 6(a), 7(a) and (b), 8, 9(a) and (c), 11(a) and (b), 12 to 15, 17, 19 and 20 shall apply;
(4)to a database managed by an individual — regulations 1, 2, 6(a), 9(a), 11(a), 12 to 14 and 20 shall apply.

Commencement§

22.

These Regulations shall come into force one year from the date of their publication.

Transitional Provision§

23.

Notwithstanding the provisions of regulation 7(a), with respect to persons who are authorised persons on the date of commencement of these Regulations, a database owner to whom that regulation applies shall examine their suitability for access to the database by reasonable means customary in employee screening and placement procedures, all with regard to the sensitivity of the information and the type of access authorisation, and shall update the access authorisations accordingly as necessary.

Revocation§

24.

Regulations 2, 3, 9, 10, 12, 13, 14 and 15 of the Privacy Protection Regulations (Conditions for Holding and Maintaining Information and Procedures for Transferring Information between Public Bodies), 5746-1986 — are revoked.

Relationship to Other Legislation§

25.

These Regulations shall apply in addition to the provisions concerning information security in other legislation, unless there is a contradiction between them.

Need to cite this law in a foreign court?

Eli Shimony Israeli Attorneys-at-Law provides certified Expert Legal Opinions on Israeli law within 24–48 hours, accepted by courts worldwide.

Contact Us →

Page 1 of 2

Read the entire law on one page — continuous text, no page breaks, plus PDF downloads.

RegulationsCivil Law

תקנות הגנת הפרטיות (אבטחת מידע), תשע"ז-2017

Tkanot Hganat Piratiyut

Takkanot Hganat Piratiyut

Information Security Regulations

Privacy Protection Regulations

Data Protection Regulations Israel

PPISR 2017

Israeli Privacy Regulations

Data Security Takkanot

Information Protection Law