Privacy Protection (Information Security) Regulations, 5777-2017
תקנות הגנת הפרטיות (אבטחת מידע), תשע"ז-2017
Unofficial English translation — for reference only. It may contain errors or omissions and cannot be relied on as a legal text. Only the Hebrew text published in Reshumot is legally binding.More
This English text was translated from the official Hebrew using a range of translation tools, and it undergoes ongoing checks and updates. It is not a certified translation.
Despite these checks, it may contain errors, omissions, or imprecise renderings of legal terminology and cross-references, and it may not yet reflect the latest amendments. It cannot be relied upon as a legal text.
The Hebrew text as published in Reshumot (ספר החוקים) and on the Knesset website is the sole authoritative and legally binding version. In any discrepancy, the Hebrew text prevails.
This translation is provided for informational purposes only and does not constitute legal advice. For use in legal proceedings, request a certified Expert Legal Opinion.
By virtue of my authority under section 36 of the Privacy Protection Law, 5741-1981 (hereinafter – the Law or the Privacy Protection Law), and with the approval of the Constitution, Law and Justice Committee of the Knesset, I hereby promulgate these Regulations:
Definitions§
In these Regulations –
"serious security incident" – any of the following:
"authorised person" – an individual who has access to any of the following pursuant to the authorisation of the database owner or the holder:
Notwithstanding the foregoing, a holder who is not an individual, or an individual who received access pursuant to the authorisation of a holder, shall not be regarded as an authorised person of the database owner;
"mobile device" – any of the following:
"computer material" and "computer" – as defined in the Computer Law, 5755-1995;
"database managed by an individual" – a database managed by an individual or by a corporation owned by an individual, in which only the individual and at most two additional authorised persons are entitled to make use of it and are capable of making use of it, excluding the following databases:
"databases to which the basic security level applies" – databases that are not of the types listed in the First or Second Schedule and are not a database managed by an individual;
"databases to which the medium security level applies" – databases of the types listed in the First Schedule that are not a database managed by an individual;
"databases to which the high security level applies" – databases of the types listed in the Second Schedule;
"biometric information" – information used to identify a person, being a physiological, unique human characteristic susceptible to computerised measurement;
"security officer" – as that term is used in section 17b of the Law;
"database systems" – systems serving the database that are of importance from an information security perspective;
"data subject" – the person about whom information exists in the database;
"Israel National Cyber Directorate" – the Israel National Cyber Directorate whose purpose is the protection of cyberspace, established pursuant to a Government decision and operating in accordance with its decisions;
"public network" – a communications network that enables use also by a person who is not an authorised person.
Database Definition Document§
Information Security Officer§
Where there is an obligation to appoint an information security officer, or where an information security officer has been appointed for a database, the following provisions shall apply:
Security Procedure§
Mapping of Database Systems and Conducting a Risk Survey§
Physical and Environmental Security§
Information Security in Human Resources Management§
Management of Access Authorisations§
Identification and Authentication§
Access Monitoring and Logging§
Documentation of Security Incidents§
Mobile Devices§
A database owner shall restrict or prevent the possibility of connecting mobile devices to the database systems in a manner consistent with the information security level applicable to the database, the sensitivity of the information, the particular risks to the database systems or to the information arising from the connection of the mobile device, and the existence of appropriate protective measures against such risks; a database owner who permits the use of information from the database on a mobile device or its copying to a mobile device shall take protective measures having regard to the particular risks associated with the use of a mobile device in connection with that database; for this purpose, the use of accepted encryption methods shall be regarded as the taking of reasonable measures to protect information that has been copied to the mobile device.
Secure and Updated Management of Database Systems§
Communications Security§
Outsourcing§
Periodic Audits§
Retention of Security Data§
Backup and Recovery of Security Data§
Obligations of Database Owner Apply to Database Manager and Holder, and Documentation of Performance of an Action§
Powers of the Registrar§
"competent authority" – a public body empowered under law to issue instructions on information security;
"guidance document on information security" – an official standard, an Israeli standard or an international standard as those terms are defined in the Standards Law, 5713-1953, or a reference document approved by the Registrar for this purpose.
Application and Exceptions to Application§
In these Regulations —
Commencement§
These Regulations shall come into force one year from the date of their publication.
Transitional Provision§
Notwithstanding the provisions of regulation 7(a), with respect to persons who are authorised persons on the date of commencement of these Regulations, a database owner to whom that regulation applies shall examine their suitability for access to the database by reasonable means customary in employee screening and placement procedures, all with regard to the sensitivity of the information and the type of access authorisation, and shall update the access authorisations accordingly as necessary.
Revocation§
Regulations 2, 3, 9, 10, 12, 13, 14 and 15 of the Privacy Protection Regulations (Conditions for Holding and Maintaining Information and Procedures for Transferring Information between Public Bodies), 5746-1986 — are revoked.
Relationship to Other Legislation§
These Regulations shall apply in addition to the provisions concerning information security in other legislation, unless there is a contradiction between them.
Need to cite this law in a foreign court?
Eli Shimony Israeli Attorneys-at-Law provides certified Expert Legal Opinions on Israeli law within 24–48 hours, accepted by courts worldwide.
Contact Us →Read the entire law on one page — continuous text, no page breaks, plus PDF downloads.
תקנות הגנת הפרטיות (אבטחת מידע), תשע"ז-2017
Tkanot Hganat Piratiyut
Takkanot Hganat Piratiyut
Information Security Regulations
Privacy Protection Regulations
Data Protection Regulations Israel
PPISR 2017
Israeli Privacy Regulations
Data Security Takkanot
Information Protection Law