
מאז תיקון 13 לחוק הגנת הפרטיות, כל ארגון שמחזיק מידע אישי צריך לדעת בדיוק אילו מאגרים יש לו, מה רמת האבטחה שחלה על כל אחד מהם, מי אחראי, ומה הוא עושה כשמשהו משתבש. אנחנו מלווים חברות, עמותות ומוסדות מהמיפוי הראשון ועד למסמכים חתומים, לנהלים שעובדים בפועל ולהסמכה, בשפה שההנהלה מבינה ובלי לייצר בירוקרטיה מיותרת.
Since Amendment 13 to the Israeli Privacy Protection Law, every organization that holds personal data must know exactly which databases it has, which security level applies to each, who is accountable, and what happens when something goes wrong. We guide companies, non-profits and institutions from the first mapping to signed documents, procedures that work in practice and certification, in language management understands and without creating unnecessary bureaucracy.

איתור כל מאגרי המידע בארגון, סיווג לפי סוג המידע ומספר הנושאים, וקביעת רמת האבטחה שחלה על כל מאגר: בסיסית, בינונית או גבוהה.
תקנות אבטחת מידע · תקנה 1בדיקת החובות החדשות שחלות על הארגון: חובת מינוי ממונה הגנת פרטיות (DPO), חובות דיווח ורישום, הסמכות הרשות להגנת הפרטיות והעיצומים הכספיים, ותוכנית סגירת פערים.
תיקון 13 · בתוקף מאוגוסט 2025כתיבת מסמך הגדרות המאגר, נוהל אבטחת מידע, נוהל ניהול הרשאות, נוהל אירוע אבטחה ונוהל עבודה עם ספקים, מותאמים לגודל הארגון ולא מועתקים מתבנית.
תקנות אבטחת מידע 2017מילוי תפקיד ה-DPO עבור ארגונים שחייבים במינוי או בוחרים בו: תוכנית עבודה שנתית, הדרכות, מענה לפניות נושאי מידע, וקשר שוטף מול הרשות להגנת הפרטיות.
DPO as a Serviceניתוח פערים מול התקן, בניית מערכת ניהול אבטחת מידע, הצהרת ישימות, ניהול סיכונים, מבדק פנימי והכנה למבדק ההסמכה מול הגוף המסמיך.
ISO/IEC 27001:2022הדרכות פרטיות ואבטחת מידע לעובדים, להנהלה ולדירקטוריון, כולל תיעוד ההדרכה כנדרש בתקנות, ותרגול תגובה לאירוע ברמת ההנהלה.
תקנה 7 · הדרכה תקופתיתIdentifying every personal-data database in the organization, classifying it by data type and number of data subjects, and determining the applicable security level: basic, medium or high.
Data Security Regulations · Reg. 1Review of the new obligations that apply to the organization: mandatory DPO appointment, reporting and registration duties, the Privacy Protection Authority's enforcement powers and fines, and a gap-closure plan.
Amendment 13 · in force since August 2025Writing the database definitions document, the information security procedure, access-management, security-incident and vendor-management procedures, tailored to the organization rather than copied from a template.
Data Security Regulations 2017Serving as the organization's DPO where appointment is mandatory or chosen: annual work plan, training, handling data-subject requests, and ongoing contact with the Privacy Protection Authority.
DPO as a ServiceGap analysis against the standard, building the information security management system, statement of applicability, risk management, internal audit and preparation for the certification audit.
ISO/IEC 27001:2022Privacy and security training for staff, management and the board, documented as the regulations require, plus incident-response exercises at management level.
Reg. 7 · periodic trainingחמישה שלבים, כל אחד מסתיים בתוצר שאפשר להציג לרשות, ללקוח או למבקר.
ראיונות עם בעלי התפקידים, סקירת מערכות וחוזים, ומפת פערים מול החוק, התקנות והתקן.
תעדוף לפי סיכון וחובה חוקית, לוחות זמנים ואחריות, מאושר על ידי ההנהלה.
כתיבת המסמכים והנהלים, הגדרת בקרות, ליווי צוותי ה-IT והספקים בהטמעה.
הדרכות, בדיקת יישום בפועל, מבדק פנימי ותיקון ממצאים לפני הסמכה או ביקורת.
עדכון שנתי של המסמכים, מעקב אחר שינויי רגולציה, ומענה לאירועים ולפניות.
Five stages, each ending in a deliverable you can show a regulator, a client or an auditor.
Interviews with role holders, review of systems and contracts, and a gap map against the law, the regulations and the standard.
Prioritized by risk and legal obligation, with timelines and owners, approved by management.
Writing documents and procedures, defining controls, supporting IT teams and vendors through rollout.
Training, checking actual implementation, internal audit and fixing findings before certification or inspection.
Annual document updates, tracking regulatory changes, and handling incidents and requests.
שיחת היכרות קצרה, ותוך ימים ספורים תדעו איפה אתם עומדים מול תיקון 13.
לחץ כאן ליצירת קשרA short intro call, and within days you will know where you stand against Amendment 13.
Contact us