Doogree
Compliance · Amendment 13

Amendment 13 — A Practical Checklist for Your Business

07/02/2026 · ~7 min read
Amendment 13privacycomplianceinformation security

Amendment 13 to Israel's Privacy Protection Law substantially expands the information-security and reporting obligations of every business that holds a database — with meaningful enforcement powers and fines. Here's what the law actually requires, and how to close each requirement without a six-month project.

What changed — in brief

The amendment shifts the emphasis from "registering databases" to a duty of effective information security, transparency, and incident response. A business needs to know what information it holds, to protect it with proven controls, to document who accessed what, and to be able to report a security incident on time. Administrative enforcement plus financial penalties turn this from "nice to have" into "mandatory."

The principle: the law doesn't require a specific tool — it requires an outcome: information that is mapped, protected, documented, and reportable. The checklist below is how you get to that outcome.

The checklist — the 7 requirements and how to meet them in practice

1. Mapping information and assets

You need to know which devices, servers and cloud services hold information. With us: a single asset inventory (endpoints + servers + cloud AWS/Azure/GCP/M365/Google) with a 3D connections map and a 0–100 health score for each asset.

2. Proven security controls

Defender/firewall active, encryption, permissions management, backup. With us: continuous monitoring of the controls + automatic remediation when something gets turned off, malware hunting (YARA), and behavioral anomaly detection (UEBA).

3. Access management and tiered permissions

Access on a need-to-have basis, not everything-for-everyone. With us: per-tenant isolation, device sharing at 3 levels (view/control/manage), and deletion reserved for the owner alone.

4. Access documentation (audit trail)

Who accessed, when, why. With us: a full audit log for every action + audit-on-reveal for every secret exposed in the vault — evidence that cannot be denied.

5. Backup and recovery

Information you can restore even after a ransomware attack. With us: immutable backup (WORM · Object-Lock) that an attacker cannot delete — even with stolen keys — with automatic restore testing.

6. Incident detection and reporting

Detect a security incident and report it on time. With us: real-time alerts + a forensic timeline in plain language (who, what, when, with MITRE tagging) — the basis for an orderly report to the regulator.

7. Periodic compliance report

Proof for management/insurer/regulator. With us: a CIS → Amendment 13 / ISO 27001 / SOC 2 mapping, and a report ready to download in one click — without collecting evidence manually.

Bottom line: Amendment 13 is not just a risk — it's a sales engine. A business that can show a compliance report in one click, a full audit trail, and ransomware-proof backup — closes deals with customers and insurers faster. That's exactly why we unified everything into a single system.

← Back to the blog · How it works →