Services / Advisory
DPO as a Service
A named Data Protection Officer, and the records to back the title.
The problem
A customer contract requires a Data Protection Officer. Israeli law now expects one for a large class of companies, and the GDPR did already. Nobody in the company wants the title, and the person who would take it does not know what the role has to produce. Appointing a name and hoping is a risk in itself.
The method.
Establish lawful basis and data map
Map every processing activity: what personal data, whose, on what legal basis, retained how long, shared with which processors, hosted in which region. Produced as a Record of Processing Activities under GDPR Article 30 and as the database registration and data-inventory records expected under the Israeli Privacy Protection Law and its 2017 Security Regulations.
Classify data and set the security tier
Assign each database to its security tier under the Israeli Privacy Protection (Data Security) Regulations (basic, medium or high) and derive the control set the tier imposes: access logging, separation of environments, periodic access review, penetration testing, breach notification duties.
Run DPIAs and transfer assessments where they are triggered
Data Protection Impact Assessments for high-risk processing (profiling, large-scale special-category data, systematic monitoring). Transfer Impact Assessments and Standard Contractual Clauses for flows out of the EEA. We do the ones the law requires and skip the ones it does not.
Stand up the data-subject rights pipeline
A working intake path for access, deletion, correction and objection requests, with identity verification, an internal search procedure across production and backups, and the statutory clock tracked per request: 30 days under GDPR, 30 days under the Israeli statute for access requests.
Hold the breach clock
Breach assessment procedure that determines, within hours, whether a notification duty is triggered: 72 hours to the supervisory authority under GDPR Article 33, and immediate notification to the Israeli Privacy Protection Authority for severe incidents in medium- and high-tier databases. Notification templates are written before the incident, not during it.
Serve as the named DPO
We appear in your privacy notice and your customer DPAs, take the contact-point email, correspond with supervisory authorities, and report independently to management as the role requires.
What is DPO as a Service?
DPO as a Service is an outsourced Data Protection Officer engagement. An external, qualified privacy professional is formally appointed as your DPO: they maintain your Record of Processing Activities, run Data Protection Impact Assessments, handle data-subject requests, manage breach notification, and act as the contact point for regulators and for your customers.
Is an Israeli company required to appoint a Data Protection Officer?
Amendment 13 to the Israeli Privacy Protection Law requires a Data Protection Officer for defined categories of organisations, including public bodies, data brokers, and controllers whose core activity involves large-scale processing of sensitive personal data. Separately, any Israeli company offering services to individuals in the EU may be required to appoint a DPO under GDPR Article 37. An external DPO satisfies both.
Can the Data Protection Officer be an external service provider?
Yes. Both the GDPR and Israeli law permit the DPO role to be filled on the basis of a service contract rather than employment. An external DPO is often the cleaner option, because the role must be free of conflicts of interest, which excludes the CTO, the head of R&D, and anyone who decides how personal data is processed.