Adv. Elen Yosef , Partner and Head ofthe Privacy Protection and Information Security practice at ABADI & CO.,presents the key points of the Authority’s position paper regarding the obligation to appoint a Data Protection Officer, and clarifies the practical implications for organizations with respect to the applicability of the obligation, voluntary appointment, the DPO’s independence, and conflicts of interest.
On July 14,2026, the Privacy Protection Authority (the “Authority”) published its position paper regarding the obligation to appoint a Data Protection Officer (a “DPO”),pursuant to Amendment No. 13 to the Privacy Protection Law, 5741-1981 (the“Privacy Protection Law”).
The Authority expressed its view that the appointment of a DPO is a central component of the principle of accountability. This principle requires an organization not only tocomply with the provisions of law applicable to the use of information, butalso to implement internal mechanisms, procedures, and work methods that will ensureeffective compliance with legal requirements.
The positionpaper reflects the Authority’s position regarding the interpretation of the provisions of the Privacy Protection Law in this context and addresses, among other matters, the circumstances in which the obligation to appoint a DPO arises, the DPO’s duties, required qualifications, organizational status, and terms of engagement.
Set out beloware the key issues arising from the position paper:
To whomdoes the obligation to appoint a DPO apply?
In accordance with the provisions of the Privacy Protection Law, the obligation to appoint aDPO applies, among others, to:
· Public bodies and, in certain cases, organizations that process personal informationon their behalf.
· Organizations whose main activity is the collection of personal information for disclosure too thers, including entities engaged in data trading and, in certaincircumstances, entities providing direct mailing services.
· Organizations whose main activities include regular and systematic monitoring of individuals,for example through applications, websites, search services, location data,surveillance cameras, wearable devices, and IoT products
· Organizations whose main activity involves large-scale processing of especially sensitive information, including banks, insurance companies, hospitals, and health funds/HMOs.
What is “large-scale”?
With respect tocases in which the obligation to appoint a DPO applies, and particularly where entities process especially sensitive information on a “large-scale” basis, the Authority clarifies that there is no uniform quantitative thres hold or unequivocal numerical test.
For purposes of the assessment, consideration should be given, among other things, to the number of data subjects, their proportion within a particular population, the types of information, the volume of information, the duration and frequency of processing, the retention period, and the geographic scope of the processing activity.
Accordingly,even where the number of data subjects is not especially large, the processing may still be considered large-scale in the relevant circumstances.
Voluntary appointment
The Authority recommends that organizations that are not legally required to appoint a DPO never the less consider doing so. The Authority emphasizes that voluntary appointment may be particularly important for dual-nature entities, namely organizations that a resubject, at least in certain aspects of their activities, to principles derivedf rom public law.
Conflicts of interest
The Privacy Protection Law provides that a DPO may not hold an additional position, or be subordinate to an officer, if doing so could give rise to a concern of aconflict of interest in the performance of the DPO’s duties. The purpose ofthis restriction is to ensure that the DPO can formulate independent professional positions, free from external influence or competing considerations.
In this context,the Authority clarifies that a DPO may not hold a role, or report to office holders,who have the authority or responsibility to determine the organization’s policy regarding the processing of personal information, including the purposes,methods, and means of such processing.
According to the Authority’s position, a concern of a conflict of interest may arise, among other things, in senior roles such as Chief Marketing Officer, Head of Customer Relations, Chief Financial Officer, and CTO. In addition, as a general rule, a concern of a conflict of interest also exists with respect to the Chief Information Officer and those reporting to that role.
Distinction between the DPO role and legal counsel
The Authority clarifies that a DPO may be positioned within the organization’s legal department, provided that this does not give rise to a conflict of interest.
However, theAuthority considers that such positioning may not necessarily enable the organization to derive the full benefit of the role, given the substantivedistinction between the role of legal counsel and the role of the DPO: while legal counsel is primarily focused on ensuring compliance with legalrequirements, the DPO’s role also includes promoting privacy protection beyondthe minimum standard required by law.
According to theAuthority’s position, a DPO who also serves as legal counsel must “take organizational and other measures through which it will be possible to clearly distinguish between their activities as DPO and their activities as legal counsel”. One example of such measures is that the DPO should ensurethat they sign as DPO, rather than as legal counsel, when acting in thecapacity of DPO. Another example proposed by the Authority is to separate the email inboxes used for the different roles: one inbox for activity as DPO, andone inbox for activity as legal counsel.
Therelationship between the DPO and the Information Security Officer
The Authority expresses its view that a DPO and an Information Security Officer are two separate rolesthat are fundamentally different in nature, each requiring different knowledge,skills, and capabilities.
The Authority does not rule out the possibility that an Information Security Officer may also serve as the DPO but emphasizes that such an appointment raises substantive questions regarding suitability, independence, the ability to perform bothroles simultaneously in terms of workload and reporting lines and therefore requires an individual assessment.
An organization seeking to appoint one person to serve both as DPO and as Information Security Officer must be able to demonstrate, on a substantiated and documented basis, that all applicable requirements relating to the DPO’s qualifications, availability, seniority, andindependence are in fact satisfied.
Conclusion
The Authority’sposition paper emphasizes that appointing a DPO is not merely a formal step,but rather an integral part of an organization’s corporate governance andprivacy compliance framework.
Organizations considering appointing a DPO from among their legal, technology, or information security functions should examine not only the candidate’s professional qualifications, but also their position within the organizational structure, the scope of their authority, andtheir ability to exercise independent and impartial judgment with respect to organizational decisions concerning the processing of personal information.
We would be pleased to assist with such assessment and, of course, to answer any questionson this matter.
Legal disclaimer:
The foregoingis provided for general informational purposes only and does not constitute a legal opinion or a substitute for legal advice tailored to the circumstances ofeach organization. In light of the possible implications of the position paper,we recommend examining its implementation on a case-by-case basis and obtaining specific legal advice accordingly.
The Authority’s position paper is available here .

