© All rights reserved to Barnea Jaffa Lande Law offices

Together is powerful

Position Statement on the Obligation to Appoint a DPO: Not a Change in the Law, but a Change in the Rules of the Game

Summary

  • The Privacy Protection Authority’s position statement: Israel’s Privacy Protection Authority (PPA) has published the final version of its position statement on the appointment of a data protection officer (DPO). Although, formally speaking, it is only a position statement rather than binding guidance, it is expected to have a significant practical impact on the PPA’s supervision and enforcement going forward.
  • The central message is clear: It is no longer enough to “tick a box” by appointing a DPO. The PPA expects an individualized, reasoned, and documented assessment, and a DPO with genuine independence, adequate resources, a direct reporting line, and meaningful involvement in organizational processes. In other words, a “paper” appointment has become a source of exposure rather than protection.
  • Practical implications: The implications are broader than they may first appear. Cloud, SaaS, and outsourcing providers must assess whether the obligation applies based on the cumulative scope of their activities across all clients, not on a client-by-client basis—a shift that may bring many organizations within the scope of the appointment obligation. The PPA also chose not to set clear quantitative thresholds, and its interpretation of terms such as “core business” and “ongoing and systematic monitoring” may expand the range of organizations that need to assess whether the obligation applies.
  • Dual roles and engagement model: The position statement sharpens the requirements regarding dual roles, conflicts of interest, and the engagement model. It emphasizes the advantages of an internal appointment while remaining silent on those of an external appointment, even though the law itself does not prefer one route over the other.
  • Required preparedness: Organizations that have not recently revisited whether they need to appoint a DPO should do so now. This is not merely an internal policy update, but a strategic decision that should be supported by documentation, an appropriate reporting structure, clear role definitions, and genuine involvement. The decision whether to appoint a DPO is legitimate either way, provided it is informed, reasoned, and documented.

1.     The final position statement: Why does it matter now?

Last week, Israel’s Privacy Protection Authority (PPA) published the final version of its position statement on the appointment of a data protection officer (DPO) in organizations, following the draft published in July 2025.

 

The position statement does not change the law and does not, in and of itself, create a new obligation to appoint a DPO. However, the PPA makes clear that the interpretation set out in the position statement will guide its supervision and enforcement. Accordingly, even organizations that have so far assumed that they are not required to appoint a DPO—including service providers, SaaS providers, cloud service providers, and operators of websites and apps—must now, at a minimum, conduct an individualized, reasoned, and documented assessment of their position.

 

The document comes about a year after Amendment 13 to the Privacy Protection Law took effect and marks the official transition from the preparation phase to the practical enforcement phase. The appointment question is no longer theoretical, but a practical compliance decision that every organization must address in an informed way.

 

2.     What is new in the final position statement?

The final position statement does not change the law, but it does change the rules of the game and the practical starting point. The PPA’s message is clear: no more “paper” appointments and no more easy reliance on legal ambiguity without a concrete assessment of the organization in light of its characteristics and the privacy protection risks arising from its activities.

 

The DPO is presented as an independent and significant function within the organization, and the focus shifts to conflicts of interest, resources, independence, the structure of the appointment, and orderly documentation of the decision-making process, including where the conclusion is that no appointment is required, and the reasons for that conclusion.

 

3.     What does the role of a DPO actually include?

The DPO is a substantive, active privacy governance function, not merely a formal appointment. The role is to lead and oversee privacy within the organization and to embody the accountability principle, under which an organization must both comply with the law and be able to demonstrate compliance.

 

However, the final position statement clarifies that the DPO is an advisory, supervisory, and auditing function, not the organization’s decision-maker on processing. Accordingly, the DPO bears no personal responsibility for the organization’s compliance and is not personally required to report violations or security incidents to the PPA, although the DPO must be involved in handling them and in any required reporting.

 

4.     Which organizations are required to appoint a DPO, and who needs to reassess?

The obligation to appoint a DPO applies to organizations that meet the criteria set out in Section 17B1(a) of the Privacy Protection Law, including public bodies (and holders acting on their behalf), entities engaged in data trading, entities whose core business includes “ongoing and systematic monitoring,” and entities whose core business includes “large-scale processing” of sensitive information.

 

Key points of the position statement and their practical implications:

 

  • The appointment obligation for a “holder” (cloud service, SaaS, or outsourcing providers): The PPA clarifies that a holder’s obligation to appoint a DPO must be assessed cumulatively across all clients, not on a client-by-client basis. As a result, processing small databases for many clients may still be regarded as “large-scale” processing.
  • Expansion of the term “core business”: The position statement adopts a broad reading of “core business,” under which data processing may suffice if it is a central or inherent component of the core activity, even if it is not essential to it. This may broaden the appointment obligation beyond the law’s clearer examples and raises doubt as to whether a position statement should do so.
  • “Ongoing and systematic monitoring”: The final text still leaves significant interpretive uncertainty. The PPA’s examples, especially those relating to websites, apps, and analytics tools, may be read so broadly that almost any website or app appears to require a DPO. As a result, even organizations using basic analytics tools may need to assess carefully whether the appointment obligation applies.
  • The need for an individualized assessment: Despite public comments, the PPA chose not to set quantitative thresholds that could have helped in applying ambiguous terms such as “large-scale processing,” and in the final text it appears to have expanded the scope of application beyond the binding statutory language.

 

5.     Engagement model: Must the DPO be an internal employee?

Unlike the earlier draft, the final text suggests a possible advantage, though not a legal preference, for an internal DPO, especially one who serves full-time. The law also permits an external appointment, which may offer advantages in terms of independence, expertise, and broader perspective. The choice should depend on the organization’s characteristics, complexity, and scale of processing, not on any assumption that an internal appointment is preferable.

 

6.     Identity of the DPO in an outsourced model

The position statement emphasizes that only an individual—that is, a natural person—may be appointed as a DPO. This is intended to address organizations engaging an external company or corporate entity for DPO services and to clarify that the appointment itself must identify a specific individual with the required qualifications.

 

7.     Can the DPO also serve in another role within the organization?

Many organizations tend to assign the DPO role to existing officeholders. The final position statement does not rule out all dual-role arrangements, but it imposes limits, conditions, and a requirement for an individualized assessment and documentation.

 

  • Combining the DPO role with the legal department:

According to the position statement, the PPA permits the DPO to be positioned within the legal department, but where the role is assigned to the in-house general counsel (GC), a clear organizational and digital separation between the roles is required, for example through a separate signature block and a dedicated email inbox. The PPA is thus making clear that a dual-role arrangement cannot remain merely formal, but requires an individualized assessment and concrete internal structuring.

  • Dual roles of CISO and DPO:

The PPA clarifies that the law does not prohibit a chief information security officer (CISO) from also serving as DPO, but such an appointment requires an individualized assessment, reasoned analysis, and written documentation. Although the final text softens the claim of an inherent conflict of interest, it still presents practical difficulties, especially in terms of resources, time, privacy law expertise, and the ability to perform both roles independently and effectively.

 

8.     Conflict of interest issues: a substantive threshold requirement for DPO appointments

The duty to prevent conflicts of interest is a standalone substantive threshold requirement. It requires an organization to carry out an active review of reporting lines and internal roles, regardless of whether the officeholder appears on the list of examples provided by the PPA. In other words, the list is not a closed list, but merely a starting point for a broader review.

 

The final text makes clear that roles such as chief marketing officer, account manager, chief financial officer, and CTO often raise conflict-of-interest concerns because they may help determine the purposes or means of processing. It also states categorically that an IT manager or chief information officer (CIO) and those subordinate to that function may not serve as DPO due to an inherent conflict of interest. This rules out a common organizational practice and may require changes to existing appointments.

 

Recommendations

In light of the final position statement, we recommend that organizations take the following steps:

 

  • Reassess the obligation to appoint a DPO, especially in light of the interpretation given to the terms “holder,” “core business,” “large-scale processing,” and “ongoing and systematic monitoring.”
  • Document the decision-making process, even where the conclusion is that no appointment is required. In light of the PPA’s position that the interpretation in the position statement will guide its supervision and enforcement, the existence of a reasoned and documented review may be as important as the conclusion itself.
  • Where the appointment obligation applies, define the DPO’s position within the organization, including responsibilities, resources, a direct reporting line, and involvement in relevant processes.
  • Review the engagement model and the identity of the DPO, including the option of an internal or external appointment, and ensure that the appointment is personal—that is, made in respect of a specific qualified individual—and supported by a substantive and documented assessment.
  • In cases of dual roles or potential conflicts of interest, carry out an individualized legal assessment and document the decision and the arrangements put in place to safeguard the DPO’s independence, particularly if the role is combined with GC or CISO functions or interfaces with IT/CIO functions.
  • Update internal working and control procedures to ensure the DPO’s effective involvement in key matters, including information security incidents, data subject requests, reporting to the PPA, and other privacy-related processes.

 

The choice whether to appoint a DPO should no longer rest on a formal review alone. Organizations must revisit the question of DPO appointment on the basis of an individualized, substantive, and documented legal assessment tailored to their activities and privacy risks. Where needed, and particularly in complex or borderline cases, it is advisable to obtain a supporting legal opinion to reinforce the decision taken.

 

***

 

Dr. Avishay Klein is a partner and head of the firm’s Privacy, Cyber and Artificial Intelligence Department.

Adv. Liav Shapira is a partner in the firm’s Privacy, Cyber and Artificial Intelligence Department.

Adv. Masha Yudashkin is an associate in the firm’s Privacy, Cyber and Artificial Intelligence Department.

 

Our PrivacyAI, and Cyber Department is at your disposal to advise on the implications of the position statement and the risks arising from the PPA’s requirements, to assess their impact on your activities, and to assist with the organizational preparations required to meet the standards set out in the document.

 

Tags: DPO | Privacy Law