Board Data Security Duties: The Privacy Authority’s New Binding Guideline

3 min. read

In September 2024, Israel’s Privacy Protection Authority published the final, binding version of Guideline 1/2024, on the board’s role in fulfilling a company’s data security duties. The guideline provides that companies whose core activity involves processing personal data, or whose activity creates heightened privacy risk, require closer board oversight. The board must discuss the database definitions document, the data security procedure’s principles, risk survey and penetration test results, security incidents, and periodic audit findings. Non-compliance may be deemed a violation of the law, and could even form the basis for a derivative suit against directors.

About a year ago, the Israeli Privacy Protection Authority published a draft guideline on the role of the board of directors in fulfilling a company’s personal data security duties. Last Thursday, September 12, 2024, the Authority published the guideline’s final, binding version.

In the Authority’s view, the guideline’s purpose is to spotlight existing law (as derived from a purposive interpretation of privacy protection law and fundamental corporate governance principles) – emphasizing that companies whose activity involves privacy risks require closer board attention and oversight.

Accordingly, the guideline applies to companies where the processing of personal data is at the core of their activity, or whose activity creates heightened privacy risk. Heightened privacy risk may arise from the sensitivity of the personal data processed, the volume of personal data processed, or the number of people with access to it and to the systems through which it is processed.

Given that many commercial activities involve the processing of sensitive personal data, or the processing of large volumes of personal data, or granting access to numerous authorized users – and at times a combination of all of these – the guideline is expected to apply to many companies.

In 2017, the Privacy Protection (Data Security) Regulations, 5777-2017, were enacted, coming into force in May 2018 (the “Data Security Regulations” or the “Regulations”). The Data Security Regulations impose a long list of duties on database owners and other parties.

For example, the Regulations require that a database definitions document be prepared for every database, describing, among other things, the data collection and use activities, the types of personal data, the purposes of its use, and more.

The new guideline provides that fulfillment of these duties must take place under the board’s oversight and control, under an implementation policy and effective compliance and control processes, and in particular through:

  • Discussion of the database definitions document before its final approval (per Regulation 2(a));
  • Discussion of the key principles of the organizational data security procedure before its final approval (per Regulations 3(2) and 4(a));
  • Discussion of the results of risk surveys and penetration tests, and of the actions required to correct the deficiencies found (per Regulations 5(c) and 5(d));
  • A quarterly or annual discussion (depending on the database’s security level) of data security incidents that occurred in the organization (per Regulation 11(c));
  • Discussion of the results of the periodic audit (to be conducted once every two years) regarding compliance with the Regulations (per Regulation 16(c)).

In certain cases, the guideline permits the board to delegate its duties to another function within the company, while overseeing their fulfillment.

The guideline clarifies that it does not diminish the responsibility of other parties under the Data Security Regulations or the law (or the company’s foundational documents), such as company management, database managers, and others.

Failure to comply with the guideline may constitute an apparent violation of the law and the Regulations by the company. Combined with Amendment 13 to the law, which is due to come into force in about a year, this will significantly increase the cost of non-compliance with the law and the Regulations.

Failure to comply with the guideline may also, in certain cases, serve as a basis for a derivative suit against directors.

The guideline does not address corporations subject to parallel regulation, such as banks or insurance companies. Under specific Privacy Protection Authority guidance, the Data Security Regulations do not apply in full to such entities – only in part – provided they comply with the parallel regulation applicable to them. For such corporations, the new guideline likely addresses the board’s duties only with respect to those specific duties that apply to them.

you might be interested in

Articles

Amit Steinman, Managing Partner at S. Horowitz: AI is a tool, not a source of authority

Updates

Israel’s new Legislative Memorandum sets out a licensing regime for stablecoin issuers – what it means for the market.

Updates

Israel Tax Authority guidance on secondary sale transactions and a new position paper on income spreading for employee options.

Subscribe

Get the latest updates straight to your inbox

SHARE

Facebook
LinkedIn
WhatsApp
Email
Print