ממונה הגנת מידע

What happens when there is no data protection officer in the organization – the case that cost hundreds of thousands of shekels

Introduction: The Importance of a Data Protection Officer

Many organizations in Israel still refer to the term “data protection” as a recommendation. But Amendment 13 to Privacy Protection Law, combined with new enforcement trends from the Privacy Protection Authority, make it clear: this is a binding, critical issue – and very costly when ignored. 

At the center of the article is a real-life case of an organization that neglected its data protection responsibilities until the painful consequences set in. This is not a story about a hacker attack – but about internal management failure that turned into a legal and financial breach.

The case: open database, closed regulation

This is a medium-sized organization in the financial services sector, which manages databases with sensitive personal information: ID cards, financial status, addresses, family members' details, and more. For years, the data was accumulated - but procedures were not updated, no data protection officer was appointed, and no data retention policy was defined.
When a customer complained that his information was distributed to unauthorized parties, the authority launched an investigation, revealing shortcomings: open permissions, partial registration, lack of documentation, and above all, the lack of a legally appointed DPO.

The price: not just money

The result: a fine of 150,000 NIS, in addition to the requirement to appoint a DPO within 14 days, establish a system of controls, training courses for employees, and regular annual reporting to the Authority. The damage to the image was no less serious: a media article, the departure of key customers, and a loss of trust.

How could this have been avoided?

By simply appointing a data protection officer, the organization could prepare in advance:
The DPO is not just “another role” – it is a management protection mechanism that proves to the world (and the regulator) that the organization understands the importance of protecting personal information.

Who needs a DPO?

According to Israeli law, every public body, and every private body that manages sensitive information or over 100,000 records, is required to appoint a data protection officer. However, even organizations that are not required to do so are choosing today to appoint a DPO as a preventive, business, and responsible act.

In conclusion

One thing is for sure: it’s easier to be prepared than to apologize. Appointing a DPO is not an expense – but a huge potential savings. It protects the organization legally, prevents costly mistakes, and conveys responsibility and regulatory compliance – in the eyes of customers, partners, and public bodies.
Cybersecurity and IT – two worlds, one solution.
Picture1
Author

Idan Zabari

IDAN ZABARI is a leading strategic IT and cyber consultant. He helps businesses and organizations secure their data, promote technological innovation, and meet regulatory requirements. He believes in a practical and realistic approach tailored to the needs of small and medium-sized businesses.
Facebook
Twitter
LinkedIn
Scroll to Top