תיקון 13 הוא לא פרויקט של החלפת נוסח במדיניות הפרטיות. הוא מחייב ארגונים להבין איזה מידע אישי הם מחזיקים, למה הם משתמשים בו, מי מקבל אותו ואיך הם מגנים עליו.
Art of Cyber מלווה חברות בהיערכות מעשית לתיקון 13: מיפוי מידע ותהליכים, בדיקת החובות שחלות על הארגון, תיעוד פערים, תוכנית תיקון ובקרות שאפשר להפעיל גם אחרי שהפרויקט מסתיים.
העבודה נעשית יחד עם ההנהלה, IT, אבטחת מידע, תפעול ומשפטי. הייעוץ אינו תחליף לייעוץ משפטי. הוא הופך את דרישות הדין לתוכנית עבודה ארגונית וטכנית.
מה תיקון 13 שינה?
התיקון הרחיב את סמכויות האכיפה של הרשות להגנת הפרטיות, עדכן הגדרות וחובות, וחידד את האחריות של ארגונים שמעבדים מידע אישי. בחלק מהארגונים קיימת גם חובת מינוי ממונה על הגנת הפרטיות, בהתאם לסוג הפעילות ולהיקף העיבוד.
לא כל ארגון כפוף לאותן חובות. הצעד הראשון הוא לא לקנות תבנית, אלא לבדוק מה חל על הפעילות הספציפית.
למי השירות מתאים?
- חברות שאוספות מידע על לקוחות, עובדים, מועמדים או משתמשים
- SaaS, פינטק, מדטק, בריאות וחברות עם מאגרי מידע משמעותיים
- ארגונים שמעבירים מידע לספקי ענן או לספקים מחוץ לישראל
- חברות שצריכות לענות ללקוחות על פרטיות ואבטחת מידע
- הנהלות שרוצות לדעת מה חסר לפני ביקורת, עסקה או אירוע
- ארגונים שבודקים אם הם חייבים למנות DPO או צריכים DPO as a Service
מה כולל הליווי?
ההיקף מותאם לארגון ויכול לכלול:
- מיפוי מאגרי מידע, סוגי מידע ותהליכי עיבוד
- מיפוי מטרות השימוש, מקורות המידע והעברות לצדדים שלישיים
- בדיקת חובות רישום, הודעה לרשות ותיעוד
- בדיקת חובת מינוי ממונה על הגנת הפרטיות
- בחינת הודעות פרטיות, טפסים ותהליכי הסכמה
- תהליך לטיפול בבקשות עיון ותיקון
- מיפוי ספקים, הסכמים וגישה למידע
- בחינת העברות מידע מחוץ לישראל
- מדיניות שמירה, מזעור ומחיקה
- סקר פערי אבטחה ובקרות לפי הסיכון
- תוכנית טיפול עם סדרי עדיפויות, בעלי אחריות ולוחות זמנים
- הדרכת הנהלה ועובדים לפי הצורך
כאשר נדרשת פרשנות משפטית, עובדים לצד היועץ המשפטי של הארגון. Art of Cyber מרכזת את הצד המעשי: מערכות, תהליכים, ספקים, בקרות, ראיות ומעקב.
איך נראה התהליך?
1. קובעים את ההיקף
מבינים אילו פעילויות, מערכות וחברות בקבוצה נמצאות בתוך הבדיקה.
2. ממפים מידע ותהליכים
לא מסתפקים ברשימת מערכות. בודקים מה נכנס, למה, מי משתמש, למי מועבר וכמה זמן נשמר.
3. מזהים חובות ופערים
מפרידים בין חוסר משפטי, חוסר תהליכי וחוסר טכני. כל פער מקבל חומרה, בעלים ודרך סגירה.
4. מתקנים ומתעדים
מעדכנים טפסים ומדיניות, סוגרים הרשאות, מסדירים ספקים ובונים תהליכים שאפשר להפעיל.
5. עוברים לניהול שוטף
פרטיות אינה מסמך חד-פעמי. שינויים במוצרים, ספקים, AI ושיווק דורשים בדיקה חוזרת.
תוצרים אפשריים
- מפת מידע ומאגרי מידע
- רשימת חובות שחלה על הארגון
- דוח פערים ותוכנית תיקון
- מדיניות פרטיות והודעות איסוף מעודכנות בתיאום משפטי
- נוהל זכויות נושאי מידע
- נוהל שמירה ומחיקה
- רשימת ספקים והעברות מידע
- דרישות אבטחה ותוכנית בקרות
- חבילת דיווח להנהלה
כמה עולה ליווי לתיקון 13?
המחיר תלוי במספר המערכות והחברות, סוגי המידע, היקף הספקים, מורכבות ההעברות והמצב הקיים.
אפשר לעבוד בשלושה מודלים:
- סקר פערים ממוקד עם דוח ותוכנית טיפול
- פרויקט היערכות מלא ממיפוי ועד הטמעה
- ליווי שוטף / DPO as a Service לאחר סגירת הפערים הראשוניים
אחרי שיחת מיפוי קצרה אפשר להגדיר את ההיקף ולתת הצעה קבועה לפרויקט או מסגרת חודשית ברורה.
השורה התחתונה
המטרה אינה להבטיח ש"הכול תואם" אחרי פגישה אחת. המטרה היא לדעת אילו חובות חלות, מה הסיכון בפועל, מה צריך לתקן קודם ואיך מוכיחים שהארגון מנהל פרטיות באופן שוטף.
השאירו פרטים לשיחת מיפוי. נבדוק את סוג הפעילות ונגדיר את הצעד הראשון בלי למכור פרויקט גדול מהנדרש.
שאלות נפוצות
האם כל חברה חייבת למנות DPO בעקבות תיקון 13?
לא. החובה תלויה בסוג הפעילות, סוגי המידע והיקף העיבוד. צריך לבדוק את הפעילות הספציפית ולא להסתמך על מספר עובדים בלבד.
האם עדכון מדיניות הפרטיות מספיק?
לא. מדיניות היא רק חלק מהתמונה. צריך לבדוק גם מערכות, הרשאות, ספקים, שמירה ומחיקה, זכויות נושאי מידע ובקרות אבטחה.
האם Art of Cyber מספקת ייעוץ משפטי?
לא. השירות מתמקד בהיבטים הארגוניים, הטכנולוגיים והתפעוליים ועובד לצד יועצים משפטיים כאשר נדרשת פרשנות משפטית.
אפשר להתחיל רק בסקר פערים?
כן. סקר ממוקד מתאים לארגון שרוצה קודם להבין מה חל עליו, מה חסר ומה סדר העדיפויות.
Amendment 13 readiness is not a privacy-policy rewrite. Organizations need to understand what personal information they hold, why they use it, who receives it, how long they keep it, and how it is protected.
Art of Cyber supports companies with practical Amendment 13 readiness: data and process mapping, applicability of the law's duties, gap documentation, a remediation plan and controls that keep working after the project ends. The work is done with leadership, IT, security, operations and legal. The service does not replace legal advice; it turns legal requirements into an organizational and technical work plan.
What did Amendment 13 change?
The amendment widened the Privacy Protection Authority's enforcement powers, updated definitions and duties, and sharpened the responsibility of organizations processing personal data. Some organizations must also appoint a data protection officer, depending on the type of activity and the scale of processing. Not every organization carries the same duties. The first step is not buying a template. It is checking what applies to your specific activity.
Who is it for?
- Companies collecting data on customers, employees, candidates or users
- SaaS, fintech, medtech, health and companies with significant data repositories
- Organizations transferring data to cloud vendors or providers outside Israel
- Companies that must answer customers on privacy and security
- Leadership teams that want to know what is missing before an audit, a deal or an incident
- Organizations checking whether they must appoint a DPO or need DPO as a Service
What does the work include?
Scope is tailored to the organization and can include:
- Mapping data repositories, data types and processing activities
- Mapping purposes, data sources and transfers to third parties
- Checking registration, notification and documentation duties
- Checking whether a data protection officer must be appointed
- Reviewing privacy notices, forms and consent processes
- A process for data-subject access and correction requests
- Vendor, contract and data-access mapping
- Reviewing data transfers outside Israel
- Retention, minimization and deletion policy
- A security gap review and risk-based controls
- A remediation plan with priorities, owners and timelines
- Management and employee training as needed
Where legal interpretation is required, we work alongside the organization's legal counsel. Art of Cyber owns the practical side: systems, processes, vendors, controls, evidence and tracking.
How does the process look?
1. Set the scope
We understand which activities, systems and group companies are inside the review.
2. Map data and processes
Not a system list. We check what comes in, why, who uses it, who receives it and how long it is kept.
3. Identify duties and gaps
We separate legal gaps, process gaps and technical gaps. Each gap gets a severity, an owner and a closing path.
4. Remediate and document
Update forms and policies, close permissions, regulate vendors and build processes that can actually run.
5. Move to ongoing management
Privacy is not a one-time document. Changes in products, vendors, AI and marketing require re-checks.
Possible deliverables
- A data and repository map
- A list of duties that apply to the organization
- A gap report and remediation plan
- Updated privacy policy and collection notices, coordinated with counsel
- A data-subject rights procedure
- A retention and deletion procedure
- A vendor and data-transfer register
- Security requirements and a control plan
- A management reporting pack
How much does Amendment 13 support cost?
Price depends on the number of systems and entities, data types, vendor count, transfer complexity and current state. Three models are available: a focused gap assessment with a report and remediation plan; a full readiness project from mapping to implementation; or ongoing support and DPO as a Service after the initial gaps close. After a short scoping call we can define scope and give a fixed project price or a clear monthly frame.
Bottom line
The goal is not to declare "everything is compliant" after one meeting. The goal is to know which duties apply, what the actual risk is, what to fix first, and how to prove the organization manages privacy continuously.
Book a scoping call and we will come back with a precise proposal.