Israel Protection of Privacy Law (5741-1981)
Israel POPL Incident Response + Breach

Israel Protection of Privacy Law (5741-1981) IsraelPPL-Incident-Response-Breach-Notification-PPA-Affected-Customers-Section32A-DSR2017-24Hours: Israel POPL Incident Response + Section 32A Severe Security Incident Notification + Data Security Regulations 2017 Article 11 + PPA Notification + Affected Customers + 24-72 Hour Window + Amendment 13 Enforcement

Incident response and breach notification governed by Section 32A POPL + Article 11 of Data Security Regulations 5777-2017 + Amendment 13 reinforcement. (1) Section 32A Severe Security Incident: controller must notify the Privacy Protection Authority of a severe security incident defined as an incident that (a) raises a real concern of compromise to information integrity; (b) involves transmission of information without authorisation; (c) involves use of information without authorisation; (d) affects substantial number of data subjects or sensitive data. (2) Article 11 Data Security Regulations 2017 - Notification Timelines: (a) PPA notification - severity-based + typically within 24-72 hours of becoming aware of severe incident; (b) Data subjects affected - notification where there is a real risk of substantial harm + content includes (i) description of incident; (ii) categories of data affected; (iii) likely consequences; (iv) measures taken; (v) advice to mitigate. (3) Incident Categories per Article 11: (a) Unauthorised access to or theft of database; (b) Loss of removable media containing personal data; (c) Ransomware affecting database availability; (d) Insider misuse + employee theft; (e) Cloud/CSP breach; (f) Cyber attack including phishing + business email compromise + supply chain. (4) Incident Response Plan: documented IR plan + IR team + IR phases (Detection + Containment + Eradication + Recovery + Lessons Learned) + tabletop exercises + cooperation with Israeli National Cyber Directorate (INCD) + IL-CERT + sectoral CERTs + criminal referral to police + Bank of Israel notification for financial sector + Ministry of Health for medical + INCD for critical infrastructure + INTERPOL/Europol for international. (5) Forensics: forensically sound investigation + chain of custody + cooperation with law enforcement + retention of digital evidence + reporting to insurer if cyber insurance applicable. (6) Customer Communication: transparent communication including incident page + customer email + SMS where appropriate + call centre support + identity theft monitoring offer + credit monitoring + transparency around containment + remediation + lessons learned. (7) Multi-Jurisdictional Coordination: where breach affects EU data subjects - additional GDPR 72-hour breach notification + Article 33 + Article 34; where US data subjects - state breach notification laws; where UK data subjects - UK ICO + GDPR. (8) Amendment 13 Enforcement: enhanced PPA enforcement powers + administrative fines for non-notification + clarified incident reporting framework + enhanced cyber resilience expectations. Coordinates with GDPR Arts 33 + 34 + DPDP Sec 8(5) 72-hour + Israeli National Cyber Directorate + IL-CERT + Bank of Israel + Ministry of Health + INTERPOL/Europol + ISO 27035 + NIST SP 800-61. Israel POPL Incident Response applies.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.