Data Protection Matters
הגנת פרטיות: מהתיאוריה לפרקטיקה
מאמרים ומדריכים מקוריים, אינדקס חוקי הפרטיות של העולם וכלים חינמיים, לחיפוש וסינון במקום אחד.
התוכן נועד להעשרה ולעיון כללי, ואינו מהווה ייעוץ משפטי. אנו עושים מאמץ מרבי להבטיח את דיוק המידע אך איננו יכולים להתחייב לכך, ויש לאמת אותו תמיד מול המקורות הרשמיים (הערה משפטית מלאה מופיעה מטה).
מאגר הידע הישראלי
כלים ותוכן מקוריים בעברית למסגרת הישראלית, לצד מאמרים ומדריכים שנוסיף כאן.
חיפוש בחוק הישראלי ובפרסומי הרשות
שאלו שאלה בעברית וקבלו ציטוט מדויק מחוק הגנת הפרטיות או מפרסומי הרשות להגנת הפרטיות, עם קישור ישיר למקור המלא.
ISO 27001 נועד לנהל סיכונים, לא לייצר מסמכים
ISO 27001 לא נועד לייצר מסמכים אלא להקים מערכת ניהול אבטחת מידע מבוססת סיכון, שפועלת כל השנה ולא רק לקראת ביקורת. על ההבדל בין תיעוד לבין ניהול.
קריאה → מסגרות עבודה וממשל תאגידיהזכות לעיון במידע אישי: האם הארגון באמת יודע מה הוא מחזיק עלינו?
הזכות לעיין במידע אישי נראית כדרישה פשוטה, אבל כדי להשיב עליה הארגון צריך לדעת איזה מידע הוא מחזיק, היכן ולמה. על מיפוי מידע כתהליך חי.
קריאה →מאגר הידע הבינלאומי
מאמרים, מדריכים ואינדקס חוקי הפרטיות של העולם. התוכן באנגלית, וניתן לחיפוש וסינון יחד עם התוכן הישראלי.
Articles
חיפוש ב-GDPR וב-EDPB
חיפוש בטקסט המלא של ה-GDPR, הסעיפים וההקדמות, יחד עם ההנחיות וההמלצות של ה-EDPB, מהמקורות הרשמיים.
Turn your DPIA into a business asset, not a box to tick
A Data Protection Impact Assessment done well is not paperwork. It is one of the clearest views of risk your organization will ever produce. Here is how to get there.
Read → AI & GovernanceWhy Ethical AI Is an Engineering Problem, Not Just a Policy One
Ethical AI is not just about policy and regulation. It is fundamentally an engineering challenge. Learn why fairness, transparency, and security need to be treated with the same rigor as performance and reliability in the AI development lifecycle.
Read → Global RegulationsVietnam's New Data Privacy Frontier: A Comprehensive Guide to Law No. 91/2025/QH15
Vietnam is no longer just a manufacturing alternative; it has officially emerged as a mature technology hub with a rigorous legal framework to match. As of January 1, 2026, the new Law on Personal Data Protection is in full effect, introducing GDPR-style mandates, mandatory DPIAs, and aggressive revenue-based fines. Is your organization ready for the 'Brussels Effect' in Southeast Asia?
Read → AI & GovernanceAccountability in Motion: OpenAI Appeals and Age Assurance
This week features a major legal win for OpenAI as an Italian court canceled its €15 million fine, signaling a more mature phase in AI enforcement. Meanwhile, the UK ICO's penalty against Reddit underscores that "self-declaration" for age checks is no longer sufficient; platforms must implement robust age assurance. Across Europe, a growing push for "joined-up" regulation highlights that privacy, AI, and competition laws must now be managed as a single strategic ecosystem.
Read → EU Data Strategy & GDPRGuest Checkout: No Longer a Luxury, but a GDPR Requirement
The EDPB's Recommendations 2/2025 (published for consultation in December 2025) indicate that forcing users to create an account for one-time purchases is hard to justify under the GDPR. Unless strictly necessary for the contract, guest checkout should be the default. Personalization and administrative convenience do not justify mandatory registration. This shift pushes retailers to adopt "privacy by design" by offering guest modes to ensure data minimization and respect user choice.
Read → Industry SpotlightsSimplifying the GDPR: The EU Digital Omnibus and EdTech Privacy
The EU's new "Digital Omnibus" aims to simplify GDPR and AI laws by refining personal data definitions and streamlining consent. Simultaneously, the EU Court is re-evaluating the US-EU data flow agreement, creating potential residency risks for global firms. In the US, the FTC's settlement with Illuminate Education over student data misuse underscores a shift toward aggressive enforcement in the EdTech sector, demanding stricter retention and security protocols for minors' data.
Read → Industry SpotlightsMandatory User Accounts: The EDPB Challenges Common E-commerce Practices
The EDPB's Recommendations 2/2025, published for public consultation, directly challenge the legality of mandatory user registration in e-commerce. This insight explores why the "business as usual" approach to online shopping is no longer defensible under the GDPR, and how retailers can move to a privacy-first checkout.
Read → Industry SpotlightsThe Hidden Ecosystem: Why Tracking Pixels are Your Biggest Legal Liability
Tracking pixels are leaking sensitive data from thousands of sites to tech giants. Meta faces legal pressure as regulators highlight "joint-controller" liability for site owners using these tools. Consequently, many organizations are switching to privacy-preserving, first-party analytics to reduce risk and restore trust.
Read → EU Data Strategy & GDPRThe Right to be Forgotten: California's AB 656 and New GenAI Guidance
This week highlights California's new AB 656 law, which requires large social media platforms to offer a clear "Delete Account" option and to erase user data when an account is deleted, alongside the Delete Act's data broker deletion regime. Meanwhile, the EDPS issued guidance on Generative AI, stressing that GDPR principles like transparency and lawful basis apply fully to AI training and outputs. Lastly, a shift in cyber threats is noted: "silent breaches" involve long-term infiltration and slow data siphoning, requiring organizations to pivot from perimeter defense to proactive anomaly detection.
Read → Industry SpotlightsCross-Regulatory Synergy: The Digital Clearinghouse and Ethical AI in Hiring
This week's insights cover major shifts in data governance: the EU's move toward cross-regulatory coordination (Digital Clearinghouse 2.0), the launch of responsible AI standards for the education sector (K-20 collaboration), and a shift toward ethical AI in hiring. The key takeaway is that privacy and AI governance must be context-specific, requiring organizations to unify oversight across legal frameworks to protect consumers and students effectively.
Read → Frameworks & GovernanceBridging the CISO-DPO Divide: Uniting Cybersecurity and Data Privacy
Tired of CISO-DPO friction? Learn how to transform cybersecurity and data privacy into a powerful, unified force for stronger data protection
Read → Frameworks & GovernanceNavigating the Data Maze: Understanding Processor, Controller, and Joint Controller Roles is Key to Your Data Strategy
Understanding who holds responsibility for personal data is a legal necessity under GDPR. The Data Controller decides the "why" and "how" of processing, while the Data Processor acts only on the controller's instructions. In some cases, Joint Controllers share decision-making. Clearly defining these roles in a Data Processing Agreement (DPA) is crucial for legal compliance, allocating liability in case of breaches, and building trust with customers and partners.
Read → Global RegulationsConsent in the Digital Age: A Case Study of Meta's "Consent or Pay" Tactic
Consent is a fundamental concept in data privacy, serving as the linchpin that aligns personal autonomy with technological advancement. It is the mechanism through which individuals exercise control over their personal information, granting or withholding permission for organizations to collect, process, and share their data.
Read → EU Data Strategy & GDPRNavigating the Complexities of Data Processing Agreements
Data Processing Agreements (DPAs) are the bedrock of trust and compliance in the digital ecosystem, where personal data flows between various stakeholders. These agreements are not mere documents but are foundational to establishing a clear, structured, and legally binding relationship between data controllers and data processors.
Read → Frameworks & GovernanceThe evolving role in the world of privacy protection: a symphony for the rights of data subjects
The world of data protection has evolved beyond a solitary endeavor. Enter Data Privacy Operations (DPOps), a harmonious assembly playing an endless symphony for the rights of data subjects.
Read → Global RegulationsAn In-Depth Look at China's Personal Information Protection Law (PIPL) and Its Comparison with GDPR
China's PIPL sets stringent rules for collecting and processing personal data, drawing many parallels to the GDPR. It grants individuals rights to access, correct, and delete data while imposing heavy fines for violations. Key differences include PIPL's specific focus on businesses within China and its unique consent requirements. This landmark law significantly impacts how global companies manage information, requiring strict adherence to principles like data minimization and security.
Read → EU Data Strategy & GDPRGuidelines for Ensuring Privacy of Health-Related Data
The Council of Europe's Recommendation CM/Rec(2019)2 provides a framework for protecting sensitive health data in the digital age. It emphasizes key principles: transparency, lawfulness, and fairness in data processing. Organizations must obtain explicit consent, implement "privacy by design," and ensure robust security measures. These guidelines balance the need for medical research with the fundamental right to individual privacy, ensuring public trust in healthcare technologies.
Read → Frameworks & GovernanceElevating Security Standards: Embracing the Transition to ISO 27001:2022
ISO 27001:2022 updates the global standard for information security management. Key changes include a more risk-based approach, simplified control themes (Organizational, People, Physical, Technological), and 11 new controls like threat intelligence and cloud security. This version offers greater flexibility and addresses modern cyber threats. Transitioning helps organizations strengthen their security posture, ensure continuous improvement, and protect sensitive data in an evolving landscape.
Read → Global RegulationsAn In-Depth Look at South Africa's Protection of Personal Information Act (POPIA) and Its Comparison with GDPR
South Africa's POPIA regulates personal data processing with strict conditions on consent, security, and accuracy. While sharing core principles with GDPR, it has unique jurisdictional rules, different breach reporting timelines, and criminal penalties including imprisonment. Organizations must ensure compliance with eight key conditions, such as purpose limitation and data minimization, to avoid heavy fines and ensure lawful cross-border data transfers.
Read → AI & GovernanceThe Importance of Responsible Use: An Overview of the Proposed AI Act
The proposed AI Act and the importance of responsible use of AI, including protecting privacy and aligning AI with human values and rights
Read →Guides & Tools
DPIA Questionnaire: the free EDPB tool
A complete Data Protection Impact Assessment built from the EDPB template. Work through controller details, lawfulness, necessity, risk scoring and the decision, all in your browser. Nothing is sent or stored; export and resume anytime.
Start the DPIA →Privacy Regulations and Cloud Applications
Navigating privacy compliance in cloud-based, microservices-driven environments: data fragmentation, secure communication, vendor compliance, and privacy by design.
Download PDFSafeguarding Privacy in eCommerce
Practical recommendations for e-commerce: understanding data flow, a comprehensive privacy policy, strong security, customer consent, and staying current with regulations.
Download PDFEnsuring Privacy of Health-Related Data
An overview of the Council of Europe's Recommendation CM/Rec(2019)2 and key principles for the ethical, secure processing of health data.
Download PDFNavigating Standard Contractual Clauses (SCCs)
SCCs for international transfers: common pitfalls, best practices, and why they must be tailored, with the Meta fine as a cautionary tale.
Download PDFSouth Korea's Personal Information Protection Act (PIPA)
A comprehensive analysis of PIPA, its enforcement mechanisms, and how it compares with the GDPR.
Download PDFChina's Personal Information Protection Law (PIPL)
An overview of PIPL compared with the GDPR, and the rights and obligations it creates for individuals and businesses.
Download PDFResponsible AI: Ethics, Data Protection and Governance
How responsible AI, fairness, transparency, accountability, privacy, aligns with data protection and governance, and how to get there.
Download PDFNavigating the Complexities of DPAs
Why Data Processing Agreements matter for trust and compliance, and the practical steps to create and manage them.
Download PDFProtecting HR Data
Guidelines for HR: transparency, limited collection, access controls, secure storage, and team education to protect employee and candidate data.
Download PDFEmbracing the Transition to ISO 27001:2022
Key updates in ISO 27001:2022, its risk-based approach and new controls, and how to transition to the new standard.
Download PDFThe DPO Role: Same Same, But Different
How the Data Protection Officer's role is shifting from compliance enforcer to strategic business partner.
Download PDFSouth Africa's Protection of Personal Information Act (POPIA)
A comparison of POPIA with the GDPR: scope, consent, security, penalties, and what it means for organizations.
Download PDFInternational Privacy Laws
Privacy laws around the world
Tap a highlighted country to open its overview, or browse the full list below.
Privacy Act 1988
Australia's federal privacy law and the Australian Privacy Principles.
LGPD
Lei Geral de Protecao de Dados (2020), Brazil's GDPR-inspired data protection law.
CCPA / CPRA
California Consumer Privacy Act as amended by the CPRA: rights to know, delete, correct and opt out.
PIPEDA
Personal Information Protection and Electronic Documents Act.
PIPL
Personal Information Protection Law (2021): strict rules on processing and cross-border transfers.
GDPR
General Data Protection Regulation (2018), the EU's comprehensive privacy law and the global benchmark.
DPDP Act 2023
Digital Personal Data Protection Act, India's new consent-based framework.
Privacy Protection Law
Israel's Privacy Protection Law and Amendment 13, enforced by the PPA.
PDPL
The Personal Data Protection Law of the Kingdom of Saudi Arabia.
POPIA
Protection of Personal Information Act, South Africa's comprehensive privacy law.
PIPA
Personal Information Protection Act, one of Asia's strictest privacy regimes.
PDPA
Thailand's Personal Data Protection Act, modelled on the GDPR.
PDPL
The UAE's federal Personal Data Protection Law.
UK GDPR & DPA 2018
The UK's post-Brexit version of the GDPR, with the Data Protection Act 2018.
HIPAA
Health Insurance Portability and Accountability Act: privacy and security of health data.
Law No. 91/2025/QH15
Vietnam's first comprehensive Personal Data Protection Law (2025).
We work hard to keep everything here accurate and current, but it may contain errors or omissions, and we make no warranty, express or implied, as to its accuracy or completeness. Everything on this page is a general reference, not legal advice, and using it does not create a lawyer-client or advisory relationship. Our articles and guides reflect the law at the time of writing, and this index of laws is not exhaustive. Each card opens our own plain-English overview, which is not the law and not binding; from there we link to the official source. Some countries publish the authoritative text only in their own language, so an English version may be an unofficial translation. Always rely on the official source, seek professional advice for your specific situation, and treat any reliance on this content as at your own risk.
לא נמצאו תוצאות. נסו מונח אחר.
