DATA SECURITY · LAW AND SOFTWARE
Data security for small businesses — what you actually need
Most of what is written about data security is written for organisations with an IT department. A five-person business is bound by the same Israeli regulations with not a single security officer — and here is the good news: most of what the regulations ask of it should be solved by the software it works in, not by a binder of policies.
Which data security duties apply to a small business?
The duty does not come from the size of the business but from the existence of a database. Israel's Protection of Privacy Regulations (Data Security), 5777-2017 apply to every digital database — a client list, work files, an appointments diary — and their application does not depend at all on whether the database must be registered.
That is the misconception most worth correcting: Amendment 13 to the Protection of Privacy Law sharply narrowed the registration duty, but the security duty stayed in place — and since 14 August 2025 the Privacy Protection Authority can enforce it through monetary sanctions, without a criminal proceeding. We covered this in the article on Amendment 13 to the Protection of Privacy Law.
And the good news: the regulations do not ask the same of everyone. They tier their demands by the sensitivity and scale of the data — and a small business's tier is far lower than commonly painted.
Which security level does a small business fall under?
Regulation 1 sets four tracks: a database managed by an individual, and the basic, medium and high security levels. The assignment depends on the type of data, the number of people it covers and the number of authorisation holders — not on the business's turnover.
The lightest track is the "database managed by an individual" — a database run by an individual, or a company owned by one, where only the individual and at most two more authorisation holders use it. But Regulation 1 expressly excludes a database holding data on 10,000 people or more, a data trader's database — and a database holding data covered by professional confidentiality. A lawyer, doctor or therapist stays outside this track even when working entirely alone.
The medium security level applies, under the First Schedule, to databases holding sensitive data — medical and mental-health, genetic, biometric, data on a person's financial situation, criminal record, political opinions and religious beliefs, and more. On paper that catches almost any business holding anything beyond a name and a phone number.
And here is the relief most worth knowing: item 2(2) of the First Schedule sends such a database back to the basic level if the number of authorisation holders at the database owner does not exceed ten. In plain words — a business where up to ten people access the data is almost always at the basic level, even when the data itself is sensitive.
The high security level is reserved, under the Second Schedule, for sensitive databases holding data on 100,000 people or more, or with over 100 authorisation holders — orders of magnitude away from any small business.
What does the basic level actually require?
Regulation 21 lists which regulations apply at each level. At the basic level the list is shorter than it seems, and this is its core:
- A database definitions document (Regulation 2) — a short description of what data is collected, for what purposes, who holds it and what the main security risks are; plus a yearly check that no more data is kept than needed.
- A security procedure (Regulation 4) — a document covering, among other things, physical security, access permissions and how a security incident is handled.
- Role-based access permissions (Regulation 8) — each role sees only what it needs, with an up-to-date record of the permissions.
- Identification and authentication (Regulation 9) — making sure only authorisation holders get in, and revoking permissions the moment an employee leaves a role.
- Screening and training (Regulation 7) — checking suitability and explaining the duties before an employee is given access to data.
- Documenting security incidents (Regulation 11) — every suspected misuse of data or harm to it is recorded.
- Up-to-date systems (Regulation 13) — ongoing updates, and no systems the maker no longer supports.
- Encryption and communications (Regulation 14) — data sent over a public network or the internet uses accepted encryption methods, and remote access only with identification and authentication.
- Outsourcing (Regulation 15) — an external provider given access to data requires an agreement defining what it may do and what happens to the data when the engagement ends.
Note what is not on the list: automatic access logging (Regulation 10), periodic audits (Regulation 16) and backup and recovery procedures (Regulation 18) are required only from the medium level up. That does not make backups optional in practice — it means the regulator does not load a small business with the control mechanisms of a large organisation.
What is solved in software, and what needs a procedure?
Now the part that saves money: most of the list above is not a "security project" at all. In a system built correctly, the system-side demands already exist in the software itself — and what remains for the business is a few short documents that reflect reality.
| Requirement | Where in the regulations | Where it is solved |
|---|---|---|
| Role-based access permissions | Regulation 8 | In software — a system that distinguishes users and roles |
| Identification and authentication | Regulation 9 | In software — a personal login per user, no shared password |
| Encrypted traffic and remote access | Regulation 14 | In software — HTTPS and authentication built in |
| System updates | Regulation 13 | In software — as part of ongoing maintenance |
| Access logging and backups | Regulations 10 and 18 (from the medium level) | In software — a good system provides them even when not required |
| Database definitions document | Regulation 2 | Procedure — a short document, updated when something changes |
| Screening and training staff | Regulation 7 | Procedure — part of onboarding |
| Agreement with an external provider | Regulation 15 | Procedure — clauses in the engagement contract |
The distinction is also a buying test. When you examine a management system — off the shelf or bespoke — the right questions are exactly the regulations' questions: are there role-based permissions? Is there logging? Is the data encrypted and backed up? If the answer is "that comes in the extended plan", it is not a system built with security — it is a system selling it separately. We expanded on the principle in a system built around how you actually work.
Why is a binder of policies not security?
A whole industry sells small businesses "compliance" in the form of a binder: dozens of pages of generic policies, risk tables, declarations. The binder gets filed, and the business goes on working in a shared spreadsheet whose password everyone knows.
The regulations themselves are built the other way round. Most of what they demand at the basic level happens — or does not happen — in the system: permissions, authentication, encryption, updates. A procedure describing a reality that does not exist not only fails to protect; it is written evidence that you knew what was required and did not do it.
A real minimum of data security for a small business looks like this: the data lives in one system rather than scattered across a spreadsheet, WhatsApp and an inbox; each user has their own login and their own permissions; the data is encrypted and backed up; and there is a short definitions document describing what actually happens. It is less impressive than a binder — and it is what stands up to an inspection.
At appotto that is the default, not an add-on: role-based permissions, encryption and backups go into every project from day one, and every privacy and data security question goes through an orderly legal review by the software house's legal counsel. The highest bar we built is our CRM for law firms, where attorney–client privilege dictates full separation between matters and per-matter permissions — and once you clear that bar, the basic level is long behind you.
Fair disclosure. This article is general information only, not legal advice, and does not create an attorney–client relationship. appotto is a software house, not a law firm. Which security level applies depends on the specific facts of each business — the type of data, its scale and the number of authorisation holders — so seek individual legal advice before making decisions. The details are correct as of the update date, and the source list below lets you check for yourself.
And if you are weighing replacing the spreadsheet with a system and want to understand what that means for your budget, the fastest way to find out is to send us a short message about what data you hold and how you work today.
Frequently asked questions
Do the Data Security Regulations apply to a business that never registered a database?
Yes. The Protection of Privacy Regulations (Data Security), 5777-2017 do not depend on registration — they apply to every database, including one that is not required to be registered. A small business managing a digital client list is subject to them at the level that fits it, and since Amendment 13 came into force they are also enforced through monetary sanctions.
Which security level does a typical small business fall under?
Usually the basic level. Even a database holding sensitive data — medical or financial, for example — drops from the medium security level back to the basic level if the number of authorisation holders at the database owner does not exceed ten, under item 2(2) of the First Schedule to the regulations. A business where up to ten people access the data usually meets that condition.
What is a database managed by an individual, and who is excluded from it?
It is a lighter track for a database managed by an individual, or by a company owned by an individual, where only the individual and at most two more authorisation holders use it. Regulation 1 expressly excludes data traders, databases holding data on 10,000 people or more, and databases holding data covered by professional confidentiality — so a lawyer, doctor or therapist is outside it even when working entirely alone.
Does a small business have to encrypt its data?
When data from the database travels over a public network or the internet, Regulation 14(b) requires the transfer to use accepted encryption methods — and that applies at the basic level too. Remote access requires identifying and authenticating whoever connects, under Regulation 14(c). Encryption of stored data is addressed in the security procedure as one of the means of handling risks, and in modern software it is a cheap default.
What happens to a business that does not comply?
Since Amendment 13 to the Protection of Privacy Law came into force on 14 August 2025, the Privacy Protection Authority can supervise, conduct administrative inquiries and impose monetary sanctions without a criminal proceeding. The law sets reduced amounts for micro and small businesses, but the duties themselves apply in full — and the cheap way to meet them is a system built correctly from the start.
Sources
- Primary source: Protection of Privacy Regulations (Data Security), 5777-2017 — Wikisource (Hebrew) — Regulations 1, 2, 4, 7, 8, 9, 10, 11, 13, 14, 15, 16, 18 and 21, and the First and Second Schedules.
- Primary source: Protection of Privacy Law, 5741-1981 — consolidated text, Wikisource (Hebrew) — the enforcement powers and monetary sanctions added by Amendment 13.
- Protection of Privacy Regulations (Data Security), 5777-2017 — Nevo (Hebrew)
- Privacy Protection Authority — Amendment 13 to the Protection of Privacy Law (Hebrew)
How much of that list is already solved for you?
Tell us what data you hold and what tools you work in today. We will go over it with you against the requirements, and you will get a clear picture — and a price fixed in advance. First consultation free.
Email us