Reference
Answers to specific questions about vendor liability, cross-border transfers, and AI data exposure under Israeli and EU law — not a blog, a fixed set of pieces kept current as the law changes.
- Cross-border data transfers: PPL and GDPR, side by side
If your customers or vendors are outside Israel, you may be running two transfer regimes at once. Where Israeli and EU rules actually diverge, and where they don't.
- Security-tier classification under the Data Security Regulations, walked through
Israel's Privacy Protection (Data Security) Regulations sort every database into a security tier, and the tier sets concrete, auditable requirements. Here's how the classification actually works.
- The three ways AI touches your data: API calls, RAG, and fine-tuning
Not all AI usage carries the same risk. API calls, retrieval-augmented generation, and fine-tuning create three different — and increasingly hard to reverse — kinds of exposure for personal data.
- Vendor liability under Amendment 13: why the controller stays on the hook
Using a vendor doesn't transfer your liability under Israeli or EU privacy law. Amendment 13 made vendor oversight a controller's direct, non-delegable duty — here's what that means in practice.
- What a vendor's DPA should actually cover — and what a click-through TOS doesn't
A vendor's standard terms of service are not a data processing agreement, even when they mention privacy. The gap, and what to check before onboarding an AI vendor.