Employee Database and Amendment 13 to the Privacy Protection Law—What Actually Constitutes “Particularly Sensitive Information”?

Amendment 13 to the Protection of Privacy Law, 1981Here is: The law), which recently came into effect, constitutes the most significant reform in this field in decades. Among other things, the amendment redefined the obligations of database owners, oversight mechanisms, and the duty to take Adequate security measures According to the sensitivity level of the information.

One of the main points of change is Section 3 of the law, which defines what constitutes “especially sensitive information”.

The definition includes, among other things:

“Medical information about a person, genetic information, biometric information, information about their opinions and beliefs, information about their criminal past, and information about the privacy of a person's family life, their personal privacy, and their sexual orientation.”

In addition to the definition in the law, the Privacy Protection Regulations (Information Security), 2017, establish three levels of security—basic, medium, and high—depending on the types of information and the risk posed by its breach. A database containing "information of special sensitivity,“ as defined in the law, is required, at a minimum, to have a certain level of security. Medium, including stricter requirements for access rights management, backups, auditing, documentation, and risk management.

One of the issues that raises interpretive questions is the status of Employee database – A database that, in almost every organization, contains a great deal of personal information: identification details, marital status, salary information, sick days, and more. The question that arose is: Is such a database considered By design For a database with sensitive information?

On the one hand, Section 3 of the law states “information concerning family life privacy,” which may include data on an employee's marital status. On the other hand, the First Addendum to the Security Regulations contains an explicit exception regarding employee databases, intended to ease burdens on employers. This exception does not include Section 1(3)(a) of the First Addendum to the Regulations – “information concerning a person's family life privacy, their personal privacy, and their sexual orientation” – which leaves doubt regarding the nature of the database.

Against this backdrop of uncertainty, the Privacy Protection Authority's position is two-pronged:

  1. Personal and family status in itself For example, “married,” “single,” “number of children" not included Within the scope of “information of special sensitivity” as defined in section 1(3)(a) of the First Addendum to the Regulations. This means that an employee database containing only data of this type Not required For medium security level.
  2. Data on absences and sick days – This data is not automatically considered “medical information.” However, if it is In a large number of sick days, which may indicate a particular health condition, it is information that indicates “a person's health status” according to Section 3(2) of the law, and therefore the entire database may be considered particularly sensitive and require Medium security level Pursuant to Regulation 2 of the First Addendum.

In other words, it's about In a question that is both quantitative and substantiveNot all sick day data create an increased security obligation, but the more the data may reveal a medical pattern or information about a health condition, the more the required security obligation changes accordingly.

The practical meaning for employers and pool owners is clear:

Not only must we examine What type of information Saved, but also What is its scope and context?. A database containing medical information—even if only partially or indirectly—will require stricter security measures, whereas a database containing only administrative data may require only a basic level of security.

Finally, it must be remembered that each case is examined according to its circumstances. Even a “simple” employee database can become a sensitive database, depending on how the information is collected and stored within it. The purpose of Amendment 13 is a transition from a technical concept To an essential perception Privacy Protection.

The office team assists companies and organizations in database classification reviews, the implementation of information security procedures, and preparation for amendment 13. We would be happy to help you ensure that your employee database is managed in accordance with legal requirements and regulations.

Did you like the article?

Share on Facebook
Share on Twitter
Share on LinkedIn

Leave a comment

More articles

Accessibility Toolbar

Your referral is on its way to us.
Talk to you soon

For legal advice