AI Features and Israel's Privacy Amendment 13
Amendment 13 has been in force since August 2025 and the grace period is over. What Israeli teams must change in AI features that touch customer data.
A customer emails and asks you to delete everything you hold about them. You delete the row. Then you remember the summariser that ran on their support tickets last quarter, the embeddings sitting in your vector store, the prompt logs in your observability tool, and the thirty-day retention window at your model provider that nobody ever configured.
That is the shape of the problem Amendment 13 creates for AI features. It has been in force since 14 August 2025, the initial grace period on enforcement has expired, and the Privacy Protection Authority now has the fining powers and the appetite to use them. We build software rather than legal opinions, so treat scope questions as a conversation with counsel — what follows is the engineering.
Every AI Call Is a Data Transfer
The prompt is the part people forget
Teams document their database carefully and then pass whatever the user typed, plus a retrieved context block, plus a system prompt with three account fields in it, to a third-party API. That is a transfer of personal data to a processor. It needs a basis, a contract that covers it, and a record that it happens.
On releadr, where the product holds AI-assisted conversations with real leads over SMS and WhatsApp, the message body is personal data. There is no version of that feature where the model sees less than the customer wrote.
Your logs are the second copy
The prompt goes to the provider. It also usually goes to your tracing tool, your error reporter, and a debug table someone added during launch week. Each of those is another place holding personal data with its own retention and its own access list. When you map data flows, map the observability path too — the tooling from LLM observability work is useful and it is also a liability if you log raw payloads forever.
What Changed, Concretely
Thresholds, notification, and a named owner
Amendment 13 moved Israel from blanket database registration to a risk-based model. Databases holding specially sensitive data — health, biometric, genetic, data about minors — on more than 100,000 people carry notification duties, and organisations in that band need a Data Protection Officer with real authority. Breaches likely to cause substantial harm get reported without undue delay.
A platform like MediMe, built around health insurance documents, sits squarely in the sensitive category from its first customer. So does a payroll system like HRHive. Volume arrives faster than founders expect.
The draft AI guidance signals the direction
The Authority’s draft guidance on AI, published for comment in 2025 and still not final, is worth reading as a statement of intent. Its themes: specific notice at collection, including when a bot is doing the collecting; an impact assessment before deployment; no scraping personal data for training on the assumption that public means consenting; and an internal policy for employee use of tools like ChatGPT. None of that is settled law yet. All of it is where questions will come from.
Design for Minimisation
Redact before the call, not after
The cheapest compliance work is not sending the data. Strip identifiers, swap names for tokens, pass an account ID instead of an account record, and rehydrate on the way back. Most AI features need the shape of the data, not the identity attached to it. This belongs in the same layer as your output guardrails — one boundary that everything crosses, not a filter bolted onto each caller.
Retention has a default you did not choose
Model providers offer zero-retention or short-retention modes, and enterprise terms that keep your data out of training. These are settings and contract clauses, not defaults. Check what your account is on, write it down, and re-check when you switch providers — a swap that looks like a routine model change can quietly move your data onto different terms.
Pin the region and isolate the tenant
Where inference runs matters to your customers’ procurement teams even when the law is silent. Pick a region, keep it in configuration, and keep tenant data separated end to end including in caches and vector indexes. This is ordinary cloud and infrastructure discipline applied to the AI path, which is usually the newest and least reviewed part of the stack.
Deletion Is the Test You Will Fail First
Keep a source identifier on every derived copy
Embeddings, summaries, cached completions, and memory rows are all derived personal data. If your semantic search index or your AI memory store holds vectors with no pointer back to the record they came from, you cannot answer a deletion request truthfully. Store the identifier from the first migration. It costs nothing then and it is painful later.
Rehearse the request before you receive one
Write the deletion path as a runnable job and test it against a seeded account: row, derivations, caches, logs, provider-side artefacts. Then do the same for an access request. A team that has run the drill answers in a day; a team that has not spends a week discovering where the copies live.
Privacy work reads like a tax until you notice it is mostly the same work as building an AI feature you can reason about — known data flows, one boundary, deletable state. If you are adding AI to a product that holds real customer data and want that designed in from the start, that is how we scope AI development engagements. Tell us what you are building.
Yaniv Amrami is founder of quickdev. He builds AI features for Israeli startups in health, HR, and fintech, where the personal data question shows up in the first architecture meeting.
Work with us
Ready to build something?
quickdev is a full-service software studio based in Tel Aviv. We build MVPs, SaaS platforms, mobile apps, and AI-powered products — fast and without compromise.
Let's Talk