Privacy Law Amendment 13 and AI Agents: What to Do

Tuesday, 21:20. A dental clinic in Rishon LeZion gets a WhatsApp message: "I have pain in a molar, I take blood thinners, can I come tomorrow?". Within three minutes it passes through three stations: a screenshot into the staff group, a copy into the receptionist spreadsheet, and a reply from the private phone of a dentist sitting at home. Nobody did anything malicious, yet identifiable medical information about a patient now sits in three places nobody manages: no permissions, no logging, no deletion policy. Since Amendment 13 to the Privacy Protection Law came into force in August 2025, that is no longer just sloppy operations - it is regulatory exposure.
The conclusion that surprises business owners: an AI agent running your inquiries reduces that exposure rather than increasing it, provided it is set up correctly. What follows is an operational guide, not legal advice - applicability and classification for your specific business need a privacy lawyer.
What Amendment 13 changed, briefly
Amendment 13 is the most significant change to the Israeli Privacy Protection Law since it was enacted, in force since August 2025. Four points a business owner should know:
- Enforcement with teeth. The Privacy Protection Authority has administrative tools for financial sanctions, sized by the volume of data and the severity of the violation. Before the amendment, enforcement against smaller businesses was rare.
- Less paperwork, more accountability. The database registration duty was abolished for most businesses and replaced by a notification duty on some entities. In its place came a more practical demand: know what data you hold, for what purpose, where it sits and who can access it.
- A category of particularly sensitive information. Medical, genetic and biometric data, location data, financial information, criminal record and more. Holding that data puts a business at a different exposure level, and it is exactly what flows through a clinic, an insurance agent or a law firm.
- The duty to inform. When you collect data from a person you must say for what purpose, to whom it will be passed and why, and whether providing it is mandatory. Enforced differently now.
The duty to appoint a data protection officer applies to public bodies, data brokers and entities whose main business is processing sensitive data at large scale; most small businesses fall outside it. The data security regulations, which predate the amendment, do apply broadly: every database has a required security level, and a severe incident is reported to the Authority.
Why an AI agent actually reduces exposure
The common reflex is that a new system adds privacy risk. In practice the exposure in most small Israeli businesses comes not from a system but from its absence: an employee private WhatsApp number, a staff group where inquiries get screenshotted, a spreadsheet on a receptionist desktop, a notebook at the front desk. No list of what is held, no permissions, no record of who saw what, and no way to answer a deletion request.
One system delivers the four things a regulator looks for: a defined place where the data sits, permissions that decide who sees what, a log of actions on the card, and a practical way to locate a customer and delete what can be deleted. A system does not make a business compliant by itself, and the policy stays a business decision. But without that infrastructure there is nothing to discuss.
| Aspect | Private WhatsApp and groups | AI agent with CRM ✓ |
|---|---|---|
| Where the data sits | Private phones, spreadsheets, notebooks | One card in the system |
| Who sees the data | Everyone in the group | By the permissions you set |
| Notice on first contact | Depends who answered | Fixed in every conversation |
| Record of who touched it | None | Action log on the card |
| Access or deletion request | No way to locate | Search by customer |
| An employee who leaves | History leaves the business | Stays in the business |
| Sensitive data in an inquiry | Stays in the open chat | Handed to the team by rule |
Eight things to define during setup
This decides whether the agent reduces exposure or adds to it. All eight are written during setup, not after go-live:
- A notice in the first message. One line: this is the business AI agent, what the data is collected for, and a pointer to the privacy policy. Short, not a legal wall nobody reads.
- A list of what the agent never asks. ID numbers, card details in free text, detailed medical history, health fund data beyond what is needed. That list matters more than what it does ask: data you never collected is data you do not have to protect.
- Minimum fields. Only what the action needs: name, phone, type of inquiry, preferred time. Every extra nice-to-have field is an asset you have to guard.
- Permissions and ownership. Who sees which cards, what happens when someone leaves, and who actually owns the data - one named person, not "everyone".
- Retention and deletion policy. How long conversations are kept, what gets deleted on request, what has to stay for another reason such as a medical record retention duty, and what happens to old material with no remaining use.
- Handoff to a human on sensitive topics. Once a conversation moves into detailed medical, legal or financial territory, the agent collects what the appointment needs and hands off with the chat history. That also limits how much sensitive data piles up in chat.
- Official channel only. A connection through the official Meta API, not a grey gateway or an employee number. The risk there is not only a blocked number, but customer data flowing through a third party you have no agreement with.
- Separating the knowledge base from customer data. The knowledge base is what the agent answers from: price list, service catalogue, cancellation policy, opening hours. It is not the place for a customer list, a backup export of the booking system, or case summaries. That separation is one of the cheapest and most consequential definitions in the project.
Clinics and practices: the particularly sensitive case
In a business holding medical data, everything above gets stronger. A typical inquiry to a clinic contains a symptom, a medication, an age and a health fund - particularly sensitive information - and in most small Israeli clinics it is handled today exactly as in the opening scenario.
The structure that works separates two kinds of conversation. The agent handles everything around the appointment: what the service includes, the price range, openings, booking the calendar, a confirmation email and a reminder the day before. The moment the patient moves into medical content, it does not run an intake and does not advise: it collects the minimum and hands off. Follow-ups and reminders are unlimited on every plan with no trigger meter, so there is no incentive to cut corners to save runs. The full picture for the sector is on the AI agents for clinics page, and the split between booking and calendar management is detailed in the secretary agent.
Want to consult with us?
We can help you choose, build and deploy the perfect AI solution for your business. Leave your details and we'll get back to you.
Three mistakes we see in the field
Pasting a customer chat into a public assistant to "summarise" it. An employee copies a conversation with a name, a phone number and a symptom into a free AI tool for a summary - a transfer of personal data to a third party with no basis and no agreement, almost always with good intentions. The difference between a public tool and infrastructure defined for the business is covered in our guide to data security in AI systems.
Connecting the agent through an unofficial gateway. Tempting, cheap and fast, and it creates two problems at once: a number that may get blocked, and customer data flowing through an undefined party. What is and is not allowed on WhatsApp in 2026 is collected in our guide to Meta policy.
Setting permissions after the storm. In small businesses "everyone sees everything" feels natural until an employee resigns and takes the history with them, or a patient asks who had access to their inquiry. Five minutes during setup.
What it costs
Solo costs 490 ILS per month: one agent on one channel, 2,000 AI messages per month (about 300 conversations), a knowledge base of up to ten documents and WhaleBiz CRM. Pro costs 990 ILS per month: up to three channels, 5,000 AI messages (about 750 conversations), an unlimited extended knowledge base, up to a hundred media files and in-chat payments. On top of that there is a one-time setup fee from 490 ILS for full setup by our team, priced by scope: agent characterisation, the knowledge base, the handoff rules and the CRM card definition. Setup takes up to 14 business days from receipt of all your materials, and the subscription only starts counting when the agent goes live. Prices exclude VAT, and the full breakdown is on the pricing page.
The right comparison is not against doing nothing. A business running inquiries through WhatsApp groups and spreadsheets pays in time, in lost leads, and in exposure nobody can quantify until it materialises. Sorting out the inquiry channel is a project most Israeli service businesses will run anyway; the only thing worth changing is doing it with privacy defined in from day one.
Frequently asked questions
Is an AI agent allowed to handle conversations that involve medical information?
The law does not ban a digital channel. It requires a defined purpose, an informed customer, and proper storage and access. In practice the agent collects only what the booking needs, does not run a medical intake in chat, and hands off to the team beyond that point. Whether a specific business meets the requirements is a question for a privacy lawyer, not a software vendor.
Where are agent conversations stored and who on the team can see them?
Every conversation opens as a card in WhaleBiz CRM with the chat history, the contact details and the source of the inquiry. It sits in one place rather than on a private phone or in a WhatsApp group, and you define during setup who sees which cards.
Does a small business need to appoint a data protection officer because of an AI agent?
The appointment duty applies to public bodies, data brokers and entities whose main business is processing sensitive data at large scale, so most small businesses fall outside it. The data security regulations do apply broadly: every database has a required security level, and a severe incident is reported to the Privacy Protection Authority.
What do you do when a customer asks to delete their data?
Define the procedure in advance: who receives the request, who locates the card, what gets deleted and what has to stay for another reason such as a medical record retention duty. When all conversations sit in one system you can find a customer and handle the request; when they are spread across private phones and spreadsheets, you cannot.

Michael Romm
Michael is the founder and CEO of WhaleBiz, leading business and marketing strategy. An expert in data (SQL, Python) and developing automation and AI solutions for businesses.