Vendor liability under Amendment 13: why the controller stays on the hook
Written by Meir · Last reviewed 2026-08-13
Using a vendor doesn't transfer your liability under Israeli or EU privacy law. Amendment 13 made vendor oversight a controller's direct, non-delegable duty — here's what that means in practice.
No. If a vendor you pay for mishandles your customers’ personal data, the legal responsibility stays with you — not jointly, not partially. You chose the vendor, and the law treats that choice as yours to answer for.
Amendment 13 to Israel’s Protection of Privacy Law made this explicit. Appointing a processor — a payroll platform, a support-ticket tool, an AI assistant your team started using — does not discharge your own obligations as controller. You remain liable for what that processor does with the data, unless you can show you exercised real oversight over it. GDPR’s Article 28 sets the equivalent standard for any data with an EU nexus: a controller may only use a processor that offers “sufficient guarantees” to protect the data, and the controller stays accountable for verifying that.
What “controller” and “processor” mean here
You are the controller for any personal data you decide to collect and why you collect it — your customer list, your applicant data, your patient records. A vendor is a processor when it handles that data on your instructions and for your purposes — hosting it, running it through a model, storing it in a support queue. The label doesn’t depend on the vendor’s size or reputation. A well-known AI platform is still a processor, and you’re still the controller, the moment your customers’ data goes through it.
What “proper oversight” actually requires
Oversight isn’t a one-time contract signature. In practice it means knowing, on an ongoing basis: what the vendor is actually configured to do with the data (not just what its marketing page says), whether a signed data processing agreement is in place, where the data is physically processed and by which sub-processors, and what happens to the data if you stop using the vendor. A privacy policy that was accurate when it was written two years ago, and hasn’t been checked since, is not oversight — it’s paperwork that stopped tracking the system it describes.
What this means in practice
This is why “we use a reputable vendor” is not a defense on its own. A customer, an insurer, or the regulator asking where your data goes is asking a question only you can answer — not your vendor. If your vendor’s AI feature quietly started training on your customers’ inputs, or a sub-processor changed without notice, that’s still your exposure, discovered or not.
It also means the highest-leverage compliance work isn’t drafting a new policy — it’s finding out what your existing vendor accounts are actually configured to do, and fixing the gap between that and what your paperwork claims.
How DataCycles fits in
This is the reasoning behind the Assess engagement: reading vendor configurations directly rather than relying on questionnaire answers, so the answer to “what does our AI vendor actually do with this data” is something you can prove, not something you’re hoping is true. See what we check for the specifics.