Protection of Privacy Law
Israel
In force since 1981, Amendment 13 effective 14 August 2025
Amendment No. 13 to the Protection of Privacy Law entered into force on 14 August 2025, alongside the Protection of Privacy Regulations (Data Security), 5777-2017.
Asia & Africa
Protection of Privacy Law, 5741-1981
Amendment No. 13
5 August 2024
14 August 2025
Israel
Middle East / Asia
Privacy Protection Authority (PPA)
Protection of Privacy Law plus regulations
Protection of Privacy Regulations (Data Security), 5777-2017
Required where consent is the applicable legal basis; must be informed
Significantly narrowed under Amendment 13
Mandatory for specified organisations
Subject to enhanced requirements
Access, correction and additional statutory protections
Regulated through the Israeli privacy framework and applicable regulations
Expanded substantially under Amendment 13
Available under the amended law
Available under the law, including statutory or exemplary damages in specified circumstances
The Israeli privacy framework can apply broadly to organisations that collect, hold or process personal information in databases. Potentially affected organisations include Israeli companies, public authorities, financial institutions, healthcare organisations, employers, technology companies, e-commerce businesses, SaaS providers, advertising platforms, data brokers, telecommunications companies, search engines, organisations operating customer databases, and organisations conducting behavioural or location tracking. Businesses should assess the law based on the nature and location of their processing activities rather than relying solely on their place of incorporation. Amendment 13 also expanded and modernised the framework's application to contemporary digital processing activities.
Amendment 13 introduced a new framework for administrative monetary sanctions. The potential amount depends on factors such as the nature of the violation, the number of affected individuals, the type of database, the sensitivity of the information, the circumstances of the violation, and whether the organisation failed to comply with specific statutory obligations. The framework can result in substantial monetary sanctions reaching millions of Israeli shekels for certain violations, with specific statutory calculation and limitation rules, so the sanctions should not be represented as one universal fixed fine applicable to every violation. The amended framework also provides for civil remedies and strengthens personal accountability for certain violations, including provisions allowing courts to award exemplary damages of up to NIS 10,000 in specified circumstances without proof of actual harm. The law retains criminal provisions for certain serious privacy violations.
Israel's privacy regime is broader than a simple consent requirement. The Protection of Privacy Law remains the core statute, while Amendment 13 significantly changed how the law operates in practice from August 2025 onward.
The Protection of Privacy Law, 5741-1981 is Israel's foundational privacy statute.
The law regulates activities involving personal information and databases and protects individuals against unlawful or inappropriate uses of their information.
Historically, the Israeli framework focused heavily on the concept of “databases” and the responsibilities of database owners, holders and managers.
Amendment 13 updated the terminology and structure to bring the law closer to modern data-protection concepts and expanded the concept of personal information.
Under the amended framework, personal information broadly means information concerning an identified individual or an individual who can be identified.
Amendment No. 13 represents the most significant modernisation of Israel's privacy framework in decades.
It entered into force on 14 August 2025, one year after its publication and enactment.
The key changes cover:
Amendment 13 also established the PPA's statutory independence and expanded its enforcement powers. Each of these changes is set out in the sections that follow.
The amended law uses the broader concept of personal information, covering information relating to an identified or identifiable individual.
This is particularly relevant to digital businesses processing:
Amendment 13 substantially narrowed the categories of databases that must be registered.
Registration generally continues to apply to:
However, the removal of a registration requirement does not mean that an organisation is exempt from the substantive privacy and security obligations of the law.
Certain organisations must appoint a Data Protection Officer.
These include specified:
Banks, insurance companies, hospitals and health funds are specifically among the types of organisations identified in the statutory framework.
The PPA now has substantially stronger enforcement and monetary-sanction powers.
Amendment 13 enables regulatory enforcement without requiring every sanction to proceed through the ordinary court process.
The amended PPL defines personal information broadly.
Depending on the circumstances, personal information may include:
The key question is whether the information relates to an identified or identifiable individual.
Amendment 13 introduced and expanded the concept of information of special sensitivity.
This category includes information relating to matters such as:
The treatment of specially sensitive information is particularly important when assessing:
For organisations processing specially sensitive information at substantial scale, the processing may trigger the statutory requirement to appoint a DPO.
Consent is an important legal mechanism, but it is not accurate to describe Israeli privacy law as requiring consent for every instance of personal-data processing.
The PPL establishes requirements concerning informed consent, but processing may also be permitted under other provisions of the law or another applicable legal authority.
Organisations should therefore determine:
The PPA has issued guidance addressing informed consent following Amendment 13.
Where consent is required, it should be informed.
Individuals should receive meaningful information about the processing before providing consent.
A consent mechanism should therefore clearly communicate:
Organisations should avoid:
The PPA published updated material concerning Amendment 13 and consent, including guidance intended to help organisations implement the amended requirements.
Where processing is based on consent, organisations should provide an appropriate mechanism for withdrawing that consent.
A withdrawal mechanism should be:
Organisations should also maintain records showing the consent state and subsequent changes.
For websites and applications, this means privacy choices should not be treated as a one-time event.
Israel's privacy framework places significant importance on transparency.
When collecting personal information, organisations should provide individuals with appropriate information concerning the collection and intended use of their information.
A privacy notice should generally explain:
This has become particularly important following Amendment 13 because the amended law strengthens transparency and accountability expectations.
Personal information should be processed consistently with the purposes for which it was lawfully collected.
Organisations should avoid collecting information on a “collect now, decide later” basis.
Before introducing a new processing activity, businesses should ask:
Purpose documentation should be maintained as part of the organisation's privacy governance programme.
Organisations should limit personal-information collection to information that is relevant to the intended purpose.
For example, an organisation should avoid collecting:
Data minimisation also reduces security and compliance risks.
The Israeli privacy framework provides individuals with important rights concerning personal information.
Right to access information. Individuals have rights concerning access to information held about them, subject to statutory conditions and exceptions. Organisations should maintain processes capable of locating relevant information and responding to qualifying requests.
Right to correction. Individuals can request correction of information where it is inaccurate or incomplete.
Organisations should therefore maintain mechanisms for:
Privacy objections and complaints. Individuals can raise concerns regarding unlawful or inappropriate processing and may use applicable regulatory and judicial mechanisms.
The organisation should maintain a documented process for handling privacy complaints and rights requests.
Israel has a detailed security framework under the Protection of Privacy Regulations (Data Security), 5777-2017.
The regulations establish technical and organisational requirements relating to database security.
The PPA's implementation guidance addresses requirements such as:
For example, the PPA's guidance states that access permissions should be limited according to the employee's role and that an updated list of permissions should be maintained.
For databases connected to the internet or public networks, the regulations also establish requirements for protection against unauthorised access and malicious software and require appropriate encryption for certain data transmissions.
Israeli data-security regulations establish specific requirements concerning serious security incidents.
Organisations should have documented procedures for:
The PPA provides detailed guidance concerning information-security obligations and serious security incidents.
Organisations should not assume that a generic global 72-hour breach rule automatically applies to every Israeli incident.
One of the most important changes introduced by Amendment 13 is the statutory DPO regime.
A DPO is required for specified categories of organisations, including certain organisations that:
The DPO must have appropriate knowledge and professional capabilities and perform statutory privacy-governance functions.
The PPA has subsequently published final guidance concerning the DPO appointment obligation, including its interpretation of the statutory requirements.
A DPO is not universally required for every Israeli business. Organisations should assess whether they fall within one of the statutory categories.
Before Amendment 13, Israeli businesses frequently focused on whether their databases needed to be registered.
The amended law significantly narrows the registration regime.
Registration now primarily concerns:
For other organisations, the absence of a registration requirement does not remove substantive obligations under the Protection of Privacy Law or Data Security Regulations.
This distinction is important: no registration requirement ≠ no privacy compliance requirement.
Amendment 13 also introduced notification requirements for certain large databases containing specially sensitive information.
Where a database contains specially sensitive information concerning more than 100,000 individuals and does not otherwise fall under the registration requirement, the controller may be required to notify the PPA and provide specified information concerning the database and relevant DPO arrangements.
Organisations operating large datasets should therefore assess both:
Businesses frequently use third-party providers to process personal information.
Examples include:
Organisations should establish appropriate controls over these relationships, including:
Israel permits international transfers of personal information subject to the applicable statutory and regulatory framework.
Organisations transferring information outside Israel should assess:
Israel also maintains specific rules concerning information transferred to Israel from the European Economic Area, including the Privacy Protection Regulations concerning EEA-originating data. The PPA's official legal-information portal lists these regulations as part of the Israeli privacy framework.
Websites and applications should assess cookies, pixels, SDKs, advertising technologies and analytics tools under Israel's privacy framework when those technologies process personal information.
However, it is too broad to state that every cookie in Israel automatically requires opt-in consent.
The appropriate analysis depends on:
For websites, organisations should maintain a complete tracker inventory and map each technology to its purpose and legal basis.
Where consent is required, the consent interface should provide users with meaningful information and an appropriate choice.
A robust consent-management implementation should include:
This is particularly important for websites using:
Amendment 13 pays particular attention to organisations whose business involves collecting personal information and transferring it to others for compensation or as a business activity.
This includes certain data-broker and direct-mail activities.
Where a database has more than 10,000 individuals and its principal purpose meets the statutory data-transfer or business criteria, additional regulatory obligations can apply, including registration and DPO requirements.
Organisations involved in advertising, lead generation or data brokerage should therefore assess whether their business model brings them within these provisions.
The amended Israeli privacy framework is increasingly relevant to organisations using:
Organisations should assess whether automated processing creates risks to privacy or involves specially sensitive personal information.
High-risk processing should be subject to documented privacy-risk assessment and appropriate governance.
The PPA has highlighted privacy risks associated with modern technologies and the need for organisations to adapt their privacy governance to the evolving technological environment.
Israel's PPL framework should not be described as imposing a universal GDPR-style Article 35 DPIA requirement on every high-risk processing activity.
However, privacy-risk assessments are an important compliance tool, particularly for:
Organisations should document privacy risks and the measures implemented to address them.
Privacy should be considered when developing or modifying systems rather than after deployment.
Organisations should incorporate privacy considerations when:
A privacy-by-design approach can help identify consent, security, transparency, retention and data-sharing issues before they become operational problems.
Organisations should define retention periods according to:
Personal information should not be retained indefinitely simply because storage is inexpensive.
A good retention programme should identify:
Following Amendment 13, organisations should maintain a structured privacy governance programme.
This can include:
The PPA has also created updated compliance resources and guidance following Amendment 13.
Amendment 13 significantly expanded the enforcement powers of the Privacy Protection Authority.
The PPA can exercise enhanced regulatory powers, including monetary sanctions for specified violations.
The reform also strengthened regulatory supervision over:
The PPA's strengthened enforcement framework means organisations should treat privacy compliance as an ongoing operational obligation rather than a one-time documentation exercise.
The amended law introduced a new framework for administrative monetary sanctions.
The potential amount depends on factors such as:
The framework can result in substantial monetary sanctions reaching millions of Israeli shekels for certain violations, with specific statutory calculation and limitation rules.
The sanctions should therefore not be represented as one universal fixed fine applicable to every violation.
The amended framework also provides for civil remedies and strengthens personal accountability for certain violations.
Amendment 13 introduced provisions allowing courts to award exemplary damages of up to NIS 10,000 in specified circumstances without proof of actual harm.
The law also retains criminal provisions for certain serious privacy violations.
This means organisations should consider privacy compliance from both:
Use this checklist to assess your organisation's readiness.
For organisations operating websites in Israel, privacy compliance increasingly requires visibility into how personal information is collected and processed through digital technologies.
A website may contain dozens of:
Without a tracker inventory and consent-management process, organisations may have difficulty demonstrating what information is collected and how user choices are respected.
ConsentX provides a technical layer for managing these website privacy workflows.
Scan your website to identify cookies, pixels, analytics tools, advertising scripts, third-party trackers and embedded technologies.
Present users with clear information and meaningful choices where consent is the applicable basis.
Prevent optional technologies from executing before the required consent is obtained.
Record user choices so organisations can demonstrate what was presented, which purpose was selected, when consent was given, whether consent was withdrawn and which consent version applied.
Give users an accessible way to modify their privacy choices.
ConsentX can help organisations manage privacy requests and workflows relating to access, correction and other applicable data-subject rights.
Use regional controls to configure different consent experiences based on applicable privacy requirements.
Maintain structured records that can help privacy teams demonstrate how website consent and tracking controls operate.
Israel's privacy framework has undergone a major transformation following Amendment 13. Organisations should now consider privacy compliance as an ongoing operational programme covering data collection → purpose → transparency → consent → tracking → security → third parties → rights → retention → governance. ConsentX can help organisations implement the website-level controls needed to support this process: scan your website, control trackers, capture consent and maintain evidence.
This page provides general information about Israel's Protection of Privacy Law and related regulations and is not legal advice. Israeli privacy requirements can depend on the nature of the organisation, database, processing activity, type and volume of personal information, sector, international transfers and applicable regulatory guidance. Organisations should review the current legislation and Privacy Protection Authority guidance and obtain qualified Israeli legal advice where appropriate.
Run a ConsentX scan to identify cookies, scripts, pixels and third-party trackers.
Determine what information each technology collects and whether it constitutes personal information.
Document why each tracker or processing technology is used.
Assess whether consent is required or whether another statutory basis applies.
Create clear, purpose-specific choices for processing that requires consent.
Prevent consent-dependent scripts from running until the appropriate choice is received.
Maintain evidence of the user's decision and the notice presented at the time.
Allow users to modify or withdraw consent where applicable.
Maintain workflows for access, correction and other applicable privacy rights.
Identify all external providers receiving personal information through your website.
Determine where third-party services process Israeli personal information and assess applicable transfer requirements.
Regularly rescan the website and update the consent configuration when trackers, vendors, purposes or privacy requirements change.