Israel PPL Compliance with ConsentX
Protection of Privacy Law
Israel
In force since 1981, Amendment 13 effective 14 August 2025
Amendment No. 13 to the Protection of Privacy Law entered into force on 14 August 2025, alongside the Protection of Privacy Regulations (Data Security), 5777-2017.
Asia & Africa
Israel PPL at a glance
Protection of Privacy Law, 5741-1981
Amendment No. 13
5 August 2024
14 August 2025
Israel
Middle East / Asia
Privacy Protection Authority (PPA)
Protection of Privacy Law plus regulations
Protection of Privacy Regulations (Data Security), 5777-2017
Required where consent is the applicable legal basis; must be informed
Significantly narrowed under Amendment 13
Mandatory for specified organisations
Subject to enhanced requirements
Access, correction and additional statutory protections
Regulated through the Israeli privacy framework and applicable regulations
Expanded substantially under Amendment 13
Available under the amended law
Available under the law, including statutory or exemplary damages in specified circumstances
Who must comply with Israel PPL?
The Israeli privacy framework can apply broadly to organisations that collect, hold or process personal information in databases. Potentially affected organisations include Israeli companies, public authorities, financial institutions, healthcare organisations, employers, technology companies, e-commerce businesses, SaaS providers, advertising platforms, data brokers, telecommunications companies, search engines, organisations operating customer databases, and organisations conducting behavioural or location tracking. Businesses should assess the law based on the nature and location of their processing activities rather than relying solely on their place of incorporation. Amendment 13 also expanded and modernised the framework's application to contemporary digital processing activities.
Penalties under Israel PPL
Amendment 13 introduced a new framework for administrative monetary sanctions. The potential amount depends on factors such as the nature of the violation, the number of affected individuals, the type of database, the sensitivity of the information, the circumstances of the violation, and whether the organisation failed to comply with specific statutory obligations. The framework can result in substantial monetary sanctions reaching millions of Israeli shekels for certain violations, with specific statutory calculation and limitation rules, so the sanctions should not be represented as one universal fixed fine applicable to every violation. The amended framework also provides for civil remedies and strengthens personal accountability for certain violations, including provisions allowing courts to award exemplary damages of up to NIS 10,000 in specified circumstances without proof of actual harm. The law retains criminal provisions for certain serious privacy violations.
In short
- Lawful and purpose-specific processing
- Transparency and notice
- Informed consent where consent is the applicable basis
- Data-subject access and correction rights
- Protection of sensitive personal information
- Data security
- Processor and third-party controls
- International data transfers
- Data retention and purpose limitation
- Data-breach obligations
- Data Protection Officer requirements for specified organisations
- Database registration or notification where applicable
- Privacy governance and documentation
- Automated processing and profiling risks
- Regulatory supervision and enforcement
Israel's privacy regime is broader than a simple consent requirement. The Protection of Privacy Law remains the core statute, while Amendment 13 significantly changed how the law operates in practice from August 2025 onward.
What is Israel's Protection of Privacy Law?
The Protection of Privacy Law, 5741-1981 is Israel's foundational privacy statute.
The law regulates activities involving personal information and databases and protects individuals against unlawful or inappropriate uses of their information.
Historically, the Israeli framework focused heavily on the concept of “databases” and the responsibilities of database owners, holders and managers.
Amendment 13 updated the terminology and structure to bring the law closer to modern data-protection concepts and expanded the concept of personal information.
Under the amended framework, personal information broadly means information concerning an identified individual or an individual who can be identified.
Amendment 13 to Israel's Privacy Protection Law
Amendment No. 13 represents the most significant modernisation of Israel's privacy framework in decades.
It entered into force on 14 August 2025, one year after its publication and enactment.
The key changes cover:
- An expanded definition of personal information
- Narrower database-registration obligations
- New Data Protection Officer obligations
- Stronger regulatory enforcement
Amendment 13 also established the PPA's statutory independence and expanded its enforcement powers. Each of these changes is set out in the sections that follow.
Amendment 13: expanded definition of personal information
The amended law uses the broader concept of personal information, covering information relating to an identified or identifiable individual.
This is particularly relevant to digital businesses processing:
- Names
- Email addresses
- Telephone numbers
- Identification numbers
- Online identifiers
- Location information
- Financial information
- Health information
- Biometric information
- Behavioural information
- Other information capable of identifying an individual
Amendment 13: narrower database-registration obligations
Amendment 13 substantially narrowed the categories of databases that must be registered.
Registration generally continues to apply to:
- Databases maintained by public bodies, subject to statutory exceptions
- Certain databases containing information about at least 10,000 individuals where the primary purpose is collecting personal information for transfer to others as a business or for compensation, including direct-mail activities
However, the removal of a registration requirement does not mean that an organisation is exempt from the substantive privacy and security obligations of the law.
Amendment 13: new DPO obligations
Certain organisations must appoint a Data Protection Officer.
These include specified:
- Public bodies
- Data brokers and direct-marketing organisations meeting statutory thresholds
- Organisations conducting systematic and ongoing monitoring at substantial scale
- Organisations whose principal activities involve processing specially sensitive personal information at substantial scale
Banks, insurance companies, hospitals and health funds are specifically among the types of organisations identified in the statutory framework.
Amendment 13: stronger regulatory enforcement
The PPA now has substantially stronger enforcement and monetary-sanction powers.
Amendment 13 enables regulatory enforcement without requiring every sanction to proceed through the ordinary court process.
What personal information is covered?
The amended PPL defines personal information broadly.
Depending on the circumstances, personal information may include:
- Full name
- Identification number
- Contact details
- Address
- Email address
- Telephone number
- Employment information
- Financial information
- Health information
- Biometric information
- Location information
- Online identifiers
- Behavioural information
- Information relating to an individual's family or personal life
The key question is whether the information relates to an identified or identifiable individual.
Specially sensitive personal information
Amendment 13 introduced and expanded the concept of information of special sensitivity.
This category includes information relating to matters such as:
- Family life
- Sexual orientation
- Health
- Genetic information
- Origin
- Criminal records
- Political opinions
- Certain biometric identifiers
- Other information classified as specially sensitive under the law
The treatment of specially sensitive information is particularly important when assessing:
- Security requirements
- Transparency
- Data governance
- DPO obligations
- Large-scale processing
- Regulatory risk
For organisations processing specially sensitive information at substantial scale, the processing may trigger the statutory requirement to appoint a DPO.
Does Israel require consent for personal-data processing?
Consent is an important legal mechanism, but it is not accurate to describe Israeli privacy law as requiring consent for every instance of personal-data processing.
The PPL establishes requirements concerning informed consent, but processing may also be permitted under other provisions of the law or another applicable legal authority.
Organisations should therefore determine:
- What personal information is being collected
- Why it is being collected
- What statutory provision permits the processing
- Whether consent is required
- What information must be provided to the individual
- Whether another legal requirement applies
The PPA has issued guidance addressing informed consent following Amendment 13.
Informed consent under Israel PPL
Where consent is required, it should be informed.
Individuals should receive meaningful information about the processing before providing consent.
A consent mechanism should therefore clearly communicate:
- What information is collected
- Why it is collected
- How it will be used
- Relevant recipients or third parties
- The consequences of providing or refusing consent where relevant
- How the individual can exercise applicable rights
Organisations should avoid:
- Preselected optional choices
- Ambiguous consent wording
- Hidden processing purposes
- Bundled purposes that cannot reasonably be separated
- Consent obtained without sufficient information
The PPA published updated material concerning Amendment 13 and consent, including guidance intended to help organisations implement the amended requirements.
Consent withdrawal
Where processing is based on consent, organisations should provide an appropriate mechanism for withdrawing that consent.
A withdrawal mechanism should be:
- Easy to locate
- Understandable
- Accessible
- Consistent with the original consent mechanism
- Capable of being implemented operationally
Organisations should also maintain records showing the consent state and subsequent changes.
For websites and applications, this means privacy choices should not be treated as a one-time event.
Privacy notices and transparency
Israel's privacy framework places significant importance on transparency.
When collecting personal information, organisations should provide individuals with appropriate information concerning the collection and intended use of their information.
A privacy notice should generally explain:
- The identity of the relevant organisation
- The purpose of collection
- The nature of the information collected
- How the information will be used
- Relevant recipients
- Applicable rights
- How individuals can contact the organisation
- Other information required by the law
This has become particularly important following Amendment 13 because the amended law strengthens transparency and accountability expectations.
Purpose limitation
Personal information should be processed consistently with the purposes for which it was lawfully collected.
Organisations should avoid collecting information on a “collect now, decide later” basis.
Before introducing a new processing activity, businesses should ask:
- Was the information collected for this purpose?
- Is the new use compatible with the original purpose?
- Was the individual appropriately informed?
- Is additional consent required?
- Is there another legal basis?
- Does the new use create additional privacy risks?
Purpose documentation should be maintained as part of the organisation's privacy governance programme.
Data minimisation
Organisations should limit personal-information collection to information that is relevant to the intended purpose.
For example, an organisation should avoid collecting:
- Excessive identification information
- Unnecessary demographic information
- Sensitive information without a defined need
- Additional marketing information without a clear purpose
Data minimisation also reduces security and compliance risks.
Data-subject rights under Israel PPL
The Israeli privacy framework provides individuals with important rights concerning personal information.
Right to access information. Individuals have rights concerning access to information held about them, subject to statutory conditions and exceptions. Organisations should maintain processes capable of locating relevant information and responding to qualifying requests.
Right to correction. Individuals can request correction of information where it is inaccurate or incomplete.
Organisations should therefore maintain mechanisms for:
- Receiving correction requests
- Verifying the request
- Updating relevant records
- Notifying applicable recipients where required
Privacy objections and complaints. Individuals can raise concerns regarding unlawful or inappropriate processing and may use applicable regulatory and judicial mechanisms.
The organisation should maintain a documented process for handling privacy complaints and rights requests.
Data security requirements
Israel has a detailed security framework under the Protection of Privacy Regulations (Data Security), 5777-2017.
The regulations establish technical and organisational requirements relating to database security.
The PPA's implementation guidance addresses requirements such as:
- Access management
- Authorisation controls
- Personnel security
- Identification and authentication
- Network security
- Data transfer security
- Backup and recovery
- Physical security
- Documentation
- Periodic reviews
- Security incident handling
For example, the PPA's guidance states that access permissions should be limited according to the employee's role and that an updated list of permissions should be maintained.
For databases connected to the internet or public networks, the regulations also establish requirements for protection against unauthorised access and malicious software and require appropriate encryption for certain data transmissions.
Data breach and security incident requirements
Israeli data-security regulations establish specific requirements concerning serious security incidents.
Organisations should have documented procedures for:
- Detecting security incidents
- Assessing their severity
- Containing the incident
- Investigating the cause
- Preserving evidence
- Determining regulatory notification requirements
- Communicating with affected parties where required
- Correcting the underlying vulnerability
The PPA provides detailed guidance concerning information-security obligations and serious security incidents.
Organisations should not assume that a generic global 72-hour breach rule automatically applies to every Israeli incident.
Data Protection Officer (DPO)
One of the most important changes introduced by Amendment 13 is the statutory DPO regime.
A DPO is required for specified categories of organisations, including certain organisations that:
- Are public bodies
- Process data on behalf of public bodies
- Operate data-broker or direct-mail businesses meeting the statutory threshold
- Conduct systematic and ongoing monitoring of individuals at substantial scale
- Process specially sensitive personal information at substantial scale
The DPO must have appropriate knowledge and professional capabilities and perform statutory privacy-governance functions.
The PPA has subsequently published final guidance concerning the DPO appointment obligation, including its interpretation of the statutory requirements.
A DPO is not universally required for every Israeli business. Organisations should assess whether they fall within one of the statutory categories.
Database registration after Amendment 13
Before Amendment 13, Israeli businesses frequently focused on whether their databases needed to be registered.
The amended law significantly narrows the registration regime.
Registration now primarily concerns:
- Certain public-body databases
- Certain large-scale data-broker or direct-marketing databases meeting the statutory conditions
For other organisations, the absence of a registration requirement does not remove substantive obligations under the Protection of Privacy Law or Data Security Regulations.
This distinction is important: no registration requirement ≠ no privacy compliance requirement.
Notification for large databases containing specially sensitive information
Amendment 13 also introduced notification requirements for certain large databases containing specially sensitive information.
Where a database contains specially sensitive information concerning more than 100,000 individuals and does not otherwise fall under the registration requirement, the controller may be required to notify the PPA and provide specified information concerning the database and relevant DPO arrangements.
Organisations operating large datasets should therefore assess both:
- Registration requirements
- Notification requirements
Data processors and third-party vendors
Businesses frequently use third-party providers to process personal information.
Examples include:
- Cloud providers
- CRM platforms
- Analytics providers
- Advertising platforms
- Payment processors
- Marketing automation tools
- Customer-support systems
- Hosting providers
- SaaS applications
Organisations should establish appropriate controls over these relationships, including:
- Defined processing purposes
- Contractual requirements
- Security requirements
- Access restrictions
- Confidentiality obligations
- Incident-management procedures
- Data-deletion requirements
- International-transfer controls
International data transfers
Israel permits international transfers of personal information subject to the applicable statutory and regulatory framework.
Organisations transferring information outside Israel should assess:
- Destination country
- Recipient organisation
- Purpose of transfer
- Categories of information
- Applicable Israeli transfer requirements
- Security safeguards
- Contractual arrangements
- Additional restrictions applicable to the specific transfer
Israel also maintains specific rules concerning information transferred to Israel from the European Economic Area, including the Privacy Protection Regulations concerning EEA-originating data. The PPA's official legal-information portal lists these regulations as part of the Israeli privacy framework.
Cookies and online tracking under Israel PPL
Websites and applications should assess cookies, pixels, SDKs, advertising technologies and analytics tools under Israel's privacy framework when those technologies process personal information.
However, it is too broad to state that every cookie in Israel automatically requires opt-in consent.
The appropriate analysis depends on:
- Whether the technology processes personal information
- Whether the individual is identifiable
- The purpose of the processing
- The applicable legal requirement
- Whether consent is required
- Whether the processing is covered by another lawful provision
For websites, organisations should maintain a complete tracker inventory and map each technology to its purpose and legal basis.
Cookie consent for Israeli websites
Where consent is required, the consent interface should provide users with meaningful information and an appropriate choice.
A robust consent-management implementation should include:
- Clear privacy notice
- Purpose-based categories
- Optional tracking controls
- Separate consent choices where appropriate
- Prior blocking of consent-dependent technologies
- Consent records
- Withdrawal mechanisms
- Policy and version history
- Regional configuration
This is particularly important for websites using:
- Advertising pixels
- Retargeting technologies
- Social-media trackers
- Behavioural analytics
- Personalisation technologies
- Cross-site tracking
Direct marketing and data brokers
Amendment 13 pays particular attention to organisations whose business involves collecting personal information and transferring it to others for compensation or as a business activity.
This includes certain data-broker and direct-mail activities.
Where a database has more than 10,000 individuals and its principal purpose meets the statutory data-transfer or business criteria, additional regulatory obligations can apply, including registration and DPO requirements.
Organisations involved in advertising, lead generation or data brokerage should therefore assess whether their business model brings them within these provisions.
Automated decision-making, profiling and AI
The amended Israeli privacy framework is increasingly relevant to organisations using:
- AI
- Profiling
- Behavioural analytics
- Automated decision systems
- Facial recognition
- Biometric identification
- Location tracking
- Predictive analytics
Organisations should assess whether automated processing creates risks to privacy or involves specially sensitive personal information.
High-risk processing should be subject to documented privacy-risk assessment and appropriate governance.
The PPA has highlighted privacy risks associated with modern technologies and the need for organisations to adapt their privacy governance to the evolving technological environment.
Data Protection Impact Assessments
Israel's PPL framework should not be described as imposing a universal GDPR-style Article 35 DPIA requirement on every high-risk processing activity.
However, privacy-risk assessments are an important compliance tool, particularly for:
- Large-scale processing
- Systematic monitoring
- Sensitive-data processing
- AI systems
- Biometric processing
- Location tracking
- Large databases
- New technologies
Organisations should document privacy risks and the measures implemented to address them.
Privacy by design
Privacy should be considered when developing or modifying systems rather than after deployment.
Organisations should incorporate privacy considerations when:
- Launching websites
- Developing mobile applications
- Implementing CRM systems
- Deploying analytics tools
- Introducing AI
- Integrating advertising technologies
- Connecting databases
- Implementing employee-monitoring systems
- Introducing biometric systems
A privacy-by-design approach can help identify consent, security, transparency, retention and data-sharing issues before they become operational problems.
Data retention and deletion
Organisations should define retention periods according to:
- The purpose for which information was collected
- Applicable legal requirements
- Contractual obligations
- Regulatory requirements
- Business necessity
- Security and privacy risks
Personal information should not be retained indefinitely simply because storage is inexpensive.
A good retention programme should identify:
- Data category
- Processing purpose
- Retention period
- Storage location
- Deletion method
- Responsible business owner
Privacy governance and accountability
Following Amendment 13, organisations should maintain a structured privacy governance programme.
This can include:
- Data inventories
- Processing records
- Privacy notices
- Consent records
- Rights-request procedures
- Vendor assessments
- Security controls
- Retention policies
- Incident-response procedures
- Privacy-risk assessments
- DPO governance where applicable
- Regular compliance reviews
The PPA has also created updated compliance resources and guidance following Amendment 13.
Enforcement under Israel PPL
Amendment 13 significantly expanded the enforcement powers of the Privacy Protection Authority.
The PPA can exercise enhanced regulatory powers, including monetary sanctions for specified violations.
The reform also strengthened regulatory supervision over:
- Privacy obligations
- Database requirements
- Security requirements
- DPO obligations
- Processing activities
- Compliance with the law and regulations
The PPA's strengthened enforcement framework means organisations should treat privacy compliance as an ongoing operational obligation rather than a one-time documentation exercise.
Administrative monetary sanctions
The amended law introduced a new framework for administrative monetary sanctions.
The potential amount depends on factors such as:
- Nature of the violation
- Number of affected individuals
- Type of database
- Sensitivity of the information
- Circumstances of the violation
- Whether the organisation failed to comply with specific statutory obligations
The framework can result in substantial monetary sanctions reaching millions of Israeli shekels for certain violations, with specific statutory calculation and limitation rules.
The sanctions should therefore not be represented as one universal fixed fine applicable to every violation.
Civil and criminal liability
The amended framework also provides for civil remedies and strengthens personal accountability for certain violations.
Amendment 13 introduced provisions allowing courts to award exemplary damages of up to NIS 10,000 in specified circumstances without proof of actual harm.
The law also retains criminal provisions for certain serious privacy violations.
This means organisations should consider privacy compliance from both:
- Corporate risk perspective
- Individual decision-maker perspective
Israel PPL compliance checklist
Use this checklist to assess your organisation's readiness.
- Determine whether the Protection of Privacy Law applies
- Identify all personal information processed
- Map databases and processing activities
- Identify specially sensitive information
- Document processing purposes
- Determine applicable legal requirements
- Obtain informed consent where required
- Maintain appropriate privacy notices
- Implement data-minimisation controls
- Establish retention and deletion procedures
- Implement appropriate security measures
- Review Data Security Regulations requirements
- Establish security-incident procedures
- Assess database-registration obligations
- Assess large-database notification requirements
- Determine whether a DPO is mandatory
- Appoint a qualified DPO where required
- Establish data-subject request procedures
- Implement access and correction workflows
- Review processor and vendor contracts
- Assess international data transfers
- Review cookies and online trackers
- Configure consent where required
- Maintain consent evidence
- Provide consent withdrawal mechanisms
- Assess AI and automated-processing risks
- Conduct privacy-risk assessments where appropriate
- Review compliance regularly
Why consent management matters under Israel PPL
For organisations operating websites in Israel, privacy compliance increasingly requires visibility into how personal information is collected and processed through digital technologies.
A website may contain dozens of:
- Analytics scripts
- Advertising pixels
- Social-media trackers
- Marketing tools
- Personalisation technologies
- Third-party integrations
Without a tracker inventory and consent-management process, organisations may have difficulty demonstrating what information is collected and how user choices are respected.
ConsentX provides a technical layer for managing these website privacy workflows.
How ConsentX helps with Israel PPL compliance
Discover cookies and trackers
Scan your website to identify cookies, pixels, analytics tools, advertising scripts, third-party trackers and embedded technologies.
Create informed consent experiences
Present users with clear information and meaningful choices where consent is the applicable basis.
Block consent-dependent trackers
Prevent optional technologies from executing before the required consent is obtained.
Maintain consent records
Record user choices so organisations can demonstrate what was presented, which purpose was selected, when consent was given, whether consent was withdrawn and which consent version applied.
Support consent withdrawal
Give users an accessible way to modify their privacy choices.
Support privacy-rights workflows
ConsentX can help organisations manage privacy requests and workflows relating to access, correction and other applicable data-subject rights.
Support regional privacy rules
Use regional controls to configure different consent experiences based on applicable privacy requirements.
Improve audit readiness
Maintain structured records that can help privacy teams demonstrate how website consent and tracking controls operate.
Get Israel PPL ready with ConsentX
Israel's privacy framework has undergone a major transformation following Amendment 13. Organisations should now consider privacy compliance as an ongoing operational programme covering data collection → purpose → transparency → consent → tracking → security → third parties → rights → retention → governance. ConsentX can help organisations implement the website-level controls needed to support this process: scan your website, control trackers, capture consent and maintain evidence.
This page provides general information about Israel's Protection of Privacy Law and related regulations and is not legal advice. Israeli privacy requirements can depend on the nature of the organisation, database, processing activity, type and volume of personal information, sector, international transfers and applicable regulatory guidance. Organisations should review the current legislation and Privacy Protection Authority guidance and obtain qualified Israeli legal advice where appropriate.
How to comply with Israel PPL using ConsentX
- 1
Scan your website
Run a ConsentX scan to identify cookies, scripts, pixels and third-party trackers.
- 2
Classify processing activities
Determine what information each technology collects and whether it constitutes personal information.
- 3
Identify the purpose
Document why each tracker or processing technology is used.
- 4
Determine the applicable legal requirement
Assess whether consent is required or whether another statutory basis applies.
- 5
Configure your consent experience
Create clear, purpose-specific choices for processing that requires consent.
- 6
Block optional technologies
Prevent consent-dependent scripts from running until the appropriate choice is received.
- 7
Record consent
Maintain evidence of the user's decision and the notice presented at the time.
- 8
Enable withdrawal
Allow users to modify or withdraw consent where applicable.
- 9
Connect privacy requests
Maintain workflows for access, correction and other applicable privacy rights.
- 10
Review third parties
Identify all external providers receiving personal information through your website.
- 11
Review international transfers
Determine where third-party services process Israeli personal information and assess applicable transfer requirements.
- 12
Maintain ongoing compliance
Regularly rescan the website and update the consent configuration when trackers, vendors, purposes or privacy requirements change.