DPDPA is now in force in India. Run a free privacy scan on your site. Scan now

Israel

Israel PPL Compliance with ConsentX

Protection of Privacy Law

The Israel Protection of Privacy Law (PPL), 5741-1981, is Israel's principal privacy and data-protection law. The framework regulates the collection, use, disclosure, storage and processing of personal information and establishes rights for individuals whose information is held in databases. A major reform, Amendment No. 13 to the Protection of Privacy Law, entered into force on 14 August 2025. The amendment significantly modernised Israel's privacy framework by expanding the definition of personal information, strengthening transparency and governance requirements, introducing mandatory Data Protection Officer (DPO) obligations for specified organisations, narrowing database-registration requirements, and giving the Privacy Protection Authority (PPA) stronger enforcement and monetary-sanction powers. Israel's privacy framework also includes the Protection of Privacy Regulations (Data Security), 5777-2017, which establish technical and organisational security requirements for databases. The Privacy Protection Authority continues to publish implementation guidance for organisations.
Region

Israel

Status

In force since 1981, Amendment 13 effective 14 August 2025

Amendment No. 13 to the Protection of Privacy Law entered into force on 14 August 2025, alongside the Protection of Privacy Regulations (Data Security), 5777-2017.

Group

Asia & Africa

Israel PPL at a glance

Official law

Protection of Privacy Law, 5741-1981

Major reform

Amendment No. 13

Amendment approved

5 August 2024

Amendment effective

14 August 2025

Country

Israel

Region

Middle East / Asia

Regulator

Privacy Protection Authority (PPA)

Core framework

Protection of Privacy Law plus regulations

Security framework

Protection of Privacy Regulations (Data Security), 5777-2017

Consent

Required where consent is the applicable legal basis; must be informed

Database registration

Significantly narrowed under Amendment 13

DPO

Mandatory for specified organisations

Sensitive information

Subject to enhanced requirements

Data-subject rights

Access, correction and additional statutory protections

International transfers

Regulated through the Israeli privacy framework and applicable regulations

Regulatory enforcement

Expanded substantially under Amendment 13

Administrative monetary sanctions

Available under the amended law

Private claims

Available under the law, including statutory or exemplary damages in specified circumstances

Who must comply with Israel PPL?

The Israeli privacy framework can apply broadly to organisations that collect, hold or process personal information in databases. Potentially affected organisations include Israeli companies, public authorities, financial institutions, healthcare organisations, employers, technology companies, e-commerce businesses, SaaS providers, advertising platforms, data brokers, telecommunications companies, search engines, organisations operating customer databases, and organisations conducting behavioural or location tracking. Businesses should assess the law based on the nature and location of their processing activities rather than relying solely on their place of incorporation. Amendment 13 also expanded and modernised the framework's application to contemporary digital processing activities.

Penalties under Israel PPL

Amendment 13 introduced a new framework for administrative monetary sanctions. The potential amount depends on factors such as the nature of the violation, the number of affected individuals, the type of database, the sensitivity of the information, the circumstances of the violation, and whether the organisation failed to comply with specific statutory obligations. The framework can result in substantial monetary sanctions reaching millions of Israeli shekels for certain violations, with specific statutory calculation and limitation rules, so the sanctions should not be represented as one universal fixed fine applicable to every violation. The amended framework also provides for civil remedies and strengthens personal accountability for certain violations, including provisions allowing courts to award exemplary damages of up to NIS 10,000 in specified circumstances without proof of actual harm. The law retains criminal provisions for certain serious privacy violations.

In short

  • Lawful and purpose-specific processing
  • Transparency and notice
  • Informed consent where consent is the applicable basis
  • Data-subject access and correction rights
  • Protection of sensitive personal information
  • Data security
  • Processor and third-party controls
  • International data transfers
  • Data retention and purpose limitation
  • Data-breach obligations
  • Data Protection Officer requirements for specified organisations
  • Database registration or notification where applicable
  • Privacy governance and documentation
  • Automated processing and profiling risks
  • Regulatory supervision and enforcement

Israel's privacy regime is broader than a simple consent requirement. The Protection of Privacy Law remains the core statute, while Amendment 13 significantly changed how the law operates in practice from August 2025 onward.

What is Israel's Protection of Privacy Law?

The Protection of Privacy Law, 5741-1981 is Israel's foundational privacy statute.

The law regulates activities involving personal information and databases and protects individuals against unlawful or inappropriate uses of their information.

Historically, the Israeli framework focused heavily on the concept of “databases” and the responsibilities of database owners, holders and managers.

Amendment 13 updated the terminology and structure to bring the law closer to modern data-protection concepts and expanded the concept of personal information.

Under the amended framework, personal information broadly means information concerning an identified individual or an individual who can be identified.

Amendment 13 to Israel's Privacy Protection Law

Amendment No. 13 represents the most significant modernisation of Israel's privacy framework in decades.

It entered into force on 14 August 2025, one year after its publication and enactment.

The key changes cover:

  • An expanded definition of personal information
  • Narrower database-registration obligations
  • New Data Protection Officer obligations
  • Stronger regulatory enforcement

Amendment 13 also established the PPA's statutory independence and expanded its enforcement powers. Each of these changes is set out in the sections that follow.

Amendment 13: expanded definition of personal information

The amended law uses the broader concept of personal information, covering information relating to an identified or identifiable individual.

This is particularly relevant to digital businesses processing:

  • Names
  • Email addresses
  • Telephone numbers
  • Identification numbers
  • Online identifiers
  • Location information
  • Financial information
  • Health information
  • Biometric information
  • Behavioural information
  • Other information capable of identifying an individual

Amendment 13: narrower database-registration obligations

Amendment 13 substantially narrowed the categories of databases that must be registered.

Registration generally continues to apply to:

  • Databases maintained by public bodies, subject to statutory exceptions
  • Certain databases containing information about at least 10,000 individuals where the primary purpose is collecting personal information for transfer to others as a business or for compensation, including direct-mail activities

However, the removal of a registration requirement does not mean that an organisation is exempt from the substantive privacy and security obligations of the law.

Amendment 13: new DPO obligations

Certain organisations must appoint a Data Protection Officer.

These include specified:

  • Public bodies
  • Data brokers and direct-marketing organisations meeting statutory thresholds
  • Organisations conducting systematic and ongoing monitoring at substantial scale
  • Organisations whose principal activities involve processing specially sensitive personal information at substantial scale

Banks, insurance companies, hospitals and health funds are specifically among the types of organisations identified in the statutory framework.

Amendment 13: stronger regulatory enforcement

The PPA now has substantially stronger enforcement and monetary-sanction powers.

Amendment 13 enables regulatory enforcement without requiring every sanction to proceed through the ordinary court process.

What personal information is covered?

The amended PPL defines personal information broadly.

Depending on the circumstances, personal information may include:

  • Full name
  • Identification number
  • Contact details
  • Address
  • Email address
  • Telephone number
  • Employment information
  • Financial information
  • Health information
  • Biometric information
  • Location information
  • Online identifiers
  • Behavioural information
  • Information relating to an individual's family or personal life

The key question is whether the information relates to an identified or identifiable individual.

Specially sensitive personal information

Amendment 13 introduced and expanded the concept of information of special sensitivity.

This category includes information relating to matters such as:

  • Family life
  • Sexual orientation
  • Health
  • Genetic information
  • Origin
  • Criminal records
  • Political opinions
  • Certain biometric identifiers
  • Other information classified as specially sensitive under the law

The treatment of specially sensitive information is particularly important when assessing:

  • Security requirements
  • Transparency
  • Data governance
  • DPO obligations
  • Large-scale processing
  • Regulatory risk

For organisations processing specially sensitive information at substantial scale, the processing may trigger the statutory requirement to appoint a DPO.

Does Israel require consent for personal-data processing?

Consent is an important legal mechanism, but it is not accurate to describe Israeli privacy law as requiring consent for every instance of personal-data processing.

The PPL establishes requirements concerning informed consent, but processing may also be permitted under other provisions of the law or another applicable legal authority.

Organisations should therefore determine:

  • What personal information is being collected
  • Why it is being collected
  • What statutory provision permits the processing
  • Whether consent is required
  • What information must be provided to the individual
  • Whether another legal requirement applies

The PPA has issued guidance addressing informed consent following Amendment 13.

Informed consent under Israel PPL

Where consent is required, it should be informed.

Individuals should receive meaningful information about the processing before providing consent.

A consent mechanism should therefore clearly communicate:

  • What information is collected
  • Why it is collected
  • How it will be used
  • Relevant recipients or third parties
  • The consequences of providing or refusing consent where relevant
  • How the individual can exercise applicable rights

Organisations should avoid:

  • Preselected optional choices
  • Ambiguous consent wording
  • Hidden processing purposes
  • Bundled purposes that cannot reasonably be separated
  • Consent obtained without sufficient information

The PPA published updated material concerning Amendment 13 and consent, including guidance intended to help organisations implement the amended requirements.

Consent withdrawal

Where processing is based on consent, organisations should provide an appropriate mechanism for withdrawing that consent.

A withdrawal mechanism should be:

  • Easy to locate
  • Understandable
  • Accessible
  • Consistent with the original consent mechanism
  • Capable of being implemented operationally

Organisations should also maintain records showing the consent state and subsequent changes.

For websites and applications, this means privacy choices should not be treated as a one-time event.

Privacy notices and transparency

Israel's privacy framework places significant importance on transparency.

When collecting personal information, organisations should provide individuals with appropriate information concerning the collection and intended use of their information.

A privacy notice should generally explain:

  • The identity of the relevant organisation
  • The purpose of collection
  • The nature of the information collected
  • How the information will be used
  • Relevant recipients
  • Applicable rights
  • How individuals can contact the organisation
  • Other information required by the law

This has become particularly important following Amendment 13 because the amended law strengthens transparency and accountability expectations.

Purpose limitation

Personal information should be processed consistently with the purposes for which it was lawfully collected.

Organisations should avoid collecting information on a “collect now, decide later” basis.

Before introducing a new processing activity, businesses should ask:

  • Was the information collected for this purpose?
  • Is the new use compatible with the original purpose?
  • Was the individual appropriately informed?
  • Is additional consent required?
  • Is there another legal basis?
  • Does the new use create additional privacy risks?

Purpose documentation should be maintained as part of the organisation's privacy governance programme.

Data minimisation

Organisations should limit personal-information collection to information that is relevant to the intended purpose.

For example, an organisation should avoid collecting:

  • Excessive identification information
  • Unnecessary demographic information
  • Sensitive information without a defined need
  • Additional marketing information without a clear purpose

Data minimisation also reduces security and compliance risks.

Data-subject rights under Israel PPL

The Israeli privacy framework provides individuals with important rights concerning personal information.

Right to access information. Individuals have rights concerning access to information held about them, subject to statutory conditions and exceptions. Organisations should maintain processes capable of locating relevant information and responding to qualifying requests.

Right to correction. Individuals can request correction of information where it is inaccurate or incomplete.

Organisations should therefore maintain mechanisms for:

  • Receiving correction requests
  • Verifying the request
  • Updating relevant records
  • Notifying applicable recipients where required

Privacy objections and complaints. Individuals can raise concerns regarding unlawful or inappropriate processing and may use applicable regulatory and judicial mechanisms.

The organisation should maintain a documented process for handling privacy complaints and rights requests.

Data security requirements

Israel has a detailed security framework under the Protection of Privacy Regulations (Data Security), 5777-2017.

The regulations establish technical and organisational requirements relating to database security.

The PPA's implementation guidance addresses requirements such as:

  • Access management
  • Authorisation controls
  • Personnel security
  • Identification and authentication
  • Network security
  • Data transfer security
  • Backup and recovery
  • Physical security
  • Documentation
  • Periodic reviews
  • Security incident handling

For example, the PPA's guidance states that access permissions should be limited according to the employee's role and that an updated list of permissions should be maintained.

For databases connected to the internet or public networks, the regulations also establish requirements for protection against unauthorised access and malicious software and require appropriate encryption for certain data transmissions.

Data breach and security incident requirements

Israeli data-security regulations establish specific requirements concerning serious security incidents.

Organisations should have documented procedures for:

  • Detecting security incidents
  • Assessing their severity
  • Containing the incident
  • Investigating the cause
  • Preserving evidence
  • Determining regulatory notification requirements
  • Communicating with affected parties where required
  • Correcting the underlying vulnerability

The PPA provides detailed guidance concerning information-security obligations and serious security incidents.

Organisations should not assume that a generic global 72-hour breach rule automatically applies to every Israeli incident.

Data Protection Officer (DPO)

One of the most important changes introduced by Amendment 13 is the statutory DPO regime.

A DPO is required for specified categories of organisations, including certain organisations that:

  • Are public bodies
  • Process data on behalf of public bodies
  • Operate data-broker or direct-mail businesses meeting the statutory threshold
  • Conduct systematic and ongoing monitoring of individuals at substantial scale
  • Process specially sensitive personal information at substantial scale

The DPO must have appropriate knowledge and professional capabilities and perform statutory privacy-governance functions.

The PPA has subsequently published final guidance concerning the DPO appointment obligation, including its interpretation of the statutory requirements.

A DPO is not universally required for every Israeli business. Organisations should assess whether they fall within one of the statutory categories.

Database registration after Amendment 13

Before Amendment 13, Israeli businesses frequently focused on whether their databases needed to be registered.

The amended law significantly narrows the registration regime.

Registration now primarily concerns:

  • Certain public-body databases
  • Certain large-scale data-broker or direct-marketing databases meeting the statutory conditions

For other organisations, the absence of a registration requirement does not remove substantive obligations under the Protection of Privacy Law or Data Security Regulations.

This distinction is important: no registration requirement ≠ no privacy compliance requirement.

Notification for large databases containing specially sensitive information

Amendment 13 also introduced notification requirements for certain large databases containing specially sensitive information.

Where a database contains specially sensitive information concerning more than 100,000 individuals and does not otherwise fall under the registration requirement, the controller may be required to notify the PPA and provide specified information concerning the database and relevant DPO arrangements.

Organisations operating large datasets should therefore assess both:

  • Registration requirements
  • Notification requirements

Data processors and third-party vendors

Businesses frequently use third-party providers to process personal information.

Examples include:

  • Cloud providers
  • CRM platforms
  • Analytics providers
  • Advertising platforms
  • Payment processors
  • Marketing automation tools
  • Customer-support systems
  • Hosting providers
  • SaaS applications

Organisations should establish appropriate controls over these relationships, including:

  • Defined processing purposes
  • Contractual requirements
  • Security requirements
  • Access restrictions
  • Confidentiality obligations
  • Incident-management procedures
  • Data-deletion requirements
  • International-transfer controls

International data transfers

Israel permits international transfers of personal information subject to the applicable statutory and regulatory framework.

Organisations transferring information outside Israel should assess:

  • Destination country
  • Recipient organisation
  • Purpose of transfer
  • Categories of information
  • Applicable Israeli transfer requirements
  • Security safeguards
  • Contractual arrangements
  • Additional restrictions applicable to the specific transfer

Israel also maintains specific rules concerning information transferred to Israel from the European Economic Area, including the Privacy Protection Regulations concerning EEA-originating data. The PPA's official legal-information portal lists these regulations as part of the Israeli privacy framework.

Cookies and online tracking under Israel PPL

Websites and applications should assess cookies, pixels, SDKs, advertising technologies and analytics tools under Israel's privacy framework when those technologies process personal information.

However, it is too broad to state that every cookie in Israel automatically requires opt-in consent.

The appropriate analysis depends on:

  • Whether the technology processes personal information
  • Whether the individual is identifiable
  • The purpose of the processing
  • The applicable legal requirement
  • Whether consent is required
  • Whether the processing is covered by another lawful provision

For websites, organisations should maintain a complete tracker inventory and map each technology to its purpose and legal basis.

Cookie consent for Israeli websites

Where consent is required, the consent interface should provide users with meaningful information and an appropriate choice.

A robust consent-management implementation should include:

  • Clear privacy notice
  • Purpose-based categories
  • Optional tracking controls
  • Separate consent choices where appropriate
  • Prior blocking of consent-dependent technologies
  • Consent records
  • Withdrawal mechanisms
  • Policy and version history
  • Regional configuration

This is particularly important for websites using:

  • Advertising pixels
  • Retargeting technologies
  • Social-media trackers
  • Behavioural analytics
  • Personalisation technologies
  • Cross-site tracking

Direct marketing and data brokers

Amendment 13 pays particular attention to organisations whose business involves collecting personal information and transferring it to others for compensation or as a business activity.

This includes certain data-broker and direct-mail activities.

Where a database has more than 10,000 individuals and its principal purpose meets the statutory data-transfer or business criteria, additional regulatory obligations can apply, including registration and DPO requirements.

Organisations involved in advertising, lead generation or data brokerage should therefore assess whether their business model brings them within these provisions.

Automated decision-making, profiling and AI

The amended Israeli privacy framework is increasingly relevant to organisations using:

  • AI
  • Profiling
  • Behavioural analytics
  • Automated decision systems
  • Facial recognition
  • Biometric identification
  • Location tracking
  • Predictive analytics

Organisations should assess whether automated processing creates risks to privacy or involves specially sensitive personal information.

High-risk processing should be subject to documented privacy-risk assessment and appropriate governance.

The PPA has highlighted privacy risks associated with modern technologies and the need for organisations to adapt their privacy governance to the evolving technological environment.

Data Protection Impact Assessments

Israel's PPL framework should not be described as imposing a universal GDPR-style Article 35 DPIA requirement on every high-risk processing activity.

However, privacy-risk assessments are an important compliance tool, particularly for:

  • Large-scale processing
  • Systematic monitoring
  • Sensitive-data processing
  • AI systems
  • Biometric processing
  • Location tracking
  • Large databases
  • New technologies

Organisations should document privacy risks and the measures implemented to address them.

Privacy by design

Privacy should be considered when developing or modifying systems rather than after deployment.

Organisations should incorporate privacy considerations when:

  • Launching websites
  • Developing mobile applications
  • Implementing CRM systems
  • Deploying analytics tools
  • Introducing AI
  • Integrating advertising technologies
  • Connecting databases
  • Implementing employee-monitoring systems
  • Introducing biometric systems

A privacy-by-design approach can help identify consent, security, transparency, retention and data-sharing issues before they become operational problems.

Data retention and deletion

Organisations should define retention periods according to:

  • The purpose for which information was collected
  • Applicable legal requirements
  • Contractual obligations
  • Regulatory requirements
  • Business necessity
  • Security and privacy risks

Personal information should not be retained indefinitely simply because storage is inexpensive.

A good retention programme should identify:

  • Data category
  • Processing purpose
  • Retention period
  • Storage location
  • Deletion method
  • Responsible business owner

Privacy governance and accountability

Following Amendment 13, organisations should maintain a structured privacy governance programme.

This can include:

  • Data inventories
  • Processing records
  • Privacy notices
  • Consent records
  • Rights-request procedures
  • Vendor assessments
  • Security controls
  • Retention policies
  • Incident-response procedures
  • Privacy-risk assessments
  • DPO governance where applicable
  • Regular compliance reviews

The PPA has also created updated compliance resources and guidance following Amendment 13.

Enforcement under Israel PPL

Amendment 13 significantly expanded the enforcement powers of the Privacy Protection Authority.

The PPA can exercise enhanced regulatory powers, including monetary sanctions for specified violations.

The reform also strengthened regulatory supervision over:

  • Privacy obligations
  • Database requirements
  • Security requirements
  • DPO obligations
  • Processing activities
  • Compliance with the law and regulations

The PPA's strengthened enforcement framework means organisations should treat privacy compliance as an ongoing operational obligation rather than a one-time documentation exercise.

Administrative monetary sanctions

The amended law introduced a new framework for administrative monetary sanctions.

The potential amount depends on factors such as:

  • Nature of the violation
  • Number of affected individuals
  • Type of database
  • Sensitivity of the information
  • Circumstances of the violation
  • Whether the organisation failed to comply with specific statutory obligations

The framework can result in substantial monetary sanctions reaching millions of Israeli shekels for certain violations, with specific statutory calculation and limitation rules.

The sanctions should therefore not be represented as one universal fixed fine applicable to every violation.

Civil and criminal liability

The amended framework also provides for civil remedies and strengthens personal accountability for certain violations.

Amendment 13 introduced provisions allowing courts to award exemplary damages of up to NIS 10,000 in specified circumstances without proof of actual harm.

The law also retains criminal provisions for certain serious privacy violations.

This means organisations should consider privacy compliance from both:

  • Corporate risk perspective
  • Individual decision-maker perspective

Israel PPL compliance checklist

Use this checklist to assess your organisation's readiness.

  • Determine whether the Protection of Privacy Law applies
  • Identify all personal information processed
  • Map databases and processing activities
  • Identify specially sensitive information
  • Document processing purposes
  • Determine applicable legal requirements
  • Obtain informed consent where required
  • Maintain appropriate privacy notices
  • Implement data-minimisation controls
  • Establish retention and deletion procedures
  • Implement appropriate security measures
  • Review Data Security Regulations requirements
  • Establish security-incident procedures
  • Assess database-registration obligations
  • Assess large-database notification requirements
  • Determine whether a DPO is mandatory
  • Appoint a qualified DPO where required
  • Establish data-subject request procedures
  • Implement access and correction workflows
  • Review processor and vendor contracts
  • Assess international data transfers
  • Review cookies and online trackers
  • Configure consent where required
  • Maintain consent evidence
  • Provide consent withdrawal mechanisms
  • Assess AI and automated-processing risks
  • Conduct privacy-risk assessments where appropriate
  • Review compliance regularly

Why consent management matters under Israel PPL

For organisations operating websites in Israel, privacy compliance increasingly requires visibility into how personal information is collected and processed through digital technologies.

A website may contain dozens of:

  • Analytics scripts
  • Advertising pixels
  • Social-media trackers
  • Marketing tools
  • Personalisation technologies
  • Third-party integrations

Without a tracker inventory and consent-management process, organisations may have difficulty demonstrating what information is collected and how user choices are respected.

ConsentX provides a technical layer for managing these website privacy workflows.

How ConsentX helps with Israel PPL compliance

Discover cookies and trackers

Scan your website to identify cookies, pixels, analytics tools, advertising scripts, third-party trackers and embedded technologies.

Create informed consent experiences

Present users with clear information and meaningful choices where consent is the applicable basis.

Block consent-dependent trackers

Prevent optional technologies from executing before the required consent is obtained.

Maintain consent records

Record user choices so organisations can demonstrate what was presented, which purpose was selected, when consent was given, whether consent was withdrawn and which consent version applied.

Support consent withdrawal

Give users an accessible way to modify their privacy choices.

Support privacy-rights workflows

ConsentX can help organisations manage privacy requests and workflows relating to access, correction and other applicable data-subject rights.

Support regional privacy rules

Use regional controls to configure different consent experiences based on applicable privacy requirements.

Improve audit readiness

Maintain structured records that can help privacy teams demonstrate how website consent and tracking controls operate.

Get Israel PPL ready with ConsentX

Israel's privacy framework has undergone a major transformation following Amendment 13. Organisations should now consider privacy compliance as an ongoing operational programme covering data collection → purpose → transparency → consent → tracking → security → third parties → rights → retention → governance. ConsentX can help organisations implement the website-level controls needed to support this process: scan your website, control trackers, capture consent and maintain evidence.

This page provides general information about Israel's Protection of Privacy Law and related regulations and is not legal advice. Israeli privacy requirements can depend on the nature of the organisation, database, processing activity, type and volume of personal information, sector, international transfers and applicable regulatory guidance. Organisations should review the current legislation and Privacy Protection Authority guidance and obtain qualified Israeli legal advice where appropriate.

How to comply with Israel PPL using ConsentX

  1. 1

    Scan your website

    Run a ConsentX scan to identify cookies, scripts, pixels and third-party trackers.

  2. 2

    Classify processing activities

    Determine what information each technology collects and whether it constitutes personal information.

  3. 3

    Identify the purpose

    Document why each tracker or processing technology is used.

  4. 4

    Determine the applicable legal requirement

    Assess whether consent is required or whether another statutory basis applies.

  5. 5

    Configure your consent experience

    Create clear, purpose-specific choices for processing that requires consent.

  6. 6

    Block optional technologies

    Prevent consent-dependent scripts from running until the appropriate choice is received.

  7. 7

    Record consent

    Maintain evidence of the user's decision and the notice presented at the time.

  8. 8

    Enable withdrawal

    Allow users to modify or withdraw consent where applicable.

  9. 9

    Connect privacy requests

    Maintain workflows for access, correction and other applicable privacy rights.

  10. 10

    Review third parties

    Identify all external providers receiving personal information through your website.

  11. 11

    Review international transfers

    Determine where third-party services process Israeli personal information and assess applicable transfer requirements.

  12. 12

    Maintain ongoing compliance

    Regularly rescan the website and update the consent configuration when trackers, vendors, purposes or privacy requirements change.

שאלות נפוצות