Middle East & Africa Israel

Israel Privacy Protection Law: Amendment 13 Changes Everything

Israel's Privacy Protection Law after Amendment 13 (effective August 2025): PPA enforcement powers, DPO duties, narrowed database registration, and NIS-scaled fines.

Regulation

Protection of Privacy Law, 5741-1981, as amended by Amendment No. 13 (2024, effective August 14, 2025); Data Security Regulations 2017

Max Penalty

Amendment 13 administrative fines scale with violation type and database size, reaching millions of NIS for large-scale violations; criminal provisions remain for listed offenses

Enforcing Authority

Privacy Protection Authority (PPA)

Official Source

www.gov.il

Executive Summary

  • Israel's Protection of Privacy Law dates to 1981, but Amendment No. 13, passed August 2024 and effective August 14, 2025, is the largest reform in its history, modernizing definitions, enforcement, and governance toward GDPR alignment.
  • The Privacy Protection Authority (PPA) gained real teeth: administrative fines scaled to violation type and database size (reaching millions of NIS for large databases), enforcement orders, and expanded investigation powers.
  • Database registration, once required for most databases, was narrowed to databases whose main purpose is collecting data for third parties (data brokers) and large sensitive-data databases held by public bodies, replaced for most companies by notification and governance duties.
  • A DPO ('privacy protection officer') became mandatory for public bodies, data brokers, and entities whose core activities involve large-scale sensitive data or systematic monitoring, a GDPR-style trigger set.
  • Israel holds EU adequacy (2011, reaffirmed in the Commission's January 2024 review), and Amendment 13 was designed partly to keep it; the Data Security Regulations 2017 remain the binding security baseline.

Israel ran a 1981 privacy law, one of the world’s oldest, well into the platform era, patching it with regulations while enforcement leaned on criminal provisions too heavy to use. Amendment 13 is the generational correction: effective August 14, 2025, it swaps registration bureaucracy for GDPR-style governance, arms the PPA with size-scaled administrative fines, and modernizes definitions written before the internet. The strategy is explicit, keep EU adequacy, keep Israeli tech exportable, and it makes Israeli compliance legible to anyone who knows the GDPR, with the 2017 Data Security Regulations remaining the unusually prescriptive security floor beneath it.

LawProtection of Privacy Law 5741-1981, Amendment 13
Amendment 13 effectiveAugust 14, 2025
RegulatorPrivacy Protection Authority (PPA)
RegistrationNarrowed to brokers and public-body sensitive databases
DPOMandatory for public bodies, brokers, large-scale sensitive/monitoring processing
EU adequacyHeld since 2011; reaffirmed January 2024

Building Israel compliance post-Amendment 13

Re-baseline against the amended law, not the old registration regime. Registration effort converts into governance artifacts: database definitions documents, notifications where thresholds are met, and DPO appointments on the new triggers.

Treat the Data Security Regulations as an audit checklist. Tiering, logging, testing cycles, and incident notification are specific enough to self-assess against, and the PPA does exactly that after breaches.

Segregate EEA-origin data duties. The 2023 EEA-data regulations impose deletion, accuracy, and retention duties on EEA-sourced records inside Israeli systems; flag that lineage in the inventory, and see the Israel-EU adequacy guide for the transfer mechanics.

Extend the GDPR program, don’t fork it. Amendment 13’s DPO, breach, and fine structures were designed to rhyme with the EU’s; a jurisdiction annex covering the regional contrasts usually suffices.

Israeli-facing sites’ trackers and consent behavior feed PPA complaint files: check yours with a free scan.

Frequently Asked Questions

What did Amendment 13 actually change?

Five headlines: (1) definitions modernized, 'personal data' and 'sensitive data' ('data of special sensitivity') now read like GDPR terms, covering biometric, genetic, location, and behavioral data explicitly; (2) enforcement transformed, the PPA can levy administrative fines scaled by violation and database size instead of relying on the old criminal-first toolkit; (3) database registration largely abolished, retained only for data brokers and certain public-body databases, with notification duties replacing it; (4) mandatory privacy protection officers for defined categories; (5) expanded judicial remedies including statutory damages without proof of harm for listed violations. It applies from August 14, 2025, with organizations expected compliant on day one.

Who needs a privacy protection officer (DPO)?

Under Amendment 13: public bodies; database brokers (entities whose main purpose is collecting personal data to provide it to others); and controllers or processors whose core activities involve processing data of special sensitivity at scale, or regular and systematic monitoring of individuals at scale, banks, insurers, HMOs, telecoms, and large digital platforms are the paradigm cases. The officer must have suitable qualifications, report to management, avoid conflicts of interest, and serve as the PPA contact point. It is deliberately parallel to GDPR Article 37, letting multinationals extend their EU DPO structure to Israel with a local mandate.

What happened to database registration?

The old law required registering most databases with the Registrar, a bureaucratic regime honored substantially in the breach (hundreds of thousands of unregistered databases by the PPA's own estimates). Amendment 13 scrapped it for ordinary companies: registration now applies mainly to data brokers and to public bodies holding large sensitive databases, while databases above defined size/sensitivity thresholds owe the PPA a notification with prescribed particulars. The practical shift: effort moves from filing forms to maintaining governance, database definitions documents, security protocols under the 2017 Regulations, DPO appointments, and breach readiness.

What do the Data Security Regulations require?

The 2017 Regulations remain Israel's binding, prescriptive security floor, unusual globally for their specificity. Databases are tiered (basic, medium, high security) by sensitivity, number of subjects, and access population; duties scale accordingly: a written database definitions document, security procedures, access management, audit logging, physical safeguards, encryption expectations for transfers and portable media, penetration testing and risk surveys on fixed cycles for higher tiers, incident documentation, and mandatory notification of serious incidents to the PPA. They are enforceable independently of Amendment 13 and are the first thing the PPA asks for after a breach.

How does Israel's EU adequacy status work with all this?

Israel has held an EU adequacy decision since 2011 (covering automated international transfers), meaning EU/EEA data flows to Israel without SCCs. The Commission's first periodic review, concluded January 2024, reaffirmed Israel's adequacy alongside ten other pre-GDPR decisions, explicitly noting Israel's strengthened framework, and Amendment 13 plus the 2023 privacy regulations on data originating from the EEA (which impose GDPR-style duties on Israeli holders of EEA data: deletion rights, retention limits, notification duties) were central to that outcome. For companies, the practical consequences: EU-Israel flows stay paperless, and EEA-origin data inside Israeli systems carries its own enhanced duty set. See the Israel adequacy guide for the mechanics.

Regulatory Crosswalk

GDPREU adequacyIsrael PPL

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.