Middle East & Africa Israel / EU

Israel EU Adequacy: Paperless Transfers and Their Conditions

How Israel's EU adequacy decision works: the 2011 decision, the January 2024 reaffirmation, the EEA-origin data regulations, and what Israeli companies must maintain.

Regulation

Commission Decision 2011/61/EU; GDPR Article 45; Israeli Privacy Protection Regulations (EEA-origin data, 2023); Amendment 13

Max Penalty

Adequacy itself carries no fine; violating the EEA-data regulations or the amended PPL triggers PPA enforcement and can imperil the adequacy finding

Enforcing Authority

European Commission (adequacy); Privacy Protection Authority (Israeli side)

Official Source

eur-lex.europa.eu

Executive Summary

  • Commission Decision 2011/61/EU recognizes Israel as providing adequate protection for automated personal-data transfers from the EU/EEA, so those flows need no SCCs, BCRs, or derogations.
  • The Commission's first periodic review under the GDPR, concluded January 15, 2024, reaffirmed Israel's adequacy along with ten other pre-GDPR decisions, citing Israel's strengthened framework.
  • Israel's 2023 Privacy Protection Regulations on EEA-origin data impose GDPR-style duties (deletion, accuracy, retention limits, notification) on Israeli entities holding data received from the EEA under adequacy, duties that attach to the data's lineage.
  • Amendment 13 (effective August 2025) reinforced the adequacy case by modernizing enforcement and governance; maintaining adequacy is an explicit design goal of Israeli reform.
  • Adequacy covers EU-to-Israel flows; onward transfers from Israel to third countries must not undermine the protection, and Israeli exporters need their own lawful mechanisms for those.

Israel’s adequacy is the quiet infrastructure of its tech economy: every EU customer of an Israeli SaaS, security, or analytics vendor relies on Decision 2011/61/EU to skip the SCC-and-assessment machinery that Schrems II inflicted on US flows. The January 2024 reaffirmation settled a decade of doubt about the pre-GDPR decisions, but it converted adequacy from a grandfathered fact into a monitored status, which is why Israel legislated the EEA-data regulations and Amendment 13. Israeli companies keep the privilege by carrying its costs: lineage-tracked duties on EEA data and a credible domestic enforcement regime.

InstrumentCommission Decision 2011/61/EU
EffectEU/EEA-to-Israel transfers without SCCs or TIAs
ReaffirmedJanuary 15, 2024 (first periodic review)
Israeli sideEEA-origin data regulations (2023); Amendment 13 (2025)
Onward transfersNeed Israeli-law mechanisms; must not undermine protection

Operating under adequacy

Tag lineage at ingestion. The EEA-origin duty set attaches to where data came from, not what it is; systems that cannot distinguish EEA-sourced records cannot comply, and this is the single most common gap in Israeli vendors’ architectures.

Keep the domestic house in order. Amendment 13 governance and the Data Security Regulations are what the Commission’s reviewers weigh; PPA findings against your company are adequacy-relevant facts.

Paper the onward chain. Sub-processors outside Israel need lawful onward mechanisms your EU customers can diligence, the same discipline Argentina maintains for its adequacy.

Use it commercially. Adequacy is a differentiator against non-adequate competitors in EU procurement; say so, accurately, in security documentation.

EU customers verify vendors’ public data practices before contracts: preview what they see on your site with a free scan.

Frequently Asked Questions

What exactly does the adequacy decision allow?

Transfers of personal data from EU/EEA controllers and processors to recipients in Israel on the same footing as intra-EU flows, no standard contractual clauses, no transfer impact assessments, no derogations, for automated processing (the decision's scope covers automated transfers and automated processing of transferred data). All other GDPR duties still apply to the EU exporter: lawful basis, notice, processor contracts under Article 28 where the Israeli recipient is a processor. Adequacy solves Chapter V only; it is a transfer mechanism, not a compliance waiver.

What did the January 2024 review conclude?

The Commission's report on the eleven pre-GDPR adequacy decisions (published January 15, 2024) found that Israel continues to provide an adequate level of protection, pointing to developments including the Data Security Regulations 2017, the 2023 regulations on EEA-origin data, PPA enforcement activity, and the then-pending Amendment 13. The review also standardized ongoing monitoring: adequacy is now periodically reassessed, and material regressions, weakened oversight, or surveillance-law changes could reopen it. For planning purposes: adequacy is stable but conditional, and Israeli reforms have been calibrated to keep it.

What are the EEA-origin data regulations and who do they bind?

Israeli regulations from 2023 that attach extra duties to personal data an Israeli entity received from the EEA under the adequacy decision: obligations to delete data on request and when no longer needed, ensure accuracy, limit retention, pass rectifications along, and notify data subjects in defined cases, essentially importing GDPR expectations the older Israeli law lacked, but only for EEA-lineage data. Israeli companies therefore run dual-track obligations: baseline Israeli law for domestic data, enhanced duties for EEA-sourced records. Systems need lineage tagging to apply the right track, which is the operational cost of paperless transfers.

Does adequacy cover onward transfers from Israel to other countries?

Not automatically. The decision requires that onward transfers from Israel not undermine the protection guaranteed; the EEA-origin regulations and Israeli transfer rules (Privacy Protection (Transfer of Data Abroad) Regulations, 5761-2001) govern the Israeli exporter's side, permitting transfers to countries with adequate protection (including EU members and countries the EU recognizes), or on conditions like consent and contractual safeguards. So an Israeli SaaS company receiving EU customer data and sub-processing it in the US needs its own lawful onward mechanism, and its EU customers will diligence exactly that chain in vendor reviews.

What should Israeli companies do to stay on the right side of adequacy?

Four disciplines: (1) tag EEA-origin data and enforce the 2023 regulations' deletion, accuracy, and retention duties on it; (2) comply with Amendment 13's governance (DPO where triggered, breach notification, fine-backed duties) since PPA enforcement credibility is part of the EU's assessment; (3) maintain the Data Security Regulations' tiered controls, they are the demonstrable security baseline; (4) paper onward transfers properly. Commercially, adequacy is a sales asset for Israeli vendors, EU customers skip transfer assessments, and it survives only as long as the aggregate system persuades the Commission's periodic reviews.

Regulatory Crosswalk

GDPREU adequacyIsrael PPL

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.