Israel’s adequacy is the quiet infrastructure of its tech economy: every EU customer of an Israeli SaaS, security, or analytics vendor relies on Decision 2011/61/EU to skip the SCC-and-assessment machinery that Schrems II inflicted on US flows. The January 2024 reaffirmation settled a decade of doubt about the pre-GDPR decisions, but it converted adequacy from a grandfathered fact into a monitored status, which is why Israel legislated the EEA-data regulations and Amendment 13. Israeli companies keep the privilege by carrying its costs: lineage-tracked duties on EEA data and a credible domestic enforcement regime.
| Instrument | Commission Decision 2011/61/EU |
|---|---|
| Effect | EU/EEA-to-Israel transfers without SCCs or TIAs |
| Reaffirmed | January 15, 2024 (first periodic review) |
| Israeli side | EEA-origin data regulations (2023); Amendment 13 (2025) |
| Onward transfers | Need Israeli-law mechanisms; must not undermine protection |
Operating under adequacy
Tag lineage at ingestion. The EEA-origin duty set attaches to where data came from, not what it is; systems that cannot distinguish EEA-sourced records cannot comply, and this is the single most common gap in Israeli vendors’ architectures.
Keep the domestic house in order. Amendment 13 governance and the Data Security Regulations are what the Commission’s reviewers weigh; PPA findings against your company are adequacy-relevant facts.
Paper the onward chain. Sub-processors outside Israel need lawful onward mechanisms your EU customers can diligence, the same discipline Argentina maintains for its adequacy.
Use it commercially. Adequacy is a differentiator against non-adequate competitors in EU procurement; say so, accurately, in security documentation.
EU customers verify vendors’ public data practices before contracts: preview what they see on your site with a free scan.