EnglishHE
Israel flag

Israel

Israel Data Privacy Laws: Complete Guide to the PPL and Amendment 13 (2026)

By Recording Law Editorial TeamReviewed May 20, 202623 min read
Israel Data Privacy Laws: Complete Guide to the PPL and Amendment 13 (2026)

Frequently Asked Questions

Does the Israeli Protection of Privacy Law apply to foreign companies?

The PPL applies to anyone who maintains a database containing personal data of Israeli residents, regardless of where the organization is located. A foreign company that actively collects data from Israeli residents or operates a service targeting Israeli users falls within its scope. However, the law's extraterritorial reach is more limited in practice than the GDPR. The PPA has signaled willingness to pursue enforcement against foreign entities in cases involving serious violations.

What is the deadline for appointing a DPO under Amendment 13?

Amendment 13 took effect on August 14, 2025. The PPA granted a grace period until October 31, 2025, during which it would not enforce the DPO requirement. That grace period has expired. Organizations that fall within the mandatory categories (public bodies, data brokers with 10,000+ records, large-scale ISS processors, and systematic monitoring entities) should have a DPO in place. DPO compliance is a stated 2026 enforcement priority.

Does Israel's EU adequacy status mean GDPR compliance is automatic?

No. EU adequacy status means that personal data can flow from the EU to Israel without additional transfer mechanisms like Standard Contractual Clauses. It does not mean that Israeli organizations automatically comply with the GDPR. If your organization processes data of EU residents, you must comply with the GDPR independently. The adequacy decision simplifies the transfer mechanism; it does not substitute for substantive GDPR compliance.

Can individuals sue for privacy violations without proving harm under Amendment 13?

Yes. This is one of Amendment 13's most significant changes. Individuals can now bring civil claims for privacy violations and receive statutory damages of up to NIS 100,000 (approximately USD 27,000) per person without proving actual harm. The statute of limitations for such claims is seven years. Class action lawsuits are also possible, meaning organizations facing widespread violations could face substantial aggregate liability.

Do I still need to register my database with the PPA after Amendment 13?

Most private-sector organizations no longer need to register. Registration is now mandatory only for data brokers with databases covering more than 10,000 individuals, and for public agencies. However, private-sector organizations that process Information of Special Sensitivity about more than 100,000 individuals must notify the PPA of their identity, contact details, and DPO information, even if full registration is not required.

What counts as Information of Special Sensitivity under Amendment 13?

Information of Special Sensitivity (ISS) under Amendment 13 includes: health conditions and genetic information, biometric identifiers used for identification or verification, sexual orientation and intimate family life, political views and opinions, ethnic or racial origin, criminal record, geolocation data, and financial details. Processing ISS requires explicit, separate consent and triggers the strictest security requirements and highest fine multipliers.

What are the PPA's enforcement priorities for 2026?

The PPA has identified DPO compliance as a key 2026 priority, with particular focus on whether DPOs have genuine independence, adequate resources, and proper governance integration. Enforcing data subject access and rectification rights is also a stated priority. AI governance and cookie consent standards are emerging enforcement areas, with the PPA expected to finalize its AI guidelines and begin active enforcement during 2026.

Updates

Full audit-and-evolve refresh. Added AI guidelines section (PPA draft guidance, April 2025), expanded Amendment 13 coverage (DPO independence rules, statute of limitations extension to 7 years, pre-ruling procedure), added first enforcement cases under Amendment 13, corrected EU adequacy renewal date to January 15, 2024, and expanded compliance section. Word count: ~6,200.

Initial publication covering PPL 1981, Amendment 13 overview, EU adequacy, Data Security Regulations, and penalties.

Sources and References

  1. Protection of Privacy Law, 5741-1981 (Full Text)(wipo.int)
  2. Privacy Protection Authority Official Page(gov.il).gov
  3. Israel: Amendment to Privacy Protection Law Goes into Effect(loc.gov).gov
  4. Privacy Protection (Data Security) Regulations, 5777-2017(gov.il).gov
  5. Privacy Protection (Transfer of Data Abroad) Regulations(gov.il).gov
  6. EU Data Protection Adequacy Decisions(commission.europa.eu).gov
  7. European Commission Reaffirms Israel Adequacy Status(gov.il).gov
  8. Israel Marks a New Era in Privacy Law: Amendment 13(iapp.org)
  9. Israeli PPA Legislation Page(gov.il).gov
  10. EU Parliament Question on Israel Adequacy Agreement(europarl.europa.eu).gov
  11. Civil Society Urges EU to Reassess Israel Adequacy Status(edri.org)
  12. PPA First Fines Under Amendment 13(ai-law.co.il)
  13. Draft Clarification on DPO Requirements Under Amendment 13(arnontl.com)
  14. Board Responsibility and DPO Appointment Under Amendment 13(barlaw.co.il)
  15. Israeli PPA Draft Guidance on AI Systems(arnontl.com)
  16. EU Renews Israel Data Protection Adequacy Recognition January 2024(law.co.il)
  17. Israel Privacy Protection Law Amendment A Landmark Reform(ilflaw.com)
  18. Israel Amendment 13 What the New Law Means for Your Business(safetica.com)
Share: