Law note · Israel

Protection of Privacy Law, breach notification duty

cite Privacy Protection Regulations (Data Security) 5777-2017, Art. 11(d)(1); Protection of Privacy Law, 5741-1981, monetary sanctions schedule item (21) stage IN FORCE in force since 2018-05-08 kind Breach notification binds public and private bodies reviewed 2026-08-29

What it requires

  • An app that suffers a severe security incident affecting the personal data of a person in Israel must immediately notify the Head of the Privacy Protection Authority under the Data Security Regulations' Art. 11(d)(1) duty; the regulations' own text, including any data-subject notification duty, was not independently read for this document and should be confirmed before relying on this summary for full compliance detail.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • processes_biometrics
  • processes_voice

What we found

The Privacy Protection Regulations (Data Security), 5777-2017 were fetched directly for this pass.

Regulation 11(d)(1) requires a database controller to immediately notify the Registrar (Head of the Privacy Protection Authority) of a severe security incident and report on the measures taken in response; this confirms and replaces the main Act's cross-referenced monetary-sanctions-schedule item (21), which separately fines a controller or processor who fails that duty at up to 80,000 or 320,000 NIS for an individual or corporate violator.

A severe security incident is defined by Regulation 1 by reference to the database's security-level tier (unauthorized use or integrity damage affecting a high-security database, or a substantial part of a medium-security one).

Regulation 22 (the regulations' own commencement clause) provides that the regulations take effect one year after their publication; the regulations' own text carries a footnote citing publication as Reshumot Regulations File 5777 no. 7809 dated 8 May 2017, so the one-year clock runs from that date to 8 May 2018. The Minister of Justice signed the regulations 5 April 2017.

Any data-subject notification duty distinct from the Registrar-notification duty was not independently confirmed and is not recorded here.

← Back to the example  ·  Lint your app →