Law note · Israel
Protection of Privacy Law, breach notification duty
What it requires
- An app that suffers a severe security incident affecting the personal data of a person in Israel must immediately notify the Head of the Privacy Protection Authority under the Data Security Regulations' Art. 11(d)(1) duty; the regulations' own text, including any data-subject notification duty, was not independently read for this document and should be confirmed before relying on this summary for full compliance detail.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotprocesses_biometricsprocesses_voice
What we found
The Privacy Protection Regulations (Data Security), 5777-2017 were fetched directly for this pass.
Regulation 11(d)(1) requires a database controller to immediately notify the Registrar (Head of the Privacy Protection Authority) of a severe security incident and report on the measures taken in response; this confirms and replaces the main Act's cross-referenced monetary-sanctions-schedule item (21), which separately fines a controller or processor who fails that duty at up to 80,000 or 320,000 NIS for an individual or corporate violator.
A severe security incident is defined by Regulation 1 by reference to the database's security-level tier (unauthorized use or integrity damage affecting a high-security database, or a substantial part of a medium-security one).
Regulation 22 (the regulations' own commencement clause) provides that the regulations take effect one year after their publication; the regulations' own text carries a footnote citing publication as Reshumot Regulations File 5777 no. 7809 dated 8 May 2017, so the one-year clock runs from that date to 8 May 2018. The Minister of Justice signed the regulations 5 April 2017.
Any data-subject notification duty distinct from the Registrar-notification duty was not independently confirmed and is not recorded here.