Privacy Protection Regulations (Data Security), information security programme
Privacy Protection Regulations (Data Security) 5777-2017, Regs. 1-10, 11(a)-(c), 12-20, 22; Protection of Privacy Law, 5741-1981, Art. 23KF and Third Schedule (enforcement)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force since 8 May 2018.
A security baseline statutes rule binding public and private bodies.
As of 18 September 2026.
What it requires
- An app operating a database of the personal data of a person in Israel, above the small-collection thresholds already recorded on this jurisdiction's privacy-topic row, must prescribe a written data security procedure covering physical protection, access authorizations, identification and authentication, encryption, and incident handling, scaled to the security-level tier (basic, medium, or high) that the volume and sensitivity of the data it holds places it in.
- At the medium or high tier, run an automatic mechanism monitoring access to the database's systems, retained at least 24 months, and appoint a data security officer where required.
- At the high tier, conduct a data security risk assessment and a penetration test of the database's systems at least once every 18 months, and hold a quarterly internal discussion of security incidents.
- At the medium or high tier, conduct an internal or external audit of compliance with these Regulations at least once every 24 months.
- Where an external service provider is given access to the database, agree in writing on the data and systems it may access, its reporting and data-destruction duties, and monitor its compliance.
If you get it wrong
Criminal exposureNo
Private right of actionNo
Criminal exposure note
The Third Schedule's monetary sanctions are administrative, imposed by the Head of the Authority under Article 23KF of the Protection of Privacy Law. No criminal offense specific to a bare failure of these security-programme duties, as distinct from an actual privacy infringement under Article 5, was found in either instrument read for this row.
Penalty structure
The Protection of Privacy Law's Third Schedule (Art. 23KF(h)) sets a distinct monetary sanction for each of 29 numbered categories of violation of the Data Security Regulations, in four columns keyed to the database's security tier (individually-managed, basic, medium, high). Amounts observed across the schedule's safeguards violations (excluding item (21), the Regulation 11(d) breach-notification duty already filed as this jurisdiction's privacy row) range from 1,000 NIS, for a basic-tier or individually-managed database's failure of the physical-protection duty under Regulation 6(a), up to 320,000 NIS at the high tier, for example a high-tier database controller's failure to monitor and supervise an external service provider's compliance under Regulation 15(a)(4). Most other numbered violations sit at 2,000 NIS (individual or basic tier) rising to 40,000 NIS (medium tier) and 160,000 NIS (high tier). Article 2(a) to (d) of the Law separately scales the sanction down for a micro- or small-enterprise violator.
- Rule
- Fixed only
- As of
- 18 September 2026
- Minimum
- 1,000
- Currency
- ILS
- Fixed cap
- 320,000
Who enforces it
Enforcement body
Privacy Protection Authority (Head of the Authority), a unit of Israel's Ministry of Justice, acting as Registrar under the Protection of Privacy Law.
What it reaches
Obligation class
Security
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Every database controller in Israel, private or public, must prescribe a written data security procedure covering physical protection, access authorizations, identification and authentication, encryption of stored and transmitted data, and incident handling, scaled to one of four security-level tiers (individually-managed, basic, medium, high) set by the type, volume, and sensitivity of data the database holds.
A database controller subject to the medium or high tier must additionally run an automatic access-monitoring mechanism retained at least 24 months, and a controller subject to the high tier must conduct a data security risk assessment and a penetration test at least once every 18 months.
Every controller other than one managing a database individually must appoint a data security officer where the Protection of Privacy Law requires one, and must conduct an internal or external audit of compliance with these Regulations at least once every 24 months for a medium- or high-tier database.
A controller engaging an external service provider with access to the database must agree in writing on the data the provider may process, the systems it may access, and the provider's own reporting and destruction duties, and must monitor the provider's compliance.
The Registrar (Head of the Privacy Protection Authority) may exempt a specific database from these duties, or extend them to one that would not otherwise be covered, by written notice given the database's size, the type of information it holds, and its number of authorized users. These duties are separate from Regulation 11(d)'s duty to notify the Registrar of a severe security incident, which is this jurisdiction's privacy-topic breach-notification row.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotautomated_outreachhigh_risk_decisionsprocesses_voiceprocesses_biometricsserves_minorsoperates_social_platformships_mobile_appdistributes_software_product
Read the law
official government publication, Privacy Protection Authority unofficial English translation of the Data Security Regulations' own text
the Protection of Privacy Law's own Third Schedule and Schedule 1 for the enforcement mechanism and the Authority's own definition