Law note · Israel
Protection of Privacy Law, enforcement, DPO duty and private rights of action
What it requires
- An app processing the personal data of a person in Israel must be prepared to answer to the Privacy Protection Authority's monetary sanctions, and an individual harmed by a privacy infringement may bring a civil claim for statutory or exemplary damages without needing to prove actual damage.
When LexLint raises it
crawls_webtrains_modelsgenerates_contentdeploys_chatbotautomated_outreachhigh_risk_decisionsprocesses_voiceprocesses_biometrics
- Private right of action
- Yes
What we found
The Privacy Protection Authority (Head of the Authority) enforces the Act, with Chapters D3-D4 monetary sanctions scaled to violation type and database security level, observed up to 320,000 NIS for an individual violator in the severe-incident non-reporting tier of the schedule read for this document, with a higher corporate tier.
Two independent private-right-of-action mechanisms, both not requiring proof of damage, exist: Art. 29A lets a court award statutory damages up to 50,000 NIS per infringement, doubled to 100,000 NIS where intent to harm is proven, for any civil privacy infringement under the Chapter A general tort, expressly not dependent on damage; Art. 15A separately lets a court award exemplary damages up to 10,000 NIS, narrower in scope (six specific database-controller procedural violations), where the court is directed not to consider the extent of damage caused.
Art. 31B extends ordinary civil-wrong liability under the Torts Ordinance to a violation of Chapters B or D or regulations made under the Act, beyond the Chapter A tort alone. Amendment No. 13 added the Data Protection Officer duty at Arts. 17B1-17B3.