Instruments
Each one links to its
LexLint note, which carries what it requires and what it flags on.
Biometric privacy
cite Protection of Privacy Law 5741-1981, as amended by Amendment No. 13, Art. 3 (biometric identifier and data of special sensitivity definitions), security-level provisions
stage IN FORCE in force since 2025-08-14
binds public and private bodies
source official government publication, Privacy Protection Authority unofficial English translation
What it requires →
Art. 3 defines data of special sensitivity to include, among eight-plus enumerated categories, a biometric identifier used or intended to be used to identify a person or verify his identity in a digital manner, itself defined as a biometric data item used to identify a person or verify that person's identity, or a biometric measure from which the said data item can be derived, where biometric means a unique human, physiological, or behavioral characteristic that can be measured through digital measurement.
The derivation clause affirmatively brings in an identifier derived from a recording; a facial image is confirmed within scope by a separate security-level provision that gives a biometric identifier limited to a facial image a lighter basic-security-level treatment only when confined to internal employee or supplier management, a security-tier carve-out, not a substantive consent exemption.
Chapter D3/D4 imposes tiered security-level obligations keyed partly to biometric-identifier volume, automatically classifying a database of 100,000 or more biometric identifiers as high security level. No voice-specific provision or dedicated biometric retention or destruction duty was found; Art. 2(6) separately prohibits commercial use of a person's name, image, or voice without consent as a distinct tort, outside the database regime.
Breach notification
cite Privacy Protection Regulations (Data Security) 5777-2017, Art. 11(d)(1); Protection of Privacy Law, 5741-1981, monetary sanctions schedule item (21)
stage IN FORCE in force since 2018-05-08
binds public and private bodies
source official government publication, Privacy Protection Authority unofficial English translation of the Data Security Regulations' own text
What it requires →
The Privacy Protection Regulations (Data Security), 5777-2017 were fetched directly for this pass.
Regulation 11(d)(1) requires a database controller to immediately notify the Registrar (Head of the Privacy Protection Authority) of a severe security incident and report on the measures taken in response; this confirms and replaces the main Act's cross-referenced monetary-sanctions-schedule item (21), which separately fines a controller or processor who fails that duty at up to 80,000 or 320,000 NIS for an individual or corporate violator.
A severe security incident is defined by Regulation 1 by reference to the database's security-level tier (unauthorized use or integrity damage affecting a high-security database, or a substantial part of a medium-security one).
Regulation 22 (the regulations' own commencement clause) provides that the regulations take effect one year after their publication; the regulations' own text carries a footnote citing publication as Reshumot Regulations File 5777 no. 7809 dated 8 May 2017, so the one-year clock runs from that date to 8 May 2018. The Minister of Justice signed the regulations 5 April 2017.
Any data-subject notification duty distinct from the Registrar-notification duty was not independently confirmed and is not recorded here.
Comprehensive regime
What it requires →
Israel's Protection of Privacy Law, 5741-1981, creates a general tort of privacy infringement in Chapter A (Arts. 1-2, 4) and regulates 'databases' specifically from Art. 7 onward in Chapter B. A database excludes purely personal-use collections and small (100,000-or-fewer-person) name, address, or contact-only collections.
Amendment No. 13 rebuilt registration and notification duty at Art. 8A: mandatory registration is now limited to databases whose main purpose is commercial data provision with more than 10,000 individuals, or public-body databases, plus a separate notification duty, short of full registration, for any database holding special-sensitivity data on more than 100,000 individuals, including naming a Data Protection Officer where one is required.
Cross border transfer
What it requires →
Under PPL Art. 36(2), these regulations bar transfer of personal data outside Israel unless the destination country's law ensures protection no less than Israeli law provides, subject to five baseline principles: fair collection, purpose limitation, accuracy, an inspection right, and security.
Regulation 2 lists eight independent grounds permitting transfer regardless of that default rule: consent; vital-interest necessity where consent cannot be obtained; transfer to a corporation under common control with a privacy guarantee; transfer to a party bound by agreement to the same conditions; data already made public or open for inspection; public safety or security necessity; a legally mandated transfer; or transfer to a Convention 108 party, a state receiving data from EU member states on equivalent terms, or a state the Registrar of Databases has gazetted as having an adequate privacy authority.
Regulation 3 requires a written guarantee from the recipient in every case. No data localization is compelled.
Regulation 5 (the regulations' own commencement clause) provides that the regulations enter into force six months after the date of their publication; the regulations were signed 17 June 2001 (26 Sivan 5761), but their Reshumot publication date, which Regulation 5's six-month clock actually runs from, was not established at primary source this pass, so effective_date is left blank rather than computed from the signature date. Whether Amendment 13 touched this 2001 regulation was not confirmed against the Reshumot in this research pass.
Data subject rights
What it requires →
Arts. 13 and 13A give a data subject the right to access their own data held by a database, and Art. 14 gives a right to demand rectification or deletion, with follow-through notice to prior recipients of the corrected or deleted data; Art. 16 imposes a confidentiality duty on anyone with database access. A separate compensation right exists through the enforcement provisions rather than as a standalone rights article.
No General Data Protection Regulation (GDPR) Art. 22-style right to object to a fully automated decision was confirmed in what was read for this document; this should not be asserted either way pending a further pass.
Arts. 13 and 14 are original 1981 enactment provisions, sitting in Chapter B, whose own Art. 37 commencement clause provides that Chapter B comes into force six months from the date of publication of this Law rather than on Knesset passage; the original Hebrew enactment (fetched directly from the Knesset's own legislative archive) confirms this wording and confirms Art. 13A is not present in that 1981 text, so it was inserted by a later amendment.
Neither the original Law's Reshumot publication date nor Art. 13A's own insertion date was established at primary source this pass, so effective_date is left blank and status is recorded as enacted rather than a guessed in_effect date.
Enforcement supervision
What it requires →
The Privacy Protection Authority (Head of the Authority) enforces the Act, with Chapters D3-D4 monetary sanctions scaled to violation type and database security level, observed up to 320,000 NIS for an individual violator in the severe-incident non-reporting tier of the schedule read for this document, with a higher corporate tier.
Two independent private-right-of-action mechanisms, both not requiring proof of damage, exist: Art. 29A lets a court award statutory damages up to 50,000 NIS per infringement, doubled to 100,000 NIS where intent to harm is proven, for any civil privacy infringement under the Chapter A general tort, expressly not dependent on damage; Art. 15A separately lets a court award exemplary damages up to 10,000 NIS, narrower in scope (six specific database-controller procedural violations), where the court is directed not to consider the extent of damage caused.
Art. 31B extends ordinary civil-wrong liability under the Torts Ordinance to a violation of Chapters B or D or regulations made under the Act, beyond the Chapter A tort alone. Amendment No. 13 added the Data Protection Officer duty at Arts. 17B1-17B3.