Law / Israel

Israel

privacy

Israel's Protection of Privacy Law, 5741-1981, was substantially amended by Amendment No. 13 (enacted by the Knesset 5 August 2024, in force since 14 August 2025), which rebuilt registration and notification duties, added a Data Protection Officer requirement, and introduced exemplary damages; this document is built on the Privacy Protection Authority's own amended-text translation, not the pre-2025 posture that most secondary sources still describe.

Data of special sensitivity expressly includes a biometric identifier used to identify or verify a person's identity in a digital manner, defined broadly enough to cover a measure from which the identifier can be derived, including a facial image; no voice-specific carve-out exists.

Cross-border transfer is governed by a separate 2001 regulation requiring the destination's protection to be no less than Israeli law's, or one of eight alternative grounds including consent, corporate-control, and an authority-gazetted adequacy list, correcting the seed's flat absence of restriction to a real, conditioned regime.

Two independent no-proof-of-damage statutory-damages mechanisms, Art. 29A (general, up to 50,000 NIS, doubled for proven intent to harm) and Art. 15A (narrower, up to 10,000 NIS for enumerated procedural violations), arm a private plaintiff without requiring proof of actual damage, the standout enforcement feature among this batch's jurisdictions.

15 instruments named 6 researched in detail As of 2026-08-29

Instruments

Each one links to its LexLint note, which carries what it requires and what it flags on.

Biometric privacy

Protection of Privacy Law, biometric identifier definition and security-level tiering

cite Protection of Privacy Law 5741-1981, as amended by Amendment No. 13, Art. 3 (biometric identifier and data of special sensitivity definitions), security-level provisions stage IN FORCE in force since 2025-08-14 binds public and private bodies source official government publication, Privacy Protection Authority unofficial English translation
What it requires

Art. 3 defines data of special sensitivity to include, among eight-plus enumerated categories, a biometric identifier used or intended to be used to identify a person or verify his identity in a digital manner, itself defined as a biometric data item used to identify a person or verify that person's identity, or a biometric measure from which the said data item can be derived, where biometric means a unique human, physiological, or behavioral characteristic that can be measured through digital measurement.

The derivation clause affirmatively brings in an identifier derived from a recording; a facial image is confirmed within scope by a separate security-level provision that gives a biometric identifier limited to a facial image a lighter basic-security-level treatment only when confined to internal employee or supplier management, a security-tier carve-out, not a substantive consent exemption.

Chapter D3/D4 imposes tiered security-level obligations keyed partly to biometric-identifier volume, automatically classifying a database of 100,000 or more biometric identifiers as high security level. No voice-specific provision or dedicated biometric retention or destruction duty was found; Art. 2(6) separately prohibits commercial use of a person's name, image, or voice without consent as a distinct tort, outside the database regime.

Breach notification

Protection of Privacy Law, breach notification duty

cite Privacy Protection Regulations (Data Security) 5777-2017, Art. 11(d)(1); Protection of Privacy Law, 5741-1981, monetary sanctions schedule item (21) stage IN FORCE in force since 2018-05-08 binds public and private bodies source official government publication, Privacy Protection Authority unofficial English translation of the Data Security Regulations' own text
What it requires

The Privacy Protection Regulations (Data Security), 5777-2017 were fetched directly for this pass.

Regulation 11(d)(1) requires a database controller to immediately notify the Registrar (Head of the Privacy Protection Authority) of a severe security incident and report on the measures taken in response; this confirms and replaces the main Act's cross-referenced monetary-sanctions-schedule item (21), which separately fines a controller or processor who fails that duty at up to 80,000 or 320,000 NIS for an individual or corporate violator.

A severe security incident is defined by Regulation 1 by reference to the database's security-level tier (unauthorized use or integrity damage affecting a high-security database, or a substantial part of a medium-security one).

Regulation 22 (the regulations' own commencement clause) provides that the regulations take effect one year after their publication; the regulations' own text carries a footnote citing publication as Reshumot Regulations File 5777 no. 7809 dated 8 May 2017, so the one-year clock runs from that date to 8 May 2018. The Minister of Justice signed the regulations 5 April 2017.

Any data-subject notification duty distinct from the Registrar-notification duty was not independently confirmed and is not recorded here.

Comprehensive regime

Protection of Privacy Law, comprehensive regime and database registration

cite Protection of Privacy Law, 5741-1981, as amended by Amendment No. 13, 5784-2024, Arts. 1-2, 4, 7-8A stage IN FORCE in force since 2025-08-14 binds public and private bodies source official government publication, Privacy Protection Authority unofficial English translation
What it requires

Israel's Protection of Privacy Law, 5741-1981, creates a general tort of privacy infringement in Chapter A (Arts. 1-2, 4) and regulates 'databases' specifically from Art. 7 onward in Chapter B. A database excludes purely personal-use collections and small (100,000-or-fewer-person) name, address, or contact-only collections.

Amendment No. 13 rebuilt registration and notification duty at Art. 8A: mandatory registration is now limited to databases whose main purpose is commercial data provision with more than 10,000 individuals, or public-body databases, plus a separate notification duty, short of full registration, for any database holding special-sensitivity data on more than 100,000 individuals, including naming a Data Protection Officer where one is required.

Cross border transfer

Privacy Protection (Transfer of Data to Databases Abroad) Regulations, cross-border transfer

cite Privacy Protection (Transfer of Data to Databases Abroad) Regulations, 5761-2001 stage IMMINENT commencement not set binds public and private bodies source official government publication, Privacy Protection Authority unofficial English translation
What it requires

Under PPL Art. 36(2), these regulations bar transfer of personal data outside Israel unless the destination country's law ensures protection no less than Israeli law provides, subject to five baseline principles: fair collection, purpose limitation, accuracy, an inspection right, and security.

Regulation 2 lists eight independent grounds permitting transfer regardless of that default rule: consent; vital-interest necessity where consent cannot be obtained; transfer to a corporation under common control with a privacy guarantee; transfer to a party bound by agreement to the same conditions; data already made public or open for inspection; public safety or security necessity; a legally mandated transfer; or transfer to a Convention 108 party, a state receiving data from EU member states on equivalent terms, or a state the Registrar of Databases has gazetted as having an adequate privacy authority.

Regulation 3 requires a written guarantee from the recipient in every case. No data localization is compelled.

Regulation 5 (the regulations' own commencement clause) provides that the regulations enter into force six months after the date of their publication; the regulations were signed 17 June 2001 (26 Sivan 5761), but their Reshumot publication date, which Regulation 5's six-month clock actually runs from, was not established at primary source this pass, so effective_date is left blank rather than computed from the signature date. Whether Amendment 13 touched this 2001 regulation was not confirmed against the Reshumot in this research pass.

Data subject rights

Protection of Privacy Law, data subject rights

cite Protection of Privacy Law, 5741-1981, Arts. 13, 13A, 14 stage IMMINENT commencement not set binds public and private bodies source official government publication, Privacy Protection Authority unofficial English translation
What it requires

Arts. 13 and 13A give a data subject the right to access their own data held by a database, and Art. 14 gives a right to demand rectification or deletion, with follow-through notice to prior recipients of the corrected or deleted data; Art. 16 imposes a confidentiality duty on anyone with database access. A separate compensation right exists through the enforcement provisions rather than as a standalone rights article.

No General Data Protection Regulation (GDPR) Art. 22-style right to object to a fully automated decision was confirmed in what was read for this document; this should not be asserted either way pending a further pass.

Arts. 13 and 14 are original 1981 enactment provisions, sitting in Chapter B, whose own Art. 37 commencement clause provides that Chapter B comes into force six months from the date of publication of this Law rather than on Knesset passage; the original Hebrew enactment (fetched directly from the Knesset's own legislative archive) confirms this wording and confirms Art. 13A is not present in that 1981 text, so it was inserted by a later amendment.

Neither the original Law's Reshumot publication date nor Art. 13A's own insertion date was established at primary source this pass, so effective_date is left blank and status is recorded as enacted rather than a guessed in_effect date.

Enforcement supervision

Protection of Privacy Law, enforcement, DPO duty and private rights of action

cite Protection of Privacy Law, 5741-1981, as amended by Amendment No. 13, Arts. 15A, 17B1-17B3, 29A, 31B, Chapters D3-D4 stage IN FORCE in force since 2025-08-14 binds public and private bodies source official government publication, Privacy Protection Authority unofficial English translation
What it requires

The Privacy Protection Authority (Head of the Authority) enforces the Act, with Chapters D3-D4 monetary sanctions scaled to violation type and database security level, observed up to 320,000 NIS for an individual violator in the severe-incident non-reporting tier of the schedule read for this document, with a higher corporate tier.

Two independent private-right-of-action mechanisms, both not requiring proof of damage, exist: Art. 29A lets a court award statutory damages up to 50,000 NIS per infringement, doubled to 100,000 NIS where intent to harm is proven, for any civil privacy infringement under the Chapter A general tort, expressly not dependent on damage; Art. 15A separately lets a court award exemplary damages up to 10,000 NIS, narrower in scope (six specific database-controller procedural violations), where the court is directed not to consider the extent of damage caused.

Art. 31B extends ordinary civil-wrong liability under the Torts Ordinance to a violation of Chapters B or D or regulations made under the Act, beyond the Chapter A tort alone. Amendment No. 13 added the Data Protection Officer duty at Arts. 17B1-17B3.

This summary covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted above and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.