Publication
Publication
S. Horowitz
Pini Azaria
Tel: +972 (0)3 5670700
pini.azaria@s-horowitz.com
Supervisory Authority
National Legislation
Privacy Protection Regulations (Data Security), 5777-2017
(Please note these links are provided for information only. Any translations may not be accurate and the text may not include amendments to that legislation).
Contributed by S. Horowitz
Last updated August 2026
General | Data Protection Laws
National Legislation
National Supervisory Authority
Scope of Application
Personal Data
Sensitive Personal Data
Data Protection Officers
Accountability and Privacy Impact Assessments
Rights of Data Subjects
Security
Transfer of Personal Data to Third Countries
Enforcement
ePrivacy | Marketing and cookies
National Legislation
Cookies
Marketing by E-mail
Marketing by Telephone
General data protection laws
The right to privacy is a fundamental constitutional right in Israel that is enshrined in the Basic Law: Human Dignity and Liberty.
The Israeli data protection framework consists of general, cross-sector (horizontal) legislation, supplemented by sector-specific and subject-specific laws.
The primary legislation governing data protection is the Protection of Privacy Law, 5741-1981 (the "PPL") and its subsidiary regulations, most notably the Privacy Protection Regulations (Data Security), 5777-2017 (the "Data Security Regulations").
Supplementing laws include the Credit Data Law, 5776-2016; the Criminal Information and Rehabilitation Law, 5779-2019; the Patient's Rights Law, 5756-1996; and the Genetic Information Law, 5761-2000.
Israel’s data protection regime is broadly aligned with the principles of the EU General Data Protection Regulation (“GDPR”), although key differences remain in its practical application.
In August 2025, a comprehensive amendment to the PPL ("Amendment 13") came into effect, introducing significant changes to the law. These include mandating the appointment of a Data Protection Officer (“DPO”) for various entities, significantly narrowing database registration requirements, updating statutory terminology, expanding obligations and the scope of those subject to them, and substantially increasing administrative monetary penalties and enforcement powers for non-compliance.
Entry into force
The PPL entered into force in 1981.
Amendment 13 came into force on 14 August 2025.
Details of the competent national supervisory authority
The primary regulator is the Privacy Protection Authority (the "PPA"), operating alongside sector-specific regulators (such as the Supervisor of Banks, the Capital Market, Insurance and Savings Authority, the Ministry of Health, and the Israel Securities Authority) and the National Cyber Directorate.
The Privacy Protection Authority
2 Wolfson Boulevard, David Ben-Gurion Government Quarter, Jerusalem
P.O. Box 49029
Zip Code: 9149001
www.gov.il/he/Departments/the_privacy_protection_authority (HEB)
www.gov.il/en/departments/the_privacy_protection_authority (ENG)
Notification or registration scheme and timing
Registration: Following the entry into force of Amendment 13, the database registration obligation has been significantly narrowed. Registration is currently required only for databases that: (i) contain personal data of more than 10,000 data subjects and whose primary purpose is the collection of personal data for provision to others as a business or for consideration, including direct mailing services; or (ii) are controlled by a public body, excluding databases containing personal data relating solely to the public body's employees.
Notification: Databases that are not subject to registration but contain personal data of special sensitivity relating to more than 100,000 data subjects must be notified to the PPA within 30 days from the date on which the number of data subjects whose sensitive personal data is processed in the database exceeds 100,000. This notification must be accompanied by a database definition document (the Israeli equivalent of a Record of Processing Activities (ROPA) under the GDPR).
In addition, any change to the database details must be notified to the PPA within 30 days, including changes to the identity of the database controller or the DPO, material changes requiring an update to the database definition document or the cessation of the database's operations.
Exemptions to notification
The registration and notification obligations do not apply to databases containing only information that has been published or made available to the public under lawful authority. Additionally, the Head of the PPA and the Minister of Justice have the authority to exempt specific entities or databases from these obligations.
What is the territorial scope of application?
The PPL does not contain an explicit provision regarding its extraterritorial application. Generally, it applies to data processing activities carried out in Israel or by Israeli entities.
However, based on emerging trends in case law and various PPA guidelines, Israeli data protection law may also apply to foreign entities located outside of Israel where they process personal data relating to data subjects in Israel on a large scale (the threshold for which may be influenced by the categories of the data subjects and the sensitivity of the data processed - the more sensitive the data, the lower the numerical threshold for the law's applicability, and vice versa), or where the entity directs its activities toward Israel.
Is there a concept of a controller and a processor?
Yes, the PPL recognizes concepts that are substantively similar to those under the GDPR.
A "database controller" (equivalent to a controller under the GDPR) is defined as "whoever determines, alone or together with another, the purposes of the processing of data in the database, or a body that, or an officeholder in which, has been authorized by enactment to process data in a database."
A "database processor" referred to under Israeli law as a "Holder" (and equivalent to a processor under the GDPR) is defined as "an external party to the database controller that processes data on its behalf."
Are both manual and electronic records subject to data protection legislation?
No. Israeli data protection legislation applies only to personal data processed by digital means. Manual records (non-digital) are protected under general privacy law (Chapter A to the PPL).
Are there any national derogations?
There are several national derogations, some of which are similar to those under European law, though their manner of application differs somewhat and they are at times more limited than those under European law.
The Protection of Privacy Law includes arrangements for the transfer of information between public bodies, and certain exemptions from some of its provisions in cases involving state security, the state's foreign relations, and various public publications of the legislative, executive, and judicial authorities.
What is personal data?
The PPL defines "personal data" as "data relating to an identified individual or an identifiable individual; for the purpose of this definition, an 'identifiable individual' is one who can be identified with reasonable effort, directly or indirectly, including by means of an identifier such as a name, identity number, biometric identifier, location data, online identifier, or one or more elements relating to that individual's physical, health, economic, social, or cultural condition."
Is information about legal entities personal data?
No. It is noted that older case law has recognized that corporations may enjoy a right to privacy in certain limited circumstances; however, the prevailing approach is that privacy rights do not extend to legal entities.
What are the rules for processing personal data?
The PPL applies to "databases", i.e. any digital personal data processed for a specific purpose (such as HR or customer relationship management).
As a general rule, processing personal data in a database requires a lawful basis. Israeli law recognizes two primary lawful bases for processing personal data: the informed consent of the data subject, or the existence of a statutory obligation.
Additionally, database controllers are subject to various obligations in connection with data processing, including processing data only for the purpose for which it was collected and only to the extent necessary ('purpose limitation'), data security, confidentiality and transparency.
Further obligations apply in respect of: (i) data subjects' rights of access and correction; (ii) specific obligations when using data for direct mailing purposes; (iii) accountability; (iv) administrative and corporate governance obligations (such as appointing a DPO); and (v) various obligations when engaging external parties.
Are there any formalities to obtain consent to process personal data?
Consent under Israeli law may be either explicit or implied, but it must be "informed" and "freely given".
A threshold requirement for obtaining consent is set out in Section 11 of the PPL, which sets out the details that must be communicated to the data subject, prior to data collection, in order to establish valid consent (please see further detail below).
According to the PPA's Opinion on "Consent in Data Protection Law" published February 2026 (“Consent Opinion”), compliance with Section 11 constitutes only a minimum requirement and does not in itself guarantee valid consent. The more sensitive the personal data being processed, or the further the processing departs from the original purpose for which the data was collected, the greater the disclosure obligation becomes, and in certain cases, consent must be explicit.
According to the PPA, in order to establish that consent is freely given, the use of manipulative design techniques and "dark patterns" that impede consent or improperly influence it must be avoided. Additionally, in situations characterized by inherent power imbalances (such as employment relationships or consumer dealings with monopolies and essential service providers), consent may be considered "suspect". To establish genuine choice in such cases, the database controller must ensure that reasonable alternatives are offered, or refrain from conditioning the provision of services on the collection of data that is not reasonably necessary.
Are there any special rules when processing personal data about children?
The PPL does not contain specific provisions regarding the processing of personal data about children, though several bills on this matter have been proposed over the years.
Currently, the processing of minors' personal data is governed by general law, which in certain cases requires the consent of a legal guardian for the processing of such data.
In addition, the Consent Opinion notes that special consideration must be given to specific populations, such as adolescents, regarding how information is made accessible, and that using children's personal data for purposes beyond the original scope of the service requires separate parental consent.
Are there any special rules when processing personal data about employees?
There are two key rules regarding the processing of employee data. The first derives from labor court case law, under which consent alone is insufficient, and compliance with the criteria of the Basic Law: Human Dignity and Liberty, for infringement of the right to privacy is required (a proper purpose and proportionality – a rational connection between the purpose and the means, the absence of a less harmful and equally effective alternative means, and a reasonable and balanced relationship between the benefit and the harm to privacy).
Additionally, under the PPL and the Data Security Regulations, there is a relief in the classification of the security level of databases designated for HR management, provided that they do not process biometric data of employees other than facial photographs, or certain categories of sensitive personal data, and that they are used solely for HR management purposes in the workplace.
What is sensitive personal data?
Personal data of special sensitivity is defined under the PPL as personal data concerning, relating to or subject to: (i) the intimacy of an individual's family life, intimate life, or sexual orientation; (ii) an individual's health; (iii) personal data constituting genetic information; (iv) biometric identifiers; (v) personal data concerning an individual's ethnic origin; (vi) an individual's criminal record; (vii) an individual's political opinions, religious beliefs, or worldview; (viii) a personality assessment conducted by a professional; (ix) personal data constituting location data and traffic data, as defined in the Criminal Procedure Law (Enforcement Powers - Communications Data), 5768-2007, generated by a licensed provider as defined therein regarding an individual, as well as data concerning an individual's location that is capable of revealing sensitive personal data; (x) an individual's salary and financial activity; or (xi) a statutory duty of confidentiality.
It also includes any other personal data designated by the Minister of Justice, provided that it is personal data held in a database located in Israel that was transferred from outside the country, and that in the country of origin, data of that type is subject to special legal provisions relative to those applicable to other personal data.
Finally, with respect to data transferred to Israel from the European Economic Area (subject to limited exceptions), the definition also includes data concerning trade union membership.
Are there additional rules for processing sensitive personal data?
Yes. Databases containing sensitive personal data are usually subject to enhanced data security obligations (please see the Security section below for further detail). Additionally, as noted above, in certain circumstances a notification obligation to the PPA is required.
Are there additional rules for processing information about criminal offences?
Personal data concerning an individual's criminal record is classified as sensitive personal data under the PPL.
Additionally, under the Criminal Information and Rehabilitation Law, 5779-2019, information from the criminal registry and the police registry ("criminal information") is confidential, and requesting such information, directly or indirectly, is strictly prohibited, including by way of an affidavit, declaration, or written questionnaire. The law designates specific bodies authorized to receive criminal information from the police, and prohibits any party not entitled to receive such information from taking it into account in its decision-making process.
Are there any formalities to obtain consent to process sensitive personal data?
As a general rule, the PPL does not prescribe specific requirements for obtaining consent to process sensitive personal data.
However, according to the PPA's position, where sensitive personal data is being processed, a heightened disclosure obligation applies. In such cases, it is recommended to obtain the individual's explicit consent rather than relying on implied consent, particularly when the processing
When must a data protection officer be appointed?
The obligation to appoint a DPO applies to four categories of entities: (1) public bodies and their database processors; (2) database controllers whose primary purpose is the collection of personal data for provision to others as a business or for consideration (including direct mailing services), and whose database contains personal data of more than 10,000 individuals; (3) database controllers or database processors whose core activities involve, or are linked to, data processing operations which, by virtue of their nature, scope, or purpose, require regular and systematic monitoring of individuals; and (4) database controllers or database processors whose core activity involves processing sensitive personal data on a large scale, including, among others, banking corporations, insurers, hospitals and health maintenance organisations.
The PPL clarifies that processing on a "large scale" is to be assessed with regard to, among other things, the number of data subjects about whom data is processed, their proportion within a given population, the volume and range of categories of data processed, the duration and frequency of the processing operations, the data retention period, and the geographical scope of the processing activities.
According to the PPA, this assessment must be made on a case-by-case basis. The scale of processing is a function of the data processed, and with respect to a database processor, is assessed cumulatively across all of its clients. Furthermore, the term "core activity" is interpreted such that data processing is either: (i) a central component in achieving the primary business or organizational objectives of the database controller or processor; or (ii) an inherent part of the organization's core operations (even if not essential to their fulfilment).
It is noted that the PPA also recommends that entities not subject to this statutory obligation voluntarily appoint a DPO.
What are the duties of a data protection officer?
The DPO shall act to ensure the organization's compliance with the PPL and to promote the protection of privacy and data security in the organization's databases. The DPO's duties include, among others: (i) serving as a professional authority and knowledge center, advising management and employees, and preparing and overseeing the implementation of a training program; (ii) preparing a program for ongoing monitoring of compliance with the PPL with respect to databases, ensuring its implementation by the organization, reporting findings to management, and proposing remedial measures; (iii) ensuring that a data security policy and a database definition document are in place and submitted for management approval; (iv) ensuring the handling of inquiries from individuals; the DPO's contact details must be published in an accessible and simple manner; and (v) serving as the organization's contact point for the PPA.
Is there a general accountability obligation?
Yes. However, this is not by virtue of an express statutory provision, but rather as a corollary of the statutory obligations imposed on database controllers and processors. The Data Security Regulations require the establishment and maintenance of a range of administrative and technological measures, as well as extensive documentation in connection with databases, thereby effectively creating an accountability framework.
These obligations include, among others, preparing a database definition document (applicable to database controllers only) and a database mapping document, establishing a data security procedure, conducting periodic audits, training employees, and maintaining reasonable documentation (or other evidence) of such activities.
Are privacy impact assessments mandatory?
Israeli law does not impose an express obligation to conduct a Privacy Impact Assessment (“PIA”).
However, the PPA recommends conducting PIAs and has published a comprehensive guide on the subject. According to the PPA, a PIA should be conducted prior to any use of personal data that may pose a significant risk to data subjects' privacy or a material change to their rights. This is particularly recommended when implementing new technologies, carrying out large-scale processing of personal data, or processing sensitive personal data, whether due to the nature of the data itself or the identity of the data subjects concerned (such as minors or patients in a medical facility).
Privacy notices
The PPL provides that any request made to an individual to provide personal data for processing in a database must be accompanied by a notice specifying: (i) whether there is a statutory obligation to provide the data, or whether providing it is voluntary and subject to the individual's consent, and the consequences of withholding consent; (ii) the purpose for which the data is requested; (iii) the name of the database controller and its contact details; (iv) to whom the data will be transferred and the purposes of such transfer; and (v) the existence of the right of access to personal data and the right to request correction of the personal data. It is common practice to fulfil this disclosure obligation by presenting a privacy policy to the individual prior to data collection.
Given that under Israeli law, consent is the primary (and often the only) lawful basis for processing personal data, in many cases (particularly where there are significant power imbalances between the parties or where the processing has the potential to seriously infringe on privacy), broader disclosure beyond that required under Section 11 is necessary in order to establish valid, informed consent.
With respect to data received by a database in Israel from the European Economic Area (subject to limited exceptions), an extended disclosure obligation applies (subject to certain exemptions), requiring that the data subject be notified within one month of receipt of the data and, in the case of a transfer to a third party, no later than the time of the actual transfer. Among other things, this notice must include, beyond the details listed above, explicit notification regarding the extended right to erasure conferred under the special regulations applicable to such data.
Rights to access information
Every individual is entitled to access the personal data held about them in a database, either personally, through an authorized representative, or through a guardian.
Upon a written request, the database controller is required to allow the individual to access their personal data within 30 days of receipt of the request. In the event of a refusal, the individual must be notified within 21 days of the request.
According to the PPA's guidelines, the right of access includes the right to receive the personal data in a digital file format that can be read, heard, or viewed (depending on the format in which the communication was originally saved) using software generally available to the public.
The right of access is subject to certain exceptions, such as privilege established under law, or where the disclosure of medical or psychological information may cause serious harm to the physical or mental health of the requesting individual, or endanger their life (in which case, the information must be provided to a physician or psychologist designated by the individual).
Rights to data portability
The PPL does not recognize a general right to data portability. However, the PPA's position (that personal data should be provided in a digital file format that can be read, heard, or viewed using software generally available to the public) may serve as a basis for the future development of a data portability right under Israeli law.
Nevertheless, an explicit right to data portability exists in certain sectors. For example, the Financial Information Service Law, 5782-2021 (commonly referred to as "Open Banking") establishes a mechanism substantively similar to data portability, enabling customers to share their financial information among service providers.
Right to be forgotten
The PPL does not recognize a right to be forgotten.
However, every individual is entitled to request that a database controller operating a database used for direct mailing services delete personal data relating to them from the database. Additionally, the law imposes on database controllers an obligation to review, on an annual basis, whether the database contains excess data no longer required for the database's purposes (data minimization obligation).
With respect to data held in a database that includes data transferred from the European Economic Area (subject to limited exceptions), the database controller is required to delete the data, upon the written request of the individual, where one of the following applies: (i) the data was created, received, accumulated, or collected in violation of any law, or its continued use is contrary to law; or (ii) the data is no longer necessary for the purposes for which it was created, received, accumulated, or collected, subject to the exceptions set out in the relevant regulations.
Objection to direct marketing and profiling
Every individual is entitled to demand, in writing, from a database controller operating a database used for direct mailing services, that personal data relating to them be deleted from the database and/or refrain from transferring such data to any person, category of persons, or specific individuals, for a limited or unlimited period. "Direct mailing" (the Israeli law equivalent of profiling) is a personal approach to an individual based on their membership in a population group determined according to one or more characteristics of persons whose names are included in a database.
The Israeli equivalent of direct marketing is the Anti-Spam Law, which allows any individual to refuse to receive marketing communications. See also below.
Other rights
An individual who has accessed their personal data and found it to be inaccurate, incomplete, unclear or outdated, may request the database controller to correct or delete the personal data. Where the database controller grants the request, it must notify any party who received the data from it during the three years preceding the correction or deletion, of such correction or deletion.
Security requirements in order to protect personal data
The PPL imposes an obligation to secure information contained in a database on the database controller and on anyone who processes information on its behalf (i.e. the Holder). The manner of implementing this obligation is set out in extensive detail in the Data Security Regulations (which apply directly to both the database controller and the Holder).
Entities subject to sectoral regulation (such as banks, insurance companies, payment service providers, and healthcare organizations) are also subject to additional obligations. The PPA has published guidelines addressing the interaction between the Data Security Regulations and many sectoral requirements.
The Data Security Regulations are structured modularly according to the security level of the database. Put simply, the more the database contains information of a particularly sensitive nature, the greater the obligations - databases are classified into three security levels (with most databases controlled by an individual subject to reduced obligations outside this classification), and as the level increases, so do the obligations. There is also a certain correlation between reporting obligations to the PPA (regarding the mere existence of the database, and regarding the scope of cases in which reporting of information security incidents is required) and the security level of the database.
Specific rules governing processing by third party agents (processors)
The Data Security Regulations prescribe detailed obligations for database controllers engaging with an external party for services involving access to the database. Prior to entering into such an engagement, the database controller is required to assess the security risks associated therewith.
Additionally, the database controller must incorporate in its agreement with the external party specific provisions prescribed by the Regulations, including: (i) the types of data the external party is permitted to process and the permitted purposes of use; (ii) the type of processing or actions the external party is permitted to perform; (iii) the manner of returning or destroying the data upon termination of the engagement; (iv) written confidentiality obligations, compliance with data security procedures and use of the data solely for the service provision, of the database processor's employees; (v) the external party's data security arrangements; (vi) provisions regarding the engagement of sub-processors; and (vii) obligations to report security incidents and on the implementation of its obligations under the Regulations.
Furthermore, the database controller must address this matter in the database's security policy, referencing the agreement with the external party and the external party's security policy, and must implement monitoring and oversight measures to verify the external party's compliance with the agreement and the Regulations.
Notice of breach laws
For databases classified under the high security level, there is an obligation to report to the PPA any incident involving the use of data from the database without authorization or in excess of authorization, or any compromise of data integrity - i.e., any security incident.
For databases classified under the medium security level, the database controller must report to the PPA any incident involving the use of a substantial part of the database without authorization or in excess of authorization, or any compromise of data integrity with respect to a substantial part of the database.
The reporting obligation is immediate, and the notification must include details of the steps taken in response to the incident, along with a requirement to submit supplementary reports as necessary.
The PPA (after consulting with the National Cyber Directorate) may instruct the database controller to notify any data subjects who may be harmed by the incident.
Additionally, entities subject to sector-specific regulation may be subject to additional reporting obligations in connection with security incidents. For example, insurance companies are required to report certain security incidents in certain cases to the Capital Market, Insurance and Savings Authority under various circumstances.
Restrictions on transfers to third countries
Under the Privacy Protection Regulations (Transfer of Data to Databases Outside the Borders of the State), 5761-2001 (the "Cross-Border Transfer Regulations"), the transfer of personal data (including granting access to such data) outside Israel is permitted only if two cumulative conditions are met.
First, the information must either be transferred to a country that ensures a level of protection that is not lower than the level of protection prescribed under Israeli law or one of the following conditions must be fulfilled.
Those conditions are: (i) the data subject has consented to the transfer; (ii) the consent is essential for protecting the health or bodily integrity of the data subject; (iii) the transfer is to a corporation controlled by the database controller, and protection of privacy after the transfer has been ensured; (iv) the transferee has undertaken, in an agreement with the database controller, to uphold the conditions for holding and using data that apply to a database in Israel, with the necessary changes; (v) the information has been published to the public or made available for public inspection under lawful authority; (vi) the transfer is essential for protecting public safety or public security; (vii) the transfer is required by law; (viii) the transfer is to a database in a country that is a party to the European Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data, or to a country that receives data from countries that are members of the European Community, subject to the same conditions of receipt applicable to those member states.
Second, a written undertaking is obtained from the recipient of the information that it employs sufficient means to ensure the privacy of the data subjects, and further, that it will obtain approval for any additional transfer of the information, including to sub-processors.
Where the transferee is a Holder (processing on behalf of the database controller), the provisions of the Data Security Regulations regarding engagement with an external party, as detailed above, also apply.
Notification and approval of national regulator (including notice of use of Model Contracts)
As a general rule, there is no obligation to obtain the PPA's approval for, or to notify the PPA of, cross-border data transfers (except where database registration or notification is required, as detailed above).
Use of binding corporate rules
Israeli law does not prescribe specific provisions regarding Binding Corporate Rules (BCRs) as a basis for transferring data outside Israel. However, a narrow framework in the Cross-Border Transfer Regulations is substantively equivalent to a BCR.
Accordingly, a transfer to a corporation controlled by the transferring database controller constitutes a lawful basis, provided that: (i) the recipient ensures the protection of privacy after the transfer; and (ii) the above-mentioned requirements regarding a written undertaking and onward transfer restrictions are met.
Fines
The PPL grants the Head of the PPA the power to impose administrative fines for violations of the PPL and the regulations promulgated thereunder, in amounts that can range from thousands to millions of NIS. The PPL establishes the authority to impose a fine for nearly any violation of a provision of the PPL and the regulations enacted pursuant to it (including, and primarily, violations of the provisions of the Data Security Regulations), such that the amount of the fines depends on various variable factors. Those factors will include the nature of the violation, the number of violations, the number of data subjects, the security level of the database, and more. For example, a violation involving a database classified at a higher security level, or a violation affecting a larger number of data subjects may well be subject to a significant fine.
Additionally, the PPL provides that where a database processor has violated a provision of the Data Security Regulations, the database controller must be notified and is required to act to bring the violation to an end. If the violation is not ceased and the database controller fails to carry out the PPA's demands to bring the violation to an end, the Head of the PPA may impose an administrative monetary penalty on the database controller in the amount that could have been imposed on the processor, as if the controller were the violator.
Imprisonment
Violations of the PPL may result in imprisonment of up to five years, depending on the type of the violation.
Compensation
The PPL allows a person whose privacy has been infringed to sue the infringer for damages without proof of damage (for an infringement of their privacy), in the amount of up to NIS 50,000 (~Euro 15,000), or up to NIS 100,000 (~Euro 30,000) in cases where the infringement was committed with intent to harm.
Additionally, the PPL allows a data subject, in respect of the violation of various provisions relating to data subjects’ rights concerning databases (such as failure to provide notice under Section 11, including failure to do so within 30 days of a request by a data subject on the matter, or failure to grant a right of access), to sue the infringer for statutory damages of up to NIS 10,000 (~Euro 3,000).
Other powers
Amendment 13 significantly expanded the PPA's supervisory and enforcement powers. In the event of a violation of the PPL, the PPA may initiate criminal or administrative enforcement proceedings, depending on the severity of the violation. Within the scope of its powers, the PPA may demand information, documents, and reports, conduct searches, order the cessation of a violation and the remediation of deficiencies, or issue an administrative warning to the violator. Failure to cease the violation may result in administrative monetary penalties.
Additionally, where appropriate, the PPA is authorized to initiate criminal proceedings or to apply to the court for an order to cease data processing or to delete personal data.
The PPA also has the authority to conduct sector-wide compliance audits to examine adherence to the PPL and its regulations.
Practice
Administrative Enforcement
Following the entry into force of Amendment 13, the PPA has begun to exercise its enforcement powers significantly more vigorously. Although it is still too early to establish a clear enforcement trend, given that the amendment came into effect only recently, an initial indication of its practical application can already be identified.
As a first practical example, the PPA recently imposed an administrative monetary penalty of NIS 256,000 (~Euro 75,000), after reductions in accordance with the provisions of the PPL, on a healthcare organization for failing to immediately report a security incident, as required under the Data Security Regulations.
By way of comparison, in May 2025, prior to the entry into force of Amendment 13 and the introduction of administrative monetary penalties for violations of the Data Security Regulations, a mere finding of non-compliance was issued in similar circumstances. In light of these developments, enforcement under the new framework is expected to intensify in the near future.
Civil enforcement
There is a prominent and growing trend of civil enforcement in Israel, primarily through the filing of class actions for privacy violations or breaches of the Anti-Spam Law.
Private litigation is expected to increase further in the near future in light of the expanded authority of the courts to award statutory damages without proof of damage.
ePrivacy laws
Certain matters regulated under the ePrivacy Directive are addressed through dedicated Israeli legislation, while others are governed by general privacy law.
The Israeli equivalent of direct marketing regulation is Section 30A of the Communications Law (Telecommunications and Broadcasting), 5742-1982 (the "Anti-Spam Law"), which regulates the sending of commercial communications via electronic messages, text messages, faxes, and automated dialing systems. The Israeli equivalent of profiling is "direct mailing" which is regulated under the PPL.
While there is no dedicated legislation governing cookies under Israeli law, general privacy law applies to the collection of personal data through cookies, as detailed below.
Conditions for use of cookies
Israeli law does not contain specific legislation regulating the use of cookies.
However, the PPL applies to the collection, use and transfer of personal data through cookies and similar tracking technologies, where they process or enable processing of personal information. In such cases, all provisions of the PPL apply to the use of cookies, including the requirement to obtain the data subject's informed consent and the disclosure and transparency obligations.
Regulatory guidance on the use of cookies
Apart from a specific reference in the context of guidelines on payment applications, no regulatory guidance exists specifically addressing cookies.
However, given that the use of cookies is assessed under general privacy law, under which consent is the primary lawful basis for processing personal data, the Consent Opinion is relevant in this context. It is further noted that in its 2021 guidelines on privacy in advanced payment methods for transferring funds and merchant payments, the PPA specifically addressed cookies and stated that the process of obtaining consent for non-essential cookies should be conducted separately, accompanied by an explanation of the consequences of such consent, and subject to active consent (opt-in).
Conditions for direct marketing by e-mail to individual subscribers
The Anti-Spam Law prohibits sending commercial communications by electronic messages (including e-mails), short messages (such as SMS), fax, or automated dialing systems, without the prior, express, and written consent of the recipient, subject to the exemptions detailed below. The recipient may withdraw their consent at any time.
Conditions for direct marketing by e-mail to corporate subscribers
The Anti-Spam Law does not distinguish between corporate and individual recipients. Accordingly, commercial communications may not be sent to corporate subscribers without prior, express, and written consent, subject to the exemptions detailed below.
Exemptions and other issues
Exemptions
The sending of commercial communications without consent is permitted through a "customer route" provided that: (i) the recipient's details were provided in the course of a purchase (or negotiations for a purchase) of a product or service; (ii) the advertiser informed the recipient that their details would be used for sending commercial communications; (iii) the recipient was given an opportunity to refuse; and (iv) the commercial communication relates to a product or service of a similar type.
Additionally, a one-time approach to a recipient that is a business, or to a recipient for the purpose of soliciting a donation or for propaganda purposes, constituting an offer to agree to receive commercial communications, shall not be considered an unsolicited approach.
Formal requirements
When sending commercial communications by e-mail, the following details must be prominently displayed: (i) the e-mail header must indicate that it is a commercial communication, a request for a donation, or propaganda; (ii) the name of the advertiser, its address, and contact details must be specified; and (iii) it must be made clear that the recipient may send a refusal notice at any time, and a feasible, simple, and reasonable method for sending such refusal notice must be provided, as well as a valid internet address of the advertiser for the purpose of delivering the refusal notice.
Refusal upon termination of an ongoing transaction
In an ongoing transaction for the purchase of a good or service, the customer shall be deemed to have requested to cease receiving commercial communications at the time the engagement is terminated (even if it was terminated as a result of a lawful cancellation notice).
Conditions for direct marketing by telephone to individual subscribers (excludes automated calls)
The Anti-Spam Law applies to marketing calls made through an automated dialing system, but does not apply to marketing calls made by a human representative.
Telephone marketing calls to individual consumers are regulated, among other things, under the Consumer Protection Law, 5741-1981 (the "Consumer Protection Law"), under which the "Do Not Call" registry was established, enabling consumers to register in order to limit marketing approaches.
A business may not make a marketing call to a consumer who has registered their number in this registry, except in the following cases: (i) a return call at the consumer's request; (ii) a business with an ongoing transaction with the consumer may approach them regarding that transaction only, including changes to its terms, but excluding an offer for a new transaction or an extension of the existing one, unless the consumer initiated such a request; (iii) express, separate written consent of the consumer to marketing approaches, provided that the consent was not obtained through a telephone call. Such consent is valid for one year and may be renewed with the consumer's agreement; (iv) a proactive approach by the consumer to the business and the giving of express consent to a marketing approach. Such consent is valid for one year, and the consumer may withdraw it at any time.
Additionally, marketing approaches by way of direct mailing are subject to the provisions of the PPL, as detailed above.
It is further noted that in certain circumstances, an excessive volume of marketing approaches to a consumer may constitute harassment and a violation of the PPL.
Conditions for direct marketing by telephone to corporate subscribers (excludes automated calls)
The Consumer Protection Law applies by definition to consumers, i.e., those who purchase a product or service primarily for personal, domestic, or family use, and therefore generally does not apply to business recipients. However, marketing approaches by way of direct mailing are subject to the provisions of the PPL, as detailed above.
Exemptions and other issues
There are no additional specific provisions beyond those stated above.