WorldPrivacyAtlas
Laws by country

Jurisdiction Guides / Middle East

Israel Privacy & Data Protection Laws

Every regime below can apply to a business handling Israel residents' data, depending on whether you have an established presence there, actively offer goods or services to residents, or monitor their behavior. This is a general reference, not a determination for your specific business — run the full questionnaire to see which of these actually apply to you.

Comprehensive Privacy Law · 1

1981 (Law); Amendment No. 13 entered into force August 14, 2025
Protection of Privacy Law, 5741-1981, as amended by Amendment No. 13
Israel PPL (Amendment 13)
Verify details

Amendment 13 is the most significant overhaul of Israeli privacy law since 1981 and took effect August 14, 2025. It modernizes the definitions — personal data now expressly covers online identifiers, IP addresses and geolocation, and a redefined 'especially sensitive data' category captures biometric, genetic, criminal-record, sexual-orientation and financial information — and rebuilds enforcement, giving the Privacy Protection Authority substantially expanded investigative powers and a turnover-scaled administrative fine regime in place of the previous largely criminal model. It also mandates Data Protection Officers for public bodies, data brokers, and controllers processing especially sensitive data at scale, and adds specific duties for data brokers. On reach: the PPA's position is that the Law extends to databases holding data about people in Israel even without a local establishment, and the Israeli database-registration regime has been narrowed but not eliminated. Israel holds an EU adequacy decision, which the Amendment was partly designed to preserve. The extraterritorial triggers below reflect regulator position rather than an express statutory Article-3 clause — confirm with Israeli counsel for a specific business.

Protection of Privacy Law, 5741-1981; Amendment No. 13 (2024); Protection of Privacy Regulations (Data Security), 5777-2017Read regulation →

Cross-Border Data Transfer · 1

2001 (Regulations); Amendment No. 13 in force August 14, 2025
Privacy Protection (Transfer of Data to Databases Abroad) Regulations, 5761-2001
Israel transfer regulations
Verify details

The duty comes from a dedicated 2001 regulation rather than from the Law. Reg. 2's baseline is that data may be transferred out of Israel only where the destination country's law ensures a level of protection at least equal to Israeli law — with a set of alternative grounds, the most used being reg. 2(4): the recipient is bound by agreement with the Israeli database owner to comply with the conditions governing the holding and use of data applicable to a database in Israel, with the necessary modifications. Reg. 3 adds a cumulative requirement often missed: the database owner must obtain the recipient's WRITTEN GUARANTEE that it is taking adequate measures to protect privacy and that it will not pass the data on to anyone else — so an onward-transfer prohibition is mandatory, not optional. Israel holds an EU adequacy decision, which Amendment 13 was partly designed to preserve. Marked 'check': the primary texts are Hebrew-language, the PPA has issued further guidance on these regulations, and the interaction with Amendment 13's expanded enforcement powers is still bedding in.

Privacy Protection (Transfer of Data to Databases Outside the Borders of the State) Regulations, 5761-2001, regs. 2-3; Protection of Privacy Law, 5741-1981, as amended by Amendment No. 13Read regulation →

Data Security & Breach Notification · 1

May 8, 2018 (Regulations); Amendment No. 13 in force August 14, 2025
Protection of Privacy Regulations (Data Security), 5777-2017 — severe security incident notification
Israel data security regs, reg. 11
Verify details

The duty comes from the 2017 Data Security Regulations rather than from the Law itself: the owner of a database at the high or medium security level must immediately notify the Privacy Protection Authority of a 'severe security incident' and follow up with a report on the steps taken. What counts as severe depends on the database's assigned security level — for a high-level database, any unauthorised use of data or harm to its integrity; for a medium-level database, the same but only as to a material part. Israel differs structurally from the GDPR on who tells the individual: the PPA may ORDER the database owner to notify affected data subjects, after consulting the head of the National Cyber Directorate, rather than the owner making that call itself. Amendment 13, in force August 14, 2025, substantially expanded the PPA's investigative and administrative-fine powers, raising the stakes on this duty. Marked 'check': the security-level classification that determines the trigger is fact-specific, and the primary texts are Hebrew-language.

Protection of Privacy Regulations (Data Security), 5777-2017, reg. 11; Protection of Privacy Law, 5741-1981, as amended by Amendment No. 13Read regulation →

Other Middle East jurisdictions