Data Security & Breach Notification
Protection of Privacy Regulations (Data Security), 5777-2017 — severe security incident notification
Israel · May 8, 2018 (Regulations); Amendment No. 13 in force August 14, 2025
Verify detailsThe duty comes from the 2017 Data Security Regulations rather than from the Law itself: the owner of a database at the high or medium security level must immediately notify the Privacy Protection Authority of a 'severe security incident' and follow up with a report on the steps taken. What counts as severe depends on the database's assigned security level — for a high-level database, any unauthorised use of data or harm to its integrity; for a medium-level database, the same but only as to a material part. Israel differs structurally from the GDPR on who tells the individual: the PPA may ORDER the database owner to notify affected data subjects, after consulting the head of the National Cyber Directorate, rather than the owner making that call itself. Amendment 13, in force August 14, 2025, substantially expanded the PPA's investigative and administrative-fine powers, raising the stakes on this duty. Marked 'check': the security-level classification that determines the trigger is fact-specific, and the primary texts are Hebrew-language.
This is a general reference, not legal advice or a determination that this law applies to your specific business. Run the full questionnaire to check against your actual presence, activities, and data types.