Our Expert in Israel
No results available
Israel’s Privacy Protection Authority now operates under a substantially strengthened enforcement regime that reframes how organisations operating in Israel must treat breach reporting. Amendment 13 to the Protection of Privacy Law entered into force on 14 August 2025, giving the Privacy Protection Authority (PPA) meaningful administrative sanctioning powers for the first time. Under this expanded regime, the duty to notify the regulator of a data security incident is best understood as a standalone substantive obligation rather than a procedural afterthought. This article explains what Amendment 13 changed, why it matters, and what compliance officers, in-house counsel, IT security teams, procurement functions and public bodies should do now.
Who this article is for: compliance officers, legal counsel, in-house counsel, IT security teams, procurement teams and public bodies operating in Israel. What you will get: a clear explanation of the PPA’s enforcement powers, the legal significance of Amendment 13, practical steps to update incident-response and breach-notification processes, and a checklist you can use to test your readiness.
Under Israeli law, an organisation that experiences a data security incident meeting the regulatory threshold must report it to the Privacy Protection Authority within the timeframe required by the Data Security Regulations, 2017. The critical point for compliance teams is the distinction between two separate failures: the underlying security failure that leads to an incident, and the separate failure to tell the regulator about that incident in time.
Timely notification is essential to allow the authority to assess risk to data subjects, coordinate mitigation, and protect the public interest, particularly where sensitive health data or a public body are involved. Late reporting undermines the entire purpose of the notification framework. An organisation cannot treat notification as a discretionary or secondary step to be handled once the technical clean-up is complete. The duty to report is a legal obligation in its own right, and non-compliance is directly sanctionable under the enforcement powers introduced by Amendment 13.
To understand why breach-reporting compliance now carries real financial risk, it is necessary to understand what Amendment 13 did to the Protection of Privacy Law framework. Amendment 13 entered into force on 14 August 2025 and transformed the Privacy Protection Authority from a body focused largely on registration and oversight into an enforcement authority equipped with meaningful sanctioning tools.
Before Amendment 13, the PPA’s enforcement model relied heavily on registration of databases, administrative supervision, and the threat of criminal or civil proceedings that were, in practice, slow and rarely triggered for procedural failures such as late notification. The amendment fundamentally changed this. It introduced administrative financial sanctions that the PPA can impose directly, expanded its investigative powers, and broadened its enforcement remit across the private and public sectors. Amendment 13 also revised aspects of the law’s terminology and structure, including changes to definitions and to the database registration regime.
The shift matters because administrative fines are faster, more flexible and more targeted than criminal prosecution. They allow the regulator to respond proportionately to specific compliance failures without the evidentiary and procedural burdens of a criminal case. In effect, Amendment 13 handed the PPA a tool that can be deployed routinely, including for notification failures.
Amendment 13 was legislated in 2024 with a transitional period before the enforcement powers activated on 14 August 2025. That transitional design signalled to the market that organisations were expected to bring their compliance posture into line before active enforcement began. With the enforcement powers now operational, boards and general counsel should read the current period as an active enforcement phase and prepare accordingly rather than assume continued regulatory forbearance.
The notification duty is rooted in the Protection of Privacy (Data Security) Regulations, 5777-2017. These regulations sit beneath the Protection of Privacy Law and set out concrete obligations for organisations that control or process databases, including a tiered classification of databases by security level, definitions of what constitutes a data security incident, the circumstances that trigger a reporting obligation, and the mechanics for informing the regulator.
Under the Data Security Regulations, 2017, the obligation to notify is triggered by a security incident that meets the regulatory threshold, broadly, a “severe” event affecting personal data held in a covered database, as defined in the regulations. Where such an incident occurs, the organisation must report it to the PPA immediately, and the PPA may in turn direct the organisation to notify affected data subjects. The regulations impose prompt-reporting expectations, and delay in reporting is a distinct compliance failure.
It is worth distinguishing the layers of the framework. The Protection of Privacy Law provides the overarching statutory scheme and is where Amendment 13’s enforcement powers live. The Data Security Regulations, 2017 provide the operational detail, the classification tiers, the definitions, the triggers and the reporting mechanics. Enforcement draws on both: the substantive duty comes from the regulations, and the power to sanction breach of that duty comes from the statute as amended. Organisations that want to defend their compliance posture need to map both layers, because a gap in either creates exposure.
Health data adds a further dimension. Entities holding medical information are subject to the heightened sensitivity attached to that data category under the regulations, which places larger and more sensitive databases in the highest security tier. The combination of sensitive data and, where relevant, a public body increases the seriousness with which a failure to report is likely to be assessed.
The most important feature of the current regime is the characterisation of notification as a substantive duty. In many compliance cultures, late reporting is treated as a lesser, procedural lapse, an administrative box left unticked. That framing does not hold under Israeli law. The duty to notify serves a protective function that is independent of, and additional to, any duty to prevent the incident in the first place.
Several considerations typically influence whether the regulator acts and how severely:
Enforcement blends disciplinary and remedial aims. It penalises a specific failure while establishing expectations that shape future behaviour across the sector. The practical message is straightforward: report on time, or expect consequences.
For organisations that already operate under the EU General Data Protection Regulation, the Israeli approach will feel familiar in principle but distinct in its emphasis. The comparison below sets out the key differences.
| Issue | Israel PPA (post-Amendment 13) | EU GDPR (for comparison) |
|---|---|---|
| Ground for sanction | Failure to notify is a substantive duty and can be sanctioned in its own right under the enforcement powers introduced by Amendment 13. | Failure to notify can be an independent breach under Articles 33 and 34; supervisory authorities may fine for it. |
| Typical timeline | Notification obligation under the Data Security Regulations, 2017, with prompt/immediate-reporting expectations for severe incidents. | Notification without undue delay and, where feasible, within 72 hours of becoming aware. |
| Enforcement approach | Administrative fines now authorised under Amendment 13; clear focus on procedural and reporting compliance. | Supervisory authorities enforce, though approaches vary by member state; fines cover both processing and procedural lapses. |
| Practical impact | Heightened focus on incident-response processes and governance, especially for public bodies and the health sector. | Similar practical impact; a mature, standalone enforcement culture around the notification duty. |
The headline takeaway is that Israel has moved decisively toward the international mainstream on breach-notification enforcement. The GDPR’s 72-hour standard is not a direct import into Israeli law, but the underlying principle, that regulators expect prompt, proactive disclosure, is firmly embedded in the Israeli framework.
The strengthened regime has operational implications that reach well beyond the security team. Legal, procurement and governance functions all need to respond, because notification obligations are triggered across supply chains and depend on contractual clarity.
Most organisations do not hold all their data in-house. Processors, cloud providers and outsourced service partners frequently detect or cause incidents. If a vendor learns of a breach but does not tell you promptly, you cannot meet your own reporting deadline, yet the liability remains yours. Review every data-processing agreement to ensure it contains:
A short sample clause might require that “the Processor shall notify the Controller without undue delay, and in any event within [X] hours, of becoming aware of any personal data security incident, and shall provide all information reasonably necessary to enable the Controller to comply with its notification obligations to the Privacy Protection Authority.” Any such clause should be adapted and reviewed by qualified counsel.
Cyber-insurance policies increasingly turn on prompt notification, both to the insurer and to regulators. A notification failure that leads to a regulatory sanction may also affect coverage. Review your policy wording to confirm that regulatory fines of this type are addressed and that your internal reporting timelines align with policy conditions. At board level, ensure that incident escalation reaches decision-makers quickly enough to allow a reporting decision within the regulatory window.
Public bodies face particular exposure. They should ensure that internal governance does not slow notification, bureaucratic layers, sign-off chains and inter-departmental coordination can all consume the time that the regulator expects to be used for reporting. Building a streamlined, pre-authorised reporting pathway is essential.
The single most effective response to the strengthened enforcement regime is to test your notification readiness before you need it. A plan that has never been exercised will fail under pressure, and a failure carries a direct financial cost. The following is a practical testing programme.
Run a facilitated tabletop exercise built around a realistic scenario, for example, a ransomware event affecting a database of sensitive personal records. Walk the team through the timeline from detection to regulatory notification, forcing decisions at each stage. Key questions to test include: Who declares an incident? Who assesses whether the regulatory threshold is met? Who drafts and approves the notification to the PPA? Can all of this happen within the required window?
Beyond discussion, run a timed drill. Measure how long it actually takes from the moment an incident is detected to the moment a draft regulatory notification is ready. Compare that elapsed time against the reporting expectations under the Data Security Regulations, 2017. If the gap is uncomfortable, redesign the process.
Maintain a current list of everyone who must be involved:
Keep contemporaneous records of every incident and every decision, including incidents you conclude do not require notification. If the PPA later reviews your handling of an event, a clear, timestamped record of your reasoning is your best defence. Prepare a redacted incident-notification template in advance so that you are not drafting from scratch under pressure.
Track measurable indicators to demonstrate improvement over time: mean time from detection to declaration, mean time from declaration to regulatory notification, percentage of vendor contracts containing compliant notification clauses, and frequency of tabletop exercises. These KPIs give boards a concrete view of readiness. Organisations that can point to a tested, measured process will be in a far stronger position if scrutinised.
Health-sector entities hold data of exceptional sensitivity, and public bodies carry a heightened accountability to the citizens they serve. Both features increase regulatory scrutiny and the likely severity of enforcement, and both are recognised in the way the Data Security Regulations tier databases by risk.
For health-sector organisations, incident response must account for medical confidentiality obligations alongside data-protection duties, and should incorporate any relevant Ministry of Health guidance on the handling and reporting of health-data incidents. Practically, this means dedicated escalation tracks, pre-approved notification templates tailored to health data, and clear coordination between clinical, IT and legal functions. Public bodies should also anticipate greater public and media interest, making a prepared communications track essential. The mitigation priority is speed without sacrificing accuracy: rapid escalation, early legal assessment and disciplined documentation.
The likely direction of travel is that the PPA will make active use of its administrative sanctioning powers, particularly where sensitive data or public bodies are involved and where reporting failures are identified. Organisations willing to engage cooperatively and remediate quickly may find the regulator more open to proportionate outcomes, while contested or repeated failures are likely to attract firmer sanctions.
For counsel and boards, the recommended monitoring steps are clear: track PPA publications for new decisions and guidance, benchmark internal reporting timelines against emerging enforcement patterns, and treat notification readiness as a standing board-level risk item rather than a one-time project. Israeli data-protection enforcement is now active, and reporting discipline is a core compliance priority.
Under Amendment 13, breach notification is a substantive legal duty, and non-compliance is directly sanctionable. Organisations operating in Israel should act now rather than wait to be tested by an incident. The five immediate steps are:
For tailored advice on incident-response planning, contract drafting and breach-notification compliance in Israel, consult a Commercial lawyer in Israel through Global Law Experts.
This article was produced by Global Law Experts. For specialist advice on this topic, contact Karin Horev at Karin Horev & CO. Law Office, a member of the Global Law Experts network.
posted 13 minutes ago
posted 2 hours ago
posted 2 hours ago
posted 2 hours ago
posted 2 hours ago
posted 2 hours ago
posted 2 hours ago
posted 2 hours ago
posted 2 hours ago
posted 2 hours ago
posted 3 hours ago
posted 3 hours ago
No results available
Find the right Legal Expert for your business
Send welcome message