[codicts-css-switcher id=”346″]

Global Law Experts Logo
israel's privacy protection authority

Israel's Privacy Protection Authority and Amendment 13: How Enforcement of the Data Breach Reporting Duty Has Changed

By Global Law Experts
– posted 43 minutes ago

Israel’s Privacy Protection Authority now operates under a substantially strengthened enforcement regime that reframes how organisations operating in Israel must treat breach reporting. Amendment 13 to the Protection of Privacy Law entered into force on 14 August 2025, giving the Privacy Protection Authority (PPA) meaningful administrative sanctioning powers for the first time. Under this expanded regime, the duty to notify the regulator of a data security incident is best understood as a standalone substantive obligation rather than a procedural afterthought. This article explains what Amendment 13 changed, why it matters, and what compliance officers, in-house counsel, IT security teams, procurement functions and public bodies should do now.

TL;DR, key facts at a glance

  • Amendment 13 in force. 14 August 2025.
  • What changed. The PPA gained the power to impose administrative fines and expanded investigative powers.
  • Notification duty. Reporting a severe data security incident to the PPA is an enforceable obligation under the Data Security Regulations, 2017.
  • Health data. Medical information is among the most sensitive data categories and attracts heightened scrutiny.
  • Legal basis. The Protection of Privacy Law, 5741-1981 (as amended) together with the Protection of Privacy (Data Security) Regulations, 5777-2017.
  • Why it matters. Notification is now treated as an independently enforceable duty, backed by the PPA’s administrative fining powers.

Who this article is for: compliance officers, legal counsel, in-house counsel, IT security teams, procurement teams and public bodies operating in Israel. What you will get: a clear explanation of the PPA’s enforcement powers, the legal significance of Amendment 13, practical steps to update incident-response and breach-notification processes, and a checklist you can use to test your readiness.

The core issue: reporting a data security incident is a duty in its own right

Under Israeli law, an organisation that experiences a data security incident meeting the regulatory threshold must report it to the Privacy Protection Authority within the timeframe required by the Data Security Regulations, 2017. The critical point for compliance teams is the distinction between two separate failures: the underlying security failure that leads to an incident, and the separate failure to tell the regulator about that incident in time.

Timely notification is essential to allow the authority to assess risk to data subjects, coordinate mitigation, and protect the public interest, particularly where sensitive health data or a public body are involved. Late reporting undermines the entire purpose of the notification framework. An organisation cannot treat notification as a discretionary or secondary step to be handled once the technical clean-up is complete. The duty to report is a legal obligation in its own right, and non-compliance is directly sanctionable under the enforcement powers introduced by Amendment 13.

How Amendment 13 changed the PPA’s powers

To understand why breach-reporting compliance now carries real financial risk, it is necessary to understand what Amendment 13 did to the Protection of Privacy Law framework. Amendment 13 entered into force on 14 August 2025 and transformed the Privacy Protection Authority from a body focused largely on registration and oversight into an enforcement authority equipped with meaningful sanctioning tools.

From registry-based oversight to active enforcement

Before Amendment 13, the PPA’s enforcement model relied heavily on registration of databases, administrative supervision, and the threat of criminal or civil proceedings that were, in practice, slow and rarely triggered for procedural failures such as late notification. The amendment fundamentally changed this. It introduced administrative financial sanctions that the PPA can impose directly, expanded its investigative powers, and broadened its enforcement remit across the private and public sectors. Amendment 13 also revised aspects of the law’s terminology and structure, including changes to definitions and to the database registration regime.

The shift matters because administrative fines are faster, more flexible and more targeted than criminal prosecution. They allow the regulator to respond proportionately to specific compliance failures without the evidentiary and procedural burdens of a criminal case. In effect, Amendment 13 handed the PPA a tool that can be deployed routinely, including for notification failures.

Why the timing of Amendment 13 matters

Amendment 13 was legislated in 2024 with a transitional period before the enforcement powers activated on 14 August 2025. That transitional design signalled to the market that organisations were expected to bring their compliance posture into line before active enforcement began. With the enforcement powers now operational, boards and general counsel should read the current period as an active enforcement phase and prepare accordingly rather than assume continued regulatory forbearance.

The legal framework for breach notification in Israel

The notification duty is rooted in the Protection of Privacy (Data Security) Regulations, 5777-2017. These regulations sit beneath the Protection of Privacy Law and set out concrete obligations for organisations that control or process databases, including a tiered classification of databases by security level, definitions of what constitutes a data security incident, the circumstances that trigger a reporting obligation, and the mechanics for informing the regulator.

Notification triggers and timing

Under the Data Security Regulations, 2017, the obligation to notify is triggered by a security incident that meets the regulatory threshold, broadly, a “severe” event affecting personal data held in a covered database, as defined in the regulations. Where such an incident occurs, the organisation must report it to the PPA immediately, and the PPA may in turn direct the organisation to notify affected data subjects. The regulations impose prompt-reporting expectations, and delay in reporting is a distinct compliance failure.

Statutory versus regulatory obligations

It is worth distinguishing the layers of the framework. The Protection of Privacy Law provides the overarching statutory scheme and is where Amendment 13’s enforcement powers live. The Data Security Regulations, 2017 provide the operational detail, the classification tiers, the definitions, the triggers and the reporting mechanics. Enforcement draws on both: the substantive duty comes from the regulations, and the power to sanction breach of that duty comes from the statute as amended. Organisations that want to defend their compliance posture need to map both layers, because a gap in either creates exposure.

Health data adds a further dimension. Entities holding medical information are subject to the heightened sensitivity attached to that data category under the regulations, which places larger and more sensitive databases in the highest security tier. The combination of sensitive data and, where relevant, a public body increases the seriousness with which a failure to report is likely to be assessed.

Why the failure-to-notify duty is treated as substantive

The most important feature of the current regime is the characterisation of notification as a substantive duty. In many compliance cultures, late reporting is treated as a lesser, procedural lapse, an administrative box left unticked. That framing does not hold under Israeli law. The duty to notify serves a protective function that is independent of, and additional to, any duty to prevent the incident in the first place.

Factors that shape enforcement outcomes

Several considerations typically influence whether the regulator acts and how severely:

  • Nature of the data. The involvement of health data, which is among the most sensitive categories of personal information, raises the stakes.
  • Sector and status. A public body providing an essential public service heightens the public interest in transparency and timely regulatory oversight.
  • The purpose of notification. Delay deprives the regulator of the opportunity to assess risk to data subjects and to require or coordinate mitigation.
  • Deterrence. Enforcement decisions serve a signalling function, telling the wider market that notification failures will be sanctioned.

Enforcement blends disciplinary and remedial aims. It penalises a specific failure while establishing expectations that shape future behaviour across the sector. The practical message is straightforward: report on time, or expect consequences.

Comparison: Israel and the EU GDPR approach

For organisations that already operate under the EU General Data Protection Regulation, the Israeli approach will feel familiar in principle but distinct in its emphasis. The comparison below sets out the key differences.

Issue Israel PPA (post-Amendment 13) EU GDPR (for comparison)
Ground for sanction Failure to notify is a substantive duty and can be sanctioned in its own right under the enforcement powers introduced by Amendment 13. Failure to notify can be an independent breach under Articles 33 and 34; supervisory authorities may fine for it.
Typical timeline Notification obligation under the Data Security Regulations, 2017, with prompt/immediate-reporting expectations for severe incidents. Notification without undue delay and, where feasible, within 72 hours of becoming aware.
Enforcement approach Administrative fines now authorised under Amendment 13; clear focus on procedural and reporting compliance. Supervisory authorities enforce, though approaches vary by member state; fines cover both processing and procedural lapses.
Practical impact Heightened focus on incident-response processes and governance, especially for public bodies and the health sector. Similar practical impact; a mature, standalone enforcement culture around the notification duty.

The headline takeaway is that Israel has moved decisively toward the international mainstream on breach-notification enforcement. The GDPR’s 72-hour standard is not a direct import into Israeli law, but the underlying principle, that regulators expect prompt, proactive disclosure, is firmly embedded in the Israeli framework.

Practical consequences for organisations: contracts, procurement and incident-response plans

The strengthened regime has operational implications that reach well beyond the security team. Legal, procurement and governance functions all need to respond, because notification obligations are triggered across supply chains and depend on contractual clarity.

Vendor contracts and data-processing agreements

Most organisations do not hold all their data in-house. Processors, cloud providers and outsourced service partners frequently detect or cause incidents. If a vendor learns of a breach but does not tell you promptly, you cannot meet your own reporting deadline, yet the liability remains yours. Review every data-processing agreement to ensure it contains:

  • Rapid notification clauses. Require processors to notify you of any suspected or confirmed security incident within a short, defined window (for example, within a fixed number of hours of detection).
  • Cooperation obligations. Oblige the vendor to provide the information you need to assess and report the incident to the PPA.
  • Escalation and contact points. Name the individuals or roles responsible on both sides and keep those details current.
  • Audit and testing rights. Reserve the right to test the vendor’s incident-notification process.

A short sample clause might require that “the Processor shall notify the Controller without undue delay, and in any event within [X] hours, of becoming aware of any personal data security incident, and shall provide all information reasonably necessary to enable the Controller to comply with its notification obligations to the Privacy Protection Authority.” Any such clause should be adapted and reviewed by qualified counsel.

Insurance and governance

Cyber-insurance policies increasingly turn on prompt notification, both to the insurer and to regulators. A notification failure that leads to a regulatory sanction may also affect coverage. Review your policy wording to confirm that regulatory fines of this type are addressed and that your internal reporting timelines align with policy conditions. At board level, ensure that incident escalation reaches decision-makers quickly enough to allow a reporting decision within the regulatory window.

Public-sector compliance

Public bodies face particular exposure. They should ensure that internal governance does not slow notification, bureaucratic layers, sign-off chains and inter-departmental coordination can all consume the time that the regulator expects to be used for reporting. Building a streamlined, pre-authorised reporting pathway is essential.

Incident-response and breach-notification testing: what to test now

The single most effective response to the strengthened enforcement regime is to test your notification readiness before you need it. A plan that has never been exercised will fail under pressure, and a failure carries a direct financial cost. The following is a practical testing programme.

Tabletop exercises

Run a facilitated tabletop exercise built around a realistic scenario, for example, a ransomware event affecting a database of sensitive personal records. Walk the team through the timeline from detection to regulatory notification, forcing decisions at each stage. Key questions to test include: Who declares an incident? Who assesses whether the regulatory threshold is met? Who drafts and approves the notification to the PPA? Can all of this happen within the required window?

Notification drills and timelines

Beyond discussion, run a timed drill. Measure how long it actually takes from the moment an incident is detected to the moment a draft regulatory notification is ready. Compare that elapsed time against the reporting expectations under the Data Security Regulations, 2017. If the gap is uncomfortable, redesign the process.

Stakeholder mapping

Maintain a current list of everyone who must be involved:

  • Data protection or privacy lead. Owns the notification decision and regulatory interface.
  • Legal counsel. Assesses the reporting threshold and drafts the notification.
  • IT security. Provides technical facts and containment status.
  • Communications and PR. Manages messaging to affected individuals and the public.
  • Executive sponsor. Provides rapid sign-off so that governance does not delay reporting.
  • Regulator contact. The confirmed, current channel for notifying the PPA.

Documentation and record-keeping

Keep contemporaneous records of every incident and every decision, including incidents you conclude do not require notification. If the PPA later reviews your handling of an event, a clear, timestamped record of your reasoning is your best defence. Prepare a redacted incident-notification template in advance so that you are not drafting from scratch under pressure.

Key performance indicators

Track measurable indicators to demonstrate improvement over time: mean time from detection to declaration, mean time from declaration to regulatory notification, percentage of vendor contracts containing compliant notification clauses, and frequency of tabletop exercises. These KPIs give boards a concrete view of readiness. Organisations that can point to a tested, measured process will be in a far stronger position if scrutinised.

Sectoral considerations: health data and public bodies

Health-sector entities hold data of exceptional sensitivity, and public bodies carry a heightened accountability to the citizens they serve. Both features increase regulatory scrutiny and the likely severity of enforcement, and both are recognised in the way the Data Security Regulations tier databases by risk.

For health-sector organisations, incident response must account for medical confidentiality obligations alongside data-protection duties, and should incorporate any relevant Ministry of Health guidance on the handling and reporting of health-data incidents. Practically, this means dedicated escalation tracks, pre-approved notification templates tailored to health data, and clear coordination between clinical, IT and legal functions. Public bodies should also anticipate greater public and media interest, making a prepared communications track essential. The mitigation priority is speed without sacrificing accuracy: rapid escalation, early legal assessment and disciplined documentation.

How enforcement is likely to develop

The likely direction of travel is that the PPA will make active use of its administrative sanctioning powers, particularly where sensitive data or public bodies are involved and where reporting failures are identified. Organisations willing to engage cooperatively and remediate quickly may find the regulator more open to proportionate outcomes, while contested or repeated failures are likely to attract firmer sanctions.

For counsel and boards, the recommended monitoring steps are clear: track PPA publications for new decisions and guidance, benchmark internal reporting timelines against emerging enforcement patterns, and treat notification readiness as a standing board-level risk item rather than a one-time project. Israeli data-protection enforcement is now active, and reporting discipline is a core compliance priority.

Conclusion: immediate next steps for counsel and leadership

Under Amendment 13, breach notification is a substantive legal duty, and non-compliance is directly sanctionable. Organisations operating in Israel should act now rather than wait to be tested by an incident. The five immediate steps are:

  1. Update incident-response plans to make regulatory notification a distinct, time-bound obligation with clear ownership.
  2. Run a tabletop test of your notification process against the timelines in the Data Security Regulations, 2017.
  3. Review every data-processing agreement for rapid, enforceable notification clauses.
  4. Confirm your regulator contact channel and pre-approve a notification template.
  5. Brief the board on the enforcement reality and establish notification readiness as a monitored risk.

For tailored advice on incident-response planning, contract drafting and breach-notification compliance in Israel, consult a Commercial lawyer in Israel through Global Law Experts.

Need Legal Advice?

This article was produced by Global Law Experts. For specialist advice on this topic, contact Karin Horev at Karin Horev & CO. Law Office, a member of the Global Law Experts network.

Sources

  1. Israel Privacy Protection Authority (PPA)
  2. Israel Ministry of Health
  3. Israel Bar Association
  4. EU General Data Protection Regulation (Regulation (EU) 2016/679), EUR-Lex
  5. OECD, Privacy and data protection guidance

FAQs

What is Amendment 13 and when did it take effect?
Amendment 13 to the Protection of Privacy Law expanded the PPA’s enforcement powers to include administrative financial sanctions and enhanced investigative tools, and revised aspects of the law’s definitions and registration regime. Its enforcement provisions entered into force on 14 August 2025.
Yes. Following Amendment 13, the PPA may impose administrative sanctions for compliance failures, including failure to report a severe data security incident, treating notification as a standalone substantive duty rather than a mere procedural formality.
Because it means organisations can no longer treat reporting as a secondary step to be handled after technical remediation. The duty to notify carries its own legal weight and can be sanctioned independently of any underlying security failure.
The Data Security Regulations, 2017 set out the triggers and timing for notification, requiring immediate reporting of severe incidents to the PPA. Organisations should confirm the applicable requirements for their database’s security tier and report promptly.
The Protection of Privacy Law provides the overarching scheme and, as amended by Amendment 13, the enforcement powers. The Data Security Regulations, 2017 provide the operational detail, including database classification, incident definitions and reporting mechanics.
Public bodies and health-sector entities face heightened scrutiny because of the sensitivity of the data and the public interest involved. They should prioritise rapid escalation, tested notification processes and dedicated compliance and communications tracks.
The Israeli regime shares the GDPR principle that regulators expect prompt, proactive disclosure of breaches, and both treat failure to notify as capable of independent enforcement. The GDPR’s 72-hour standard is not a direct feature of Israeli law, which instead requires immediate reporting of severe incidents under the Data Security Regulations.
Update incident-response plans, run tabletop tests of the notification process, review all data-processing agreements for notification clauses, and confirm that regulatory reporting contacts and templates are current.
omans personal data
By Global Law Experts

posted 43 minutes ago

By A&M Consulting Co.

posted 49 minutes ago

By A&M Consulting Co.

posted 50 minutes ago

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

Israel's Privacy Protection Authority and Amendment 13: How Enforcement of the Data Breach Reporting Duty Has Changed

Send welcome message

Custom Message