Israeli Legislation.com

Financial Information Service Law, 5782-2021

חוק שירות מידע פיננסי, תשפ"ב-2021

Published: 2021-11-18Consolidated Hebrew text as of 2026-07-27 · Last amended 2026-07-26✓ Amendment status checked against the Knesset legislation record on 2026-09-29
Premium
Unofficial English translation — for reference only. It may contain errors or omissions and cannot be relied on as a legal text. Only the Hebrew text published in Reshumot is legally binding.More

This English text was translated from the official Hebrew using a range of translation tools, and it undergoes ongoing checks and updates. It is not a certified translation.

Despite these checks, it may contain errors, omissions, or imprecise renderings of legal terminology and cross-references, and it may not yet reflect the latest amendments. It cannot be relied upon as a legal text.

The Hebrew text as published in Reshumot (ספר החוקים) and on the Knesset website is the sole authoritative and legally binding version. In any discrepancy, the Hebrew text prevails.

This translation is provided for informational purposes only and does not constitute legal advice. For use in legal proceedings, request a certified Expert Legal Opinion.

First Schedule (the definition "regulator's instructions" in section 1)

Second Schedule (the definition "financial information interface system" in section 1)

1.§

Direct communication between an information source and a service provider by means of Application Programming Interface technology, in a secure transport layer.

2.§

Identification of the service provider before the information source is required upon each request by the service provider to the information source for the purpose of accessing financial information held by it, and is effected by means of a digitally signed certificate issued by the service provider regulator for the purpose of obtaining such access.

3.§

The components of the system enable the granting of an access authorisation by a customer, the revocation of the access authorisation, and the ongoing provision of access to financial information concerning the customer to a service provider pursuant to the access authorisation.

Need to cite this law in a foreign court?

Eli Shimony Israeli Attorneys-at-Law provides certified Expert Legal Opinions on Israeli law within 24–48 hours, accepted by courts worldwide.

Contact Us →

Third Schedule (the definition "information baskets" in section 1)

Part 1

Information baskets in respect of an information source that is a bank or an auxiliary corporation

1.§

Information concerning a payment account, as defined in the Payment Services Law, in new shekels, including details of account balances and details of all debits and credits to the account.

2.§

Information concerning a payment account, as defined in the Payment Services Law, in foreign currency, including details of account balances and details of all debits and credits to the account.

3.§

Information concerning a debit card, as defined in section 11b of the Banking (Licensing) Law, including details of debits and credits effected by means of the card and the fees for use of the card.

4.§

Information concerning credit, including details of the credit balance, the interest and fees agreed in respect of the credit, the dates of repayment thereof, and the existence of charges (security interests) given against the credit.

5.§

Information concerning savings, including the amounts of savings, the interest, linkage and fees agreed in respect of the savings, the dates of entitlement to release of the savings funds, and the date of termination of the savings.

6.§

Information concerning securities, including the types of securities, activity in securities, and fees paid in respect of the securities portfolio; for this purpose, "security" – as defined in section 52 of the Securities Law, including financial assets as defined in the Investment Advice Law, excluding study funds.

s3i3a.§

Information concerning the clearing of transactions by debit card, as defined in section 11b(a) of the Banking (Licensing) Law, including details of the balances, debits and credits of the customer and the fees for the clearing service.

Part 2

Information baskets in respect of an information source that is a holder of a stability payment services provider licence

1.§

Each of the information baskets listed in items 1 to 4 of Part 1.

Part 3

Information baskets in respect of an information source that is a holder of a licence to provide deposit and credit services

1.§

Each of the information baskets listed in items 1 to 6 of Part 1.

Part 4

Information baskets in respect of an information source that is an institutional body, a holder of a credit-granting licence and a holder of a licence to operate a credit intermediation system

1.§

The information basket listed in item 4 of Part 1.

Part 5

Information baskets in respect of an information source that is a payment company

1.§

Each of the information baskets listed in items 1 to 4 of Part 1.

Need to cite this law in a foreign court?

Eli Shimony Israeli Attorneys-at-Law provides certified Expert Legal Opinions on Israeli law within 24–48 hours, accepted by courts worldwide.

Contact Us →

Fourth Schedule (the definition "similar product or service" in section 25(d)(1)(b))

1.§

Savings and investment products – any financial product that may serve for short-term or medium-term investment, including interest-bearing deposits, provident funds for investment, study funds, securities as defined in section 52 of the Securities Law, mutual funds, index products, and savings plans of all types.

Need to cite this law in a foreign court?

Eli Shimony Israeli Attorneys-at-Law provides certified Expert Legal Opinions on Israeli law within 24–48 hours, accepted by courts worldwide.

Contact Us →

Fifth Schedule (section 46)

1.§

An information source may charge a service provider consideration for granting access to financial information as referred to in section 46, commencing from the fifth request of that service provider to the information source on the same day and by virtue of all access authorisations granted by the customer to that service provider; for this purpose –

(a)all requests submitted by the service provider to the information source by means of the financial information interface system, by virtue of all access authorisations granted by the customer to that service provider, within a period of 10 minutes, shall be deemed a single request;
(b)a request by the service provider to the information source submitted while the customer is directly connected online to the service provider for the purpose of receiving a service from the service provider that involves access to information for which the request is made, shall not be counted among the requests for the purposes of this section.

Need to cite this law in a foreign court?

Eli Shimony Israeli Attorneys-at-Law provides certified Expert Legal Opinions on Israeli law within 24–48 hours, accepted by courts worldwide.

Contact Us →

Sixth Schedule (the definition "base amount" in section 49)

1.§

In relation to a licence holder – NIS 25,000;

2.§

In relation to a bank, an auxiliary corporation or a holder of a stability payment services provider licence – NIS 100,000;

3.§

In relation to an insurer – NIS 100,000;

4.§

In relation to a managing company – an amount as set out below, in accordance with the scope of the assets of the provident funds, as defined in the Provident Funds Supervision Law, under its management:

(a)if the scope of the assets of the provident funds under its management does not exceed ten billion New Israeli Shekels – NIS 50,000;
(b)if the scope of the assets of the provident funds under its management exceeds ten billion New Israeli Shekels – NIS 100,000;
5.§

In relation to a holder of a licence to provide deposit and credit services, a holder of a credit-granting licence or a holder of a licence to operate a credit intermediation system – NIS 50,000;

6.§

In relation to a credit bureau and a business information bureau – NIS 50,000;

7.§

In relation to a holder of a portfolio manager licence – an amount as set out below, in accordance with the holder's total asset value, as defined in the First Schedule A to the Investment Advice Law:

(a)if the holder's total asset value does not exceed one billion New Israeli Shekels – NIS 50,000;
(b)if the holder's total asset value exceeds one billion New Israeli Shekels – NIS 100,000;
8.§

In relation to a holder of a control permit – NIS 6,000.

9.§

In relation to a payment company – an amount as set out below, in accordance with the average monthly scope of payment transactions carried out by the company on behalf of its customers in the 12 months preceding the date of commission of the breach, and in relation to a payment company that received a payment services licence during that period, the amount shall be calculated on the basis of the average monthly scope in the months since the licence was received (in this item – average monthly scope):

(a)if the average monthly scope did not exceed NIS 10 million – NIS 50,000;
(b)if the average monthly scope exceeded NIS 10 million – NIS 100,000.

Need to cite this law in a foreign court?

Eli Shimony Israeli Attorneys-at-Law provides certified Expert Legal Opinions on Israeli law within 24–48 hours, accepted by courts worldwide.

Contact Us →

Seventh Schedule: Part 1 (section 50(b))

1.§

Failed to report to the Authority on the occurrence of a circumstance from among the circumstances listed in section 27(c)(1) to (6) of the Investment Advice Law, in relation to itself or in relation to a senior office holder therein, contrary to the provisions of section 20(a).

2.§

Failed to enable a customer to cancel the agreement with it or to reduce the agreement, at any time, contrary to the provisions of section 28(a), or failed to enable the customer to cancel or reduce such an agreement by means of the delivery of notice online, contrary to the provisions of section 28(b).

3.§

Failed to disclose to the customer the particulars prescribed in section 33(1) to (4), contrary to the provisions of that section.

4.§

Failed to comply with the requirements in relation to insurance, minimum equity capital or other security, as prescribed by the Authority in regulator's instructions, contrary to the provisions of section 36(a).

5.§

Breached instructions prescribed by the service provider's regulator pursuant to section 37.

Part 2

1.§

Failed to keep in confidence information about the customer, including documents transferred to its possession and their contents, or any other detail relating to transactions carried out in the framework of the provision of the service to the customer, contrary to the provisions of section 23.

2.§

Received a benefit, directly or indirectly, in connection with the provision of a service, contrary to the provisions of section 24.

3.§

Collected financial information, received such information or used it otherwise than for the purpose of providing a service to the customer concerning the customer's economic conduct, on the basis of that information, or without the customer having given express consent thereto in the agreement with it, contrary to the provisions pursuant to section 25(a), (b) or (d)(3).

4.§

Collected financial information, received such information or used it, for the purpose of making a proposal on its behalf to enter into an engagement with the customer, in relation to a financial product or financial service in respect of which the matter referred to in section 25(d)(1) applies, contrary to the provisions of that section.

5.§

Used financial information that it collected or received from another for statistical purposes without obtaining the express consent of the customer thereto, contrary to the provisions of section 25(d)(2).

6.§

Entered into an engagement with the customer without a written agreement for the provision of a financial information service, or failed to enable the customer, within the framework of such an agreement, to select the matters listed in paragraphs (1) to (3) of section 26(a), contrary to the provisions of that section, or failed to draw up the agreement in accordance with regulator's instructions pursuant to section 26(d).

7.§

Failed to take the measures necessary to ensure that the customer is aware that the access option remains in force in accordance with the customer's consent, contrary to regulator's instructions issued pursuant to section 26(b).

8.§

Held financial information about the customer for a period exceeding three years, or a shorter period if prescribed pursuant to section 27(a), without the customer's express written consent, or held such information for a period exceeding seven years, or a shorter period if prescribed pursuant to that section, all contrary to the provisions of that section.

9.§

Retained financial information required by the service provider for the purpose of legal proceedings or for the purpose of an internal audit or supervision procedure under law, otherwise than in accordance with the provisions of section 27(c)(1) or the instructions prescribed by the service provider's regulator pursuant to that section; used such information for purposes other than those listed in section 27(c)(2); or failed to ensure that access to the information would be as provided in section 27(c)(3).

10.§

Failed to delete financial information about a customer upon the expiry of seven years from the date of termination of the provision of the service, contrary to the provisions of section 27(c)(4).

11.§

Failed to notify the information source of the cancellation or reduction of the agreement within two days, contrary to the provisions of section 28(c)(2).

12.§

Failed to delete the financial information that is no longer required, following the customer's notice, for the purpose of providing the service to the customer, contrary to the provisions of section 28(c)(3).

13.§

Transferred financial information of a customer to a person who is not one of the parties listed in section 29(a) or prescribed pursuant to subsection (f)(2)(b) or (c) of that section, or transferred financial information of a customer to such a party, contrary to the conditions and regulator's instructions of the service provider's regulator pursuant to section 29(a) and (f)(2)(b), (c) or (g).

14.§

Transferred financial information to a party listed in section 29(a) without notifying that party, in the framework of the engagement with it, that the information was received from the information source by means of the financial information interface system, contrary to the provisions of section 29(b).

15.§

Failed to notify the service provider's regulator, the information source, the Registrar as defined in section 31(a), or another service provider from whom the information was received, immediately upon the occurrence of a serious security incident, all contrary to the provisions of that section.

16.§

Carried out an action involving a conflict of interests as referred to in Regulations made pursuant to section 32(b)(1), contrary to the provisions of section 32(a), where it has been prescribed in such Regulations that a financial sanction may be imposed in respect of carrying out such action.

17.§

Provided a cost-comparison or intermediation service in connection with a financial product or financial service as referred to in sub-paragraphs (a) or (b) of section 32(b)(2), contrary to the provisions of that section.

18.§

Did anything liable to mislead a customer in a material matter in a transaction for the provision of a financial information service, contrary to the provisions of section 34.

19.§

Failed to maintain adequate and advanced mechanisms for information security, risk management and cyber protection, contrary to regulator's instructions prescribed by the service provider's regulator pursuant to section 35(b).

20.§

Failed to submit to the Authority a report or notice in accordance with instructions prescribed by the Authority, contrary to the provisions of section 36(b), or failed to provide the Authority with an explanation, particulars, information or documents in connection with the details contained in such a report or notice in accordance with a demand by the Authority or an employee of the Authority authorised to that effect, contrary to the provisions of section 36(c).

21.§

Accessed financial information about a customer held by an information source for the purpose of providing the customer with a service relating to the customer's financial conduct, where the access was made in the course of a business, by means of an online system and using the customer's access credentials to the customer's account that are intended to verify the customer's identity before the information source, contrary to the provisions of section 60.

22.§

Failed to correct a defect in information for which it is responsible, contrary to the provisions of section 61(c).

23.§

Violated an instruction prescribed by the Authority pursuant to section 63(b).

Need to cite this law in a foreign court?

Eli Shimony Israeli Attorneys-at-Law provides certified Expert Legal Opinions on Israeli law within 24–48 hours, accepted by courts worldwide.

Contact Us →

Eighth Schedule: Part 1 (section 50(c))

1.§

Failed to report a serious security incident to the information source's regulator after receiving notice thereof, contrary to the provisions of section 31(a).

2.§

Made access to financial information about a customer held by it, by means of the financial information interface system, conditional upon the existence of an agreement between it and the service provider, contrary to the provisions of section 39(b).

3.§

Failed to enable the customer to grant an access authorisation, or failed to enable the customer to include in the access authorisation the particulars listed in paragraphs (1) to (3) of section 40(a), contrary to the provisions of that section.

4.§

Did not notify the service provider, as soon as possible, that it had not granted access to financial information, did not notify the information source regulator thereof, did not document the denial of access and the reasons therefor, or did not retain the documentation, all in contravention of the provisions of section 41(a)(2) or otherwise than in accordance with the regulator's instructions prescribed in these matters pursuant to section 41(a)(4).

5.§

Granted a service provider access to financial information by means of the financial information interface system, without the service provider having identified itself to it as a service provider in accordance with the instructions prescribed by the information source regulator, in contravention of the provisions of section 42.

6.§

Did not notify all joint account holders of an access authorisation granted by one of them and of their right to revoke the authorisation, in contravention of the provisions of section 43(b).

7.§

Did not notify joint account holders, jointly and severally, at the time of signing the engagement agreement with them, that an access authorisation under this Law granted by each of them would be regarded as an access authorisation granted by all account holders, in contravention of the provisions of section 43(d).

8.§

Did not enable an account holder in a corporation's account to authorise, at any time, a signatory, or did not offer that account holder, at the time of opening the account, to authorise a signatory, all in contravention of the provisions of section 44(a).

9.§

Presented to a customer a position or warning regarding the granting of access to financial information to the service provider or regarding the quality of the service provided by the service provider, as referred to in section 47(b), or performed an act regarded as the exercise of undue influence on a customer as referred to in Regulations made pursuant to section 47(c), if those Regulations provide that a monetary sanction may be imposed in respect of its performance, all in contravention of the provisions of section 47(a).

10.§

Violated instructions prescribed by the information source regulator, in regulator's instructions, pursuant to section 48.

Part 2

1.§

Did not grant a service provider access to financial information concerning a customer that is held by it, by means of the financial information interface system, even though an access authorisation was granted by the customer, or granted a service provider such access otherwise than in accordance with the access authorisation granted by the customer, all in contravention of the provisions of section 39(a).

2.§

Enabled a service provider access to financial information relating to a joint account without the access authorisation having been granted by all joint account holders, in contravention of the provisions of section 43(a).

3.§

Did not enable a person listed in section 45(a)(1) to (3) to revoke, at any time, the access authorisation granted by that person, in contravention of the provisions of that subsection, or did not enable that person to revoke the access authorisation by means of delivering a notice online, in contravention of the provisions of section 45(b).

4.§

Collected consideration from an account holder for the granting or revocation of an access authorisation or for granting access to the service provider in accordance with the access authorisation, in contravention of the provisions of section 46(a).

5.§

Collected consideration from a service provider for granting access to financial information held by it otherwise than in accordance with the provisions of the Fifth Schedule, or collected from the service provider a payment for the granting or revocation of an access authorisation, in contravention of the provisions of section 46(b).

Need to cite this law in a foreign court?

Eli Shimony Israeli Attorneys-at-Law provides certified Expert Legal Opinions on Israeli law within 24–48 hours, accepted by courts worldwide.

Contact Us →

Page 7 of 8

Read the entire law on one page — continuous text, no page breaks, plus PDF downloads.