Translation Notice — This is an English translation of a Hebrew law and may contain inaccuracies. In any dispute or legal matter, the original Hebrew text as published in Reshumot (ספר החוקים) is the sole authoritative and legally binding version.
Protection of Privacy Law, 5741-1981
חוק הגנת הפרטיות
Chapter V: Miscellaneous
Application to the State
[Amendment: 1985]
This Law applies to the State.
Death of the Injured Party
[Amendment: 2024]
Application of Provisions
The provisions of Sections 21, 23, and 24 of the Prohibition of Defamation Law, 5725–1965, shall apply, mutatis mutandis, to legal proceedings in respect of a privacy violation.
Evidence of Bad Reputation, Character, or Past
In criminal or civil proceedings in respect of a privacy violation, no evidence may be adduced and no witness may be examined concerning the bad reputation of the injured party, or concerning his or her character, past, acts, or opinions.
Additional Orders
[Amendment: 1996, 2007]
Compensation Without Proof of Damage
[Amendment: 2007]
"index" — the Consumer Price Index published by the Central Bureau of Statistics;
"new index" — the index for the month preceding the month of update;
"base index" — the index for May 2007.
Liability for Publication in a Newspaper
[Amendment: 2017]
Liability of Printer and Distributor
[Amendment: 2017]
Where a privacy violation is published in print, other than in a newspaper with a frequency of publication of forty days or less, criminal and civil liability for the violation shall also attach to the owner of the printing house in which the publication was printed, and to any person who sells the publication or otherwise distributes it, provided that they shall not bear liability unless they knew or ought to have known that the publication contains a privacy violation.
[Amendment: 1996, 2024]
Tort
[Amendment: 1996]
An act or omission contrary to the provisions of Chapter B or Chapter D, or contrary to Regulations made under this Law, shall constitute a tort under the Torts Ordinance [New Version].
Inadmissible Evidence
Material obtained through a privacy violation shall be inadmissible as evidence in court without the consent of the injured party, unless the court has permitted, for reasons to be recorded, the use of such material, or unless the person who caused the violation, being a party to the proceedings, had a defence or exemption under this Law.
Preservation of Laws
The provisions of this Law shall not derogate from the provisions of any other law.
Implementation and Regulations
[Amendment: 1996, 2024]
The Minister of Justice is charged with the implementation of this Law and may make Regulations, with the approval of the Constitution Committee, on any matter relating to its implementation, including:
Fees
[Amendment: 1996, 2000, 2024]
Amendment of Schedules
[Amendment: 2024]
The Minister of Justice may, by Order, with the approval of the Constitution Committee, amend the Third Schedule, the Fourth Schedule, and the Fifth Schedule.
Commencement
Chapter B shall come into force six months from the day of publication of this Law.
Need to cite this law in a foreign court?
Eli Shimony Israeli Attorneys-at-Law provides certified Expert Legal Opinions on Israeli law within 24–48 hours, accepted by courts worldwide.
Contact Us →Section A
Section B
First Schedule (The Definition "the Authority", "the Privacy Protection Authority", in Section 3) Text
The functions of the Authority are, among others, the following:
To amend Government Decision No. 4660 of 19.1.2006 and to determine that:
Need to cite this law in a foreign court?
Eli Shimony Israeli Attorneys-at-Law provides certified Expert Legal Opinions on Israeli law within 24–48 hours, accepted by courts worldwide.
Contact Us →Second Schedule (Paragraph (12) of the Definition "Information of Special Sensitivity", in Section 3)
Information regarding membership in a labor organization as referred to in Regulation 7 of the Privacy Protection Regulations (Provisions Regarding Information Transferred to Israel from the European Economic Area), 5783–2023.
Need to cite this law in a foreign court?
Eli Shimony Israeli Attorneys-at-Law provides certified Expert Legal Opinions on Israeli law within 24–48 hours, accepted by courts worldwide.
Contact Us →Third Schedule (Section 23kf(h)): Financial Penalty for Violation
Definitions and Schedule of Financial Penalties
In this Schedule –
"External Party" – as defined in Regulation 15(a) of the Regulations;
"Individual" – a person and their relative, a person and their representative; for this purpose, "relative" means a spouse, brother, sister, parent, grandparent, descendant and descendant of a spouse, and the spouse of each of the foregoing, as well as a descendant of a brother or sister, and a brother or sister of a parent;
"Database Managed by an Individual" – a database in which the controlling owner is an individual, or a corporation owned by an individual, or a corporation owned by two individuals, and in which at most two additional authorized users are permitted to use it and are capable of using it, excluding the following types of databases:
"Database Subject to the Basic Security Level" – a database that is not a database managed by an individual, in which all of the following conditions are met:
"Database Subject to the Intermediate Security Level" – a database that is not a database managed by an individual and is not a database subject to the high security level, and in which one of the following applies:
"Database Subject to the High Security Level" – a database in which one of the following applies:
"Information Security Regulations" – the Privacy Protection Regulations (Information Security), 5777–2017.
| Violation | Individual-Managed DB (NIS) | Basic Security Level (NIS) | Intermediate Security Level (NIS) | High Security Level (NIS) |
|---|---|---|---|---|
| (1) Preparation of the Database Definition Document: A controlling owner of a database who failed to define in the database definition document all the matters specified in Regulation 2(a) of the Information Security Regulations, contrary to the provisions of that Regulation, including the various types of information contained in the database pursuant to sub-regulation (3), having regard to the list of types of information constituting information of special sensitivity under Section 3 of the Law | 2,000 | 2,000 | 40,000 | 160,000 |
| (2) Updating the Database Definition Document: A controlling owner of a database who failed to update the database definition document, contrary to the provisions of Regulation 2(b) of the Information Security Regulations | 2,000 | 2,000 | 40,000 | 160,000 |
| (3) Examination of Excess Information: A controlling owner of a database who failed to examine or document the examination of whether the information stored in the database exceeds what is required for the purposes of the database, contrary to the provisions of Regulation 2(c) or 19(b) of the Information Security Regulations | 2,000 | 2,000 | 40,000 | 160,000 |
| (4) Preparation of an Information Security Procedure: A controlling owner of a database or a holder of a database who failed to establish in a document an information security procedure in accordance with the database definition document and the Information Security Regulations (hereinafter – Security Procedure), contrary to the provisions of Regulation 4(a) of the Information Security Regulations or those provisions as applied under Regulation 19(a) of those Regulations, as applicable | – | 2,000 | 40,000 | 160,000 |
| (5) Security Procedure – Preparation, Retention and Establishment of Provisions: A controlling owner of a database or a holder of a database who failed to do any one of the following: (a) retained the Security Procedure such that its details would be disclosed to authorized users only to the extent required for the performance of their duties, contrary to the provisions of Regulation 4(b) of the Information Security Regulations or those provisions as applied under Regulation 19(a) of those Regulations, as applicable; (b) included in the Security Procedure the particulars enumerated in Regulation 4(c) of the Information Security Regulations; and, with respect to a database subject to the intermediate or high security level – included therein reference to the particulars enumerated in Regulation 4(d) of the Information Security Regulations or the provisions referred to in Regulation 9(b)(2) of the Information Security Regulations or those provisions as applied under Regulation 19(a) of those Regulations, as applicable; (c) established in the Security Procedure provisions with respect to dealing with information security incidents or with respect to reporting to the controlling owner of the database, contrary to the provisions of Regulation 11(b) of the Information Security Regulations or those provisions as applied under Regulation 19(a) of those Regulations, as applicable; (d) detailed in the Security Procedure the matters enumerated in Regulation 15(a)(2)(a) through (e) of the Information Security Regulations, contrary to the provisions of Regulation 15(a)(3) of those Regulations | – | 2,000 | 40,000 | 160,000 |
| (6) Database Structure and Systems: A controlling owner of a database or a holder of a database who failed to maintain an updated document of the database structure or an updated inventory list of the database systems, in accordance with the provisions of Regulation 5(a) of the Information Security Regulations or those provisions as applied under Regulation 19(a) of those Regulations, as applicable | – | 1,000 | 20,000 | 80,000 |
| (7) Disclosure of Database Structure Details and Inventory List: A controlling owner of a database or a holder of a database who failed to retain the updated document of the database structure or the inventory list in accordance with the access permissions established pursuant to the provisions of Regulation 5(b) of the Information Security Regulations or those provisions as applied under Regulation 19(a) of those Regulations, as applicable | – | 1,000 | 20,000 | 80,000 |
| (8) System Protection: A controlling owner of a database or a holder of a database who failed to ensure that the systems specified in Regulation 5(a)(1) of the Information Security Regulations are kept in a protected location that prevents unauthorized penetration and entry, in a manner consistent with the nature of the database's operations and the sensitivity of the information therein, in accordance with the provisions of Regulation 6(a) of the Information Security Regulations or those provisions as applied under Regulation 19(a) of those Regulations, as applicable | 1,000 | 1,000 | 20,000 | 80,000 |
| (9) Risk Survey: A controlling owner of a database or a holder of a database who failed to ensure that a survey to identify information security risks was conducted at least once every 18 months (hereinafter – Risk Survey), or who failed to discuss the results of the Risk Survey transmitted to them and failed to examine the need to update the database definition document or the Security Procedure in light thereof, or who failed to act to remedy the deficiencies identified in the Risk Survey, contrary to the provisions of Regulation 5(c) of the Information Security Regulations or those provisions as applied under Regulation 19(a) of those Regulations, as applicable | – | – | – | 320,000 |
| (10) Penetration Tests: A controlling owner of a database or a holder of a database who failed to ensure that penetration tests of the database systems were conducted at least once every 18 months, or who failed to discuss the results of the penetration tests, or who failed to act to remedy the deficiencies identified, contrary to the provisions of Regulation 5(d) of the Information Security Regulations or those provisions as applied under Regulation 19(a) of those Regulations, as applicable | – | – | – | 320,000 |
| (11) Control and Documentation of Site Entry: A controlling owner of a database or a holder of a database who failed to take measures for control and documentation in accordance with the provisions of Regulation 6(b) of the Information Security Regulations or those provisions as applied under Regulation 19(a) of those Regulations, as applicable | – | – | 20,000 | 80,000 |
| (12) Personnel Management: A controlling owner of a database or a holder of a database who granted access to information in the database or changed the scope of a permission granted, without taking any reasonable measure as referred to in Regulation 7(a) of the Information Security Regulations, contrary to the provisions of that Regulation or those provisions as applied under Regulation 19(a) of the Information Security Regulations, as applicable | – | 1,000 | 20,000 | 80,000 |
| (13) Personnel Training: A controlling owner of a database or a holder of a database who granted access to information in the database or changed the scope of a permission granted, without having previously conducted training sessions or without having provided authorized users with the required information, contrary to the provisions of Regulation 7(b) of the Information Security Regulations or those provisions as applied under Regulation 19(a) of those Regulations, as applicable | – | 1,000 | 20,000 | 80,000 |
| (14) Periodic Training: A controlling owner of a database or a holder of a database who failed to conduct periodic training activities for its authorized users, contrary to the provisions of Regulation 7(c) of the Information Security Regulations or those provisions as applied under Regulation 19(a) of those Regulations, as applicable | – | – | 20,000 | 80,000 |
| (15) Establishment and Management of Access Permissions: A controlling owner of a database or a holder of a database who failed to establish access permissions for authorized users to the database and to the database systems, contrary to the provisions of Regulation 8(a) of the Information Security Regulations or those provisions as applied under Regulation 19(a) of the Information Security Regulations, as applicable, or who failed to maintain an updated register of valid permissions, contrary to the provisions of Regulation 8(b) of the Information Security Regulations or those provisions as applied under Regulation 19(a) of those Regulations, as applicable (hereinafter – Valid Permissions List) | – | 2,000 | 40,000 | 160,000 |
| (16) Implementation of Access Permissions Procedure: A controlling owner of a database or a holder of a database who failed to take customary measures in the circumstances of the matter and in accordance with the nature and character of the database, in order to verify that access to the database and to the database systems is carried out solely by an authorized user who is authorized to do so under the Valid Permissions List, contrary to the provisions of Regulation 9(a) of the Information Security Regulations or those provisions as applied under Regulation 19(a) of those Regulations, as applicable | 2,000 | 2,000 | 40,000 | 160,000 |
| (17) Implementation of Access Permissions Procedure with Respect to an Authorized User Who Has Concluded Their Role: A controlling owner of a database or a holder of a database who failed to ensure the revocation of permissions of an authorized user who has concluded their role, contrary to the provisions of Regulation 9(c) of the Information Security Regulations or those provisions as applied under Regulation 19(a) of those Regulations, as applicable | – | 2,000 | 40,000 | 160,000 |
| (18) Control and Documentation Mechanism for Access: A controlling owner of a database or a holder of a database who failed to perform any one of the following: (a) ensured that a control mechanism was operated, contrary to the provisions of Regulation 10(a) and (b) of the Information Security Regulations (hereinafter – Control Mechanism) or those provisions as applied under Regulation 19(a) of those Regulations, as applicable; (b) established a routine inspection procedure for the documentation data of the Control Mechanism and compiled a report of the problems identified and the measures taken in response thereto, contrary to the provisions of Regulation 10(c) of the Information Security Regulations or those provisions as applied under Regulation 19(a) of those Regulations, as applicable; (c) ensured that the documentation data of the Control Mechanism is retained for at least 12 months, contrary to the provisions of Regulation 10(d) of the Information Security Regulations or those provisions as applied under Regulation 19(a) of those Regulations, as applicable; (d) informed the authorized users of the database of the existence of the Control Mechanism, contrary to the provisions of Regulation 10(e) of the Information Security Regulations or those provisions as applied under Regulation 19(a) of those Regulations, as applicable | – | – | 40,000 | 160,000 |
| (19) Documentation of an Information Security Incident: A controlling owner of a database or a holder of a database who failed to ensure documentation of every case in which an incident was discovered giving rise to concern of harm to the integrity of the information, unauthorized use thereof, or exceeding authorization (hereinafter – Information Security Incidents), contrary to the provisions of Regulation 11(a) of the Information Security Regulations or those provisions as applied under Regulation 19(a) of those Regulations, as applicable | 2,000 | 2,000 | 40,000 | 160,000 |
| (20) Periodic Discussion of Information Security Incidents: A controlling owner of a database or a holder of a database who failed to hold a discussion of information security incidents, or who failed to examine the need to update the Security Procedure and to document such discussion and examination, contrary to the provisions of Regulation 11(c) and Regulation 19(b) of the Information Security Regulations or those provisions as applied under Regulation 19(a) of those Regulations, as applicable | – | – | 40,000 | 160,000 |
| (21) Reporting to the Authority Regarding a Serious Security Incident: A controlling owner of a database or a holder of a database who failed to immediately notify the Head of the Authority of a serious security incident, or who failed to report to the Head of the Authority on the measures taken in the aftermath of the incident, contrary to the provisions of Regulation 11(d)(1) of the Information Security Regulations or those provisions as applied under Regulation 19(a) of those Regulations, as applicable | – | – | 80,000 | 320,000 |
| (22) Updating Database Systems: A controlling owner of a database or a holder of a database who failed to ensure that routine updates of the database systems, including the computer hardware required for their operation, were carried out, or that no use was made of systems whose manufacturer does not support their security aspects without any security response being provided, contrary to the provisions of Regulation 13(c) of the Information Security Regulations or those provisions as applied under Regulation 19(a) of those Regulations, as applicable | 2,000 | 2,000 | 40,000 | 160,000 |
| (23) Network Connection Security: A controlling owner of a database or a holder of a database who connected the database systems to the internet or to another public network, without installing any protective measures, contrary to the provisions of Regulation 14(a) of the Information Security Regulations or those provisions as applied under Regulation 19(a) of those Regulations, as applicable | 2,000 | 2,000 | 40,000 | 160,000 |
| (24) Control and Supervision of an External Party (Outsourcing): A controlling owner of a database who entered into an engagement with an External Party for the purpose of receiving a service, who failed to expressly stipulate in the agreement with the External Party the matters enumerated in Regulation 15(a)(2) of the Information Security Regulations, or who failed to take any measure of control and supervision over the External Party's compliance with the provisions established in said agreement with respect to the matters specified in sub-paragraphs (d) and (f) through (h) of that Regulation, contrary to Regulation 15(a)(4) of the Information Security Regulations | – | 4,000 | 80,000 | 320,000 |
| (25) Documentation: A controlling owner of a database or a holder of a database who failed to securely retain, for at least one year, the data accumulated in the course of implementing the provisions of Regulations 6(b), 8 through 11, 14, 15(a)(4) and 16 of the Information Security Regulations applicable to them, contrary to the provisions of Regulation 17(a) of the Information Security Regulations or those provisions as applied under Regulation 19(a) of the Information Security Regulations, as applicable | – | 1,000 | 20,000 | 80,000 |
| (26) Backup of Documentation Data: A controlling owner of a database or a holder of a database who failed to do any one of the following: (a) backed up the retained data in a manner that ensures that the data can be restored to its original state at any time, contrary to the provisions of Regulation 17(b) of the Information Security Regulations or those provisions as applied under Regulation 19(a) of those Regulations, as applicable; (b) established in a document the matters enumerated in Regulation 18(a)(1) and (3) of the Information Security Regulations and established procedures for ensuring data restoration, as referred to in Regulation 17(b) of those Regulations; (c) ensured that a backup copy of the data and the procedures referred to in Regulation 18(a) of the Information Security Regulations is retained in a manner that ensures the integrity of the information and the possibility of data restoration, contrary to the provisions of Regulation 18(b) of the Information Security Regulations or those provisions as applied under Regulation 19(a) of those Regulations, as applicable | – | – | 20,000 | 80,000 |
| (27) Violation of Documentation Obligations: A controlling owner of a database or a holder of a database who failed to document the manner of performance of an action that does not constitute the creation of a document, which they are obligated or responsible to perform under the Regulations, contrary to the provisions of Regulation 19(b) of those Regulations | – | 1,000 | 20,000 | 80,000 |
| (28) Separation of Database Systems (Compartmentalization): A controlling owner of a database or a holder of a database who failed to separate the database systems through which personal information can be accessed from other computing systems used by them, contrary to the provisions of Regulation 13(b) of the Information Security Regulations or those provisions as applied under Regulation 19(a) of those Regulations, as applicable | – | – | 20,000 | 80,000 |
| (29) Periodic Audit: A controlling owner of a database or a holder of a database who failed to ensure that an internal or external audit was conducted at least once every 24 months, contrary to the provisions of Regulation 16(a) of the Information Security Regulations or those provisions as applied under Regulation 19(a) of those Regulations, as applicable, or who failed to discuss the audit reports transmitted to them, or who failed to examine the need to update the database definition document or the Security Procedure in light thereof, contrary to the provisions of Regulation 16(c) of the Information Security Regulations or those provisions as applied under Regulation 19(a) of those Regulations, as applicable | – | – | 40,000 | 160,000 |
Need to cite this law in a foreign court?
Eli Shimony Israeli Attorneys-at-Law provides certified Expert Legal Opinions on Israeli law within 24–48 hours, accepted by courts worldwide.
Contact Us →Fourth Schedule (Section 23kf(i)): Monetary Penalty for Violation of
In this Schedule, "Regulations for the Transfer of Information from the European Economic Area" means the Privacy Protection Regulations (Provisions Regarding Information Transferred to Israel from the European Economic Area), 5783–2023.
Need to cite this law in a foreign court?
Eli Shimony Israeli Attorneys-at-Law provides certified Expert Legal Opinions on Israeli law within 24–48 hours, accepted by courts worldwide.
Contact Us →Fourth Schedule — Part A
| The Violation | The Amount of the Monetary Penalty |
|---|---|
| (1) A controller of a database who failed to notify the data subject in writing of the decision on a request pursuant to the provisions of the Privacy Protection Regulations (Provisions Regarding Information Transferred to Israel from the European Economic Area)#Section 3, in contravention of the provisions of the Privacy Protection Regulations (Provisions Regarding Information Transferred to Israel from the European Economic Area)#Section 3 | 15,000 New Shekels |
| (2) A controller of a database who failed to implement any organizational, technological, or other mechanism designed to ensure that the database does not retain information that is no longer necessary for the purpose for which it was collected or held, or for another purpose for which it is permitted to be held under any law (hereinafter – unnecessary information), in contravention of the provisions of the Privacy Protection Regulations (Provisions Regarding Information Transferred to Israel from the European Economic Area)#Section 4 | An amount of 2 New Shekels for each individual whose personal information is held in the database, and if the personal information in the database constituted information of special sensitivity – an amount of 4 New Shekels for each individual; if the amount of the administrative fine is less than 20,000 New Shekels, or, where the said information constitutes information of special sensitivity, less than 40,000 New Shekels, the Head of the Authority may impose upon a controller of a database or a holder of a database an administrative fine in the amount of 20,000 New Shekels or 40,000 New Shekels, as the case may be. |
| (3) A controller of a database who failed to implement any organizational, technological, or other mechanism designed to ensure that the information held in the database is accurate, complete, clear, and up to date, in contravention of the provisions of the Privacy Protection Regulations (Provisions Regarding Information Transferred to Israel from the European Economic Area)#Section 5 | An amount of 2 New Shekels for each individual whose personal information is held in the database, and if the personal information in the database constituted information of special sensitivity – an amount of 4 New Shekels for each individual; if the amount of the administrative fine is less than 20,000 New Shekels, or, where the said information constitutes information of special sensitivity, less than 40,000 New Shekels, the Head of the Authority may impose upon a controller of a database or a holder of a database an administrative fine in the amount of 20,000 New Shekels or 40,000 New Shekels, as the case may be. |
| (4) A controller of a database who found that the database holds information that is inaccurate, incomplete, unclear, or not up to date, and failed to take any measure to correct or delete such information, in contravention of the provisions of the Privacy Protection Regulations (Provisions Regarding Information Transferred to Israel from the European Economic Area)#Section 5 | An amount of 2 New Shekels for each individual whose personal information is held in the database, and if the personal information in the database constituted information of special sensitivity – an amount of 4 New Shekels for each individual; if the amount of the administrative fine is less than 20,000 New Shekels, or, where the said information constitutes information of special sensitivity, less than 40,000 New Shekels, the Head of the Authority may impose upon a controller of a database or a holder of a database an administrative fine in the amount of 20,000 New Shekels or 40,000 New Shekels, as the case may be. |
Need to cite this law in a foreign court?
Eli Shimony Israeli Attorneys-at-Law provides certified Expert Legal Opinions on Israeli law within 24–48 hours, accepted by courts worldwide.
Contact Us →Fourth Schedule — Part B
| The Violation | The Amount of the Financial Penalty |
|---|---|
| (1) A controller of a database who received a written request for the deletion of personal data as provided in the Privacy Protection Regulations (Provisions Regarding Information Transferred to Israel from the European Economic Area)#Section 3, and the exceptions set out in the Privacy Protection Regulations (Provisions Regarding Information Transferred to Israel from the European Economic Area)#Section 3 did not apply, and who did not delete the data or carry out measures ensuring that, by reasonable means, the data subject cannot be identified, contrary to the provisions of the Privacy Protection Regulations (Provisions Regarding Information Transferred to Israel from the European Economic Area)#Section 3, after having received notice from the Head of the Authority pursuant to the said provisions that his acts constitute a violation, and who did not cease the violation within the period directed by the Head of the Authority; | An amount of 4 New Shekels for each person whose personal data is held in the database, and if the personal data in the database constituted data of special sensitivity — an amount of 8 New Shekels for each person; if the said administrative fine is less than 200,000 New Shekels, the Head of the Authority may impose on a controller of a database or on a holder of a database an administrative fine of 200,000 New Shekels; for the purposes of items (1), (3) and (4) — the administrative fine shall be calculated according to the number of persons whose personal data the controller did not delete as required or to whom the controller did not provide notice as required under the Privacy Protection Regulations (Provisions Regarding Information Transferred to Israel from the European Economic Area)#Section 3, the Privacy Protection Regulations (Provisions Regarding Information Transferred to Israel from the European Economic Area)#Section 6, and the Privacy Protection Regulations (Provisions Regarding Information Transferred to Israel from the European Economic Area)#Section 6, as applicable. |
| (2) A controller of a database who found that the database holds personal data that is no longer necessary as provided in the Privacy Protection Regulations (Provisions Regarding Information Transferred to Israel from the European Economic Area)#Section 4, and who did not carry out measures ensuring that the data subject cannot be identified as aforesaid, and the circumstances prescribed therein did not apply, and who did not delete the said data at the earliest possible time under the circumstances, contrary to the provisions of the Privacy Protection Regulations (Provisions Regarding Information Transferred to Israel from the European Economic Area)#Section 4, after having received notice from the Head of the Authority pursuant to the said provisions that his acts constitute a violation, and who did not cease the violation within the period directed by the Head of the Authority; | An amount of 4 New Shekels for each person whose personal data is held in the database, and if the personal data in the database constituted data of special sensitivity — an amount of 8 New Shekels for each person; if the said administrative fine is less than 200,000 New Shekels, the Head of the Authority may impose on a controller of a database or on a holder of a database an administrative fine of 200,000 New Shekels; for the purposes of items (1), (3) and (4) — the administrative fine shall be calculated according to the number of persons whose personal data the controller did not delete as required or to whom the controller did not provide notice as required under the Privacy Protection Regulations (Provisions Regarding Information Transferred to Israel from the European Economic Area)#Section 3, the Privacy Protection Regulations (Provisions Regarding Information Transferred to Israel from the European Economic Area)#Section 6, and the Privacy Protection Regulations (Provisions Regarding Information Transferred to Israel from the European Economic Area)#Section 6, as applicable. |
| (3) A controller of a database who received personal data concerning an individual and did not provide that individual with notice as required under the Privacy Protection Regulations (Provisions Regarding Information Transferred to Israel from the European Economic Area)#Section 6, and none of the circumstances prescribed in the Privacy Protection Regulations (Provisions Regarding Information Transferred to Israel from the European Economic Area)#Section 6 applied, contrary to the Privacy Protection Regulations (Provisions Regarding Information Transferred to Israel from the European Economic Area)#Section 6, after having received notice from the Head of the Authority pursuant to the said provisions that his acts constitute a violation, and who did not cease the violation within the period directed by the Head of the Authority; | An amount of 4 New Shekels for each person whose personal data is held in the database, and if the personal data in the database constituted data of special sensitivity — an amount of 8 New Shekels for each person; if the said administrative fine is less than 200,000 New Shekels, the Head of the Authority may impose on a controller of a database or on a holder of a database an administrative fine of 200,000 New Shekels; for the purposes of items (1), (3) and (4) — the administrative fine shall be calculated according to the number of persons whose personal data the controller did not delete as required or to whom the controller did not provide notice as required under the Privacy Protection Regulations (Provisions Regarding Information Transferred to Israel from the European Economic Area)#Section 3, the Privacy Protection Regulations (Provisions Regarding Information Transferred to Israel from the European Economic Area)#Section 6, and the Privacy Protection Regulations (Provisions Regarding Information Transferred to Israel from the European Economic Area)#Section 6, as applicable. |
| (4) A controller of a database who sought to transfer personal data received by him to a third party and did not provide notice thereof to the data subject as required under the Privacy Protection Regulations (Provisions Regarding Information Transferred to Israel from the European Economic Area)#Section 6, and none of the circumstances prescribed in the Privacy Protection Regulations (Provisions Regarding Information Transferred to Israel from the European Economic Area)#Section 6 applied, contrary to the Privacy Protection Regulations (Provisions Regarding Information Transferred to Israel from the European Economic Area)#Section 6, after having received notice from the Head of the Authority pursuant to the said provisions that his acts constitute a violation, and who did not cease the violation within the period directed by the Head of the Authority. | An amount of 4 New Shekels for each person whose personal data is held in the database, and if the personal data in the database constituted data of special sensitivity — an amount of 8 New Shekels for each person; if the said administrative fine is less than 200,000 New Shekels, the Head of the Authority may impose on a controller of a database or on a holder of a database an administrative fine of 200,000 New Shekels; for the purposes of items (1), (3) and (4) — the administrative fine shall be calculated according to the number of persons whose personal data the controller did not delete as required or to whom the controller did not provide notice as required under the Privacy Protection Regulations (Provisions Regarding Information Transferred to Israel from the European Economic Area)#Section 3, the Privacy Protection Regulations (Provisions Regarding Information Transferred to Israel from the European Economic Area)#Section 6, and the Privacy Protection Regulations (Provisions Regarding Information Transferred to Israel from the European Economic Area)#Section 6, as applicable. |
Need to cite this law in a foreign court?
Eli Shimony Israeli Attorneys-at-Law provides certified Expert Legal Opinions on Israeli law within 24–48 hours, accepted by courts worldwide.
Contact Us →Fifth Schedule (Section 23la): Reduced Amounts for the Purpose of a Financial Sanction
Definitions
In this Schedule –
"Confirmation Regarding the Volume of Transaction Turnover" – as detailed below, as the case may be:
"Transaction Turnover" – the transaction turnover of a dealer as defined in the Value Added Tax Law, 5736–1975; with respect to a non-profit organization ("malkar") as defined in that Law – turnover as defined in the Second Schedule to the Associations Law, 5740–1980, and with respect to a public body that is not one of the foregoing – the annual budget of that public body;
"Micro Business" – a violator whose transaction turnover in the year preceding the date of the violation did not exceed 4 million New Shekels;
"Small Business" – a violator, excluding a micro business, whose transaction turnover in the year preceding the date of the violation exceeded 4 million New Shekels and did not exceed 10 million New Shekels.
Reduction Due to Conduct of the Violator
The Head of the Authority shall reduce the amount of the financial sanction imposed on a violator by the rates set out below, if one or more of the following circumstances exist:
Reduction Due to Payment or Other Compensation Paid
The Head of the Authority may reduce the amount of the financial sanction imposed on a violator on account of compensation paid or adjudged against the violator in respect of the same violations – by a rate not exceeding 30%.
Reduction Due to Personal Circumstances
If the Head of the Authority finds, with respect to a violator who is an individual, that the violation was caused by personal circumstances that justify a reduction of the financial sanction, or that difficult personal circumstances exist that justify refraining from imposing the full extent of the law on the violator, the Head of the Authority may reduce the amount of the financial sanction imposed on the violator by a rate of 20%.
Reduction Due to Multiple Circumstances
Where several circumstances as referred to in Sections 2, 3, and 4 exist with respect to a violator, the Head of the Authority may reduce from the amount of the financial sanction imposed on the violator the rates listed alongside those circumstances, cumulatively, provided that the cumulative rate of reduction shall not exceed 70% of the amount of the financial sanction.
Reduction for a Micro or Small Business
If the Head of the Authority finds, upon the request of the violator, that the violator is a micro business or a small business, as the case may be, the Head of the Authority shall reduce the amounts of the sanction to be imposed on the violator – whether or not they have been reduced pursuant to Section 2, 3, or 4 – such that the amount of the sanction in respect of violations under each of the paragraphs set out below shall not exceed the amount specified alongside them:
Where a violator who is a micro business or a small business commits a number of violations under paragraphs (1) through (3) – the violator shall not bear an amount exceeding the highest financial sanction among those paragraphs.
Reduction Due to Consideration of Transaction Turnover
Menachem Begin, Prime Minister
Moshe Nissim, Minister of Justice
Yitzhak Navon, President of the State
Need to cite this law in a foreign court?
Eli Shimony Israeli Attorneys-at-Law provides certified Expert Legal Opinions on Israeli law within 24–48 hours, accepted by courts worldwide.
Contact Us →