Israeli LegislationEnglish Edition

Translation Notice — This is an English translation of a Hebrew law and may contain inaccuracies. In any dispute or legal matter, the original Hebrew text as published in Reshumot (ספר החוקים) is the sole authoritative and legally binding version.

Law

Protection of Privacy Law, 5741-1981

חוק הגנת הפרטיות

Chapter V: Miscellaneous

Application to the State

24.

[Amendment: 1985]

This Law applies to the State.

Death of the Injured Party

25.
(a)Where a person whose privacy was violated dies within six months after the violation without having filed a civil action or complaint in respect of that violation, his or her spouse, child, or parent — and if no spouse, children, or parents survive — his or her brother or sister, may file, within six months after the person's death, a civil action or complaint in respect of that violation.
(b)Where a person who filed a civil action or complaint in respect of a privacy violation dies before the conclusion of the proceedings, his or her spouse, child, or parent — and if no spouse, children, or parents survive — his or her brother or sister, may notify the court, within six months after the person's death, of their wish to continue the action or complaint, and upon giving such notice they shall step into the place of the plaintiff or complainant.
26.

[Amendment: 2024]

Application of Provisions

27.

The provisions of Sections 21, 23, and 24 of the Prohibition of Defamation Law, 5725–1965, shall apply, mutatis mutandis, to legal proceedings in respect of a privacy violation.

Evidence of Bad Reputation, Character, or Past

28.

In criminal or civil proceedings in respect of a privacy violation, no evidence may be adduced and no witness may be examined concerning the bad reputation of the injured party, or concerning his or her character, past, acts, or opinions.

Additional Orders

29.

[Amendment: 1996, 2007]

(a)In addition to any other punishment or remedy, the court may, in criminal or civil proceedings in respect of a violation of any provision of this Law, order as set out below, as the case may be:
(1)A prohibition on the distribution of copies of the injurious material or its forfeiture; a forfeiture order under this paragraph shall be effective against any person in whose possession such material is found for the purpose of sale, distribution, or storage, even if that person was not a party to the proceedings; where the court orders forfeiture, it shall direct what is to be done with the forfeited copies;
(2)Publication of the judgment, in whole or in part; the publication shall be at the expense of the accused or the defendant, in the place, to the extent, and in the manner determined by the court;
(3)Delivery of the injurious material to the injured party;
(4)Destruction of information obtained unlawfully, or a prohibition on the use of such information or of surplus information as defined in Section 23e, or any other direction with respect to such information.
(b)Nothing in the provisions of this Section shall prevent the holding of a copy of a publication in public libraries, archives, and the like, unless the court has imposed, by a forfeiture order under subsection (a)(1), a restriction also on such holding; and nothing therein shall prevent the holding of a copy of a publication by a private individual.

Compensation Without Proof of Damage

29a.

[Amendment: 2007]

(a)Where a person has been convicted of an offence under Section 5, the court may order that person to pay the injured party compensation not exceeding 50,000 New Shekels, without proof of damage; an obligation to pay compensation under this subsection shall have the force of a judgment of that court given in civil proceedings brought by the person entitled against the person obligated.
(b)(1) In proceedings in respect of a civil wrong under Section 4, the court may order the defendant to pay the injured party compensation not exceeding 50,000 New Shekels, without proof of damage.
(2)In proceedings as referred to in paragraph (1) in which it has been proved that the privacy violation was committed with intent to cause harm, the court may order the defendant to pay the injured party compensation not exceeding double the amount referred to in that paragraph, without proof of damage.
(c)A person shall not receive compensation without proof of damage under this Section in respect of the same privacy violation more than once.
(d)The amounts referred to in this Section shall be updated on the 16th of each month in accordance with the rate of change in the new index relative to the base index; for this purpose —

"index" — the Consumer Price Index published by the Central Bureau of Statistics;

"new index" — the index for the month preceding the month of update;

"base index" — the index for May 2007.

Liability for Publication in a Newspaper

30.

[Amendment: 2017]

(a)Where a privacy violation is published in a newspaper, criminal and civil liability for the violation shall attach to the person who brought the matter to the newspaper and thereby caused its publication, to the editor of the newspaper, and to the person who actually decided on the publication of that violation in the newspaper; civil liability shall also attach to the publisher of the newspaper.
(b)In a criminal charge under this Section, it shall be a good defence for the editor of the newspaper that the editor took reasonable measures to prevent the publication of that violation and was unaware of its publication.
(c)In this Section, "editor of a newspaper" — includes an acting editor.

Liability of Printer and Distributor

31.

[Amendment: 2017]

Where a privacy violation is published in print, other than in a newspaper with a frequency of publication of forty days or less, criminal and civil liability for the violation shall also attach to the owner of the printing house in which the publication was printed, and to any person who sells the publication or otherwise distributes it, provided that they shall not bear liability unless they knew or ought to have known that the publication contains a privacy violation.

31a.

[Amendment: 1996, 2024]

Tort

31b.

[Amendment: 1996]

An act or omission contrary to the provisions of Chapter B or Chapter D, or contrary to Regulations made under this Law, shall constitute a tort under the Torts Ordinance [New Version].

Inadmissible Evidence

32.

Material obtained through a privacy violation shall be inadmissible as evidence in court without the consent of the injured party, unless the court has permitted, for reasons to be recorded, the use of such material, or unless the person who caused the violation, being a party to the proceedings, had a defence or exemption under this Law.

Preservation of Laws

35.

The provisions of this Law shall not derogate from the provisions of any other law.

Implementation and Regulations

36.

[Amendment: 1996, 2024]

The Minister of Justice is charged with the implementation of this Law and may make Regulations, with the approval of the Constitution Committee, on any matter relating to its implementation, including:

(1)Conditions for the holding and safekeeping of information in databases;
(2)Conditions for the transfer of information to databases outside the borders of the State or from such databases;
(3)Rules of conduct and ethics for owners or holders of databases and their employees;
(4)Provisions regarding the destruction of information upon the cessation of operations of a database.

Fees

36a.

[Amendment: 1996, 2000, 2024]

(a)The Minister of Justice, with the approval of the Constitution Committee, may prescribe fees for access to databases under this Law.

Amendment of Schedules

36b.

[Amendment: 2024]

The Minister of Justice may, by Order, with the approval of the Constitution Committee, amend the Third Schedule, the Fourth Schedule, and the Fifth Schedule.

Commencement

37.

Chapter B shall come into force six months from the day of publication of this Law.

Need to cite this law in a foreign court?

Eli Shimony Israeli Attorneys-at-Law provides certified Expert Legal Opinions on Israeli law within 24–48 hours, accepted by courts worldwide.

Contact Us →

Section A

Section B

First Schedule (The Definition "the Authority", "the Privacy Protection Authority", in Section 3) Text

1.
(a)The Privacy Protection Authority (hereinafter: the Authority) is a unit within the Ministry of Justice headed by the Head of the Authority.
(b)The Authority shall be independent in the exercise of the powers vested in the Head of the Authority for the purpose of fulfilling its functions through the Authority's employees and in accordance with the provisions of any law, and the operational budget of the Authority shall be managed separately within the budget of the Ministry of Justice. Out of respect for the Authority's independence, the Authority shall operate independently when exercising the powers vested in the Head of the Authority.
1.
(a)The Privacy Protection Authority (hereinafter: the Authority) is a unit within the Ministry of Justice headed by the Head of the Authority.
(b)The Authority shall be independent in the exercise of the powers vested in the Head of the Authority for the purpose of fulfilling its functions through the Authority's employees and in accordance with the provisions of any law, and the operational budget of the Authority shall be managed separately within the budget of the Ministry of Justice. Out of respect for the Authority's independence, the Authority shall operate independently when exercising the powers vested in the Head of the Authority.
2.

The functions of the Authority are, among others, the following:

(a)To supervise compliance with the provisions of the Privacy Protection Law, 5741–1981, and the Regulations thereunder with respect to databases.
(b)To investigate suspicions of the commission of offenses under the Privacy Protection Law, 5741–1981, with respect to databases, in accordance with its powers under the law.
(c)To raise public awareness of the right to privacy in databases, of the value of privacy protection, and of its importance in the information age, through education, guidance, and public outreach.
(d)To handle substantive public inquiries concerning harm to data subjects under the Privacy Protection Law, 5741–1981.
(e)To develop and implement professional programs and training in its areas of activity.
(f)To promote and maintain relations with counterpart bodies worldwide and within the framework of international forums in which counterpart bodies participate.
(g)To exercise the powers of the Registrar of Certifying Entities under the Electronic Signature Law, 5761–2001.
3.
(a)In continuation of Government Decisions No. 4660 of 19.1.2006 and No. 3543 of 11.2.2018, to determine that the eligibility requirements for appointment as Head of the Authority shall be as follows:
(1)A person who meets the eligibility requirements for appointment as a judge of the District Court;
(2)A person shall not be appointed as Head of the Authority if they have been convicted of a criminal offense or a disciplinary offense which, by reason of its nature, severity, or circumstances, renders them unfit to serve as Head of the Authority, or if an indictment or complaint has been filed against them for such an offense and a final judgment has not yet been rendered in their matter.
(b)It is hereby clarified that, in accordance with Government Decision No. 4470 of 8.2.2009, the Head of the Authority shall be appointed for a single term of six years.
4.

To amend Government Decision No. 4660 of 19.1.2006 and to determine that:

(a)The Government shall appoint the Head of the Authority by notice in the Official Gazette as Registrar for the purposes of Section 7 of the Privacy Protection Law, 5741–1981.
(b)The Minister of Justice shall appoint the Head of the Authority as Registrar for the purposes of Section 9 of the Electronic Signature Law, 5761–2001.

Need to cite this law in a foreign court?

Eli Shimony Israeli Attorneys-at-Law provides certified Expert Legal Opinions on Israeli law within 24–48 hours, accepted by courts worldwide.

Contact Us →

Second Schedule (Paragraph (12) of the Definition "Information of Special Sensitivity", in Section 3)

(1).

Information regarding membership in a labor organization as referred to in Regulation 7 of the Privacy Protection Regulations (Provisions Regarding Information Transferred to Israel from the European Economic Area), 5783–2023.

Need to cite this law in a foreign court?

Eli Shimony Israeli Attorneys-at-Law provides certified Expert Legal Opinions on Israeli law within 24–48 hours, accepted by courts worldwide.

Contact Us →

Third Schedule (Section 23kf(h)): Financial Penalty for Violation

Definitions and Schedule of Financial Penalties

1.

In this Schedule –

"External Party" – as defined in Regulation 15(a) of the Regulations;

"Individual" – a person and their relative, a person and their representative; for this purpose, "relative" means a spouse, brother, sister, parent, grandparent, descendant and descendant of a spouse, and the spouse of each of the foregoing, as well as a descendant of a brother or sister, and a brother or sister of a parent;

"Database Managed by an Individual" – a database in which the controlling owner is an individual, or a corporation owned by an individual, or a corporation owned by two individuals, and in which at most two additional authorized users are permitted to use it and are capable of using it, excluding the following types of databases:

(1)a database whose primary purpose is the collection of personal information for the purpose of transferring it to another in the course of business or for consideration, including direct mailing services;
(2)a database containing personal information on 10,000 persons or more;
(3)a database that includes personal information with respect to which the database owner is subject to a duty of professional confidentiality under law or under principles of professional ethics;

"Database Subject to the Basic Security Level" – a database that is not a database managed by an individual, in which all of the following conditions are met:

(1)its primary purpose is not the collection of personal information for the purpose of transferring it to another in the course of business or for consideration, including direct mailing services;
(2)the controlling owner of the database is not a public body as defined in Section 23;
(3)if the database contains information of special sensitivity, at least one of the following also applies:
(a)the number of authorized users of the database held by the controlling owner does not exceed ten;
(b)the database includes information of special sensitivity only with respect to employees of the controlling owner or its suppliers, it serves solely for the business management purposes of the controlling owner of the database, and it is of the following types only:
(1)information pursuant to paragraphs (2), (6) and (8) through (10) of the definition of "information of special sensitivity";
(2)personal information concerning the sexual orientation of the employee or their spouse, arising from information provided by the employee;
(3)personal information concerning the employee's religious beliefs;
(4)personal information that is a biometric identifier as referred to in paragraph (4) of the definition of "information of special sensitivity" consisting solely of a facial photograph;

"Database Subject to the Intermediate Security Level" – a database that is not a database managed by an individual and is not a database subject to the high security level, and in which one of the following applies:

(1)its primary purpose is the collection of information for the purpose of transferring it to another in the course of business or for consideration, including direct mailing services;
(2)its controlling owner is a public body as defined in Section 23 of the Law;
(3)the database contains information of special sensitivity, except for information of special sensitivity excluded under paragraph (3)(b) of the definition of "Database Subject to the Basic Security Level";

"Database Subject to the High Security Level" – a database in which one of the following applies:

(1)a database as referred to in item (1) of the definition of "Database Subject to the Intermediate Security Level", or a database containing information of special sensitivity in which the number of authorized users held by its controlling owner exceeds 100, or that contains personal information on 100,000 persons or more;
(2)a database containing biometric identifiers of 100,000 persons or more;

"Information Security Regulations" – the Privacy Protection Regulations (Information Security), 5777–2017.

ViolationIndividual-Managed DB (NIS)Basic Security Level (NIS)Intermediate Security Level (NIS)High Security Level (NIS)
(1) Preparation of the Database Definition Document: A controlling owner of a database who failed to define in the database definition document all the matters specified in Regulation 2(a) of the Information Security Regulations, contrary to the provisions of that Regulation, including the various types of information contained in the database pursuant to sub-regulation (3), having regard to the list of types of information constituting information of special sensitivity under Section 3 of the Law2,0002,00040,000160,000
(2) Updating the Database Definition Document: A controlling owner of a database who failed to update the database definition document, contrary to the provisions of Regulation 2(b) of the Information Security Regulations2,0002,00040,000160,000
(3) Examination of Excess Information: A controlling owner of a database who failed to examine or document the examination of whether the information stored in the database exceeds what is required for the purposes of the database, contrary to the provisions of Regulation 2(c) or 19(b) of the Information Security Regulations2,0002,00040,000160,000
(4) Preparation of an Information Security Procedure: A controlling owner of a database or a holder of a database who failed to establish in a document an information security procedure in accordance with the database definition document and the Information Security Regulations (hereinafter – Security Procedure), contrary to the provisions of Regulation 4(a) of the Information Security Regulations or those provisions as applied under Regulation 19(a) of those Regulations, as applicable2,00040,000160,000
(5) Security Procedure – Preparation, Retention and Establishment of Provisions: A controlling owner of a database or a holder of a database who failed to do any one of the following: (a) retained the Security Procedure such that its details would be disclosed to authorized users only to the extent required for the performance of their duties, contrary to the provisions of Regulation 4(b) of the Information Security Regulations or those provisions as applied under Regulation 19(a) of those Regulations, as applicable; (b) included in the Security Procedure the particulars enumerated in Regulation 4(c) of the Information Security Regulations; and, with respect to a database subject to the intermediate or high security level – included therein reference to the particulars enumerated in Regulation 4(d) of the Information Security Regulations or the provisions referred to in Regulation 9(b)(2) of the Information Security Regulations or those provisions as applied under Regulation 19(a) of those Regulations, as applicable; (c) established in the Security Procedure provisions with respect to dealing with information security incidents or with respect to reporting to the controlling owner of the database, contrary to the provisions of Regulation 11(b) of the Information Security Regulations or those provisions as applied under Regulation 19(a) of those Regulations, as applicable; (d) detailed in the Security Procedure the matters enumerated in Regulation 15(a)(2)(a) through (e) of the Information Security Regulations, contrary to the provisions of Regulation 15(a)(3) of those Regulations2,00040,000160,000
(6) Database Structure and Systems: A controlling owner of a database or a holder of a database who failed to maintain an updated document of the database structure or an updated inventory list of the database systems, in accordance with the provisions of Regulation 5(a) of the Information Security Regulations or those provisions as applied under Regulation 19(a) of those Regulations, as applicable1,00020,00080,000
(7) Disclosure of Database Structure Details and Inventory List: A controlling owner of a database or a holder of a database who failed to retain the updated document of the database structure or the inventory list in accordance with the access permissions established pursuant to the provisions of Regulation 5(b) of the Information Security Regulations or those provisions as applied under Regulation 19(a) of those Regulations, as applicable1,00020,00080,000
(8) System Protection: A controlling owner of a database or a holder of a database who failed to ensure that the systems specified in Regulation 5(a)(1) of the Information Security Regulations are kept in a protected location that prevents unauthorized penetration and entry, in a manner consistent with the nature of the database's operations and the sensitivity of the information therein, in accordance with the provisions of Regulation 6(a) of the Information Security Regulations or those provisions as applied under Regulation 19(a) of those Regulations, as applicable1,0001,00020,00080,000
(9) Risk Survey: A controlling owner of a database or a holder of a database who failed to ensure that a survey to identify information security risks was conducted at least once every 18 months (hereinafter – Risk Survey), or who failed to discuss the results of the Risk Survey transmitted to them and failed to examine the need to update the database definition document or the Security Procedure in light thereof, or who failed to act to remedy the deficiencies identified in the Risk Survey, contrary to the provisions of Regulation 5(c) of the Information Security Regulations or those provisions as applied under Regulation 19(a) of those Regulations, as applicable320,000
(10) Penetration Tests: A controlling owner of a database or a holder of a database who failed to ensure that penetration tests of the database systems were conducted at least once every 18 months, or who failed to discuss the results of the penetration tests, or who failed to act to remedy the deficiencies identified, contrary to the provisions of Regulation 5(d) of the Information Security Regulations or those provisions as applied under Regulation 19(a) of those Regulations, as applicable320,000
(11) Control and Documentation of Site Entry: A controlling owner of a database or a holder of a database who failed to take measures for control and documentation in accordance with the provisions of Regulation 6(b) of the Information Security Regulations or those provisions as applied under Regulation 19(a) of those Regulations, as applicable20,00080,000
(12) Personnel Management: A controlling owner of a database or a holder of a database who granted access to information in the database or changed the scope of a permission granted, without taking any reasonable measure as referred to in Regulation 7(a) of the Information Security Regulations, contrary to the provisions of that Regulation or those provisions as applied under Regulation 19(a) of the Information Security Regulations, as applicable1,00020,00080,000
(13) Personnel Training: A controlling owner of a database or a holder of a database who granted access to information in the database or changed the scope of a permission granted, without having previously conducted training sessions or without having provided authorized users with the required information, contrary to the provisions of Regulation 7(b) of the Information Security Regulations or those provisions as applied under Regulation 19(a) of those Regulations, as applicable1,00020,00080,000
(14) Periodic Training: A controlling owner of a database or a holder of a database who failed to conduct periodic training activities for its authorized users, contrary to the provisions of Regulation 7(c) of the Information Security Regulations or those provisions as applied under Regulation 19(a) of those Regulations, as applicable20,00080,000
(15) Establishment and Management of Access Permissions: A controlling owner of a database or a holder of a database who failed to establish access permissions for authorized users to the database and to the database systems, contrary to the provisions of Regulation 8(a) of the Information Security Regulations or those provisions as applied under Regulation 19(a) of the Information Security Regulations, as applicable, or who failed to maintain an updated register of valid permissions, contrary to the provisions of Regulation 8(b) of the Information Security Regulations or those provisions as applied under Regulation 19(a) of those Regulations, as applicable (hereinafter – Valid Permissions List)2,00040,000160,000
(16) Implementation of Access Permissions Procedure: A controlling owner of a database or a holder of a database who failed to take customary measures in the circumstances of the matter and in accordance with the nature and character of the database, in order to verify that access to the database and to the database systems is carried out solely by an authorized user who is authorized to do so under the Valid Permissions List, contrary to the provisions of Regulation 9(a) of the Information Security Regulations or those provisions as applied under Regulation 19(a) of those Regulations, as applicable2,0002,00040,000160,000
(17) Implementation of Access Permissions Procedure with Respect to an Authorized User Who Has Concluded Their Role: A controlling owner of a database or a holder of a database who failed to ensure the revocation of permissions of an authorized user who has concluded their role, contrary to the provisions of Regulation 9(c) of the Information Security Regulations or those provisions as applied under Regulation 19(a) of those Regulations, as applicable2,00040,000160,000
(18) Control and Documentation Mechanism for Access: A controlling owner of a database or a holder of a database who failed to perform any one of the following: (a) ensured that a control mechanism was operated, contrary to the provisions of Regulation 10(a) and (b) of the Information Security Regulations (hereinafter – Control Mechanism) or those provisions as applied under Regulation 19(a) of those Regulations, as applicable; (b) established a routine inspection procedure for the documentation data of the Control Mechanism and compiled a report of the problems identified and the measures taken in response thereto, contrary to the provisions of Regulation 10(c) of the Information Security Regulations or those provisions as applied under Regulation 19(a) of those Regulations, as applicable; (c) ensured that the documentation data of the Control Mechanism is retained for at least 12 months, contrary to the provisions of Regulation 10(d) of the Information Security Regulations or those provisions as applied under Regulation 19(a) of those Regulations, as applicable; (d) informed the authorized users of the database of the existence of the Control Mechanism, contrary to the provisions of Regulation 10(e) of the Information Security Regulations or those provisions as applied under Regulation 19(a) of those Regulations, as applicable40,000160,000
(19) Documentation of an Information Security Incident: A controlling owner of a database or a holder of a database who failed to ensure documentation of every case in which an incident was discovered giving rise to concern of harm to the integrity of the information, unauthorized use thereof, or exceeding authorization (hereinafter – Information Security Incidents), contrary to the provisions of Regulation 11(a) of the Information Security Regulations or those provisions as applied under Regulation 19(a) of those Regulations, as applicable2,0002,00040,000160,000
(20) Periodic Discussion of Information Security Incidents: A controlling owner of a database or a holder of a database who failed to hold a discussion of information security incidents, or who failed to examine the need to update the Security Procedure and to document such discussion and examination, contrary to the provisions of Regulation 11(c) and Regulation 19(b) of the Information Security Regulations or those provisions as applied under Regulation 19(a) of those Regulations, as applicable40,000160,000
(21) Reporting to the Authority Regarding a Serious Security Incident: A controlling owner of a database or a holder of a database who failed to immediately notify the Head of the Authority of a serious security incident, or who failed to report to the Head of the Authority on the measures taken in the aftermath of the incident, contrary to the provisions of Regulation 11(d)(1) of the Information Security Regulations or those provisions as applied under Regulation 19(a) of those Regulations, as applicable80,000320,000
(22) Updating Database Systems: A controlling owner of a database or a holder of a database who failed to ensure that routine updates of the database systems, including the computer hardware required for their operation, were carried out, or that no use was made of systems whose manufacturer does not support their security aspects without any security response being provided, contrary to the provisions of Regulation 13(c) of the Information Security Regulations or those provisions as applied under Regulation 19(a) of those Regulations, as applicable2,0002,00040,000160,000
(23) Network Connection Security: A controlling owner of a database or a holder of a database who connected the database systems to the internet or to another public network, without installing any protective measures, contrary to the provisions of Regulation 14(a) of the Information Security Regulations or those provisions as applied under Regulation 19(a) of those Regulations, as applicable2,0002,00040,000160,000
(24) Control and Supervision of an External Party (Outsourcing): A controlling owner of a database who entered into an engagement with an External Party for the purpose of receiving a service, who failed to expressly stipulate in the agreement with the External Party the matters enumerated in Regulation 15(a)(2) of the Information Security Regulations, or who failed to take any measure of control and supervision over the External Party's compliance with the provisions established in said agreement with respect to the matters specified in sub-paragraphs (d) and (f) through (h) of that Regulation, contrary to Regulation 15(a)(4) of the Information Security Regulations4,00080,000320,000
(25) Documentation: A controlling owner of a database or a holder of a database who failed to securely retain, for at least one year, the data accumulated in the course of implementing the provisions of Regulations 6(b), 8 through 11, 14, 15(a)(4) and 16 of the Information Security Regulations applicable to them, contrary to the provisions of Regulation 17(a) of the Information Security Regulations or those provisions as applied under Regulation 19(a) of the Information Security Regulations, as applicable1,00020,00080,000
(26) Backup of Documentation Data: A controlling owner of a database or a holder of a database who failed to do any one of the following: (a) backed up the retained data in a manner that ensures that the data can be restored to its original state at any time, contrary to the provisions of Regulation 17(b) of the Information Security Regulations or those provisions as applied under Regulation 19(a) of those Regulations, as applicable; (b) established in a document the matters enumerated in Regulation 18(a)(1) and (3) of the Information Security Regulations and established procedures for ensuring data restoration, as referred to in Regulation 17(b) of those Regulations; (c) ensured that a backup copy of the data and the procedures referred to in Regulation 18(a) of the Information Security Regulations is retained in a manner that ensures the integrity of the information and the possibility of data restoration, contrary to the provisions of Regulation 18(b) of the Information Security Regulations or those provisions as applied under Regulation 19(a) of those Regulations, as applicable20,00080,000
(27) Violation of Documentation Obligations: A controlling owner of a database or a holder of a database who failed to document the manner of performance of an action that does not constitute the creation of a document, which they are obligated or responsible to perform under the Regulations, contrary to the provisions of Regulation 19(b) of those Regulations1,00020,00080,000
(28) Separation of Database Systems (Compartmentalization): A controlling owner of a database or a holder of a database who failed to separate the database systems through which personal information can be accessed from other computing systems used by them, contrary to the provisions of Regulation 13(b) of the Information Security Regulations or those provisions as applied under Regulation 19(a) of those Regulations, as applicable20,00080,000
(29) Periodic Audit: A controlling owner of a database or a holder of a database who failed to ensure that an internal or external audit was conducted at least once every 24 months, contrary to the provisions of Regulation 16(a) of the Information Security Regulations or those provisions as applied under Regulation 19(a) of those Regulations, as applicable, or who failed to discuss the audit reports transmitted to them, or who failed to examine the need to update the database definition document or the Security Procedure in light thereof, contrary to the provisions of Regulation 16(c) of the Information Security Regulations or those provisions as applied under Regulation 19(a) of those Regulations, as applicable40,000160,000

Need to cite this law in a foreign court?

Eli Shimony Israeli Attorneys-at-Law provides certified Expert Legal Opinions on Israeli law within 24–48 hours, accepted by courts worldwide.

Contact Us →

Fourth Schedule (Section 23kf(i)): Monetary Penalty for Violation of

1.

In this Schedule, "Regulations for the Transfer of Information from the European Economic Area" means the Privacy Protection Regulations (Provisions Regarding Information Transferred to Israel from the European Economic Area), 5783–2023.

Need to cite this law in a foreign court?

Eli Shimony Israeli Attorneys-at-Law provides certified Expert Legal Opinions on Israeli law within 24–48 hours, accepted by courts worldwide.

Contact Us →

Fourth Schedule — Part A

The ViolationThe Amount of the Monetary Penalty
(1) A controller of a database who failed to notify the data subject in writing of the decision on a request pursuant to the provisions of the Privacy Protection Regulations (Provisions Regarding Information Transferred to Israel from the European Economic Area)#Section 3, in contravention of the provisions of the Privacy Protection Regulations (Provisions Regarding Information Transferred to Israel from the European Economic Area)#Section 315,000 New Shekels
(2) A controller of a database who failed to implement any organizational, technological, or other mechanism designed to ensure that the database does not retain information that is no longer necessary for the purpose for which it was collected or held, or for another purpose for which it is permitted to be held under any law (hereinafter – unnecessary information), in contravention of the provisions of the Privacy Protection Regulations (Provisions Regarding Information Transferred to Israel from the European Economic Area)#Section 4An amount of 2 New Shekels for each individual whose personal information is held in the database, and if the personal information in the database constituted information of special sensitivity – an amount of 4 New Shekels for each individual; if the amount of the administrative fine is less than 20,000 New Shekels, or, where the said information constitutes information of special sensitivity, less than 40,000 New Shekels, the Head of the Authority may impose upon a controller of a database or a holder of a database an administrative fine in the amount of 20,000 New Shekels or 40,000 New Shekels, as the case may be.
(3) A controller of a database who failed to implement any organizational, technological, or other mechanism designed to ensure that the information held in the database is accurate, complete, clear, and up to date, in contravention of the provisions of the Privacy Protection Regulations (Provisions Regarding Information Transferred to Israel from the European Economic Area)#Section 5An amount of 2 New Shekels for each individual whose personal information is held in the database, and if the personal information in the database constituted information of special sensitivity – an amount of 4 New Shekels for each individual; if the amount of the administrative fine is less than 20,000 New Shekels, or, where the said information constitutes information of special sensitivity, less than 40,000 New Shekels, the Head of the Authority may impose upon a controller of a database or a holder of a database an administrative fine in the amount of 20,000 New Shekels or 40,000 New Shekels, as the case may be.
(4) A controller of a database who found that the database holds information that is inaccurate, incomplete, unclear, or not up to date, and failed to take any measure to correct or delete such information, in contravention of the provisions of the Privacy Protection Regulations (Provisions Regarding Information Transferred to Israel from the European Economic Area)#Section 5An amount of 2 New Shekels for each individual whose personal information is held in the database, and if the personal information in the database constituted information of special sensitivity – an amount of 4 New Shekels for each individual; if the amount of the administrative fine is less than 20,000 New Shekels, or, where the said information constitutes information of special sensitivity, less than 40,000 New Shekels, the Head of the Authority may impose upon a controller of a database or a holder of a database an administrative fine in the amount of 20,000 New Shekels or 40,000 New Shekels, as the case may be.

Need to cite this law in a foreign court?

Eli Shimony Israeli Attorneys-at-Law provides certified Expert Legal Opinions on Israeli law within 24–48 hours, accepted by courts worldwide.

Contact Us →

Fourth Schedule — Part B

The ViolationThe Amount of the Financial Penalty
(1) A controller of a database who received a written request for the deletion of personal data as provided in the Privacy Protection Regulations (Provisions Regarding Information Transferred to Israel from the European Economic Area)#Section 3, and the exceptions set out in the Privacy Protection Regulations (Provisions Regarding Information Transferred to Israel from the European Economic Area)#Section 3 did not apply, and who did not delete the data or carry out measures ensuring that, by reasonable means, the data subject cannot be identified, contrary to the provisions of the Privacy Protection Regulations (Provisions Regarding Information Transferred to Israel from the European Economic Area)#Section 3, after having received notice from the Head of the Authority pursuant to the said provisions that his acts constitute a violation, and who did not cease the violation within the period directed by the Head of the Authority;An amount of 4 New Shekels for each person whose personal data is held in the database, and if the personal data in the database constituted data of special sensitivity — an amount of 8 New Shekels for each person; if the said administrative fine is less than 200,000 New Shekels, the Head of the Authority may impose on a controller of a database or on a holder of a database an administrative fine of 200,000 New Shekels; for the purposes of items (1), (3) and (4) — the administrative fine shall be calculated according to the number of persons whose personal data the controller did not delete as required or to whom the controller did not provide notice as required under the Privacy Protection Regulations (Provisions Regarding Information Transferred to Israel from the European Economic Area)#Section 3, the Privacy Protection Regulations (Provisions Regarding Information Transferred to Israel from the European Economic Area)#Section 6, and the Privacy Protection Regulations (Provisions Regarding Information Transferred to Israel from the European Economic Area)#Section 6, as applicable.
(2) A controller of a database who found that the database holds personal data that is no longer necessary as provided in the Privacy Protection Regulations (Provisions Regarding Information Transferred to Israel from the European Economic Area)#Section 4, and who did not carry out measures ensuring that the data subject cannot be identified as aforesaid, and the circumstances prescribed therein did not apply, and who did not delete the said data at the earliest possible time under the circumstances, contrary to the provisions of the Privacy Protection Regulations (Provisions Regarding Information Transferred to Israel from the European Economic Area)#Section 4, after having received notice from the Head of the Authority pursuant to the said provisions that his acts constitute a violation, and who did not cease the violation within the period directed by the Head of the Authority;An amount of 4 New Shekels for each person whose personal data is held in the database, and if the personal data in the database constituted data of special sensitivity — an amount of 8 New Shekels for each person; if the said administrative fine is less than 200,000 New Shekels, the Head of the Authority may impose on a controller of a database or on a holder of a database an administrative fine of 200,000 New Shekels; for the purposes of items (1), (3) and (4) — the administrative fine shall be calculated according to the number of persons whose personal data the controller did not delete as required or to whom the controller did not provide notice as required under the Privacy Protection Regulations (Provisions Regarding Information Transferred to Israel from the European Economic Area)#Section 3, the Privacy Protection Regulations (Provisions Regarding Information Transferred to Israel from the European Economic Area)#Section 6, and the Privacy Protection Regulations (Provisions Regarding Information Transferred to Israel from the European Economic Area)#Section 6, as applicable.
(3) A controller of a database who received personal data concerning an individual and did not provide that individual with notice as required under the Privacy Protection Regulations (Provisions Regarding Information Transferred to Israel from the European Economic Area)#Section 6, and none of the circumstances prescribed in the Privacy Protection Regulations (Provisions Regarding Information Transferred to Israel from the European Economic Area)#Section 6 applied, contrary to the Privacy Protection Regulations (Provisions Regarding Information Transferred to Israel from the European Economic Area)#Section 6, after having received notice from the Head of the Authority pursuant to the said provisions that his acts constitute a violation, and who did not cease the violation within the period directed by the Head of the Authority;An amount of 4 New Shekels for each person whose personal data is held in the database, and if the personal data in the database constituted data of special sensitivity — an amount of 8 New Shekels for each person; if the said administrative fine is less than 200,000 New Shekels, the Head of the Authority may impose on a controller of a database or on a holder of a database an administrative fine of 200,000 New Shekels; for the purposes of items (1), (3) and (4) — the administrative fine shall be calculated according to the number of persons whose personal data the controller did not delete as required or to whom the controller did not provide notice as required under the Privacy Protection Regulations (Provisions Regarding Information Transferred to Israel from the European Economic Area)#Section 3, the Privacy Protection Regulations (Provisions Regarding Information Transferred to Israel from the European Economic Area)#Section 6, and the Privacy Protection Regulations (Provisions Regarding Information Transferred to Israel from the European Economic Area)#Section 6, as applicable.
(4) A controller of a database who sought to transfer personal data received by him to a third party and did not provide notice thereof to the data subject as required under the Privacy Protection Regulations (Provisions Regarding Information Transferred to Israel from the European Economic Area)#Section 6, and none of the circumstances prescribed in the Privacy Protection Regulations (Provisions Regarding Information Transferred to Israel from the European Economic Area)#Section 6 applied, contrary to the Privacy Protection Regulations (Provisions Regarding Information Transferred to Israel from the European Economic Area)#Section 6, after having received notice from the Head of the Authority pursuant to the said provisions that his acts constitute a violation, and who did not cease the violation within the period directed by the Head of the Authority.An amount of 4 New Shekels for each person whose personal data is held in the database, and if the personal data in the database constituted data of special sensitivity — an amount of 8 New Shekels for each person; if the said administrative fine is less than 200,000 New Shekels, the Head of the Authority may impose on a controller of a database or on a holder of a database an administrative fine of 200,000 New Shekels; for the purposes of items (1), (3) and (4) — the administrative fine shall be calculated according to the number of persons whose personal data the controller did not delete as required or to whom the controller did not provide notice as required under the Privacy Protection Regulations (Provisions Regarding Information Transferred to Israel from the European Economic Area)#Section 3, the Privacy Protection Regulations (Provisions Regarding Information Transferred to Israel from the European Economic Area)#Section 6, and the Privacy Protection Regulations (Provisions Regarding Information Transferred to Israel from the European Economic Area)#Section 6, as applicable.

Need to cite this law in a foreign court?

Eli Shimony Israeli Attorneys-at-Law provides certified Expert Legal Opinions on Israeli law within 24–48 hours, accepted by courts worldwide.

Contact Us →

Fifth Schedule (Section 23la): Reduced Amounts for the Purpose of a Financial Sanction

Definitions

1.

In this Schedule –

"Confirmation Regarding the Volume of Transaction Turnover" – as detailed below, as the case may be:

(1)With respect to a violator who is required by law to appoint an auditing accountant as defined in the Companies Law, 5759–1999 – a confirmation given by the auditing accountant;
(2)With respect to a violator who is a cooperative society – a confirmation by the person who audited the accounts of the cooperative society pursuant to Section 20 of the Cooperative Societies Ordinance;
(3)With respect to any other violator – a confirmation given by an accountant or a representing tax consultant, that the volume of transaction turnover presented by the violator corresponds to what is stated in a document submitted to the Israel Tax Authority or to the National Insurance Institute pursuant to law; for this purpose, "representing tax consultant" – as defined in the Regulation of Practice of Representation by Tax Consultants Law, 5765–2005;

"Transaction Turnover" – the transaction turnover of a dealer as defined in the Value Added Tax Law, 5736–1975; with respect to a non-profit organization ("malkar") as defined in that Law – turnover as defined in the Second Schedule to the Associations Law, 5740–1980, and with respect to a public body that is not one of the foregoing – the annual budget of that public body;

"Micro Business" – a violator whose transaction turnover in the year preceding the date of the violation did not exceed 4 million New Shekels;

"Small Business" – a violator, excluding a micro business, whose transaction turnover in the year preceding the date of the violation exceeded 4 million New Shekels and did not exceed 10 million New Shekels.

Reduction Due to Conduct of the Violator

2.

The Head of the Authority shall reduce the amount of the financial sanction imposed on a violator by the rates set out below, if one or more of the following circumstances exist:

(1)In the five years preceding the violation of the provision in respect of which the financial sanction is imposed on the violator, no financial sanction or administrative enforcement measure was imposed on the violator pursuant to Sections B through E of Chapter D3 in respect of a violation of that same provision – by a rate of 20%; and if in the three years preceding the violation no financial sanction or administrative enforcement measure as aforesaid was imposed on the violator – by a rate of 10%;
(2)The violator ceased the violation on their own initiative and reported it to the Head of the Authority – by a rate of 30%;
(3)The violator took measures to prevent the recurrence of the violation and to minimize the damage, to the satisfaction of the Head of the Authority – by a rate of 20%;
(4)The violator is obligated to appoint a Privacy Protection Officer pursuant to Section 17b1(a)(3) and (4) only, and appointed such an officer prior to the delivery of the notice of intent to impose liability – by a rate of 10%; such a reduction shall apply as long as the Minister of Justice has not prescribed, with the approval of the Constitution Committee, an order pursuant to Section 23kf(d)(1)(g).

Reduction Due to Payment or Other Compensation Paid

3.

The Head of the Authority may reduce the amount of the financial sanction imposed on a violator on account of compensation paid or adjudged against the violator in respect of the same violations – by a rate not exceeding 30%.

Reduction Due to Personal Circumstances

4.

If the Head of the Authority finds, with respect to a violator who is an individual, that the violation was caused by personal circumstances that justify a reduction of the financial sanction, or that difficult personal circumstances exist that justify refraining from imposing the full extent of the law on the violator, the Head of the Authority may reduce the amount of the financial sanction imposed on the violator by a rate of 20%.

Reduction Due to Multiple Circumstances

5.

Where several circumstances as referred to in Sections 2, 3, and 4 exist with respect to a violator, the Head of the Authority may reduce from the amount of the financial sanction imposed on the violator the rates listed alongside those circumstances, cumulatively, provided that the cumulative rate of reduction shall not exceed 70% of the amount of the financial sanction.

Reduction for a Micro or Small Business

6.

If the Head of the Authority finds, upon the request of the violator, that the violator is a micro business or a small business, as the case may be, the Head of the Authority shall reduce the amounts of the sanction to be imposed on the violator – whether or not they have been reduced pursuant to Section 2, 3, or 4 – such that the amount of the sanction in respect of violations under each of the paragraphs set out below shall not exceed the amount specified alongside them:

Where a violator who is a micro business or a small business commits a number of violations under paragraphs (1) through (3) – the violator shall not bear an amount exceeding the highest financial sanction among those paragraphs.

Reduction Due to Consideration of Transaction Turnover

7.
(a)If the Head of the Authority finds, upon the request of the violator, that the amount of the financial sanction imposed on the violator – whether or not it has been reduced pursuant to Section 2, 3, 4, or 6 – exceeds 5% of the violator's transaction turnover, the Head of the Authority shall reduce the amount of the financial sanction to 5% of the violator's transaction turnover; however, with respect to a dealer who has no transaction turnover, the Head of the Authority shall not reduce the amount of the sanction pursuant to this Section to an amount less than the maximum amount that may be imposed pursuant to Section 6 with respect to a micro business.
(b)A violator seeking a reduction of the amount of the financial sanction pursuant to Section 6 or this Section shall submit to the Head of the Authority a confirmation regarding the volume of their transaction turnover within 30 days from the date of delivery of the notice of intent to impose liability.

Menachem Begin, Prime Minister

Moshe Nissim, Minister of Justice

Yitzhak Navon, President of the State

Need to cite this law in a foreign court?

Eli Shimony Israeli Attorneys-at-Law provides certified Expert Legal Opinions on Israeli law within 24–48 hours, accepted by courts worldwide.

Contact Us →

Page 7 of 7

⚠ Disclaimer: This is an unofficial AI-assisted translation. The Hebrew version published in the official records (Reshumot) is the sole binding and legally valid text.