What it is
The Privacy Protection Law, 5741-1981, is Israel's main privacy statute. It has two parts: a general prohibition on infringing another person's privacy (Chapter A), and rules for the management and use of databases containing personal information (Chapter B). Supporting regulations, notably the Data Security Regulations of 2017 and the regulations on transfers of data abroad, fill in much of the operational detail.
Amendment 13
Amendment 13 is the most extensive reform of the law since it was enacted. It came into force in August 2025. It updated the core definitions, such as "personal information" and "information of special sensitivity", reshaped the database registration regime, introduced a duty to appoint a privacy protection officer in defined cases, and gave the Privacy Protection Authority (PPA) much stronger supervisory and enforcement powers, including administrative fines.
Who it applies to
The law covers the holding and use of personal information in databases by private and public bodies in Israel. It distinguishes the "controller" (the party that determines the purposes of processing) from the "holder" (a party that holds or processes a database on another's behalf). Individuals can invoke the privacy protections of Chapter A, while many database duties fall on corporate and public-sector controllers.
Database registration and notification
Before Amendment 13, almost every database of any size had to be registered. The reformed regime narrows mandatory registration to defined categories: for example, databases whose main purpose is collecting personal information in order to pass it to others in the course of business (above a size threshold) and databases of public bodies. A separate duty to notify the PPA applies to non-registrable databases that hold sensitive information about a large number of people. Details and thresholds are set in the statute, so check the current text.
Core principles
The law builds on purpose limitation: personal information may be used only for the purpose for which it was provided. Collection requires informed consent and a notice explaining the purpose and whether providing the data is mandatory. Information of special sensitivity, such as health, genetic, biometric, or financial data, attracts stricter treatment, and security measures must match the risk of the database.
Individual rights
People have the right to inspect personal information held about them in a database and to ask for it to be corrected or deleted if it is inaccurate, incomplete, unclear, or out of date. Individuals can object to the use of their data for direct mailing and can ask to be removed from direct-mailing lists.
Key obligations
Controllers and holders must secure personal information in line with the Data Security Regulations, which set requirements by database security level. Certain bodies, including public bodies and organizations processing sensitive data on a large scale, must appoint a privacy protection officer. Transfers of personal data abroad are subject to separate regulations; Israel also holds an EU adequacy decision, which shapes how data flows from Europe.
Data breaches
Under the Data Security Regulations, owners and holders of databases must notify the PPA immediately of a severe security incident and report the steps taken in response. Depending on the circumstances, the PPA can also direct that affected individuals be informed. Documentation and incident-response procedures are expected as part of the security program.
Enforcement and penalties
The PPA is an independent unit within the Ministry of Justice, headed by the Head of the Authority, and acts as the regulator. After Amendment 13 it can open investigations, issue orders, and impose administrative fines, with higher fines for databases covering a very large number of people. The law also contains criminal offences, and individuals can claim compensation in civil proceedings, including statutory compensation without proof of damage in defined cases.
The official text
The authoritative version is the Hebrew text of the Privacy Protection Law, 5741-1981, as published in the Israeli Official Gazette (Sefer HaChukim) and amended since. The link above leads to the current consolidated Hebrew text on the Nevo legal database; the Knesset also publishes consolidated editions. Use that text, not this summary, for anything that matters.
Below is the source we understand to be the official text (Hebrew, current consolidated text (Nevo legal database)). We cannot guarantee it is correct, current, complete, or the authoritative version, and we may have linked or labelled it wrong, so please check it yourself and do not rely on it or on our summary:
Go to the source →