Israel's Privacy Protection Law5741-1981 · including Amendment 13, in force 14 August 2025 · the statute text with a plain-English explanation
What the Law protects, what counts as a database, who must appoint a Data Protection Officer, and what a company holding Israeli employees' personal data actually has to do. Each topic gives the English translation of the statutory section first, then a plain-English explanation. The English is unofficial; the Hebrew original is legally binding.
AI summary · Privacy Protection LawClick to read the page summary
The Privacy Protection Law, 5741-1981 provides that a person shall not infringe the privacy of another without their consent (section 1), and lists eleven forms of infringement (section 2) · a civil wrong under section 4, and for most of them a criminal offence punishable by 5 years' imprisonment under section 5. The chapter on databases governs lawful processing (section 8), the duty to register or notify (section 8A), the rights of access and correction (sections 13 to 14), data security (section 17) and the duty to appoint a Data Protection Officer (section 17B1). Amendment 13, whose main provisions came into force on 14 August 2025, broadened the Authority's enforcement powers and financial sanctions, introduced the DPO duty, narrowed database registration, created new offences and aligned the definitions with the GDPR. Below: the statutory text next to a plain-English explanation, what a foreign employer must actually do, a short knowledge check and an FAQ. The English is unofficial; the Hebrew text is legally binding.
- Section 1 · no infringement of another's privacy without their consent.
- Section 2 · eleven listed forms of infringement of privacy.
- Database · a collection of personal information processed by digital means (section 3).
- DPO · appointment mandatory for the bodies listed in section 17B1.
- Up to 50,000 shekels compensation without proof of damage (section 29A).
- This page is informational only · the binding text is the Hebrew in Reshumot.
- The law in numbers
- About the law
- Infringement of privacy · sections 1 to 5
- Databases & processing · sections 3 to 14
- Data security & the DPO · sections 17 to 17B2
- Enforcement & compensation
- Amendment 13 · what changed
- What a foreign employer must do
- Test your knowledge
- Frequently asked questions
- In summary
- Related guides
The Privacy Protection Law in numbers
About the Privacy Protection Law
The Privacy Protection Law, 5741-1981, is the primary privacy and data protection statute in Israel. It does two distinct things. First, it makes infringement of a person's privacy unlawful: section 1 prohibits it without consent, section 2 lists eleven specific forms, section 4 makes it a civil wrong to which the Torts Ordinance applies, and section 5 makes a wilful infringement by most of those forms a criminal offence.
Second, it regulates databases and the processing of personal information: processing tied to the purpose lawfully set for the database (section 8), the duty to register or notify (section 8A), a notice duty when information is requested from a person (section 11), the rights of access and correction (sections 13 to 14), data security (section 17), and the duty to appoint an information security officer (section 17B) and a Data Protection Officer (sections 17B1 to 17B2). Amendment 13 substantially reworked this second half and came into force, in the main, on 14 August 2025.
If you employ people in Israel, this Law sits alongside the rest of the employment framework · see our guides to Israeli labor law, employee rights in Israel and the Wage Protection Law.
- Each topic · first the statutory translation, then a plain-English explanation.
- Infringement of privacy, databases, access and correction, data security.
- Amendment 13 · the DPO duty, enforcement powers and penalties.
The statutory text was translated from, and cross-checked against, the official Hebrew version on Nevo as in force after Amendment 13. The original Hebrew is the only legally binding text. See also the Hebrew page.
The Privacy Protection Law · section by section
For each topic, the English translation of the statutory section is shown first (inside the expandable boxes, marked as statute text) · and below it a plain-English explanation in a teal box tagged "Explanation · not part of the statute". The English is unofficial; only the Hebrew text on Nevo is legally binding.
Privacy Protection Law, 5741-1981 (unofficial English translation, as in force after Amendment 13)
A law that prohibits infringement of a person's privacy, makes it a civil wrong and in most forms a criminal offence, and regulates the management of databases and the processing of personal information · including lawful processing, registration, the rights of access and correction, data security, the Data Protection Officer, supervision, enforcement and compensation.
Chapter A · Infringement of privacy · sections 1 to 5
Section 1 · Prohibition of infringement of privacy
A person shall not infringe the privacy of another without their consent.
Section 2 · What constitutes an infringement of privacy
An infringement of privacy is any of the following:
(1) spying on or trailing a person, in a manner liable to harass them, or other harassment;
(2) listening in that is prohibited by law;
(3) photographing a person while they are in a private domain;
(4) publishing a person's photograph in public, in circumstances in which the publication is liable to humiliate or degrade them;
(4a) publishing in public the photograph of a casualty, taken at the time of the injury or shortly afterwards, in a manner allowing them to be identified and in circumstances in which the publication is liable to cause them embarrassment · other than publication of a photograph without delay between the moment of filming and the moment of actual broadcast, which does not exceed what is reasonable in those circumstances; for this purpose, "casualty" means a person who suffered physical or mental injury as a result of a sudden event and whose injury is visible;
(5) copying the content of a letter or other writing not intended for publication, or using its content, without permission from the addressee or the writer, all provided that the writing is not of historical value and that fifteen years have not passed from the date it was written; for this purpose, "writing" includes an electronic message as defined in the Electronic Signature Law, 5761-2001;
(6) using a person's name, appellation, image or voice for profit;
(7) breach of a duty of confidentiality laid down by law in respect of a person's private affairs;
(8) breach of a duty of confidentiality in respect of a person's private affairs, laid down by an express or implied agreement;
(9) using information about a person's private affairs, or delivering it to another, other than for the purpose for which it was given;
(10) publishing or delivering a matter obtained by way of an infringement of privacy under paragraphs (1) to (7) or (9);
(11) publishing a matter relating to a person's intimate personal life, including their sexual past, or their state of health, or their conduct in the private domain.
Section 3 · Definitions (key definitions)
For the purposes of this Law (the key definitions are reproduced here; the full list of definitions appears in the official Hebrew text) ·
"information security" · protection of the integrity of the personal information, or protection of the personal information against processing without lawful authorisation;
"controller" of a database · a person who determines, alone or together with another, the purposes of processing the information in the database, or a body which, or a post-holder in which, is empowered by enactment to process information in a database;
"direct mailing" · a personal approach to a person, based on their belonging to a population group determined by one or more characteristics of persons whose names are included in a database;
"consent" · informed consent, express or implied;
"database" · a collection of items of personal information processed by digital means, other than one of the following:
(1) a collection for personal use that is not for business purposes;
(2) a collection that includes only name, address and contact details, in respect of 100,000 people or fewer, that does not in itself indicate any further personal information about the persons whose names are included in it, provided that the owner of the collection, or a corporation under their control, has no other collection that includes other items of information about those same people;
"holder", in relation to a database · a party external to the controller of the database, who processes information on their behalf;
"personal information" · a datum relating to an identified person or to an identifiable person; for the purposes of this definition, "identifiable person" means a person who can be identified with reasonable effort, directly or indirectly, including by means of an identifying particular such as a name, an identity number, a biometric identifier, location data, an online identifier, or one or more data relating to their physical, health, economic, social or cultural condition;
"information of special sensitivity" · each of the following:
(1) personal information about the intimacy of a person's family life, their intimate relations and their sexual orientation;
(2) personal information relating to a person's state of health, including medical information as defined in the Patient's Rights Law, 5756-1996;
(3) personal information that is genetic information as defined in the Genetic Information Law, 5761-2000;
(4) personal information that is a biometric identifier used, or intended to be used, to identify a person or to verify their identity by computerised means;
(5) personal information about a person's origin;
(6) personal information about a person's criminal past;
(7) personal information about a person's political opinions or religious beliefs or worldview;
(10) personal information about a person's salary data and their financial activity;
(11) personal information to which a duty of confidentiality laid down by law applies;
"processing", "use" · any operation performed on personal information, including receiving it, collecting it, storing it, copying it, inspecting it, disclosing it, exposing it, transferring it, delivering it or granting access to it;
"integrity of the information" · the identity of the data in a database with the source from which they were drawn, without having been altered, delivered or destroyed without lawful authorisation.
Section 4 · Infringement of privacy as a civil wrong
An infringement of privacy is a civil wrong, and the provisions of the Torts Ordinance [New Version] shall apply to it, subject to the provisions of this Law.
Section 5 · Infringement of privacy as an offence
A person who wilfully infringes the privacy of another, in one of the ways stated in section 2(1), (3) to (7) and (9) to (11), is liable to 5 years' imprisonment.
This is the backbone of the Law. Section 1 states the principle: privacy is protected, and it may be infringed only with consent · which section 3 defines as informed consent, express or implied. Section 2 then converts that principle into a closed list of eleven forms. Note that the list is not limited to surveillance: paragraphs (7) to (9) cover breaches of confidentiality and using information other than for the purpose for which it was given · which is exactly where an employer mishandling staff data usually lands.
The consequences run on two tracks. Section 4 makes an infringement a civil wrong, so the injured person can sue in tort. Section 5 makes a wilful infringement, by most of the listed forms, a criminal offence carrying up to 5 years' imprisonment. Paragraphs (2) and (8) are excluded from the criminal track.
Chapter B · Databases and processing of personal information
Section 8 · Managing a database and lawful processing of personal information
(a) In this section, "processing" · other than incidental storage in good faith.
(b) A person shall not process personal information in a database other than for the purpose of the database that was lawfully set for it.
(c) A person shall not process personal information from a database without authorisation from the controller of the database, or in deviation from such authorisation.
(d) (1) A controller of a database shall not process personal information in the database, and shall not permit another to process such information on their behalf, if the personal information included in the database was created, received, accumulated or collected contrary to the provisions of this Law or to the provisions of any other law regulating the processing of information;
(2) where personal information was delivered to a controller of a database by another party, and the controller neither knew nor ought to have known that that party acted unlawfully, the controller shall not bear responsibility under this subsection for processing of personal information carried out before they knew or ought to have known as aforesaid;
(3) the provisions of paragraph (1) shall not apply to a breach of law that is of minor significance in the circumstances of the case, and in respect of personal information delivered as stated in paragraph (2), even if the controller knew or ought to have known.
Section 8A · Duty of registration or notification
(a) (1) A database is subject to registration where one of the following applies:
(a) its main purpose is the collection of personal information in order to deliver it to another as a way of business or for consideration, including direct mailing services, and the database contains personal information about more than 10,000 people;
(b) the controller of the database is a public body as defined in paragraph (1) of the definition of "public body" in section 23, unless the database includes personal information about the employees of the public body only;
(2) a controller of a database shall not process personal information in a database that is subject to registration, and shall not permit another to process such information on their behalf, unless the database has been entered in the register;
(b) (1) where the number of people about whom information of special sensitivity is held in a database that is not subject to registration under subsection (a)(1) exceeds 100,000, the controller of the database shall notify the Authority, within 30 days from the occurrence of the aforesaid, of the identity of the controller, their address and contact details, of the identity of the Data Protection Officer · if their appointment is required under section 17B1 · and of the contact details for them, and shall deliver to the Authority a copy of the database definitions document whose preparation is required under the regulations pursuant to sections 17(b) and 36;
(c) The provisions of this section shall not apply to a database that contains nothing but information published to the public under lawful authority, or made available for public inspection under lawful authority.
Section 11 · Duty of the person requesting information · notice and consent
An approach to a person for the purpose of obtaining personal information in order to process it in a database shall be accompanied by a notice stating ·
(1) whether that person is under a legal duty to deliver the information, or whether delivery of the information depends on their will and consent, and what the consequence of non-consent is;
(2) the purpose for which the information is requested;
(2a) the name of the controller of the database, and the contact details for them;
(3) to whom the information will be delivered and the purposes of the delivery;
(4) the existence of a right of access to the personal information under section 13 and of a right to request correction of the personal information under section 14.
Section 13 · Right of access to personal information
(a) Every person is entitled to inspect, in person, or through a representative authorised by them in writing, or through their guardian, the personal information about them that is held in a database.
(b) A controller of a database shall allow inspection of the personal information, at the request of a person as stated in subsection (a) (in this section · the applicant), in the Hebrew, Arabic or English language.
(c) The controller of the database may refrain from delivering to the applicant personal information relating to their medical or mental condition if, in their view, the information is liable to cause serious harm to the applicant's physical or mental health or to endanger their life; in such a case the controller of the database shall deliver the information to a physician or psychologist on the applicant's behalf.
Section 14 · Correction of personal information
(a) A person who has inspected the personal information about them and found that it is not correct, complete, clear or up to date, may apply to the controller of the database, and if they are a foreign resident · to the holder of the database, with a request to correct the personal information or to delete it.
(b) Where the controller of the database has agreed to a request as stated in subsection (a), they shall make the required changes to the personal information in their possession and shall notify them to every person who received the personal information from them within the period prescribed in the regulations.
(c) Where the controller of the database has refused to comply with a request as stated in subsection (a), they shall notify the applicant thereof, in the manner and by the means prescribed in the regulations.
This is the part most companies get wrong. A database is broader than people expect: under section 3 it is simply a collection of items of personal information processed by digital means. A spreadsheet of Israeli employees with salary data is a database. The two carve-outs are narrow · a purely personal, non-business collection, and a bare contact list (name, address, contact details only) of up to 100,000 people that reveals nothing further.
Section 8 fixes the central rule: processing must serve the purpose lawfully set for the database, and nothing else. Section 8(d) adds the Amendment 13 prohibition on processing information that was collected or created unlawfully · with a good-faith carve-out where the controller neither knew nor ought to have known.
Section 8A now targets registration at higher-risk databases: registration is required mainly where the database's main purpose is supplying personal information to others as a business, on more than 10,000 people, or where the controller is a public body (with an exception for a body's own employee database). A separate notification duty bites where a non-registrable database holds information of special sensitivity on more than 100,000 people.
Sections 11, 13 and 14 are the individual's rights: you must tell people what you are collecting, why, who receives it, who the controller is and that they have access and correction rights; you must let them see their information, in Hebrew, Arabic or English; and you must correct or delete it when it is wrong, and tell downstream recipients.
Data security and the Data Protection Officer · sections 17 to 17B2
Section 17 · Responsibility for information security
(a) A controller of a database and a holder of a database are each responsible for the security of the information in the database.
(b) (1) The Minister of Justice, with the agreement of the Prime Minister and the approval of the Constitution Committee, may make regulations concerning the responsibility for information security laid down in subsection (a) and in section 17B(b), including its scope and the duties comprised in it, and concerning the means of information security as aforesaid, among other things in the following matters:
(a) physical and logical protection of the database;
(b) the management arrangements and working rules in and in connection with the database, including with regard to setting restrictions on the access of employed persons to the information.
Section 17B · Information security officer
(a) The bodies listed below are required to appoint a suitably qualified person to be an information security officer:
(1) a controller of five databases that are subject to registration or notification under section 8A, or a holder of five such databases;
(2) a public body as defined in section 23;
(3) a bank, an insurance company, a company engaged in credit rating or credit assessment.
(c) A person who has been convicted of an offence involving moral turpitude, or of an offence under the provisions of this Law, shall not be appointed as an information security officer.
Section 17B1 · Duty to appoint a Data Protection Officer
(a) The bodies listed below are required to appoint a Data Protection Officer:
(1) a controller of a database that is a public body as defined in section 23, or a holder of such a database, other than a security body as defined in section 23T;
(2) a controller of a database whose main purpose is the collection of personal information in order to deliver it to another as a way of business or for consideration, including direct mailing services, and the database contains personal information about more than 10,000 people;
(3) a controller of a database or a holder of a database whose main activities include, or involve, processing operations which, by reason of their nature, scope or purpose, require regular and systematic monitoring of people, including systematic surveillance or tracking of a person's conduct, location or actions, on a significant scale;
(4) a controller of a database or a holder of a database whose main activity includes processing information of special sensitivity on a significant scale, among others a banking corporation, an insurer, a general hospital and a health fund.
Section 17B2 · Functions of the Data Protection Officer
(a) The Data Protection Officer shall act to ensure compliance with the provisions of this Law by the controller of the database or the holder of the database, and to promote the protection of privacy and the security of information in the databases, including ·
(1) shall serve as the professional authority and a knowledge centre, shall advise the management of the body in which they hold their office and its employees, shall prepare a training programme and supervise its implementation;
(2) shall prepare a programme for ongoing control of compliance with the provisions of this Law in respect of databases, shall verify its implementation, shall report their findings to the management of the body and shall propose measures to correct deficiencies;
(4) shall ensure that approaches by people whose personal information is held in the database are handled, including requests for access or correction; the contact details for the Officer shall be published to the public in an accessible and simple manner;
(5) shall serve as the body's liaison with the Authority.
Section 17 puts responsibility for information security on both the controller and the holder · each of them, separately. If you use an external payroll provider, that provider is a holder, and responsibility does not transfer away from you: it attaches to both of you.
The Amendment 13 headline is section 17B1 · the duty to appoint a Data Protection Officer. Note carefully what triggers it. It is not a headcount threshold. It is: being a public body; being a data broker with information on more than 10,000 people; carrying out regular and systematic monitoring of people on a significant scale; or processing information of special sensitivity on a significant scale. An ordinary employer holding its own staff records does not usually fall into any of these · but a company whose core business involves tracking users, or handling health, biometric, financial or salary data at scale, very well may.
Section 17B2 then defines what the Officer actually does: professional authority and knowledge centre, training, an ongoing control programme with reporting to management, handling access and correction requests, and acting as liaison with the Authority. The Officer's contact details must be published publicly in an accessible and simple manner. Note that 17B (information security officer) and 17B1 (Data Protection Officer) are two different appointments with different triggers.
Confidentiality, public bodies, enforcement and compensation
Section 16 · Confidentiality
A person shall not disclose personal information that reached them by virtue of their office as an employee, as a manager or as a holder of a database, other than for the purpose of performing their work, or for the implementation of this Law, or under a court order in connection with legal proceedings; if the application was made before the commencement of the proceedings, the application shall be heard in the Magistrates' Court. A person who breaches the provisions of this section is liable to 5 years' imprisonment.
Section 23B · Prohibition on delivery of information by a public body
(a) The delivery of personal information by a public body is prohibited, unless the information was published to the public under lawful authority, or was made available for public inspection under lawful authority, or the person to whom the personal information relates gave their consent to the delivery.
(b) Nothing in the provisions of this section shall prevent a security authority, within the meaning of section 19, from receiving or delivering personal information for the purpose of performing its function, provided that the delivery or receipt has not been prohibited by enactment.
Section 15A · Statutory damages
(a) Where a controller of a database or a holder of a database has breached one of the provisions set out below, the court may award, in respect of that breach, damages that are not dependent on damage (in this section · statutory damages), in an amount not exceeding 10,000 new shekels:
(1) in respect of a controller of a database · if the database is subject to registration under the provisions of section 8A · processed personal information in the database without it having been registered, contrary to the provisions of that section, provided that a person to whom the personal information relates approached the controller with a demand to register the database, and 90 days have passed since their approach;
(3) in respect of a controller of a database · did not allow a person who requested to inspect the personal information about them held in the database to inspect the information, contrary to the provisions of sections 13 or 13A, at the time and in the manner prescribed in the regulations pursuant to section 13;
Section 29A · Compensation without proof of damage
(a) Where a person has been convicted of an offence under section 5, the court may order them to pay the injured person compensation not exceeding 50,000 new shekels, without proof of damage; an order for compensation under this subsection shall be as a judgment of that court given in a civil action of the person entitled against the person liable.
(b) (1) In an action for a civil wrong under section 4, the court may order the defendant to pay the injured person compensation not exceeding 50,000 new shekels, without proof of damage;
(2) in an action as stated in paragraph (1) in which it has been proved that the infringement of privacy was committed with intent to harm, the court may order the defendant to pay the injured person compensation not exceeding double the amount stated in that paragraph, without proof of damage.
(d) The amounts stated in this section shall be updated on the 16th of each month, in accordance with the rate of change of the new index compared with the base index.
Section 16 is the one employees and contractors most often trip over: anyone who obtained personal information by virtue of their job may not disclose it except for the purposes of that job, under the Law, or under a court order. Breach is a criminal offence carrying up to 5 years' imprisonment · the same maximum as section 5.
On the money: section 29A allows compensation of up to 50,000 shekels without proof of damage · and up to double that where the infringement was committed with intent to harm. Because no damage need be proved, this is a realistic exposure even where nothing measurable was lost. The amounts are index-linked and updated monthly. Section 15A adds narrower statutory damages of up to 10,000 shekels for specific failures around registration and the right of access. These sit alongside the financial sanctions the Authority may impose, which Amendment 13 substantially increased.
Legal notice. The statutory text above is an unofficial English translation provided for general information and ease of reading only · it is not legal advice and must not be relied on as such. It was translated from and cross-checked against the official Hebrew version on Nevo. The only legally binding text is the original Hebrew as published in the Official Gazette (Reshumot), which may contain later amendments and updates; where the translation and the Hebrew differ, the Hebrew prevails. Not every section of the Law is reproduced here. For any legal use, consult the official Hebrew text and a qualified lawyer. See also the Hebrew page and the Privacy Protection Authority.
Amendment 13 · what changed
Amendment No. 13 to the Privacy Protection Law is the most significant reform of the Law since it was enacted. Its main provisions came into force on 14 August 2025. The following is a summary of the principal changes in NETO's own words · an explanatory summary only; the binding text is the Law itself, translated in the sections above and authoritative only in the Hebrew original.
- Enforcement. Broadened supervision, investigation and enforcement powers for the Privacy Protection Authority, and increased financial sanctions on those who breach the Law.
- DPO duty. A duty to appoint a Data Protection Officer in public bodies, and in bodies whose activity involves processing on a significant scale or the processing of sensitive information (section 17B1).
- Security bodies. Regulation of supervision in security bodies and the appointment of an internal privacy supervisor, with the necessary adaptations.
- Registration narrowed. The database registration duty was reduced and refocused on higher-risk databases, alongside a route for a preliminary opinion from the Authority.
- New offences. New criminal offences, and an express prohibition on processing personal information that was collected or created unlawfully.
- GDPR alignment. Definitions were updated to align with the GDPR · including personal information, processing, controller, holder and information of special sensitivity.
- Civil enforcement. Compensation without proof of damage was broadened and the amounts increased, strengthening private enforcement.
What a foreign employer of Israeli staff must do
Two worked scenarios mapping the facts to the statutory sections. Illustrative only and not legal advice · in any specific case the precise facts must be examined and a professional consulted.
Scenario 1 · A company holding a staff database
Scenario 2 · Is a DPO required? (section 17B1)
The practical minimum for a company holding Israeli employees' data. Set and record the purpose of the database and keep processing inside it (section 8). Give a section 11 notice at the point of collection · what you are collecting, why, whether it is voluntary, who the controller is, who receives the data, and that access and correction rights exist. Be able to answer an access request in Hebrew, Arabic or English (section 13) and to correct or delete and inform downstream recipients (section 14). Secure the data, and remember the duty is on you and on any external processor holding it for you (section 17). Check the section 17B1 triggers honestly · and if any applies, appoint a Data Protection Officer and publish their contact details (section 17B2). Impose confidentiality on everyone who touches the data (section 16).
Employing through an Employer of Record does not make these duties disappear, but it does change who holds what: the EOR becomes the employer of record and the controller of the payroll database, while the client company's own holding of personal data narrows. See also EOR services for foreign companies and hiring in Israel without a local entity.
Employ in Israel without holding the data yourself
NETO employs your Israeli workers as the employer of record, under manpower contractor license #1565 and supervised by the Ministry of Labor · running payroll, payslips and the personal data that goes with them inside a defined, secured database. Yizhar Cohen, NETO's Data Protection Officer, leads privacy compliance under Amendment 13.
Test your knowledge · Privacy Protection Law
Five short questions on the essentials. Pick an answer for each · you will see straight away whether you were right, with the relevant section.
1 How many forms of infringement of privacy does section 2 list?
Correct · section 2 lists eleven forms, from spying and unlawful listening in through to publishing a matter relating to a person's intimate personal life.
2 What is a database under section 3?
Correct · the definition is broad. The exclusions are a personal, non-business collection, and a bare contact list of up to 100,000 people revealing nothing further.
3 When did the main provisions of Amendment 13 come into force?
Correct · the main provisions of Amendment 13 came into force on 14 August 2025.
4 Does simply employing staff and holding their records trigger the DPO duty?
Correct · section 17B1 turns on being a public body, being a data broker with information on more than 10,000 people, regular and systematic monitoring at significant scale, or processing specially sensitive information at significant scale. It is not a headcount test.
5 What is the maximum compensation without proof of damage under section 29A?
Correct · section 29A allows up to 50,000 shekels without proof of damage, and up to double where intent to harm is proved. The 10,000 shekel figure is the separate statutory damages under section 15A.
Privacy Protection Law · frequently asked questions
Is this English text the official version of the Privacy Protection Law?
What counts as an infringement of privacy under the Law?
What is a database under the Privacy Protection Law?
Who must appoint a Data Protection Officer in Israel?
When must a database be registered in Israel?
What is the right of access to personal information?
What compensation is available without proof of damage?
What did Amendment 13 change, and when did it take effect?
In summary
The Privacy Protection Law, 5741-1981, in eight points · as in force after Amendment 13.
- Section 1 · a person shall not infringe the privacy of another without their consent, meaning informed consent, express or implied.
- Section 2 · eleven listed forms of infringement, including using information other than for the purpose for which it was given.
- Sections 4 and 5 · a civil wrong, and for most forms a wilful infringement is an offence carrying up to 5 years' imprisonment.
- Section 3 · a database is any collection of personal information processed by digital means, with two narrow exclusions.
- Sections 8 and 8A · process only for the purpose lawfully set; register only where the section 8A thresholds are met.
- Sections 11, 13 and 14 · notice on collection, access in Hebrew, Arabic or English, and correction or deletion.
- Sections 17 and 17B1 · security duties on controller and holder alike; a Data Protection Officer where a listed trigger applies.
- Section 29A · up to 50,000 shekels compensation without proof of damage, and up to double where intent to harm is proved.


