Company FormationUpdated August 24, 2026·8 min read

Israel's Privacy Law Amendment 13: Foreign Companies

How Israel's Privacy Protection Law after Amendment 13 reaches foreign companies holding Israeli data: the fines, the DPO rule, registration, and breach reporting.

Adv. Eli Shimony

Adv. Eli Shimony

Israeli Attorney

Foreign businesses tend to treat Israeli privacy law as somebody else's problem, right up to the day an Israeli customer sends a demand letter citing a statute nobody in the company has read. The awkward reality is that Israel rebuilt its privacy regime, the new rules took effect on 14 August 2025, and they hang on where the data subjects live rather than on where the server or the company sits. A retailer in Manchester, a SaaS provider in Austin, and an insurer in Sydney can all fall inside the same law without ever setting foot in Israel.

This guide is written for owners and managers of companies outside Israel that hold data on Israeli residents. It explains when Amendment 13 catches you, what it now costs to get it wrong, and the handful of duties that trip up a business with no Israeli entity to lean on.

Why a Foreign Company Is Caught at All

The Privacy Protection Law 5741-1981 has always been drafted around a database, not around a company's nationality. A collection of personal data on Israeli residents is an Israeli database for these purposes whether the controller is registered in Delaware, London, or Sydney. That single design choice is why the law reaches across borders. If you hold a customer list, a mailing list, an app's user records, or an employee file that includes Israeli residents, you are holding an Israeli database, and the statute follows the people rather than the paperwork.

What changed with Amendment 13 is not that reach. It is what happens when the reach bites. Before the amendment the Privacy Protection Authority was largely a supervisory body whose heavy weapon was a criminal referral, which meant that in practice almost nothing happened to anyone. The amendment handed the Authority direct administrative fines and a broader civil exposure behind them, and that is the shift a foreign company needs to absorb.

What Amendment 13 Changed

The amendment kept the old database architecture and rebuilt the enforcement machinery on top of it. The Privacy Protection Authority now imposes fines itself, without going to court first, calibrated to the size and sensitivity of the database and to the nature of the breach. It also modernised the definitions, widening what counts as especially sensitive information and tightening the security duties that attach to it. For a company used to the pre-2025 quiet, the practical message is that the regulator finally has teeth and has started to use them.

In Practice: Amendment 13 to the Privacy Protection Law 5741-1981 took effect on 14 August 2025. The Privacy Protection Authority now levies administrative fines directly, running to roughly NIS 320,000 per data security violation and into the millions of shekels for database and governance failures, scaled by the size and sensitivity of the database. The Authority allowed a grace period to 31 October 2025 before enforcing the new Data Protection Officer requirement, so the enforcement window is already open rather than years away.

The Fines, and the Claim That Matters More

The administrative fines are the headline, but for a foreign defendant the civil route is often the sharper risk. Amendment 13 lets an Israeli claimant sue for statutory damages without proving any actual loss, which changes the economics of a complaint completely. A single upset customer is a nuisance. The same claim multiplied across a customer list, packaged as a class action, is a serious number, and it does not depend on anyone showing that they were harmed.

In Practice: Under Section 29A of the Privacy Protection Law 5741-1981, an Israeli court may award statutory damages without proof of loss, which Amendment 13 set at up to NIS 10,000 per violation. Across a database of thousands of Israeli residents, a class action aggregates those awards quickly, and certification of a privacy class action in the District Court typically takes 12 to 24 months. Unlike the regulator, a class claimant needs no cooperation from you and no Israeli filing of your own to get started.

Two Duties That Catch Foreign Companies Off Guard

The first is registration, and the surprise is that it shrank. Most ordinary customer databases no longer need to be registered at all. Registration now bites on databases whose main purpose is commercialising personal data on 10,000 or more individuals, and on public-body databases. If your business is selling or trading data on Israelis at scale, registration is live; if you merely hold customer records to run your own service, it usually is not.

The second duty reaches further than registration does. The obligation to appoint a Data Protection Officer (in Hebrew, memuneh al haganat hapratiyut) binds three groups: controllers of registrable databases, bodies whose core activity involves regular and systematic monitoring of individuals at significant scale, and controllers or processors whose main business is handling highly sensitive data at scale. That last category sweeps in health, financial, and insurance operations that never thought of themselves as Israeli at all. A foreign health-tech company with Israeli users can owe a DPO duty even though it owes no registration duty.

For a company with no Israeli entity, the hard questions are procedural rather than substantive. How does the Authority serve a notice at a foreign address? How does a breach get reported to a regulator in a different time zone inside the period the regulations allow? Who signs the Hebrew filings? Companies that already hold an Israeli subsidiary or a payroll presence should treat that as the natural anchor for compliance, and the structuring choice is set out in our comparison of a foreign company branch and an Israeli subsidiary.

Breach Reporting Across a Time Zone

The reporting duty is where the new enforcement has actually landed. The Data Security Regulations 5777-2017 require the controller of a database to report a serious security incident to the Privacy Protection Authority, and the clock runs from the moment the incident is discovered, not from the moment lawyers finish arguing about it. A company scattered across offices in three countries can lose the reporting window simply because the discovery happened on a Friday afternoon in one place and the Israeli deadline expired before anyone in the right seat was awake.

Common Mistake: Treating an Israeli data breach as a matter to investigate fully before reporting. On 21 July 2026 the Privacy Protection Authority fined a health fund NIS 256,000 for reporting a data security incident late under the Data Security Regulations 5777-2017, its first penalty aimed specifically at the notification duty. The case shows the Authority prosecuting timing rather than the breach itself, so a foreign company that waits to gather every fact before notifying can be penalised even where the underlying incident was minor. Report inside the regulatory window first, then complete the investigation.

The EU Adequacy Backdrop

There is a strategic reason the reform happened when it did. Israel holds a European Commission adequacy decision, which lets personal data flow from the EU to Israel without extra safeguards, and that status depends on Israel keeping a regime the EU regards as broadly equivalent. Amendment 13 was, in part, a modernisation to protect that alignment. For a foreign company the useful takeaway is that a mature GDPR programme is a good base to build from, because the vocabulary and the instincts overlap. It is only a base, though. The Israeli law attaches to a database rather than to a processing activity, hands claimants statutory damages without proof, and expects its filings in Hebrew, so a GDPR file cannot simply be relabelled and filed in Tel Aviv.

Practical Steps for a Company With No Israeli Entity

Start by mapping which of your systems actually hold data on Israeli residents, because nobody can say whether a registration or DPO duty bites until the scope is known. Decide, on that map, whether you cross the 10,000-person commercialisation threshold or fall into one of the DPO categories. If you have any Israeli corporate footprint, use it as the compliance anchor and the address for service; if you do not, work out in advance who is authorised to sign a Hebrew filing and who reports a breach on an Israeli timeline. A company considering its first Israeli presence for exactly these reasons will find the mechanics in our guide to registering a company in Israel as a foreigner.

Practical Checklist

  • Map every system that holds personal data on Israeli residents, including employee and contractor records.
  • Decide whether your database is mainly for commercialising data on 10,000 or more people, which triggers registration.
  • Test whether you fall into a DPO category: registrable database, systematic monitoring at scale, or sensitive data at scale.
  • Build a breach-reporting process that meets the Israeli deadline from the moment of discovery, across time zones.
  • Nominate, in advance, who signs Hebrew filings and correspondence with the Privacy Protection Authority.
  • If you have an Israeli subsidiary or branch, make it the compliance anchor and the address for service.
  • Treat any demand letter claiming statutory damages seriously; these claims are cheap to bring and need no proof of loss.

Speak With an Israeli Attorney

Amendment 13 turned a dormant regime into an enforced one, and the hardest parts for a foreign company are procedural: scope, Hebrew filings, and a reporting clock that runs on Israeli time. We assess whether your database falls inside the Israeli regime, handle registration and DPO questions for a company with no Israeli entity, and manage breach reporting and Authority correspondence.

Contact us for a confidential initial consultation.

Frequently Asked Questions

Very likely yes. The Privacy Protection Law 5741-1981 is built around the concept of a database, and a collection of personal data on Israeli residents is an Israeli database whether the company sits in Delaware, London, or Sydney. Amendment 13 kept that architecture and sharpened enforcement, so a foreign company that markets to Israeli consumers can be caught even with no Israeli entity.

Related Questions

Common questions on this topic answered by our attorneys.

Real Case Studies

How non-residents resolved similar situations with our help.

Related Guides

About the Author

Adv. Eli Shimony

Adv. Eli Shimony

Israeli Attorney

LL.B. + M.B.A.Israeli Bar Association MemberCertified Compliance Officer (ICA)Certified Mediator & Arbitrator

Adv. Eli Shimony is the founder of IsraelNonResident.com and a practising Israeli attorney specialising in inheritance, real estate, and cross-border legal matters for non-resident clients worldwide.

Legal Disclaimer: The information on this page is provided for general informational purposes only and does not constitute legal advice. Israeli law is complex and fact-specific. Always consult with a qualified Israeli attorney before taking any action regarding your specific situation. See our full disclaimer.