How a US Company Closed an Israeli Data Breach File Without a Fine
A Denver retailer's vendor leaked 38,000 Israeli customer records. Israeli law wanted notice immediately, not after the forensics. How the Authority file closed with no penalty.
Outcome
We notified the Privacy Protection Authority within 31 hours, ran the Hebrew notification to the affected customers, and the Authority closed its file with a supervisory letter and no financial sanction against an exposure that reached NIS 320,000 in administrative penalties alone.
Result: Privacy Protection Authority file closed with a supervisory letter and no financial sanction, and the threatened class action never filed ยท Timeline: Five months from discovery to closure, with the first Israeli notice inside 31 hours ยท Challenge: Israeli law demanded immediate notice while US counsel wanted the forensics first ยท Authority: Privacy Protection Authority (Rashut LeHaganat HaPratiyut) ยท Financial Impact: NIS 320,000 of administrative exposure avoided for NIS 96,000 of Israeli legal and translation cost
Background
The client sells outdoor equipment online from a warehouse outside Denver. No Israeli company, no Israeli office, no Israeli server, no employee who has ever been to Israel. What it does have is nine years of shipping to Israeli addresses and a customer table with 38,000 Israeli buyers in it, built up through a Hebrew language checkout page and a very effective affiliate in Tel Aviv.
On a Thursday in March 2026 an engineer noticed that a storage bucket belonging to their email marketing vendor had been readable without authentication for at least eleven days. The exported table held names, delivery addresses, telephone numbers, email addresses, order histories and the last four digits of payment cards. Their outside counsel in Denver gave the advice that US counsel almost always gives, and which is correct in the United States: retain a forensic firm, establish scope, and do not notify anybody until you know what you are saying. Their state notification clocks allowed for that. Israel's did not.
The general counsel found our firm on a Sunday, which in Israel is a working day, roughly forty hours after the exposure was confirmed.
The Challenge
The threshold question was whether Israeli law reached a Colorado company at all, and it does. The Privacy Protection Law 5741-1981 is built around the database rather than around an establishment, and a collection of personal data on Israeli residents is an Israeli database whether the servers sit in Oregon or in Petah Tikva. Amendment 13, in force since 14 August 2025, did not widen that reach. It changed what happens when the reach bites, because it handed the Privacy Protection Authority direct administrative fines in place of a criminal referral that in practice never came.
The specific duty was the hard part. Regulation 11(d)(1) of the Privacy Protection Regulations (Data Security) 5777-2017 requires the owner of a database subject to the medium or high security level to notify the Authority immediately of a serious security incident, and to report the steps taken in consequence. For a high level database that means any use of data from the database without authorisation or in excess of authorisation, or any harm to the integrity of the data. For a medium level database the duty is triggered where the unauthorised use or the harm concerned a substantial part of the database. This one was the whole table. The Authority has since narrowed its own reading of the word immediately, stepping back from an earlier position that treated it as a fixed clock of 24 hours from discovery and in any event no later than 72 hours, but nothing in that retreat helps a company that waits three weeks for a forensic report.
Two other exposures sat behind the notification duty. The first was administrative. Breaches of the Data Security Regulations carry fines in bands running from NIS 20,000 to NIS 320,000 according to the security level applicable to the database, with the overall administrative ceiling under Amendment 13 reaching up to 5 percent of annual turnover for the most serious cases. The second was civil, and for a consumer business it is the sharper of the two. Section 29A of the Privacy Protection Law lets an Israeli court award compensation for infringement of privacy without proof of any damage, up to NIS 50,000, and up to double that where the infringement was made with intent to harm. Section 15A separately allows exemplary damages of up to NIS 10,000, again without proof of damage, for specified breaches of the database chapter. Multiply either figure across 38,000 people and package it as a class action under Item 1 of the Second Schedule to the Class Actions Law 5766-2006, which covers a claim against a dealer in a matter between the dealer and a customer, and the arithmetic stops being theoretical.
In Practice: Regulation 11(d)(1) of the Privacy Protection Regulations (Data Security) 5777-2017 obliges the owner of a medium or high level database to notify the Privacy Protection Authority of a serious security incident immediately, and to report the remedial steps taken. Administrative fines for data security breaches run in bands from NIS 20,000 to NIS 320,000 by security level, with registration and notification failures at NIS 150,000, doubling to NIS 300,000 for a database of more than one million data subjects. We filed our client's notice 31 hours after unauthorised access was confirmed, which is the single fact the Authority returned to at every stage of the file.
What We Did
The first call lasted an hour and produced one decision: notify now, investigate in parallel, and accept that the first notice would be incomplete. That is uncomfortable for American management, because a notice you may have to correct feels like an admission you have not finished thinking. Under Regulation 11(d)(1) an incomplete notice filed immediately is the compliant outcome and a complete notice filed in three weeks is not.
We filed the notice on the Monday, in Hebrew, through the Authority's reporting channel, setting out what was known: the vendor, the bucket, the eleven day window, the fields exposed, the approximate number of Israeli data subjects, and the containment already carried out. We said plainly that scope was still being established and undertook to supplement. That is the second half of the regulation and it is the half people forget, because the duty is not only to notify but to report the steps taken.
Then we classified the database properly, which nobody in Denver had done. The security level is not a matter of self description. It turns on the nature of the data, the number of data subjects and the number of people with access. With 38,000 Israeli data subjects, contact details, purchase histories and truncated card data, the database sat at the medium level, and the breach plainly touched a substantial part of it. Getting that classification recorded early mattered, because the fine bands are keyed to the level and a company that has never thought about the question tends to be assessed at the level the regulator picks.
The Authority came back within nine days with a written enquiry: eleven questions on the vendor relationship, the contractual data security terms, the retention period for the exported table, and whether the Israeli data subjects had been told. We answered inside the deadline with the forensic report attached, which by then had established that the bucket had been accessed by three external addresses, all of them from commercial scanning services, with no evidence of bulk download.
On the customer notification we did not wait to be ordered. The Authority can direct that data subjects be notified, and being directed to do something you could have done voluntarily reads badly in a file that may end in a penalty decision. We drafted a Hebrew notice, sent it to all 38,000 Israeli addresses within three weeks of discovery, and made it a real notice rather than a reassurance exercise: what was exposed, what was not, the eleven day window, what the company had done, and a named contact who answered in Hebrew.
The remediation package was the last piece. The vendor contract was rewritten with Israeli data security terms, the export routine that had created the file was removed, retention was cut to eighteen months, and the company appointed a privacy point of contact for its Israeli database. It does not control a registrable database, since after Amendment 13 registration is confined largely to databases whose main purpose is trading in personal data on 10,000 people or more and to public bodies, and its core activity is retail rather than monitoring, so the Data Protection Officer duty under Section 17B1(a) was not engaged. We said so in writing rather than leaving the question open.
In Practice: Under Section 29A of the Privacy Protection Law 5741-1981 an Israeli court may award compensation for infringement of privacy without proof of damage up to NIS 50,000, and up to NIS 100,000 where the infringement was committed with intent to harm, while Section 15A allows exemplary damages up to NIS 10,000 without proof of damage for specified database breaches. Certification of a consumer class action in the District Court commonly takes 12 to 24 months before the merits are reached, and a claimant needs no cooperation from the foreign defendant to start the clock. Across 38,000 Israeli customers the Section 15A figure alone frames a headline exposure well beyond any administrative fine, which is why the file the regulator builds becomes the defence document in the civil claim.
The Outcome
The Authority closed its file in August 2026 with a supervisory letter and no financial sanction. The letter recorded the timing of the notice, the voluntary notification of data subjects, and the remediation, and it set out expectations for vendor management going forward. Against a data security band that reached NIS 320,000 before any consideration of turnover, and against the civil arithmetic sitting behind it, the Israeli side of the incident cost the company NIS 96,000 in legal fees, Hebrew drafting and translation.
A letter of claim from an Israeli plaintiff firm arrived in June, addressed to the Denver office in English, announcing an intention to file a certification motion. We answered it with the Authority correspondence, the notification record and the forensic finding that no bulk download had occurred. No motion was filed. That is not a guarantee about the seven year window in which a claim could still be brought, and we told the client so, but a file in which the regulator has documented prompt notice and voluntary remediation is a poor candidate for a certification motion when there are better ones available.
Key Takeaways
What this case illustrates for foreign companies in similar situations:
- The Israeli clock is not the American clock. Regulation 11(d)(1) of the Data Security Regulations 5777-2017 requires immediate notice of a serious security incident, and a US state notification window measured in weeks gives no shelter at all. File an incomplete notice on time and supplement it.
- Reach follows the database, not the entity. A Colorado company with no Israeli presence still owns an Israeli database when it holds personal data on Israeli residents, and Amendment 13 gave the Authority the tools to act on that in a way it previously lacked.
- Classify the security level before you need it. The fine bands and the trigger for the notification duty both key off the level, and a company that has never made the assessment gets assessed at the level the regulator chooses.
- Notify the data subjects before you are told to. The Authority can direct it, and a direction in the file changes the tone of everything that follows. Do it in Hebrew, with a named contact who can answer in Hebrew.
- The regulator file becomes the litigation file. Statutory damages under Sections 15A and 29A need no proof of loss, so the class action risk is driven by the record of how you behaved rather than by how much harm anyone suffered. Our guide to Israel's Privacy Law Amendment 13 for foreign companies works through the standing obligations that sit behind the incident response.
Facing a Similar Situation?
If your company holds personal data on Israeli residents and something has gone wrong with it, the first 48 hours decide most of what follows, and they are governed by an Israeli rule rather than by the one your usual counsel is applying.
Contact us for a confidential consultation about your Israeli legal matter.
Key Takeaways for Non-Residents
This case illustrates the importance of engaging experienced Israeli legal counsel early in the process. The complexity of cross-border matters โ including language barriers, document requirements, and court procedures โ makes professional guidance essential.
Related Q&A

Adv. Eli Shimony
Israeli Attorney
Adv. Eli Shimony is the founder of IsraelNonResident.com and a practising Israeli attorney specialising in inheritance, real estate, and cross-border legal matters for non-resident clients worldwide.
Note: This case study is based on a real matter. All identifying details โ including names, locations, nationalities, and financial figures โ have been anonymized and modified to protect confidentiality. The outcome described reflects the specific facts of that particular case and does not constitute a guarantee, representation, or warranty of any result in any other matter. Legal outcomes are inherently fact-specific and depend on individual circumstances, applicable law at the time, and factors that vary from case to case. Nothing in this case study constitutes legal advice, and it should not be relied upon as a substitute for qualified legal counsel in any specific situation. See our full disclaimer.