Amendment No. 13 to the Privacy Protection Law: The New Requirements Every Company Must Know

On August 14, 2025, Amendment No. 13 to the Privacy Protection Law (hereinafter: "The Law") – the most significant change made to Israeli law in the field of personal information processing since the law was enacted in 1981. The amendment anchors the core privacy principles practiced in Europe and worldwide for the first time, while simultaneously granting the Privacy Registrar extensive and significant enforcement powers, including the imposition of financial sanctions.

Starting from the effective date of the amendment, any organization that manages personal information – of customers, suppliers, employees – is required to comply with the new legal requirements. Here are some key points of the amendment:

1.Expanding enforcement powers – and heavy fines – For the first time, the Privacy Protection Authority is authorized to impose High financial sanctions Organizations that violate laws and regulations in the field of information security. Additionally, criminal investigation powers have been expanded, and the possibility of appealing to the court for a judicial order to stop/delete personal data processing has been established. The implication: The responsibility for information security in an organization is Must Carries significant economic and legal weight.

2. Mandatory Appointment of a Privacy Officer – The Obligation Applies to the Following Entities:

    • Public organizations (excluding security bodies).
    • Companies that process extensive sensitive personal information (such as banks, hospitals, etc.).
    • Companies engaged in processing personal information for the purpose of transferring it to others as a business or in exchange for payment, and which operate a database of over 10,000 individuals.
    • Companies that continuously and systematically track a person's behavior, location, or activities (such as tracking location data).

    The ombudsman's role is to ensure compliance with legal instructions, promote the implementation of internal policies and procedures, provide ongoing guidance to management and employees, serve as the organization's point of contact with the Privacy Protection Authority, and more.

    3. Database registration and notification obligation reduction The obligation to register databases of private entities has been almost entirely abolished. Those who are required to register a database are:

    • Public body
    • Companies engaged in processing personal information for the purpose of transferring it to others as a business or in exchange for payment, and which operate a database of over 10,000 individuals.

    However, the amendment includes a new requirement for reporting to the Privacy Protection Authority. A controller of a database containing "particularly sensitive information," as defined by law, and which holds information on more than 100,000 individuals, is required to notify the Authority of their identity, address, contact details, the identity of the person responsible for data protection, and more., Despite not being required to register.

    4. Defining new criminal offenses for processing illegally collected personal information –  As part of the amendment, a dedicated chapter was added to the law defining criminal offenses in the field of databases. Among other things, this includes the processing of personal information without the authorization of the database controller and misleading a person in order to obtain personal information about them. In addition, it was determined Sweeping prohibition For any use of personal information collected illegally.

    5. Expanded jurisdiction of courts to award damages The courts have received broader authority to award monetary compensation, up to NIS 10,000, for a citizen who was harmed by a violation of the law, even without proof of damage, by virtue of additional grounds provided in the law.

    Summary:

    Preparing for the entry into force of Amendment No. 13 to the law is critical, as non-compliance with the law's requirements may lead to significant financial penalties, damage to the company's reputation, and even exposure to criminal proceedings.

    What do you need to do?

    • Examine whether your organization has databases that require registration/reporting.
    • Examine whether there is an obligation to appoint a data protection officer. If so, ensure their appointment as soon as possible.
    • All privacy and information security procedures must be updated in accordance with the new legal instructions.
    • All managers and employees must be updated on the new guidelines.

    Our firm accompanies and guides companies in the process of preparing for Amendment No. 13, including providing ongoing legal counsel, drafting procedures and privacy policies, updating agreements, and implementing the legal mechanisms required in accordance with the nature of the organization's activity. If you have not yet organized yourselves – now is the time to act. We would be happy to be at your service.

    Did you like the article?

    Share on Facebook
    Share on Twitter
    Share on LinkedIn

    Leave a comment

    More articles

    Accessibility Toolbar

    Your referral is on its way to us.
    Talk to you soon

    For legal advice