Frameworks / Israel
Amendment 13 (Israeli Privacy Law)
Amendment 13 is the most significant overhaul of Israeli privacy law in decades: it hands the Privacy Protection Authority real administrative enforcement powers, and it makes the appointment of a Data Protection Officer and of an information security officer a legal duty for defined categories of organisation.
What it requires
Amendment 13 was passed by the Knesset in August 2024 and entered into force on 14 August 2025. It substantially expands the enforcement powers of the Privacy Protection Authority (PPA), including investigative powers and the ability to impose significant administrative financial sanctions calculated by reference to the nature of the violation and the scale of the database, replacing an enforcement regime that was previously largely toothless. It creates a statutory duty to appoint a Data Protection Officer (DPO) for defined categories of organisation (including public bodies, data brokers, and controllers whose core activity involves large-scale processing of highly sensitive personal data) and a duty to appoint an information security officer for defined categories of database holders, alongside the pre-existing obligation under the Privacy Protection (Data Security) Regulations, 5777-2017. It narrows the long-standing database registration requirement, replacing blanket registration with notification and registration duties for defined higher-risk categories, and it modernises definitions (including the treatment of highly sensitive information), moving Israeli law closer to the GDPR in structure and vocabulary. The Data Security Regulations of 2017 remain the operative security baseline: databases are classified by security level, and higher-level databases carry heavier obligations including a database definition document, access control and logging, periodic risk surveys and penetration testing, and incident reporting to the PPA.
Amendment 13 applies to organisations processing personal data in Israel (controllers, database holders and processors), with obligations scaling by the sensitivity and volume of the data. Israeli mid-market companies in healthcare, fintech, insurance, HR-tech, and any business holding large customer databases are squarely in scope. The practical trigger is twofold: the PPA now has the power to fine, and Israeli enterprise customers have begun writing Amendment 13 compliance into their vendor contracts, so the requirement arrives from both the regulator and the buyer.
The controls people actually fail
- No DPO appointed, or the title given to someone who already runs IT or legal operations, creating a conflict of interest and no real independence or reporting line to management.
- The database definition document required by the 2017 Data Security Regulations does not exist, or was written years ago and no longer describes the systems, the data, or the people who have access.
- Access to the database is not restricted or logged as the regulations require: shared admin accounts, no periodic review of who holds access, and no ability to reconstruct who accessed what.
- No periodic risk survey or penetration testing for databases at the higher security levels, or the tests were run once at project launch and never repeated.
- Data security incidents are not reported to the Privacy Protection Authority as required, because there is no internal process for recognising that an incident meets the reporting threshold.
- Outsourcing arrangements have no data security terms: third parties hold or process the database with no written agreement covering security, access, retention or return of the data.
- The organisation assumed the old registration-based regime still governs everything, and has not reassessed its obligations against the amended law.
When did Amendment 13 come into force?
Amendment No. 13 to the Protection of Privacy Law was passed by the Knesset in August 2024 and entered into force on 14 August 2025, following a transition period intended to let organisations prepare. The Privacy Protection Authority's expanded enforcement and sanctioning powers apply from that date.
Does Amendment 13 require us to appoint a DPO?
It requires a Data Protection Officer for defined categories of organisation, including public bodies, entities whose business is data brokerage, and controllers whose core activity involves processing highly sensitive personal data at large scale. It also carries a duty to appoint an information security officer for defined database holders, which sits alongside the security-officer obligations under the Privacy Protection (Data Security) Regulations, 5777-2017. The DPO must have appropriate expertise, must be able to act without conflict of interest, and may be an external appointment, which is how most mid-market companies satisfy the requirement, since the role demands independence that an internal IT or legal owner usually cannot provide.
How does Amendment 13 compare to the GDPR?
Amendment 13 deliberately moves Israeli law toward the GDPR: comparable roles (DPO), comparable emphasis on the controller's accountability, modernised definitions of sensitive data, and, critically, an enforcement authority with the power to impose meaningful administrative fines. It is not a copy. Israeli law retains its own database-centric structure, its own registration and notification duties, and the Data Security Regulations of 2017 as the operative security baseline with their tiered security levels. A company already GDPR-compliant has a substantial head start but is not automatically compliant with Amendment 13, and vice versa.
What are the penalties under Amendment 13?
The amendment gives the Privacy Protection Authority the power to impose administrative financial sanctions that are, by design, far more substantial than the previous regime, with the amount driven by factors such as the severity and duration of the violation and the size of the database concerned. Exact figures depend on the specific violation and the statutory calculation, and are the subject of PPA guidance: the material shift is not any single number but that meaningful monetary enforcement now exists at all, alongside investigative powers and the authority's ability to compel corrective action.