Compliance · Israel
Protection of Privacy Law, 5741-1981 Amendment 13, effective August 2025

Israeli Privacy Law & Amendment 13

Plain-English definition

Amendment 13 is not a standalone law. It's a 2024 reform of Israel's existing Protection of Privacy Law (1981) that significantly expands enforcement powers, breach-notification duties, and database-registration obligations. If your organization processes personal data of Israeli residents, both the base law and this reform apply to you.

Covers the base law's general framework and the specific Amendment 13 reform, not amendment-only shorthand.

Who needs it

Any organization, Israeli or foreign, that collects, stores or processes personal data belonging to individuals in Israel, regardless of where the organization itself is based.

Key requirements

Data breach notification to the Privacy Protection Authority, expanded data-subject rights, database registration updates, and materially increased penalties for non-compliance.

Cyber/privacy implications

Security controls must now be demonstrably mapped to specific data classes, with evidence trails the regulator can request directly, not just an internal policy document.

Assessment methodology

Data-flow mapping, database classification review, breach-response readiness test, and a gap analysis against the Authority's current enforcement guidance.

Implementation phases

01
Assess

Map data flows and databases; identify regulated personal data.

02
Remediate

Close control gaps; update breach-response and notification procedures.

03
Evidence

Document controls and maintain an audit-ready evidence trail.

Evidence & documentation requirements

Database registration records, data-processing agreements, breach-response logs, and documented data-subject request handling, all reviewable on demand by the Privacy Protection Authority.

Common mistakes

Treating this as a one-time compliance project rather than an ongoing obligation; assuming GDPR compliance automatically satisfies Amendment 13 (the two regimes overlap but are not identical); under-scoping which databases count as "regulated."

Related standards

Expert review

Nitzan Levi
Nitzan Levi
Co-Founder, Cybecs · Co-Founder, RedRok · Executive Director, Privacy & GRC · CISM, CISSP, CDPSE, CCSK, CSA

FAQ

Does this apply if my company isn't based in Israel?
Yes, if you process personal data belonging to individuals in Israel, regardless of where your company is headquartered.
How is this different from GDPR?
Overlapping principles, but distinct notification timelines, regulator, and enforcement mechanism, so compliance with one doesn't automatically satisfy the other.

Request a Gap Assessment

See exactly where your data handling stands against Amendment 13 before a regulator asks.

Request a Gap Assessment →