Israel
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked today.
The answer
Israeli data can go abroad, but never by default. Either the destination country protects data as well as Israel does, or you fit one of eight listed exceptions — usually a contract in which the receiver promises to follow Israeli rules. A big reform started on 14 August 2025 and the regulator now issues real fines. No industry bans exports outright, but several add heavy conditions.
Eight questions about Israel
The questions a team asks when they are deciding where to store their users' data. Every country on this site answers the same eight, in the same order.
Do Israel's rules apply to my company?
Yes, it can reach a foreign company with no office in Israel — but the law never says so in words. Israeli privacy law simply applies to anyone who collects, uses or processes personal data, with no size or revenue threshold to fall under. There is no general requirement to appoint a local representative. Some organisations must appoint a privacy officer, and that person is allowed to be an outside contractor rather than a staff member.
Unlike Europe's General Data Protection Regulation, Israel's Protection of Privacy Law 5741-1981 contains no express territorial-scope article. The Privacy Protection Authority's own professional guide on Amendment 13 (August 2025) states only that the law applies to anyone who collects, uses or processes personal data, public or private, excluding a private collection not held for business or public purposes. Reach over foreign entities therefore rests on interpretation rather than statutory text — the Authority's binding opinion of April 2026 on transfers abroad notes in a footnote that there may be databases located abroad that are subject to the whole of Israeli law even though their controllers are not registered in Israel. The Authority has previously opened an investigation into Facebook (2018). Duty to appoint a Data Protection Officer under Article 17B1 attaches to public bodies, data brokers holding data on more than 10,000 people, organisations whose core activity involves regular and systematic monitoring of people (search engines and mobile operators are named), and organisations processing specially sensitive data at significant scale (banks, insurers, general hospitals and health funds are named). A separate and older role, the Data Security Officer under Article 17B, applies to controllers of five registrable databases, public bodies, banks, insurers and credit-rating firms.
Sources
- Official sourcePrivacy Protection Authority, Ministry of JusticePrivacy Protection Law, 5741-1981, text updated after Amendment 13 — Articles 8A, 17B and 17B1
gov.il
“The following entities are required to appoint a data protection officer: (1) A database controller that is a public body ... (3) A database controller or processor whose core activities consist of data processing operations ... which ... require regular and systematic monitoring of individuals”
Link checked 18 August 2026
- Official sourcePrivacy Protection AuthorityProfessional guide to Amendment 13 to the Privacy Protection Law, section headed 'Application'
gov.il
Link checked 18 August 2026
- Official sourcePrivacy Protection AuthorityBinding opinion on transferring personal data outside Israel — interpretation of Regulation 2(4), footnote 2
gov.il
Link checked 18 August 2026
Can I store my users' data outside Israel?
Yes, with paperwork — and you must be able to name the route you are using. The default rule is that data may only go to a country whose law protects it at least as well as Israeli law does. If the destination fails that test, you have to fit one of eight listed exceptions, and whichever route you take you also need a written promise from the receiver. No Israeli industry has a flat 'the data stays here' rule, but four sectors bolt extra conditions on top.
Sector by sector, verified on 18 August 2026. BANKING (conditional): Bank of Israel Proper Conduct of Banking Business Directive 362, current version dated 17 June 2026, section 7 — a bank may not store, transfer or process information it classifies as sensitive on a cloud outside Israel unless it has ascertained the provider's protection level complies with the European General Data Protection Regulation. Section 38 adds a duty to plan for the foreign region becoming unavailable through geopolitical events. INSURANCE AND PENSIONS (conditional plus reporting): Capital Market, Insurance and Savings Authority institutional-bodies circular 2018-9-35 on outsourcing requires a board-level outsourcing policy dealing specifically with activity performed outside Israel or with a provider located outside Israel, an assessment of the consequences of the activity being performed abroad, an annual return to the Commissioner listing every outsourcing arrangement with a yes/no field for whether it is offshore, and immediate reporting of exceptional events. HEALTH (conditional on geography, closed on organisational control): Ministry of Health Director-General circular 2/2021 on cloud computing in the health system, section 6.5, permits cloud in a country that satisfies the transfer regulations, but circulars 1/2018 and 2/2018 on secondary use of health data require that identifiable patient data used for research stays inside a secure environment within the health organisation, and any release outside the organisation's control needs Helsinki-committee approval plus a destruction undertaking. GOVERNMENT (closed in practice): the state's own cloud landing zone was deliberately migrated out of an overseas public cloud into the new Israeli region as soon as it opened, under Project Nimbus. SECURITIES, TELECOMS, EDUCATION, GAMING, GEOSPATIAL AND DEFENCE: no data-residency rule found on an Israeli government source, checked 18 August 2026, confidence medium. The National Cyber Directorate's own published map of cyber regulation records that the Ministry of Communications has not yet issued cyber rules for telecoms operators at all.
Sources
- Official sourcePrivacy Protection Authority, Ministry of JusticePrivacy Protection (Transfer of Data to Databases Abroad) Regulations, 5761-2001, Regulations 1 to 3
gov.il
“A person shall not transfer, nor shall he enable, the transfer abroad of data from databases in Israel, unless the law of the country to which the data is transferred ensures a level of protection no lesser, mutatis mutandis, than the level of protection of data provided for by Israeli Law”
Link checked 18 August 2026
- Official sourceBank of Israel, Banking Supervision DepartmentProper Conduct of Banking Business Directive 362 — Cloud Computing, version in force from 17 June 2026, section 7
boi.org.il
Link checked 18 August 2026
- Official sourceCapital Market, Insurance and Savings AuthorityInstitutional Bodies Circular 2018-9-35 — Outsourcing in institutional bodies, 31 December 2018
gov.il
Link checked 18 August 2026
- Official sourceMinistry of HealthDirector-General Circular 2/2021 — Use of cloud computing in the health system, 21 February 2021, section 6.5
gov.il
Link checked 18 August 2026
- Official sourceIsrael National Cyber Directorate / National Digital AgencyIsrael's government moves to the cloud — Project Nimbus; the government landing zone was moved from an overseas public cloud to the local Israeli region
gov.il
Link checked 18 August 2026
- Official sourceIsrael National Cyber DirectorateRegulation in the field of cyber protection — sector-by-sector map; telecoms cyber regulation recorded as not yet published
gov.il
Link checked 18 August 2026
What do I need in place before data leaves Israel?
The model is closest to an allowlist: you may not send data out unless the destination qualifies, and the qualifying list is already populated. It counts if the country signed the Council of Europe data protection convention, or if it receives data from European Union countries on the same terms — so Europe's approved-country list does much of the work. If your destination does not qualify, the usual fallback is a contract in which the receiver promises to meet Israeli standards. Either way you also need a separate written promise from the receiver that it will protect the data and pass it to nobody else.
Regulation 1 of the Transfer of Data to Databases Abroad Regulations 5761-2001 sets the adequacy test. Regulation 2 lists eight alternatives: the person's consent; a vital health interest where consent cannot be obtained; transfer to a corporation under the transferor's control that has guaranteed privacy; transfer to a party contractually bound to comply with the conditions applying to a database in Israel, with necessary modifications; data already lawfully public; transfer vital to public safety or security; transfer required by Israeli law; and transfer to a country that is party to the Council of Europe convention, or that receives data from European Community member states under the same terms of acceptance, or that the Registrar has announced in the official gazette has a privacy authority with which a cooperation arrangement has been reached. Regulation 3 imposes the written guarantee on top of whichever route is used, including a promise not to onward-transfer. On 9 April 2026, updated 30 April 2026, the Privacy Protection Authority published its final binding opinion on what 'with necessary modifications' means in the contract route. The contract must bind the receiver to: purpose limitation; the right of access under Article 13; the right of correction or deletion under Article 14; and the confidentiality duty under Article 16. On security, the receiver must undertake to meet the substantive obligations of the Data Security Regulations 5777-2017, or alternatively declare it holds ISO/IEC 27001 certification including the Annex A controls and undertakes the specific regulations listed in the Authority's Guideline 3/2018. The Authority accepts that the Israeli database registration and notification duties need not be replicated abroad where the destination has no comparable duty. Critically, the opinion also confirms that where the Israeli database also holds data that arrived from the European Economic Area, the foreign receiver must additionally undertake Regulations 3 to 7 of the 2023 European Economic Area regulations.
Sources
- Official sourcePrivacy Protection AuthorityFinal binding opinion on transferring personal data outside Israel — interpretation of Regulation 2(4), published 9 April 2026, updated 30 April 2026
gov.il
Link checked 18 August 2026
- Official sourcePrivacy Protection AuthorityOpinion text — contract must mirror Articles 2(9), 8(b), 13, 14 and 16, plus the Data Security Regulations or ISO/IEC 27001
gov.il
Link checked 18 August 2026
- Official sourcePrivacy Protection Authority, Ministry of JusticeTransfer of Data to Databases Abroad Regulations 5761-2001, Regulation 2(8) and Regulation 3
gov.il
“the owner of the database shall ensure, in a written guarantee by the recipient of the data, that recipient of the data is taking adequate measures to ensure the privacy of the data subjects, and that he guarantees that the data shall be transferred to no other person”
Link checked 18 August 2026
Who enforces the rules in Israel, and what can they do?
The Privacy Protection Authority, part of the Ministry of Justice, and it is fully operational. It has a serving commissioner, an administrative enforcement department, and it publishes its decisions with names and amounts. In 2026 it fined a national health fund about 256,000 shekels (roughly $72,000) for taking two months to report a security incident, and a small leisure company about 12,000 shekels (roughly $3,400) for a defective privacy notice. Industry regulators — the Bank of Israel, the insurance regulator and the Ministry of Health — enforce their own rules separately.
The Authority is headed by Commissioner Gilad Semama. Amendment 13, in force since 14 August 2025, gave it inspectors, administrative inquiry powers, search and seizure powers, monetary sanctions, cease-processing orders and the ability to ask a court to order deletion of personal data. Two published post-Amendment-13 decisions as at 18 August 2026: Meuhedet Health Fund, for failing to report a severe security incident immediately as required by Regulation 11(d)(1) of the Data Security Regulations — a technical fault let some members view other people's medical records; the fund learned of it in November 2025 but only reported on 27 January 2026. Original sanction 640,000 shekels (about $180,000), reduced by 60 percent to 256,000 shekels because it had no prior violations, stopped the breach on its own initiative and had appointed a privacy officer. Second, A.D. Karting Hutzot (2014) Ltd, for a booking form that collected personal data without the notice required by Article 11 — 20,000 shekels reduced to 12,000. Rating this 'active' rather than 'aggressive': the Authority is clearly staffed, has published a graduated sanctions framework and reduction schedule, and is using it, but the published caseload is still small and the first fines are modest.
Sources
- Official sourcePrivacy Protection AuthorityAdministrative enforcement — published enforcement proceedings after Amendment 13 came into force
gov.il
“תיקון 13 לחוק הגנת הפרטיות, שנכנס לתוקפו באוגוסט 2025, עדכן את סמכויות האכיפה של הרשות”
Link checked 18 August 2026
- Official sourcePrivacy Protection AuthorityThe Privacy Protection Authority — role holders, Commissioner Gilad Semama; regulator for administrative and criminal enforcement
gov.il
Link checked 18 August 2026
- Official sourceIsrael National Cyber DirectorateCyber regulation is deliberately decentralised to sector regulators under Government Resolution 2443 of 15 February 2015
gov.il
Link checked 18 August 2026
How long do I have to keep the data?
There is a clear floor and a clear ceiling, and they sit close together. The floor: security and access-monitoring records must be kept for at least 24 months, and organisations with medium or high security databases must keep a restorable backup of them. The ceiling: if a database contains anything that came from Europe, you must run a mechanism that finds data you no longer need and delete it, and you must delete data on request. Where another law says you must keep something, that wins over the duty to delete.
The 24-month floor comes from Regulations 10(d) and 17(a) of the Data Security Regulations 5777-2017 — records of the access-monitoring mechanism, and data collected in applying the documentation, access-control, incident and outsourcing-control regulations, all retained securely for 24 months. Regulation 17(b) requires medium and high security databases to back that up so it can always be restored. The ceiling comes from the European Economic Area regulations of 2023: Regulation 4 requires a standing organisational or technological mechanism to identify data no longer needed and delete it at the earliest opportunity, and Regulation 3 gives a written right to erasure where data was collected unlawfully or is no longer needed for its purpose. Conflicts are resolved in favour of keeping: both regulations carve out data needed to perform a legal obligation, conduct a legal proceeding or collect a debt, address fraud, protect a public interest including archival and research purposes, or meet an international agreement. Amendment 13 also pushes minimisation generally — the Authority's own preparation guidance tells businesses to reduce existing data that is no longer needed. Note that Israeli tax and company bookkeeping rules impose their own longer retention floors; we did not verify those against an official source on this run.
Sources
- Official sourcePrivacy Protection Authority, Ministry of JusticePrivacy Protection (Data Security) Regulations 5777-2017, Regulations 10(d) and 17
gov.il
“The records of the monitoring mechanism will be retained for at least 24 months.”
Link checked 18 August 2026
- Official sourcePrivacy Protection Authority, Ministry of JusticePrivacy Protection Regulations (Instructions for Data Transferred to Israel from the European Economic Area) 5783-2023, Regulations 3 and 4
gov.il
Link checked 18 August 2026
- Official sourcePrivacy Protection AuthorityHow to prepare for Amendment 13 — official preparation steps including reducing data no longer needed
govextra.gov.il
Link checked 18 August 2026
What happens if there is a breach?
There is one main clock and it has no hours attached to it: a severe security incident must be reported to the Privacy Protection Authority immediately, along with what you did about it. 'Immediately' is taken literally — a health fund was fined for a two-month delay. Telling the affected people is not automatic; the Authority decides, after consulting the national cyber agency, and can order you to notify them. Israel has no general law forcing every company to report cyber incidents to the state, so your second clock, if you have one, comes from your industry regulator.
Regulation 11(d)(1) of the Data Security Regulations 5777-2017: on a severe security incident the controller must immediately notify the Registrar (now the head of the Privacy Protection Authority) and report the measures taken. Regulation 11(d)(2): the Registrar may, after consulting the head of the National Cyber Defence Authority, order the controller to notify a data subject who may suffer damage. 'Severe security incident' is defined narrowly: in a high-security database, any unauthorised use of data or damage to data integrity; in a medium-security database, unauthorised use of a substantial part of the database or damage to the integrity of a substantial part. Low-security databases are outside the duty. Israel's cyber regulation is deliberately decentralised — Government Resolution 2443 of 15 February 2015 chose to empower existing sector regulators rather than create a new one, so there is no cross-economy incident reporting deadline. Sector clocks that do exist include the insurance regulator's duty on institutional bodies to report an exceptional event to the Commissioner close to the time they learn of it. The Ministry of Communications had still not published cyber rules for telecoms operators as of the National Cyber Directorate's current published map.
Sources
- Official sourcePrivacy Protection Authority, Ministry of JusticeData Security Regulations 5777-2017, Regulation 1 definition of 'severe security incident' and Regulation 11(d)
gov.il
“In case of a severe security incident - (1) The database controller will immediately notify the Registrar and report to the Registrar on the measures he took following the incident;”
Link checked 18 August 2026
- Official sourcePrivacy Protection AuthorityEnforcement decision against Meuhedet Health Fund for failing to report a severe security incident immediately
gov.il
Link checked 18 August 2026
- Official sourceIsrael National Cyber DirectorateCyber regulation map — no single national cyber regulator; each sector regulator sets its own rules
gov.il
Link checked 18 August 2026
What trips people up in Israel?
Five things that are not in the summary. One: a single record that arrived from Europe drags the whole database into the stricter European rules — since 1 January 2025 those rules apply to any other data sitting in the same database. Two: 'immediately' really means immediately, and there is no safe 72-hour habit to fall back on. Three: fines are calculated per person, not as a flat cap, so a large database turns a small breach into a very large bill. Four: privacy breaches are criminal offences, not just regulatory ones, with prison terms attached. Five: 'data security officer' and 'data protection officer' are two different Israeli roles with different triggers, and having one does not satisfy the other.
(1) Regulation 2(a)(2) of the European Economic Area regulations extends them to 'any other data that is in a database in Israel that contains data' transferred from the European Economic Area, in force for co-mingled data from 1 January 2025. The consequences bite on export too: the Authority's April 2026 opinion requires the foreign receiver to undertake Regulations 3 to 7 as well. (2) The Meuhedet decision fined a two-month delay. (3) Article 23KF prices most breaches per data subject — 2 shekels per person, doubled to 4 for specially sensitive data, for failures such as not appointing a data security officer or data protection officer; 4 shekels per person, doubled to 8 for specially sensitive data, for processing for an unlawful purpose or ignoring a cease-processing order. On a million-person sensitive database the second band produces 8 million shekels, roughly $2.2 million. Registration breaches carry a flat 150,000 shekels (about $42,000), doubled where the database covers a million people or more; refusing an inspector documents carries 300,000 shekels (about $85,000). (4) Article 5 makes wilful infringement of privacy punishable by five years' imprisonment. Amendment 13 added a chapter of database offences: processing personal data from a database without the controller's authorisation, three years; misleading someone when asking for their personal data, three years; unlawful transfer of data out of a public body, three years. (5) Article 17B (data security officer) is triggered by holding five registrable databases, or being a public body, bank, insurer or credit rater. Article 17B1 (data protection officer) is triggered by being a public body, a data broker with more than 10,000 people, a systematic monitor, or a large-scale processor of specially sensitive data. A bonus trap: Amendment 13 abolished the short two-year limitation period for civil privacy claims, so historic exposure now runs for the ordinary limitation period.
Sources
- Official sourcePrivacy Protection Authority, Ministry of JusticePrivacy Protection Law 5741-1981 updated after Amendment 13 — Articles 5, 23KF, 23NE to 23NG
gov.il
“Processing personal data from a database without authorization from the database controller, contrary to the provisions of Article 8(c), is subject to three years imprisonment.”
Link checked 18 August 2026
- Official sourcePrivacy Protection Authority, Ministry of JusticeEuropean Economic Area regulations 5783-2023, Regulation 2(a)(2) — application to any other data in the same database
gov.il
“(2) Any other data that is in a database in Israel that contains data as stated in sub-regulation (1).”
Link checked 18 August 2026
- Official sourcePrivacy Protection AuthorityProfessional guide to Amendment 13 — abolition of the shortened limitation period for civil privacy claims
gov.il
Link checked 18 August 2026
What is changing soon in Israel?
The big change already happened on 14 August 2025. What is landing now is the detail underneath it. In April 2026 the regulator finalised its binding rules on the contract you must sign before sending data abroad, and separate regulations came into force giving a short grace period — a warning instead of a fine — for brand-new obligations. A guideline applying privacy law to artificial intelligence, including a requirement of consent before scraping the web to train models, is also in play. Watch three switches the government can flip without warning.
Dated items. 14 August 2025: Amendment 13 in force, one year after publication in the official gazette on 14 August 2024. 1 January 2025: the European Economic Area regulations extended to co-mingled data. 9 April 2026, updated 30 April 2026: the final binding opinion on the contract route for transfers abroad. 16 April 2026: the Privacy Protection (Administrative Warning) Regulations 5786-2026 came into force. They let the Authority issue a warning instead of a monetary sanction in four situations — within three months of a new obligation taking effect; a first breach of certain data security regulations; up to six months after the Authority tightens its enforcement policy in an area it had not previously enforced; and up to six months where the obligation is genuinely unclear. A warning is only available where a fine could lawfully have been imposed. Dormant switches, each of which can change the picture with no consultation. First, the Authority may announce in the official gazette that a named foreign country has a privacy authority with which it has a cooperation arrangement, which turns that country into a permitted destination overnight; we could not confirm whether any such announcement has been published. Second, the Minister of Justice may by order, with the approval of the Knesset Constitution Committee, extend the per-person monetary sanction for ignoring a cease-or-rectify order to systematic monitors and large-scale processors of sensitive data, who are currently outside it. Third, Israel's European adequacy status, reaffirmed by the European Commission on 15 January 2024 and expected to be debated further in European Union institutions, is the load-bearing beam under the whole transfer regime — Israeli exporters rely on the European approved-country list through Regulation 2(8), and Israeli importers rely on adequacy in the other direction. On artificial intelligence, the Authority has published a guideline applying the Privacy Protection Law across the whole life cycle of an artificial intelligence system, from training to use, including that scraping personal data from the internet to train models requires informed consent and that publishing something about yourself online does not imply that consent; consultation on the draft closed 31 July 2025.
Sources
- Official sourcePrivacy Protection AuthorityPrivacy Protection (Administrative Warning) Regulations 5786-2026 — entered into force 16 April 2026
gov.il
Link checked 18 August 2026
- Official sourcePrivacy Protection AuthorityGuideline — application of the Privacy Protection Law to artificial intelligence systems
gov.il
Link checked 18 August 2026
- Official sourcePrivacy Protection AuthorityThe EU Commission reaffirmed its recognition of Israel's adequate level of data protection, 15 January 2024
gov.il
“on 15 January 2024 the European Commission published its decision, according to which Israel continues to provide an adequate level of protection for personal data transferred from the EU”
Link checked 18 August 2026
- Official sourceKnessetPrivacy Protection Law (Amendment No. 13), 5784-2024 — national legislation database; gazette publication 14 August 2024, Sefer HaChukim 3287 p. 1430
main.knesset.gov.il
Link checked 18 August 2026
The rules, layer by layer
Rules stack in layers. Knowing which layer a rule sits in tells you whether your industry, your state, or a contract can override it.
Layer 1
National rules
Added by this country on top of any bloc rules.
6 rules here
Layer 2
Industry rules
Made by an industry regulator. These usually beat the general position.
5 rules here
Layer 3
Contract-imposed rule
Binds you because you signed something, typically a government contract.
1 rule here
Read the stack from the top down. Anything lower normally wins: an industry rule beats the national position, and the national position sits on top of the bloc rules.
National rules6 rules
חוק הגנת הפרטיות, התשמ"א-1981 (כנוסחו לאחר תיקון מס' 13)
Act of parliament · Privacy Protection Law 5741-1981, as amended by Amendment No. 13, 5784-2024; Sefer HaChukim 3287, p. 1430
Israel's general privacy law, rewritten by Amendment 13 which started on 14 August 2025. It cut private-sector database registration almost to nothing, added a data protection officer duty, created new criminal offences, and gave the regulator inspectors and per-person monetary sanctions.
Enforced by Privacy Protection Authority
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses
What it makes you do
- Tell people what you doArticle 11. You must tell people why you are asking, who holds the database and how to reach them, and about their access and correction rights.
- Let people see their dataArticle 13.
- Let people correct their dataArticle 14.
- Let people delete their dataArticle 14, plus the wider erasure right for European-origin data.
- Secure the dataArticle 17. The controller and any holder are jointly responsible.
- Appoint a data protection officer — applies at: Public bodies; data brokers with more than 10,000 people; organisations doing regular systematic monitoring; large-scale processors of specially sensitive dataArticle 17B1. May be an outside contractor. Reports directly to the chief executive or someone reporting directly to them.
- Appoint a data protection officer — applies at: Controllers or processors of five registrable databases; public bodies; banks; insurers; credit ratersArticle 17B — the separate and older 'data security officer' role. Someone convicted of an offence involving moral turpitude may not be appointed.
- Register or notify — applies at: Databases whose main purpose is supplying personal data to others as a business and holding data on more than 10,000 people; public bodiesArticle 8A(a). Amendment 13 all but abolished private-sector registration.
- Keep records of processing — applies at: More than 100,000 people with specially sensitive data, in a database not otherwise registrable, 1 monthArticle 8A(b). Notify the Authority within 30 days, with the controller's and privacy officer's details and a copy of the database definitions document.
What it costs if you get it wrong
- Fixed maximum fine: 300,000 NIS — about $85 thousandProcessing a registrable database without registering it, where the database covers a million people or more (150,000 NIS otherwise)
- Fixed maximum fine: 300,000 NIS — about $85 thousandFailing to give an inspector a document or a copy of computer material
- Fixed maximum fine: 8 NIS per person in the database — about $2.25Processing for an unlawful purpose, or ignoring a cease-processing order, where the data is specially sensitive. On a million-person database this is about 8m NIS (roughly $2.2m).
- Criminal liability: 5 years imprisonmentWilfully infringing another person's privacy (Article 5)
- Criminal liability: 3 years imprisonmentProcessing data from a database without the controller's authorisation; misleading someone when requesting their data; unlawful transfer of data out of a public body
- Order to stopCourt order to stop processing or to delete personal data, on the Authority's application
- Claims by individualsInfringement of privacy is a civil wrong; Amendment 13 abolished the shortened two-year limitation period
Sources
- Official sourcePrivacy Protection Authority, Ministry of JusticePrivacy Protection Law, 5741-1981 — official English translation updated after Amendment 13
gov.il
Link checked 18 August 2026
- Official sourceKnessetPrivacy Protection Law (Amendment No. 13), 5784-2024 — national legislation database record
main.knesset.gov.il
Link checked 18 August 2026
- Official sourcePrivacy Protection AuthorityProfessional guide: Amendment No. 13 — 'entered into force on 14 August 2025'
gov.il
Link checked 18 August 2026
תקנות הגנת הפרטיות (העברת מידע אל מאגרי מידע שמחוץ לגבולות המדינה), התשס"א-2001
Directly binding regulation · Privacy Protection (Transfer of Data to Databases Abroad) Regulations, 5761-2001
Data may only leave Israel if the destination country's law protects it at least as well as Israeli law, or one of eight listed exceptions applies. Whichever route you use, the receiver must also sign a written promise to protect the data and not pass it on.
Enforced by Privacy Protection Authority
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Explicit consent, Someone's life is at risk, Important public interest
What it makes you do
- Put a transfer safeguard in placeRegulation 3 — a written guarantee from the receiver that it protects the data and will pass it to nobody else, in any country. This applies on top of whichever route you use.
- Written vendor contractRegulation 2(4) — the receiver contractually accepts the conditions that would apply to a database in Israel.
Sources
- Official sourcePrivacy Protection Authority, Ministry of JusticeProtection of Privacy (Transfer of Data Abroad) Regulations — official English translation
gov.il
“The data is transferred to a database in a country- (1) which is a Party to the European Convention for the Protection of Individuals with Regard to Automatic Processing of Sensitive Data; (2) which receives data from Member States of the European Community, under the same terms of acceptance”
Link checked 18 August 2026
- Official sourcePrivacy Protection AuthorityLegislation page of the Privacy Protection Authority, listing the transfer regulations
gov.il
Link checked 18 August 2026
גילוי דעת בנושא העברת מידע אישי מחוץ לישראל - פרשנות תקנה 2(4)
Regulator guideline · Privacy Protection Authority binding opinion on Regulation 2(4) of the Transfer of Data Abroad Regulations
The regulator's final and binding reading of the contract route out of Israel, published in April 2026. Without these specific undertakings in the contract, you cannot rely on that route at all.
Enforced by Privacy Protection Authority
Transfer model: Allowlist · Accepted routes: Standard contract clauses, Certification scheme
What it makes you do
- Written vendor contract — from 9 April 2026The contract must bind the receiver to purpose limitation, the access right, the correction and deletion right, and the confidentiality duty.
- Hold a security certificateAlternative to promising the Data Security Regulations in full: declare ISO/IEC 27001 certification including all relevant Annex A controls, plus the specific regulations named in the Authority's Guideline 3/2018.
- Put a transfer safeguard in placeWhere the Israeli database also holds data from the European Economic Area, the receiver must additionally undertake Regulations 3 to 7 of the 2023 European Economic Area regulations.
Sources
- Official sourcePrivacy Protection AuthorityFinal binding opinion on transferring personal data outside Israel — Regulation 2(4), published 9 April 2026, updated 30 April 2026
gov.il
Link checked 18 August 2026
- Official sourcePrivacy Protection AuthorityOpinion text, paragraphs 8 to 13
gov.il
Link checked 18 August 2026
תקנות הגנת הפרטיות (הוראות לעניין מידע שהועבר לישראל מהאזור הכלכלי האירופי), התשפ"ג-2023
Directly binding regulation · Privacy Protection Regulations (Instructions for Data Transferred to Israel from the European Economic Area), 5783-2023
Extra European-style duties on data that arrived in Israel from the European Economic Area. The trap is Regulation 2(a)(2): from 1 January 2025 the duties also cover any other data sitting in the same database, so one European record can pull an entire customer database into the stricter regime.
Enforced by Privacy Protection Authority
Transfer model: Allowlist · Accepted routes: Standard contract clauses
What it makes you do
- Let people delete their dataRegulation 3 — delete on written request where the data was collected unlawfully or is no longer needed, subject to listed exceptions.
- Delete data after a periodRegulation 4 — run a standing mechanism that finds data no longer needed and delete it at the earliest opportunity.
- Tell people what you do — within 720 hoursRegulation 6 — tell the person within one month of receiving their data who you are, why it was transferred, what type of data it is and what rights they have. Tell them again before passing it to a third party.
Sources
- Official sourcePrivacy Protection Authority, Ministry of JusticeEuropean Economic Area regulations 5783-2023 — official English translation
gov.il
Link checked 18 August 2026
- Official sourcePrivacy Protection AuthorityPrivacy Protection Authority page for the European Economic Area regulations
gov.il
Link checked 18 August 2026
- Official sourcePrivacy Protection AuthorityAuthority opinion, footnote 7 — the regulations apply to co-mingled Israeli data from 1 January 2025
gov.il
Link checked 18 August 2026
תקנות הגנת הפרטיות (אבטחת מידע), התשע"ז-2017
Directly binding regulation · Privacy Protection (Data Security) Regulations, 5777-2017
The operational rulebook: security levels, a written procedure, access controls, 24-month record retention and, above all, immediate reporting of a severe security incident. This is where the regulator's first big fine landed.
Enforced by Privacy Protection Authority
What it makes you do
- Report breaches to the regulatorRegulation 11(d)(1) — 'immediately', with no hour count. Applies to a severe security incident in a medium or high security database.
- Tell affected peopleRegulation 11(d)(2) — not automatic. The regulator may order it, after consulting the head of the National Cyber Defence Authority.
- Keep logs — 2 yearsRegulations 10(d) and 17. Access-monitoring records and other security records, held securely, and backed up restorably in medium and high security databases.
- Secure the dataWritten data security procedure, database definitions document, access control, physical and network security.
- Written vendor contractRegulation 15 — a controller contracting with an external provider must set out what data, for what purpose, for how long, and must control and supervise the provider.
- Independent auditPeriodic audit; one audit may cover several databases of the same security level.
What it costs if you get it wrong
- Fixed maximum fine: 640,000 NIS imposed, reduced to 256,000 NIS — about $180 thousandActual 2026 sanction on Meuhedet Health Fund for failing to report a severe security incident immediately
Sources
- Official sourcePrivacy Protection Authority, Ministry of JusticePrivacy Protection (Data Security) Regulations 5777-2017 — official English translation
gov.il
Link checked 18 August 2026
- Official sourcePrivacy Protection AuthorityAdministrative enforcement decisions — Meuhedet Health Fund, Regulation 11(d)(1)
gov.il
Link checked 18 August 2026
תקנות הגנת הפרטיות (התראה מינהלית), התשפ"ו-2026
Directly binding regulation · Privacy Protection (Administrative Warning) Regulations, 5786-2026
A grace mechanism, not a duty. The regulator may issue a warning instead of a fine in four situations, including within three months of a brand-new obligation starting and for up to six months where the obligation is genuinely unclear. A warning is only possible where a fine could lawfully have been imposed.
Enforced by Privacy Protection Authority
Sources
- Official sourcePrivacy Protection AuthorityPrivacy Protection (Administrative Warning) Regulations 5786-2026 — 'today the regulations come into force', 16 April 2026
gov.il
Link checked 18 August 2026
Industry rules5 rules
הוראות ניהול בנקאי תקין 362 - מחשוב ענן
Regulator directive · Proper Conduct of Banking Business Directive 362 — Cloud Computing; current version issued by Circular 2849 · Banking
Israeli banks may use cloud outside Israel, including for material services, but only after verifying that the provider protects sensitive customer data to European standards. The directive also forces the bank to plan for a foreign region going dark for geopolitical reasons.
Enforced by Bank of Israel — Banking Supervision Department
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses
What it makes you do
- Put a transfer safeguard in placeSection 7 — a bank may not store, move or process information it classifies as sensitive on a cloud outside Israel unless it has verified the provider's protection matches the European General Data Protection Regulation.
- Written vendor contractThe contract must state where the cloud facility is and where data is stored, and commit the provider to that location.
- Hold a security certificateSection 39 — main and alternate cloud sites must meet Uptime Institute Tier 3, evidenced by certificate or independent opinion.
- Assess high-risk projectsSections 38 and the risk chapter — the bank must plan for the foreign region becoming unavailable through communications failure or geopolitical events, and assess regulatory risk from a cloud located outside Israel.
Sources
- Official sourceBank of Israel, Banking Supervision DepartmentDirective 362 — Cloud Computing, Hebrew text as updated 17 June 2026, sections 7, 9, 38
boi.org.il
Link checked 18 August 2026
- Official sourceBank of IsraelDirective 362 — Cloud Computing, English translation (June 2022 version), section 7
boi.org.il
“A banking corporation shall not store, transfer, or process information that it defines as "sensitive" (e.g., customer data, confidential business information, etc.) on a cloud outside the borders of the State of Israel unless it has ascertained that the cloud-service provider maintains a level of protection that complies with the European Union General Data Protection Regulation (GDPR).”
Link checked 18 August 2026
- Official sourceBank of IsraelDirective 362 landing page showing publication date 17/06/2026 and circular number 2849
boi.org.il
Link checked 18 August 2026
חוזר גופים מוסדיים 2018-9-35 - מיקור חוץ בגופים מוסדיים
Regulator directive · Institutional Bodies Circular 2018-9-35 — Outsourcing in institutional bodies · Insurance
Insurers and pension providers may outsource abroad, but the regulator sees every arrangement. There is a board-level policy duty, a specific requirement to assess what it means to run the activity outside Israel, and an annual list to the Commissioner flagging each offshore arrangement.
Enforced by Capital Market, Insurance and Savings Authority
What it makes you do
- Written vendor contractBoard-approved outsourcing policy must deal expressly with activity carried out outside Israel or with a provider located outside Israel, and with the consequences of the activity being performed abroad.
- Keep records of processing — 1 yearAnnual return to the Commissioner listing every outsourcing arrangement in force at 31 December, including a yes/no field for whether the activity is outsourced abroad, filed as a spreadsheet.
- Report breaches to the regulatorImmediate report to the Commissioner of an exceptional event, close to the time the body learns of it.
Sources
- Official sourceCapital Market, Insurance and Savings AuthorityInstitutional Bodies Circular 2018-9-35 — Outsourcing, 31 December 2018
gov.il
Link checked 18 August 2026
- Official sourceIsrael National Cyber DirectorateNational Cyber Directorate map confirming this circular is the operative outsourcing rule for the insurance and savings sector
gov.il
Link checked 18 August 2026
חוזר מנכ"ל משרד הבריאות 2/2021 - שימוש במחשוב ענן במערכת הבריאות
Regulator directive · Ministry of Health Director-General Circular 2/2021 — Use of cloud computing in the health system · Health and social care
Israeli hospitals and health funds may use cloud abroad, but only in a country that satisfies the national transfer regulations, and only after assessing what foreign law would do to the data. The circular is permissive on geography and demanding on governance.
Enforced by Ministry of Health
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses
What it makes you do
- Assess high-risk projectsBefore contracting, the health organisation must assess the consequences of using a cloud located outside Israel, including which foreign law would apply to the data.
- Written vendor contractThe contract must cover division of responsibility, security controls, audit rights over the provider and its subcontractors, incident handling and reporting, exit and data return or deletion, and business continuity.
- Independent audit — 2 yearsRe-evaluate the provider and the services at least once every two years.
Sources
- Official sourceMinistry of HealthDirector-General Circular 2/2021 — Use of cloud computing in the health system, sections 6.2.5 and 6.5
gov.il
Link checked 18 August 2026
- Official sourcePrivacy Protection AuthorityProtecting patient privacy when transferring medical data by digital means — text updated after Amendment 13; bans routine use of consumer messaging and consumer cloud backup for patient data
gov.il
Link checked 18 August 2026
חוזרי מנכ"ל משרד הבריאות 1/2018 ו-2/2018 - שימושים משניים במידע בריאות
Regulator directive · Ministry of Health Director-General Circulars 1/2018 and 2/2018 — Secondary uses of health data, and collaborations based on secondary uses · Health and social care
For research use of health records, the rule is not 'keep it in Israel' but 'keep it inside the hospital or health fund'. Identifiable data should be worked on in a secure research environment within the organisation, and taking individual-level records outside its control needs ethics-committee approval and a destruction promise.
Enforced by Ministry of Health
Transfer model: Approval each time · Accepted routes: Government sign-off needed, Explicit consent
What it makes you do
- Keep the data in the countryThe wall is organisational rather than geographic: identifiable patient data used for research must stay under the health organisation's control, normally accessed inside a secure physical or virtual research room. Releasing individual-level data, including de-identified data, needs a reasoned approval from the ethics committee and the organisation's authorised officer.
- Extra vendor secrecy termsEveryone receiving access, inside or outside the organisation, must sign an undertaking of confidentiality, no re-identification attempts, no other use and no onward transfer without approval.
- Delete data after a periodThe recipient must destroy every identifying variable when the research ends.
What it costs if you get it wrong
- Order to stopThe Director-General may suspend the organisation's ethics committee authority to approve secondary uses, in whole or in part
Sources
- Official sourceMinistry of HealthDirector-General Circular 1/2018 — Secondary uses of health data, sections 8.3, 8.4 and 8.6
gov.il
Link checked 18 August 2026
- Official sourceMinistry of HealthDirector-General Circular 2/2018 — Collaborations based on secondary uses of health data, section 6.3.4
gov.il
Link checked 18 August 2026
הנחיה - תחולת חוק הגנת הפרטיות על מערכות בינה מלאכותית
Regulator guideline · Privacy Protection Authority guideline on the application of the Privacy Protection Law to artificial intelligence systems · Artificial intelligence
The regulator's position that Israeli privacy law covers not only data fed into an artificial intelligence system but also data the system infers. Its sharpest point: training a model on scraped personal data needs the person's informed consent.
Enforced by Privacy Protection Authority
What it makes you do
- Get consentConsent is needed at every stage of the life cycle, including training. Scraping personal data from the internet to train a model requires informed consent — the fact someone posted about themselves online does not by itself imply it.
- Tell people what you doPeople must be told they are dealing with an automated system rather than a human where that materially affects their consent, and told enough about how the system works to consent meaningfully.
- Let people correct their dataThe right to correct wrong data may extend to correcting the algorithm that produced it.
- Assess high-risk projectsThe Authority says it will press on privacy impact assessments and will enforce the duty to appoint a privacy officer especially firmly in artificial intelligence contexts.
Sources
- Official sourcePrivacy Protection AuthorityGuideline — application of the Privacy Protection Law to artificial intelligence systems
gov.il
Link checked 18 August 2026
Contract-imposed rule1 rule
פרויקט נימבוס - מדיניות הענן הממשלתית
Government policy document · Project Nimbus; Government Resolutions 852 (2021), 231 (2021), 1700 (2024), 2273 (2024) and 3574 of 4 December 2025; Accountant General instruction 16.12.1 · Government
Central government buys cloud only through the Nimbus framework, and its shared platform sits in Israeli cloud regions on purpose. This is a procurement wall rather than a law, but in practice selling cloud to the Israeli state requires an in-country region.
Transfer model: Approval each time · Accepted routes: Government sign-off needed
What it makes you do
- Keep the data in the countryNot a statute. The government's central cloud landing zone was deliberately migrated out of an overseas public cloud into the Israeli region the moment it opened, described by officials as preserving sovereignty over the data of Israeli citizens and government systems.
- Register or notifyMinistries must buy cloud only from the providers selected in the central Nimbus tenders, and must use designated cross-government solutions rather than building their own.
Sources
- Official sourceIsrael National Cyber Directorate / National Digital AgencyIsrael's government moves to the cloud — Project Nimbus; the government landing zone was relocated from an overseas public cloud to the Israeli region
gov.il
Link checked 18 August 2026
- Official sourceGovernment SecretariatGovernment Resolution 3574 of 4 December 2025 — accelerating digital services, data and artificial intelligence on the Nimbus public cloud
gov.il
Link checked 18 August 2026
- Official sourceMinistry of Finance, Accountant GeneralAccountant General instruction 16.12.1 — Project Nimbus, general guidance on procuring public cloud services
takam.mof.gov.il
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.
Whether any country has actually been named in the official gazette under Regulation 2(8)(3) as having a privacy authority with a cooperation arrangement with Israel.
The regulation creates the power, and the Authority has signed cooperation statements with the Dubai International Financial Centre and Abu Dhabi Global Market, but we could not find a published gazette announcement confirming any country has been designated. Treat this route as unavailable until you see the announcement.
That Israeli tax and company law require books and records to be kept for seven years.
This is the widely reported floor under the Income Tax (Bookkeeping) Instructions 1973, but we could not reach an Israel Tax Authority page stating it on this run, so we have not asserted a number in the record.
That there is no data-residency rule for securities firms, telecoms operators, education, online gaming, mapping or defence.
No such rule was found on an Israeli government source, checked 18 August 2026. This is an absence of evidence, not evidence of absence. The National Cyber Directorate's own map records that the Ministry of Communications has not published cyber rules for telecoms at all, and that a public consultation on adding cyber conditions to telecoms licences was opened in August 2021 and has not visibly concluded. Israel Securities Authority cloud or outsourcing guidance could not be retrieved.
The exact date on which the artificial intelligence guideline moved from draft to final.
The Privacy Protection Authority page is titled as a guideline and states it was published 'in a first stage' as a draft with comments due by 31 July 2025, but the rendered page did not expose a publication or update date. We have dated it to the consultation period and set confidence to medium.
That the Privacy Protection Law reaches foreign companies with no Israeli presence.
The statute contains no territorial-scope article. Our conclusion rests on the Authority's own guide, a footnote in its April 2026 opinion acknowledging that databases abroad can be subject to Israeli law, and its past investigation of a foreign platform — not on express legislative words. A foreign company with no Israeli establishment has a real argument here, which is why confidence on Q1 is medium.
That the Project Nimbus localisation requirement is legally binding rather than contractual.
We verified that the government's shared cloud platform was moved into the Israeli region and that ministries must buy through the central tenders, but we did not obtain the tender conditions themselves. The rule is recorded as a procurement layer, not a statute.
The precise commencement date of the Data Security Regulations 5777-2017.
Regulation 22 says only that they take effect one year after publication. We have used 8 May 2018, the date generally cited, but did not verify the gazette publication date directly.
Freshness and refresh
Freshness
Checked today — on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.
Compare with
- Israel versus Argentina
- Israel versus Armenia
- Israel versus Australia
- Israel versus Austria
- Israel versus Azerbaijan
- Israel versus Brazil
- Israel versus Bulgaria
- Israel versus Cambodia
- Israel versus Canada
- Israel versus China
- Israel versus Croatia
- Israel versus Cyprus
- Israel versus Estonia
- Israel versus France
- Israel versus Georgia
- Israel versus Germany
- Israel versus Greece
- Israel versus Hong Kong SAR
- Israel versus Hungary
- Israel versus Iceland
- Israel versus India
- Israel versus Indonesia
- Israel versus Ireland
- Israel versus Italy
- Israel versus Japan
- Israel versus Latvia
- Israel versus Lithuania
- Israel versus Luxembourg
- Israel versus Malta
- Israel versus Mexico
- Israel versus Mongolia
- Israel versus Nepal
- Israel versus Netherlands
- Israel versus Poland
- Israel versus Russia
- Israel versus Saudi Arabia
- Israel versus Serbia
- Israel versus Singapore
- Israel versus Slovakia
- Israel versus Slovenia
- Israel versus South Korea
- Israel versus Spain
- Israel versus Sri Lanka
- Israel versus Sweden
- Israel versus Switzerland
- Israel versus Taiwan
- Israel versus Thailand
- Israel versus Turkey
- Israel versus Ukraine
- Israel versus United Arab Emirates
- Israel versus United Kingdom
- Israel versus United States
- Israel versus Uzbekistan