Skip to the content
Global Data RulesData governance rules, country by country

Israel

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.

If you collect data about people in Israel — customers, users, employees — these are the rules you have to follow. Here is the short version.

The short version

Yes, with paperworkWork: HighEnforcement: Active

You can send Israeli data abroad, but you need paperwork every time. Either the country you send to protects data as well as Israel does. Or you fit one of eight listed exceptions. The usual exception is a contract where the receiver promises to follow Israeli rules. A big reform started on 14 August 2025. The regulator now issues real fines. No industry bans sending data abroad outright, but several add heavy conditions.

Data governance in Israel

The eight things that decide how you handle data about people in Israel. Same eight on every country page, so you can compare.

Who has to follow these rules

Yes, the law can reach a foreign company with no office in Israel. The law never says this in words. Israeli privacy law applies to anyone who collects, uses or stores personal data. There is no size or revenue threshold. You do not have to appoint a local representative. Some organisations must appoint a privacy officer. That person can be an outside contractor rather than a staff member.

What you have to do here:
Appoint a data protection officer
Not fully verified — see “What we're not sure about” below.

Where the data is allowed to live

Yes, you can send data abroad, but you need paperwork. You must be able to name the route you are using. The basic rule is that data may only go to a country whose law protects it at least as well as Israeli law does. If the country fails that test, you must fit one of eight listed exceptions. Whichever route you take, you also need a written promise from the receiver. No Israeli industry says data must stay in the country. But four industries add extra conditions on top.

What to do: Get the paperwork for one of the routes below signed before any data leaves Israel.

Sending data out of the country

You can only send data to countries that qualify, and the qualifying list is already large. A country counts if it signed the Council of Europe data protection convention. It also counts if it receives data from European Union countries on the same terms. So Europe's approved-country list does much of the work. If your destination does not qualify, the usual fallback is a contract. In it, the receiver promises to meet Israeli standards. Either way, you also need a separate written promise from the receiver. It must promise to protect the data and pass it to nobody else.

What you have to do here:
Put a transfer safeguard in place
Ways to send data out:
Official 'this country is safe' decision · Standard contract clauses · Approved group rules · Explicit consent · To save someone’s life · Important public interest

What to do: Get the approved standard contract clauses signed with every vendor that touches this data, before it leaves.

The regulator, and whether it actually acts

The Privacy Protection Authority enforces the rules. It is part of the Ministry of Justice and is fully up and running. It has a serving commissioner and an enforcement department. It publishes its decisions with names and amounts. In 2026 it fined a national health fund about 256,000 shekels (roughly 72,000 US dollars). The fund had taken two months to report a security incident. It also fined a small leisure company about 12,000 shekels (roughly 3,400 US dollars) for a faulty privacy notice. Industry regulators enforce their own rules separately. Those are the Bank of Israel, the insurance regulator and the Ministry of Health.

What it costs if you get it wrong:
Fixed maximum fine · Order to stop · Criminal liability

How long you must keep it — and when to delete it

There is a minimum keeping time and a duty to delete, and they sit close together. You must keep security and access-monitoring records for at least 24 months. If you run a medium or high security database, you must also keep a backup you can restore. On the other side, if your database holds anything that came from Europe, you must delete data you no longer need. You need a working method that finds it. You must also delete data when someone asks. If another law says you must keep something, that law wins.

What you have to do here:
Keep data for a minimum period · Delete data after a period · Let people delete their data

What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.

If something goes wrong

You must report a severe security incident to the Privacy Protection Authority immediately. No number of hours is given. 'Immediately' is taken literally. A health fund was fined for a two-month delay. You must also say what you did about the incident. Telling the affected people is not automatic. The Authority decides, after asking the national cyber agency, and it can order you to tell them. Israel has no general law making every company report cyber incidents to the state. So any second deadline comes from your industry regulator.

What you have to do here:
Report breaches to the regulator · Tell affected people · Report cyber incidents

What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.

What catches people out

Five things the summary does not cover. One: a single record that arrived from Europe pulls the whole database into the stricter European rules. Since 1 January 2025 those rules cover any other data sitting in the same database. Two: 'immediately' really means immediately. There is no safe 72-hour habit to fall back on. Three: fines are worked out per person, not as a flat cap. A large database turns a small breach into a very large bill. Four: privacy breaches are crimes, not just regulatory matters, and they carry prison terms. Five: 'data security officer' and 'data protection officer' are two different Israeli roles. They have different triggers. Having one does not cover the other.

What you have to do here:
Appoint a data protection officer · Report breaches to the regulator
What it costs if you get it wrong:
Criminal liability · Fixed maximum fine · Claims by individuals

What's changing next

The big change already happened on 14 August 2025. The detail underneath it is landing now. In April 2026 the regulator finalised its binding rules on the contract you must sign before sending data abroad. Separate regulations also came into force. They give a short grace period, a warning instead of a fine, for brand-new duties. A guideline applying privacy law to artificial intelligence is also live. It includes a need for consent before scraping the web to train models. Three further changes can happen with no warning.

Not fully verified — see “What we're not sure about” below.

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries5 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Banking

Cloud and outsourcing rules

Official name: הוראות ניהול בנקאי תקין 362 - מחשוב ענן · Proper Conduct of Banking Business Directive 362 — Cloud Computing; current version issued by Circular 2849 · Regulator directive

In forceYes, with paperwork

Israeli banks may use cloud outside Israel, including for important services. First they must check that the provider protects sensitive customer data to European standards. The bank must also plan for a foreign region becoming unavailable for political reasons.

In force since 13 June 2022Enforced from 17 June 2026

Enforced by Bank of Israel — Banking Supervision Department

How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses

Insurance

Cloud and outsourcing rules (Insurance)

Official name: חוזר גופים מוסדיים 2018-9-35 - מיקור חוץ בגופים מוסדיים · Institutional Bodies Circular 2018-9-35 — Outsourcing in institutional bodies · Regulator directive

In forceYes, with paperwork

Insurers and pension providers may outsource abroad, but the regulator sees every deal. Your board must approve a policy. You must assess what it means to run the work outside Israel. You must send the Commissioner an annual list marking each deal that is abroad.

In force since 31 December 2018

Enforced by Capital Market, Insurance and Savings Authority

Health and social care

Cloud and outsourcing rules (Health and social care)

Official name: חוזר מנכ"ל משרד הבריאות 2/2021 - שימוש במחשוב ענן במערכת הבריאות · Ministry of Health Director-General Circular 2/2021 — Use of cloud computing in the health system · Regulator directive

In forceYes, with paperwork

Israeli hospitals and health funds may use cloud abroad. The country must meet the national transfer regulations. You must first assess what foreign law would do to the data. The rules are relaxed about where the data goes and strict about how you manage it.

In force since 21 February 2021

Enforced by Ministry of Health

How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses

Applies to every company6 rules

These bind you whatever business you are in, once the country's rules reach you.

General data protection law

Official name: חוק הגנת הפרטיות, התשמ"א-1981 (כנוסחו לאחר תיקון מס' 13) · Privacy Protection Law 5741-1981, as amended by Amendment No. 13, 5784-2024; Sefer HaChukim 3287, p. 1430 · Act of parliament

In forceYes, with paperwork

Israel's general privacy law. Amendment 13 rewrote it, starting on 14 August 2025. It cut private-sector database registration almost to nothing. It added a duty to appoint a data protection officer. It created new crimes. It gave the regulator inspectors and money penalties charged per person.

In force since 14 August 2025

Enforced by Privacy Protection Authority

How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses

Data rules

Official name: תקנות הגנת הפרטיות (העברת מידע אל מאגרי מידע שמחוץ לגבולות המדינה), התשס"א-2001 · Privacy Protection (Transfer of Data to Databases Abroad) Regulations, 5761-2001 · Directly binding regulation

In forceYes, with paperwork

Data may only leave Israel if the country you send to protects it at least as well as Israeli law does. If not, one of eight listed exceptions must apply. Whichever route you use, the receiver must also sign a written promise. It must promise to protect the data and not pass it on.

In force since 17 December 2001

Enforced by Privacy Protection Authority

How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Explicit consent, To save someone’s life, Important public interest

Data rules (2026)

Official name: גילוי דעת בנושא העברת מידע אישי מחוץ לישראל - פרשנות תקנה 2(4) · Privacy Protection Authority binding opinion on Regulation 2(4) of the Transfer of Data Abroad Regulations · Regulator guideline

In forceYes, with paperwork

The regulator's final and binding reading of the contract route out of Israel, published in April 2026. Your contract must contain these exact promises. Without them you cannot use that route.

In force since 9 April 2026Enforced from 30 April 2026

Enforced by Privacy Protection Authority

How this country controls where data goes: Only approved countries · Accepted routes: Standard contract clauses, Certification scheme

Applies only if you signed a contract1 rule

Usually a government or enterprise contract that adds rules of its own.

Government

Government data must stay in the country

Official name: פרויקט נימבוס - מדיניות הענן הממשלתית · Project Nimbus; Government Resolutions 852 (2021), 231 (2021), 1700 (2024), 2273 (2024) and 3574 of 4 December 2025; Accountant General instruction 16.12.1 · Government policy document

In forceNo — it stays put

Central government buys cloud only through the Nimbus tenders. Its shared platform sits in Israeli cloud regions on purpose. This is a buying rule, not a law. But selling cloud to the Israeli state needs a region inside the country.

In force since 24 May 2021Enforced from 4 December 2025

How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed

Not fully verified — see “What we're not sure about” below.

Who you would hear from

  • הרשות להגנת הפרטיות

    All personal data held in digital databases, private and public; administrative and criminal enforcement

    Fully up and running. Headed by Commissioner Gilad Semama. It has an administrative enforcement department. In 2026 it published two named money penalties: Meuhedet Health Fund, 256,000 shekels after reduction, and A.D. Karting Hutzot, 12,000 shekels after reduction. It issued a final binding opinion on sending data abroad in April 2026. It also published a guideline on artificial intelligence.

  • בנק ישראל - הפיקוח על הבנקים

    Banks and credit card companies; cloud computing, information technology and cyber directives

    Active. Reissued the cloud computing directive on 17 June 2026 via Circular 2849, restructuring it around the new Directive 364 and cancelling Directives 361 and 363.

  • רשות שוק ההון, ביטוח וחיסכון

    Insurers, pension and provident funds; outsourcing, cyber risk and information technology circulars

    Active. It receives annual outsourcing returns from every institutional body, plus immediate reports of unusual events.

  • משרד הבריאות

    Hospitals, health funds and other health organisations; cloud use, secondary use of health data, medical confidentiality

    Active through Director-General circulars. It does not fine. It can suspend a health organisation's ethics committee from approving further uses of data.

  • מערך הסייבר הלאומי

    National cyber defence; professional guidance to sector regulators; consulted before individuals are ordered to be notified of a data breach

    Up and running, but on purpose it does not regulate the whole economy. Government Resolution 2443 of 15 February 2015 gave the powers to existing industry regulators instead. So there is no general duty to report cyber incidents to it.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.

  • Whether any country has actually been named in the official gazette under Regulation 2(8)(3) as having a privacy authority with a cooperation arrangement with Israel.

    The regulation creates the power. The Authority has signed cooperation statements with the Dubai International Financial Centre and Abu Dhabi Global Market. But we found no published gazette announcement naming any country. Treat this route as unavailable until you see the announcement.

  • That Israeli tax and company law require books and records to be kept for seven years.

    This figure is widely reported as the minimum under the Income Tax (Bookkeeping) Instructions 1973. We could not confirm it on an Israel Tax Authority page, so we have not put a number in the record. Check with the Israel Tax Authority before you rely on it.

  • That there is no where data has to be stored rule for securities firms, telecoms operators, education, online gaming, mapping or defence.

    We found no such rule on an Israeli government source, checked 18 August 2026. We could not confirm it either way. The National Cyber Directorate's own map records that the Ministry of Communications has published no cyber rules for telecoms at all. A public consultation on adding cyber conditions to telecoms licences opened in August 2021 and has not visibly finished. We could not reach Israel Securities Authority cloud or outsourcing guidance. If you work in these industries, check before you rely on this.

  • The exact date on which the artificial intelligence guideline moved from draft to final.

    The Privacy Protection Authority page is titled as a guideline. It says it was published 'in a first stage' as a draft, with comments due by 31 July 2025. The page did not show a publication or update date. We have dated it to the consultation period and set confidence to medium.

  • That the Privacy Protection Law reaches foreign companies with no Israeli presence.

    The law itself says nothing about who and where it covers. Our conclusion rests on three things. The Authority's own guide. A footnote in its April 2026 opinion accepting that databases abroad can be subject to Israeli law. And its past investigation of a foreign platform. None of these are express words in the law. A foreign company with no Israeli office has a real argument here. That is why confidence on question one is medium.

  • That the Project Nimbus localisation requirement is legally binding rather than contractual.

    We confirmed that the government's shared cloud platform was moved into the Israeli region. We also confirmed that ministries must buy through the central tenders. We could not get the tender conditions themselves. So we record this as a buying rule, not a law.

  • The precise commencement date of the Data Security Regulations 5777-2017.

    Regulation 22 says only that they take effect one year after publication. We have used 8 May 2018, the date usually cited. We could not confirm the gazette publication date directly.

Freshness and refresh

Freshness

Checked about 2 months ago, on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.