Israel
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.
If you collect data about people in Israel — customers, users, employees — these are the rules you have to follow. Here is the short version.
The short version
You can send Israeli data abroad, but you need paperwork every time. Either the country you send to protects data as well as Israel does. Or you fit one of eight listed exceptions. The usual exception is a contract where the receiver promises to follow Israeli rules. A big reform started on 14 August 2025. The regulator now issues real fines. No industry bans sending data abroad outright, but several add heavy conditions.
Data governance in Israel
The eight things that decide how you handle data about people in Israel. Same eight on every country page, so you can compare.
Who has to follow these rules
Yes, the law can reach a foreign company with no office in Israel. The law never says this in words. Israeli privacy law applies to anyone who collects, uses or stores personal data. There is no size or revenue threshold. You do not have to appoint a local representative. Some organisations must appoint a privacy officer. That person can be an outside contractor rather than a staff member.
- What you have to do here:
- Appoint a data protection officer
Europe's General Data Protection Regulation states which companies it covers. Israel's Protection of Privacy Law 5741-1981 has no such article. The Privacy Protection Authority published a professional guide on Amendment 13 in August 2025. It says only that the law applies to anyone who collects, uses or stores personal data. That covers public and private bodies. It leaves out a private collection not held for business or public purposes. So the reach over foreign companies comes from interpretation, not from the words of the law. The Authority's binding opinion of April 2026 on sending data abroad has a footnote on this. It says some databases held abroad may be subject to all of Israeli law. That can hold even where the company running them is not registered in Israel. The Authority opened an investigation into Facebook in 2018. Article 17B1 says who must appoint a Data Protection Officer. Public bodies. Data brokers holding data on more than 10,000 people. Companies whose main activity is regular and systematic monitoring of people, such as search engines and mobile operators. And companies that handle specially sensitive data at large scale, such as banks, insurers, general hospitals and health funds. There is a second, older role called the Data Security Officer, under Article 17B. It applies to anyone running five registrable databases, and to public bodies, banks, insurers and credit-rating firms.
Sources
- Official sourcePrivacy Protection Authority, Ministry of JusticePrivacy Protection Law, 5741-1981, text updated after Amendment 13 — Articles 8A, 17B and 17B1
gov.il
“The following entities are required to appoint a data protection officer: (1) A database controller that is a public body ... (3) A database controller or processor whose core activities consist of data processing operations ... which ... require regular and systematic monitoring of individuals”
Link checked 18 August 2026
- Official sourcePrivacy Protection AuthorityProfessional guide to Amendment 13 to the Privacy Protection Law, section headed 'Application'
gov.il
Link checked 18 August 2026
- Official sourcePrivacy Protection AuthorityBinding opinion on transferring personal data outside Israel — interpretation of Regulation 2(4), footnote 2
gov.il
Link checked 18 August 2026
Where the data is allowed to live
Yes, you can send data abroad, but you need paperwork. You must be able to name the route you are using. The basic rule is that data may only go to a country whose law protects it at least as well as Israeli law does. If the country fails that test, you must fit one of eight listed exceptions. Whichever route you take, you also need a written promise from the receiver. No Israeli industry says data must stay in the country. But four industries add extra conditions on top.
Here is each industry, checked on 18 August 2026. BANKS: conditional. Bank of Israel Proper Conduct of Banking Business Directive 362, current version dated 17 June 2026, section 7. A bank may not store, move or use information it treats as sensitive on a cloud outside Israel. It may only do so once it has checked that the provider's protection meets the European General Data Protection Regulation. Section 38 adds a duty to plan for the foreign region going offline because of political events. INSURANCE AND PENSIONS: conditional, plus reporting. Capital Market, Insurance and Savings Authority circular 2018-9-35 on outsourcing applies to institutional bodies. The board must approve an outsourcing policy. It must deal specifically with work done outside Israel, or with a provider based outside Israel. You must assess what it means for the work to happen abroad. You must file an annual return to the Commissioner listing every outsourcing deal, with a yes or no field for whether it is abroad. You must report unusual events straight away. HEALTH: conditional on where the data goes, and closed on who controls it. Ministry of Health Director-General circular 2/2021 on cloud computing in the health system, section 6.5, allows cloud in a country that meets the transfer regulations. But circulars 1/2018 and 2/2018 on secondary use of health data go further. Patient data that names people and is used for research must stay in a secure space inside the health organisation. Sending it outside the organisation's control needs Helsinki-committee approval and a promise to destroy it. GOVERNMENT: closed. Under Project Nimbus, the state moved its own cloud landing zone out of an overseas public cloud. It moved into the new Israeli region as soon as that region opened. SECURITIES, TELECOMS, EDUCATION, GAMING, MAPPING AND DEFENCE. We found no rule requiring data to stay in the country on an Israeli government source. We checked on 18 August 2026. Confidence medium. The National Cyber Directorate's published map of cyber rules records that the Ministry of Communications has not issued any cyber rules for telecoms operators.
Sources
- Official sourcePrivacy Protection Authority, Ministry of JusticePrivacy Protection (Transfer of Data to Databases Abroad) Regulations, 5761-2001, Regulations 1 to 3
gov.il
“A person shall not transfer, nor shall he enable, the transfer abroad of data from databases in Israel, unless the law of the country to which the data is transferred ensures a level of protection no lesser, mutatis mutandis, than the level of protection of data provided for by Israeli Law”
Link checked 18 August 2026
- Official sourceBank of Israel, Banking Supervision DepartmentProper Conduct of Banking Business Directive 362 — Cloud Computing, version in force from 17 June 2026, section 7
boi.org.il
Link checked 18 August 2026
- Official sourceCapital Market, Insurance and Savings AuthorityInstitutional Bodies Circular 2018-9-35 — Outsourcing in institutional bodies, 31 December 2018
gov.il
Link checked 18 August 2026
- Official sourceMinistry of HealthDirector-General Circular 2/2021 — Use of cloud computing in the health system, 21 February 2021, section 6.5
gov.il
Link checked 18 August 2026
- Official sourceIsrael National Cyber Directorate / National Digital AgencyIsrael's government moves to the cloud — Project Nimbus; the government landing zone was moved from an overseas public cloud to the local Israeli region
gov.il
Link checked 18 August 2026
- Official sourceIsrael National Cyber DirectorateRegulation in the field of cyber protection — sector-by-sector map; telecoms cyber regulation recorded as not yet published
gov.il
Link checked 18 August 2026
What to do: Get the paperwork for one of the routes below signed before any data leaves Israel.
Sending data out of the country
You can only send data to countries that qualify, and the qualifying list is already large. A country counts if it signed the Council of Europe data protection convention. It also counts if it receives data from European Union countries on the same terms. So Europe's approved-country list does much of the work. If your destination does not qualify, the usual fallback is a contract. In it, the receiver promises to meet Israeli standards. Either way, you also need a separate written promise from the receiver. It must promise to protect the data and pass it to nobody else.
- What you have to do here:
- Put a transfer safeguard in place
- Ways to send data out:
- Official 'this country is safe' decision · Standard contract clauses · Approved group rules · Explicit consent · To save someone’s life · Important public interest
Regulation 1 of the Transfer of Data to Databases Abroad Regulations 5761-2001 sets the test for whether a country protects data well enough. Regulation 2 lists eight alternatives. The person consents. Or the transfer protects someone's life or health and you cannot get consent. Or you send to a company you control that has guaranteed privacy. Or the receiver signs a contract accepting the conditions that would apply to a database in Israel, with the changes needed to fit. Or the data is already lawfully public. Or the transfer is vital to public safety or security. Or Israeli law requires it. Or the country is party to the Council of Europe convention. Or it receives data from European Community member states under the same terms of acceptance. Or the Registrar has announced in the official gazette that it has a privacy authority Israel has a cooperation arrangement with. Regulation 3 adds a written guarantee on top of whichever route you use, including a promise not to pass the data on again. On 9 April 2026, updated 30 April 2026, the Privacy Protection Authority published its final binding opinion. It explains what 'with necessary modifications' means in the contract route. The contract must bind the receiver to four things. Use the data only for the stated purpose. Honour the right of access under Article 13. Honour the right of correction or deletion under Article 14. And keep the data confidential under Article 16. On security, the receiver must promise to meet the substance of the Data Security Regulations 5777-2017. Or it can declare that it holds ISO/IEC 27001 certification, including the Annex A controls. It must also promise the specific regulations listed in the Authority's Guideline 3/2018. The Authority accepts that Israeli database registration and notification duties need not be copied abroad where the destination has no similar duty. The opinion also confirms one more point. Say your Israeli database also holds data that arrived from the European Economic Area. Then the foreign receiver must also promise Regulations 3 to 7 of the 2023 European Economic Area regulations.
Sources
- Official sourcePrivacy Protection AuthorityFinal binding opinion on transferring personal data outside Israel — interpretation of Regulation 2(4), published 9 April 2026, updated 30 April 2026
gov.il
Link checked 18 August 2026
- Official sourcePrivacy Protection AuthorityOpinion text — contract must mirror Articles 2(9), 8(b), 13, 14 and 16, plus the Data Security Regulations or ISO/IEC 27001
gov.il
Link checked 18 August 2026
- Official sourcePrivacy Protection Authority, Ministry of JusticeTransfer of Data to Databases Abroad Regulations 5761-2001, Regulation 2(8) and Regulation 3
gov.il
“the owner of the database shall ensure, in a written guarantee by the recipient of the data, that recipient of the data is taking adequate measures to ensure the privacy of the data subjects, and that he guarantees that the data shall be transferred to no other person”
Link checked 18 August 2026
What to do: Get the approved standard contract clauses signed with every vendor that touches this data, before it leaves.
The regulator, and whether it actually acts
The Privacy Protection Authority enforces the rules. It is part of the Ministry of Justice and is fully up and running. It has a serving commissioner and an enforcement department. It publishes its decisions with names and amounts. In 2026 it fined a national health fund about 256,000 shekels (roughly 72,000 US dollars). The fund had taken two months to report a security incident. It also fined a small leisure company about 12,000 shekels (roughly 3,400 US dollars) for a faulty privacy notice. Industry regulators enforce their own rules separately. Those are the Bank of Israel, the insurance regulator and the Ministry of Health.
- What it costs if you get it wrong:
- Fixed maximum fine · Order to stop · Criminal liability
The Authority is headed by Commissioner Gilad Semama. Amendment 13 has been in force since 14 August 2025. It gave the Authority inspectors, powers to run inquiries, and powers to search and seize. It can also impose money penalties, order you to stop using data, and ask a court to order personal data deleted. As at 18 August 2026 it has published two decisions since Amendment 13. The first was against Meuhedet Health Fund. A technical fault let some members view other people's medical records. Regulation 11(d)(1) of the Data Security Regulations says you must report a severe security incident immediately. The fund learned of the fault in November 2025 but only reported it on 27 January 2026. The penalty started at 640,000 shekels (about 180,000 US dollars). It was cut by 60 percent to 256,000 shekels. The fund had no earlier breaches, stopped the problem on its own initiative and had appointed a privacy officer. The second decision was against A.D. Karting Hutzot (2014) Ltd. Its booking form collected personal data without the notice Article 11 requires. The penalty was 20,000 shekels, reduced to 12,000. We rate the Authority 'active' rather than 'aggressive'. It is clearly staffed. It has published a graduated scale of penalties and reductions, and it is using it. But the published caseload is still small and the first fines are modest.
Sources
- Official sourcePrivacy Protection AuthorityAdministrative enforcement — published enforcement proceedings after Amendment 13 came into force
gov.il
“תיקון 13 לחוק הגנת הפרטיות, שנכנס לתוקפו באוגוסט 2025, עדכן את סמכויות האכיפה של הרשות”
Link checked 18 August 2026
- Official sourcePrivacy Protection AuthorityThe Privacy Protection Authority — role holders, Commissioner Gilad Semama; regulator for administrative and criminal enforcement
gov.il
Link checked 18 August 2026
- Official sourceIsrael National Cyber DirectorateCyber regulation is deliberately decentralised to sector regulators under Government Resolution 2443 of 15 February 2015
gov.il
Link checked 18 August 2026
How long you must keep it — and when to delete it
There is a minimum keeping time and a duty to delete, and they sit close together. You must keep security and access-monitoring records for at least 24 months. If you run a medium or high security database, you must also keep a backup you can restore. On the other side, if your database holds anything that came from Europe, you must delete data you no longer need. You need a working method that finds it. You must also delete data when someone asks. If another law says you must keep something, that law wins.
- What you have to do here:
- Keep data for a minimum period · Delete data after a period · Let people delete their data
The 24-month minimum comes from Regulations 10(d) and 17(a) of the Data Security Regulations 5777-2017. You must keep records from the access-monitoring system for 24 months, held securely. The same goes for data collected under the documentation, access-control, incident and outsourcing-control rules. Regulation 17(b) says medium and high security databases must back that up so it can always be restored. The duty to delete comes from the European Economic Area regulations of 2023. Regulation 4 requires a standing method, organisational or technical, that finds data you no longer need and deletes it at the earliest opportunity. Regulation 3 gives people a written right to erasure where data was collected unlawfully or is no longer needed for its purpose. When the two pull in opposite directions, keeping wins. Both regulations let you keep data you need for certain purposes. Meeting a legal duty. Running a legal case. Collecting a debt. Tackling fraud. Protecting a public interest, including archives and research. Or meeting an international agreement. Amendment 13 also pushes you to hold less data overall. The Authority's own guidance tells businesses to cut down existing data they no longer need. Israeli tax and company bookkeeping rules set their own longer minimum keeping times. We did not check those against an official source.
Sources
- Official sourcePrivacy Protection Authority, Ministry of JusticePrivacy Protection (Data Security) Regulations 5777-2017, Regulations 10(d) and 17
gov.il
“The records of the monitoring mechanism will be retained for at least 24 months.”
Link checked 18 August 2026
- Official sourcePrivacy Protection Authority, Ministry of JusticePrivacy Protection Regulations (Instructions for Data Transferred to Israel from the European Economic Area) 5783-2023, Regulations 3 and 4
gov.il
Link checked 18 August 2026
- Official sourcePrivacy Protection AuthorityHow to prepare for Amendment 13 — official preparation steps including reducing data no longer needed
govextra.gov.il
Link checked 18 August 2026
What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.
If something goes wrong
You must report a severe security incident to the Privacy Protection Authority immediately. No number of hours is given. 'Immediately' is taken literally. A health fund was fined for a two-month delay. You must also say what you did about the incident. Telling the affected people is not automatic. The Authority decides, after asking the national cyber agency, and it can order you to tell them. Israel has no general law making every company report cyber incidents to the state. So any second deadline comes from your industry regulator.
- What you have to do here:
- Report breaches to the regulator · Tell affected people · Report cyber incidents
Regulation 11(d)(1) of the Data Security Regulations 5777-2017 sets the main duty. On a severe security incident you must immediately tell the Registrar. That is now the head of the Privacy Protection Authority. You must also report what you did about it. Under Regulation 11(d)(2), the Registrar may order you to tell a person who could be harmed. It must first consult the head of the National Cyber Defence Authority. 'Severe security incident' is defined narrowly. In a high-security database it means any unauthorised use of data, or damage to the integrity of data. In a medium-security database it means unauthorised use of a substantial part of the database, or damage to the integrity of a substantial part. Low-security databases are outside the duty. Israel spreads cyber rules across industry regulators on purpose. Government Resolution 2443 of 15 February 2015 chose to give powers to existing regulators rather than create a new one. So there is no single incident reporting deadline across the economy. Some industries do set deadlines. Insurers and pension bodies must report an unusual event to the Commissioner close to the time they learn of it. As of the National Cyber Directorate's current published map, the Ministry of Communications had still not published cyber rules for telecoms operators.
Sources
- Official sourcePrivacy Protection Authority, Ministry of JusticeData Security Regulations 5777-2017, Regulation 1 definition of 'severe security incident' and Regulation 11(d)
gov.il
“In case of a severe security incident - (1) The database controller will immediately notify the Registrar and report to the Registrar on the measures he took following the incident;”
Link checked 18 August 2026
- Official sourcePrivacy Protection AuthorityEnforcement decision against Meuhedet Health Fund for failing to report a severe security incident immediately
gov.il
Link checked 18 August 2026
- Official sourceIsrael National Cyber DirectorateCyber regulation map — no single national cyber regulator; each sector regulator sets its own rules
gov.il
Link checked 18 August 2026
What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.
What catches people out
Five things the summary does not cover. One: a single record that arrived from Europe pulls the whole database into the stricter European rules. Since 1 January 2025 those rules cover any other data sitting in the same database. Two: 'immediately' really means immediately. There is no safe 72-hour habit to fall back on. Three: fines are worked out per person, not as a flat cap. A large database turns a small breach into a very large bill. Four: privacy breaches are crimes, not just regulatory matters, and they carry prison terms. Five: 'data security officer' and 'data protection officer' are two different Israeli roles. They have different triggers. Having one does not cover the other.
- What you have to do here:
- Appoint a data protection officer · Report breaches to the regulator
- What it costs if you get it wrong:
- Criminal liability · Fixed maximum fine · Claims by individuals
(1) Regulation 2(a)(2) of the European Economic Area regulations widens their reach. They cover 'any other data that is in a database in Israel that contains data' transferred from the European Economic Area. This has applied to mixed data since 1 January 2025. It also matters when you send data out. The Authority's April 2026 opinion makes the foreign receiver promise Regulations 3 to 7 as well. (2) The Meuhedet decision fined a two-month delay. (3) Article 23KF prices most breaches per person. It is 2 shekels per person, doubled to 4 for specially sensitive data. That band covers failures such as not appointing a data security officer or data protection officer. It is 4 shekels per person, doubled to 8 for specially sensitive data. That band covers using data for an unlawful purpose, or ignoring an order to stop. On a database of a million people holding sensitive data, the second band gives 8 million shekels, roughly 2.2 million US dollars. Registration breaches carry a flat 150,000 shekels (about 42,000 US dollars), doubled where the database covers a million people or more. Refusing to give an inspector documents carries 300,000 shekels (about 85,000 US dollars). (4) Article 5 makes deliberate invasion of privacy punishable by five years in prison. Amendment 13 added a chapter of database crimes. Using personal data from a database without permission from the company that holds it carries three years. Misleading someone when asking for their personal data carries three years. Unlawfully moving data out of a public body carries three years. (5) Article 17B, the data security officer, is triggered by holding five registrable databases, or by being a public body, bank, insurer or credit rater. Article 17B1 covers the data protection officer. It is triggered by being a public body. Or a data broker with more than 10,000 people. Or a systematic monitor. Or a large-scale handler of specially sensitive data. One more trap. Amendment 13 removed the short two-year time limit for civil privacy claims. Old exposure now runs for the ordinary time limit.
Sources
- Official sourcePrivacy Protection Authority, Ministry of JusticePrivacy Protection Law 5741-1981 updated after Amendment 13 — Articles 5, 23KF, 23NE to 23NG
gov.il
“Processing personal data from a database without authorization from the database controller, contrary to the provisions of Article 8(c), is subject to three years imprisonment.”
Link checked 18 August 2026
- Official sourcePrivacy Protection Authority, Ministry of JusticeEuropean Economic Area regulations 5783-2023, Regulation 2(a)(2) — application to any other data in the same database
gov.il
“(2) Any other data that is in a database in Israel that contains data as stated in sub-regulation (1).”
Link checked 18 August 2026
- Official sourcePrivacy Protection AuthorityProfessional guide to Amendment 13 — abolition of the shortened limitation period for civil privacy claims
gov.il
Link checked 18 August 2026
What's changing next
The big change already happened on 14 August 2025. The detail underneath it is landing now. In April 2026 the regulator finalised its binding rules on the contract you must sign before sending data abroad. Separate regulations also came into force. They give a short grace period, a warning instead of a fine, for brand-new duties. A guideline applying privacy law to artificial intelligence is also live. It includes a need for consent before scraping the web to train models. Three further changes can happen with no warning.
Dated items. 14 August 2025: Amendment 13 came into force, one year after it was published in the official gazette on 14 August 2024. 1 January 2025: the European Economic Area regulations were extended to mixed data. 9 April 2026, updated 30 April 2026: the final binding opinion on the contract route for sending data abroad. 16 April 2026: the Privacy Protection (Administrative Warning) Regulations 5786-2026 came into force. They let the Authority give a warning instead of a money penalty in four cases. Within three months of a new duty taking effect. On a first breach of certain data security regulations. For up to six months after the Authority tightens its enforcement policy in an area it had not enforced before. And for up to six months where the duty is unclear. A warning is only possible where a fine could lawfully have been imposed. Three things can change with no warning and no consultation. First, the Authority may announce in the official gazette that a named foreign country has a privacy authority it has a cooperation arrangement with. That would make the country a permitted destination overnight. We could not confirm whether any such announcement has been published. Second, the Minister of Justice may issue an order, with the approval of the Knesset Constitution Committee. It would extend the per-person money penalty for ignoring an order to stop or fix to systematic monitors and large-scale handlers of sensitive data. They are currently outside it. Third, Israel holds an official European decision that it protects data well enough. The European Commission reaffirmed it on 15 January 2024, and European Union bodies are expected to debate it further. Everything about sending data in and out rests on that decision. Israeli exporters use Europe's approved-country list through Regulation 2(8). Israeli importers rely on the decision in the other direction. On artificial intelligence, the Authority has published a guideline. It applies the Privacy Protection Law across the whole life of an artificial intelligence system, from training to use. It says scraping personal data from the internet to train models needs informed consent. Posting something about yourself online does not give that consent. Consultation on the draft closed 31 July 2025.
Sources
- Official sourcePrivacy Protection AuthorityPrivacy Protection (Administrative Warning) Regulations 5786-2026 — entered into force 16 April 2026
gov.il
Link checked 18 August 2026
- Official sourcePrivacy Protection AuthorityGuideline — application of the Privacy Protection Law to artificial intelligence systems
gov.il
Link checked 18 August 2026
- Official sourcePrivacy Protection AuthorityThe EU Commission reaffirmed its recognition of Israel's adequate level of data protection, 15 January 2024
gov.il
“on 15 January 2024 the European Commission published its decision, according to which Israel continues to provide an adequate level of protection for personal data transferred from the EU”
Link checked 18 August 2026
- Official sourceKnessetPrivacy Protection Law (Amendment No. 13), 5784-2024 — national legislation database; gazette publication 14 August 2024, Sefer HaChukim 3287 p. 1430
main.knesset.gov.il
Link checked 18 August 2026
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries5 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Cloud and outsourcing rules
Official name: הוראות ניהול בנקאי תקין 362 - מחשוב ענן · Proper Conduct of Banking Business Directive 362 — Cloud Computing; current version issued by Circular 2849 · Regulator directive
Israeli banks may use cloud outside Israel, including for important services. First they must check that the provider protects sensitive customer data to European standards. The bank must also plan for a foreign region becoming unavailable for political reasons.
Enforced by Bank of Israel — Banking Supervision Department
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses
What you have to do
- Put a transfer safeguard in placeSection 7. A bank may not store, move or use information it treats as sensitive on a cloud outside Israel. It may only do so once it has checked that the provider's protection matches the European General Data Protection Regulation.
- Written vendor contractThe contract must state where the cloud facility is and where data is stored, and commit the provider to that location.
- Hold a security certificateSection 39. Main and backup cloud sites must meet Uptime Institute Tier 3. Prove it with a certificate or an independent opinion.
- Assess high-risk projectsSection 38 and the risk chapter. The bank must plan for the foreign region becoming unavailable. Causes include a communications failure or political events. The bank must also assess the legal risk of using a cloud outside Israel.
Sources
- Official sourceBank of Israel, Banking Supervision DepartmentDirective 362 — Cloud Computing, Hebrew text as updated 17 June 2026, sections 7, 9, 38
boi.org.il
Link checked 18 August 2026
- Official sourceBank of IsraelDirective 362 — Cloud Computing, English translation (June 2022 version), section 7
boi.org.il
“A banking corporation shall not store, transfer, or process information that it defines as "sensitive" (e.g., customer data, confidential business information, etc.) on a cloud outside the borders of the State of Israel unless it has ascertained that the cloud-service provider maintains a level of protection that complies with the European Union General Data Protection Regulation (GDPR).”
Link checked 18 August 2026
- Official sourceBank of IsraelDirective 362 landing page showing publication date 17/06/2026 and circular number 2849
boi.org.il
Link checked 18 August 2026
Cloud and outsourcing rules (Insurance)
Official name: חוזר גופים מוסדיים 2018-9-35 - מיקור חוץ בגופים מוסדיים · Institutional Bodies Circular 2018-9-35 — Outsourcing in institutional bodies · Regulator directive
Insurers and pension providers may outsource abroad, but the regulator sees every deal. Your board must approve a policy. You must assess what it means to run the work outside Israel. You must send the Commissioner an annual list marking each deal that is abroad.
Enforced by Capital Market, Insurance and Savings Authority
What you have to do
- Written vendor contractYour board must approve an outsourcing policy. It must deal directly with work carried out outside Israel, or with a provider based outside Israel. It must also cover what follows from the work being done abroad.
- Keep records of how you use data — 1 yearSend the Commissioner an annual return as a spreadsheet. List every outsourcing deal in force at 31 December. Include a yes or no field for whether the work is outsourced abroad.
- Report breaches to the regulatorReport an unusual event to the Commissioner immediately, close to the time you learn of it.
Sources
- Official sourceCapital Market, Insurance and Savings AuthorityInstitutional Bodies Circular 2018-9-35 — Outsourcing, 31 December 2018
gov.il
Link checked 18 August 2026
- Official sourceIsrael National Cyber DirectorateNational Cyber Directorate map confirming this circular is the operative outsourcing rule for the insurance and savings sector
gov.il
Link checked 18 August 2026
Cloud and outsourcing rules (Health and social care)
Official name: חוזר מנכ"ל משרד הבריאות 2/2021 - שימוש במחשוב ענן במערכת הבריאות · Ministry of Health Director-General Circular 2/2021 — Use of cloud computing in the health system · Regulator directive
Israeli hospitals and health funds may use cloud abroad. The country must meet the national transfer regulations. You must first assess what foreign law would do to the data. The rules are relaxed about where the data goes and strict about how you manage it.
Enforced by Ministry of Health
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses
What you have to do
- Assess high-risk projectsBefore you sign, assess what using a cloud outside Israel means. That includes which foreign law would apply to the data.
- Written vendor contractThe contract must cover who is responsible for what, security controls, and audit rights over the provider and its subcontractors. It must also cover incident handling and reporting, how you exit and get data back or deleted, and keeping the service running.
- Independent audit — 2 yearsRe-evaluate the provider and the services at least once every two years.
Sources
- Official sourceMinistry of HealthDirector-General Circular 2/2021 — Use of cloud computing in the health system, sections 6.2.5 and 6.5
gov.il
Link checked 18 August 2026
- Official sourcePrivacy Protection AuthorityProtecting patient privacy when transferring medical data by digital means — text updated after Amendment 13; bans routine use of consumer messaging and consumer cloud backup for patient data
gov.il
Link checked 18 August 2026
Health and social care data must stay in the country
Official name: חוזרי מנכ"ל משרד הבריאות 1/2018 ו-2/2018 - שימושים משניים במידע בריאות · Ministry of Health Director-General Circulars 1/2018 and 2/2018 — Secondary uses of health data, and collaborations based on secondary uses · Regulator directive
For research use of health records, the data must stay inside the hospital or health fund. Staying inside Israel is not enough. Work on data that names people in a secure research space inside the organisation. Taking individual records outside the organisation's control needs ethics-committee approval and a promise to destroy the data.
Enforced by Ministry of Health
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed, Explicit consent
What you have to do
- Keep the data in the countryWhat matters is who controls the data, not which country it is in. Patient data that names people and is used for research must stay under the health organisation's control. You normally access it inside a secure physical or virtual research room. Releasing individual records, even with names removed, needs a reasoned approval from the ethics committee and the organisation's authorised officer.
- Extra vendor secrecy termsEveryone given access must sign a promise, inside or outside the organisation. They will keep the data confidential. They will not try to re-identify people. They will not use it for anything else. They will not pass it on without approval.
- Delete data after a periodThe recipient must destroy every identifying variable when the research ends.
What it costs if you get it wrong
- Order to stopThe Director-General may suspend the organisation's ethics committee authority to approve secondary uses, in whole or in part
Sources
- Official sourceMinistry of HealthDirector-General Circular 1/2018 — Secondary uses of health data, sections 8.3, 8.4 and 8.6
gov.il
Link checked 18 August 2026
- Official sourceMinistry of HealthDirector-General Circular 2/2018 — Collaborations based on secondary uses of health data, section 6.3.4
gov.il
Link checked 18 August 2026
AI rules
Official name: הנחיה - תחולת חוק הגנת הפרטיות על מערכות בינה מלאכותית · Privacy Protection Authority guideline on the application of the Privacy Protection Law to artificial intelligence systems · Regulator guideline
The regulator says Israeli privacy law covers data you feed into an artificial intelligence system. It also covers data the system works out for itself. Its sharpest point: training a model on scraped personal data needs the person's informed consent.
Enforced by Privacy Protection Authority
What you have to do
- Get consentYou need consent at every stage of the life cycle, including training. Scraping personal data from the internet to train a model needs informed consent. Someone posting about themselves online does not count as giving it.
- Tell people what you doTell people when they are dealing with an automated system rather than a human. This applies where it would change their decision to consent. Tell them enough about how the system works for their consent to mean something.
- Let people correct their dataThe right to correct wrong data may extend to correcting the algorithm that produced it.
- Assess high-risk projectsThe Authority says it will push on privacy impact assessments. It will enforce the duty to appoint a privacy officer especially firmly where artificial intelligence is involved.
Sources
- Official sourcePrivacy Protection AuthorityGuideline — application of the Privacy Protection Law to artificial intelligence systems
gov.il
Link checked 18 August 2026
Applies to every company6 rules
These bind you whatever business you are in, once the country's rules reach you.
General data protection law
Official name: חוק הגנת הפרטיות, התשמ"א-1981 (כנוסחו לאחר תיקון מס' 13) · Privacy Protection Law 5741-1981, as amended by Amendment No. 13, 5784-2024; Sefer HaChukim 3287, p. 1430 · Act of parliament
Israel's general privacy law. Amendment 13 rewrote it, starting on 14 August 2025. It cut private-sector database registration almost to nothing. It added a duty to appoint a data protection officer. It created new crimes. It gave the regulator inspectors and money penalties charged per person.
Enforced by Privacy Protection Authority
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses
What you have to do
- Tell people what you doArticle 11. You must tell people why you are asking, who holds the database and how to reach them, and about their access and correction rights.
- Let people see their dataArticle 13.
- Let people correct their dataArticle 14.
- Let people delete their dataArticle 14. There is also a wider right to deletion for data that came from Europe.
- Secure the dataArticle 17. The company that decides how the data is used and anyone holding it are both responsible.
- Appoint a data protection officer — applies at: Public bodies; data brokers with more than 10,000 people; organisations doing regular systematic monitoring; large-scale processors of specially sensitive dataArticle 17B1. May be an outside contractor. Reports directly to the chief executive or someone reporting directly to them.
- Appoint a data protection officer — applies at: Controllers or processors of five registrable databases; public bodies; banks; insurers; credit ratersArticle 17B. This is the separate, older 'data security officer' role. You may not appoint someone convicted of a crime involving moral turpitude.
- Register or notify — applies at: Databases whose main purpose is supplying personal data to others as a business and holding data on more than 10,000 people; public bodiesArticle 8A(a). Amendment 13 all but abolished private-sector registration.
- Keep records of how you use data — applies at: More than 100,000 people with specially sensitive data, in a database not otherwise registrable, 1 monthArticle 8A(b). Tell the Authority within 30 days. Include details of the company that decides how the data is used, details of the privacy officer, and a copy of the database definitions document.
What it costs if you get it wrong
- Fixed maximum fine: 300,000 NIS — about $85 thousandProcessing a registrable database without registering it, where the database covers a million people or more (150,000 NIS otherwise)
- Fixed maximum fine: 300,000 NIS — about $85 thousandFailing to give an inspector a document or a copy of computer material
- Fixed maximum fine: 8 NIS per person in the database — about $2.25Processing for an unlawful purpose, or ignoring a cease-processing order, where the data is specially sensitive. On a million-person database this is about 8m NIS (roughly $2.2m).
- Criminal liability: 5 years imprisonmentWilfully infringing another person's privacy (Article 5)
- Criminal liability: 3 years imprisonmentProcessing data from a database without the controller's authorisation; misleading someone when requesting their data; unlawful transfer of data out of a public body
- Order to stopCourt order to stop processing or to delete personal data, on the Authority's application
- Claims by individualsInfringement of privacy is a civil wrong; Amendment 13 abolished the shortened two-year limitation period
Sources
- Official sourcePrivacy Protection Authority, Ministry of JusticePrivacy Protection Law, 5741-1981 — official English translation updated after Amendment 13
gov.il
Link checked 18 August 2026
- Official sourceKnessetPrivacy Protection Law (Amendment No. 13), 5784-2024 — national legislation database record
main.knesset.gov.il
Link checked 18 August 2026
- Official sourcePrivacy Protection AuthorityProfessional guide: Amendment No. 13 — 'entered into force on 14 August 2025'
gov.il
Link checked 18 August 2026
Data rules
Official name: תקנות הגנת הפרטיות (העברת מידע אל מאגרי מידע שמחוץ לגבולות המדינה), התשס"א-2001 · Privacy Protection (Transfer of Data to Databases Abroad) Regulations, 5761-2001 · Directly binding regulation
Data may only leave Israel if the country you send to protects it at least as well as Israeli law does. If not, one of eight listed exceptions must apply. Whichever route you use, the receiver must also sign a written promise. It must promise to protect the data and not pass it on.
Enforced by Privacy Protection Authority
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Explicit consent, To save someone’s life, Important public interest
What you have to do
- Put a transfer safeguard in placeRegulation 3. You need a written guarantee from the receiver. It protects the data and passes it to nobody else, in any country. This applies on top of whichever route you use.
- Written vendor contractRegulation 2(4). The receiver signs a contract accepting the conditions that would apply to a database in Israel.
Sources
- Official sourcePrivacy Protection Authority, Ministry of JusticeProtection of Privacy (Transfer of Data Abroad) Regulations — official English translation
gov.il
“The data is transferred to a database in a country- (1) which is a Party to the European Convention for the Protection of Individuals with Regard to Automatic Processing of Sensitive Data; (2) which receives data from Member States of the European Community, under the same terms of acceptance”
Link checked 18 August 2026
- Official sourcePrivacy Protection AuthorityLegislation page of the Privacy Protection Authority, listing the transfer regulations
gov.il
Link checked 18 August 2026
Data rules (2026)
Official name: גילוי דעת בנושא העברת מידע אישי מחוץ לישראל - פרשנות תקנה 2(4) · Privacy Protection Authority binding opinion on Regulation 2(4) of the Transfer of Data Abroad Regulations · Regulator guideline
The regulator's final and binding reading of the contract route out of Israel, published in April 2026. Your contract must contain these exact promises. Without them you cannot use that route.
Enforced by Privacy Protection Authority
How this country controls where data goes: Only approved countries · Accepted routes: Standard contract clauses, Certification scheme
What you have to do
- Written vendor contract — from 9 April 2026The contract must make the receiver use the data only for the stated purpose. It must also honour the right of access, the right of correction and deletion, and the duty of confidentiality.
- Hold a security certificateThere is an alternative to promising the Data Security Regulations in full. Declare that you hold ISO/IEC 27001 certification, including all relevant Annex A controls. Add the specific regulations named in the Authority's Guideline 3/2018.
- Put a transfer safeguard in placeSay the Israeli database also holds data from the European Economic Area. Then the receiver must also promise Regulations 3 to 7 of the 2023 European Economic Area regulations.
Sources
- Official sourcePrivacy Protection AuthorityFinal binding opinion on transferring personal data outside Israel — Regulation 2(4), published 9 April 2026, updated 30 April 2026
gov.il
Link checked 18 August 2026
- Official sourcePrivacy Protection AuthorityOpinion text, paragraphs 8 to 13
gov.il
Link checked 18 August 2026
Data rules (2025)
Official name: תקנות הגנת הפרטיות (הוראות לעניין מידע שהועבר לישראל מהאזור הכלכלי האירופי), התשפ"ג-2023 · Privacy Protection Regulations (Instructions for Data Transferred to Israel from the European Economic Area), 5783-2023 · Directly binding regulation
Extra European-style duties on data that arrived in Israel from the European Economic Area. Watch Regulation 2(a)(2). From 1 January 2025 the duties also cover any other data sitting in the same database. So one European record can pull an entire customer database into the stricter rules.
Enforced by Privacy Protection Authority
How this country controls where data goes: Only approved countries · Accepted routes: Standard contract clauses
What you have to do
- Let people delete their dataRegulation 3. Delete data on written request where it was collected unlawfully or is no longer needed. Listed exceptions apply.
- Delete data after a periodRegulation 4. Run a standing method that finds data you no longer need. Delete it at the earliest opportunity.
- Tell people what you do — within 720 hoursRegulation 6. Within one month of receiving someone's data, tell them four things. Who you are. Why the data was transferred. What type of data it is. And what rights they have. Tell them again before you pass it to anyone else.
Sources
- Official sourcePrivacy Protection Authority, Ministry of JusticeEuropean Economic Area regulations 5783-2023 — official English translation
gov.il
Link checked 18 August 2026
- Official sourcePrivacy Protection AuthorityPrivacy Protection Authority page for the European Economic Area regulations
gov.il
Link checked 18 August 2026
- Official sourcePrivacy Protection AuthorityAuthority opinion, footnote 7 — the regulations apply to co-mingled Israeli data from 1 January 2025
gov.il
Link checked 18 August 2026
Breach reporting rules
Official name: תקנות הגנת הפרטיות (אבטחת מידע), התשע"ז-2017 · Privacy Protection (Data Security) Regulations, 5777-2017 · Directly binding regulation
The day-to-day security rulebook. It covers security levels, a written procedure, access controls and keeping records for 24 months. Most important, you must report a severe security incident immediately. The regulator's first big fine came from this rulebook.
Enforced by Privacy Protection Authority
What you have to do
- Report breaches to the regulatorRegulation 11(d)(1). Report immediately. No number of hours is given. This covers a severe security incident in a medium or high security database.
- Tell affected peopleRegulation 11(d)(2). This is not automatic. The regulator may order it, after asking the head of the National Cyber Defence Authority.
- Keep logs — 2 yearsRegulations 10(d) and 17. Keep access-monitoring records and other security records securely. In medium and high security databases, back them up so they can be restored.
- Secure the dataWritten data security procedure, database definitions document, access control, physical and network security.
- Written vendor contractRegulation 15. If you hire an outside provider, your contract must set out what data it gets, for what purpose and for how long. You must also control and supervise the provider.
- Independent auditAudit regularly. One audit may cover several databases of the same security level.
What it costs if you get it wrong
- Fixed maximum fine: 640,000 NIS imposed, reduced to 256,000 NIS — about $180 thousandActual 2026 sanction on Meuhedet Health Fund for failing to report a severe security incident immediately
Sources
- Official sourcePrivacy Protection Authority, Ministry of JusticePrivacy Protection (Data Security) Regulations 5777-2017 — official English translation
gov.il
Link checked 18 August 2026
- Official sourcePrivacy Protection AuthorityAdministrative enforcement decisions — Meuhedet Health Fund, Regulation 11(d)(1)
gov.il
Link checked 18 August 2026
Data rules (Privacy Protection (Administrative Warning) Regulations, 5786-2026)
Official name: תקנות הגנת הפרטיות (התראה מינהלית), התשפ"ו-2026 · Privacy Protection (Administrative Warning) Regulations, 5786-2026 · Directly binding regulation
This gives you grace, it does not add a duty. The regulator may give a warning instead of a fine in four situations. One is within three months of a brand-new duty starting. Another is for up to six months where the duty is unclear. A warning is only possible where a fine could lawfully have been imposed.
Enforced by Privacy Protection Authority
Sources
- Official sourcePrivacy Protection AuthorityPrivacy Protection (Administrative Warning) Regulations 5786-2026 — 'today the regulations come into force', 16 April 2026
gov.il
Link checked 18 August 2026
Applies only if you signed a contract1 rule
Usually a government or enterprise contract that adds rules of its own.
Government data must stay in the country
Official name: פרויקט נימבוס - מדיניות הענן הממשלתית · Project Nimbus; Government Resolutions 852 (2021), 231 (2021), 1700 (2024), 2273 (2024) and 3574 of 4 December 2025; Accountant General instruction 16.12.1 · Government policy document
Central government buys cloud only through the Nimbus tenders. Its shared platform sits in Israeli cloud regions on purpose. This is a buying rule, not a law. But selling cloud to the Israeli state needs a region inside the country.
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed
What you have to do
- Keep the data in the countryThis is not a law. The government moved its central cloud landing zone out of an overseas public cloud and into the Israeli region as soon as it opened. Officials described this as keeping control over the data of Israeli citizens and government systems.
- Register or notifyMinistries must buy cloud only from the providers chosen in the central Nimbus tenders. They must use the named cross-government solutions rather than build their own.
Sources
- Official sourceIsrael National Cyber Directorate / National Digital AgencyIsrael's government moves to the cloud — Project Nimbus; the government landing zone was relocated from an overseas public cloud to the Israeli region
gov.il
Link checked 18 August 2026
- Official sourceGovernment SecretariatGovernment Resolution 3574 of 4 December 2025 — accelerating digital services, data and artificial intelligence on the Nimbus public cloud
gov.il
Link checked 18 August 2026
- Official sourceMinistry of Finance, Accountant GeneralAccountant General instruction 16.12.1 — Project Nimbus, general guidance on procuring public cloud services
takam.mof.gov.il
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.
Whether any country has actually been named in the official gazette under Regulation 2(8)(3) as having a privacy authority with a cooperation arrangement with Israel.
The regulation creates the power. The Authority has signed cooperation statements with the Dubai International Financial Centre and Abu Dhabi Global Market. But we found no published gazette announcement naming any country. Treat this route as unavailable until you see the announcement.
That Israeli tax and company law require books and records to be kept for seven years.
This figure is widely reported as the minimum under the Income Tax (Bookkeeping) Instructions 1973. We could not confirm it on an Israel Tax Authority page, so we have not put a number in the record. Check with the Israel Tax Authority before you rely on it.
That there is no where data has to be stored rule for securities firms, telecoms operators, education, online gaming, mapping or defence.
We found no such rule on an Israeli government source, checked 18 August 2026. We could not confirm it either way. The National Cyber Directorate's own map records that the Ministry of Communications has published no cyber rules for telecoms at all. A public consultation on adding cyber conditions to telecoms licences opened in August 2021 and has not visibly finished. We could not reach Israel Securities Authority cloud or outsourcing guidance. If you work in these industries, check before you rely on this.
The exact date on which the artificial intelligence guideline moved from draft to final.
The Privacy Protection Authority page is titled as a guideline. It says it was published 'in a first stage' as a draft, with comments due by 31 July 2025. The page did not show a publication or update date. We have dated it to the consultation period and set confidence to medium.
That the Privacy Protection Law reaches foreign companies with no Israeli presence.
The law itself says nothing about who and where it covers. Our conclusion rests on three things. The Authority's own guide. A footnote in its April 2026 opinion accepting that databases abroad can be subject to Israeli law. And its past investigation of a foreign platform. None of these are express words in the law. A foreign company with no Israeli office has a real argument here. That is why confidence on question one is medium.
That the Project Nimbus localisation requirement is legally binding rather than contractual.
We confirmed that the government's shared cloud platform was moved into the Israeli region. We also confirmed that ministries must buy through the central tenders. We could not get the tender conditions themselves. So we record this as a buying rule, not a law.
The precise commencement date of the Data Security Regulations 5777-2017.
Regulation 22 says only that they take effect one year after publication. We have used 8 May 2018, the date usually cited. We could not confirm the gazette publication date directly.
Freshness and refresh
Freshness
Checked about 2 months ago, on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.