Skip to the content
Global Data RulesData governance rules, country by country

Israel

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked today.

The answer

Yes, with paperworkWork: HighEnforcement: Active

Israeli data can go abroad, but never by default. Either the destination country protects data as well as Israel does, or you fit one of eight listed exceptions — usually a contract in which the receiver promises to follow Israeli rules. A big reform started on 14 August 2025 and the regulator now issues real fines. No industry bans exports outright, but several add heavy conditions.

Eight questions about Israel

The questions a team asks when they are deciding where to store their users' data. Every country on this site answers the same eight, in the same order.

Do Israel's rules apply to my company?

Yes, it can reach a foreign company with no office in Israel — but the law never says so in words. Israeli privacy law simply applies to anyone who collects, uses or processes personal data, with no size or revenue threshold to fall under. There is no general requirement to appoint a local representative. Some organisations must appoint a privacy officer, and that person is allowed to be an outside contractor rather than a staff member.

Medium confidenceNational rulesAppoint a data protection officerController

Can I store my users' data outside Israel?

Yes, with paperwork — and you must be able to name the route you are using. The default rule is that data may only go to a country whose law protects it at least as well as Israeli law does. If the destination fails that test, you have to fit one of eight listed exceptions, and whichever route you take you also need a written promise from the receiver. No Israeli industry has a flat 'the data stays here' rule, but four sectors bolt extra conditions on top.

High confidenceYes, with paperworkAllowlistBankingInsuranceHealth and social careGovernment

What do I need in place before data leaves Israel?

The model is closest to an allowlist: you may not send data out unless the destination qualifies, and the qualifying list is already populated. It counts if the country signed the Council of Europe data protection convention, or if it receives data from European Union countries on the same terms — so Europe's approved-country list does much of the work. If your destination does not qualify, the usual fallback is a contract in which the receiver promises to meet Israeli standards. Either way you also need a separate written promise from the receiver that it will protect the data and pass it to nobody else.

High confidenceAllowlistOfficial 'this country is safe' decisionStandard contract clausesApproved group rulesExplicit consentSomeone's life is at riskImportant public interestPut a transfer safeguard in place

Who enforces the rules in Israel, and what can they do?

The Privacy Protection Authority, part of the Ministry of Justice, and it is fully operational. It has a serving commissioner, an administrative enforcement department, and it publishes its decisions with names and amounts. In 2026 it fined a national health fund about 256,000 shekels (roughly $72,000) for taking two months to report a security incident, and a small leisure company about 12,000 shekels (roughly $3,400) for a defective privacy notice. Industry regulators — the Bank of Israel, the insurance regulator and the Ministry of Health — enforce their own rules separately.

High confidenceActiveFixed maximum fineOrder to stopCriminal liability

How long do I have to keep the data?

There is a clear floor and a clear ceiling, and they sit close together. The floor: security and access-monitoring records must be kept for at least 24 months, and organisations with medium or high security databases must keep a restorable backup of them. The ceiling: if a database contains anything that came from Europe, you must run a mechanism that finds data you no longer need and delete it, and you must delete data on request. Where another law says you must keep something, that wins over the duty to delete.

High confidenceKeep logsKeep data for a minimum periodDelete data after a periodLet people delete their data

What happens if there is a breach?

There is one main clock and it has no hours attached to it: a severe security incident must be reported to the Privacy Protection Authority immediately, along with what you did about it. 'Immediately' is taken literally — a health fund was fined for a two-month delay. Telling the affected people is not automatic; the Authority decides, after consulting the national cyber agency, and can order you to notify them. Israel has no general law forcing every company to report cyber incidents to the state, so your second clock, if you have one, comes from your industry regulator.

High confidenceReport breaches to the regulatorTell affected peopleReport cyber incidents

What trips people up in Israel?

Five things that are not in the summary. One: a single record that arrived from Europe drags the whole database into the stricter European rules — since 1 January 2025 those rules apply to any other data sitting in the same database. Two: 'immediately' really means immediately, and there is no safe 72-hour habit to fall back on. Three: fines are calculated per person, not as a flat cap, so a large database turns a small breach into a very large bill. Four: privacy breaches are criminal offences, not just regulatory ones, with prison terms attached. Five: 'data security officer' and 'data protection officer' are two different Israeli roles with different triggers, and having one does not satisfy the other.

High confidenceCriminal liabilityFixed maximum fineClaims by individualsAppoint a data protection officerReport breaches to the regulator

What is changing soon in Israel?

The big change already happened on 14 August 2025. What is landing now is the detail underneath it. In April 2026 the regulator finalised its binding rules on the contract you must sign before sending data abroad, and separate regulations came into force giving a short grace period — a warning instead of a fine — for brand-new obligations. A guideline applying privacy law to artificial intelligence, including a requirement of consent before scraping the web to train models, is also in play. Watch three switches the government can flip without warning.

Medium confidenceIn forceArtificial intelligenceRegulator guideline

The rules, layer by layer

Rules stack in layers. Knowing which layer a rule sits in tells you whether your industry, your state, or a contract can override it.

  1. Layer 1

    National rules

    Added by this country on top of any bloc rules.

    6 rules here

  2. Layer 2

    Industry rules

    Made by an industry regulator. These usually beat the general position.

    5 rules here

  3. Layer 3

    Contract-imposed rule

    Binds you because you signed something, typically a government contract.

    1 rule here

Read the stack from the top down. Anything lower normally wins: an industry rule beats the national position, and the national position sits on top of the bloc rules.

National rules6 rules

חוק הגנת הפרטיות, התשמ"א-1981 (כנוסחו לאחר תיקון מס' 13)

Act of parliament · Privacy Protection Law 5741-1981, as amended by Amendment No. 13, 5784-2024; Sefer HaChukim 3287, p. 1430

In forceYes, with paperwork

Israel's general privacy law, rewritten by Amendment 13 which started on 14 August 2025. It cut private-sector database registration almost to nothing, added a data protection officer duty, created new criminal offences, and gave the regulator inspectors and per-person monetary sanctions.

In force since 14 August 2025

Enforced by Privacy Protection Authority

Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses

High confidence

תקנות הגנת הפרטיות (העברת מידע אל מאגרי מידע שמחוץ לגבולות המדינה), התשס"א-2001

Directly binding regulation · Privacy Protection (Transfer of Data to Databases Abroad) Regulations, 5761-2001

In forceYes, with paperwork

Data may only leave Israel if the destination country's law protects it at least as well as Israeli law, or one of eight listed exceptions applies. Whichever route you use, the receiver must also sign a written promise to protect the data and not pass it on.

In force since 17 December 2001

Enforced by Privacy Protection Authority

Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Explicit consent, Someone's life is at risk, Important public interest

High confidence

גילוי דעת בנושא העברת מידע אישי מחוץ לישראל - פרשנות תקנה 2(4)

Regulator guideline · Privacy Protection Authority binding opinion on Regulation 2(4) of the Transfer of Data Abroad Regulations

In forceYes, with paperwork

The regulator's final and binding reading of the contract route out of Israel, published in April 2026. Without these specific undertakings in the contract, you cannot rely on that route at all.

In force since 9 April 2026But only enforceable from 30 April 2026

Enforced by Privacy Protection Authority

Transfer model: Allowlist · Accepted routes: Standard contract clauses, Certification scheme

High confidence

Industry rules5 rules

הוראות ניהול בנקאי תקין 362 - מחשוב ענן

Regulator directive · Proper Conduct of Banking Business Directive 362 — Cloud Computing; current version issued by Circular 2849 · Banking

In forceYes, with paperwork

Israeli banks may use cloud outside Israel, including for material services, but only after verifying that the provider protects sensitive customer data to European standards. The directive also forces the bank to plan for a foreign region going dark for geopolitical reasons.

In force since 13 June 2022But only enforceable from 17 June 2026

Enforced by Bank of Israel — Banking Supervision Department

Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses

High confidence

חוזר גופים מוסדיים 2018-9-35 - מיקור חוץ בגופים מוסדיים

Regulator directive · Institutional Bodies Circular 2018-9-35 — Outsourcing in institutional bodies · Insurance

In forceYes, with paperwork

Insurers and pension providers may outsource abroad, but the regulator sees every arrangement. There is a board-level policy duty, a specific requirement to assess what it means to run the activity outside Israel, and an annual list to the Commissioner flagging each offshore arrangement.

In force since 31 December 2018

Enforced by Capital Market, Insurance and Savings Authority

High confidence

חוזר מנכ"ל משרד הבריאות 2/2021 - שימוש במחשוב ענן במערכת הבריאות

Regulator directive · Ministry of Health Director-General Circular 2/2021 — Use of cloud computing in the health system · Health and social care

In forceYes, with paperwork

Israeli hospitals and health funds may use cloud abroad, but only in a country that satisfies the national transfer regulations, and only after assessing what foreign law would do to the data. The circular is permissive on geography and demanding on governance.

In force since 21 February 2021

Enforced by Ministry of Health

Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses

High confidence

Contract-imposed rule1 rule

פרויקט נימבוס - מדיניות הענן הממשלתית

Government policy document · Project Nimbus; Government Resolutions 852 (2021), 231 (2021), 1700 (2024), 2273 (2024) and 3574 of 4 December 2025; Accountant General instruction 16.12.1 · Government

In forceNo — it stays put

Central government buys cloud only through the Nimbus framework, and its shared platform sits in Israeli cloud regions on purpose. This is a procurement wall rather than a law, but in practice selling cloud to the Israeli state requires an in-country region.

In force since 24 May 2021But only enforceable from 4 December 2025

Transfer model: Approval each time · Accepted routes: Government sign-off needed

Medium confidence

Who you would hear from

  • הרשות להגנת הפרטיות

    All personal data held in digital databases, private and public; administrative and criminal enforcement

    Fully operational. Headed by Commissioner Gilad Semama. Has an administrative enforcement department, published two named monetary sanctions in 2026 (Meuhedet Health Fund, 256,000 shekels after reduction; A.D. Karting Hutzot, 12,000 shekels after reduction), issued a final binding opinion on transfers abroad in April 2026, and published a guideline on artificial intelligence.

  • בנק ישראל - הפיקוח על הבנקים

    Banks and credit card companies; cloud computing, information technology and cyber directives

    Active. Reissued the cloud computing directive on 17 June 2026 via Circular 2849, restructuring it around the new Directive 364 and cancelling Directives 361 and 363.

  • רשות שוק ההון, ביטוח וחיסכון

    Insurers, pension and provident funds; outsourcing, cyber risk and information technology circulars

    Active. Receives annual outsourcing returns and immediate reports of exceptional events from every institutional body.

  • משרד הבריאות

    Hospitals, health funds and other health organisations; cloud use, secondary use of health data, medical confidentiality

    Active through Director-General circulars. Its sanction is administrative rather than financial: it can suspend a health organisation's ethics committee authority to approve secondary uses of data.

  • מערך הסייבר הלאומי

    National cyber defence; professional guidance to sector regulators; consulted before individuals are ordered to be notified of a data breach

    Operational but deliberately not a cross-economy regulator. Government Resolution 2443 of 15 February 2015 chose to empower existing sector regulators instead, so there is no general duty to report cyber incidents to it.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.

  • Whether any country has actually been named in the official gazette under Regulation 2(8)(3) as having a privacy authority with a cooperation arrangement with Israel.

    The regulation creates the power, and the Authority has signed cooperation statements with the Dubai International Financial Centre and Abu Dhabi Global Market, but we could not find a published gazette announcement confirming any country has been designated. Treat this route as unavailable until you see the announcement.

  • That Israeli tax and company law require books and records to be kept for seven years.

    This is the widely reported floor under the Income Tax (Bookkeeping) Instructions 1973, but we could not reach an Israel Tax Authority page stating it on this run, so we have not asserted a number in the record.

  • That there is no data-residency rule for securities firms, telecoms operators, education, online gaming, mapping or defence.

    No such rule was found on an Israeli government source, checked 18 August 2026. This is an absence of evidence, not evidence of absence. The National Cyber Directorate's own map records that the Ministry of Communications has not published cyber rules for telecoms at all, and that a public consultation on adding cyber conditions to telecoms licences was opened in August 2021 and has not visibly concluded. Israel Securities Authority cloud or outsourcing guidance could not be retrieved.

  • The exact date on which the artificial intelligence guideline moved from draft to final.

    The Privacy Protection Authority page is titled as a guideline and states it was published 'in a first stage' as a draft with comments due by 31 July 2025, but the rendered page did not expose a publication or update date. We have dated it to the consultation period and set confidence to medium.

  • That the Privacy Protection Law reaches foreign companies with no Israeli presence.

    The statute contains no territorial-scope article. Our conclusion rests on the Authority's own guide, a footnote in its April 2026 opinion acknowledging that databases abroad can be subject to Israeli law, and its past investigation of a foreign platform — not on express legislative words. A foreign company with no Israeli establishment has a real argument here, which is why confidence on Q1 is medium.

  • That the Project Nimbus localisation requirement is legally binding rather than contractual.

    We verified that the government's shared cloud platform was moved into the Israeli region and that ministries must buy through the central tenders, but we did not obtain the tender conditions themselves. The rule is recorded as a procurement layer, not a statute.

  • The precise commencement date of the Data Security Regulations 5777-2017.

    Regulation 22 says only that they take effect one year after publication. We have used 8 May 2018, the date generally cited, but did not verify the gazette publication date directly.

Freshness and refresh

Freshness

Checked today — on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

Compare with

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.