HomeNewsIsrael's First Administrative Fines under Amendment 13: A New Enforcement Era for Privacy Compliance
8 October 2026Dr. Tobias Höllwarth

Israel's First Administrative Fines under Amendment 13: A New Enforcement Era for Privacy Compliance

Amendment 13 to Israel's Protection of Privacy Law, 1981 (the "PPL") entered into force on 14 August 2025, giving the Israeli Privacy Protection Authority (the "PPA") — for the first time — the ability to impose meaningful financial sanctions directly on organisations that breach Israeli data protection rules. A little over a year later, the first sanctions have arrived. Between July and September 2026 the PPA published three decisions imposing fines on a health fund, a small leisure business and a municipality. Modest in amount, they are significant in signal: Israeli privacy obligations that were long treated as formalities now carry a direct price tag.

Israel's First Administrative Fines under Amendment 13: A New Enforcement Era for Privacy Compliance

Why Amendment 13 Matters
Amendment 13 is the most substantial overhaul of Israeli privacy law since the PPL was enacted in 1981. It modernises core definitions, narrows the much-criticised database registration regime, introduces mandatory privacy protection officers for specified organisations, creates new criminal offences, expands statutory damages awarded without proof of damage, and abolishes the shortened limitation period for civil privacy claims. It also anchors the independent status of the PPA within the Ministry of Justice.
For practitioners familiar with the GDPR, the definitional changes will feel recognisable. "Personal information" now covers any data relating to an identified or reasonably identifiable individual, directly or indirectly, including identifiers such as name, ID number, biometric identifiers, location data and online identifiers. A new category of "information of special sensitivity" replaces the former notion of sensitive information and covers, among other things, health and genetic data, biometric identifiers, criminal records, political and religious views, salary and financial activity data, certain location and traffic data, and information subject to legal confidentiality. The former "database owner" has become the "database controller" — the party that alone or jointly determines the purposes of processing — while a "holder" is an external party processing information on the controller's behalf, broadly comparable to a processor.
Amendment 13 also added substantive prohibitions that sit at the heart of the new enforcement regime: processing personal information for purposes contrary to the lawfully defined purposes of the database, processing without the controller's authorisation, and processing information that was collected unlawfully.
The Administrative Fines Mechanism
The previous, largely symbolic administrative fine mechanism under the PPL was abolished and replaced with a financial sanctions regime with real teeth. The PPA may now impose sanctions for breaches of the PPL itself, of the Privacy Protection Regulations (Information Security), 2017, and of the Privacy Protection Regulations (Instructions for Data Transferred to Israel from the European Economic Area), 2023.
The Amendment distinguishes between two supervisory tracks. Supervision may be exercised without any suspicion of a breach, as a routine regulatory activity. An administrative inquiry, by contrast, may be opened where there is a reasonable basis to believe that a violation has occurred and that it may attract a financial sanction or a cessation order. Most of the published decisions to date have followed the inquiry route, triggered either by a breach notification or by an individual complaint.
Sanction amounts are set by statutory formulas rather than by open-ended regulatory discretion. Registration and notification breaches attract NIS 150,000, doubled for databases concerning more than one million data subjects. Breaches of the notice duty owed to individuals at the point of collection are calculated per person — NIS 50, or NIS 100 where information of special sensitivity is involved — with the statute itself illustrating a NIS 500,000 sanction in appropriate circumstances. Unlawful processing is priced at NIS 4 per data subject in the database, subject to a NIS 200,000 floor. Breaches of access, correction and deletion rights attract NIS 15,000. Other database-size-based breaches run at NIS 2 per data subject, or NIS 4 where the database contains especially sensitive information, with minimums of NIS 20,000 and NIS 40,000 respectively.
Information security breaches are tiered according to the security level applicable to the database. For databases at the medium security level, illustrative tiers are NIS 20,000, NIS 40,000 and NIS 80,000; for high security level databases, the corresponding tiers are NIS 80,000, NIS 160,000 and NIS 320,000. These amounts, too, double where the database concerns more than one million data subjects. Databases at the basic level and those managed by individuals attract materially lower amounts, generally NIS 1,000 to NIS 2,000, rising to NIS 4,000 for certain outsourcing-control failures. Breaches of the EEA data transfer regulations are calculated at NIS 2 or NIS 4 per data subject depending on the data type and the obligation breached.
Several moderating features apply. Reductions may be granted on request, but cannot exceed 70% of the sanction in aggregate. Caps apply where multiple violations are addressed in a single enforcement proceeding, and in all cases the total sanction may not exceed 5% of the violator's annual turnover, with lower caps for small and very small businesses. Importantly, where a sanction is imposed on a holder, the controller must also be notified and ordered to act to stop the holder's violation; if the controller fails to do so, the same sanction may be imposed on the controller as if it were itself the violator.
Procedurally, the PPA issues a notice of intent, the alleged violator may submit written arguments, and the Head of the PPA then decides whether to impose a sanction and whether statutory reduction grounds apply. If a sanction is imposed, a written payment demand follows. Regulations issued in April 2026 also allow the PPA to issue an administrative warning instead of a sanction in defined circumstances — although, as the decisions below show, the PPA is willing to refuse a warning where the statutory conditions are not met.
The First Published Sanctions
The three decisions published by the PPA between July and September 2026 — the first financial sanctions published since Amendment 13 entered into force — are instructive precisely because they target different obligations and very different organisations.
Meuhedet Health Fund (July 2026). In the first published sanction under the new regime, the PPA fined Meuhedet Health Fund NIS 256,000 for failing to report a serious security incident immediately. A technological fault in a digital system allowed insured persons, in certain combinations of circumstances, to view the medical files of relatives; the database concerned contained especially sensitive health information about a very large number of data subjects. The fault surfaced when an insured person reported that he could see his stepsister's medical file. Meuhedet became aware of the incident in November 2025, established some six weeks later that the fault was systemic, fixed it at the end of January 2026 and reported it to the PPA on 27 January 2026 — roughly two months after the initial approach. The PPA held that this breached the immediate reporting duty under Regulation 11(d) of the Information Security Regulations, emphasising that the duty crystallises upon becoming aware of a serious incident and must be discharged close to discovery and without delay. It expressly rejected the argument that an organisation may wait until its internal checks are complete: an initial report based on what is known at the time is required, and may be supplemented later.
A.D Karting Hutzot (2014) Ltd. (August 2026). Following a complaint filed in December 2025, the PPA fined a karting business NIS 12,000 for breaching the notice duty under Section 11 of the PPL. A customer registering for an activity was required to submit, through an online form, her ID number, full name, date of birth, telephone number, city of residence and details of her minor child, without being presented with a notice containing all of the legally required elements. The company's terms of use and privacy policy omitted the identity and contact details of the controller, the purposes of use, the recipients or categories of recipients, and the individual's access and rectification rights; a full privacy policy was not even available on the website when the complaint was filed and was uploaded only after the inquiry had begun. The PPA set the sanction at NIS 20,000 and reduced it to NIS 12,000 in light of the absence of prior violations and the steps taken to prevent recurrence, while rejecting arguments of de minimis and good faith and declining to issue an administrative warning.
Beit Shemesh Municipality (September 2026). The PPA imposed a NIS 64,000 sanction on Beit Shemesh Municipality following a serious security incident, reported on 20 August 2025, in which a fault in the municipal GIS system exposed personal and medical information concerning approximately 4,600 residents. Welfare information intended for internal use only — including data classified as information of special sensitivity — was accessible through the municipality's public website; the system was disabled and access blocked upon discovery. The inquiry identified two breaches of the Information Security Regulations. First, a supplier that had provided support and information-processing services with continuous access to the welfare database systems for nearly two years qualified as a holder, yet was not identified as such in the database definitions document, contrary to Regulation 2(a)(7). The PPA rejected the municipality's plea that this was a good-faith administrative gap arising because Amendment 13 had entered into force only a week before the incident, noting that organisations had a full year to prepare. Second, the municipality's information security procedure failed to regulate the obligations required for engagements with external parties granted access to the database — permitted purposes, categories of information, access arrangements and engagement duration — and did not cross-refer to supplier agreements and security procedures, contrary to Regulation 15(a)(3). The sanction was set at NIS 40,000 per breach and reduced by 20% because no sanction or administrative enforcement measure had been imposed on the municipality in respect of the same obligations in the preceding five years.

Recommendation

Practical Takeaways
First, "immediate" means immediate. The Meuhedet decision is the clearest statement yet that the reporting clock starts on awareness of a serious incident, not on completion of the forensic investigation. Organisations operating in Israel should build an initial-notification template and a clear internal escalation trigger, and should treat supplementation as the normal course rather than an admission of incompleteness.
Second, transparency notices are substantive obligations, not boilerplate. The karting decision shows that the PPA will pursue a small business over an incomplete online privacy notice, and that the per-person calculation basis makes consumer-facing collection forms a genuine exposure. Every collection point should be mapped against the full list of Section 11 elements.
Third, vendor and holder documentation is an enforcement target in its own right. Beit Shemesh was not sanctioned for the exposure as such but for failing to identify its supplier as a holder and for an outsourcing procedure that did not regulate the required terms. Database definitions documents, supplier registers and information security procedures should be reviewed and reconciled.
Fourth, reduction factors matter — but remediation after the fact does not avoid liability. In both the karting and Beit Shemesh cases, corrective steps and a clean enforcement history produced meaningful reductions, yet in neither case did they prevent a sanction. Conversely, the PPA has shown that it will decline requests for an administrative warning where the statutory conditions are not satisfied.
Finally, and most broadly, Amendment 13 converts formal PPL obligations into quantifiable financial risk. The amounts imposed so far are not headline-grabbing by European standards, but the statutory formulas scale sharply with database size and data sensitivity, and the 5% turnover cap leaves considerable headroom. International groups with Israeli operations, and non-Israeli controllers receiving data from Israel, should revisit their Israeli compliance posture on the assumption that the PPA now intends to enforce it.

Article provided by INPLP member: Eyal Roy Sage (AYR Lawyers, Israel)

By Dr. Tobias Höllwarth← All news