Privacy Protection (Transfer of Data to Databases Abroad) Regulations, cross-border transfer
Privacy Protection (Transfer of Data to Databases Abroad) Regulations, 5761-2001
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
Commencement not set.
A cross border transfer rule binding public and private bodies.
As of 29 August 2026.
What it requires
- An app transferring the personal data of a person in Israel to a recipient outside Israel must rely on the destination providing protection no less than Israeli law's, or on one of the regulation's eight alternative grounds, most commonly consent, a common-control guarantee, an inter-party agreement, or an authority-gazetted adequate jurisdiction, and must obtain a written guarantee from the recipient in every case.
Who checks it
Audit expectation
none
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Under PPL Art. 36(2), these regulations bar transfer of personal data outside Israel unless the destination country's law ensures protection no less than Israeli law provides, subject to five baseline principles: fair collection, purpose limitation, accuracy, an inspection right, and security.
Regulation 2 lists eight independent grounds permitting transfer regardless of that default rule: consent; vital-interest necessity where consent cannot be obtained; transfer to a corporation under common control with a privacy guarantee; transfer to a party bound by agreement to the same conditions; data already made public or open for inspection; public safety or security necessity; a legally mandated transfer; or transfer to a Convention 108 party, a state receiving data from EU member states on equivalent terms, or a state the Registrar of Databases has gazetted as having an adequate privacy authority.
Regulation 3 requires a written guarantee from the recipient in every case. No data localization is compelled.
Regulation 5 (the regulations' own commencement clause) provides that the regulations enter into force six months after the date of their publication; the regulations were signed 17 June 2001 (26 Sivan 5761), but their Reshumot publication date, which Regulation 5's six-month clock actually runs from, was not established at primary source, so no effective date is recorded, rather than one computed from the signature date. Whether Amendment 13 touched this 2001 regulation was not confirmed against the Reshumot.
When LexLint raises it
crawls_webtrains_modelsprocesses_biometricsprocesses_voice
Read the law
official government publication, Privacy Protection Authority unofficial English translation
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.