Law / Israel

Protection of Privacy Law, biometric identifier definition and security-level tiering

Protection of Privacy Law 5741-1981, as amended by Amendment No. 13, Art. 3 (biometric identifier and data of special sensitivity definitions), security-level provisions

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 14 August 2025.

A biometric privacy rule binding public and private bodies.

As of 29 August 2026.

What it requires

  • An app that captures or stores a facial image, voiceprint, or other biometric identifier of a person in Israel, including one derived from a photo, video, or audio recording, must treat it as data of special sensitivity and apply Israel's tiered security-level obligations, which scale up automatically at 100,000 or more biometric identifiers held.

What it reaches

Excludes recording-derived identifiersNo

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Art. 3 defines data of special sensitivity to include, among eight-plus enumerated categories, a biometric identifier used or intended to be used to identify a person or verify his identity in a digital manner, itself defined as a biometric data item used to identify a person or verify that person's identity, or a biometric measure from which the said data item can be derived, where biometric means a unique human, physiological, or behavioral characteristic that can be measured through digital measurement.

The derivation clause affirmatively brings in an identifier derived from a recording; a facial image is confirmed within scope by a separate security-level provision that gives a biometric identifier limited to a facial image a lighter basic-security-level treatment only when confined to internal employee or supplier management, a security-tier carve-out, not a substantive consent exemption.

Chapter D3/D4 imposes tiered security-level obligations keyed partly to biometric-identifier volume, automatically classifying a database of 100,000 or more biometric identifiers as high security level. No voice-specific provision or dedicated biometric retention or destruction duty was found; Art. 2(6) separately prohibits commercial use of a person's name, image, or voice without consent as a distinct tort, outside the database regime.

When LexLint raises it

  • processes_biometrics
  • processes_voice

Read the law

official government publication, Privacy Protection Authority unofficial English translation

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app