Protection of Privacy Law, enforcement, DPO duty and private rights of action
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 14 August 2025.
An enforcement supervision rule binding public and private bodies.
As of 2 September 2026.
What it requires
- An app processing the personal data of a person in Israel must be prepared to answer to the Privacy Protection Authority's monetary sanctions, and an individual harmed by a privacy infringement may bring a civil claim for statutory or exemplary damages without needing to prove actual damage.
If you get it wrong
Criminal exposureYes
Private right of actionYes
Criminal exposure note
A person who willfully infringes another's privacy in any of the ways listed in Art. 2(1), (3) to (7), and (9) to (11) is liable to imprisonment for up to five years under Art. 5, the same maximum that applies to breaching the Act's confidentiality duty under Art. 16. Separate administrative-enforcement offenses in Chapter D4 carry shorter terms: up to six months for obstructing the Head of the Authority, an investigator, or an inspector; up to two years for misleading them; and up to three years each for processing personal data from a database without authorization, providing incorrect information when requesting data, or an unlawful data transfer from a public body.
Penalty structure
Art. 23KF sets several distinct tiers rather than one ceiling. Registration and notification violations carry a base 150,000 NIS sanction, doubled to 300,000 NIS where the database holds 1,000,000 or more individuals' data. Obstructing an inspector's document request carries a flat 300,000 NIS sanction. Violations of the Data Security Regulations are sanctioned per the Third Schedule's table, which varies by the database's security tier (individual-managed, basic, medium, or high) and reaches 320,000 NIS at the high tier, doubled to 640,000 NIS where that high-security database also holds 1,000,000 or more individuals. The most severe general violations under Art. 23KF(e), including unauthorized processing, processing for an unlawful purpose, and failing to comply with a cessation order, are sanctioned per affected individual at 4 NIS, or 8 NIS where the data is of special sensitivity, with a 200,000 NIS floor and no stated ceiling, so exposure for these violations scales with the size of the affected population rather than stopping at a fixed sum. A continuing violation adds 1 percent of the sanction per day it continues, and a repeated violation within 2 years adds a further full sanction amount, under Art. 23L.
- Rule
- Per violation only
- As of
- 2 September 2026
- Minimum
- 200,000
- Currency
- ILS
- Per violation unit
- Person
- Per violation amount
- 8
Statutory damages
Art. 29A(b) lets a court award a civil plaintiff statutory damages up to 50,000 NIS per infringement of privacy under Art. 4, doubled to 100,000 NIS where intent to cause harm is proven, without the plaintiff proving actual damage. A person cannot recover statutory damages under Art. 29A more than once for the same infringement, and the amounts are indexed monthly to the change in Israel's consumer price index. Art. 29A(a) separately lets a court order the same 50,000 NIS civil payment following a criminal conviction under Art. 5. A narrower, independent mechanism sits at Art. 15A: exemplary damages up to 10,000 NIS for six enumerated database-controller procedural violations, mainly registration and access-related failures, where the court is directed to award them without regard to the extent of damage caused, and no more than once for the same act or omission. Whether a class action is available for either mechanism is not addressed in the Act's own text.
- As of
- 2 September 2026
- Currency
- ILS
- Per person reckless
- 100,000
- Per person negligent
- 50,000
Who enforces it
Enforcement body
Privacy Protection Authority (Head of the Authority), a unit of Israel's Ministry of Justice
What it reaches
Obligation class
Governance
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
The Privacy Protection Authority (Head of the Authority) enforces the Act, with Chapters D3-D4 monetary sanctions scaled to violation type and database security level, reaching 320,000 NIS for an individual violator in the severe-incident non-reporting tier of the schedule, with a higher corporate tier.
Two independent private-right-of-action mechanisms, both not requiring proof of damage, exist: Art. 29A lets a court award statutory damages up to 50,000 NIS per infringement, doubled to 100,000 NIS where intent to harm is proven, for any civil privacy infringement under the Chapter A general tort, expressly not dependent on damage; Art. 15A separately lets a court award exemplary damages up to 10,000 NIS, narrower in scope (six specific database-controller procedural violations), where the court is directed not to consider the extent of damage caused.
Art. 31B extends ordinary civil-wrong liability under the Torts Ordinance to a violation of Chapters B or D or regulations made under the Act, beyond the Chapter A tort alone. Amendment No. 13 added the Data Protection Officer duty at Arts. 17B1-17B3.
When LexLint raises it
crawls_webtrains_modelsgenerates_contentdeploys_chatbotautomated_outreachhigh_risk_decisionsprocesses_voiceprocesses_biometrics
Read the law
official government publication, Privacy Protection Authority unofficial English translation
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.