Law / Israel

Israel

10 of 12 named instruments researched to a stage, across four of the six areas of law we track: 8 in force and 2 enacted but not yet in force. As of 18 September 2026.

When they take effect8 of 10 carry a date, 2 do not. Earlier is before 2014.
Before 2014: 3 instruments (3 in force) earlier 2014: 0 instruments 2015: 0 instruments ’15 2016: 0 instruments 2017: 0 instruments 2018: 2 instruments (2 in force) 2019: 0 instruments 2020: 0 instruments ’20 2021: 0 instruments 2022: 0 instruments 2023: 0 instruments 2024: 0 instruments 2025: 3 instruments (3 in force) 2026: 0 instruments ’26 today

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

  1. AI law none researched
  2. Privacy law 6
  3. Scraping law 2
  4. Cybersecurity law 1
  5. Age gating law none researched
  6. News aggregation law 1

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Privacy law6 instruments, 4 in force, 2 enacted but not yet in force

Research summary (194 words)

Israel's Protection of Privacy Law, 5741-1981, was substantially amended by Amendment No. 13 (enacted by the Knesset 5 August 2024, in force since 14 August 2025), which rebuilt registration and notification duties, added a Data Protection Officer requirement, and introduced exemplary damages; the account here rests on the Privacy Protection Authority's own amended-text translation, not the pre-2025 posture that most secondary sources still describe.

Data of special sensitivity expressly includes a biometric identifier used to identify or verify a person's identity in a digital manner, defined broadly enough to cover a measure from which the identifier can be derived, including a facial image; no voice-specific carve-out exists.

Cross-border transfer is governed by a separate 2001 regulation requiring the destination's protection to be no less than Israeli law's, or one of eight alternative grounds including consent, corporate-control, and an authority-gazetted adequacy list, a real and conditioned regime.

Two independent no-proof-of-damage statutory-damages mechanisms, Art. 29A (general, up to 50,000 NIS, doubled for proven intent to harm) and Art. 15A (narrower, up to 10,000 NIS for enumerated procedural violations), arm a private plaintiff without requiring proof of actual damage, the standout enforcement feature among this batch's jurisdictions.

Biometric privacy

Protection of Privacy Law, biometric identifier definition and security-level tiering

Protection of Privacy Law 5741-1981, as amended by Amendment No. 13, Art. 3 (biometric identifier and data of special sensitivity definitions), security-level provisionsofficial government publication, Privacy Protection Authority unofficial English translation

In force since 14 August 2025. Binds public and private bodies.

What this law does

Art. 3 defines data of special sensitivity to include, among eight-plus enumerated categories, a biometric identifier used or intended to be used to identify a person or verify his identity in a digital manner, itself defined as a biometric data item used to identify a person or verify that person's identity, or a biometric measure from which the said data item can be derived, where biometric means a unique human, physiological, or behavioral characteristic that can be measured through digital measurement.

The derivation clause affirmatively brings in an identifier derived from a recording; a facial image is confirmed within scope by a separate security-level provision that gives a biometric identifier limited to a facial image a lighter basic-security-level treatment only when confined to internal employee or supplier management, a security-tier carve-out, not a substantive consent exemption.

Chapter D3/D4 imposes tiered security-level obligations keyed partly to biometric-identifier volume, automatically classifying a database of 100,000 or more biometric identifiers as high security level. No voice-specific provision or dedicated biometric retention or destruction duty was found; Art. 2(6) separately prohibits commercial use of a person's name, image, or voice without consent as a distinct tort, outside the database regime.

What it requires

Breach notification

Protection of Privacy Law, breach notification duty

Privacy Protection Regulations (Data Security) 5777-2017, Art. 11(d)(1); Protection of Privacy Law, 5741-1981, monetary sanctions schedule item (21)official government publication, Privacy Protection Authority unofficial English translation of the Data Security Regulations' own text

In force since 8 May 2018. Binds public and private bodies.

What this law does

The Privacy Protection Regulations (Data Security), 5777-2017 are confirmed at primary source.

Regulation 11(d)(1) requires a database controller to immediately notify the Registrar (Head of the Privacy Protection Authority) of a severe security incident and report on the measures taken in response; this confirms and replaces the main Act's cross-referenced monetary-sanctions-schedule item (21), which separately fines a controller or processor who fails that duty at up to 80,000 or 320,000 NIS for an individual or corporate violator.

A severe security incident is defined by Regulation 1 by reference to the database's security-level tier (unauthorized use or integrity damage affecting a high-security database, or a substantial part of a medium-security one).

Regulation 22 (the regulations' own commencement clause) provides that the regulations take effect one year after their publication; the regulations' own text carries a footnote citing publication as Reshumot Regulations File 5777 no. 7809 dated 8 May 2017, so the one-year clock runs from that date to 8 May 2018. The Minister of Justice signed the regulations 5 April 2017.

Any data-subject notification duty distinct from the Registrar-notification duty was not independently confirmed and is not recorded here.

What it requires

Comprehensive regime

Protection of Privacy Law, comprehensive regime and database registration

Protection of Privacy Law, 5741-1981, as amended by Amendment No. 13, 5784-2024, Arts. 1-2, 4, 7-8Aofficial government publication, Privacy Protection Authority unofficial English translation

In force since 14 August 2025. Binds public and private bodies.

What this law does

Israel's Protection of Privacy Law, 5741-1981, creates a general tort of privacy infringement in Chapter A (Arts. 1-2, 4) and regulates 'databases' specifically from Art. 7 onward in Chapter B. A database excludes purely personal-use collections and small (100,000-or-fewer-person) name, address, or contact-only collections.

Amendment No. 13 rebuilt registration and notification duty at Art. 8A: mandatory registration is now limited to databases whose main purpose is commercial data provision with more than 10,000 individuals, or public-body databases, plus a separate notification duty, short of full registration, for any database holding special-sensitivity data on more than 100,000 individuals, including naming a Data Protection Officer where one is required.

What it requires

Cross border transfer

Privacy Protection (Transfer of Data to Databases Abroad) Regulations, cross-border transfer

Privacy Protection (Transfer of Data to Databases Abroad) Regulations, 5761-2001official government publication, Privacy Protection Authority unofficial English translation

Commencement not set. Binds public and private bodies.

What this law does

Under PPL Art. 36(2), these regulations bar transfer of personal data outside Israel unless the destination country's law ensures protection no less than Israeli law provides, subject to five baseline principles: fair collection, purpose limitation, accuracy, an inspection right, and security.

Regulation 2 lists eight independent grounds permitting transfer regardless of that default rule: consent; vital-interest necessity where consent cannot be obtained; transfer to a corporation under common control with a privacy guarantee; transfer to a party bound by agreement to the same conditions; data already made public or open for inspection; public safety or security necessity; a legally mandated transfer; or transfer to a Convention 108 party, a state receiving data from EU member states on equivalent terms, or a state the Registrar of Databases has gazetted as having an adequate privacy authority.

Regulation 3 requires a written guarantee from the recipient in every case. No data localization is compelled.

Regulation 5 (the regulations' own commencement clause) provides that the regulations enter into force six months after the date of their publication; the regulations were signed 17 June 2001 (26 Sivan 5761), but their Reshumot publication date, which Regulation 5's six-month clock actually runs from, was not established at primary source, so no effective date is recorded, rather than one computed from the signature date. Whether Amendment 13 touched this 2001 regulation was not confirmed against the Reshumot.

What it requires

Data subject rights

Protection of Privacy Law, data subject rights

Protection of Privacy Law, 5741-1981, Arts. 13, 13A, 14official government publication, Privacy Protection Authority unofficial English translation

Commencement not set. Binds public and private bodies.

What this law does

Arts. 13 and 13A give a data subject the right to access their own data held by a database, and Art. 14 gives a right to demand rectification or deletion, with follow-through notice to prior recipients of the corrected or deleted data; Art. 16 imposes a confidentiality duty on anyone with database access. A separate compensation right exists through the enforcement provisions rather than as a standalone rights article.

No General Data Protection Regulation (GDPR) Art. 22-style right to object to a fully automated decision is identified, and none is asserted either way.

Arts. 13 and 14 are original 1981 enactment provisions, sitting in Chapter B, whose own Art. 37 commencement clause provides that Chapter B comes into force six months from the date of publication of this Law rather than on Knesset passage; the original Hebrew enactment (from the Knesset's own legislative archive) confirms this wording and confirms Art. 13A is not present in that 1981 text, so it was inserted by a later amendment.

Neither the original Law's Reshumot publication date nor Art. 13A's own insertion date was established at primary source, so no effective date is recorded, and the status is enacted rather than an inferred in-force date.

What it requires

Enforcement supervision

Protection of Privacy Law, enforcement, DPO duty and private rights of action

Protection of Privacy Law, 5741-1981, as amended by Amendment No. 13, Arts. 15A, 17B1-17B3, 29A, 31B, Chapters D3-D4official government publication, Privacy Protection Authority unofficial English translation

In force since 14 August 2025. Binds public and private bodies.

What this law does

The Privacy Protection Authority (Head of the Authority) enforces the Act, with Chapters D3-D4 monetary sanctions scaled to violation type and database security level, reaching 320,000 NIS for an individual violator in the severe-incident non-reporting tier of the schedule, with a higher corporate tier.

Two independent private-right-of-action mechanisms, both not requiring proof of damage, exist: Art. 29A lets a court award statutory damages up to 50,000 NIS per infringement, doubled to 100,000 NIS where intent to harm is proven, for any civil privacy infringement under the Chapter A general tort, expressly not dependent on damage; Art. 15A separately lets a court award exemplary damages up to 10,000 NIS, narrower in scope (six specific database-controller procedural violations), where the court is directed not to consider the extent of damage caused.

Art. 31B extends ordinary civil-wrong liability under the Torts Ordinance to a violation of Chapters B or D or regulations made under the Act, beyond the Chapter A tort alone. Amendment No. 13 added the Data Protection Officer duty at Arts. 17B1-17B3.

What it requires

Scraping law2 instruments, 2 in force

Research summary (257 words)

Israel has no scraping-specific statute, so general law governs each dimension separately. The Computers Law, 5755-1995 criminalizes unlawful penetration of computer material in section 4 without expressly requiring that a security measure be defeated, so whether reading a public, unauthenticated web page falls inside or outside the offence has not been confirmed by a reported decision.

No Israeli case addressing the enforceability of a browsewrap or clickwrap terms-of-service against a scraper was located.

The Copyright Act, 5768-2007 permits fair use for purposes including research and quotation under section 19, and a non-binding December 2022 Ministry of Justice opinion concluded that training a machine-learning model on copyrighted text is generally permitted under the fair use, incidental use, and transient use exceptions, but Israel has not enacted a text-and-data-mining-specific opt-out mechanism and no statute assigns legal weight to a robots.txt directive.

Israel confers no sui generis database right; a compilation, including a database, is protected only through the originality of its selection and arrangement under section 4(b) of the Copyright Act.

The Protection of Privacy Law, 5741-1981 applies to personal data without a general carve-out for publicly accessible information, so scraping personal data from a public Israeli website remains subject to that law's registration, notification, and security duties, already documented in this jurisdiction's privacy-topic record; the Privacy Protection Authority's non-binding draft guidance states that bulk collection of personal data by AI crawlers without notice or consent may violate the law.

No Israeli statute or reported case establishes a scraping-specific unfair-competition, misappropriation, or trespass doctrine distinct from ordinary tort law.

Computer misuse

Computers Law, unlawful penetration of computer material

Computers Law, 5755-1995 (as amended 2012), s. 4 (unlawful penetration of computer material), s. 5 (penetration to commit another offence)official consolidated Hebrew text of the Computers Law, reproduced by WIPO Lex from the Nevo legal database with permission

In force since 25 October 1995. Binds public and private bodies.

What this law does

Section 4 makes it an offence, punishable by three years' imprisonment, to unlawfully penetrate computer material located in a computer, defining penetration as connecting or communicating with a computer, or operating it, except a penetration that constitutes wiretapping under the Secret Monitoring Law, 5739-1979. Section 5 raises the maximum to five years' imprisonment where the section 4 act is done to commit a further offence under any other law.

Unlike a computer-misuse statute conditioned expressly on defeating a security measure, section 4's own text does not state that requirement, and no reported Israeli decision confirming or excluding a public, unauthenticated web page from the offence has been located.

What it requires

Cybersecurity law1 instrument, 1 in force

Research summary (443 words)

Israel has no enacted law setting security requirements a software product or connected device must meet before or after it reaches the market, and no general private-sector duty to report an exploited vulnerability, as such, to an authority; this is a researched absence rather than a gap in coverage.

Israel's one baseline security-programme statute is the Privacy Protection Regulations (Data Security), 5777-2017, a standalone regulation promulgated by the Minister of Justice under Article 36 of the Protection of Privacy Law, 5741-1981, rather than a bare clause of that comprehensive Act: it requires every database controller to maintain a written data security procedure, appoint a data security officer where required, run access controls, encryption, and network-security measures, conduct periodic risk assessments and penetration testing at the high security tier, audit compliance at least every 24 months, and govern an external service provider's access by written agreement, scaled across four security-level tiers (individually-managed, basic, medium, high) set by the volume and sensitivity of the data held.

Its own Regulation 11(d) duty to notify the Registrar of a severe security incident is a personal-data breach notice and is already this jurisdiction's privacy-topic row; the safeguards provisions filed here are a separate instrument.

The Computers Law, 5755-1995 (as amended 2012) was checked for any operator-facing security duty beyond its offense provisions and carries none: its Chapter B offenses (unauthorized computer penetration, disruption, false data or output, prohibited software actions) and Chapter C torts both bind the person attacking a computer system, not its operator, so it stays entirely a scraping-topic instrument.

The Israel National Cyber Directorate (INCD), by its own published description, provides incident handling services and guidance for civilian entities and critical infrastructure operators; nothing located confirms a generally binding cybersecurity regulation issued under the Israel National Cyber Directorate Law, 5778-2018, that reaches a private software or platform provider outside that advisory and coordination role.

Whether such a regulation exists is not confirmed in the primary text consulted here, and the absence rests on that one official source rather than on an exhaustive survey of Israeli cyber legislation.

Israel's financial-sector regulators, the Bank of Israel for licensed banks and the Capital Market, Insurance and Savings Authority for insurers, are understood to issue their own binding cyber-defense directives to their regulated entities; whether either does, and its exact citation, is not confirmed in the primary text consulted here.

If such a directive exists, its bound party (a banking or insurance licensee) is a role the current activity vocabulary cannot express, so it is deferred without a flagged instrument here, the same pattern this sweep has applied to DORA, NY DFS Part 500, and Connecticut's insurance cyber regulation.

Security baseline statutes

Privacy Protection Regulations (Data Security), information security programme

Privacy Protection Regulations (Data Security) 5777-2017, Regs. 1-10, 11(a)-(c), 12-20, 22; Protection of Privacy Law, 5741-1981, Art. 23KF and Third Schedule (enforcement)official government publication, Privacy Protection Authority unofficial English translation of the Data Security Regulations' own text

In force since 8 May 2018. Binds public and private bodies.

What this law does

Every database controller in Israel, private or public, must prescribe a written data security procedure covering physical protection, access authorizations, identification and authentication, encryption of stored and transmitted data, and incident handling, scaled to one of four security-level tiers (individually-managed, basic, medium, high) set by the type, volume, and sensitivity of data the database holds.

A database controller subject to the medium or high tier must additionally run an automatic access-monitoring mechanism retained at least 24 months, and a controller subject to the high tier must conduct a data security risk assessment and a penetration test at least once every 18 months.

Every controller other than one managing a database individually must appoint a data security officer where the Protection of Privacy Law requires one, and must conduct an internal or external audit of compliance with these Regulations at least once every 24 months for a medium- or high-tier database.

A controller engaging an external service provider with access to the database must agree in writing on the data the provider may process, the systems it may access, and the provider's own reporting and destruction duties, and must monitor the provider's compliance.

The Registrar (Head of the Privacy Protection Authority) may exempt a specific database from these duties, or extend them to one that would not otherwise be covered, by written notice given the database's size, the type of information it holds, and its number of authorized users. These duties are separate from Regulation 11(d)'s duty to notify the Registrar of a severe security incident, which is this jurisdiction's privacy-topic breach-notification row.

What it requires

News aggregation law1 instrument, 1 in force

Research summary (153 words)

Israel has no press-publisher neighbouring right and no mandatory platform-to-publisher bargaining code; the general copyright framework of the Copyright Act, 5768-2007 is the only law reaching an aggregator's reproduction of news content.

Section 5(5) excludes news of the day from copyright subsistence, while extending protection only to a report's particular expression, and section 19's fair-use exception permits quotation, criticism, review, and journalistic reporting subject to a four-factor test, with no headline-length or short-extract cap and no restriction to the press industry.

No reported Israeli decision applying either provision to a systematic news aggregator, as opposed to an individual quoting a published work, was located. No statute or case law located addresses whether a hyperlink is itself a communication to the public, or whether framing or inline display changes the answer, and no hot-news or misappropriation doctrine distinct from ordinary copyright law was found. The Act carries no machine-readable text-and-data-mining reservation or opt-out mechanism.

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.