Does a company in Israel still have to register its customer database with the Privacy Protection Authority?
The old regime required almost any business holding a customer or employee database to file a registration form, and compliance was poor because the duty was broad and the benefit unclear. Amendment 13 replaced it with an enforcement model closer to the European approach. It defines the roles of controller and processor, requires a data protection officer for public bodies, data brokers, and controllers whose core activity involves large-scale processing of highly sensitive data, and gives the Privacy Protection Authority a scaled administrative fine power in place of a criminal track that was rarely used. Dropping registration narrowed the paperwork, not the exposure.
A foreign company selling into Israel should not read the change as deregulation. Internal database documentation is still expected, and the Privacy Protection Authority can demand it during an inspection, so the register you no longer file is the register you now keep. The Privacy Protection (Data Security) Regulations 5777-2017 remain in force and require every database to be classified at a basic, medium, or high security level, with controls that follow the classification. Practical priorities are a published privacy notice in Hebrew, a written processor agreement with any vendor touching Israeli personal data, a documented breach response, and a decision on whether the officer threshold applies.
- Governing law: Protection of Privacy Law 5741-1981 as amended by Amendment 13, in force 14 August 2025; Privacy Protection (Data Security) Regulations 5777-2017
- Competent authority: Israeli Privacy Protection Authority (HaRashut LeHaganat HaPratiyut), Ministry of Justice
- Who must still register: databases whose principal purpose is delivering personal data to third parties, and databases held by public bodies
- Penalties: administrative fines scaled to the number of data subjects and the controller's size, replacing the earlier criminal-only enforcement track
- Still mandatory for everyone: internal database documentation, a security level classification under the 2017 regulations, a privacy notice at the point of collection, and a data protection officer where the statutory thresholds apply
From the full guide: Data Protection Law in Israel for Businesses and Foreign Companies
Related Questions
Get a Free Consultation with Adv. Eli ShimonyPrepared under the direction of Adv. Eli Shimony, Eli Shimony Law Office · Editorial policy