Must a company report a data breach to Israel's Privacy Protection Authority?
The Regulations sort every database into one of four security tiers according to its size, sensitivity and the number of people who can access it, and the reporting duty attaches at the medium and high tiers. A severe incident means unauthorized use or copying of a substantial part of the database, or damage to its integrity where the tier is high, rather than a routine failed login. The report goes to the Privacy Protection Authority, which then decides whether the affected individuals must be told and may require the company to publish that notice. Running alongside the reporting duty are record-keeping obligations: an incident log, a documented response, and a periodic review of the security arrangements, all producible on demand.
Foreign companies most often trip on speed and language rather than on substance. The Israeli trigger is immediate reporting, not a 72-hour window, so a legal team pacing itself against the European clock is already late by the time it files. Name someone before an incident who can prepare and submit the report in Hebrew, and keep a standing incident log rather than reconstructing events afterwards. Compliance with the GDPR does not discharge the Israeli duty, because the two regimes define the trigger, the recipient and the timing differently, and our guide to Israeli data protection law for businesses sets out the wider framework a foreign controller has to meet.
- Governing law: Privacy Protection (Data Security) Regulations 5777-2017; Privacy Protection Law 5741-1981 as amended by Amendment 13, in force August 2025
- Competent authority: Israel Privacy Protection Authority (HaRashut LeHaganat HaPratiyut), Ministry of Justice
- Reporting trigger: a severe security incident affecting a database held at the medium or high security tier
- Timing: the report is due immediately, not on a 72-hour clock as under the GDPR
- Notice to individuals: the Authority decides whether affected people must be informed and can require the company to publish the notice
- Penalties: administrative fines under Amendment 13 scale with the number of data subjects and reach into the millions of shekels for large databases
From the full guide: Israel Data Protection Law for Businesses
Related Questions
Get a Free Consultation with Adv. Eli ShimonyPrepared under the direction of Adv. Eli Shimony, Eli Shimony Law Office · Editorial policy