Corporate Law

Must a company report a data breach to Israel's Privacy Protection Authority?

Yes, where the database sits at the medium or high security tier. The Privacy Protection (Data Security) Regulations 5777-2017 require the controller of such a database to report a severe security incident to the Privacy Protection Authority immediately, and the Authority can then direct the company to notify the individuals whose data was exposed. Reach follows the data rather than the company address, so a foreign business holding personal data on Israeli residents is inside the regime. Amendment 13 to the Privacy Protection Law 5741-1981, in force since August 2025, put administrative fines behind the obligation, scaled to the size of the data holding.

The Regulations sort every database into one of four security tiers according to its size, sensitivity and the number of people who can access it, and the reporting duty attaches at the medium and high tiers. A severe incident means unauthorized use or copying of a substantial part of the database, or damage to its integrity where the tier is high, rather than a routine failed login. The report goes to the Privacy Protection Authority, which then decides whether the affected individuals must be told and may require the company to publish that notice. Running alongside the reporting duty are record-keeping obligations: an incident log, a documented response, and a periodic review of the security arrangements, all producible on demand.

Foreign companies most often trip on speed and language rather than on substance. The Israeli trigger is immediate reporting, not a 72-hour window, so a legal team pacing itself against the European clock is already late by the time it files. Name someone before an incident who can prepare and submit the report in Hebrew, and keep a standing incident log rather than reconstructing events afterwards. Compliance with the GDPR does not discharge the Israeli duty, because the two regimes define the trigger, the recipient and the timing differently, and our guide to Israeli data protection law for businesses sets out the wider framework a foreign controller has to meet.

⚖ In Practice
  • Governing law: Privacy Protection (Data Security) Regulations 5777-2017; Privacy Protection Law 5741-1981 as amended by Amendment 13, in force August 2025
  • Competent authority: Israel Privacy Protection Authority (HaRashut LeHaganat HaPratiyut), Ministry of Justice
  • Reporting trigger: a severe security incident affecting a database held at the medium or high security tier
  • Timing: the report is due immediately, not on a 72-hour clock as under the GDPR
  • Notice to individuals: the Authority decides whether affected people must be informed and can require the company to publish the notice
  • Penalties: administrative fines under Amendment 13 scale with the number of data subjects and reach into the millions of shekels for large databases

From the full guide: Israel Data Protection Law for Businesses


Related Questions

Related Guides

Need legal help with this topic?
Get a Free Consultation with Adv. Eli ShimonyPrepared under the direction of Adv. Eli Shimony, Eli Shimony Law Office · Editorial policy

← Browse all Q&A