Skip to content
هذه ترجمة للتسهيل فقط. النسخة الإنجليزية هي النسخة الرسمية والملزمة قانونيا. عرض النسخة الإنجليزية
ILMEDIUM coverage1 enforcement action

Israel — Privacy Protection Law (Amendment 13) + PPA AI Guidelines: AI Compliance Requirements

Israel's Privacy Protection Law (PPL, 1981) was comprehensively overhauled by Amendment 13 (approved 2024-08-05, most provisions effective 2025-08-14) — the most significant Israeli privacy reform since the original law. It created a mandatory Privacy Protection Officer (PPO) duty for large-scale/sensitive-data processors, breach notification to the PPA, database registration (100,000+ sensitive records), enhanced consent/opt-out requirements, and cross-border transfer obligations. The PPA published draft AI guidelines (April 2025) explicitly applying the PPL to AI systems across training, development, and deployment: privacy-by-design, separate active consent for high-risk/complex AI processing, transparency for significant automated decisions, and controller accountability for third-party AI vendors. The PPA has begun active Amendment 13 enforcement, including its first sanction (Meuhedet Health Fund, NIS 256,000, 2026-07-21). Israel has EU adequacy status.

Summary of publicly-available regulatory text as of 2026-08-22. Verify against current official sources before relying on this for compliance decisions. Not legal advice.

Key Facts

Effective Date

January 1, 1981

Maximum Penalty

Tiered under Amendment 13: per-offense fines NIS 1,000-320,000; aggravated cases doubled to NIS 640,000; large-scale violations add a per-data-subject component up to NIS 100/individual; capped at 5% of annual turnover in the most serious cases (which can exceed the flat NIS 3.2M figure for large organizations). Small/micro businesses receive reduced thresholds.

What Your Business Must Do

3 compliance requirements identified. Critical requirements carry the highest risk of enforcement action.

Privacy Notice for AI Processing

High Priority

Israel's Privacy Protection Law requires notification when personal data is processed by AI for profiling, automated decisions, or marketing. Disclose: existence of AI processing, categories of data used, logic of automated decisions, and the individual's right to object. The PPA's draft AI guidelines (April 2025) require separate, active consent (not repurposed prior consent) where AI processing is complex, deviates from reasonable expectations, or is high-risk. Review PPA guidance at ppa.gov.il.

Privacy Protection Law (Amendment 13, effective 2025-08-14); PPA draft AI guidelines (2025-04)

Privacy Protection Officer (PPO) Designation (Amendment 13)

High Priority

Amendment 13 requires organizations meeting certain thresholds — including large-scale sensitive-data processing or systematic monitoring (a common profile for AI/ML operations) — to appoint an independent Privacy Protection Officer reporting directly to senior leadership; the role cannot be held by someone with conflicting decision-making authority. Also requires breach notification to the PPA and registration of databases holding sensitive information on 100,000+ individuals.

Deadline: August 14, 2025

Privacy Protection Law (Amendment 13, effective 2025-08-14)

PPA Draft AI Guidelines Compliance (April 2025)

Medium Priority

The PPA's draft AI guidelines (April 2025) apply the PPL to AI systems that collect, process, or use personal data during training, development, and deployment: embed privacy-by-design from inception; obtain separate active consent for complex/high-risk/expectation-deviating AI processing; provide transparency about the logic of automated decisions with significant effects; and remain accountable as the data controller for third-party AI vendors' processing. Document AI risk assessment and governance demonstrating explainability and fairness.

PPA draft AI guidelines (2025-04)

Recent Enforcement Actions

2026-07-21Source verified· as of 2026-08-22

Against:

Recent Regulatory Guidance

guidance2025-04

PPA — draft AI guidelines applying the PPL to AI systems (April 2025)

The PPA published draft guidelines confirming the PPL applies to AI systems that collect, process, or use personal data during training, development, and deployment: privacy-by-design from inception; separate active consent (not repurposed prior consent) where AI processing is complex, deviates from reasonable expectations, or is high-risk; transparency about the logic of automated decisions with significant effects; and controller accountability for third-party AI vendors' processing.

guidance2024-06

Israel Technology Authority — AI Governance Guidelines (2024, voluntary policy layer)

Israel's Innovation Authority and Technology Authority published voluntary AI governance guidelines covering: AI risk assessment and documentation; transparency requirements for automated decision-making affecting individuals; bias testing methodology for AI models making decisions in regulated sectors; human oversight requirements for high-impact AI decisions (employment, credit, healthcare); and alignment with EU AI Act principles. Distinct from and supplementary to the PPA's binding PPL/Amendment 13 obligations above.

Frequently Asked Questions

Does Israel — Privacy Protection Law (Amendment 13) + PPA AI Guidelines apply to my business?

Israel's Privacy Protection Law (PPL, 1981) was comprehensively overhauled by Amendment 13 (approved 2024-08-05, most provisions effective 2025-08-14) — the most significant Israeli privacy reform since the original law. It created a mandatory… Use Aegis Firma's free scanner to get a personalized assessment in under 5 minutes.

What is the penalty for non-compliance?

The maximum penalty under Israel — Privacy Protection Law (Amendment 13) + PPA AI Guidelines is: Tiered under Amendment 13: per-offense fines NIS 1,000-320,000; aggravated cases doubled to NIS 640,000; large-scale violations add a per-data-subject component up to NIS 100/individual; capped at 5% of annual turnover in the most serious cases (which can exceed the flat NIS 3.2M figure for large organizations). Small/micro businesses receive reduced thresholds.. Fines are typically scaled by company size, severity of violation, and whether violations were willful or accidental.

How do I comply with Israel — Privacy Protection Law (Amendment 13) + PPA AI Guidelines?

The 3 requirements above cover the core obligations. The fastest path to compliance is: (1) conduct an AI risk assessment, (2) document your AI systems, (3) implement transparency disclosures where required. Aegis Firma generates all required documents automatically.

Official Source

https://www.gov.il/en/departments/digital-technology-department

Last updated: 2026-08-22 — verify at source before relying on this information.

Don't leave compliance to chance

Aegis Firma scans your AI tools, tells you exactly which regulations apply, and generates all required documents — in 30 minutes.

Start your free compliance scan