Israel Privacy Protection Law (PPL 5741-1981) + Amendment 13 + INCD AI: AI Compliance Requirements
Israel's Privacy Protection Law (PPL, 5741-1981) is administered by the Privacy Protection Authority (PPA, formerly ILITA). Israel received an EU adequacy decision in 2011 (under periodic EU review). Amendment 13 — approved by the Knesset 2024-08-05, with most provisions effective 2025-08-14 (NOT January 2024, a date this entry previously stated in error) — added GDPR-aligned provisions: a mandatory Privacy Protection Officer (PPO) for large-scale/sensitive-data processors, breach notification to the PPA, database registration (100,000+ sensitive records), and enhanced cross-border transfer controls. The PPA published draft AI guidelines in April 2025 explicitly applying the PPL to AI systems across training, development, and deployment. The Israel National Cyber Directorate (INCD) has issued AI security guidelines. Israeli technology companies are major AI developers and face full EU AI Act compliance for EU market access.
Summary of publicly-available regulatory text as of 2026-08-22. Verify against current official sources before relying on this for compliance decisions. Not legal advice.
Key Facts
January 1, 1981
August 14, 2025
Tiered under Amendment 13: per-offense fines ILS 1,000-320,000; aggravated cases doubled to ILS 640,000; large-scale violations add a per-data-subject component up to ILS 100/individual; capped at 5% of annual turnover in the most serious cases. Class actions permitted under PPL Section 31. Criminal sanctions for willful breaches.
What Your Business Must Do
4 compliance requirements identified. Critical requirements carry the highest risk of enforcement action.
Database Registration with Privacy Protection Authority
CriticalPPL Section 8 requires organizations maintaining databases of Israeli residents' personal data to register with the PPA (Privacy Protection Authority). AI training datasets containing Israeli personal data constitute registrable databases. Amendment 13 (effective 2025-08-14) adds mandatory registration for databases holding sensitive information on 100,000+ individuals.
Deadline: August 14, 2025
PPL Section 8; Amendment 13 (effective 2025-08-14)Informed Consent and AI Processing Disclosure
CriticalPPL Section 11 requires organizations to inform individuals of data processing purposes before collection. The PPA's draft AI guidelines (April 2025) require separate active consent for AI processing that is complex, deviates from reasonable expectations, or is high-risk — prior/repurposed consent is insufficient. Privacy notices must explicitly mention AI use and automated decision logic.
Privacy Protection Officer Appointment (Amendment 13)
High PriorityAmendment 13 (effective 2025-08-14) requires organizations engaged in large-scale sensitive-data processing or systematic monitoring to appoint an independent Privacy Protection Officer reporting directly to senior leadership — a common profile for AI/ML operations. AI systems processing sensitive categories (health, financial, biometric, political) fall within this scope.
Deadline: August 14, 2025
Amendment 13 (effective 2025-08-14)INCD AI Security Guidelines Compliance
Medium PriorityThe Israel National Cyber Directorate (INCD) published AI security guidelines covering prompt injection defense, model security, and AI supply chain integrity. Organizations deploying AI in critical infrastructure, defense-adjacent sectors, or government contracts must comply with INCD guidelines and conduct AI security assessments. Israeli high-tech companies exporting AI must also comply with EU AI Act for European customers.
Recent Enforcement Actions
Against:
Recent Regulatory Guidance
PPA — Amendment 13 implementation + draft AI guidelines (2025)
Amendment 13 (approved 2024-08-05, effective 2025-08-14) requires: (1) a Privacy Protection Officer for large-scale/sensitive-data processors; (2) breach notification to the PPA; (3) database registration for 100,000+ sensitive records; (4) enhanced consent/opt-out and cross-border-transfer requirements. The PPA's draft AI guidelines (April 2025) apply the PPL to AI systems across training, development, and deployment: privacy-by-design, separate active consent for high-risk/complex AI processing, transparency for significant automated decisions, and controller accountability for third-party AI vendors. INCD AI security guidance imposes parallel cybersecurity obligations on AI systems handling sensitive personal data. Israel's EU adequacy decision (2011) is subject to periodic EU review.
Frequently Asked Questions
Does Israel Privacy Protection Law (PPL 5741-1981) + Amendment 13 + INCD AI apply to my business?
Israel's Privacy Protection Law (PPL, 5741-1981) is administered by the Privacy Protection Authority (PPA, formerly ILITA). Israel received an EU adequacy decision in 2011 (under periodic EU review). Amendment 13 — approved by the Knesset… Use Aegis Firma's free scanner to get a personalized assessment in under 5 minutes.
What is the penalty for non-compliance?
The maximum penalty under Israel Privacy Protection Law (PPL 5741-1981) + Amendment 13 + INCD AI is: Tiered under Amendment 13: per-offense fines ILS 1,000-320,000; aggravated cases doubled to ILS 640,000; large-scale violations add a per-data-subject component up to ILS 100/individual; capped at 5% of annual turnover in the most serious cases. Class actions permitted under PPL Section 31. Criminal sanctions for willful breaches.. Fines are typically scaled by company size, severity of violation, and whether violations were willful or accidental.
How do I comply with Israel Privacy Protection Law (PPL 5741-1981) + Amendment 13 + INCD AI?
The 4 requirements above cover the core obligations. The fastest path to compliance is: (1) conduct an AI risk assessment, (2) document your AI systems, (3) implement transparency disclosures where required. Aegis Firma generates all required documents automatically.
Official Source
https://www.gov.il/en/departments/the_privacy_protection_authorityLast updated: 2026-08-22 — verify at source before relying on this information.
Don't leave compliance to chance
Aegis Firma scans your AI tools, tells you exactly which regulations apply, and generates all required documents — in 30 minutes.
Start your free compliance scan