Amendment 13 to Israel’s Privacy Law: Legislated, Not Yet Implemented

Amendment 13 to Israel's Privacy Law
Amendment 13 to Israel's Privacy Protection Law took effect in August 2025, introducing real operational duties and enforceable sanctions: appointing a privacy officer, signing data processing agreements with vendors, and reporting security incidents. A year later, many organizations are still unprepared.

In August 2025, Amendment 13 to Israel’s Privacy Protection Law came into force — the most significant change to Israeli privacy law since the original statute was enacted in 1981. A year later, the picture on the ground is troubling: many private organizations still haven’t appointed a privacy officer, confidentiality and data processing agreements with vendors remain unsigned, and large parts of the market appear not to have grasped that the rules of the game have changed.

Background: why was an amendment needed in the first place?

The Privacy Protection Law was enacted in 1981, at a time when a “database” was mostly a filing cabinet. Since then, everything has changed: cloud computing, smartphones, social networks, artificial intelligence and cyber threats have turned personal data into organizations’ most critical business asset — and their greatest exposure. In Europe, the GDPR took effect back in 2018, setting a new global standard. Israel, which benefits from an “adequacy” status with the European Union that allows the free flow of data, could not afford to keep operating under a law that was four decades old.

The legislator’s move: real duties, real sanctions

Amendment 13, passed by the Knesset in August 2024, is a bold and pioneering step. For the first time, Israeli lawmakers didn’t settle for a declaration of principles — they wrote binding operational duties into the law, backed by real sanctions. This marks a shift toward an “accountability” model: it’s no longer enough to state that privacy is protected, organizations must be able to prove it. The main elements of the amendment:

– An expanded definition of “personal information” — now including digital identifiers, IP addresses, location data and cookies.
– A mandatory duty to appoint a Data Protection Officer (DPO) — for public bodies and for private organizations that meet defined criteria, including data brokers, entities that systematically monitor individuals, and organizations processing sensitive data at scale.
– Unprecedented enforcement powers for the Privacy Protection Authority — administrative financial sanctions through an expedited process, with no need for criminal proceedings, including “rolling” fines calculated according to the number of individuals in the database.
– A mandatory duty to report serious security incidents — to the Authority and, in certain cases, to the affected data subjects themselves.
– Strengthened individual rights — access, correction and deletion, alongside easier civil claims and compensation without the need to prove damage.

It’s worth stressing: these sanctions are not a recommendation or an “emergency measure.” They are a structured, binding part of the law, and the Privacy Protection Authority has been given an explicit mandate to enforce them.

So what’s actually happening? The picture is concerning

As a company that works with dozens of organizations on IT, information security and cybersecurity, we see the gap between the law and reality every day. Three patterns stand out in particular:

– Agreements aren’t being signed. Data security regulations require a formal agreement with any external party that accesses or processes personal data — an IT provider, a service center, a payroll bureau, a payment clearing system. In practice, vendors and service providers are being given full access to databases with no data processing agreement, no confidentiality agreement (NDA), and no defined liability in the event of a breach.
– Private organizations have no privacy officer. The Authority has published final guidance clarifying who is required to make the appointment, yet in many private organizations no one has been assigned to the role — and often, no one in the organization has even checked whether the duty applies to them.
– The market hasn’t internalized the change. Many executives still treat Amendment 13 as “a legal matter” or as just another regulation that no one actually enforces. But the grace period is over: since the start of 2026 the Authority has moved to active enforcement, according to reports it is managing more than a hundred enforcement files, and the first sanctions have already been issued — including for late reporting of a security incident.

What should you do? Six practical steps

1. Map your databases — what personal data is collected, where it’s stored, who has access to it, and for what purposes.
2. Check whether the duty to appoint a DPO applies — and where it does, actually appoint a qualified professional with no conflict of interest (this can also be outsourced).
3. Complete the required documentation — a database definitions document, a data security procedure, and a systems mapping, as required by the regulations.
4. Close out the agreements — data processing and confidentiality agreements with every external vendor, including managed IT service providers, along with confidentiality commitments from employees who hold access privileges.
5. Establish an incident reporting procedure — who identifies an incident, who decides how to respond, and within what timeframe it must be reported to the Authority. It’s important to ensure continuous availability of the relevant personnel and to link this procedure to the organization’s existing backup and business continuity plans. Late reporting is, by itself, grounds for a sanction.
6. Bring the issue to senior management and the board — responsibility for compliance rests with the organization, but the duty to make sure it actually happens belongs on the management table. This is a governance risk, not merely a technical issue.

Bottom line

Israeli lawmakers have taken an important and pioneering step: they turned privacy protection from a declared value into an enforceable duty with real teeth. But even a well-designed law protects no one if it stays on paper. An organization that prepares now — mapping, appointing, signing and formalizing procedures — will move through this new enforcement era quietly. An organization that keeps waiting may end up discovering Amendment 13 through a letter from the Privacy Protection Authority. Getting ready isn’t complicated, but it does require a decision — and it’s better to make that decision yourself before someone else makes it for you.

If this topic is currently open at your organization, I’d be glad to hear how you’re approaching it. Feel free to reach out to us.

The First Step Starts Here
Professionalism
Our primary asset lies in our human capital, delivering real-time solutions on-site. Therefore, our IT technicians undergo continuous training and certification to ensure top-quality service.
Quality Assurance and Reliability
We implement high-standard quality processes that include clear procedures, documented monitoring, extensive control systems, and thorough inspections.
Availability and Teamwork
We understand the importance of maintaining the continuous operation of our clients' computer systems. Our team ensures full availability to support you whenever needed.
Integrity and Reliability
Integrity and reliability are our guiding principles, serving as a solid foundation for productive and successful collaboration.
Data Protection
T.O.M is committed to maintaining the confidentiality of information and utilizing advanced technological means to safeguard the assets of the organization and, of course, all its clients.

IT solutions designed for your peace of mind

How can we assist you?

This site uses information collection technologies such as Cookies, including by third parties, in order to provide you with a better browsing experience as well as for statistical, profiling and marketing purposes. Continued browsing of this site constitutes your consent to this. For more information and the option to manage the use of these tools, please see our updated Privacy Policy