Amendment 13 has been in force since August 2025: informed consent, an expanded section 11 duty to notify, and administrative fines calculated per person. Here is what to do on your site - and what not to copy from the GDPR.

Privacy Protection Law Amendment 13 entered into force on August 14, 2025, and it is the biggest reform of Israeli privacy law in decades. It affects every business that collects, processes, or stores personal data, which in practice means almost every business in Israel. In this article we break down exactly what the law requires and what you must do on your website. We also cover the consequences of non-compliance, which can reach 10,000 NIS per civil claim.
Amendment 13 moves Israeli law closer to GDPR standards, but it does not copy it - and that is the mistake that costs the most. The core principles: informed consent (section 3), an expanded duty to notify at the point of collection (section 11), a right of access (section 13), and a right to ask for correction or deletion of information that is inaccurate, incomplete, unclear or out of date (section 14). Note: this is not the GDPR sweeping "right to be forgotten" - it is conditional on the information being defective. Likewise, "data portability" and "restriction of processing" are not rights under Israeli law. Do not promise rights in your privacy policy that you have no way to deliver.
A point that confuses many businesses: the law applies to every database of personal information, with no minimum threshold. If you have a contact form saved into a CRM, the law applies to you - even with 50 leads. The 10,000-person figure is not a condition for the law applying; it is a trigger for specific obligations (registration in the database registry, for instance, and even then only where the database exists to supply data to others as a business). "Specially sensitive information" - health, genetics, biometrics, ethnicity, criminal record, political or religious views, salary and financial activity, location data and more - raises the level of obligations, but is not what determines whether the law applies.
The sanctions are sharp. The administrative fines in section 23(26) are tiered: fixed amounts from 15,000 to 300,000 NIS depending on the breach, alongside fines calculated per person - for example 50 NIS for every person you approached without giving the notice section 11 requires, with a 30,000 NIS floor. Exposure on a breach touching a large database is therefore not capped at a comfortable number. Separately, section 15A lets a court award up to 10,000 NIS without proof of damage - but only for a closed list of breaches, and for most of them only after the person demanded a fix and 30 or 90 days passed.
1. A real Cookie Consent banner. Not "this site uses cookies, continued use means you agree." You need active consent: the option to reject, to choose categories (functional/analytics/marketing), and to keep using the site even if the user rejected. Tag Manager and Meta Pixel do not load before consent.
2. An updated, detailed privacy policy. Must include: what data is collected (name, email, IP, cookies), why it is collected, who it is shared with (Google Analytics? Meta? Mailchimp?), how long it is retained, and the user's rights. The link must be available on every page, not only in the footer.
3. Signup forms with double opt-in. A checkbox for "I agree to receive marketing messages" cannot be pre-checked; the user must choose actively. You also have to keep a record of the consent (when, how, from which IP).
4. Right of erasure and rectification. The user can ask to have their data deleted. You need a clear process: how they reach out (email? form?), how quickly you respond (within 30 days), and how the data is actually deleted across all systems - CRM, Mailchimp, Facebook, Google.
5. Data Protection Officer (DPO) - only if you actually have to. Section 17B1 sets a closed list: public bodies; anyone whose database exists to supply data to others as a business and holds more than 10,000 people; anyone whose main activity involves regular, systematic monitoring of people on a significant scale; and anyone whose main activity is processing specially sensitive information on a significant scale. An ordinary business with 10,000 customer records is not required to appoint one - volume alone is not the trigger. Check yourself against that list before buying an outsourced DPO service. If you are covered, the officer contact details must be published to the public accessibly and simply.
6. Security event notification. Do not copy the GDPR here: Israeli law has no 72-hour window. The Privacy Protection Regulations (Data Security), 5777-2017 require immediate notice to the Authority of a "severe security incident" - and only for databases at the medium or high security tier (reg. 11(d); reg. 21(3) does not extend it to a basic-tier database). What does apply to everyone: logging security incidents and keeping a documented response procedure.
Mistake #1: A "this site uses cookies" banner only. Not enough. You need an active option to reject and to choose categories. Most Israeli sites still use the old banner, which leaves them directly exposed to claims.
Mistake #2: Meta Pixel and Google Analytics loading before consent. This is a serious violation. These scripts collect data the moment the page loads. They must load only after the user clicks "agree."
Mistake #3: "I have read and agree" box pre-checked by default. Completely invalid under Amendment 13. The user must check it themselves.
Mistake #4: A generic privacy policy copied from another site. The policy must be specific to your business - which tools you use, who you share data with, etc. A generic policy does not meet the requirements.
Mistake #5: No erasure mechanism. The user cannot find how to delete their data. Within 30 days of a request - you must respond. Without a clear mechanism, you are exposed.
In every site we have built since 2025, a full Consent Management module is in place: an active banner with 3 categories, conditional script loading, consent logging, and a tailored privacy policy. We also build an automated erasure request flow connected to the CRM and email tools.
In addition, we run Privacy Audits for existing clients, going over the site to identify exposures and fix them. The audit costs 1,500 NIS and usually pays for itself by preventing a single claim.
Summary: Amendment 13 may look like one more regulatory burden, but in practice it is an opportunity to build trust with customers. A site that respects privacy is a site that generates higher-quality leads and long-term trust. The cost of non-compliance is far higher than the cost of compliance. Want a check of your site? Get in touch for a free 20-minute Privacy audit.

April 21, 2026

October 16, 2025

November 15, 2025