Amendment 13 to the Privacy Protection Law: A Practical Guide for Business Owners (2026)
Privacy Protection Law Amendment 13, in force since August 2025: what it requires, a site and ad checklist, sanctions, and what not to copy from the GDPR.

Amendment 13 to the Privacy Protection Law took effect on August 14, 2025, and it is the biggest overhaul of Israeli privacy law in decades. It applies to every business that collects, processes or stores personal information, which means almost every business in Israel: a contact form, a mailing list, a CRM, a Meta pixel. In this article we break down what the law requires, what it means in practice for your website and your campaigns, what the sanctions are, and where Israeli law differs from the GDPR. That last point matters, because most of the privacy policies we see on Israeli websites copy European clauses that simply don't exist here.
What Amendment 13 is and what it requires
Amendment 13 brings Israeli law closer to GDPR standards, but it doesn't copy it. Assuming it does is the mistake that costs the most money. The core principles: informed consent (Section 3), an expanded duty to inform at the time the information is collected (Section 11), a right of access (Section 13), and a right to request the correction or deletion of information that is not accurate, complete, clear or up to date (Section 14).
Note the difference: this is not the GDPR's sweeping "right to be forgotten." The Israeli right depends on the information being flawed. "Data portability" and "restriction of processing" are not rights under Israeli law either. So don't promise rights in your privacy policy that you have no way to deliver. A promise like that doesn't protect you; it only creates a commitment you won't meet.
On top of that, the duty to inform under Section 11 is the heart of the Amendment for a small business. Every time you ask for personal information, the person needs to know: whether there is a legal obligation to provide it, the purpose it is collected for, who it will be passed to, and what their rights are. A lead form without this information is a violation.
Who the law applies to, and what "information of special sensitivity" means
Here is a point that confuses many businesses: the law applies to every database of personal information, with no minimum threshold. If you have a contact form that saves to a CRM, the law applies to you, even with 50 leads. The 10,000-person threshold is not a condition for the law to apply but a trigger for specific obligations, such as registering the database in the registry. And even that applies only when the database was intended from the outset for providing information to others as a line of business.
"Information of special sensitivity" raises the level of obligations, but it isn't what determines whether the law applies. This category includes health, genetics, biometrics, origin, criminal record, political opinions or beliefs, salary data and financial activity, location data, and more. In other words, a clinic, a mortgage advisor or a therapist carries a higher level of obligations than a clothing store, even if their database is small.
What to do with this: write a list of every place where you collect personal information (website, WhatsApp, Google Forms, CRM, booking system, invoices). That is the list the checklist below works from.
The penalties: monetary sanctions and compensation without proof of damage
The penalties are steep. The monetary sanctions in Section 23KV are built in layers: fixed amounts of ₪15,000 to ₪300,000 depending on the type of violation, alongside sanctions calculated by the number of people involved. For example, ₪50 for each person you approached without giving the notice required by Section 11, with a floor of ₪30,000. In other words, the exposure from a violation involving a large database isn't limited by a comfortable cap.
In addition, Section 15A allows a court to award compensation without proof of damage of up to ₪10,000. But only for a closed list of violations, and for some of them only after the person demanded that you remedy the issue and 30 or 90 days have passed. The practical takeaway: if you respond to requests quickly and document your response, you reduce this exposure before it starts.
A business owner's checklist: 8 things to check this week

- Your database. Know what information you have, where it is stored, and who has access to it. Without this list, you can't meet any of the other obligations.
- A privacy policy on your website. Up to date, accurate for your business, and linked from every page. It must state what data is collected (name, email, IP, cookies), why, who it is shared with (Google Analytics? Meta? An email marketing platform?), how long it is kept, and what the user's rights are.
- Consent in forms. The "I agree to receive marketing messages" box is not pre-checked. The user checks it themselves, and you keep a record: when, how, and from which page.
- A real cookie consent banner. An option to reject, a choice of categories (functional, analytics, marketing), and a website that keeps working even after a rejection.
- Pixels and conversion tracking. Google Tag Manager, GA4 and the Meta Pixel load only after consent. This is the part most websites in Israel miss.
- WhatsApp and email marketing. Marketing messages go only to people who agreed to receive them, with a clear way to unsubscribe in every message. Consent to receive a price quote is not consent to a newsletter.
- Vendors. Every service that holds information for you (CRM, email marketing, hosting, payment processing) is part of your database. Check what your agreement with them says about security and deletion.
- A mechanism for access, correction and deletion. An email address or a dedicated form, a defined process, and a response within 30 days. A deletion has to reach every system, not just the website.
What this means for your website and campaigns

Many business owners think of Amendment 13 as a purely legal matter. In practice, it directly affects measurement and advertising. If the Meta pixel loads before consent, that's a violation. If it loads only after consent, the campaign measures fewer conversions, and you need to plan for that. The right solution is Google's Consent Mode and a similar setup in Meta, both of which report according to consent. We covered the full setup in our guide to conversion tracking with GA4, Google Ads and the Meta Pixel.
On WhatsApp the rules are even stricter, because the platform itself requires prior approval for marketing messages. What's allowed and what isn't, including the Spam Law, is explained in our article on WhatsApp marketing for business.
Finally, data security is part of the law, not an extra. A WordPress site that hasn't been updated in a year is a legal exposure, not just a technical one. The monthly checklist is in our article on website maintenance and security. And if you're building a new website, the legal obligations are also summarized in our guide to website building for small businesses.
Common mistakes we see on Israeli websites
Mistake #1: A "this site uses cookies" banner and nothing more. That's not enough. You need an active option to reject and to choose categories. Most websites in Israel still use the old banner, and that's direct exposure.
Mistake #2: The Meta Pixel and Google Analytics load before consent. These scripts collect data the moment the page loads. They must load only after a click on "I agree."
Mistake #3: An "I have read and agree" box that is checked by default. This is invalid under Amendment 13. The user must check it themselves.
Mistake #4: A generic privacy policy copied from another website. The policy has to be accurate for your business: which tools, who data is passed to, and for how long. A generic policy doesn't meet the requirements, and a policy that promises GDPR rights that don't exist in Israel only does harm.
Mistake #5: No mechanism for deletion requests. The user can't find how to reach you. Without a clear mechanism and a timely response, you're also exposed to compensation without proof of damage.
Privacy protection officers and security incident reporting: where not to copy the GDPR
A privacy protection officer (DPO), only if you're actually required to have one. Section 17B1 sets out a closed list: public bodies; those whose database is intended for providing information to others as a line of business and covers more than 10,000 people; those whose main business involves ongoing, systematic monitoring of people on a significant scale; and those whose main business is processing information of special sensitivity on a significant scale. A regular business with 10,000 customers in its database is not required to appoint one. Size alone is not the trigger. Check yourself against the list before you buy an outsourced DPO service. If you do fall within it, the ways to contact the officer must be published to the public in an accessible way.
Security incident notification. Here it's important not to copy the GDPR: Israeli law has no 72-hour window. The Privacy Protection Regulations (Data Security), 2017 require immediate reporting to the Privacy Protection Authority of a "severe security incident," and only for databases at the medium or high security level (Regulation 11(d); Regulation 21(3) does not apply it to a database at the basic level). What does apply to everyone: the duty to document security incidents and to have a procedure for handling them. Prepare the procedure in advance, because on the day you need it, there's no time to write it.
What Simple Web does about it
Every website we've built since 2025 comes with a full consent management setup: an active banner with categories, conditional script loading, consent records, and a privacy policy written for the specific business. We also build a deletion-request process that connects to the CRM and the email marketing tools, so a single request removes the data from every system. You'll find the details of the infrastructure we build on our brand website development page.
For existing clients, we run a Privacy Audit: we review the website, the forms and the pixels, identify exposures and fix them. The audit costs ₪1,500. Before that, you can start with a free 20-minute privacy check that shows whether there's a problem at all.
Simple Web is an AI-first marketing agency from Bnei Brak, certified Meta partners and Google advertising experts, with 200+ clients and 28 five-star Google reviews.
Amendment 13 may look like just another regulatory burden, but in practice it's an opportunity to build trust. A website that respects privacy generates higher-quality leads, and the cost of non-compliance is far higher than the cost of compliance. Want to know where your website stands? Get in touch for a free 20-minute privacy check.
Sources
- Amendment 13 to the Privacy Protection Law — gov.il — the text of the Amendment, its effective date and the sections cited in this article
- The Privacy Protection Authority — gov.il — enforcement powers, guidance and the data security regulations
- Google Analytics Help Center — Consent Mode and data retention settings in GA4
Tags:
Recent posts


