Back to Insights Compliance

Revolution on the Horizon: The Privacy Protection Law is About to Undergo a Comprehensive Amendment

Amendment 14 to the Privacy Protection Law, the most significant update in over 30 years, is returning to the Knesset for its second and third readings. The changes are designed to align the law with European Union requirements (GDPR) and to address the surge in cyberattacks against Israeli targets since the outbreak of the “Iron Swords” war. Key changes include reducing the obligation to register databases, strengthening enforcement tools, defining “Sensitive Information,” and re-designating the Registrar of Databases as the Data Protection Commissioner. The discussion is expected to focus on the importance of the amendment and the Authority’s enforcement capabilities. The primary changes in the amendment, if adopted in its current format, will take effect shortly.

This amendment includes significant changes as follows:

Alignment of Legal Definitions with International Laws:
* Replacing the term “Database Owner” with “Database Controller.”
* Expanding the definition of “Use” to include viewing and storage actions.
* Replacing the term “Sensitive Information” with “Information of Special Sensitivity.”

Reduction of Registration Requirements:
* Focusing oversight on large databases that pose a risk to privacy.
* Data security regulations will apply to all databases, including those that are unregistered.
* The status of currently registered databases that do not meet the new criteria remains unclear.

Strengthening Oversight and Enforcement Tools:
* Establishing an administrative enforcement mechanism as an alternative to criminal proceedings.
* Imposing financial sanctions for violations.

Additionally, the proposed law expands the definition of “Information” beyond the current Privacy Protection Law to include any data relating to an identified or identifiable person.

Legal Violations and Relevant Sanctions
The bill defines several new criminal offenses:
* Interfering with the Commissioner, an inspector, or an investigator acting under the law.
* Misleading the Commissioner or an authorized inspector.
* Fraudulently requesting information related to a database.
* Using database information for purposes other than those for which it was created.
* Unauthorized use or possession of information.
* Unlawful disclosure of information by a public body.

Under the new law, criminal offenses can also be committed through negligence, with penalties ranging from six months to five years of imprisonment, depending on the offense. The law expands the administrative enforcement tools available to the Privacy Protection Authority (PPA), allowing for the imposition of financial sanctions, administrative warnings, and formal undertakings to refrain from violations. Sanction amounts are determined by the size of the database and the type of data stored, and can be doubled based on the nature of the violation.

Currently, administrative fines range from 2,000 to 5,000 NIS for individuals and 10,000 to 25,000 NIS for corporations. Below are the new base fine amounts:

| Number of Data Subjects | Standard Information | Information of Special Sensitivity |
| :— | :— | :— |
| Up to 1,000 | 5,000 NIS | 50,000 NIS |
| 1,001 – 10,000 | 10,000 NIS | 100,000 NIS |
| 10,001 – 100,000 | 20,000 NIS | 200,000 NIS |
| 100,001 – 1,000,000 | 40,000 NIS | 400,000 NIS |
| Over 1,000,000 | 80,000 NIS | 800,000 NIS |

Key Insights from Amendment 14 to the Privacy Protection Law:
Based on the information in this article, privacy experts recommend the following steps for organizations to improve their data security and privacy practices:

  1. Reduced Registration Burden: Most databases will no longer require registration. According to the amendment, registration will generally be required for databases containing 100,000 or more records, subject to specific exemptions and the Commissioner’s discretion.
  2. Increased Compliance Pressure: Organizations will find it harder to ignore compliance with the law and regulations due to strengthened oversight and enforcement powers granted to the Commissioner as head of the Privacy Protection Authority.
  3. Harsher Penalties: Fines for non-compliance have increased significantly, and other related administrative sanctions have been tightened.
  4. Elevated Status of the Commissioner: Changing the title from “Registrar of Databases” to “Data Protection Commissioner” elevates the role’s requirements and authority (now requiring qualifications equivalent to a District Court judge rather than a Magistrate Court judge). This change underscores the importance of the field and signals increased enforcement.
  5. Refined Data Classification: The shift to “Information of Special Sensitivity” and the detailed legal breakdown of such data assist organizations in more accurately characterizing the sensitivity level of their information.
  6. Exemption Authority: The Data Protection Commissioner may, for special reasons, exempt a specific database from the registration requirement if convinced that registration is not necessary to ensure legal compliance.

Conclusion
It is hoped that the Ministry of Justice’s advancement of this bill will foster professional dialogue among all stakeholders to create a robust legislative framework capable of meeting modern privacy challenges.

Please note: This article provides a general overview only. It is recommended to consult with a privacy law expert for specific organizational guidance.

Continue the Conversation

Facing a cybersecurity challenge? Let's talk about how a managed program can strengthen your resilience.

Start a conversation