PRIVACY LAW · LAW AND SOFTWARE
Amendment 13 to the Protection of Privacy Law — what a small business has to do
Most of what has been written about the Amendment was written for large organisations. Here is what actually applies to a business with a customer list, and why the hard part of it is settled by the software you work in — not by a procedure you file away in a drawer.
What is Amendment 13 to the Protection of Privacy Law, and when did it take effect?
The Protection of Privacy Law, 5741-1981 is the Israeli statute that governs what you may do with personal information about people. Amendment No. 13 passed the Knesset plenum on 5 August 2024 and took effect on 14 August 2025 — the most significant reform of Israeli privacy law since the Law was enacted.
The Amendment did two things at once, which is why it is easy to get confused about it. On one hand it scrapped outdated paperwork requirements that burdened businesses without producing any real protection. On the other hand it gave the Privacy Protection Authority teeth — powers of supervision, administrative inquiry and administrative enforcement, chief among them the imposition of financial sanctions.
The practical upshot: fewer forms, more responsibility. The Authority no longer has to get to a criminal court for a breach to cost you money.
In practice the Authority can open an administrative inquiry, demand documents, order infringing processing to stop, and impose a financial sanction. The size of the sanction turns on, among other things, the type of breach, the number of people the database holds information about, the sensitivity of the information and the size of the database. The larger and more sensitive the database, the greater the exposure. The Law also sets reduced amounts for a “micro-business” and a “small business”, so the scale is not built to bring down a small business over a technical breach.
Is your customer list even a database?
This is the first question, and many people skip straight past it to the obligations. The Law defines a “database” as a collection of personal information items processed by digital means — and expressly excludes two cases from the definition: a collection for personal use that is not for business purposes, and a collection holding only names, addresses and contact details for 100,000 people or fewer, which does not in itself reveal any further personal information.
So a contact list with a name, a phone number and an email — and nothing else — may not be a database at all, in which case the whole discussion of registration and security simply never opens.
But note the proviso that closes the gap: the exclusion applies only if the owner of the collection, or a corporation it controls, has no other collection holding different information items about those same people. This is where most businesses fall out. If alongside the contact list you also have order history, invoices, case files or notes about those same customers, the list no longer stands on its own and the exclusion does not apply. Very few real businesses hold a name and a phone number and nothing else.
Does a small business have to register a database after Amendment 13?
In most cases — no. Before the Amendment the registration duty was broad and applied to many private-sector databases. Section 8A, as worded after the Amendment, narrows it to two cases: a database whose main purpose is collecting personal information in order to pass it on to another as a line of business or for consideration (including direct mailing services) and which holds information on more than 10,000 people; or a database whose controller is a public body — unless the database holds information on that body's employees only.
A carpentry shop that keeps a customer list, a clinic that keeps an appointment diary, a business that keeps work files — these are not data brokers. They collect information for their own purposes, not in order to sell it on.
There is a further duty worth knowing about, in section 8A(b): a party that is not required to register, but whose database holds information of special sensitivity on more than 100,000 people, must notify the Authority within 30 days of the identity of the controller, its address and contact details, the identity of the Privacy Protection Officer and their contact details (where the appointment is required under section 17B1), and must provide a copy of the database definitions document. Most small businesses are several orders of magnitude away from that threshold.
| The duty | Before Amendment 13 | From 14 August 2025 |
|---|---|---|
| Database registration | A broad duty applying to many private-sector databases | s.8A(a): data brokers holding information on more than 10,000 people, and public bodies |
| Notice to the Authority | No separate duty | s.8A(b): an unregistered database with information of special sensitivity on more than 100,000 people — notice within 30 days |
| Privacy Protection Officer | No general duty in the Law | s.17B1: a duty on four defined categories (see below) |
| Enforcement | Mainly criminal, with limited enforcement in practice | Supervision, administrative inquiry and financial sanctions by the Authority |
| Statutory damages | No such provision | s.15A: up to ₪10,000 without proof of harm, for listed breaches |
| Data security | The Data Security Regulations, 5777-2017 | Unchanged — and now enforceable by financial sanction too |
Who has to appoint a Privacy Protection Officer?
The duty to appoint a Privacy Protection Officer is new in the Amendment, and it does not apply to everyone. Section 17B1(a) lists four categories: public bodies (other than a security body); data brokers holding information on more than 10,000 people; bodies whose main activities require, given their nature, scope or purpose, regular and systematic monitoring of people on a significant scale — mobile carriers and search engines, for example; and bodies whose main activity is processing information of special sensitivity on a significant scale, including banking corporations, insurers, general hospitals and health funds.
Section 17B1(b) also explains how “significant scale” is measured: the number of people whose information is processed, their share of the population, the volume of the information and its types, the duration and frequency of the processing, and more.
A typical small business falls into none of the four categories. That does not mean nobody should be responsible for the subject in your business — it means the Law does not force a formal role on you.
What counts as information of special sensitivity?
The Amendment replaced the old term and widened it. The category includes, among other things, medical, genetic and biometric information, location data, political opinions and religious beliefs, criminal record, sexual orientation, salary and financial activity, and personal assessments.
That list is broader than it looks. A clinic holds medical information. An employer holds salary data. A system with location-based check-in holds location data. The moment you hold information like this, the security level required of you goes up — even if you are not required to register.
What can people demand from you?
This is the part that is easiest to miss, because it does not feel like an obligation — it arrives as a customer enquiry. The Law gives every person a right of access to the personal information about them held in your database (section 13), and a right to demand correction or deletion of information that is not correct, complete, clear or up to date (section 14). If you refuse, you must reply in writing and give reasons.
Amendment 13 also widened the duty to inform at the point of collection (section 11). Beyond whether providing the information is a legal obligation or voluntary, you now also have to say what the consequence of not consenting is, who the controller of the database is and how to contact them, and what the rights of access and correction are.
And those rights now have civil teeth. Section 15A, added by the Amendment, allows a court to award statutory damages that do not depend on harm, up to ₪10,000, for a closed list of breaches — among them refusing to allow access, agreeing to correct or delete information without actually doing it, and failing to deliver a notice of refusal. Some of the causes of action are conditional on a prior approach: for failure to register, a demand to register the database and 90 days having passed; for failure to give notice under section 11 — a demand and 30 days.
In setting the amount the court takes into account, among other things, encouraging the claimant to exercise their rights, and the scope and severity of the breach — and expressly not the size of the harm caused.
Now an operational question: if a customer calls tomorrow and asks to see everything you hold about them — how long would that take? If the answer is “we'd have to look in several places”, that is not a legal problem. That is a systems problem.
So what is actually left for a small business to do?
What is left, and what is the enforced part today, is the Protection of Privacy (Data Security) Regulations, 5777-2017. A critical point many people miss: the application of the Regulations does not depend on registration. They apply to a database even when there is no duty to register it.
The Regulations grade the requirements by security level — basic, medium and high — according to the type of information and its scope. Even at the basic level you need a database definitions document (reg 2) and management of access permissions by role definitions (reg 8). As you move up the levels, requirements are added for automatic access logging, backup and restore, and further controls. Under the Second Schedule, the high security level applies where a database of the sensitive types holds information on 100,000 people or more, or where the number of authorised users in it exceeds 100.
The Regulations also have an eased track — “a database managed by an individual”, in which only the individual and at most two further authorised users use the database. But regulation 1 expressly excludes three types from it, and one of them is critical: a database that includes information in respect of which the database owner is subject to a duty of professional confidentiality under law or under principles of professional ethics (as well as a database with information on 10,000 people or more, and a data broker's database).
The implication is sharp: a lawyer, a doctor, a psychologist or a therapist can never benefit from the eased track. Even a sole lawyer working alone, with a database of twenty clients, is pushed out of the definition by the duty of professional confidentiality that applies to them. This is exactly why clinic management software and a system for a law firm cannot be built like a list in a spreadsheet.
In plain terms, the questions you will be asked in an inspection are: who can see what, is the information encrypted, is access logged, can you delete a person's information when they ask, and where is the information stored in the first place.
And there is one more question that comes up almost every time: who else touches the information. When you use an external supplier — storage, backup, a mailing tool — the information passes through them, and the Regulations govern that too: reg 15 requires you to examine the security risks before entering the engagement, to set out expressly in the agreement which types of information are handed over, which uses are permitted and what happens to the information when the engagement ends, and to maintain oversight of the supplier. It is worth knowing in advance exactly what goes out and where to.
Why is this a software question and not a paperwork question?
Look again at the list of questions in the previous section. Not one of them is answered by a written procedure. They are all answered — or not answered — by the system you actually work in.
You can write a procedure saying that only the bookkeeper sees salary data. If the software cannot tell users apart, the procedure is paper. You can undertake to delete information on request — but if the data is scattered across an Excel sheet, a WhatsApp thread and a folder in the cloud, nobody can really delete it. That is exactly the gap between a system built around the way you work and a pile of tools that accumulated by accident.
At appotto, security is a default and not a paid extra: encryption, role-based permissions and backups go into the project from day one. Every privacy and data security issue goes through a proper legal review with the software house's legal counsel, so that the client is covered.
The sharpest example is the CRM system for lawyers. A partner at a large Ra'anana law firm, with dozens of lawyers, specified the system and set out its data security policy — full separation between matters, permissions per lawyer and per matter, and encryption. When attorney-client privilege is the bar, the rest of the requirements already sit below it.
Disclosure. This article is general information only, not legal advice, and nothing in it creates an attorney-client relationship. appotto is a software house, not a law firm. How the Law applies depends on the specific facts of each business — the type of information, its scope and the way it is processed — so before making decisions it is worth getting individual legal advice. The details in this article are correct as at the update date, and the list of sources is set out below so that you can check for yourself.
And if you are only at the stage of considering a system and trying to work out what it means for your budget, what makes up the cost of development is explained separately. And if you are not yet sure you need a system at all — start here.
Frequently asked questions
When did Amendment 13 to the Protection of Privacy Law take effect?
The Amendment passed the Knesset plenum on 5 August 2024 and took effect on 14 August 2025. From that date the Privacy Protection Authority has been exercising the supervision, administrative inquiry and financial sanction powers the Amendment gave it.
Does a small business have to register a database after Amendment 13?
In most cases, no. Under s.8A the registration duty applies to data brokers holding information on more than 10,000 people, and to public bodies. A small business that keeps a customer list for its own purposes usually does not have to register — but the data security obligations apply to it in full, registration or not.
Does a contact list count as a database?
Not necessarily. The Law excludes from the definition of a database a collection that holds only names, addresses and contact details for 100,000 people or fewer, and that does not in itself reveal any further personal information. But the exclusion applies only if the owner of the collection has no other collection with different details about the same people — so a business that also holds orders or invoices about those same customers usually does not benefit from it.
Who has to appoint a Privacy Protection Officer?
Section 17B1 lists four categories: public bodies (other than a security body), data brokers holding information on more than 10,000 people, bodies whose activities require regular and systematic monitoring of people on a significant scale, and bodies whose main activity is processing information of special sensitivity on a significant scale — including banks, insurers, general hospitals and health funds. A typical small business falls into none of them.
Can a lawyer or a therapist settle for the lighter security level?
No. Regulation 1 of the Data Security Regulations excludes from the eased track of a database managed by an individual any database that includes information in respect of which the database owner is subject to a duty of professional confidentiality under law or under principles of professional ethics. Even a sole lawyer with a small database is pushed out of the definition by the confidentiality duty that applies to them.
What does a small business actually need to do?
Write a database definitions document, map who is allowed to see what, make sure the information is encrypted and backed up, that access is logged, and that you can delete a person's information when they ask. Most of these items are settled by the software you work in, not by a written procedure.
Sources
- Primary source: The Protection of Privacy Law, 5741-1981 — consolidated text, Wikisource (Hebrew) — definition of “database”, ss.8A, 11, 13, 14, 15A, 17B1.
- Primary source: The Protection of Privacy (Data Security) Regulations, 5777-2017 — Wikisource (Hebrew) — regs 1, 2, 8, 15 and the First and Second Schedules.
- The Protection of Privacy Law, 5741-1981 — Nevo (Hebrew)
- The Protection of Privacy (Data Security) Regulations, 5777-2017 — Nevo (Hebrew)
- Israel Internet Association — the Knesset approved Amendment No. 13 to the Protection of Privacy Law, 5784-2024 (Hebrew; date of approval)
- The Privacy Protection Authority — Amendment 13 to the Protection of Privacy Law (Hebrew)
- The Israel Democracy Institute — Amendment 13 to the Protection of Privacy Law: its meaning, implications and shortcomings (Hebrew; background)
- S. Friedman, Abramzon & Co. — Amendment 13 to the Protection of Privacy Law takes effect (Hebrew; effective date)
- IAPP — Israel marks a new era in privacy law: Amendment 13 ushers in sweeping reform (background)
Does your system stand up to this?
Tell us what information you hold and how you work today. We will look at it with you, and you will get a fixed quote agreed up front. Initial consultation at no cost.
Send us an email