DATABASE REGISTRATION · PRIVACY AND DATA SECURITY
Database registration in Israel — when a business must, and what happens if not?
Amendment 13 turned database registration from a near-universal duty into a duty of the few. But that narrowing bred a dangerous mistake: “no registration required — so no obligations at all”. It is the other way round: the duties that remain apply to every database, registered or not, and most of them are decided in the software you work in.
What is the Israeli database registry, and who runs it?
The Protection of Privacy Law, 5741-1981 establishes a registry of databases, kept by the head of the Privacy Protection Authority (section 12 of the law). For decades, registration was the entry gate for almost every business database: a broad duty, widely known and widely ignored. Amendment 13, in force since 14 August 2025, turned it into a focused duty that applies to few.
Before asking whether you must register, it is worth asking whether you have a “database” at all. Section 3 of the law defines a database as a collection of personal data processed by digital means, and carves out two cases: a collection for personal, non-business use; and a collection holding only names, addresses and contact details on 100,000 people or fewer — provided its owner, or a corporation under the owner's control, holds no other collection with further details on the same people.
Most businesses cross that threshold without noticing: the moment order history, invoices or notes on customers sit alongside the contact list, the carve-out no longer applies, and there is a database. We covered the definition in our article on Amendment 13 to the Protection of Privacy Law.
Who must register a database after Amendment 13?
Section 8A(a) of the law, as amended, sets only two cases in which a database must be registered. The first: a database whose main purpose is collecting personal data in order to pass it to others as a business or for payment, including direct-mail services, holding personal data on more than 10,000 people — in other words, data traders. The second: a database whose controller is a public body — government ministries and state institutions, local authorities and bodies performing public functions under law — unless the database holds data on the body's own employees only.
The test is what the database is for, not how big it is. A shop running a customer club, a clinic managing patient files or a firm managing client matters collect data for their own purposes, not to sell it on. They are not data traders, and so they do not have to register — however large the database grows.
Two refinements complete the picture. The head of the Authority may exempt even a registrable database from registration, if satisfied that registration is not needed (section 8A(a)(3)); and the registration duty does not apply at all to a database holding only data lawfully published to the public (section 8A(c)).
Does mailing your customers require registering a database?
Here sits a common confusion worth untangling. The law distinguishes between direct mail — approaching a person based on data in a database, which every business does with its own customers — and direct-mail services: passing lists and data to others, as a service. Mailing your own customers does not in itself trigger a registration duty.
By contrast, whoever provides direct-mail services to others may not process data in such a database unless it is registered, with direct-mail services among its registered purposes (section 17D). And anyone trading in lists holding data on more than 10,000 people falls under the general registration duty of section 8A anyway. Even those exempt from registration remain bound by the direct-mail rules themselves — above all, everyone's right to demand that their data be deleted from a database used for direct mail (section 17F).
How is a database registered, and what happens after filing?
Whoever does have to register files an application with the head of the Privacy Protection Authority (section 9 of the law). The application states:
- the identity of the database's controller, an address in Israel and contact details, and the identity of the privacy protection officer;
- the type of service a holder provides to the controller, where the database is held by an external party;
- the purposes for which the database was set up and for which the data is intended;
- the types of data the database will hold;
- details of data transfers out of the country and of regular receipt of data from a public body.
The head of the Authority registers the database within 60 days of filing, unless there are reasonable grounds to believe the database serves unlawful activity or that its data was collected unlawfully (section 10(a)(1)). If the period passes with no notice of refusal or suspension, the database is treated as registered, and work may proceed (section 8A(a)(2)). If the head of the Authority notifies a refusal or suspension, processing data in the database is prohibited unless a court rules otherwise (section 10(b2)).
What happens if a registrable database is not registered?
The prohibition itself is sharp: the controller of a registrable database may not process personal data in it, nor allow another to process data for it, as long as the database is unregistered (section 8A(a)(2)). “Processing” under this law is almost everything — receiving, collecting, storing, viewing, disclosing. A business that must register and has not is in continuous breach, not a one-off technical slip.
On top of the prohibition sits the enforcement machinery Amendment 13 handed the Authority: the head of the Authority may impose a financial sanction for processing data in a registrable, unregistered database, for filing incorrect details in a registration application and for failing to report changes to the registered details. Failing to file the notice a large sensitive database owes the Authority is listed there too. The amounts are fixed by the law, and for very large databases they double.
There is direct civil exposure as well: a person whose data sits in a registrable, unregistered database, who demanded that the controller register it and was not answered within 90 days, may sue for exemplary damages that do not depend on proof of harm (section 15A(a)(1)). And for those who did register, the discipline continues: every change to the registered details must be reported (section 9(d)), and the head of the Authority may suspend or cancel the registration of a database that violates the law (section 10(f)).
Why is exemption from registration not exemption from the law?
And here is the trap this article was written for. Many businesses heard that “the registration duty was abolished” and concluded that privacy law no longer concerns them. But registration was always just procedure — the substantive duties never depended on it. Amendment 13 sharpened exactly that: less paperwork, more enforcement of what actually happens to the data.
| The duty | Where in the law | Does it depend on registration? |
|---|---|---|
| Registration in the registry | s. 8A(a) | Applies only to data traders and public bodies |
| Notifying the Authority of a large sensitive database | s. 8A(b) | No — it applies precisely to databases not subject to registration |
| Data security | s. 17 and the Data Security Regulations, 5777-2017 | No — applies to every database |
| Privacy protection officer | s. 17B1 | No — set by the nature and scale of the activity |
| Notice when collecting data | s. 11 | No — applies to every request for data for a database |
| Access, correction and deletion | ss. 13–14 | No — everyone's right against every database |
The central duty is data security: the database's controller and its holder are each responsible for securing the data in it (section 17(a)), and the Protection of Privacy Regulations (Data Security), 5777-2017 spell out what that means in practice — a database definitions document, access permission management, and security tiers set by the type and scale of the data. None of it depends on registration. Alongside it: the duty to notify the Authority once a database holds specially sensitive data on more than 100,000 people (section 8A(b)), and the duty to appoint a privacy protection officer for whoever falls within the categories of section 17B1.
Facing all of these stand people's rights: to know, when their data is collected, who is collecting it, for what purpose and what their rights are (section 11); to access the data held on them (section 13); and to demand its correction or deletion (section 14). An unlawful refusal to allow access, or an agreed correction never carried out, exposes the business to exemplary damages under section 15A — regardless of the registration question.
Notice what the whole list has in common: none of these duties is fulfilled by a form. Who sees which data, whether everything held on a person can be located and deleted, whether access is logged — all of that is decided by how the system is built. A system managing sensitive data — a law firm's client file is the clearest example — needs permissions, encryption and logging by default, and a system built around how you actually work answers a deletion demand with a click, instead of a manual hunt through scattered files.
How we work with this. At appotto, the privacy questions are examined at the specification stage, not after going live: which types of data the system will hold, who accesses them, how the access and deletion rights are implemented. Every legal question is reviewed by the software house's legal counsel, so the system you receive meets the requirements from day one.
If you are not sure where your business stands — whether you have a database at all, whether you are near one of the thresholds, and how your current system measures up — send us a short message about what you manage and where.
Frequently asked questions
Who must register a database after Amendment 13?
Under section 8A of the Protection of Privacy Law, the registration duty applies in only two cases: a database whose main purpose is collecting personal data in order to pass it to others as a business or for payment, holding data on more than 10,000 people; and a database controlled by a public body, unless it holds data on the body's own employees only. Most private businesses no longer have to register.
What happens if a registrable database is not registered?
Processing personal data in a registrable database that has not been registered is prohibited. The head of the Privacy Protection Authority may impose a financial sanction for the violation, and a person whose data sits in the database who demanded its registration — and was not answered within 90 days — may sue for exemplary damages that do not depend on proof of harm, under section 15A.
Is a business exempt from registration also exempt from the other duties?
No. The data security duty under section 17 and the Data Security Regulations applies to every database, registered or not. So do the duty to inform people when their data is collected, everyone's rights of access and correction, and the duty to notify the Authority once a database holds specially sensitive data on more than 100,000 people.
How is a database registered with the Privacy Protection Authority?
An application is filed with the head of the Authority, stating the identity of the database's controller, the database's purposes, the types of data it will hold, and details of transfers abroad and of regular receipt of data from public bodies. The head of the Authority registers the database within 60 days, unless there are reasonable grounds to believe it serves unlawful activity. If the period passes with no refusal or suspension, the database is treated as registered.
Does mailing your own customers require registering a database?
Mailing your own customers does not in itself trigger registration. The law requires registration for direct-mail services — passing lists and data to others: such a database must be registered, with direct-mail services among its registered purposes, under section 17D. Anyone trading in lists holding data on more than 10,000 people also falls under the general registration duty.
Sources
- Primary source: Protection of Privacy Law, 5741-1981 — consolidated text, Wikisource (Hebrew) — definitions in s. 3, ss. 8A, 9, 10, 12, 15A, 17, 17B1, 17D, 17F and 23.
- Primary source: Protection of Privacy Regulations (Data Security), 5777-2017 — Wikisource (Hebrew) — the duties that do not depend on registration.
- Privacy Protection Authority — Amendment 13 to the Protection of Privacy Law
- Protection of Privacy Law, 5741-1981 — Nevo (Hebrew)
Not sure which duties apply to the data you hold?
Tell us what data your business manages and in which tools. We will go over it with you — including a review by the software house's legal counsel — and you will get a clear picture and a price fixed in advance. First consultation free.
Email us