Cyber Law at Israel
Israel has implemented a comprehensive legal framework to address cybersecurity and data protection, aligning closely with international standards such as the European Union's General Data Protection Regulation (GDPR). Here's an overview of the key legislative developments:
🛡️ Cybersecurity and Data Protection Laws
1. Privacy Protection Law (PPL) – Amendment No. 13 (2024)
Enacted on August 5, 2024, this amendment significantly overhauls Israel's privacy legislation, introducing several key changes
Expanded Definitions:The term "Personal Data" now encompasses any data related to an identified or identifiable individual. "Highly Sensitive Data" includes categories such as biometric data, genetic information, location data, criminal records, and more
Mandatory Data Protection Officer (DPO):Entities processing sensitive data on a large scale, including banks, hospitals, and telecom providers, are required to appoint a DPO
Enhanced Enforcement Powers:The Privacy Protection Authority (PPA) has been granted expanded authority to impose fines, issue administrative orders, and conduct investigations. Fines can reach up to 5% of a business's annual turnover, with caps for small and micro-businesses
Data Breach Notification:Organizations must notify the PPA and affected individuals promptly in the event of a data breach that poses a significant risk to privacy or security
Transition Period:The amendments will come into effect on August 6, 2025, providing organizations time to comply
2. Computer Law (5745-1984)
This law criminalizes various cyber offenses, including
Unauthorized Access:Gaining access to computer systems without permission
Data Interference:Altering or deleting data without authorization
Fraudulent Activities:Using computers to commit fraud or other offenses
Distribution of Malware:Creating or disseminating malicious software
🏛️ Regulatory Authorities
Privacy Protection Authority (PPA) Oversees compliance with data protection laws, conducts investigations, and enforces regulation.
National Cyber Directorate (NCD) Responsible for national cybersecurity strategy and coordinatio.
⚖️ Enforcement and Compliance
Fines and Penalties Organizations can face substantial fines for non-compliance, with amounts varying based on the severity of the violation and the size of the organization
Civil Suits Individuals whose privacy rights have been violated may file civil suits for compensation, with potential damages up to 50,000 NIS without proof of actual harm
0 comments