Amendment 13 to the Privacy Protection Law – The “Day After”
Now that Amendment 13 has entered into force, shifting the compliance landscape and redefining organizational risk, the focus must move to “the day after”: actual enforcement and the evolving legal exposure.
This update outlines the current enforcement environment, including the Regulator’s expanding toolkit, emerging trends in class action litigation, and practical steps to mitigate significant legal risks.
The Regulator: From Theory to Enforcement
Amendment 13 to the Protection of Privacy Law (the “Law”) has effectively recalibrated the cost of privacy compliance. The Privacy Protection Authority (the “PPA”) is now equipped with broad administrative enforcement powers, including the authority to conduct extensive audits, issue stop-processing orders, demand data deletion, and impose significant financial sanctions.
We are already seeing these powers in action. Earlier this month, the PPA announced a broad sectoral audit targeting local authorities, e-commerce platforms, popular mobile apps, genetic testing institutes, and after-school care programs. This initiative will result in public reports detailing the PPA’s findings.
Data from recent years highlights a clear escalation in enforcement activity. In 2024, the PPA determined only three violations of the Law, with no administrative fines imposed. In contrast, 2025 saw 33 enforcement actions, with fines imposed in nearly half of those cases (ranging from NIS 5,000 to NIS 75,000). While most violations concerned information security, there is a notable rise in citations for other breaches, such as failure to comply with notification duties (Section 11). Given the PPA’s new statutory powers, we anticipate this upward trajectory will accelerate significantly.
Class Actions: The “Cookie” Risk
While privacy violations are not yet explicitly listed as a statutory ground for class action certification under the Class Actions Law, the “Amendment 13 effect” is clearly spilling over into civil litigation.
We are witnessing a surge in motions for class action certification where the core claim is the violation of privacy through cookies and tracking pixels on websites and email communications. Approximately 20 such motions were filed in the last year alone.
The Technical & Legal Challenge While cookies are standard for functionality (e.g., language preferences) and analytics, the legal risk arises primarily from third-party cookies (e.g., Meta, Google, TikTok). These tools transfer user data to third parties to build “profiles” for targeted advertising unrelated to the specific website visited.
The legal challenge lies in timing and consent. On many websites, tracking tools fire immediately upon a user’s entry—collecting and transferring data before the user has a chance to refuse, or even realize they are being tracked. This practice makes it difficult to argue that the website owner met their duty of notification or obtained valid informed consent.
Consequently, website owners who fail to regulate cookie usage, or who rely on non-compliant cookie banners, are becoming easy targets for litigation. This area is rapidly becoming a “hot zone” for plaintiffs, similar to the wave of internet accessibility lawsuits seen in recent years.
The Solution: Consent Banners
The most effective way to mitigate this exposure is to implement a robust Cookie Banner. However, it is crucial to distinguish between two types:
Recommendation
While Israeli case law and the PPA’s position have not yet established a definitive, sweeping rule mandating active consent for all cookies, the regulatory wind is blowing firmly toward stricter standards.
Our recommendation: Adopt an Opt-In Consent Banner for all non-essential cookies. This is particularly important if the cookies involve third-party data sharing, allow for user identification, or involve processing data for purposes other than the original intent. Relying on implied consent or passive notification is increasingly risky, especially when data collection begins the moment a user lands on your homepage.
This update provides a general summary of the issues and does not constitute legal advice. Please contact us if you require specific guidance regarding your digital assets.