Privacy Compliance Update: Enforcement Is Picking Up

11 October, 2026

Written by : Miriam Friedmann

The Israeli Privacy Protection Authority (PPA) has signaled a new era of active enforcement, and organizations should take notice. In recent months, the PPA has imposed significant financial penalties under its expanded enforcement powers granted by Amendment 13 to the Privacy Protection Law. In July 2026, the PPA imposed a NIS 256,000 fine on Kupat Holim Meuhedet for failing to immediately report a serious data breach involving unauthorized access to medical records, the first financial penalty since Amendment 13 entered into force. The PPA made clear that the duty to report arises as soon as the organization becomes aware of a serious security incident; waiting to complete a full internal investigation before filing an initial report is not an excuse. In September 2026, the PPA imposed a NIS 64,000 fine on Beit Shemesh Municipality following an incident that exposed the personal and medical data of approximately 4,600 residents. Notably, the fine was not for the breach itself but for technical regulatory failures: the municipality failed to list a data processor in the Database Specification Document as required, and its information security procedures did not properly address obligations related to external service providers with access to the database. The takeaway is clear: the PPA is now treating these “administrative” requirements seriously, and proper internal documentation, processor designations and security procedures are no longer items you can let slide.

Separately, we are seeing a sharp increase in litigation and class action threats related to online tracking technologies, particularly cookies, tracking pixels and similar tools. Globally, over 1,000 lawsuits targeting cookie banner practices were filed in 2025, and the pace has only accelerated in 2026. In Israel, plaintiffs are increasingly filing class actions against companies that place cookies or other tracking technologies on users’ devices without obtaining valid prior consent. A key area of exposure involves third-party cookies and tracking pixels that load before the user has provided consent, as well as pixels embedded in marketing emails that track whether and when recipients open them. If your website or email campaigns use these tools without proper consent or notification mechanisms, you may be exposed to litigation.

What should you be doing? We recommend reviewing and updating: (1) your Database Specification Documents and processor designations, to make sure they accurately reflect all entities with access to your data; (2) your information security procedures, particularly provisions governing engagements with external service providers; (3) your data breach response protocols, to ensure immediate reporting to the PPA upon discovery of a serious incident; and (4) your website cookie banners and email tracking practices, to confirm that no third-party cookies, pixels, or tracking technologies fire before the user provides informed, active consent. The above actions could and should be performed in the context of a more general privacy compliance project.

Our Privacy and Data Protection team can help with compliance audits, updating your privacy and security documentation, reviewing your digital tracking practices, and advising on breach response obligations. Getting ahead of these issues is far less costly than responding to a PPA inquiry or a class action demand, so please don’t hesitate to reach out.

 


The above content is a summary provided for informational purposes only and does not constitute legal advice. It should not be relied upon without obtaining further professional legal counsel.

Want to know more?
Contact us

Shiri Menache

Head of Marketing and Business Development

Matan Bar-Nir

Press Officer, OH! PR