What the Privacy Protection Law says about fingerprinting
Israel's Privacy Protection Law 5741-1981 (PPL) was enacted in 1981 and has been amended multiple times. The most material modernisation is Amendment 13 (Hok Haganat HaPratiut Tikun 13), signed 7 August 2024 and entering into force 14 August 2025, with transitional provisions for certain compliance obligations extending to August 2026.
The PPL defines personal data broadly as information about an individual's personality, personal status, intimate affairs, health, financial situation, opinions, beliefs, and similar attributes. The Privacy Protection Authority (PPA), which was restructured and empowered under Amendment 13 from the former Israeli Law, Information and Technology Authority (ILITA), has confirmed in published guidance that online identifiers fall within this definition. A browser fingerprint composed of device characteristics such as canvas output, GPU renderer, audio context, installed fonts, and time zone is personal data under the PPL the moment it is used to recognise the same browser across sessions.
Section 7 of the PPL designates a subset of personal data as 'sensitive information', attracting heightened obligations. The enumerated categories include health, financial circumstances, opinions, beliefs, behaviour in a private domain, genetic data, and biometric data. A fingerprint hash is not itself biometric data, but a fingerprinting deployment that is used to infer medical conditions, political beliefs, or private behaviour crosses into the sensitive-information category, triggering the stricter regime.
Section 8 database registration: Israel's unique requirement
Israel is the only major Western privacy regime with a mandatory database registration requirement. Section 8 of the PPL requires controllers to register their databases with the PPA before processing begins, when any one of the following triggers applies: the database contains data on more than 10,000 individuals; the database contains sensitive information as defined in Section 7; the database is used for direct marketing purposes; or the database is controlled by certain entity types specified in the statute.
A fingerprinting deployment that tracks more than 10,000 Israeli individuals will almost always meet the first threshold on its own. A deployment that processes data from fewer individuals but uses fingerprinting to infer sensitive attributes (health, political opinion) triggers the sensitive-data threshold. A deployment used for direct-marketing personalisation triggers the direct-marketing threshold independently of user count.
Amendment 13 modernised the registration requirements and the registry's operational framework but did not remove the registration obligation. Non-registration is an independent violation, separate from any failure of consent or transparency. The PPA has treated non-registration as an aggravating factor in enforcement proceedings.
Consent requirements under Amendment 13
Amendment 13 aligned Israel's consent standard with the GDPR framework. Consent must be explicit, informed, and freely given. For a fingerprinting deployment, this means three operational consequences that mirror the GDPR pattern but now apply under Israeli law.
First, consent must be obtained before the fingerprint signal is collected. A mechanism that fires the fingerprinting script before the user actively agrees is non-compliant by construction. The PPA has signalled in published guidance that passive or pre-ticked consent mechanisms do not satisfy the amended standard.
Second, refusing consent must be as straightforward as granting it. Designs that bury a 'reject' option behind multiple navigation steps, or that make 'Accept' the dominant and prominent choice while hiding 'Decline', are inconsistent with the 'freely given' element. Third, consent must be specific. A single 'I agree to the terms' checkbox that covers fingerprinting alongside unrelated processing activities does not satisfy the 'informed' element when the user could not reasonably know that fingerprinting was one of the purposes.
Common fingerprinting purposes under Israeli PPL
| Purpose | Personal data under PPL? | Sensitive information? | Consent required? | Section 8 registration trigger? | Additional obligation |
|---|---|---|---|---|---|
| Anti-fraud at login or payment | Yes | No | Likely no, if scoped and disclosed | Yes, if more than 10,000 individuals | Privacy notice disclosure; LIA documentation recommended |
| Account-takeover detection | Yes | No | Likely no, if scoped | Yes, if more than 10,000 individuals | Short retention period; separate data flow |
| Bot mitigation on a public form | Yes | No | Usually no | Yes, if more than 10,000 individuals | Disclose in privacy notice |
| Direct-marketing personalisation | Yes | Potentially | Yes, explicit | Yes, direct-marketing threshold applies regardless of count | Section 30A opt-out right; Atrr Atzmi registry check |
| Behavioural advertising (cross-site) | Yes | Potentially | Yes, explicit | Yes | Granular purpose disclosure; transfer safeguards if India-hosted |
| Product analytics (on-site funnels) | Yes | No | Yes under Amendment 13 | Yes, if more than 10,000 individuals | Retention limits; privacy notice update |
| Fingerprinting to infer health or beliefs | Yes | Yes, Section 7 | Yes, explicit and specific | Yes, sensitive-data threshold | Heightened security obligations; DPO review if DPO is required |
| Session continuity within a single visit | Yes | No | May qualify as operationally necessary | Yes, if scale exceeds 10,000 | Purpose limitation documentation |
| KYC and financial-services device binding | Yes | Yes (financial data) | Consent or legal obligation | Yes, financial sensitive-data threshold | DPO involvement; breach notification plan |
Amendment 13: what changed and why it matters for fingerprinting
Amendment 13 is the most substantial overhaul of Israeli privacy law since 1981. The headline changes most relevant to fingerprinting deployments are as follows.
Fines increased dramatically. The maximum administrative penalty rose from NIS 26,000 to NIS 320,000 per breach. For breaches classified as 'serious', a multiplier applies; for breaches classified as 'very serious' (which includes breaches involving sensitive data, large-scale processing, or non-cooperation with the PPA) the effective ceiling can reach NIS 1.6M or more. Pre-Amendment-13 fine estimates are obsolete.
Breach notification is now mandatory. Controllers must notify the PPA within 30 days of discovering a serious breach. A fingerprinting deployment that suffers a data breach exposing fingerprint hashes at scale (a breach that exposes the fingerprinting database) is likely to qualify as a serious breach, triggering the notification obligation. Internal breach-response procedures need to account for the 30-day window.
DPO obligations were introduced for designated controllers. Amendment 13 requires certain categories of controller to appoint a Data Protection Officer. Whether a specific organisation falls within the designated categories depends on factors including scale of processing, sensitivity of data, and organisational type. Controllers using fingerprinting at significant scale should assess their DPO obligation as part of Amendment 13 compliance.
Data subject rights were modernised. The rights of access, rectification, and deletion (in specific circumstances) were aligned with the GDPR baseline. A controller running a fingerprinting deployment must be able to respond to a data subject access request that asks 'what data do you hold about me?' including fingerprint-derived identifiers, and must have a process for responding to deletion requests.
EU adequacy and cross-border transfer obligations
Israel has held an EU adequacy decision since 2011. The European Commission renewed the decision in 2024 following its review of the post-Amendment-13 legal framework. Israeli controllers can freely transfer personal data to and from EU/EEA member states without additional safeguards. For an Israeli publisher or SaaS that uses a fingerprinting SDK hosted in an EU data centre, the Israeli-to-EU data flow is covered by adequacy.
The reverse direction is also covered: EU controllers sending fingerprint data to an Israeli processor receive the benefit of the adequacy decision. This is a meaningful differentiator for Israeli data processors competing for EU business.
Transfers to non-adequate jurisdictions require a separate legal basis under Section 36 of the Privacy Protection Regulations (2001). India is not on Israel's adequacy list. A controller routing fingerprint data through an India-hosted processor must rely on contractual safeguards (typically standard contractual clauses or a binding data processing agreement with equivalent protections), explicit data subject consent, or a specific statutory exemption. This obligation applies to Benny the Doorman's infrastructure specifically, as Benny processes in Chennai, India.
Direct marketing: Section 30A and the Atrr Atzmi registry
Section 30A of the PPL gives individuals an explicit opt-out right from direct marketing. Israel operates a national do-not-marketing registry called Atrr Atzmi ('My List'). A fingerprinting deployment used to identify returning users for direct-marketing personalisation must check the Atrr Atzmi registry and honour opt-outs recorded there, in addition to meeting the database registration requirement and obtaining valid consent under Amendment 13.
The direct-marketing trigger for Section 8 registration is independent of individual count. Even a small deployment targeting only 500 individuals triggers the registration obligation if the purpose includes direct marketing. This is a common compliance gap for smaller e-commerce operators using fingerprinting purely for retargeting.
Enforcement context
PPA enforcement under the pre-Amendment-13 regime was limited by the modest fine ceiling of NIS 26,000 per breach. Several enforcement actions established the PPA's willingness to use its powers, including in technology and data-handling contexts, and are relevant background for understanding how the PPA approaches violations.
In 2020, the PPA (then operating as ILITA) took enforcement action against Boeing Israel in connection with a data breach affecting employees and job applicants. The enforcement highlighted the authority's focus on both the breach-response obligation and the adequacy of security measures for databases containing personal data, including data collected through online channels.
In 2023, the PPA issued enforcement findings against Shufersal, Israel's largest supermarket chain, in connection with customer data handling. The enforcement focused on data retention practices and the scope of data processing relative to disclosed purposes, a framework directly applicable to fingerprinting deployments where the retention period and purpose scope are not clearly bounded.
Since Amendment 13 entered into force in August 2025, the PPA has published a series of enforcement notices and compliance guidance documents indicating priority focus areas for the new regime. The authority has flagged consent mechanism design, breach notification readiness, and database registration completeness as the three areas where it expects to concentrate early enforcement efforts. Controllers with fingerprinting deployments that have not been updated to reflect Amendment 13 should treat these as the primary risk vectors.
Israel PPL compliance checklist for a fingerprinting deployment
- Assess whether Section 8 registration applies: does the deployment process data on more than 10,000 individuals, process sensitive data, or use fingerprinting for direct marketing? Register with the PPA before processing begins if any trigger applies.
- Implement explicit, informed, freely given consent under Amendment 13: gate the fingerprint collection behind an affirmative user action with a reject option that is as prominent as the accept option.
- Update the privacy notice to specifically disclose fingerprinting as a processing activity, the purposes for which it is used, retention periods, and the categories of data involved.
- Check the Atrr Atzmi do-not-marketing registry if fingerprinting is used for any direct-marketing purpose.
- Assess DPO obligation under Amendment 13 for the specific organisation type and scale of processing.
- Implement a breach-detection and notification procedure capable of meeting the 30-day notification window for serious breaches.
- For India-hosted processors (including Benny the Doorman), put Section 36-compliant contractual safeguards in place before routing fingerprint data through the processor.
- Document a Legitimate Interest Assessment if relying on that basis for anti-fraud fingerprinting, and maintain it as an internal record available to the PPA on request.
- Verify that data subject rights workflows can respond to access, rectification, and deletion requests that encompass fingerprint-derived identifiers.
How Benny the Doorman fits into an Israel PPL-aware deployment
Benny is a fingerprinting SDK and hosted API, not a consent management platform and not a database registration service. The Israel PPL compliance obligations described on this page sit with the controller deploying Benny, not with Benny as a processor. That said, the integration architecture requires specific attention to two Israel-specific requirements that differ from the GDPR or CCPA patterns.
First, the Section 36 transfer obligation. Benny's processing infrastructure is located in Chennai, India. India is not on Israel's adequacy list. Before an Israeli controller routes fingerprint data through Benny's API, that controller must put in place contractual safeguards that provide equivalent protections to those available under Israeli law. Benny's standard data processing agreement (DPA) is the contractual instrument for this purpose; Israeli controllers should review it specifically against the Section 36 requirements and, where necessary, supplement it with additional clauses.
Second, the Section 8 registration obligation. If the Benny deployment will process fingerprint data on more than 10,000 Israeli individuals, or if the purpose includes sensitive data processing or direct marketing, the controller must register the database with the PPA before going live. The registration record should describe the database, its controller, the categories of data, the processing purposes, and the recipients to whom data is disclosed, including processors such as Benny.
For the consent-gating integration pattern, Benny's fingerprint API call should be deferred behind the consent signal from the controller's consent management platform for the relevant purpose category. The fingerprint collection must not fire before the user has given affirmative consent, in line with Amendment 13's explicit-consent requirement.
Frequently asked questions
Is browser fingerprinting illegal under the Israeli Privacy Protection Law?
No. Fingerprinting is not banned under the PPL. It is regulated as personal data when the fingerprint can be used to identify or single out an individual, consistent with PPA guidance on online identifiers. Lawful use requires obtaining explicit, informed consent under Amendment 13, registering the database with the PPA if any Section 8 trigger applies, and complying with the full set of obligations under the amended law.
Do I need to register my fingerprinting database with the PPA under Section 8?
Yes, if any of the Section 8 triggers apply before processing begins. The triggers are: the database covers more than 10,000 individuals; the database contains or is used to derive sensitive information as defined in Section 7 of the PPL; the database is used for direct-marketing purposes; or the controller falls within a designated entity type. A fingerprinting deployment tracking Israeli users at meaningful scale will almost always meet at least the individual-count threshold. Non-registration is an independent violation and has been treated as an aggravating factor in PPA enforcement.
What did Amendment 13 change for fingerprinting compliance?
Amendment 13, which entered into force on 14 August 2025, made four material changes for fingerprinting deployments. First, it aligned consent requirements with GDPR: consent must now be explicit, informed, and freely given, replacing the more ambiguous pre-amendment standard. Second, it introduced mandatory breach notification within 30 days for serious breaches. Third, it imposed DPO obligations on designated controllers. Fourth, it raised the maximum administrative fine from NIS 26,000 to NIS 320,000 per breach, with multipliers for serious and very serious breaches that can push effective penalties to NIS 1.6M. Any deployment reviewed before August 2025 needs reassessment.
Does Israel have an EU adequacy decision, and what does it mean for fingerprinting?
Yes. Israel has held an EU adequacy decision since 2011, renewed in 2024 following the European Commission's assessment of the post-Amendment-13 legal framework. Israeli controllers can freely transfer personal data including fingerprint hashes to and from EU/EEA member states. EU controllers using Israeli processors receive the same benefit. The adequacy decision does not extend to transfers in the other direction to non-adequate countries such as India, which still require Section 36 safeguards.
Does Israel's privacy law apply if my servers are outside Israel?
Yes, in principle, if you are processing personal data about Israeli residents. The PPL applies to processing carried out by controllers operating in Israel and, under PPA guidance, to controllers outside Israel when the processing relates to Israeli residents. The practical enforcement posture is similar to the GDPR extra-territorial principle: fingerprinting Israeli website visitors from an overseas server does not eliminate PPL obligations.
Do I need consent for anti-fraud fingerprinting under Israeli PPL?
Not necessarily. Narrowly scoped anti-fraud and security-of-service fingerprinting may be supportable without explicit consent if the controller can document a legitimate operational necessity, discloses the processing in a privacy notice, and limits retention to the fraud-detection lifecycle. However, unlike GDPR's explicit 'strictly necessary' carve-out in ePrivacy Article 5(3), the PPL does not codify the same express exception. The PPA's guidance should be reviewed for the current position, and a documented legitimate-interest-style assessment is strongly recommended to support the processing.
What are the fines for non-compliant fingerprinting under the PPL after Amendment 13?
Amendment 13 raised the maximum administrative fine to NIS 320,000 per breach, up from NIS 26,000 under the pre-amendment law. The PPA can apply multipliers for breaches classified as 'serious' (those involving sensitive data, large-scale processing, or repeat violations) or 'very serious' (those involving non-cooperation, deliberate concealment, or material harm to data subjects), which can push the effective penalty to NIS 1.6M or more for a single breach. Multiple breaches across a deployment can compound these figures significantly.
What Section 36 safeguards are required when using an India-hosted fingerprinting processor like Benny?
Section 36 of the Privacy Protection Regulations requires a legal basis for transferring personal data to a non-adequate country. India is not on Israel's adequacy list. The primary mechanism available is contractual safeguards: a data processing agreement with the processor that commits the processor to equivalent protections, including data subject rights, security standards, breach notification, and purpose limitation. Benny provides a standard DPA that Israeli controllers should review against Section 36 requirements before activating the service for Israeli users.
Tooling
Benny the Doorman is built for this compliance posture.
Free, cookieless fingerprinting that defers to your consent management platform, runs on Indian infrastructure, and ships with a DPA addendum sized for the jurisdiction above.
Last reviewed 2026-06-06

