Israel Israel Privacy Protection Law amendment

Israel's First Consumer Privacy Fine Under Amendment 13 Is Small on Purpose

A NIS 12,000 fine against a karting company shows Israel's privacy regulator calibrating penalties to severity, not maximalism.

Israel's Privacy Fines Under Amendment 13 People of Internet Research · Israel NIS 12,000 Karting company fine Reduced 40% from an initial NIS 20… NIS 20,000 Initial proposed fine Cut for a clean compliance record … NIS 256,000 Meuhedet HMO breach fine First monetary sanction under Amen… Aug 14, 2025 Amendment 13 effective date Expanded the PPA's fining, cease-a… peopleofinternet.com
Israel's Privacy Fines Under Amendment… People of Internet Research · Israel NIS 12,000 Karting company fine NIS 20,000 Initial proposed fine NIS 256,000 Meuhedet HMO breach fine Aug 14, 2025 Amendment 13 effective date peopleofinternet.com

Key Takeaways

A modest fine with an outsized signal

On August 5, 2026, Israel's Privacy Protection Authority (PPA) imposed a NIS 12,000 (~$3,200) administrative fine on A.D Karting Crossroads (2014) Ltd., a local karting operator, for collecting customers' ID numbers, birthdates, phone numbers, city of residence, and their children's personal details through an online registration form without providing the privacy notice required under Section 11 of the Protection of Privacy Law, 5741-1981 (statute text, Knesset). The case began with a customer complaint and ended with one of the PPA's first consumer-facing fines issued under the enhanced enforcement powers created by Amendment 13, which took effect August 14, 2025 (IAPP).

The number itself is unremarkable. What matters is the shape of the decision, laid out in the PPA's own announcement (gov.il): the authority initially proposed a NIS 20,000 fine, then cut it by 40% because the company had no prior violations and fixed its notice practices once the investigation began. The PPA's enforcement director, Adi Menachem Baer, rejected the company's framing of the lapse as a "trivial" formality, calling the duty to notify "a cornerstone principle in privacy law, not merely a technical or formal requirement."

Steelmanning the strict line

The strongest case for treating this as more than paperwork is the children's-data angle. A parent registering a minor for a recreational activity has no realistic way to negotiate terms with the vendor — they hand over a child's date of birth and identifying details because the alternative is being turned away at the gate. Section 11 exists precisely so that disclosure isn't optional window dressing: it requires operators to state whether providing the data is legally mandatory, what it will be used for, who might receive it, and how a customer can access or correct it. Regulators worldwide have converged on the view that this kind of information asymmetry, especially involving children, is where notice-and-consent regimes earn their keep. The PPA's insistence that a small business can't wave away that obligation as immaterial is defensible on its own terms.

Proportionality as the actual story

Where the case becomes genuinely useful — and where People of Internet's editorial instinct sees the more interesting development — is in how the PPA chose to wield its new, much larger stick. Amendment 13 gave the authority the power to levy fines running into the millions of shekels for serious or large-scale violations (IAPP). Just weeks earlier, on July 21, 2026, the PPA used exactly that firepower against Meuhedet, one of Israel's major health insurers, fining it NIS 256,000 for failing to promptly report that a system flaw had let members view relatives' sensitive medical records — a genuine security failure at a large data controller (Law.co.il).

Placed side by side, the two decisions read as a calibrated enforcement ladder rather than a blunt instrument: a quarter-million-shekel penalty for a major insurer's breach-reporting failure, a five-figure penalty — discounted for a clean record and quick remediation — against a local recreational business that skipped a notice paragraph. That is precisely the outcome a pro-innovation, evidence-based regulatory posture should want. Overzealous first-strike maximalism against small operators does nothing for data subjects and everything to chill the thousands of local Israeli businesses — sports clubs, summer camps, tutoring services — that now fall under a law built with far larger controllers in mind. A regulator that reserves its heaviest penalties for genuine security failures while nudging small businesses toward compliance through modest, negotiable fines is building the kind of predictable enforcement track record that lets businesses actually plan around the rules, rather than fear them.

The risk still on the table

That said, proportionality in this one case is not a guarantee it holds going forward. Amendment 13 also stripped away the old two-year limitation period for private lawsuits and opened the door to statutory compensation claims without proof of damage — meaning a karting rink or a youth soccer league that gets this wrong twice, or draws a class claim rather than a regulator's discretion, faces a materially different calculus than a discretionary NIS 12,000 administrative fine. The PPA has so far paired expanded powers with restraint. The test of Amendment 13's design is whether that restraint survives contact with a caseload of thousands of small operators who, unlike A.D Karting, don't fix the problem the moment a regulator calls.

For now, the PPA has given Israeli small businesses a cheap and clear lesson: publish the notice, name the purpose, say who gets the data. It's a low bar, and the fine for missing it was set low enough to make compliance the obviously rational choice rather than a fight worth having.

Sources & Citations

  1. ICE: PPA fines A.D Karting NIS 12,000
  2. Protection of Privacy Law, 5741-1981 (consolidated text)
  3. IAPP: Israel's Amendment 13 ushers in sweeping reform
  4. Pearl Cohen: PPA's first-of-its-kind Amendment 13 administrative fine
  5. Law.co.il: Meuhedet fined NIS 256,000 over breach reporting