Israel - Algorithmic Processing Guidance

Privacy Protection Authority opinion / guidance on algorithmic processing and notification obligations (automated decision‑making guidance)

גילוי דעת של רשות הגנת הפרטיות בנושא עיבוד אלגוריתמי וחובות הודעה (הנחיות קבלת החלטות אוטומטיות)

Israel

RAI-IL-NA-PPAOGXX-2022
Effective: July 31, 2022
In Force(In Force)
GuidelineData Protection and PrivacyTransparency and DisclosureAccountability and Documentation
Export PDF

Data controllers in Israel using automated processing must provide enhanced privacy notices under 2022 guidance issued by the Privacy Protection Authority under Section 11 of the Protection of Privacy Law. The instrument remains in force, effective 2022-07-31, guiding entities to explain decision logic and conduct privacy impact assessments.

Summary

Background and purpose: On 31 July 2022 the Privacy Protection Authority (PPA) published a formal opinion (giluya da'at / position paper) regarding the scope and content of the statutory notification duty under section 11 of the Protection of Privacy Law (Israel, 1981). The opinion clarifies the PPA's interpretation of controllers' duties to notify data subjects at the point of collection and provides specific guidance on the additional transparency and disclosure expectations that apply when personal data is collected or used in algorithmic and automated decision‑making systems. Scope: The opinion applies to any collection or use of personal data arising from a solicitation to a person (verbal, written, electronic or automated), whether the legal basis is the data subject's consent or another statutory basis. It does not concern collection from public sources where section 11 is inapplicable. Core principles: The PPA reiterates established privacy principles — purpose limitation, proportionality, data minimisation and informed consent — and stresses that these basic principles must be reinforced in contexts involving complex algorithmic processing. The paper links the concept of "informed consent" to the adequacy of notice: consent is only meaningful if the notification provided at collection is sufficiently specific and understandable. Algorithmic processing and automated decision‑making: The PPA identifies several privacy risks specific to algorithmic and AI systems: opacity of model logic, dynamic change of decision criteria, use of diverse data sources and secondary inferences, and potential for significant impacts on individuals (for example in credit, insurance, employment or access to services). Accordingly, controllers that collect or use personal data for such systems are expected to provide enhanced notice elements at collection, including (where feasible and lawful) an explanation of the system's purpose, categories of data used (and sources), the fact the processing is automated, the significance and potential consequences of automated decisions and whether human review is available. Contextual and adaptive disclosure: The opinion emphasizes a contextual approach — the level of disclosure and the form of notice must be adapted to the audience, the sensitivity of the data, and the likelihood and gravity of impacts on the data subject. For vulnerable or specific populations (children, certain consumer cohorts, employees), the PPA recommends simpler language, examples, and tailored formats. Practical measures: The PPA encourages controllers to adopt practical measures including privacy‑friendly user interfaces, layered notices, visual summaries, and pointers to more technical documentation. It also recommends that controllers prepare internal materials documenting the logic and data sources of automated systems to allow regulators to assess compliance while balancing trade secrets. Privacy impact assessments and documentation: The PPA explicitly recommends performing Privacy Impact Assessments (PIAs/DPIAs) for algorithmic systems and keeping up‑to‑date documentation (records of processing activities, decision logic descriptions, training data characteristics, and test/validation results). Enforcement position: The paper is a regulatory position / interpretation (giluya da'at) — non‑binding statutory guidance intended to inform enforcement and compliance assessments by the PPA under the Protection of Privacy Law and existing data security regulations. The PPA notes that a failure to provide sufficient notice, or to explain material automated decision‑making that affects individuals, may be considered a privacy violation and may lead to regulatory action under the prevailing enforcement framework. Relationship to later developments: The 2022 opinion has been referenced in subsequent PPA work on AI and in sectoral guidance; it forms part of an evolving regulatory architecture including later PPA draft guidance on AI (2025) and legislative reforms to the Protection of Privacy Law. Practical takeaway: Organisations that collect personal data — especially those using automated or algorithmic decision‑making — should review and, where necessary, strengthen their collection notices, consent processes and documentation; conduct PIAs for systems with potential high impacts; provide accessible explanations of automated processes to affected individuals; and maintain internal records that allow meaningful oversight by the PPA and other regulators.

Full article

Read full text ↗

Overview

The Privacy Protection Authority (PPA) published a formal position paper on 31 July 2022 setting out the scope and content of the statutory notification duty when personal data is collected or used, and placing special emphasis on processing that involves algorithmic or automated decision‑making. The opinion links the statutory notice obligation (section 11 of the Protection of Privacy Law) with the statutory requirement for "informed" consent and clarifies that when data are collected for, or used by, systems that incorporate automated decision‑making (including AI techniques), controllers must provide enhanced, context‑sensitive disclosure in order for consent and notice to be meaningful. The document is available from the PPA and is summarised on the PPA's publications page (Privacy Protection Authority – Ministry of Justice) and analysed in contemporary legal summaries. The guidance is procedural and interpretive: it explains enforcement expectations under the existing Protection of Privacy Law rather than creating new legislation.

Definitions

Key definitions used or clarified by the opinion include: "notification duty" (the point‑of‑collection obligation to inform a person of the purpose, recipients and legal basis for requested data), "informed consent" (consent given with a reasonable understanding of purpose and consequences), "automated decision‑making" (use of algorithmic or AI systems to reach decisions without meaningful human intervention), and "algorithmic processing" (use of computational models that may adapt or change decision criteria based on data or prior outputs). The opinion stresses that in the PPA's view, where algorithmic systems affect individuals' rights or significant interests, notification should include information about the automated nature of processing, categories and sources of data used, and the potential significance of decisions derived from the system.

Governance and Institutional Framework

The PPA positions this opinion within the existing Israeli privacy framework overseen by the Ministry of Justice's Privacy Protection Authority (PPA). The opinion is intended to guide the PPA's supervisory and enforcement activities under the Protection of Privacy Law and the Data Security Regulations (see related material on PPA and government pages). The document recommends organisational governance measures: board‑level accountability for privacy risks arising from AI, appointment and involvement of privacy and security officers in the design and deployment of algorithmic systems, and documented internal roles for technical, legal and compliance stakeholders. It also recommends clear contractual allocation of responsibilities with processors and outsourced service providers, including clauses requiring adequate notice information and support for subject requests. The PPA signals that compliance with the opinion will be an enforcement consideration when the authority inspects databases or investigates complaints.

Key Focus Areas

The opinion focuses on a number of central issues for algorithmic processing and notification obligations: (1) Adequacy of notice: notice must be meaningful, timely, and adapted to the audience; layered notices and concise summaries are encouraged. (2) Algorithmic transparency: controllers should explain, to the extent reasonably possible, how automated systems make decisions, the categories of data used, and the possible consequences for individuals. (3) Consent and its limits: consent must be informed and voluntary; in contexts of power imbalance (employment, essential services) implied or coerced consent is insufficient. (4) Data minimisation and purpose limitation: controllers must minimise the collection of data for algorithmic use and avoid secondary use that exceeds the notified purposes. (5) DPIA/PIA use: the PPA recommends DPIAs for systems that create elevated privacy risk and maintaining records of mitigation measures. (6) Human oversight & contestability: where automated decisions have material effects, individuals should be informed about the opportunity for human review or appeal. (7) Special categories and sensitive uses: heightened notice, additional safeguards, and in many cases avoidance of sensitive inference or profiling without strong safeguards. (8) Documentation and auditability: controllers should retain internal documentation (model descriptions, training data summaries, evaluation and test results) to enable supervisory review while balancing legitimate trade secret considerations. Several of these themes are described in practical examples in the opinion and in the supporting commentary published by the PPA and independent advisors (ICLG (analysis)).

Implementation Framework

The opinion sets out a flexible implementation framework that is risk‑based and context sensitive. At collection the controller should provide: concise, intelligible notice at the point of collection; a layered approach linking to more detailed explanations and technical documentation; and clear statements when data will be processed by automated systems and when decisions may follow with material consequences. For high‑impact systems the PPA recommends performing a DPIA before system deployment, publishing a non‑technical summary of the DPIA where feasible, and ensuring technical controls such as differential access, logging, and explainability outputs for affected individuals. Contracts with processors must include obligations to support notice, record‑keeping and incident reporting. The opinion also encourages sectoral regulators and professional bodies to develop sector specific templates and examples to support consistent implementation.

Monitoring and Evaluation

The PPA advises continuous monitoring of algorithmic systems: periodic re‑assessment of privacy impact, documented testing for bias and accuracy, monitoring for model drift and change of decision criteria, and logging of automated decisions for auditability. The opinion recommends that controllers maintain a cadence of evaluation aligned with system risk (for example, more frequent review for systems affecting health, finance, employment or rights). The PPA notes that where monitoring reveals material privacy risks not disclosed at collection, controllers should update notices and, where necessary, re‑obtain valid informed consent or otherwise remediate the processing to align with legal bases.

Penalties, Liability, and Appeals

The opinion itself is a regulatory interpretation and does not set new penalties; however, the PPA states that failure to meet the notification duty or to provide adequate disclosure regarding automated decision‑making will be a material factor in enforcement actions under the Protection of Privacy Law and applicable Data Security Regulations. Remedies available under Israeli law include administrative sanctions, enforcement orders, corrective directions, and (where applicable) criminal sanctions for severe wilful breaches. The PPA indicates its intention to consider the guidance when exercising enforcement discretion and to take into account efforts to comply, remediate and cooperate when assessing sanctions. Affected individuals retain existing legal remedies (complaints to the PPA, civil claims, and judicial review) where rights have been impaired.

Relationship to Other Instruments

The PPA locates the opinion among other contemporary materials: it references the Protection of Privacy Law (1981), the Data Security Regulations, prior PPA guidance (on security incidents and DPIAs), and later PPA work on consent and AI. The opinion anticipates coordination with sectoral regulators (banks, capital markets, health) and references comparative regulatory approaches in the EU (GDPR) and other jurisdictions in which automated decision‑making rules or guidance exist. The opinion should be read alongside later PPA publications (including draft guidance on AI, April 2025) and sectoral circulars.

International Alignment

Although rooted in Israeli statutory law, the opinion explicitly aligns to international standards and practices: it draws on privacy‑by‑design principles, DPIA practice common under the EU GDPR, and international recommendations on algorithmic transparency. The PPA highlights that algorithmic transparency obligations should be balanced against legitimate commercial confidentiality and IP interests and recommends mechanisms to allow supervisory review without public disclosure of trade secrets. The PPA also notes that controllers engaged in cross‑border processing must consider both Israeli notification duties and international obligations (including adequacy and transfer safeguards) when explaining algorithmic processing to data subjects and regulators.

Implementation Timeline

MilestoneDate
PPA opinion published2022-07-31
Organisations advised to review policies and noticesFrom 2022-08-01 (ongoing)
Recommended DPIA for high‑risk systemsPrior to deployment / continuous review
Ongoing supervisory assessment and references in later PPA work2022–present (referenced in subsequent guidance)

Sources and References

SourceType
Privacy Protection Authority – Department page (Ministry of Justice)Primary Source (PPA Official)
Agmon & Co. summary and commentary – July/August 2022Practice Note / Analysis
ICLG: Data Protection Laws and Regulations – Israel (analysis referencing the PPA opinion)Secondary Analysis

Requirements for a company

What an organisation has to do under Israel - Algorithmic Processing Guidance, at a glance. Not legal advice — the table below gives the provision and deadline for each item.

Must do

0

Nothing in this category.

Must not do

0

Nothing in this category.

Should do

8
  • Provide concise, context-sensitive notice at the point of data collection when using automated decision-making systems.Data controllers using automated decision-making or AI systems
  • Inform individuals about available opportunities for human review or appeal when automated decisions produce material effects.Data controllers using automated decision-making with material effects
  • Perform a Data Protection Impact Assessment before deploying high-risk or high-impact algorithmic processing systems.Data controllers deploying high-risk algorithmic systems
  • Minimize the collection of personal data for algorithmic use and restrict processing strictly to notified purposes.Data controllers using personal data in algorithmic processing
  • Establish board-level accountability for privacy risks and assign clear internal roles for legal, technical, and compliance oversight.Data controllers deploying AI and algorithmic decision systems
  • Include contractual clauses requiring data processors to assist with notice obligations, record-keeping, and subject request handling.Data controllers contracting with third-party processors
  • +2 more in the table below

Should not do

2
  • Do not rely on implied or coerced consent for algorithmic processing in situations involving significant power imbalances.Data controllers operating in power imbalance contexts
  • Do not perform sensitive inferences or profiling without implementing heightened privacy safeguards.Data controllers profiling or handling sensitive categories of data

Who must do what

The obligations under Israel - Algorithmic Processing Guidance, most serious first. Not legal advice — verify against the official text before relying on it.

#WhoRequirementBy whenWhereSeverity
1Data controllers using automated decision-making or AI systemsProvide concise, context-sensitive notice at the point of data collection when using automated decision-making systems.
when data are collected for, or used by, systems that incorporate automated decision‑making (including AI techniques), controllers must provide enhanced, context‑sensitive disclosure
At point of data collectionRecommended
2Data controllers using automated decision-making with material effectsInform individuals about available opportunities for human review or appeal when automated decisions produce material effects.
where automated decisions have material effects, individuals should be informed about the opportunity for human review or appeal.
At point of data collectionRecommended
3Data controllers deploying high-risk algorithmic systemsPerform a Data Protection Impact Assessment before deploying high-risk or high-impact algorithmic processing systems.
the PPA recommends DPIAs for systems that create elevated privacy risk and maintaining records of mitigation measures.
Prior to deploymentRecommended
4Data controllers operating in power imbalance contextsDo not rely on implied or coerced consent for algorithmic processing in situations involving significant power imbalances.
in contexts of power imbalance (employment, essential services) implied or coerced consent is insufficient.
Recommended
5Data controllers using personal data in algorithmic processingMinimize the collection of personal data for algorithmic use and restrict processing strictly to notified purposes.
controllers must minimise the collection of data for algorithmic use and avoid secondary use that exceeds the notified purposes.
Recommended
6Data controllers deploying AI and algorithmic decision systemsEstablish board-level accountability for privacy risks and assign clear internal roles for legal, technical, and compliance oversight.
The document recommends organisational governance measures: board‑level accountability for privacy risks arising from AI
Recommended
7Data controllers contracting with third-party processorsInclude contractual clauses requiring data processors to assist with notice obligations, record-keeping, and subject request handling.
Contracts with processors must include obligations to support notice, record‑keeping and incident reporting.
Before engaging processorsRecommended
8Data controllers deploying automated decision-making modelsMaintain internal technical documentation including model descriptions, training summaries, and evaluation results for regulatory review.
controllers should retain internal documentation (model descriptions, training data summaries, evaluation and test results) to enable supervisory review
Recommended
9Data controllers operating live algorithmic decision systemsContinuously monitor algorithmic systems by testing for bias, accuracy, and model drift, while logging automated decisions.
continuous monitoring of algorithmic systems: periodic re‑assessment of privacy impact, documented testing for bias and accuracy, monitoring for model drift
Recommended
10Data controllers profiling or handling sensitive categories of dataDo not perform sensitive inferences or profiling without implementing heightened privacy safeguards.
in many cases avoidance of sensitive inference or profiling without strong safeguards.
Recommended

© Regulations.AI · updated on 13-Jun-2026 · reviewed against official sources on 07-Sep-2026 using Gemini 3.6 Flash