Skip to main content
Back to blog
Blog7 min read

₪256K sanction: Israel's Amendment 13 enforcement begins

Israel's Privacy Protection Authority issued its first Amendment 13 sanction — ₪256,000 against Meuhedet. The same week, Italy fined Israeli-founded Lusha €2M. Two regulators, one kind of exposure.

Amendment 13EnforcementGDPR

On 21 July 2026, Israel's Privacy Protection Authority imposed a ₪256,000 monetary sanction (approx. €64,000 / $69,000) on Meuhedet Health Fund — the first sanction under Amendment 13 to the Protection of Privacy Law since it took effect. One week earlier, on 14 July 2026, Italy's data protection authority (the Garante) fined Lusha Systems Inc., a data broker founded in Israel, €2 million (approx. ₪8 million).

For readers outside Israel: Amendment 13 is the 2024 overhaul of Israel's Protection of Privacy Law, in force since 14 August 2025. It gave the Privacy Protection Authority the power, for the first time, to impose administrative monetary sanctions directly, without a court.

The two cases are unrelated — a health fund that reported late, and a data broker penalised for its collection model itself. Together they mark one shift: privacy enforcement has moved from statement to price tag, in two regimes at once. An Israeli company that both processes data in Israel and touches the data of people in Europe now faces exposure to two regulators, each with independent power to act.

In short

  • On 21 July 2026, Israel's Privacy Protection Authority imposed a ₪256,000 sanction on Meuhedet Health Fund for failing to report a serious security event immediately — the first sanction ever issued under Amendment 13.
  • Meuhedet knew of a fault exposing members' medical records by November 2025 but reported it to the Authority only on 27 January 2026 — about two months after the member complaint that surfaced it.
  • On 14 July 2026, Italy's Garante fined Lusha Systems Inc. €2 million and ordered it to erase the data of people located in Italy.
  • The Garante held that GDPR applies to Lusha despite its having no EU establishment, under the "monitoring" criterion of GDPR Article 3(2).

The Israeli case — Meuhedet Health Fund

Israel's Privacy Protection Authority imposed a ₪256,000 sanction on Meuhedet Health Fund for breaching the duty to report a serious security event immediately, under Regulation 11(d) of the Protection of Privacy (Data Security) Regulations. It is the first sanction the Authority has issued since Amendment 13 took effect.

The event: a technical fault in one of the fund's digital systems allowed, under a specific combination of conditions, unauthorised access to members' medical records — specially sensitive data. It surfaced when a member reported he could view his step-sister's medical file.

The failure was not the fault itself, but the timing of the report. The administrative inquiry found the fund had known of the event since November 2025. About six weeks after the member's access was blocked, it emerged that the fault was systemic. The fund fixed it in late January 2026 and only then — on 27 January 2026, roughly two months after the complaint — reported it. Getting this window right is exactly what our immediate breach-notification support is built around.

The Authority set out the principle plainly: the immediate reporting duty arises upon becoming aware of a serious security event. Waiting to complete every check empties "immediacy" of meaning. The required report is an initial one, based on what is known at the time, with details added later. The ₪256,000 figure is the amount left after reductions under the law; the base figure was not published.

The European case — Lusha

Italy's Garante fined Lusha Systems Inc. €2 million, barred it from processing the data of people in Italy, and ordered erasure. The fine was set in a decision of 14 July 2026 (document 10275035), published on 27 July 2026.

Lusha is a data broker that sells "enriched" information on individuals — job title, email addresses, phone numbers. It gathers this from multiple sources, including scraping from social networks and buying from other data brokers, and supplies it to clients for commercial or anti-fraud purposes. The data included details on senior officials, law-enforcement and judiciary figures.

The Garante found that Lusha processed the data of a large number of people in Italy in breach of the principles of lawfulness, fairness, transparency and data minimisation. The privacy notice was not clear or accessible, and legitimate interest was held not to be an adequate legal basis.

The point that matters for any Israeli company: the Garante held that GDPR applies to Lusha even though it has no establishment in the EU. The basis is the monitoring criterion of GDPR Article 3(2) — Lusha does not merely collect professional data, it also updates and controls it over time, which amounts to monitoring the behaviour and positions of individuals online. The collection-and-enrichment model itself brought it within scope.

Comparison

MeuhedetLusha
EntityMeuhedet Health FundLusha Systems Inc. (data broker)
RegulatorPrivacy Protection Authority (Israel)Garante (Italy)
Legal regimeMonetary sanction, Amendment 13; Reg. 11(d)Administrative fine, GDPR Art. 83; scope via Art. 3(2)
Core breachFailure to report a serious security event immediatelyProcessing without a valid legal basis; transparency and minimisation; monitoring
Amount₪256,000 (approx. €64,000)€2,000,000 (approx. ₪8M)
Date21 July 2026 (published)14 July 2026 (decision)

What this means in practice

Map the trigger for reporting, not just the reporting procedure. Meuhedet likely had a procedure; what failed was deciding when the clock starts. Define in advance what information is enough to call something a "serious security event," and who may authorise an initial report before the investigation is complete.

Shorten the gap between discovery and report. The Authority said explicitly that waiting to finish checks is not a defence. Build a path that lets you file an initial report within hours, with details to follow.

Test whether your data model is "monitoring" under GDPR. If you collect, update and enrich information about people over time — including in Europe — Article 3(2) may reach you with no EU office, employee or server.

Do not treat "legitimate interest" as a default. In Lusha it was rejected. If your product is built on data collection or enrichment, check the legal basis for each data stream separately. A privacy gap assessment is the usual place to start.

Run both regimes through one mechanism. Double exposure does not require two compliance systems. One officer and one framework mapping both laws prevent gaps at the seams.

Self-check checklist

  • Have you defined, in writing, what counts as a "serious security event" and who decides to report? (Yes / No)
  • Can you file an initial report to the regulator within 24 hours of discovery? (Yes / No)
  • Do you record the moment of discovery — as distinct from the moment the investigation ended? (Yes / No)
  • Do you process data on people located in the EU (customers, leads, purchased data)? (Yes / No)
  • Does your data model include tracking, updating or enrichment over time? (Yes / No)
  • Have you checked the legal basis for each collection stream, rather than relying on a blanket "legitimate interest"? (Yes / No)
  • Is one person accountable for both Israeli law and the GDPR? (Yes / No)

One or more "No" answers is a point to review, not necessarily a breach.

Questions and answers

What is the maximum monetary sanction under Amendment 13?

Amendment 13 lets Israel's Privacy Protection Authority impose sanctions reaching millions of shekels per violation, with an aggregate cap of 5% of annual turnover. The ₪256,000 on Meuhedet is the first in practice, and is below the ceiling because reductions under the law applied — see the Authority's worked sanction examples.

Does GDPR apply to an Israeli company with no customers in Europe?

It can — even without customers, an office or a server in the EU. GDPR Article 3(2) applies to anyone monitoring the behaviour of people located in the Union. In Lusha, the collection, updating and enrichment of data on people in Italy was treated as monitoring, which was enough to apply the GDPR. For the cross-border picture, see when GDPR reaches an Israeli company.

When does the duty to report a security event begin?

The immediate reporting duty arises upon becoming aware of a serious security event, not when the investigation concludes. In Meuhedet, the Authority held that waiting to complete every check empties the immediacy requirement; the initial report rests on what is known at the time.

Is "legitimate interest" a sufficient legal basis for data collection?

Not always. In Lusha, the Garante held that legitimate interest was not an adequate basis for the processing carried out. If your product relies on data collection or enrichment, examine the legal basis for each data stream rather than assuming legitimate interest covers everything.

Can one company be fined in both Israel and Europe over the same data?

Yes. The Israeli authority and the European authorities hold independent powers, each under its own regime. A company that processes data in Israel and also touches people in Europe is exposed to both at once — which is why running both laws through a single compliance function is the safer design.

Where this leaves you

Two sanctions in one week are not a coincidence — they are a trend line. We see enforcement moving from education to price, in Israel and in Europe alike. A company that touches both regimes will gain from a single compliance mechanism that maps them together, rather than two systems that leave gaps at the seams. If you want to see where you stand against both laws, that is exactly what an outsourced Data Protection Officer service is for — one point of accountability for Israeli law and the GDPR.

This is general information, not legal advice; the application of these requirements is assessed case by case. For your specific situation, consult a qualified professional.

Yona Schwebel · Data Protection Officer and Advocate · advising Israeli companies on Amendment 13 and GDPR compliance.

Sources