Beit Shemesh Fined for Exposing Data of 4,600 Residents
The Privacy Protection Authority imposed a fine of 64,000 shekels on the Beit Shemesh Municipality after personal data belonging to approximately 4,600 residents was exposed through the municipal website. The accessible details included medical data and information from social services, which are considered particularly sensitive.
Key facts
- •Authority: the Privacy Protection Authority
- •The data of approximately 4,600 residents was affected
- •Final fine: 64,000 shekels
- •Original amount: 80,000 shekels
- •Amendment No. 13 entered into force in August 2025
- •The investigation of the external provider has not yet been completed
How the Data Was Exposed
Access to the information was made possible by a malfunction in a GIS system that the municipality operated through an external provider. A journalist discovered that the details could be viewed and reported this to the municipality and the Privacy Protection Authority. As a result, the system was shut down, access to the data was blocked, and the Authority opened an administrative investigation into the municipality and the provider.
What Violations the Authority Found
In the document describing the social data database, the municipality did not identify the external provider as a “holder” of the database, even though it processed personal information and had regular access to its systems for nearly two years. In addition, the information security procedures did not define the purposes for using the data, the types of processing permitted, the systems accessible, or the duration of the engagement with the providers. They also did not include references to the contracts and security procedures of the external service providers.
Why the Municipality’s Arguments Were Rejected
The municipality argued that the provider was not a “holder” and that the violations resulted from a good-faith administrative gap following the entry into force of Amendment No. 13 to the Protection of Privacy Law. The Authority rejected these arguments: the provider’s prolonged access to the database systems was consistent with the status of a holder, and the municipality should have prepared for the new requirements on time. The Authority also rejected the claim that general internal procedures and provisions in external contracts were sufficient.
How the Fine Was Determined
Initially, the financial sanction for the two violations was set at 80,000 shekels—40,000 for each violation. It was reduced to 64,000 shekels because, during the five years preceding the violation, no financial sanctions or administrative measures had been imposed on the municipality for failure to comply with the same requirements. The investigation concerning the external provider had not yet been completed at the time of publication.
What this means for you
Government and municipal authorities are responsible not only for the technical protection of personal information, but also for precisely regulating their relationships with external providers that have access to databases. For residents, this means that medical and social information must also be protected when processed by a contractor, and that a discovered exposure may lead to an administrative investigation and a fine.
Find a lawyer for this topic
- Lawyers: Общая практика
- Lawyers in Тель-Авив
- Lawyers in Иерусалим
- Lawyers in Хайфа
- Lawyers in Ришон ле-Цион