Beit Shemesh Fined 64,000 NIS Over Data Breach Exposing Resident Welfare Files
The Privacy Protection Authority fined Beit Shemesh 64,000 NIS after a GIS system glitch exposed sensitive welfare and medical data of 4,600 residents online.

The Privacy Protection Authority has fined the Beit Shemesh Municipality 64,000 NIS for violating data protection regulations following a severe security breach. The incident exposed sensitive welfare and medical data of approximately 4,600 residents on the municipal website due to a malfunction in a GIS system operated by an external vendor.
Vendor Oversight and Legal Implications
The breach came to light after a journalist discovered the vulnerability and reported it, prompting immediate administrative enforcement. Investigators found that the municipality failed to register the external vendor as a database holder in its official documentation and neglected to regulate data security procedures concerning third-party contractors.
The Authority rejected the municipality's defense that the vendor was not a database holder or that the violations stemmed from a good-faith administrative gap following the enactment of Amendment 13 to the Privacy Protection Law in August 2025. Although the base fine was set at 80,000 NIS, it was reduced to 64,000 NIS because the municipality had no prior enforcement record in the preceding five years.
Enforcement Priorities
"Organizations that contract with external vendors and grant them access to such databases are required to strictly adhere to the law," said Adi Menachem Beer, head of the enforcement division at the Privacy Protection Authority.
This enforcement action follows a recent 250,000 NIS fine imposed on the Meuhedet Health Services, highlighting the Authority's aggressive stance on public institutions complying with updated privacy standards.





