# Israel

> Israel (ISA · Capital Market Authority · IMPA · Privacy Protection Authority): Light on-chain, heavy on data protection. Region: Middle East & Africa. Privacy with disclosure: Confidentiality is workable so long as the regulated firm can identify parties and disclose on demand.

Part of the Soda Labs Privacy Hub regulation map, which reads the instruments
themselves rather than summarising the summaries: https://www.sodalabs.xyz/privacy-hub/regulation

## Key facts

- Entry type: Jurisdiction
- Region: Middle East & Africa
- Subject: Light on-chain, heavy on data protection
- Authority: ISA · Capital Market Authority · IMPA · Privacy Protection Authority
- Stance on on-chain confidentiality: Privacy with disclosure. Confidentiality is workable so long as the regulated firm can identify parties and disclose on demand.
- Tags: no AEC ban, Amendment 13, CMA licensing, stablecoin memorandum
- Canonical page: https://www.sodalabs.xyz/privacy-hub/regulation/jur-israel

## What it actually says

Israel splits cleanly along the axis this whole section turns on. On chain, the constraint is light: no instrument restricts anonymity-enhancing assets or transfers to self-hosted wallets, and those questions fall under ordinary anti-money-laundering supervision rather than any dedicated rule. Off chain, the regime got considerably heavier a year ago. Amendment 13 to the Protection of Privacy Law came into force in August 2025, requiring privacy protection officers, widening the definition of sensitive data, and giving the regulator administrative orders and fines with real weight behind them. For a firm handling personal data alongside on-chain activity, the binding compliance burden here comes from the data protection side, not the financial one.

## The instruments that matter

- **No crypto-specific anonymity rule**: no Israeli instrument restricts privacy coins or transfers to self-hosted wallets; both sit under general anti-money-laundering monitoring
- **Prohibition on Money Laundering Order (2018)**: financial asset service providers owe customer due diligence, beneficiary and ownership declarations, monitoring and reporting, with source-of-funds enquiry above roughly ILS 100,000 of annual activity
- **Amendment 13 to the Protection of Privacy Law, in force 14 August 2025**: mandates privacy protection officers, broadens sensitive data, adds data broker duties, and gives the authority administrative orders, cease-and-desist powers and substantial fines
- **Bank of Israel Directive 411 (2022)**: bars banks from blanket refusal of crypto-related transactions

## Sources

- [Israel Securities Authority](https://www.new.isa.gov.il/)
- [Amendment 13 overview](https://iapp.org/news/a/israel-marks-a-new-era-in-privacy-law-amendment-13-ushers-in-sweeping-reform)

## Related entries

- [Ghana](https://www.sodalabs.xyz/privacy-hub/regulation/jur-ghana): The regulator that put self-custody in writing
- [Nigeria](https://www.sodalabs.xyz/privacy-hub/regulation/jur-nigeria): Securities-first, with banking access restored
- [Seychelles](https://www.sodalabs.xyz/privacy-hub/regulation/jur-seychelles): No anonymity rule, but the offshore route is closing
- [Bahrain](https://www.sodalabs.xyz/privacy-hub/regulation/jur-bahrain): A listing test written against effects, not asset names
- [Kenya](https://www.sodalabs.xyz/privacy-hub/regulation/jur-kenya): The ban written into primary legislation, not a rulebook
- [Qatar](https://www.sodalabs.xyz/privacy-hub/regulation/jur-qatar): Exclusion by perimeter rather than prohibition
