Callstrike
Compliance

Voice phishing simulations in Israel

Phone numbers in IsraelProvisioned by Callstrike after approval

Israel does not organise privacy law around lawful bases, so nothing about a voice phishing simulation here turns on picking one. It works from a closed list of infringing acts and a list of defences, and the provision that matters most is sharper than any of them: approaching someone for personal information to be processed in a database, giving false particulars and meaning to mislead them into handing it over, is a three-year offence. What the call is built to collect is therefore the whole design.

Phone numbers

Supplied by Callstrike

Local numbers in Israel, after a one-time approval.

Running a simulation

Permitted, and the script is the risk

A three-year offence turns on approaching someone for data with false particulars.

Consent

Weak as a ground, and still necessary

The regulator gives employee agreement little weight, then asks for a written policy.

Getting a phone number in Israel

One approval per country, with no documentation to gather.

Provisioned by Callstrike after approval

Numbers here are not released from open inventory. Your workspace is cleared for this country once, and Callstrike then provisions a dedicated number against it for your simulations. Approval is a one-time, per-country step and usually takes 3 to 5 business days.

Israel is one of the few countries in this portal where the carrier publishes no documentation requirement on any number type offered here, so there is no register excerpt to chase and no evidence pack to assemble. Plan for the days rather than the paperwork: what you are waiting on is the country being enabled against your workspace, not a regulator reading a submission.

What does stand between you and a working campaign is the network rather than the file, and it is decisive. In September 2024 the ministry signed instructions taking effect immediately. An international service provider must block calls originating outside Israel where the caller identity is an Israeli fixed-line number. A mobile provider must block calls from outside Israel presenting a mobile number, with an exception only for its own customer who is roaming. And a service provider must not permit its subscribers to use numbers that have not been allocated for their use. Read together, the international route most campaigns default to simply does not complete, and a compliant Israeli provider cannot enable you to present somebody else's number. Israeli traffic originates on Israeli-allocated numbers or it does not arrive.

We would rather record a gap in the sourcing than paper over it. The ministry's announcement quotes the instructions it signed but does not name the amended instrument and gives no gazette citation, and we could not locate the published regulation text. The substance above rests on the ministry's own statement of the rules it made, and that is the limit of what we can show you.

  1. 01Ask for the country to be enabled for your workspaceYour administrator, in the Callstrike console.
  2. 02Approval is granted against your workspaceTypically three to five business days, and once only for as long as you operate here.
  3. 03A dedicated number in Israel is assigned to youCallstrike
  4. 04Build and launch the campaignYour team

No regulatory documentation is required to hold a number here. The clearance step is Callstrike enabling the country for your workspace, with no forms to complete and no evidence to gather.

Is it lawful to run a simulation in Israel?

The position in short, before your counsel reads the detail below.

Yes, and the analysis runs differently from anywhere else on this site. There is no basis to select. The statute prohibits infringing another's privacy without their agreement, defines infringement as one of eleven enumerated acts, and then supplies defences, so the question is whether the campaign performs one of the eleven and, if it does, whether a defence holds. Four of the eleven can reach an exercise, and one of them predates synthetic voice by four decades: the use of a person's name, nickname, image or voice, for profit. Its gate is those last two words. The defences are more useful than they first look, covering good-faith acts done under a legal, moral, social or professional duty, or for the protection of a legitimate personal interest, or in the lawful course of an occupation and the ordinary course of work provided they were not done by public publication, and a threshold provision bars any action for an infringement of no substance. An authorised, documented, proportionate internal exercise is the shape those defences were drawn around, and the last one is a reason to keep the exercise internal rather than write it up publicly.

The provision that actually decides how the call is scripted is not about privacy in the abstract at all. An approach to a person to receive personal information for its processing in a database has to be accompanied by a notice stating whether giving the information is obligatory or voluntary and what refusing means, the purpose, who controls the database and how to reach them, who the information goes to and why, and the rights of access and rectification. That is a pretext call described backwards, and the amendment in force since August 2025 put two prices on it. Failing the notice is an administrative fine of fifty shekels multiplied by the number of people approached, doubling to a hundred where specially sensitive information was involved, with a thirty thousand shekel floor, so a two-thousand-person campaign is arithmetic rather than discretion. And giving false particulars in such an approach, meaning to mislead the person into handing the data over, is a criminal offence carrying three years.

The workable reading, and the one that should shape the script, is that both provisions bite on an approach made in order to process the information in a database. An exercise that records only that a person would have complied, and never captures or stores what they would have said, is a long way from the offence. An exercise that harvests a credential under a false identity and files it is not. Note also which statute you are reading about: the amending act was published in August 2024 and commences one year later, so anything describing Israeli privacy law from before August 2025 is describing something else.

Two provisions outside the privacy statute complete the picture and they point opposite ways. The anti-spam rule does not reach you, because advertising material is defined exhaustively in three limbs and an employer testing its own staff sends none of them, which also means the thousand-shekel-per-item exposure that makes Israeli marketing counsel nervous does not attach. But using a telecommunications installation in a manner capable of hurting, frightening, harassing, creating anxiety or annoying is an offence carrying three years and is not scoped to advertising at all. That is the one a badly designed exercise runs into, so calibrate the scenario and cap the retries. On synthetic voice the honest answer is that Israel has no duty: no statute, no disclosure obligation and no rule requiring a caller to announce that a voice is generated. What exists is a joint ministerial policy paper addressed to regulators, recommending sectoral rules, and it should not be described as a duty on a caller.

What your company needs to do

7 items, in the order you will need them.

  • Design the call so nothing is acquiredIsrael-specificBoth the notice duty and the three-year offence attach to an approach made in order to process the information in a database. An exercise configured so that a disclosed credential cannot enter a database is not making that kind of approach, and being able to show the configuration is worth more than being able to argue about intent afterwards.
  • Settle the notice question in advance, because the fine is arithmeticIsrael-specificFifty shekels for every person approached, doubling for specially sensitive information, with a thirty thousand shekel floor and no discretion in the formula. The regulator issued a fine for exactly this failure in August 2026. Record the decision you took about the statutory notice, and why, before the first call rather than in response to a complaint.
  • Write the monitoring and testing policy, detailed rather than generalIsrael-specificThis is where the Israeli deliverable lives, and it is regulatory rather than legislative. The regulator wants a clear and detailed policy on the manner, scope and purposes of the monitoring, set so far as possible after consultation with employees or their representatives, kept before them on an ongoing basis and periodically refreshed. So far as possible is not a duty to consult, and we are not going to upgrade it into one, but it is what the body investigating a complaint expects to see.
  • Fix the distribution list for call audio before you record anythingIsrael-specificKnowingly disclosing the content of a conversation obtained by monitoring to someone not authorised to receive it is a separate five-year offence, and the provision says in terms that it applies whether the monitoring was lawful or unlawful. Who may hear a debrief recording is a legal question here rather than an administrative one.
  • Document the assurance purpose before the exercise runsIsrael-specificRecording with one party's agreement is outside the secret monitoring offence by definition, but a recording made for the purpose of committing an offence or a harmful act is pulled back in and treated as secret monitoring. The purpose has to be documented in advance and it has to be an assurance purpose, not reconstructed afterwards when someone characterises the programme uncharitably.
  • Use an invented persona, and keep it clear of the profit limbOne of the eleven infringing acts is the use of a person's name, nickname, image or voice for profit, and its gate is that last phrase. A generic help desk is nobody's name or voice. Cloning a named executive puts you into an argument about a limb whose intentional breach is a five-year offence, for no gain in realism you could not get otherwise.
  • Check whether your own regulator already requires thisFor insurers and pension and provident fund managers it is not an optional maturity exercise: the capital market authority circular requires social engineering, impersonation and phishing tests at least once a year, and has done since April 2017. For a bank the central bank directive requires awareness training and exercises of the response arrays, not testing of people. Look in the right regulator before assuming either way.

The controls that do the work

How Callstrike is configured, and which provision in Israel each choice answers.

Auto-hangup before disclosure

The bot ends the call at the moment an employee starts to give up a credential or a piece of personal data, so the thing the pretext asked for is never spoken into the system and never stored.

This is the control the whole Israeli position turns on, because the sharpest provision here bites on acquiring the data rather than on placing the call. The three-year offence and the notice duty both attach to an approach made in order to receive personal information for processing in a database. The call ends the moment an employee begins to give up a credential, so the information the pretext asked for is never received and never enters a database, and the purpose element the offence is built on describes something the system is configured not to do. That is a statement about the facts rather than a claimed defence, which is the strongest form the answer can take.

In-call debrief and follow-up

A second voice breaks character as soon as the call ends, explains what just happened and why it worked, and a follow-up email repeats it in writing while the moment is still sharp.

The regulator replaces employee agreement with proportionality and transparency, and there is a separate three-year offence for using a telecommunications installation in a manner capable of frightening, creating anxiety or harassing. A second voice that breaks character the moment the call ends, with vishing training in writing the same day, speaks to both at once: it is the difference between an exercise that leaves someone frightened and one that leaves them taught, and that difference is exactly what those two tests are measuring.

Consent Management

Two modes: collect consent now, over email, Slack or Teams with a full audit trail per employee; or record that your organisation already has this covered, by uploading the policy, handbook clause or agreement and confirming the scope it applies to. The document is hashed, the attestation is signed and timestamped, and an audit email is issued. Included on every plan.

The regulator's workplace guideline is blunt: an employee's agreement to an infringement of the right to privacy, including to collection or use of information by an employer, does not carry great weight, and the reason given is the power gap. So agreement is not the ground here. What the same guideline then demands is a clear and detailed policy kept before employees on an ongoing basis, which is a notice and transparency duty, and that is precisely what this produces: the dated evidence per employee that the policy was given, or a hashed copy of the policy with a signed and timestamped attestation of the scope it covers.

SCORM module

An interactive web presentation on voice-phishing risk, delivered through your own LMS, which then invites the learner to opt into a web call with the bot. A call the person starts themselves in a browser is not a telephone call, so telephony rules do not reach it.

The Israeli obstacle is the number rather than the law, and this route does not need one. Callstrike's vishing simulator can deliver the same deepfake voice through a web call the learner starts themselves after working through the module, so the three blocking instructions have no Israeli calling identity to act on and no international origination to refuse. Be precise about the limit: Israel imposes no synthetic-voice disclosure duty for the module to satisfy, and the privacy statute governs whatever either route collects, so the module is an answer to delivery and not to the script.

Consent Management is included on every plan. See AI voice phishing simulation and human-in-the-loop voice phishing for how each is delivered.

For your legal team

The sourced position

Everything above, with the instruments behind it. Every claim cites the statute or the regulator it comes from, so your counsel can verify it rather than rely on our summary.

Eleven acts and a list of defences, not a menu of bases

Reading Israeli privacy law through a European lens produces the wrong question. There is no basis to select. The Protection of Privacy Law prohibits a person from infringing the privacy of another without their agreement, then defines infringement of privacy as one of eleven enumerated acts, and then supplies a list of defences. So the analysis is: does the campaign perform one of the eleven, and if it does, does a defence hold.

Four of the eleven can reach a simulation. Shadowing or tracking a person in a way liable to harass them, or other harassment. Monitoring prohibited by law, which routes into the separate statute described in the next section. Use of information about a person's private affairs, or its transfer to another, otherwise than for the purpose for which it was given. And a limb that predates synthetic voice by four decades: use of a person's name, nickname, image or voice, for profit. Where the infringement is intentional and falls in one of those limbs it is an offence carrying five years, so the voice limb sits inside the criminal part of the statute rather than the civil one. Its gate is the words for profit.

The defences are more useful to an internal exercise than they first look. A defendant who acted in good faith has a defence where the infringement was made in circumstances imposing on them a legal, moral, social or professional duty to do it; or for the protection of a legitimate personal interest of theirs; or in the lawful course of their occupation and in the ordinary course of their work, provided it was not done by public publication. There is also a threshold provision barring any civil or criminal action for an infringement of no substance. An authorised, documented, proportionate internal assurance exercise is the shape those defences were drawn around, and the last one is a reason to keep the exercise internal rather than write it up publicly.

Now the provision that actually decides how the call is scripted, because it is not about privacy in the abstract at all. An approach to a person to receive personal information for its processing in a database must be accompanied by a notice stating whether there is a legal duty to give the information or whether it depends on their will and agreement and what refusing means, the purpose, the name and contact details of the database controller, who the information will be passed to and why, and the rights of access and rectification.

That is a description of a pretext call read backwards, and the amendment in force since August 2025 put two prices on it. The notice failure is an administrative fine of fifty shekels multiplied by the number of people approached, doubling to one hundred where the approach concerned specially sensitive information, with a thirty thousand shekel floor, so a two-thousand-person campaign is arithmetic rather than discretion. And giving false particulars in such an approach, with intent to mislead the person into handing the data over, is a criminal offence carrying three years. The regulator is enforcing the notice duty in real cases, most recently a twelve thousand shekel fine announced in August 2026 expressly for failing to inform at the point of collection.

The workable reading, and the one that should shape the script, is that both provisions bite on an approach made in order to process the data in a database. An exercise that records only that a person would have complied, and never captures or stores what they would have said, is a long way from the offence. An exercise that harvests a credential under a false identity and files it is not.

Two currency points, because most published material about Israel is now out of date. The amending statute was published in August 2024 and its own commencement section brings it into force one year later, on 14 August 2025. Anything describing Israeli privacy law from before that date is describing a different statute. And registration went the opposite way to everyone's expectation: a private employer's own database is now almost never registrable, the duty surviving mainly for data brokerage above ten thousand people, with a separate notification duty pitched at a hundred thousand people where the data is specially sensitive. What does still bind is the rule that data may not be processed other than for the database's lawfully determined purpose.

One party is enough to record, and not enough to circulate

The Secret Monitoring Law answers the recording question cleanly, and then adds two traps that catch programmes which got the first part right.

Monitoring is defined as listening to another's conversation, or capturing or copying another's conversation, by means of a device. Secret monitoring is then defined as monitoring without the agreement of any of the parties to the conversation, and a party is defined to include the speaker and the person the conversation is directed to. A conversation expressly includes one by telephone. So a recording made with the agreement of one party is not secret monitoring at all, by definition rather than by exception, and a call your own side is on is outside the offence.

Getting it wrong is expensive. Conducting secret monitoring without a lawful permit carries five years, and so does placing or installing a device for the purpose.

The first trap is that a lawful recording can still be criminal to pass on. Knowingly using, without lawful authority, information or the content of a conversation obtained by secret monitoring, or knowingly disclosing it to a person not authorised to receive it, is a separate five-year offence, and the provision says in terms that it applies whether the monitoring was conducted lawfully or unlawfully. For a simulation that means the distribution list for call audio is a legal question rather than an administrative one. Debrief material that circulates beyond the people authorised to have it is where this provision bites.

The second trap is a carve-back that reverses the answer above in one circumstance. Monitoring a conversation and recording it, even where done with the agreement of one of the parties, are prohibited and treated as secret monitoring if done for the purpose of committing an offence or a harmful act. The purpose of the exercise therefore has to be documented before it runs, not reconstructed afterwards, and it has to be an assurance purpose. A programme that could be characterised as pursuing a harmful act loses the one-party position entirely and lands back in the five-year offence.

There is also an evidential consequence worth knowing. Material captured by secret monitoring contrary to the statute is inadmissible in court, save in a prosecution under that statute or in a proceeding for a serious crime. A recording made outside the rules is not simply risky to hold; it is largely useless for the disciplinary purpose someone will eventually want it for.

The spam rule is about advertising, and the AI paper is addressed elsewhere

Israel's anti-spam provision is the one everybody reaches for, and it does not reach an internal exercise. It applies to an advertiser sending advertising material, and advertising material is defined exhaustively in three limbs: a message distributed commercially whose purpose is to encourage buying a product or service or otherwise spending money; a message distributed to the general public soliciting a donation or propaganda; and a message distributed to the general public offering the recipient a number to call to receive some message. An employer testing its own staff sends none of the three.

The scoping matters commercially because of what sits behind the provision. A knowing breach exposes the sender to damages not dependent on damage of up to one thousand shekels for each item received, which is the number that makes Israeli marketing counsel nervous and which does not attach here. The same section defines an automatic dialling system as equipment used for automatic dialling or routing of a sequence of calls to a group of recipients in order to transmit a pre-recorded voice message, and requires a pre-recorded campaign to open with an opt-out announcement. Both sit inside the advertising scoping, so neither reaches a test, and nothing turns on whether the voice is live or synthetic.

Two provisions in the same chapter are not scoped that way and do bind. Using a telecommunications installation or terminal equipment unlawfully in a manner capable of hurting, frightening, harassing, creating anxiety or annoying is an offence carrying three years. That is the provision a badly designed exercise runs into: a pretext engineered to frighten, or repeated calls to someone who has asked them to stop, is within the words whether or not anything is being advertised. Calibrate the scenario and cap the retries.

A neighbouring provision on using fraud or a stratagem in a telecommunications installation is often quoted at this activity, and we do not rely on it. Read with the limbs around it, which concern obtaining telecommunications service or broadcasts by deception and decoders for encrypted broadcasts, it is aimed at defrauding the facility or the service rather than at deceiving a person on the phone. We flag it as arguable and leave it there.

On synthetic voice, the honest answer is that Israel has no duty at all. There is no Israeli statute on artificial intelligence, no synthetic-voice disclosure obligation and no rule requiring a caller to announce that a voice is generated. What exists is a joint policy document of the innovation ministry and the justice ministry's legislation advisory department, which by its own terms guides government ministries and regulators, directs them to work through sectoral rather than horizontal regulation at this stage, and recommends flexible instruments such as ethical principles, standardisation and self-regulation. Its transparency principle is an ethical principle addressed to regulators. It is not a disclosure duty on a caller and should not be described as one.

That absence is a live gap rather than a settled position, and the document's own direction of travel is sectoral, so the place to watch for an Israeli disclosure duty is a supervisory circular in a particular sector rather than a general statute.

Signed in a day, aimed at operators, and it closes the route from abroad

Israel moved hard on caller identity in September 2024, and the shape of what it did decides what a campaign can present. The minister signed regulatory instructions taking effect immediately, aimed by the ministry's own account at impersonation of law enforcement bodies and of companies through the use of their telephone numbers.

Three instructions were published and each one matters here. An international service provider must block telephone calls originating outside Israel where the calling subscriber's caller identity is an Israeli fixed-line number. A mobile provider must block, for its customers, calls originating outside Israel where the caller identity is a mobile number, with an exception only for its own customer who is roaming. And a service provider must not permit its subscribers to use numbers that have not been allocated for that subscriber's use.

Read together they answer the practical question without any prohibition being addressed to the caller at all. Presenting an Israeli fixed or mobile number on a call that terminates in Israel but originates on carrier infrastructure outside it is now blocked in the network, so the international route that most campaigns default to simply does not complete. And the third instruction means a compliant Israeli provider cannot enable a subscriber to present a number allocated to someone else. A campaign has to originate on Israeli-allocated numbers that the operator has allocated to it.

We would rather record a gap in the sourcing than paper over it. The ministry's announcement quotes the instructions it signed but does not name the amended instrument and gives no gazette citation, and we could not locate the published regulation text. The substance above is sourced to the ministry's own statement of the rules it made, and that is the limit of what we can show you.

Two negatives worth having, because both are commonly assumed the other way. The communications statute itself carries no caller identity or anti-impersonation provision: we searched the consolidated text for the Hebrew terms for number identification, calling-party identification and impersonation, and the only hits are inspector identification, handset identifiers and the definition of a subscriber identity module. And the separate statute that allows telephone numbers to be blocked by administrative or judicial order defines the triggering offences by reference to prostitution and drugs provisions of the penal code, so it does not reach spoofing or vishing at all.

What the country matrix holds for Israel

Number types:
Local
Restricted for automated outbound:
None recorded

Generated from the same country matrix the platform enforces at dispatch, so it cannot drift from what you can actually buy.

No council to convene, and a written policy the regulator expects you to discuss

Israel has no works-council statute and no statutory duty to consult employees before introducing monitoring or security testing. That is a real finding rather than a gap in the research, and it changes the file completely: there is no body to convene, no quorum, no agreement to obtain and no filing.

The collective agreements statute does not supply one. It governs who may make a collective agreement and over what subject matter, and the workplace committee appears in it only derivatively, as a substitute agreement-giver where an extension order conditions a right on a workers' organisation agreeing. So where a special collective agreement is in force at a particular workplace, its own terms decide whether a programme touches conditions of work and has to be negotiated. That is a question about one instrument at one employer, not a rule of general application, and we cannot answer it for you from the statute.

What fills the space is regulatory rather than legislative, and it is where the Israeli deliverable actually lives. The privacy regulator's workplace guideline, written for cameras but stating its general framework for employer monitoring, is blunt about agreement: an employee's agreement to an infringement of the constitutional right to privacy, including to collection or use of information by an employer, does not carry great weight. The reason given is the power gap, and the tests that replace it are proportionality and transparency.

From that the regulator derives a concrete requirement. To lay the ground for at least implied informed agreement, and in order to comply with the statutory notice provision, the employer must formulate a clear and detailed policy on the manner, scope and purposes of the monitoring; that policy is to be set, so far as possible, after consultation with the employees or their representatives; it must be kept before them on an ongoing basis; and the regulator's stated position is that it must be periodically refreshed. Note the qualifier. So far as possible is not a duty to consult, and we are not going to upgrade it into one, but it is an expectation from the body that would investigate a complaint.

The leading labour court authority points the same way, and we report it at one remove and say so. The judgment itself is not available from an official host, so what follows is the regulator's own account of it in that guideline. The court held that an employee has a sphere of privacy that accompanies them at work, irrespective of the employer's property right in the workplace and in the equipment used, so that allocating a computer and having the technical ability to monitor it does not extinguish the right. And it held that the employer must set an express and detailed policy on the use of information technologies, notify employees of it, and bring to their knowledge in detail both the rules and the circumstances the employer considers justify monitoring.

So the Israeli file is short but specific: a written monitoring and testing policy that is detailed rather than general, evidence that employees were told about it and are kept told, a record of whatever consultation was possible with employees or their representatives, a proportionality note explaining why the exercise is no more intrusive than it needs to be, and a decision recorded in advance about the notice provision and about who is authorised to receive the call recordings.

The one binding mandate is in the insurance regulator, not the central bank

Israel is the country in this portal where the sector answer is most often looked for in the wrong place, so it is worth taking the three instruments in the order people reach for them.

The national cyber directorate's organisational defence doctrine is the document most often cited as if it bound anyone. It says otherwise in its own words: it constitutes a recommendation to every organisation in the economy, and a working tool for cyber personnel, internal auditors, advisers and management. It is worth reading anyway, because it contains the clearest official Israeli description of what this activity measures. Its single occurrence of the Hebrew word for phishing is a metric: the number of users who clicked a link as part of a phishing exercise. The accompanying controls workbook goes further, listing social engineering against an internal or external employee in its threat catalogue and asking an auditor to verify that awareness training and relevant exercises were conducted in the past year. Recommended, and specific.

The central bank is where the mandate is usually assumed to be, and it is not there. The proper conduct of banking business directive on cyber defence management requires a comprehensive training and awareness programme covering employees, managers, developers, administrators, external parties, suppliers and customers, updated in line with the threat picture. It requires control-assessment mechanisms to be integrated with vulnerability surveys and controlled penetration tests. And it requires a programme of exercises of the various response arrays, taking account of exercise types including attack simulation and war games. But those exercises are of the response function, not of the workforce, and the directive contains no occurrence at all of the Hebrew terms for phishing, social engineering, simulation or exercise in the singular. It does not require testing people.

The instrument that does require it supervises insurers, pension and provident fund managers rather than banks. The institutional bodies circular on cyber risk management requires periodic penetration tests comprising a test simulating an attack attempt from external networks, and social engineering, impersonation and phishing tests, at least once a year. The Hebrew word it uses for impersonation covers voice pretexting on its face. It is a binding supervisory instruction made under named statutory powers, in force since April 2017, and it sits alongside an annual exercise of the relevant arrays, an annual live-event exercise by the response team, quarterly vulnerability scans and immediate reporting of significant events to the board and the commissioner.

So for an Israeli institutional body this is not an optional maturity exercise, it is the annual requirement, and the impersonation and phishing limbs are the parts an awareness course alone does not discharge. For a bank it is good practice with no instrument behind it. For everyone else it is recommended by the national directorate and required by nobody.

One caveat we would rather state than leave implied. The authority's current consolidated codex still points to that circular, or to any circular replacing it, and we did not exhaustively establish that no replacement has since been issued. Check the authority's own collection before relying on the version.

Take this further

Research prompt for your own AI assistant

Paste into Claude, Harvey or your firm's tool to pressure-test the position above.

You are advising on an authorised internal security exercise in ISRAEL. Our own employees receive a simulated voice-phishing call, placed by our vendor on our instruction, to measure susceptibility. No credential is captured or stored. The workforce is informed in advance through a written monitoring policy.

Verify or correct each proposition below against primary Israeli sources, and tell me what our written policy must contain:

1. ⚠⚠ חוק הגנת הפרטיות s 23נו makes it a THREE-YEAR offence to approach a person to receive personal information «לשם עיבוד המידע במאגר מידע», give false particulars contrary to s 11, and intend to mislead them. Assess whether an exercise that NEVER stores the disclosed data satisfies the «לשם עיבודו במאגר מידע» element, and assess the intent element.
2. s 23כו(ג)(1) prices a notice failure at NIS 50 per person approached, NIS 100 for «מידע בעל רגישות מיוחדת», with a NIS 30,000 floor. Confirm, and confirm the PPA is enforcing it (א.ד קרטינג חוצות, 05/08/2026).
3. ⚠ CURRENCY: תיקון מס' 13 was published 14 August 2024 and s 74(a) commences it on 14 August 2025. Confirm nothing relied on predates that.
4. Which of the eleven s 2 limbs does the campaign perform, and does a s 18(2) defence hold? Assess s 2(6)'s «לשם ריווח» gate against an invented persona, given s 5 makes an intentional breach a five-year offence.
5. חוק האזנת סתר: s 1 defines האזנת סתר as monitoring «ללא הסכמה של אף אחד מבעלי השיחה», so one party's agreement is outside it. But s 2(b) is a five-year offence for disclosing «בין שנעשתה כדין ובין שנעשתה שלא כדין», and s 3 pulls a one-party recording back in if made «למטרת ביצוע עבירה או מעשה נזק». Confirm all three.
6. חוק התקשורת s 30א is scoped to «דבר פרסומת» in three exhaustive limbs, so an internal test is outside it. But s 30's harassment offence is NOT so scoped. Assess our scenario design against it.
7. Israel has NO synthetic-voice disclosure duty; the 2023 innovation/justice ministry paper guides REGULATORS and is not a duty on a caller. Confirm, and identify any sectoral circular that has since created one.
8. ⚠ The binding staff-testing mandate is חוזר גופים מוסדיים 2016-9-14 of the CAPITAL MARKET AUTHORITY, not Bank of Israel Directive 361. Confirm 2016-9-14 has not been replaced.
9. Israel has no works-council statute and no statutory consultation duty. Confirm, and advise whether any special collective agreement at our own workplace changes that.

Flag anything that has changed since September 2026.

Common questions

What is the Israeli criminal risk in a pretext call?
Approaching someone for personal information to be processed in a database, giving false particulars, and intending to mislead them into handing it over is an offence carrying three years. Design the exercise so it records whether an employee would have complied without capturing or storing what they say.
How much is it if we skip the notice at the point of collection?
It is arithmetic, not discretion. The administrative fine is fifty shekels for each person approached, one hundred where the approach concerned specially sensitive information, with a thirty thousand shekel floor. The regulator issued a fine for exactly this failure in August 2026.
Can we record the calls, and can we share the recordings?
A recording made with one party's agreement is outside the secret monitoring offence by definition. Circulating it is a separate five-year offence where the recipient is not authorised to receive it, and a recording made for the purpose of a harmful act loses the one-party position entirely.
Does any Israeli regulator require this kind of testing?
One does, and it is not the central bank. The capital market authority circular on cyber risk requires insurers and pension fund managers to run social engineering, impersonation and phishing tests at least annually. The banking directive requires awareness training and response exercises, not staff testing.

Elsewhere in the Middle East and Africa

The rules differ by country even inside one region. These are the nearest guides to this one, each showing how phone numbers are obtained there.