Israel Background

Information Privacy

Chen, Fisher, Gabbay Law Firm: Thousands of Debtors' Vehicle Licences Open on the Web, and the Question Israel's Privacy Amendment 13 Raises

Our review found more than 6,000 debtors' vehicle licences on the online sales system of the Netanya law firm Chen, Fisher, Gabbay, reachable with no password and no login. A court order that allows a receiver to obtain personal data is not a licence to keep it in the shop window forever. On purpose limitation, section 8(b) of the Protection of Privacy Law, and personal data as an asset controlled by the data subject.

In short

  • More than 6,000 debtors' vehicle licences were found accessible on the sales website of the law firm Chen, Fisher, Gabbay: no password, no login, no hacking. Most were redacted in a way that allows the document to be recovered.
  • Personal data is a digital asset of the data subject. Section 1 of Israel's Protection of Privacy Law prohibits infringing privacy without consent; no one may transfer, sell or use such data beyond what was permitted.
  • A court order allowing a receiver to obtain data in order to sell a vehicle does not turn that data into the firm's marketing asset, and is not a permanent publishing licence.
  • Since Amendment 13, in force from 14 August 2025, section 8(b) states it plainly: personal data may be processed only for the purpose lawfully set for the database. Keeping a file online is processing that happens now.
  • A file that opens with a click, without identification, fails the access-control requirement of the Data Security Regulations. That is a separate ground, independent of the purpose question.

More than 6,000 debtors’ vehicle licences. No password, no login, no hacking. All from the online sales system of Chen, Fisher, Gabbay, Law Firm of Netanya, a large practice specialising in collection and receivership for banks and commercial companies.

What we found

Our review of the firm’s sales system found thousands of vehicle licences that can be reached and downloaded with a click. Most were “redacted”, but by a failed method that allows the full document to be recovered. The documents did not reach the web from a pirate site or a breached database. They were published on the firm’s own sales website, in the course of receivership proceedings, under court orders.

The firm itself states on its website that the vehicles it publishes on the site and on Bidspirit are the sole authorised source for their publication and sale, and that a copy of the relevant vehicle licence can be downloaded from the site (firm website, sales and receivership page).

That is where the genuinely interesting question begins.

Personal data belongs to the data subject

Start from the foundation. Israel’s Protection of Privacy Law opens, in section 1, with a single sentence: no person shall infringe the privacy of another without consent. Personal data is a digital asset of the person it describes. It is not the merchandise of whoever happens to hold it: it cannot be transferred, sold or used beyond what was expressly permitted, by law or by consent.

Professor Michael Birnhack and Dr Omri Rachum-Twaig sharpen the point in their new book, Information Privacy (Nevo, 2026, in Hebrew): the right to privacy in data is not simple ownership of every fact, but something deeper, control over how data about a person is collected, stored, linked to other data and used throughout the life of that data. That control stays with the data subject even while the data sits with others.

An order is not a permanent publishing licence

A receiver obtains data from a public registry for one purpose: to prove the vehicle belongs to the debtor, locate it, seize it and sell it. For that purpose alone he may receive the data, by virtue of his role as an officer of the court.

The legal expression of this is the purpose limitation principle, and it appears in the law twice.

Section 2(9) lists, as an infringement of privacy, “use of information about a person’s private affairs, or passing it on to another, for a purpose other than the one for which it was provided”. Such an infringement is a civil wrong (section 4), and whoever commits it intentionally commits a criminal offence carrying five years’ imprisonment (section 5).

Section 8(b), as worded since Amendment 13 came into force on 14 August 2025, says it in words that admit no second reading:

“No person shall process personal data in a database except for the purpose lawfully set for that database.”

Section 8(c) adds that no person shall process personal data from a database without authorisation from the database controller, or beyond that authorisation.

The point many miss: processing is not a one-off event that ended on the day of publication. Keeping a file accessible online is processing that happens here and now, even if the original publication was years ago.

The example Birnhack and Rachum-Twaig give was almost written for this case. An insurance company lawfully received, as holder of a debtor’s assets, information about an attachment in legal proceedings. It then used that same information for an underwriting decision: refusing to insure that person. The court held that a lawful source for obtaining data is not an unlimited permit for its future use (Administrative Petition 24867-02-11 IDI Insurance v. Registrar of Databases).

So what happens once the vehicle has been sold? Once the receivership ended years ago? Is there still a legal purpose that justifies the vehicle licence remaining on an open server, and a person’s history as a debtor becoming a permanent archive of a commercial website? A registration number alone is a technical datum. A vehicle licence in the context of receivership links a person, a vehicle, ownership, an address, a debt and a legal proceeding. That is no longer data about a car. It is data about a person.

A further layer: data security, and who is responsible

Separately from the purpose question, section 17(a) of the law provides that the database controller and the database holder are each responsible for the security of the data in the database. The Protection of Privacy (Data Security) Regulations, 2017 spell it out: regulation 8 requires access permissions to be defined by role, “only to the extent required to perform the role”, and regulation 9 requires measures to ensure that access to the database and its systems is made only by an authorised permission holder. A file that opens with a click, without identification and without any control mechanism, meets neither. It is an independent ground, and it does not depend on whether the proceeding has ended.

And who is responsible? Section 3 of the law defines the controller of a database as whoever determines, alone or with another, the purposes of processing the data in it, or a body (or an office-holder in it) authorised by statute to process the data, and distinguishes the controller from the holder. A sales platform operating the site is, as a rule, a holder. Whoever set the purpose of collection, received the data by virtue of his role and decided what would be published is the controller. That distinction decides who bears the duty to delete, and who is responsible for the data still being there.

What this means for anyone who holds data about others

This is not a final determination that the law was breached in this specific case. That would require examining the wording of the orders, the dates the proceedings ended, the categories of data exposed and the identity of those who controlled the publication. But the principle the case illustrates applies to every lawyer, receiver, collection agency and business:

  • Permission to obtain data is permission for a purpose, not permission forever.
  • Once the purpose has ended, continued holding and exposure is a new use that needs a new justification.
  • Data exposed to anyone who asks, without access control, is a breach even where the use itself was permitted.

Sources: Michael Birnhack and Omri Rachum-Twaig, Information Privacy (Nevo, 2026, Hebrew), pp. 49–50, 204, 207, 214–215; Protection of Privacy Law, 5741-1981 (as amended by Amendment 13), sections 1, 2(9), 3 (definitions of “personal data”, “database controller”, “holder”), 4, 5, 8(b), 8(c) and 17(a); Protection of Privacy (Data Security) Regulations, 5777-2017, regulations 8 and 9; Administrative Petition 24867-02-11 IDI Insurance Co. Ltd v. Registrar of Databases.

This section is general information, not legal advice. Every case is examined on its own facts.

Sergey Yagudin

Licensed private investigator, Israeli Ministry of Justice · Israel Background

More from NEWS

Phones and Scams

Who Called Me? How to Identify an Unknown Number in Israel, Legally

A missed call from a strange number, a text that wants you to tap a link, repeated calls with silence on the line. A practical guide: how to find out who is behind a number using lawful methods, when it is a scam, and when it is time for a private investigator.

· 6 min read

All articles