New Lawsuit Wave Targets Major Israeli Companies Over User Data Tracking
A surge of lawsuits is currently challenging major Israeli companies, with dozens of pre-litigation notices and filed cases focusing on the alleged unauthorized collection of user data. The central claim is that websites embed code or "cookies" from tech giants like Facebook and TikTok, which gather information on user behavior for targeted advertising without explicit consent.
Recent lawsuits have been filed against retailers like Tiv Ta'am and fashion sites like Shein, alleging they use TikTok's tracking code on their sites without informing users or obtaining their agreement. Similarly, a class-action lawsuit was filed against the insurance company Migdal in April, and similar actions are reportedly underway against non-bank credit companies.
The current wave of litigation appears to have been triggered by a February publication from the Israeli Privacy Protection Authority (PPA). The PPA clarified its stance on consent in privacy law, emphasizing that consent must be "informed," meaning individuals understand what they are agreeing to, the purposes of data collection, and the consequences of refusal. While the PPA stated that consent can generally be given actively (opt-in) or passively (opt-out) depending on the circumstances, and does not mandate a blanket requirement for explicit cookie consent, its guidance on the required level of detail in consent notices has drawn criticism.
Legal experts are divided on the interpretation of the PPA's guidance. Some lawyers representing the companies argue that the guidance creates a legal ambiguity that plaintiffs are exploiting. They contend that the PPA's document has been interpreted by plaintiffs as demanding a stricter standard than intended, requiring positive consent via an "accept" button for all website users, similar to European regulations. This, they argue, imposes a significant new burden on businesses without clear legal basis in Israeli law.
Conversely, other legal professionals argue that this interpretation is an overreach, as the PPA's document only specifies consent requirements based on data type and usage purpose, not a universal opt-in mandate. They point out that the PPA itself noted explicit consent is "desirable" rather than mandatory, particularly for sensitive data, a category most cookie usage does not fall into. The economic implications could be substantial, especially for "free" service websites reliant on advertising revenue and companies whose marketing strategies depend on this data. Some cookies are also used for site functionality and accessibility, and restricting them could hinder service improvements.