Beit Shemesh Municipality Fined Over Data Breach Exposing Sensitive Resident Information
The Beit Shemesh Municipality has been fined NIS 64,000 (approximately $17,300) by the Privacy Protection Authority (PPA) for severe data security violations. The penalty follows a journalistic investigation that uncovered a breach in the city's Geographic Information System (GIS), exposing sensitive welfare and medical data of thousands of residents.
Upon learning of the breach, the system was immediately disabled. A subsequent administrative investigation by the Ministry of Justice's PPA found that the municipality failed to properly define its external vendor's role in managing the welfare database, despite the vendor having continuous access for nearly two years. The PPA also identified serious deficiencies in the municipality's data security procedures concerning external contractors, including a lack of clarity on usage purposes, permitted data types, and contract duration.
The municipality's defense, citing a "good faith administrative gap" or arguing the vendor wasn't a "holder" of the data, was rejected by the PPA. The initial fine was NIS 80,000, but was reduced due to the municipality's lack of prior enforcement actions or penalties in the preceding five years.
The PPA's Enforcement Division director, Adv. Adi Menachem Bar, stated that organizations granting external access to sensitive databases must strictly adhere to privacy laws. She emphasized the PPA's continued commitment to enforcing these regulations to protect public privacy, especially concerning highly sensitive medical and welfare information.
The investigation into the external vendor involved in the breach is still ongoing.