GDPR for an Israeli company — three questions to answer on day one.
You don't need a European office to be subject to the GDPR — one European customer is enough, and sometimes less. These three questions determine most of what you'll need to do.
Privacy · August 12, 2026 · 5 min read
Question 1: does the GDPR apply to us at all?
The regulation reaches beyond the EU through two main routes (Article 3(2)):
- Offering goods or services to people in the EU — including free ones. An English-only website is not enough by itself; euro pricing, European languages, targeted marketing or actual EU customers do point to applicability.
- Monitoring the behaviour of people in the EU — behavioural analytics, profiling, or tracking of European users.
And there is a third, quieter and more common route: contractual applicability. Even where the regulation does not reach you directly, your European customer is subject to it — and is obliged (Article 28) to put a data processing agreement in place with you. In practice, an Israeli SaaS company usually meets the GDPR first through its customer's contract.
Question 2: are we a controller or a processor?
This question sets the structure of your obligations, and the usual answer is: both — in different capacities over different data sets.
- For customer data processed on the platform for your customers, you are typically a processor: acting on instructions, bound by the DPA, responsible for security, breach notification and assistance.
- For your own users, contacts, candidates and marketing lists, you are a controller: responsible for lawful basis, transparency and data-subject rights.
Mixing up the two roles is the most common failure mode — for example, using customer data for product development when the DPA does not permit it.
Question 3: how does data lawfully leave the EU?
Here Israeli companies enjoy a structural advantage: Israel benefits from a European Commission adequacy decision, reaffirmed in the Commission's periodic review in January 2024. Transfers from the EU to Israel therefore need no additional mechanism, so long as the data stays within the decision's scope.
- But the processing chain continues: if you store on AWS in the US or use sub-processors outside Israel and the EU, that onward transfer needs its own basis — usually the provider's Standard Contractual Clauses (SCCs).
- Mapping your sub-processors is therefore a day-one task: who touches the data, where, and under what transfer basis.
Also on day one
- An EU representative (Article 27): a company with no EU presence that falls under Article 3(2) must generally appoint a local representative — an obligation many discover late.
- A record of processing activities (Article 30): the foundation document every customer audit starts from.
- And do not forget Israeli law: the Privacy Protection Law, following Amendment 13, imposes its own current obligations — serious customer diligence will check both.
Frequently asked
We have one European customer. Is that enough for the GDPR to apply?
If you offer the service to the European market or monitor users there — yes, that can suffice. And even if not, the customer will apply the regulation's substance to you through the DPA. The practical difference between the two situations is smaller than it looks.
Does Israel's adequacy decision exempt us from everything?
No. It solves the EU-to-Israel transfer leg — not the processing obligations themselves, not the DPA with your customer, and not onward transfers to your own providers outside Israel.
The above is general information only, current as of the date of publication, and does not constitute legal advice or a substitute for advice on your specific circumstances. Consult a lawyer before acting.
Has the question become concrete?
A good article raises questions. When you need an answer about your own deal — email or call, and we'll talk directly.
- Email[email protected]
- Phone054-288-9554
- LinkedInlinkedin.com/company/schwebel-law-firm ↗