When a generic cookie banner no longer satisfies the law
An Israeli technology company posts the familiar banner on its site: "This website uses cookies. By continuing to browse, you agree to our use of cookies." The only button reads "OK," and even without clicking it, the site continues to function normally, loading every tracking and marketing script in the background. Until recently, this was standard practice across most Israeli websites.
Today, following the entry into force of Amendment 13 to the Privacy Protection Law and the final consent guidance published by the Privacy Protection Authority, this practice carries real legal exposure. Cookies used for profiling, audience segmentation, or direct marketing now require separate, explicit, and informed consent — not a blanket consent implied merely by continued browsing.
This article details the current legal requirements for cookie consent management on Israeli websites and applications, and offers a practical framework for implementation.
The legal framework for cookie consent in Israel
Unlike the European framework, Israel has no dedicated statute governing cookies comparable to the EU's ePrivacy Directive. Nevertheless, in most cases cookies that identify a user, collect browsing behavior, or enable targeted advertising constitute "processing of personal data" under the Privacy Protection Law, 1981, as amended by Amendment 13 (in force as of August 14, 2025).
Amendment 13 did not abolish the database registration requirement, but it narrowed it considerably — the requirement now applies mainly to public bodies and to "data brokers" whose core business is collecting personal data for transfer to third parties, above a statutory threshold. That said, the general obligation to obtain informed consent for processing personal data — including data collected through cookies — remains in place and has, if anything, been reinforced.
The Privacy Protection Authority's final consent guidance sharpens this standard further. It provides that consent for profiling purposes (building a behavioral profile of a user) and consent for direct mailing must be separate from one another and separate from consent to basic site operation. The implication for cookies is clear: advertising cookies, behavioral measurement cookies, and audience-segmentation cookies require an independent consent track that cannot rely on a single, blanket "accept" click.
In addition, when cookies are used for direct mailing or direct marketing purposes, sections 17C–17F of the Privacy Protection Law apply, setting out specific consent requirements for direct marketing activity. As of the date of this article, the law and its interpretation continue to evolve, and every company should review its cookie practices against the most current guidance available.
Cookie categories and the consent levels each requires
Not every cookie carries the same legal weight. A correct classification of cookie types is the foundation of any sound consent framework:
- Strictly necessary cookies: Required for basic site operation — such as maintaining a shopping cart or managing a secure session. These generally do not require prior consent, but they should still be disclosed in the cookie policy.
- Functional cookies: Improve user experience (such as remembering a preferred language). Consent is recommended even though the sensitivity level is lower.
- Analytics and statistics cookies: Used to measure site usage. Where the data collected is identified or identifiable, explicit consent is required.
- Marketing, advertising, and profiling cookies: Used for cross-site tracking, building behavioral profiles, and serving targeted advertising. This is the most sensitive category, and under the Privacy Protection Authority's consent guidance it requires separate, informed consent that cannot be bundled with other consents.
Many companies mistakenly present only two options — "accept all" or "reject all" — ignoring this substantive distinction. A compliant consent framework must allow users to select, on a granular basis, which categories of cookies they agree to.
Websites with EU visitors and the reach of the GDPR
Many Israeli companies operate websites that reach European audiences, or have EU-based visitors even without targeting them directly. In such cases, the GDPR and the ePrivacy Directive may apply extraterritorially.
The European standard for non-essential cookies is an opt-in standard — non-essential scripts should not load until the user has given explicit consent, rather than merely failing to object. This is a stricter standard than what has traditionally applied in Israel, though as the Privacy Protection Authority's consent guidance tightens local requirements, the gap between the two regimes is narrowing.
A company reaching an international audience should consider a geo-targeted consent framework, presenting EU-based users with a stricter opt-in track and blocking non-essential scripts until actual consent is obtained. For a broader discussion of this topic, see our comprehensive article on GDPR compliance for Israeli businesses.
Practical implementation: what a compliant consent management platform should include
A properly designed cookie consent management platform (CMP) should generally include the following elements:
- Categorized disclosure: Presenting separate cookie categories (strictly necessary, functional, analytics, marketing/profiling) with the ability to consent to each individually.
- Default off: Non-essential cookies should not load until actual consent is given — it is not enough that the user simply did not object.
- Equal prominence for rejection: The option to decline consent must be as visible and accessible as the option to accept, not buried behind additional menus.
- A withdrawal mechanism: A user who has given consent must be able to withdraw it with comparable ease, typically through a persistent link in the site footer.
- Consent logging: Recording when, how, and to what version of the notice a user consented — a critical element for demonstrating compliance in the event of a regulatory review.
- An up-to-date cookie policy: A separate document or section of the privacy policy detailing the types of cookies the site uses, their purpose, and their retention period, kept aligned with the scripts actually deployed.
- Periodic cookie audits: A recurring review of every script actually running on the site, compared against what is disclosed in the policy and consent banner — since marketing and development teams routinely add new tools, often without legal's knowledge.
Common mistakes Israeli companies make in consent management
Reviewing the consent frameworks of Israeli websites reveals a recurring set of mistakes:
- Pre-checked boxes: Presenting consent categories as already checked, requiring the user to actively uncheck them — this does not constitute informed consent.
- Cookie walls: Blocking access to site content until the user grants blanket consent to all cookie categories, with no option to continue browsing with only essential cookies enabled.
- Bundled consents: Presenting a single consent that covers basic operation, analytics, and advertising/profiling together, contrary to the separation required by the consent guidance.
- A gap between policy and practice: A cookie policy listing a partial or outdated set of cookies that does not reflect the scripts actually active on the site.
- Failing to honor withdrawal: A user who withdraws consent, yet the scripts continue running in the background until the next page refresh — or indefinitely.
Practical recommendations for technology companies
Companies operating websites or applications should treat cookie consent management as a cross-departmental project, not a purely legal task. Legal, marketing, and development teams need to work together to map every cookie and script running on the site, classify them into categories, and build a consent flow that accurately reflects what actually happens in the site's code.
It is worth reviewing an existing consent framework against three key questions: Does it distinguish between different cookie categories? Do marketing and profiling cookies receive a separate consent track, as required under the Privacy Protection Authority's guidance? And is there documentation that can demonstrate, when needed, how and when consent was given?
To the extent a company also serves a European audience, it should consider implementing a separate, stricter opt-in track for those users, consistent with GDPR and ePrivacy Directive requirements. Finally, a cookie policy is a living document — any change in analytics tools, advertising platforms, or new tracking technology requires a corresponding update to the consent framework and policy documentation.
Cookie consent management is no longer a technical detail left solely to the development team. Given the tightened standards under the Privacy Protection Authority's consent guidance, it is now a material component of a company's overall privacy compliance, requiring renewed review and ongoing maintenance.
The information contained in this article is general in nature and does not constitute legal advice. For advice tailored to the specific circumstances of your company, we invite you to contact our firm.