Israeli websites face a wave of class actions over tracking pixels

Privacy lawyers who represent Israeli companies describe a wave of class actions over cookies and tracking code on websites. According to the picture laid out on 10 September 2026, the past two months brought several motions to certify class actions and dozens of pre-suit warning letters. The defendants include the Tiv Taam supermarket chain and the fashion site Shein, both accused of embedding TikTok tracking code that follows what visitors do on the site without telling them or asking for consent. A similar suit was filed against the insurer Migdal in April, and another against a non-bank credit company.

A more detailed example is the motion against the credit company Direct Finance (Mimun Yashar), filed in February 2026 at the Central District Court. It alleges that a TikTok pixel on the company's site collected visitors' email addresses, phone numbers, ID numbers, the options they picked and the buttons they clicked. From that it built a profile that included the visitor's financial and employment situation, and all of it went to TikTok without the visitor knowing.

The defendants are large companies. The tool at the centre of the suits sits on small business websites too. An online shop that runs campaigns on Facebook or TikTok usually installs the platform's pixel to measure sales and build audiences, and that is exactly the code the suits describe.

The document behind the suits

The suits lean on the Privacy Protection Authority's opinion on consent under privacy law, published in final form on 25 February 2026 after about a year of public comment on the draft. Under it, consent has to be informed. The person asked to agree must know what data is collected, for which purposes, which kinds of parties receive it, that they may refuse and what happens if they do, and who controls the database and how to reach them. A vague description of the recipients is not enough.

The opinion separates active consent, where the visitor clicks to agree, from passive consent, where data is collected unless the visitor objects. It requires active consent in certain situations: profiling that the service does not need or that is unrelated to it, a power imbalance between the parties, and direct marketing. Elsewhere either form can work, depending on the circumstances and the type of data. The opinion does not impose a blanket duty of explicit consent for every use of cookies.

Where the lawyers disagree

The plaintiffs read the opinion as requiring the visitor to click "accept" before the code runs, and treat a banner that only informs as insufficient. Lawyers for the companies argue that Israeli law contains no explicit requirement or binding directive for affirmative cookie consent, and that moving to such a regime would create a duty the law never set. The courts will settle that question. Until they do, any site running third-party tracking code is exposed to a warning letter.

Amendment 13 and supervision of online shops

Behind the wave is Amendment 13 to the Privacy Protection Law, in force since 14 August 2025. It gave the Privacy Protection Authority the power to impose significant financial sanctions, after years in which penalties for privacy breaches were negligible.

On 10 December 2025 the Authority announced cross-sector supervision of five sectors, one of them online retail. The questionnaires sent to online shops cover, among other things, the site's privacy policy, its cookie consent mechanism, and whether the consent a visitor gives is genuine.

Checking a small business website

Start with an inventory. Which third-party code runs on the site: a Facebook pixel, a TikTok pixel, an analytics tag, a chat widget. A business that does not know what is installed cannot tell a visitor what is being collected.

Read the privacy policy against the elements the opinion lists: what is collected, for what purpose, which kind of party receives it, what happens if the visitor refuses, and whom to contact. A general line about "business partners" does not meet the requirement to describe the categories of recipients.

For each marketing pixel, ask whether it touches the two situations where the Authority expects active consent: direct marketing, and profiling the service itself does not need. A pixel that builds advertising audiences comes close to both. The cautious setup fires it only after the visitor clicks to agree, with an option to refuse on the same screen.