At the conclusion of the Authority's investigation, Beit Shemesh was found to have violated privacy protection regulations by failing to list the external contractor as a data custodian in the welfare database's definition documents. This omission occurred despite the contractor serving as an external entity that processed personal information on behalf of the municipality and maintained ongoing access to the database systems.
Additionally, deficiencies were found in the data security protocol regarding engagement with external entities. The protocol failed to regulate the purposes of use, types of information permitted for processing, access systems, duration of engagement, and other external contractors. The protocol also lacked references to engagement agreements and the security procedures of those entities.
The Authority rejected the municipality's arguments that the contractor did not qualify as a "custodian" or that the violations stemmed from an "administrative gap in good faith" following the entry into force of Amendment 13 to the law. The Authority determined that the contractor met the definition of "custodian" under the circumstances, having been granted access to the database systems for nearly two years, and that the municipality was required to prepare and comply with the law's provisions and regulations on time.
The original financial penalty for the two violations stood at ₪80,000—₪40,000 per violation—but was reduced to ₪64,000. The reduction was granted because in the five years preceding the violation, no financial penalties or administrative enforcement measures had been imposed on the municipality for violating those same provisions.