Iceland
ComprehensiveAct No. 90/2018 on Data Protection and Processing of Personal Data (implementing GDPR)
Authority: Persónuvernd (Data Protection Authority) | Enforcement: Active | Enacted: July 2018
Overview
Iceland, as an EEA member, directly implements the GDPR through Act No. 90/2018. Persónuvernd has been an active data protection authority since its establishment in 2000, making Iceland one of the earliest countries with dedicated data protection oversight. The Act provides for full GDPR implementation with national adaptations for Icelandic public administration and research.
14-Topic Coverage
Data Protection Authority
Fully AddressedPersónuvernd is the independent supervisory authority established in 2000. Active in enforcement, guidance, and international cooperation within the EEA framework.
Persónuvernd has a long track record dating back to Iceland's 2000 data protection act. The authority handles complaints, conducts investigations, issues fines, and provides guidance. It participates in EEA data protection cooperation and EDPB observer activities.
Consent Requirements
Fully AddressedGDPR consent requirements apply in full. Consent must be freely given, specific, informed, and unambiguous. All six GDPR lawful bases are available.
Iceland implements all GDPR lawful bases. Consent for special category data must be explicit. Persónuvernd has issued guidance on valid consent in the Icelandic context, particularly for health research given Iceland's prominent biobanking and genetics research sector.
Data Subject Rights
Fully AddressedFull GDPR rights: access, rectification, erasure, restriction, data portability, objection, and rights related to automated decision-making.
All GDPR data subject rights are directly applicable. Persónuvernd provides guidance in Icelandic on exercising rights. The Act includes specific provisions on restrictions of rights for research and public interest purposes, balancing data protection with Iceland's important role in genetic and health research.
Cross-Border Transfer
Fully AddressedGDPR transfer mechanisms apply. Free data flow within EEA. Adequacy decisions, SCCs, and BCRs for third-country transfers.
As an EEA member, Iceland enjoys free data flow with EU/EEA countries. For transfers to third countries, all GDPR mechanisms are available. Iceland's small market size means most organisations rely on EU adequacy decisions and SCCs rather than BCRs.
Breach Notification
Fully AddressedMust notify Persónuvernd within 72 hours of breaches likely to result in risk. Notification to data subjects required if high risk.
Iceland implements the standard GDPR breach notification framework. Persónuvernd has published templates and guidance for breach notifications. Given Iceland's small population (~380,000), breaches can have proportionally large impact and receive significant public attention.
DPO Requirements
Fully AddressedDPO required per GDPR criteria: public authorities, organisations with core activities involving large-scale systematic monitoring or special category data processing.
All GDPR DPO requirements apply. Given Iceland's small market, many DPOs serve multiple organisations. Persónuvernd maintains a DPO registry. Government institutions are actively appointing DPOs.
Children's Data
Fully AddressedIceland has set the age of digital consent at 13 for information society services. Persónuvernd provides guidance on children's data in education.
Act 90/2018 sets 13 as the minimum age for consent to information society services. Persónuvernd has focused on children's data in schools and digital services, given high internet penetration among Icelandic youth.
Penalties & Enforcement
Fully AddressedGDPR fines up to EUR 20 million or 4% of global turnover. Persónuvernd can also issue warnings, reprimands, orders, and processing bans.
While Iceland has not issued the largest GDPR fines given its small economy, Persónuvernd actively uses its enforcement toolkit including warnings, compliance orders, and proportionate fines. Enforcement decisions are published and serve as guidance for the Icelandic market.
Sector-Specific Rules
Fully AddressedFinancial sector under FME supervision, health data under the Health Records Act, and telecommunications under the Electronic Communications Act.
Iceland's Health Records Act governs health data with specific provisions for Iceland's genetic research sector. The Act on Biobanks addresses the unique Icelandic Health Sector Database (Íslensk erfðagreining). Financial sector data falls under FME (Financial Supervisory Authority) oversight.
Cookie/Tracking
Fully AddressedePrivacy requirements for cookies implemented through the Electronic Communications Act. Prior consent required for non-essential cookies.
Iceland implements ePrivacy cookie requirements through its Electronic Communications Act. The framework mirrors EU standards. Persónuvernd has provided guidance on cookie consent requirements for Icelandic websites.
AI & Automated Decisions
Fully AddressedGDPR Article 22 rights apply. Right not to be subject to solely automated decisions with legal or significant effects. Iceland follows EU AI governance developments.
GDPR automated decision-making provisions apply directly. Iceland follows EU developments on AI regulation. Persónuvernd has addressed AI-related data protection issues in the context of Iceland's growing tech sector. EU AI Act will apply through EEA Agreement.
Data Localisation
Not AddressedNo data localisation requirement. Free flow of data within EEA. Iceland promotes itself as a data centre location due to renewable energy.
Significant Data Fiduciary
Not AddressedNo equivalent concept. GDPR obligations apply based on processing activities, not organisation classification.
Government Data
Fully AddressedGDPR applies to all government processing. Act 90/2018 includes specific provisions for public administration. Information Act provides freedom of information rights.
Chapter IV of Act 90/2018 addresses processing by public authorities. The Information Act (Upplýsingalög) provides public access to government data. Police and national security processing has separate provisions within the Act.
Key Statistics
- Maximum Penalty
- EUR 20 million or 4% of global turnover (GDPR)
- Sections in Law
- 48
- Authority
- Persónuvernd
Coverage Summary
Quick Navigation
Need Compliance Help?
Our data privacy team can help you navigate Iceland's regulations.
Book a Consultation