ISschema gdpri-v2trajectory: not yet assessedregulated (omnibus)overlaps: AIC
Last updated · 10 categories · 57
claims · 19 sources in the cumulative register
10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
57Claimsbaseline..claims[]
5Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix(sums to 10 rendered categories; click to filter)
Jurisdiction brief
Standing brief, as of 23 August 2026.
Lead Signal
Iceland's most significant data protection development this cycle sits in health-sector enforcement rather than in legislative change. Persónuvernd is confirmed to have fined Primary Health Care in the Capital Area in February 2025 after the organisation granted eleven third parties access to a joint electronic medical records system covering approximately 195,000 individuals without the ministerial permission required for that access, a breach that had persisted for several years before it was addressed. This is a high-confidence, high-materiality finding: it demonstrates that Iceland has a genuine structural weak point in inter-institutional data-sharing controls within the health sector, one that went undetected or unaddressed for an extended period despite the scale of personal data involved.
Other Developments
Persónuvernd's enforcement powers remain at the GDPR-standard ceiling. The authority can impose fines up to EUR 20 million or 4% of annual global turnover for serious violations, the same penalty structure available to EU member-state supervisory authorities, underscoring that the health-sector fine sits within an enforcement framework with substantial headroom relative to the scale of the underlying breach.
Two EU-level procedural and substantive reforms are approaching that will affect obligations relevant to Iceland once incorporated. The EU has adopted Regulation (EU) 2025/2518, laying down additional procedural rules for cross-border GDPR enforcement cooperation among EEA data protection authorities including Persónuvernd, applicable from April 2027. Separately, the EU's proposed Digital Omnibus (2025/0360 (COD)) would, if adopted, extend the deadline for notifying supervisory authorities of a breach from 72 to 96 hours, but only for high-risk breaches; this remains a proposal rather than a binding rule and has not yet taken effect.
The EU AI Act's applicability to Iceland remains pending. Its incorporation into the EEA Agreement has not occurred, meaning no Icelandic AI-specific risk-assessment duty is currently in force under that instrument.
Cross-Monitor Connections
The pending EU AI Act incorporation is directly relevant to the artificial-intelligence monitor's coverage of Iceland: once incorporated via the EEA Agreement, Icelandic organisations would become subject to AI risk-assessment obligations that do not currently apply, a development the AI monitor should track for its own incorporation-timing assessment rather than this monitor re-analysing AI-specific risk methodology. The health-sector enforcement finding, while a data-protection matter in the first instance, may also be relevant to broader institutional-governance monitoring to the extent regulatory failures in inter-institutional data-sharing controls recur in other sectoral contexts, though this cycle's evidence is specific to the health sector and should not be generalised beyond it.
Outlook
Iceland's data-protection posture remains structurally stable at the level of its core framework, but three vectors are worth tracking going forward: the practical follow-through from the Persónuvernd health-sector fine, the April 2027 application of Regulation (EU) 2025/2518's cross-border enforcement procedures, and whether the Digital Omnibus proposal or the AI Act's EEA incorporation move from proposed or pending status toward adoption. None of these is confirmed to resolve on a specific date this cycle. This is intelligence-register orientation on the operating environment, not legal advice or a compliance instruction.
trust tier: ai_unverified
Standing brief, as of 23 August 2026.
Regulatory Status
Iceland's most material data-protection development this cycle is enforcement rather than legislative: Persónuvernd fined Primary Health Care in the Capital Area in February 2025 after the organisation granted eleven third parties unauthorised access to a joint electronic medical records system covering approximately 195,000 individuals, a breach persisting for several years. Persónuvernd's penalty ceiling for serious violations remains EUR 20 million or 4% of global turnover, the GDPR-standard maximum. Two EU-level instruments are on the near-term horizon: Regulation (EU) 2025/2518, applicable April 2027, formalising cross-border GDPR enforcement cooperation among EEA authorities; and the proposed Digital Omnibus (2025/0360 (COD)), which would extend high-risk breach-notification deadlines to 96 hours if adopted. Separately, the EU AI Act's incorporation into the EEA Agreement, and therefore its Icelandic applicability, remains pending.
Outlook
Iceland's core data-protection architecture is stable, but organisations should track the April 2027 application of Regulation (EU) 2025/2518, the progress of the Digital Omnibus proposal, and the timing of AI Act incorporation, alongside any follow-through from the health-sector enforcement action. This is illustrative orientation, not legal advice.
10 of 10 categories
Signal
Density
Selections OR within a group, AND across groups. Press / to search.
GDPR is directly incorporated and actively enforced by a functioning DPA with a multi-year enforcement track record.
Primary frameworkAct No. 90/2018 on Data Protection and the Processing of Personal Data (GDPR (EU) 2016/679 as incorporated into the EEA Agreement, Annex XI)
Traffic-light rationale — GreenGDPR is directly incorporated and actively enforced by a functioning DPA with a multi-year enforcement track record.
Sub-modules (5)
Regulator And AuthorityGreen
Persónuvernd is the independent statutory DPA supervising GDPR/Act 90/2018 compliance.
Claims (1):
Persónuvernd is Iceland's independent Data Protection Authority responsible for supervising compliance with Act No. 90/2018 and the GDPR as incorporated into Icelandic law, with powers to investigate and issue administrative fines against controllers and processors.
Act And InstrumentsGreen
Act No. 90/2018 is the operative implementing statute, cited jointly with GDPR articles in all enforcement decisions.
Claims (1):
Act No. 90/2018 on Data Protection and the Processing of Personal Data is Iceland's primary data protection statute, giving domestic effect to the GDPR and forming the joint legal basis cited alongside GDPR articles in Persónuvernd enforcement decisions.
Material ScopeGreen
Material scope mirrors GDPR via EEA Agreement Annex XI incorporation.
Claims (1):
The GDPR was incorporated into the EEA Agreement (Annex XI) and applies comprehensively in Iceland as an EEA EFTA state, covering the same material scope of personal data processing as within the EU.
Territorial ScopeGreen
Comprehensive implementation gives Icelandic data subjects protection equivalent to EU Member States.
Claims (1):
As an EEA EFTA state, Iceland has implemented EU data protection rules comprehensively such that individuals in Iceland benefit from the same level of protection as individuals in EU Member States.
Regulator Registration And FilingAmber
No general upfront registration regime; Persónuvernd instead operates an online breach-notification portal/form.
Claims (1):
Persónuvernd operates a dedicated online notification portal/form through which controllers submit mandatory personal data breach notifications, rather than requiring general upfront processing-notification registration filings.
Category narrative47 words
Iceland is an EEA/EFTA state that has incorporated the GDPR into its domestic legal order via Act No. 90/2018 on Data Protection and the Processing of Personal Data, giving Persónuvernd (the Icelandic Data Protection Authority) enforcement powers materially equivalent to those of an EU Member State DPA.
Sources and claims (5)
ConfirmedDataGuidance — Persónuvernd is Iceland's independent Data Protection Authority responsible for supervising compliance with Act No. 90/2018 and the GDPR as incorporated into Icelandic law, with powers to investigate and issue administrative fines against controllers and processors.observed
ConfirmedPersónuvernd (official translation) — Act No. 90/2018 on Data Protection and the Processing of Personal Data is Iceland's primary data protection statute, giving domestic effect to the GDPR and forming the joint legal basis cited alongside GDPR articles in Persónuvernd enforcement decisions.observed
ConfirmedEDPS — The GDPR was incorporated into the EEA Agreement (Annex XI) and applies comprehensively in Iceland as an EEA EFTA state, covering the same material scope of personal data processing as within the EU.observed
ConfirmedEDPS — As an EEA EFTA state, Iceland has implemented EU data protection rules comprehensively such that individuals in Iceland benefit from the same level of protection as individuals in EU Member States.observed
ProbableEuropean Data Protection Board — Persónuvernd operates a dedicated online notification portal/form through which controllers submit mandatory personal data breach notifications, rather than requiring general upfront processing-notification registration filings.observed
Persónuvernd enforcement decisions confirm that lawfulness of processing under Article 6 GDPR (as applied via Act No. 90/2018) is directly enforceable, including in the City of Reykjavík Seesaw decision where Article 6 GDPR was found violated.
Consent ThresholdsGreen
Article 7 GDPR consent-validity standards enforced against government/vendor processing.
Claims (1):
Persónuvernd applies GDPR Article 7 consent-validity conditions directly, as demonstrated in its fine against the Ministry of Industries and Innovation and YAY ehf. for the digital gift-card app, which cited Article 7 (conditions for consent) among the infringements.
Special CategoriesGreen
Article 8 of Act 90/2018 provides enhanced protection for special-category and children's data.
Claims (1):
Article 8 of Act No. 90/2018 provides enhanced protections for special categories of personal data, including children's data, as applied in Persónuvernd's fine against the City of Reykjavík for violations of Article 8(1) subparagraphs of the Act concerning student data in the Seesaw system.
Pseudonymisation And AnonymisationAmber
Article 18(1) of Act 90/2018 provides research-purpose derogations conditioned on separation/pseudonymisation safeguards.
Claims (1):
Article 18(1) of Act No. 90/2018 permits derogations from certain GDPR data-subject rights where personal data are processed solely for research or statistical purposes, subject to pseudonymisation/separation safeguards.
Category narrative29 words
Lawful bases, consent standards, and special-category protections apply directly under GDPR Articles 5-9 as incorporated via Act No. 90/2018, with Iceland-specific research derogations under Article 18(1) of the Act.
Sources and claims (4)
ConfirmedDataGuidance — Persónuvernd enforcement decisions confirm that lawfulness of processing under Article 6 GDPR (as applied via Act No. 90/2018) is directly enforceable, including in the City of Reykjavík Seesaw decision where Article 6 GDPR was found violated.observed
ConfirmedEuropean Data Protection Board — Persónuvernd applies GDPR Article 7 consent-validity conditions directly, as demonstrated in its fine against the Ministry of Industries and Innovation and YAY ehf. for the digital gift-card app, which cited Article 7 (conditions for consent) among the infringements.observed
ConfirmedDataGuidance — Article 8 of Act No. 90/2018 provides enhanced protections for special categories of personal data, including children's data, as applied in Persónuvernd's fine against the City of Reykjavík for violations of Article 8(1) subparagraphs of the Act concerning student data in the Seesaw system.observed
ProbableEuropean Data Protection Board — Article 18(1) of Act No. 90/2018 permits derogations from certain GDPR data-subject rights where personal data are processed solely for research or statistical purposes, subject to pseudonymisation/separation safeguards.observed
Rights are directly incorporated; EDPB coordinated actions (access 2025, erasure 2025-26) evidence active supervisory engagement in the EEA, including Iceland.
Primary frameworkGDPR Arts. 12-22 as incorporated via Act No. 90/2018
Traffic-light rationale — GreenRights are directly incorporated; EDPB coordinated actions (access 2025, erasure 2025-26) evidence active supervisory engagement in the EEA, including Iceland.
Persónuvernd participates as an EEA supervisory authority within the EDPB's Coordinated Enforcement Framework, which ran a 2025 action examining controllers' implementation of the right of access under Article 15 GDPR.
Rectification And ErasureAmber
Article 17 GDPR erasure right subject to 2025-26 EDPB coordinated action across EEA DPAs.
Claims (1):
The EDPB launched a coordinated action in 2025-2026 on the right to erasure (Article 17 GDPR) applicable to participating EEA supervisory authorities, with a report on outcomes expected to be adopted in the coming months.
Restriction And ObjectionAmber
Article 18(1) Act 90/2018 disapplies restriction/objection rights for research-only processing, subject to safeguards.
Claims (1):
Article 18(1) of Act No. 90/2018 disapplies the rights to access, rectification, restriction of processing, and objection where personal data are processed exclusively for research or statistical purposes, subject to safeguards.
Data PortabilityAmber
Article 20 GDPR portability applies without a documented Icelandic-specific derogation.
Claims (1):
The right to data portability under GDPR Article 20 applies directly in Iceland via incorporation of the GDPR through Act No. 90/2018, without a documented Icelandic-specific derogation identified in available sources.
Deadlines And Response WindowsAmber
Standard one-month (extendable) GDPR response window applies; no Iceland-specific modification found.
Claims (1):
Controllers in Iceland must respond to data subject rights requests within the GDPR's standard one-month period (extendable by up to two further months for complex requests), incorporated without modification via Act No. 90/2018.
Category narrative36 words
Access, rectification/erasure, restriction/objection, and portability rights apply per GDPR Arts. 13-22 via Act No. 90/2018, subject to a research-purpose carve-out under Article 18(1) of the Act; no Iceland-specific deviation from GDPR's standard response deadlines was located.
Sources and claims (5)
ProbableEuropean Data Protection Board — Persónuvernd participates as an EEA supervisory authority within the EDPB's Coordinated Enforcement Framework, which ran a 2025 action examining controllers' implementation of the right of access under Article 15 GDPR.observed
ProbableEuropean Data Protection Board — The EDPB launched a coordinated action in 2025-2026 on the right to erasure (Article 17 GDPR) applicable to participating EEA supervisory authorities, with a report on outcomes expected to be adopted in the coming months.observed
ProbableEuropean Data Protection Board — Article 18(1) of Act No. 90/2018 disapplies the rights to access, rectification, restriction of processing, and objection where personal data are processed exclusively for research or statistical purposes, subject to safeguards.observed
ProbablePersónuvernd (official translation) — The right to data portability under GDPR Article 20 applies directly in Iceland via incorporation of the GDPR through Act No. 90/2018, without a documented Icelandic-specific derogation identified in available sources.observed
ProbablePersónuvernd (official translation) — Controllers in Iceland must respond to data subject rights requests within the GDPR's standard one-month period (extendable by up to two further months for complex requests), incorporated without modification via Act No. 90/2018.observed
Core obligations are enforced (multiple fines), but repeated findings of DPIA, DPO-independence, and security failures (Reykjavík, InfoMentor, ice-cream-parlour cases) indicate persistent compliance gaps among controllers.
Traffic-light rationale — AmberCore obligations are enforced (multiple fines), but repeated findings of DPIA, DPO-independence, and security failures (Reykjavík, InfoMentor, ice-cream-parlour cases) indicate persistent compliance gaps among controllers.
Sub-modules (7)
Accountability And DpiaAmber
DPIA (Art. 35) failures found in the Reykjavík Seesaw case.
Claims (1):
Persónuvernd found the City of Reykjavík in violation of Article 35(1) GDPR (DPIA obligation) and Article 25(1)/(3) (data protection by design) in its use of the Seesaw educational system, resulting in a fine of ISK 5 million.
Dpo RequirementsAmber
DPO independence/involvement failures found against City of Reykjavík.
Claims (1):
Persónuvernd found that the City of Reykjavík's DPO failed to be involved in an appropriate and timely manner, lacked adequate independence, and had unresolved conflicts of interest, in violation of Article 35(3) of Act No. 90/2018 and Articles 38 and 39 GDPR.
Ropa RequirementsGreen
Article 30 ROPA duties apply via incorporation; Persónuvernd has published ROPA/DPA templates.
Claims (1):
Records-of-processing obligations under GDPR Article 30 apply to controllers and processors in Iceland via direct incorporation through Act No. 90/2018, and Persónuvernd has published templates for data processing agreements and records of processing to support compliance.
Joint Controller ArrangementsAmber
Processor-contract (Art. 28(3)) obligations enforced in the YAY ehf. case.
Claims (1):
Persónuvernd's enforcement action against the Ministry of Industries and Innovation and YAY ehf. addressed processor-contract obligations under Article 28(3) GDPR in the context of a government-vendor digital gift-card processing arrangement.
Security MeasuresAmber
Security/transparency failures fined in the employee-surveillance case.
Claims (1):
Persónuvernd fined a company operating ice cream parlours for failing to implement adequate security and transparency measures around employee video surveillance, finding infringements of Article 13 GDPR and related security/transparency provisions.
Breach NotificationAmber
Dedicated breach-notification portal exists; InfoMentor fined for a breach affecting 424 children.
Claims (1):
Persónuvernd operates a dedicated online breach-notification form and fined InfoMentor ISK 3.5 million for a security failure resulting in a breach affecting 424 children's personal data on an education platform.
Retention And DisposalAmber
Retention/erasure (Art. 17(1) of the Act) violation found in the Seesaw case.
Claims (1):
Persónuvernd's decision against the City of Reykjavík found violations of Article 17(1) of Act No. 90/2018 (data retention/erasure obligations) in connection with the Seesaw educational system.
Category narrative34 words
Accountability, DPIA, DPO, ROPA, security, breach-notification, and retention duties under GDPR Arts. 24-35 apply directly via Act No. 90/2018, with a substantial and growing Persónuvernd enforcement record across education, health, employment, and public-sector processing.
No new data since the standing brief. 1 periodic run re-emitted it unchanged.
Sources and claims (7)
ConfirmedDataGuidance — Persónuvernd found the City of Reykjavík in violation of Article 35(1) GDPR (DPIA obligation) and Article 25(1)/(3) (data protection by design) in its use of the Seesaw educational system, resulting in a fine of ISK 5 million.observed
ConfirmedDataGuidance — Persónuvernd found that the City of Reykjavík's DPO failed to be involved in an appropriate and timely manner, lacked adequate independence, and had unresolved conflicts of interest, in violation of Article 35(3) of Act No. 90/2018 and Articles 38 and 39 GDPR.observed
ProbableEuropean Data Protection Board — Records-of-processing obligations under GDPR Article 30 apply to controllers and processors in Iceland via direct incorporation through Act No. 90/2018, and Persónuvernd has published templates for data processing agreements and records of processing to support compliance.observed
ConfirmedEuropean Data Protection Board — Persónuvernd's enforcement action against the Ministry of Industries and Innovation and YAY ehf. addressed processor-contract obligations under Article 28(3) GDPR in the context of a government-vendor digital gift-card processing arrangement.observed
ConfirmedEuropean Data Protection Board — Persónuvernd fined a company operating ice cream parlours for failing to implement adequate security and transparency measures around employee video surveillance, finding infringements of Article 13 GDPR and related security/transparency provisions.observed
ConfirmedDataGuidance — Persónuvernd operates a dedicated online breach-notification form and fined InfoMentor ISK 3.5 million for a security failure resulting in a breach affecting 424 children's personal data on an education platform.observed
ConfirmedDataGuidance — Persónuvernd's decision against the City of Reykjavík found violations of Article 17(1) of Act No. 90/2018 (data retention/erasure obligations) in connection with the Seesaw educational system.observed
Traffic-light rationale — AmberFramework is fully harmonised (green) but enforcement shows recurring onward-transfer risk findings (amber) in ed-tech/cloud processing.
Sub-modules (6)
Transfer MechanismsAmber
Chapter V transfer mechanisms apply directly; onward-transfer risk actively scrutinised.
Claims (1):
Persónuvernd found that the City of Reykjavík's use of the Seesaw system created a high risk of personal data being transferred to the United States and processed without adequate protection, in violation of Articles 32, 35(1), and 46 GDPR.
Adequacy ReceivedGreen
EU-to-Iceland transfers are not third-country transfers due to EEA incorporation.
Claims (1):
Because the GDPR and its related adequacy decisions are incorporated into the EEA Agreement, transfers of personal data from EU Member States to Iceland are not treated as third-country transfers and do not require a separate adequacy decision.
Adequacy GrantedGreen
Iceland relies on EU Commission adequacy decisions incorporated into the EEA Agreement rather than issuing independent adequacy findings.
Claims (1):
As an EEA EFTA state applying the GDPR directly, Iceland does not issue independent third-country adequacy decisions of its own; it relies on European Commission adequacy decisions incorporated into the EEA Agreement.
Sccs And BcrsGreen
SCCs/BCRs approved under GDPR are directly available to Icelandic controllers/processors.
Claims (1):
Standard Contractual Clauses and Binding Corporate Rules approved under the GDPR are directly available as transfer mechanisms for Icelandic controllers and processors by virtue of the GDPR's incorporation into the EEA Agreement.
Transfer Impact AssessmentAmber
Persónuvernd's Seesaw decision reflects TIA-style expectations for onward transfer risk to the US.
Claims (1):
The Reykjavík Seesaw decision shows Persónuvernd expects controllers to assess and mitigate the risk of onward transfer to third countries such as the United States, consistent with a transfer-impact-assessment style analysis under GDPR Article 46.
Data LocalisationAmber
No dedicated Icelandic data-localisation mandate identified beyond GDPR Chapter V.
Claims (1):
No general data-localisation mandate beyond the GDPR's Chapter V cross-border transfer restrictions was identified for Iceland in available sources.
Category narrative40 words
Iceland applies GDPR Chapter V transfer rules directly via EEA Agreement incorporation; it neither issues nor requires separate third-country adequacy decisions relative to the EU/EEA, and its DPA has actively scrutinised onward transfers (notably to the US) in enforcement decisions.
No new data since the standing brief. 1 periodic run re-emitted it unchanged.
Sources and claims (6)
ConfirmedDataGuidance — Persónuvernd found that the City of Reykjavík's use of the Seesaw system created a high risk of personal data being transferred to the United States and processed without adequate protection, in violation of Articles 32, 35(1), and 46 GDPR.observed
ConfirmedEDPS — Because the GDPR and its related adequacy decisions are incorporated into the EEA Agreement, transfers of personal data from EU Member States to Iceland are not treated as third-country transfers and do not require a separate adequacy decision.observed
ProbableEDPS — As an EEA EFTA state applying the GDPR directly, Iceland does not issue independent third-country adequacy decisions of its own; it relies on European Commission adequacy decisions incorporated into the EEA Agreement.observed
ProbableEDPS — Standard Contractual Clauses and Binding Corporate Rules approved under the GDPR are directly available as transfer mechanisms for Icelandic controllers and processors by virtue of the GDPR's incorporation into the EEA Agreement.observed
ProbableDataGuidance — The Reykjavík Seesaw decision shows Persónuvernd expects controllers to assess and mitigate the risk of onward transfer to third countries such as the United States, consistent with a transfer-impact-assessment style analysis under GDPR Article 46.observed
UncertainPersónuvernd (official translation) — No general data-localisation mandate beyond the GDPR's Chapter V cross-border transfer restrictions was identified for Iceland in available sources.observed
Traffic-light rationale — AmberStrong evidence in education and health; gaps in financial, telecoms, credit, and insurance sub-modules necessitate primary-source escalation.
Sub-modules (7)
Financial Sector OverlayRed
No Iceland-specific financial-sector DP overlay identified.
Claims (1):
Financial-sector personal data processing in Iceland appears to be governed by the general GDPR/Act No. 90/2018 framework without a distinct financial-sector data protection overlay identified in available guidance to date.
Health Sector OverlayAmber
Genetic/health research processing scrutinised in the Landspítali/Íslensk erfðagreining case.
Claims (1):
Persónuvernd found that Landspítali, Icelandic Genetics ehf., and Íslensk erfðagreining unlawfully processed COVID-19 patients' samples and data for genetic research without proper authorisation, in violation of Article 8 of Act No. 90/2018 and Article 5 GDPR.
Telecoms And EprivacyRed
No Iceland-specific ePrivacy enforcement decision identified.
Claims (1):
The ePrivacy framework for electronic communications applies in Iceland as an EEA state, though no Iceland-specific ePrivacy/cookie enforcement decision was identified in available sources.
Persónuvernd's fine against an ice-cream-parlour operator for unlawful employee video surveillance demonstrates active enforcement of employment-context data protection obligations, including transparency and proportionality requirements.
Credit And ScoringRed
No Iceland-specific credit-scoring DP finding identified.
Claims (1):
No Iceland-specific credit-scoring or automated creditworthiness-assessment data protection finding was identified in available sources.
EducationAmber
Sustained enforcement against ed-tech/cloud vendors and municipalities.
Claims (1):
Persónuvernd fined five municipalities a combined ISK 12.8 million over alleged improper processing of primary-school student data through Google Cloud's education technology services.
InsuranceRed
No Iceland-specific insurance-sector DP finding identified.
Claims (1):
No Iceland-specific insurance-sector data protection finding or overlay was identified in available sources.
Category narrative34 words
The clearest sectoral overlay evidenced is education (repeated ed-tech/cloud-services fines) and health/genetic research (COVID-19 sample processing); financial, telecoms/ePrivacy, credit-scoring, and insurance overlays were not evidenced by dedicated Icelandic enforcement or guidance in available sources.
No new data since the standing brief. 1 periodic run re-emitted it unchanged.
Sources and claims (7)
UncertainPersónuvernd (official translation) — Financial-sector personal data processing in Iceland appears to be governed by the general GDPR/Act No. 90/2018 framework without a distinct financial-sector data protection overlay identified in available guidance to date.observed
ConfirmedDataGuidance — Persónuvernd found that Landspítali, Icelandic Genetics ehf., and Íslensk erfðagreining unlawfully processed COVID-19 patients' samples and data for genetic research without proper authorisation, in violation of Article 8 of Act No. 90/2018 and Article 5 GDPR.observed
UncertainPersónuvernd (official translation) — The ePrivacy framework for electronic communications applies in Iceland as an EEA state, though no Iceland-specific ePrivacy/cookie enforcement decision was identified in available sources.observed
ConfirmedEuropean Data Protection Board — Persónuvernd's fine against an ice-cream-parlour operator for unlawful employee video surveillance demonstrates active enforcement of employment-context data protection obligations, including transparency and proportionality requirements.observed
SpeculativePersónuvernd (official translation) — No Iceland-specific credit-scoring or automated creditworthiness-assessment data protection finding was identified in available sources.observed
ConfirmedIAPP — Persónuvernd fined five municipalities a combined ISK 12.8 million over alleged improper processing of primary-school student data through Google Cloud's education technology services.observed
SpeculativePersónuvernd (official translation) — No Iceland-specific insurance-sector data protection finding or overlay was identified in available sources.observed
Traffic-light rationale — RedFramework exists in principle (GDPR incorporation) but no dedicated Icelandic enforcement or guidance evidence found for most adtech sub-modules.
Sub-modules (6)
Cookies And TrackersAmber
General consent standards apply; no Iceland-specific cookie enforcement located.
Claims (1):
Cookie and tracker consent requirements in Iceland derive from GDPR consent standards under Act No. 90/2018 operating alongside the ePrivacy framework, though no Iceland-specific cookie-enforcement decision was located in available sources.
Dark PatternsRed
No Iceland-specific dark-pattern finding identified.
Claims (1):
No Iceland-specific dark-pattern prohibition or enforcement decision was identified in available sources.
Opt Out SignalsRed
No Iceland-specific opt-out-signal (e.g., GPC) guidance identified.
Claims (1):
No Iceland-specific guidance on opt-out signals such as Global Privacy Control was identified in available sources.
Clean Rooms And DcrRed
No Iceland-specific clean-room/DCR guidance identified.
Claims (1):
No Iceland-specific guidance on data clean rooms or data-collaboration-room arrangements was identified in available sources.
Cross Context AdvertisingRed
No Iceland-specific cross-context advertising finding identified.
Claims (1):
No Iceland-specific cross-context advertising or 'sale'/'share' of personal data finding was identified in available sources.
Direct MarketingAmber
General Art. 21 objection right applies; no Iceland-specific direct-marketing enforcement located.
Claims (1):
Direct marketing processing in Iceland is subject to GDPR consent/legitimate-interest standards and the right to object under Article 21 GDPR as incorporated via Act No. 90/2018; no Iceland-specific direct-marketing enforcement decision was identified.
Category narrative38 words
General GDPR consent and objection standards apply to cookies, direct marketing, and commercial profiling in Iceland via Act No. 90/2018, but no Iceland-specific enforcement decisions on cookies/trackers, dark patterns, opt-out signals, clean rooms, or cross-context advertising were located.
Sources and claims (6)
UncertainPersónuvernd (official translation) — Cookie and tracker consent requirements in Iceland derive from GDPR consent standards under Act No. 90/2018 operating alongside the ePrivacy framework, though no Iceland-specific cookie-enforcement decision was located in available sources.observed
SpeculativePersónuvernd (official translation) — No Iceland-specific dark-pattern prohibition or enforcement decision was identified in available sources.observed
SpeculativePersónuvernd (official translation) — No Iceland-specific guidance on opt-out signals such as Global Privacy Control was identified in available sources.observed
SpeculativePersónuvernd (official translation) — No Iceland-specific guidance on data clean rooms or data-collaboration-room arrangements was identified in available sources.observed
SpeculativePersónuvernd (official translation) — No Iceland-specific cross-context advertising or 'sale'/'share' of personal data finding was identified in available sources.observed
UncertainPersónuvernd (official translation) — Direct marketing processing in Iceland is subject to GDPR consent/legitimate-interest standards and the right to object under Article 21 GDPR as incorporated via Act No. 90/2018; no Iceland-specific direct-marketing enforcement decision was identified.observed
Genetic data and emerging AI-related engagement are evidenced; biometric regime and surveillance carve-outs remain gaps requiring primary-source escalation.
Primary frameworkGDPR Arts. 9, 22 as incorporated via Act No. 90/2018
Article 22 GDPR profiling/automated-decision-making restrictions apply directly in Iceland via Act No. 90/2018, though no Iceland-specific Persónuvernd enforcement decision addressing Article 22 was located in available sources.
Automated Decision Making TransparencyAmber
General GDPR transparency duties apply; no dedicated Icelandic ADM transparency case identified.
Claims (1):
General GDPR transparency duties regarding automated decision-making apply via Act No. 90/2018, though no dedicated Icelandic ADM-transparency enforcement case was identified in available sources.
Ai Risk AssessmentsAmber
Persónuvernd co-signed a February 2026 multilateral joint statement on AI-generated imagery risks.
Claims (1):
Persónuvernd, together with other data protection and privacy authorities, co-signed a February 2026 joint statement on AI-generated imagery emphasising that AI content-generation systems must be developed and used in accordance with applicable data protection and privacy rules, with specific attention to risks facing children and vulnerable groups.
Biometric RegimeRed
No Iceland-specific biometric-data regime or enforcement decision identified.
Claims (1):
No Iceland-specific biometric-data (facial recognition, fingerprint, gait) regime or enforcement decision was identified in available sources.
Genetic DataAmber
Genetic/biological sample processing scrutinised in the COVID-19 research case.
Claims (1):
Persónuvernd's decision regarding Landspítali, Icelandic Genetics, and Íslensk erfðagreining addressed unlawful processing of genetic/biological sample data for COVID-19 research, finding breaches of Article 8 of Act No. 90/2018 (special categories) and Article 5 GDPR.
State Surveillance CarveoutsRed
No Iceland-specific national-security/surveillance carve-out analysis identified.
Claims (1):
No Iceland-specific analysis of national-security or state-surveillance carve-outs from GDPR/Act No. 90/2018 was identified in available sources.
Category narrative44 words
Article 22 GDPR profiling/ADM restrictions and genetic-data protections apply via Act No. 90/2018, evidenced concretely in the Landspítali genetic-research case; Persónuvernd has also co-signed a 2026 multilateral statement on AI-generated imagery risks. Biometric-specific regime detail and state-surveillance carve-outs were not evidenced in available sources.
No new data since the standing brief. 1 periodic run re-emitted it unchanged.
Sources and claims (6)
UncertainPersónuvernd (official translation) — Article 22 GDPR profiling/automated-decision-making restrictions apply directly in Iceland via Act No. 90/2018, though no Iceland-specific Persónuvernd enforcement decision addressing Article 22 was located in available sources.observed
UncertainPersónuvernd (official translation) — General GDPR transparency duties regarding automated decision-making apply via Act No. 90/2018, though no dedicated Icelandic ADM-transparency enforcement case was identified in available sources.observed
ConfirmedEuropean Data Protection Supervisor / signatory authorities — Persónuvernd, together with other data protection and privacy authorities, co-signed a February 2026 joint statement on AI-generated imagery emphasising that AI content-generation systems must be developed and used in accordance with applicable data protection and privacy rules, with specific attention to risks facing children and vulnerable groups.observed
SpeculativePersónuvernd (official translation) — No Iceland-specific biometric-data (facial recognition, fingerprint, gait) regime or enforcement decision was identified in available sources.observed
ConfirmedDataGuidance — Persónuvernd's decision regarding Landspítali, Icelandic Genetics, and Íslensk erfðagreining addressed unlawful processing of genetic/biological sample data for COVID-19 research, finding breaches of Article 8 of Act No. 90/2018 (special categories) and Article 5 GDPR.observed
SpeculativePersónuvernd (official translation) — No Iceland-specific analysis of national-security or state-surveillance carve-outs from GDPR/Act No. 90/2018 was identified in available sources.observed
Traffic-light rationale — AmberStrong, repeated education-sector enforcement (green signal) offset by gaps in age-verification, minor-profiling, and dependent-adult sub-modules (red signal), yielding an overall amber rating.
Sub-modules (5)
Age VerificationRed
No Iceland-specific age-verification mechanism or enforcement identified.
Claims (1):
No Iceland-specific age-verification mechanism or Persónuvernd enforcement decision on age verification was identified in available sources.
Parental ConsentAmber
GDPR/Act 90/2018 parental-consent thresholds apply generally; no Iceland-specific enforcement case located.
Claims (1):
Act No. 90/2018 and the GDPR require parental consent for information-society services offered directly to children below the relevant age threshold, applied in Iceland via direct GDPR incorporation, though no Iceland-specific enforcement decision on the parental-consent threshold itself was located.
Minor Profiling BansRed
No Iceland-specific minor-profiling ban or enforcement identified.
Claims (1):
No Iceland-specific ban or enforcement decision on profiling of minors was identified in available sources.
Education SettingsAmber
Persónuvernd has repeatedly fined education-sector controllers/processors over children's data.
Claims (1):
Persónuvernd fined InfoMentor ISK 3.5 million after unauthorised parties accessed the personal data of 424 children through the company's education platform, treating children's data as meriting special protection under Act No. 90/2018.
Dependent AdultsRed
No Iceland-specific dependent-adult/elderly protection finding identified.
Claims (1):
No Iceland-specific dependent-adult (elderly/mentally incapacitated) data protection finding was identified in available sources.
Category narrative41 words
Children's data receives heightened protection under Act No. 90/2018, evidenced by a consistent Persónuvernd enforcement pattern targeting education-sector processors (Seesaw, InfoMentor, Google Cloud in schools) and underage employees (ice-cream-parlour surveillance). Age-verification thresholds, minor-profiling bans, and dependent-adult protections were not independently evidenced.
Sources and claims (5)
SpeculativePersónuvernd (official translation) — No Iceland-specific age-verification mechanism or Persónuvernd enforcement decision on age verification was identified in available sources.observed
UncertainPersónuvernd (official translation) — Act No. 90/2018 and the GDPR require parental consent for information-society services offered directly to children below the relevant age threshold, applied in Iceland via direct GDPR incorporation, though no Iceland-specific enforcement decision on the parental-consent threshold itself was located.observed
SpeculativePersónuvernd (official translation) — No Iceland-specific ban or enforcement decision on profiling of minors was identified in available sources.observed
ConfirmedDataGuidance — Persónuvernd fined InfoMentor ISK 3.5 million after unauthorised parties accessed the personal data of 424 children through the company's education platform, treating children's data as meriting special protection under Act No. 90/2018.observed
SpeculativePersónuvernd (official translation) — No Iceland-specific dependent-adult (elderly/mentally incapacitated) data protection finding was identified in available sources.observed
Active enforcement and appeal pathways exist (green signal) but self-reported capacity constraints and unresolved collective-redress/private-right-of-action gaps (amber/red signals) temper the overall rating.
Traffic-light rationale — AmberActive enforcement and appeal pathways exist (green signal) but self-reported capacity constraints and unresolved collective-redress/private-right-of-action gaps (amber/red signals) temper the overall rating.
Sub-modules (6)
Regulator Powers And PenaltiesGreen
Persónuvernd exercises investigative and fining powers analogous to GDPR Art. 83.
Claims (1):
Persónuvernd has issued multiple administrative fines under Act No. 90/2018 and the GDPR, ranging from ISK 1.5 million to ISK 12.8 million in identified cases, exercising investigative and sanctioning powers analogous to Article 83 GDPR's maximum-fine provisions.
Enforcement Activity IndexGreen
Multiple fines/findings across sectors documented over recent years.
Claims (1):
Persónuvernd's recent enforcement record includes fines against the City of Reykjavík (Seesaw), InfoMentor (education breach), an employer operating ice cream parlours (employee surveillance), the Ministry of Industries and Innovation/YAY ehf. (digital gift-card app), five municipalities (Google Cloud in schools), and an unlawfulness finding against Landspítali/Icelandic Genetics/Íslensk erfðagreining (COVID-19 genetic research).
Regulator Funding And CapacityAmber
Self-reported staffing constraints relative to caseload.
Claims (1):
Persónuvernd has reported resource constraints, noting it is divided into sub-units of around 3-5 staff members each with limited backup capacity, while handling several hundred open cases (approximately 800 open registered cases as reported in its GDPR Article 97 evaluation questionnaire response).
Collective Redress And Class ActionsRed
No Iceland-specific collective-redress/class-action mechanism for DP claims identified.
Claims (1):
No Iceland-specific collective-redress or class-action mechanism for data protection claims was identified in available sources.
Private Right Of ActionAmber
Judicial review of Persónuvernd decisions is available, including Supreme Court review.
Claims (1):
Data subjects in Iceland may lodge complaints with Persónuvernd and seek judicial remedies before Icelandic courts, including appeal of Persónuvernd decisions; a reported Icelandic Supreme Court ruling partially confirmed a Persónuvernd decision, evidencing an available judicial-review pathway.
Recent Developments 180DAmber
February 2026 multilateral joint statement on AI-generated imagery co-signed by Persónuvernd.
Claims (1):
In February 2026, Persónuvernd (represented by Data Protection Commissioner Helga Þórisdóttir and Head of International Affairs & Guidance Helga Sigríður Þórhallsdóttir) co-signed a multilateral joint statement with other data protection and privacy authorities addressing risks from AI-generated imagery, including harms to children and vulnerable groups.
Category narrative54 words
Persónuvernd has a sustained multi-year enforcement record (fines from ISK 1.5M to ISK 12.8M across education, health, employment, and public-sector cases) but operates under acknowledged resource constraints; judicial review of its decisions is available (Icelandic Supreme Court review reported), and it participates in cross-border EEA/international regulatory coordination including a February 2026 joint AI statement.
No new data since the standing brief. 1 periodic run re-emitted it unchanged.
Sources and claims (6)
ConfirmedIAPP — Persónuvernd has issued multiple administrative fines under Act No. 90/2018 and the GDPR, ranging from ISK 1.5 million to ISK 12.8 million in identified cases, exercising investigative and sanctioning powers analogous to Article 83 GDPR's maximum-fine provisions.observed
ConfirmedIAPP — Persónuvernd's recent enforcement record includes fines against the City of Reykjavík (Seesaw), InfoMentor (education breach), an employer operating ice cream parlours (employee surveillance), the Ministry of Industries and Innovation/YAY ehf. (digital gift-card app), five municipalities (Google Cloud in schools), and an unlawfulness finding against Landspítali/Icelandic Genetics/Íslensk erfðagreining (COVID-19 genetic research).observed
ConfirmedEuropean Data Protection Board — Persónuvernd has reported resource constraints, noting it is divided into sub-units of around 3-5 staff members each with limited backup capacity, while handling several hundred open cases (approximately 800 open registered cases as reported in its GDPR Article 97 evaluation questionnaire response).observed
UncertainPersónuvernd (official translation) — No Iceland-specific collective-redress or class-action mechanism for data protection claims was identified in available sources.observed
UncertainDataGuidance — Data subjects in Iceland may lodge complaints with Persónuvernd and seek judicial remedies before Icelandic courts, including appeal of Persónuvernd decisions; a reported Icelandic Supreme Court ruling partially confirmed a Persónuvernd decision, evidencing an available judicial-review pathway.observed
ConfirmedEuropean Data Protection Supervisor / signatory authorities — In February 2026, Persónuvernd (represented by Data Protection Commissioner Helga Þórisdóttir and Head of International Affairs & Guidance Helga Sigríður Þórhallsdóttir) co-signed a multilateral joint statement with other data protection and privacy authorities addressing risks from AI-generated imagery, including harms to children and vulnerable groups.observed
No categories match.
Filters combine as OR inside a group and AND across
groups.
Publication gate
No failing checks.
schema_valid
pass
min_t1_per_instrument_met
n/a — no subject in this jurisdiction
min_quoted_text_present
waived — floor 0%
translation_provenance_recorded
n/a — no subject in this jurisdiction
egress_verified
pass
source_tier_integrity_ok
pass
jurisdiction_source_floor_met
pass
tier_a_b_national_primary_pct
94.74
aggregator_only_jurisdiction_count
0
manual_override
Editorial metadata
Provenance only. Nothing below gates publication or affects the render.
Editorial metadata for Iceland
Field
Value
trust.lawyer_review.status
never_reviewed
trust.lawyer_review.reviewer
no reviewer on record
trust.content_source
ai_generated
Provenance and declared absence
Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.
Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.
Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.
Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.
Suppressed by doctrine: derived risk score; derived_scores = {}.
Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.
Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 57 claim(s) (57 category placement(s)), 19 source(s) in the cumulative register.
regulator_and_framework, lawful_processing_and_special_data, controller_processor_duties, cross_border_and_adequacy (transfer_mechanisms), sectoral_watch.health_sector_overlay/education, algorithmic_biometric_and_surveillance_governance.genetic_data, children_and_vulnerable_groups.education_settings, and enforcement_and_redress.regulator_powers_and_penalties/enforcement_activity_index are grounded in T1 (Act No. 90/2018, EEA Annex XI) and T2 (EDPB national news, DataGuidance case reports, IAPP, EDPB Art. 97 questionnaire) primary/secondary sources with multiple corroborating Persónuvernd enforcement decisions (2021-2024) plus a February 2026 multilateral AI statement. Modules/sub-modules relying on T3/T4 or carrying explicit gaps (absent_field_provenance) include: sectoral_watch (financial_sector_overlay, telecoms_and_eprivacy, credit_and_scoring, insurance), adtech_and_commercial_privacy (all sub-modules except general framework inference), algorithmic_biometric_and_surveillance_governance (biometric_regime, state_surveillance_carveouts, profiling_restrictions/ADM transparency enforcement specifics), children_and_vulnerable_groups (age_verification, minor_profiling_bans, dependent_adults), enforcement_and_redress (collective_redress_and_class_actions, private_right_of_action detail beyond a title-only Supreme Court reference), and cross_border_and_adequacy.data_localisation.
Unresolved questions (7):
Does Iceland maintain any financial-sector-specific data protection overlay (e.g., FME/Fjármálaeftirlitið guidance) beyond general GDPR application?
Is there a dedicated Icelandic ePrivacy/cookie enforcement decision or transposition instrument distinct from the EU ePrivacy Directive baseline?
What is the substantive holding of the Icelandic Supreme Court decision 'partially confirming' a Persónuvernd ruling (only title/metadata retrieved)?
Does Iceland have any biometric-data-specific statute or Persónuvernd guidance (facial recognition, gait, fingerprint) beyond general special-category rules?
Are there Iceland-specific age-verification or minor-profiling-ban rules beyond the GDPR Article 8 information-society-services threshold?
Is there a collective-redress or representative-action mechanism available to Icelandic data subjects analogous to GDPR Article 80?
Does Iceland impose any data-localisation requirement in specific sectors (e.g., government cloud, health records) beyond general GDPR Chapter V?