🔒 Data Protection Regulatory Intelligence
Data Protection Monitor · dataprotection.gi
IS v13-gdpri-1.0.0
content: ai_generated legal review: never_reviewed (informational) publication gate: 0 failing16 sources retrieved model claude-sonnet-5 · 2026-08-05

Iceland

IS schema gdpri-v2 trajectory: not yet assessedregulated (omnibus)overlaps: AIC

Last updated · 10 categories · 57 claims · 19 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
57Claimsbaseline..claims[]
5Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

Standing brief, as of 23 August 2026.

Lead Signal

Iceland's most significant data protection development this cycle sits in health-sector enforcement rather than in legislative change. Persónuvernd is confirmed to have fined Primary Health Care in the Capital Area in February 2025 after the organisation granted eleven third parties access to a joint electronic medical records system covering approximately 195,000 individuals without the ministerial permission required for that access, a breach that had persisted for several years before it was addressed. This is a high-confidence, high-materiality finding: it demonstrates that Iceland has a genuine structural weak point in inter-institutional data-sharing controls within the health sector, one that went undetected or unaddressed for an extended period despite the scale of personal data involved.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

GDPR is directly incorporated and actively enforced by a functioning DPA with a multi-year enforcement track record.

Primary frameworkAct No. 90/2018 on Data Protection and the Processing of Personal Data (GDPR (EU) 2016/679 as incorporated into the EEA Agreement, Annex XI)
Traffic-light rationale — GreenGDPR is directly incorporated and actively enforced by a functioning DPA with a multi-year enforcement track record.

Sub-modules (5)

Regulator And AuthorityGreen

Persónuvernd is the independent statutory DPA supervising GDPR/Act 90/2018 compliance.

Claims (1):

  • Persónuvernd is Iceland's independent Data Protection Authority responsible for supervising compliance with Act No. 90/2018 and the GDPR as incorporated into Icelandic law, with powers to investigate and issue administrative fines against controllers and processors.

Act And InstrumentsGreen

Act No. 90/2018 is the operative implementing statute, cited jointly with GDPR articles in all enforcement decisions.

Claims (1):

  • Act No. 90/2018 on Data Protection and the Processing of Personal Data is Iceland's primary data protection statute, giving domestic effect to the GDPR and forming the joint legal basis cited alongside GDPR articles in Persónuvernd enforcement decisions.

Material ScopeGreen

Material scope mirrors GDPR via EEA Agreement Annex XI incorporation.

Claims (1):

  • The GDPR was incorporated into the EEA Agreement (Annex XI) and applies comprehensively in Iceland as an EEA EFTA state, covering the same material scope of personal data processing as within the EU.

Territorial ScopeGreen

Comprehensive implementation gives Icelandic data subjects protection equivalent to EU Member States.

Claims (1):

  • As an EEA EFTA state, Iceland has implemented EU data protection rules comprehensively such that individuals in Iceland benefit from the same level of protection as individuals in EU Member States.

Regulator Registration And FilingAmber

No general upfront registration regime; Persónuvernd instead operates an online breach-notification portal/form.

Claims (1):

  • Persónuvernd operates a dedicated online notification portal/form through which controllers submit mandatory personal data breach notifications, rather than requiring general upfront processing-notification registration filings.
Category narrative47 words

Iceland is an EEA/EFTA state that has incorporated the GDPR into its domestic legal order via Act No. 90/2018 on Data Protection and the Processing of Personal Data, giving Persónuvernd (the Icelandic Data Protection Authority) enforcement powers materially equivalent to those of an EU Member State DPA.

Sources and claims (5)
  1. ConfirmedDataGuidance — Persónuvernd is Iceland's independent Data Protection Authority responsible for supervising compliance with Act No. 90/2018 and the GDPR as incorporated into Icelandic law, with powers to investigate and issue administrative fines against controllers and processors.observed
  2. ConfirmedPersónuvernd (official translation) — Act No. 90/2018 on Data Protection and the Processing of Personal Data is Iceland's primary data protection statute, giving domestic effect to the GDPR and forming the joint legal basis cited alongside GDPR articles in Persónuvernd enforcement decisions.observed
  3. ConfirmedEDPS — The GDPR was incorporated into the EEA Agreement (Annex XI) and applies comprehensively in Iceland as an EEA EFTA state, covering the same material scope of personal data processing as within the EU.observed
  4. ConfirmedEDPS — As an EEA EFTA state, Iceland has implemented EU data protection rules comprehensively such that individuals in Iceland benefit from the same level of protection as individuals in EU Member States.observed
  5. ProbableEuropean Data Protection Board — Persónuvernd operates a dedicated online notification portal/form through which controllers submit mandatory personal data breach notifications, rather than requiring general upfront processing-notification registration filings.observed

#

Directly enforced GDPR provisions with documented Icelandic case law across multiple sectors.

Primary frameworkAct No. 90/2018 (Arts. 6-9, 18) read with GDPR Arts. 5-9
Supervisory authorityPersónuvernd
Traffic-light rationale — GreenDirectly enforced GDPR provisions with documented Icelandic case law across multiple sectors.

Sub-modules (4)

Lawful BasesGreen

Article 6 GDPR lawfulness requirements actively enforced.

Claims (1):

  • Persónuvernd enforcement decisions confirm that lawfulness of processing under Article 6 GDPR (as applied via Act No. 90/2018) is directly enforceable, including in the City of Reykjavík Seesaw decision where Article 6 GDPR was found violated.

Special CategoriesGreen

Article 8 of Act 90/2018 provides enhanced protection for special-category and children's data.

Claims (1):

  • Article 8 of Act No. 90/2018 provides enhanced protections for special categories of personal data, including children's data, as applied in Persónuvernd's fine against the City of Reykjavík for violations of Article 8(1) subparagraphs of the Act concerning student data in the Seesaw system.

Pseudonymisation And AnonymisationAmber

Article 18(1) of Act 90/2018 provides research-purpose derogations conditioned on separation/pseudonymisation safeguards.

Claims (1):

  • Article 18(1) of Act No. 90/2018 permits derogations from certain GDPR data-subject rights where personal data are processed solely for research or statistical purposes, subject to pseudonymisation/separation safeguards.
Category narrative29 words

Lawful bases, consent standards, and special-category protections apply directly under GDPR Articles 5-9 as incorporated via Act No. 90/2018, with Iceland-specific research derogations under Article 18(1) of the Act.

Sources and claims (4)
  1. ConfirmedDataGuidance — Persónuvernd enforcement decisions confirm that lawfulness of processing under Article 6 GDPR (as applied via Act No. 90/2018) is directly enforceable, including in the City of Reykjavík Seesaw decision where Article 6 GDPR was found violated.observed
  2. ConfirmedEuropean Data Protection Board — Persónuvernd applies GDPR Article 7 consent-validity conditions directly, as demonstrated in its fine against the Ministry of Industries and Innovation and YAY ehf. for the digital gift-card app, which cited Article 7 (conditions for consent) among the infringements.observed
  3. ConfirmedDataGuidance — Article 8 of Act No. 90/2018 provides enhanced protections for special categories of personal data, including children's data, as applied in Persónuvernd's fine against the City of Reykjavík for violations of Article 8(1) subparagraphs of the Act concerning student data in the Seesaw system.observed
  4. ProbableEuropean Data Protection Board — Article 18(1) of Act No. 90/2018 permits derogations from certain GDPR data-subject rights where personal data are processed solely for research or statistical purposes, subject to pseudonymisation/separation safeguards.observed

#

Rights are directly incorporated; EDPB coordinated actions (access 2025, erasure 2025-26) evidence active supervisory engagement in the EEA, including Iceland.

Primary frameworkGDPR Arts. 12-22 as incorporated via Act No. 90/2018
Supervisory authorityPersónuvernd
Traffic-light rationale — GreenRights are directly incorporated; EDPB coordinated actions (access 2025, erasure 2025-26) evidence active supervisory engagement in the EEA, including Iceland.

Sub-modules (5)

Access RightGreen

Article 15 access right enforced; EEA-wide 2025 CEF action examined right-of-access implementation.

Claims (1):

  • Persónuvernd participates as an EEA supervisory authority within the EDPB's Coordinated Enforcement Framework, which ran a 2025 action examining controllers' implementation of the right of access under Article 15 GDPR.

Rectification And ErasureAmber

Article 17 GDPR erasure right subject to 2025-26 EDPB coordinated action across EEA DPAs.

Claims (1):

  • The EDPB launched a coordinated action in 2025-2026 on the right to erasure (Article 17 GDPR) applicable to participating EEA supervisory authorities, with a report on outcomes expected to be adopted in the coming months.

Restriction And ObjectionAmber

Article 18(1) Act 90/2018 disapplies restriction/objection rights for research-only processing, subject to safeguards.

Claims (1):

  • Article 18(1) of Act No. 90/2018 disapplies the rights to access, rectification, restriction of processing, and objection where personal data are processed exclusively for research or statistical purposes, subject to safeguards.

Data PortabilityAmber

Article 20 GDPR portability applies without a documented Icelandic-specific derogation.

Claims (1):

  • The right to data portability under GDPR Article 20 applies directly in Iceland via incorporation of the GDPR through Act No. 90/2018, without a documented Icelandic-specific derogation identified in available sources.

Deadlines And Response WindowsAmber

Standard one-month (extendable) GDPR response window applies; no Iceland-specific modification found.

Claims (1):

  • Controllers in Iceland must respond to data subject rights requests within the GDPR's standard one-month period (extendable by up to two further months for complex requests), incorporated without modification via Act No. 90/2018.
Category narrative36 words

Access, rectification/erasure, restriction/objection, and portability rights apply per GDPR Arts. 13-22 via Act No. 90/2018, subject to a research-purpose carve-out under Article 18(1) of the Act; no Iceland-specific deviation from GDPR's standard response deadlines was located.

Sources and claims (5)
  1. ProbableEuropean Data Protection Board — Persónuvernd participates as an EEA supervisory authority within the EDPB's Coordinated Enforcement Framework, which ran a 2025 action examining controllers' implementation of the right of access under Article 15 GDPR.observed
  2. ProbableEuropean Data Protection Board — The EDPB launched a coordinated action in 2025-2026 on the right to erasure (Article 17 GDPR) applicable to participating EEA supervisory authorities, with a report on outcomes expected to be adopted in the coming months.observed
  3. ProbableEuropean Data Protection Board — Article 18(1) of Act No. 90/2018 disapplies the rights to access, rectification, restriction of processing, and objection where personal data are processed exclusively for research or statistical purposes, subject to safeguards.observed
  4. ProbablePersónuvernd (official translation) — The right to data portability under GDPR Article 20 applies directly in Iceland via incorporation of the GDPR through Act No. 90/2018, without a documented Icelandic-specific derogation identified in available sources.observed
  5. ProbablePersónuvernd (official translation) — Controllers in Iceland must respond to data subject rights requests within the GDPR's standard one-month period (extendable by up to two further months for complex requests), incorporated without modification via Act No. 90/2018.observed

#

Core obligations are enforced (multiple fines), but repeated findings of DPIA, DPO-independence, and security failures (Reykjavík, InfoMentor, ice-cream-parlour cases) indicate persistent compliance gaps among controllers.

Primary frameworkGDPR Arts. 24-35 / Act No. 90/2018 Arts. 24-35
Supervisory authorityPersónuvernd
Traffic-light rationale — AmberCore obligations are enforced (multiple fines), but repeated findings of DPIA, DPO-independence, and security failures (Reykjavík, InfoMentor, ice-cream-parlour cases) indicate persistent compliance gaps among controllers.

Sub-modules (7)

Accountability And DpiaAmber

DPIA (Art. 35) failures found in the Reykjavík Seesaw case.

Claims (1):

  • Persónuvernd found the City of Reykjavík in violation of Article 35(1) GDPR (DPIA obligation) and Article 25(1)/(3) (data protection by design) in its use of the Seesaw educational system, resulting in a fine of ISK 5 million.

Dpo RequirementsAmber

DPO independence/involvement failures found against City of Reykjavík.

Claims (1):

  • Persónuvernd found that the City of Reykjavík's DPO failed to be involved in an appropriate and timely manner, lacked adequate independence, and had unresolved conflicts of interest, in violation of Article 35(3) of Act No. 90/2018 and Articles 38 and 39 GDPR.

Ropa RequirementsGreen

Article 30 ROPA duties apply via incorporation; Persónuvernd has published ROPA/DPA templates.

Claims (1):

  • Records-of-processing obligations under GDPR Article 30 apply to controllers and processors in Iceland via direct incorporation through Act No. 90/2018, and Persónuvernd has published templates for data processing agreements and records of processing to support compliance.

Joint Controller ArrangementsAmber

Processor-contract (Art. 28(3)) obligations enforced in the YAY ehf. case.

Claims (1):

  • Persónuvernd's enforcement action against the Ministry of Industries and Innovation and YAY ehf. addressed processor-contract obligations under Article 28(3) GDPR in the context of a government-vendor digital gift-card processing arrangement.

Security MeasuresAmber

Security/transparency failures fined in the employee-surveillance case.

Claims (1):

  • Persónuvernd fined a company operating ice cream parlours for failing to implement adequate security and transparency measures around employee video surveillance, finding infringements of Article 13 GDPR and related security/transparency provisions.

Breach NotificationAmber

Dedicated breach-notification portal exists; InfoMentor fined for a breach affecting 424 children.

Claims (1):

  • Persónuvernd operates a dedicated online breach-notification form and fined InfoMentor ISK 3.5 million for a security failure resulting in a breach affecting 424 children's personal data on an education platform.

Retention And DisposalAmber

Retention/erasure (Art. 17(1) of the Act) violation found in the Seesaw case.

Claims (1):

  • Persónuvernd's decision against the City of Reykjavík found violations of Article 17(1) of Act No. 90/2018 (data retention/erasure obligations) in connection with the Seesaw educational system.
Category narrative34 words

Accountability, DPIA, DPO, ROPA, security, breach-notification, and retention duties under GDPR Arts. 24-35 apply directly via Act No. 90/2018, with a substantial and growing Persónuvernd enforcement record across education, health, employment, and public-sector processing.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (7)
  1. ConfirmedDataGuidance — Persónuvernd found the City of Reykjavík in violation of Article 35(1) GDPR (DPIA obligation) and Article 25(1)/(3) (data protection by design) in its use of the Seesaw educational system, resulting in a fine of ISK 5 million.observed
  2. ConfirmedDataGuidance — Persónuvernd found that the City of Reykjavík's DPO failed to be involved in an appropriate and timely manner, lacked adequate independence, and had unresolved conflicts of interest, in violation of Article 35(3) of Act No. 90/2018 and Articles 38 and 39 GDPR.observed
  3. ProbableEuropean Data Protection Board — Records-of-processing obligations under GDPR Article 30 apply to controllers and processors in Iceland via direct incorporation through Act No. 90/2018, and Persónuvernd has published templates for data processing agreements and records of processing to support compliance.observed
  4. ConfirmedEuropean Data Protection Board — Persónuvernd's enforcement action against the Ministry of Industries and Innovation and YAY ehf. addressed processor-contract obligations under Article 28(3) GDPR in the context of a government-vendor digital gift-card processing arrangement.observed
  5. ConfirmedEuropean Data Protection Board — Persónuvernd fined a company operating ice cream parlours for failing to implement adequate security and transparency measures around employee video surveillance, finding infringements of Article 13 GDPR and related security/transparency provisions.observed
  6. ConfirmedDataGuidance — Persónuvernd operates a dedicated online breach-notification form and fined InfoMentor ISK 3.5 million for a security failure resulting in a breach affecting 424 children's personal data on an education platform.observed
  7. ConfirmedDataGuidance — Persónuvernd's decision against the City of Reykjavík found violations of Article 17(1) of Act No. 90/2018 (data retention/erasure obligations) in connection with the Seesaw educational system.observed

#

Framework is fully harmonised (green) but enforcement shows recurring onward-transfer risk findings (amber) in ed-tech/cloud processing.

Primary frameworkGDPR Arts. 44-49 as incorporated via Act No. 90/2018 and EEA Agreement Annex XI
Supervisory authorityPersónuvernd
Traffic-light rationale — AmberFramework is fully harmonised (green) but enforcement shows recurring onward-transfer risk findings (amber) in ed-tech/cloud processing.

Sub-modules (6)

Transfer MechanismsAmber

Chapter V transfer mechanisms apply directly; onward-transfer risk actively scrutinised.

Claims (1):

  • Persónuvernd found that the City of Reykjavík's use of the Seesaw system created a high risk of personal data being transferred to the United States and processed without adequate protection, in violation of Articles 32, 35(1), and 46 GDPR.

Adequacy ReceivedGreen

EU-to-Iceland transfers are not third-country transfers due to EEA incorporation.

Claims (1):

  • Because the GDPR and its related adequacy decisions are incorporated into the EEA Agreement, transfers of personal data from EU Member States to Iceland are not treated as third-country transfers and do not require a separate adequacy decision.

Adequacy GrantedGreen

Iceland relies on EU Commission adequacy decisions incorporated into the EEA Agreement rather than issuing independent adequacy findings.

Claims (1):

  • As an EEA EFTA state applying the GDPR directly, Iceland does not issue independent third-country adequacy decisions of its own; it relies on European Commission adequacy decisions incorporated into the EEA Agreement.

Sccs And BcrsGreen

SCCs/BCRs approved under GDPR are directly available to Icelandic controllers/processors.

Claims (1):

  • Standard Contractual Clauses and Binding Corporate Rules approved under the GDPR are directly available as transfer mechanisms for Icelandic controllers and processors by virtue of the GDPR's incorporation into the EEA Agreement.

Transfer Impact AssessmentAmber

Persónuvernd's Seesaw decision reflects TIA-style expectations for onward transfer risk to the US.

Claims (1):

  • The Reykjavík Seesaw decision shows Persónuvernd expects controllers to assess and mitigate the risk of onward transfer to third countries such as the United States, consistent with a transfer-impact-assessment style analysis under GDPR Article 46.

Data LocalisationAmber

No dedicated Icelandic data-localisation mandate identified beyond GDPR Chapter V.

Claims (1):

  • No general data-localisation mandate beyond the GDPR's Chapter V cross-border transfer restrictions was identified for Iceland in available sources.
Category narrative40 words

Iceland applies GDPR Chapter V transfer rules directly via EEA Agreement incorporation; it neither issues nor requires separate third-country adequacy decisions relative to the EU/EEA, and its DPA has actively scrutinised onward transfers (notably to the US) in enforcement decisions.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (6)
  1. ConfirmedDataGuidance — Persónuvernd found that the City of Reykjavík's use of the Seesaw system created a high risk of personal data being transferred to the United States and processed without adequate protection, in violation of Articles 32, 35(1), and 46 GDPR.observed
  2. ConfirmedEDPS — Because the GDPR and its related adequacy decisions are incorporated into the EEA Agreement, transfers of personal data from EU Member States to Iceland are not treated as third-country transfers and do not require a separate adequacy decision.observed
  3. ProbableEDPS — As an EEA EFTA state applying the GDPR directly, Iceland does not issue independent third-country adequacy decisions of its own; it relies on European Commission adequacy decisions incorporated into the EEA Agreement.observed
  4. ProbableEDPS — Standard Contractual Clauses and Binding Corporate Rules approved under the GDPR are directly available as transfer mechanisms for Icelandic controllers and processors by virtue of the GDPR's incorporation into the EEA Agreement.observed
  5. ProbableDataGuidance — The Reykjavík Seesaw decision shows Persónuvernd expects controllers to assess and mitigate the risk of onward transfer to third countries such as the United States, consistent with a transfer-impact-assessment style analysis under GDPR Article 46.observed
  6. UncertainPersónuvernd (official translation) — No general data-localisation mandate beyond the GDPR's Chapter V cross-border transfer restrictions was identified for Iceland in available sources.observed

#

Strong evidence in education and health; gaps in financial, telecoms, credit, and insurance sub-modules necessitate primary-source escalation.

Primary frameworkGDPR/Act No. 90/2018 general framework; no distinct sectoral statutes identified beyond education/health case law
Supervisory authorityPersónuvernd
Traffic-light rationale — AmberStrong evidence in education and health; gaps in financial, telecoms, credit, and insurance sub-modules necessitate primary-source escalation.

Sub-modules (7)

Financial Sector OverlayRed

No Iceland-specific financial-sector DP overlay identified.

Claims (1):

  • Financial-sector personal data processing in Iceland appears to be governed by the general GDPR/Act No. 90/2018 framework without a distinct financial-sector data protection overlay identified in available guidance to date.

Health Sector OverlayAmber

Genetic/health research processing scrutinised in the Landspítali/Íslensk erfðagreining case.

Claims (1):

  • Persónuvernd found that Landspítali, Icelandic Genetics ehf., and Íslensk erfðagreining unlawfully processed COVID-19 patients' samples and data for genetic research without proper authorisation, in violation of Article 8 of Act No. 90/2018 and Article 5 GDPR.

Telecoms And EprivacyRed

No Iceland-specific ePrivacy enforcement decision identified.

Claims (1):

  • The ePrivacy framework for electronic communications applies in Iceland as an EEA state, though no Iceland-specific ePrivacy/cookie enforcement decision was identified in available sources.

Employment DataAmber

Employee surveillance enforcement documented (ice-cream-parlour case).

Claims (1):

  • Persónuvernd's fine against an ice-cream-parlour operator for unlawful employee video surveillance demonstrates active enforcement of employment-context data protection obligations, including transparency and proportionality requirements.

Credit And ScoringRed

No Iceland-specific credit-scoring DP finding identified.

Claims (1):

  • No Iceland-specific credit-scoring or automated creditworthiness-assessment data protection finding was identified in available sources.

EducationAmber

Sustained enforcement against ed-tech/cloud vendors and municipalities.

Claims (1):

  • Persónuvernd fined five municipalities a combined ISK 12.8 million over alleged improper processing of primary-school student data through Google Cloud's education technology services.

InsuranceRed

No Iceland-specific insurance-sector DP finding identified.

Claims (1):

  • No Iceland-specific insurance-sector data protection finding or overlay was identified in available sources.
Category narrative34 words

The clearest sectoral overlay evidenced is education (repeated ed-tech/cloud-services fines) and health/genetic research (COVID-19 sample processing); financial, telecoms/ePrivacy, credit-scoring, and insurance overlays were not evidenced by dedicated Icelandic enforcement or guidance in available sources.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (7)
  1. UncertainPersónuvernd (official translation) — Financial-sector personal data processing in Iceland appears to be governed by the general GDPR/Act No. 90/2018 framework without a distinct financial-sector data protection overlay identified in available guidance to date.observed
  2. ConfirmedDataGuidance — Persónuvernd found that Landspítali, Icelandic Genetics ehf., and Íslensk erfðagreining unlawfully processed COVID-19 patients' samples and data for genetic research without proper authorisation, in violation of Article 8 of Act No. 90/2018 and Article 5 GDPR.observed
  3. UncertainPersónuvernd (official translation) — The ePrivacy framework for electronic communications applies in Iceland as an EEA state, though no Iceland-specific ePrivacy/cookie enforcement decision was identified in available sources.observed
  4. ConfirmedEuropean Data Protection Board — Persónuvernd's fine against an ice-cream-parlour operator for unlawful employee video surveillance demonstrates active enforcement of employment-context data protection obligations, including transparency and proportionality requirements.observed
  5. SpeculativePersónuvernd (official translation) — No Iceland-specific credit-scoring or automated creditworthiness-assessment data protection finding was identified in available sources.observed
  6. ConfirmedIAPP — Persónuvernd fined five municipalities a combined ISK 12.8 million over alleged improper processing of primary-school student data through Google Cloud's education technology services.observed
  7. SpeculativePersónuvernd (official translation) — No Iceland-specific insurance-sector data protection finding or overlay was identified in available sources.observed

#

Framework exists in principle (GDPR incorporation) but no dedicated Icelandic enforcement or guidance evidence found for most adtech sub-modules.

Primary frameworkGDPR consent/legitimate-interest and Art. 21 objection rights as incorporated via Act No. 90/2018
Supervisory authorityPersónuvernd
Traffic-light rationale — RedFramework exists in principle (GDPR incorporation) but no dedicated Icelandic enforcement or guidance evidence found for most adtech sub-modules.

Sub-modules (6)

Cookies And TrackersAmber

General consent standards apply; no Iceland-specific cookie enforcement located.

Claims (1):

  • Cookie and tracker consent requirements in Iceland derive from GDPR consent standards under Act No. 90/2018 operating alongside the ePrivacy framework, though no Iceland-specific cookie-enforcement decision was located in available sources.

Dark PatternsRed

No Iceland-specific dark-pattern finding identified.

Claims (1):

  • No Iceland-specific dark-pattern prohibition or enforcement decision was identified in available sources.

Opt Out SignalsRed

No Iceland-specific opt-out-signal (e.g., GPC) guidance identified.

Claims (1):

  • No Iceland-specific guidance on opt-out signals such as Global Privacy Control was identified in available sources.

Clean Rooms And DcrRed

No Iceland-specific clean-room/DCR guidance identified.

Claims (1):

  • No Iceland-specific guidance on data clean rooms or data-collaboration-room arrangements was identified in available sources.

Cross Context AdvertisingRed

No Iceland-specific cross-context advertising finding identified.

Claims (1):

  • No Iceland-specific cross-context advertising or 'sale'/'share' of personal data finding was identified in available sources.

Direct MarketingAmber

General Art. 21 objection right applies; no Iceland-specific direct-marketing enforcement located.

Claims (1):

  • Direct marketing processing in Iceland is subject to GDPR consent/legitimate-interest standards and the right to object under Article 21 GDPR as incorporated via Act No. 90/2018; no Iceland-specific direct-marketing enforcement decision was identified.
Category narrative38 words

General GDPR consent and objection standards apply to cookies, direct marketing, and commercial profiling in Iceland via Act No. 90/2018, but no Iceland-specific enforcement decisions on cookies/trackers, dark patterns, opt-out signals, clean rooms, or cross-context advertising were located.

Sources and claims (6)
  1. UncertainPersónuvernd (official translation) — Cookie and tracker consent requirements in Iceland derive from GDPR consent standards under Act No. 90/2018 operating alongside the ePrivacy framework, though no Iceland-specific cookie-enforcement decision was located in available sources.observed
  2. SpeculativePersónuvernd (official translation) — No Iceland-specific dark-pattern prohibition or enforcement decision was identified in available sources.observed
  3. SpeculativePersónuvernd (official translation) — No Iceland-specific guidance on opt-out signals such as Global Privacy Control was identified in available sources.observed
  4. SpeculativePersónuvernd (official translation) — No Iceland-specific guidance on data clean rooms or data-collaboration-room arrangements was identified in available sources.observed
  5. SpeculativePersónuvernd (official translation) — No Iceland-specific cross-context advertising or 'sale'/'share' of personal data finding was identified in available sources.observed
  6. UncertainPersónuvernd (official translation) — Direct marketing processing in Iceland is subject to GDPR consent/legitimate-interest standards and the right to object under Article 21 GDPR as incorporated via Act No. 90/2018; no Iceland-specific direct-marketing enforcement decision was identified.observed

#

Genetic data and emerging AI-related engagement are evidenced; biometric regime and surveillance carve-outs remain gaps requiring primary-source escalation.

Primary frameworkGDPR Arts. 9, 22 as incorporated via Act No. 90/2018
Supervisory authorityPersónuvernd
Traffic-light rationale — AmberGenetic data and emerging AI-related engagement are evidenced; biometric regime and surveillance carve-outs remain gaps requiring primary-source escalation.

Sub-modules (6)

Profiling RestrictionsAmber

Article 22 GDPR applies directly; no Iceland-specific ADM/profiling enforcement decision located.

Claims (1):

  • Article 22 GDPR profiling/automated-decision-making restrictions apply directly in Iceland via Act No. 90/2018, though no Iceland-specific Persónuvernd enforcement decision addressing Article 22 was located in available sources.

Automated Decision Making TransparencyAmber

General GDPR transparency duties apply; no dedicated Icelandic ADM transparency case identified.

Claims (1):

  • General GDPR transparency duties regarding automated decision-making apply via Act No. 90/2018, though no dedicated Icelandic ADM-transparency enforcement case was identified in available sources.

Ai Risk AssessmentsAmber

Persónuvernd co-signed a February 2026 multilateral joint statement on AI-generated imagery risks.

Claims (1):

  • Persónuvernd, together with other data protection and privacy authorities, co-signed a February 2026 joint statement on AI-generated imagery emphasising that AI content-generation systems must be developed and used in accordance with applicable data protection and privacy rules, with specific attention to risks facing children and vulnerable groups.

Biometric RegimeRed

No Iceland-specific biometric-data regime or enforcement decision identified.

Claims (1):

  • No Iceland-specific biometric-data (facial recognition, fingerprint, gait) regime or enforcement decision was identified in available sources.

Genetic DataAmber

Genetic/biological sample processing scrutinised in the COVID-19 research case.

Claims (1):

  • Persónuvernd's decision regarding Landspítali, Icelandic Genetics, and Íslensk erfðagreining addressed unlawful processing of genetic/biological sample data for COVID-19 research, finding breaches of Article 8 of Act No. 90/2018 (special categories) and Article 5 GDPR.

State Surveillance CarveoutsRed

No Iceland-specific national-security/surveillance carve-out analysis identified.

Claims (1):

  • No Iceland-specific analysis of national-security or state-surveillance carve-outs from GDPR/Act No. 90/2018 was identified in available sources.
Category narrative44 words

Article 22 GDPR profiling/ADM restrictions and genetic-data protections apply via Act No. 90/2018, evidenced concretely in the Landspítali genetic-research case; Persónuvernd has also co-signed a 2026 multilateral statement on AI-generated imagery risks. Biometric-specific regime detail and state-surveillance carve-outs were not evidenced in available sources.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (6)
  1. UncertainPersónuvernd (official translation) — Article 22 GDPR profiling/automated-decision-making restrictions apply directly in Iceland via Act No. 90/2018, though no Iceland-specific Persónuvernd enforcement decision addressing Article 22 was located in available sources.observed
  2. UncertainPersónuvernd (official translation) — General GDPR transparency duties regarding automated decision-making apply via Act No. 90/2018, though no dedicated Icelandic ADM-transparency enforcement case was identified in available sources.observed
  3. ConfirmedEuropean Data Protection Supervisor / signatory authorities — Persónuvernd, together with other data protection and privacy authorities, co-signed a February 2026 joint statement on AI-generated imagery emphasising that AI content-generation systems must be developed and used in accordance with applicable data protection and privacy rules, with specific attention to risks facing children and vulnerable groups.observed
  4. SpeculativePersónuvernd (official translation) — No Iceland-specific biometric-data (facial recognition, fingerprint, gait) regime or enforcement decision was identified in available sources.observed
  5. ConfirmedDataGuidance — Persónuvernd's decision regarding Landspítali, Icelandic Genetics, and Íslensk erfðagreining addressed unlawful processing of genetic/biological sample data for COVID-19 research, finding breaches of Article 8 of Act No. 90/2018 (special categories) and Article 5 GDPR.observed
  6. SpeculativePersónuvernd (official translation) — No Iceland-specific analysis of national-security or state-surveillance carve-outs from GDPR/Act No. 90/2018 was identified in available sources.observed

#

Strong, repeated education-sector enforcement (green signal) offset by gaps in age-verification, minor-profiling, and dependent-adult sub-modules (red signal), yielding an overall amber rating.

Primary frameworkGDPR Art. 8 / Act No. 90/2018 special-category provisions on children's data
Supervisory authorityPersónuvernd
Traffic-light rationale — AmberStrong, repeated education-sector enforcement (green signal) offset by gaps in age-verification, minor-profiling, and dependent-adult sub-modules (red signal), yielding an overall amber rating.

Sub-modules (5)

Age VerificationRed

No Iceland-specific age-verification mechanism or enforcement identified.

Claims (1):

  • No Iceland-specific age-verification mechanism or Persónuvernd enforcement decision on age verification was identified in available sources.

Minor Profiling BansRed

No Iceland-specific minor-profiling ban or enforcement identified.

Claims (1):

  • No Iceland-specific ban or enforcement decision on profiling of minors was identified in available sources.

Education SettingsAmber

Persónuvernd has repeatedly fined education-sector controllers/processors over children's data.

Claims (1):

  • Persónuvernd fined InfoMentor ISK 3.5 million after unauthorised parties accessed the personal data of 424 children through the company's education platform, treating children's data as meriting special protection under Act No. 90/2018.

Dependent AdultsRed

No Iceland-specific dependent-adult/elderly protection finding identified.

Claims (1):

  • No Iceland-specific dependent-adult (elderly/mentally incapacitated) data protection finding was identified in available sources.
Category narrative41 words

Children's data receives heightened protection under Act No. 90/2018, evidenced by a consistent Persónuvernd enforcement pattern targeting education-sector processors (Seesaw, InfoMentor, Google Cloud in schools) and underage employees (ice-cream-parlour surveillance). Age-verification thresholds, minor-profiling bans, and dependent-adult protections were not independently evidenced.

Sources and claims (5)
  1. SpeculativePersónuvernd (official translation) — No Iceland-specific age-verification mechanism or Persónuvernd enforcement decision on age verification was identified in available sources.observed
  2. UncertainPersónuvernd (official translation) — Act No. 90/2018 and the GDPR require parental consent for information-society services offered directly to children below the relevant age threshold, applied in Iceland via direct GDPR incorporation, though no Iceland-specific enforcement decision on the parental-consent threshold itself was located.observed
  3. SpeculativePersónuvernd (official translation) — No Iceland-specific ban or enforcement decision on profiling of minors was identified in available sources.observed
  4. ConfirmedDataGuidance — Persónuvernd fined InfoMentor ISK 3.5 million after unauthorised parties accessed the personal data of 424 children through the company's education platform, treating children's data as meriting special protection under Act No. 90/2018.observed
  5. SpeculativePersónuvernd (official translation) — No Iceland-specific dependent-adult (elderly/mentally incapacitated) data protection finding was identified in available sources.observed

#

Active enforcement and appeal pathways exist (green signal) but self-reported capacity constraints and unresolved collective-redress/private-right-of-action gaps (amber/red signals) temper the overall rating.

Primary frameworkGDPR Arts. 77-84 / Act No. 90/2018 enforcement provisions
Supervisory authorityPersónuvernd
Traffic-light rationale — AmberActive enforcement and appeal pathways exist (green signal) but self-reported capacity constraints and unresolved collective-redress/private-right-of-action gaps (amber/red signals) temper the overall rating.

Sub-modules (6)

Regulator Powers And PenaltiesGreen

Persónuvernd exercises investigative and fining powers analogous to GDPR Art. 83.

Claims (1):

  • Persónuvernd has issued multiple administrative fines under Act No. 90/2018 and the GDPR, ranging from ISK 1.5 million to ISK 12.8 million in identified cases, exercising investigative and sanctioning powers analogous to Article 83 GDPR's maximum-fine provisions.

Enforcement Activity IndexGreen

Multiple fines/findings across sectors documented over recent years.

Claims (1):

  • Persónuvernd's recent enforcement record includes fines against the City of Reykjavík (Seesaw), InfoMentor (education breach), an employer operating ice cream parlours (employee surveillance), the Ministry of Industries and Innovation/YAY ehf. (digital gift-card app), five municipalities (Google Cloud in schools), and an unlawfulness finding against Landspítali/Icelandic Genetics/Íslensk erfðagreining (COVID-19 genetic research).

Regulator Funding And CapacityAmber

Self-reported staffing constraints relative to caseload.

Claims (1):

  • Persónuvernd has reported resource constraints, noting it is divided into sub-units of around 3-5 staff members each with limited backup capacity, while handling several hundred open cases (approximately 800 open registered cases as reported in its GDPR Article 97 evaluation questionnaire response).

Collective Redress And Class ActionsRed

No Iceland-specific collective-redress/class-action mechanism for DP claims identified.

Claims (1):

  • No Iceland-specific collective-redress or class-action mechanism for data protection claims was identified in available sources.

Private Right Of ActionAmber

Judicial review of Persónuvernd decisions is available, including Supreme Court review.

Claims (1):

  • Data subjects in Iceland may lodge complaints with Persónuvernd and seek judicial remedies before Icelandic courts, including appeal of Persónuvernd decisions; a reported Icelandic Supreme Court ruling partially confirmed a Persónuvernd decision, evidencing an available judicial-review pathway.

Recent Developments 180DAmber

February 2026 multilateral joint statement on AI-generated imagery co-signed by Persónuvernd.

Claims (1):

  • In February 2026, Persónuvernd (represented by Data Protection Commissioner Helga Þórisdóttir and Head of International Affairs & Guidance Helga Sigríður Þórhallsdóttir) co-signed a multilateral joint statement with other data protection and privacy authorities addressing risks from AI-generated imagery, including harms to children and vulnerable groups.
Category narrative54 words

Persónuvernd has a sustained multi-year enforcement record (fines from ISK 1.5M to ISK 12.8M across education, health, employment, and public-sector cases) but operates under acknowledged resource constraints; judicial review of its decisions is available (Icelandic Supreme Court review reported), and it participates in cross-border EEA/international regulatory coordination including a February 2026 joint AI statement.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (6)
  1. ConfirmedIAPP — Persónuvernd has issued multiple administrative fines under Act No. 90/2018 and the GDPR, ranging from ISK 1.5 million to ISK 12.8 million in identified cases, exercising investigative and sanctioning powers analogous to Article 83 GDPR's maximum-fine provisions.observed
  2. ConfirmedIAPP — Persónuvernd's recent enforcement record includes fines against the City of Reykjavík (Seesaw), InfoMentor (education breach), an employer operating ice cream parlours (employee surveillance), the Ministry of Industries and Innovation/YAY ehf. (digital gift-card app), five municipalities (Google Cloud in schools), and an unlawfulness finding against Landspítali/Icelandic Genetics/Íslensk erfðagreining (COVID-19 genetic research).observed
  3. ConfirmedEuropean Data Protection Board — Persónuvernd has reported resource constraints, noting it is divided into sub-units of around 3-5 staff members each with limited backup capacity, while handling several hundred open cases (approximately 800 open registered cases as reported in its GDPR Article 97 evaluation questionnaire response).observed
  4. UncertainPersónuvernd (official translation) — No Iceland-specific collective-redress or class-action mechanism for data protection claims was identified in available sources.observed
  5. UncertainDataGuidance — Data subjects in Iceland may lodge complaints with Persónuvernd and seek judicial remedies before Icelandic courts, including appeal of Persónuvernd decisions; a reported Icelandic Supreme Court ruling partially confirmed a Persónuvernd decision, evidencing an available judicial-review pathway.observed
  6. ConfirmedEuropean Data Protection Supervisor / signatory authorities — In February 2026, Persónuvernd (represented by Data Protection Commissioner Helga Þórisdóttir and Head of International Affairs & Guidance Helga Sigríður Þórhallsdóttir) co-signed a multilateral joint statement with other data protection and privacy authorities addressing risks from AI-generated imagery, including harms to children and vulnerable groups.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Publication gate

No failing checks.

schema_validpass
min_t1_per_instrument_metn/a — no subject in this jurisdiction
min_quoted_text_presentwaived — floor 0%
translation_provenance_recordedn/a — no subject in this jurisdiction
egress_verifiedpass
source_tier_integrity_okpass
jurisdiction_source_floor_metpass
tier_a_b_national_primary_pct94.74
aggregator_only_jurisdiction_count0
manual_override

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Iceland
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewerno reviewer on record
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 57 claim(s) (57 category placement(s)), 19 source(s) in the cumulative register.

Think something on this page is wrong? Report an error.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (38 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsaccess right
Art. 14Data Subject Rightsaccess right
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 19Data Subject Rightsrestriction and objection
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy received
Art. 46Cross-Border & Adequacysccs and bcrs
Art. 47Cross-Border & Adequacysccs and bcrs
Art. 48Cross-Border & Adequacytransfer mechanisms
Art. 49Cross-Border & Adequacytransfer mechanisms
Art. 77Enforcement & Redressprivate right of action
Art. 78Enforcement & Redressprivate right of action
Art. 79Enforcement & Redressprivate right of action
Art. 80Enforcement & Redresscollective redress and class actions
Art. 81Enforcement & Redressregulator powers and penalties
Art. 82Enforcement & Redressregulator powers and penalties
Art. 83Enforcement & Redressregulator powers and penalties
Art. 84Enforcement & Redressregulator powers and penalties

Self-audit

regulator_and_framework, lawful_processing_and_special_data, controller_processor_duties, cross_border_and_adequacy (transfer_mechanisms), sectoral_watch.health_sector_overlay/education, algorithmic_biometric_and_surveillance_governance.genetic_data, children_and_vulnerable_groups.education_settings, and enforcement_and_redress.regulator_powers_and_penalties/enforcement_activity_index are grounded in T1 (Act No. 90/2018, EEA Annex XI) and T2 (EDPB national news, DataGuidance case reports, IAPP, EDPB Art. 97 questionnaire) primary/secondary sources with multiple corroborating Persónuvernd enforcement decisions (2021-2024) plus a February 2026 multilateral AI statement. Modules/sub-modules relying on T3/T4 or carrying explicit gaps (absent_field_provenance) include: sectoral_watch (financial_sector_overlay, telecoms_and_eprivacy, credit_and_scoring, insurance), adtech_and_commercial_privacy (all sub-modules except general framework inference), algorithmic_biometric_and_surveillance_governance (biometric_regime, state_surveillance_carveouts, profiling_restrictions/ADM transparency enforcement specifics), children_and_vulnerable_groups (age_verification, minor_profiling_bans, dependent_adults), enforcement_and_redress (collective_redress_and_class_actions, private_right_of_action detail beyond a title-only Supreme Court reference), and cross_border_and_adequacy.data_localisation.

Unresolved questions (7):

  • Does Iceland maintain any financial-sector-specific data protection overlay (e.g., FME/Fjármálaeftirlitið guidance) beyond general GDPR application?
  • Is there a dedicated Icelandic ePrivacy/cookie enforcement decision or transposition instrument distinct from the EU ePrivacy Directive baseline?
  • What is the substantive holding of the Icelandic Supreme Court decision 'partially confirming' a Persónuvernd ruling (only title/metadata retrieved)?
  • Does Iceland have any biometric-data-specific statute or Persónuvernd guidance (facial recognition, gait, fingerprint) beyond general special-category rules?
  • Are there Iceland-specific age-verification or minor-profiling-ban rules beyond the GDPR Article 8 information-society-services threshold?
  • Is there a collective-redress or representative-action mechanism available to Icelandic data subjects analogous to GDPR Article 80?
  • Does Iceland impose any data-localisation requirement in specific sectors (e.g., government cloud, health records) beyond general GDPR Chapter V?

Escalate to primary-source review: yes