Law note · Iceland
Act No. 90/2018, Breach Notification in Iceland
Act No. 90/2018 carries the General Data Protection Regulation (GDPR) breach-notification duties into Icelandic law: a controller must notify Personuvernd without undue delay, and where feasible within 72 hours of becoming aware of a personal data breach, unless the breach is unlikely to result in a risk to natural persons' rights and freedoms, and must notify affected individuals without undue delay where the breach is likely to result in a high risk.
No Icelandic-specific timeline departure was found; this dimension rests on secondary commentary corroborating the Act's GDPR-mirroring structure rather than a direct read of the breach-notification section itself.
What it asks of an app
- Notify Personuvernd without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in Iceland, unless the breach is unlikely to risk their rights and freedoms.
- Notify affected individuals without undue delay where a breach is likely to result in a high risk to their rights and freedoms.
When LexLint raises it
Declared activities: crawls_web, trains_models, deploys_chatbot, processes_biometrics, processes_voice
Primary source: DLA Piper and Recording Law secondary trackers, corroborating the Act's GDPR-mirroring breach-notification structure
not independently confirmed against the Act's own section text this pass