Law note · Iceland

Act No. 90/2018, Breach Notification in Iceland

cite Log nr. 90/2018 (breach notification provisions) stage In effect since 2018-07-15 reviewed 2026-08-24

Act No. 90/2018 carries the General Data Protection Regulation (GDPR) breach-notification duties into Icelandic law: a controller must notify Personuvernd without undue delay, and where feasible within 72 hours of becoming aware of a personal data breach, unless the breach is unlikely to result in a risk to natural persons' rights and freedoms, and must notify affected individuals without undue delay where the breach is likely to result in a high risk.

No Icelandic-specific timeline departure was found; this dimension rests on secondary commentary corroborating the Act's GDPR-mirroring structure rather than a direct read of the breach-notification section itself.

What it asks of an app

  • Notify Personuvernd without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in Iceland, unless the breach is unlikely to risk their rights and freedoms.
  • Notify affected individuals without undue delay where a breach is likely to result in a high risk to their rights and freedoms.

When LexLint raises it

Declared activities: crawls_web, trains_models, deploys_chatbot, processes_biometrics, processes_voice

Primary source: DLA Piper and Recording Law secondary trackers, corroborating the Act's GDPR-mirroring breach-notification structure
not independently confirmed against the Act's own section text this pass

← Back to the example  ·  Lint your app →