Instruments
Each one links to its
LexLint note, which carries what it requires and what it flags on.
Breach notification
cite Log nr. 90/2018 (breach notification provisions)
stage In effect
since 2018-07-15
source DLA Piper and Recording Law secondary trackers, corroborating the Act's GDPR-mirroring breach-notification structure
Act No. 90/2018 carries the General Data Protection Regulation (GDPR) breach-notification duties into Icelandic law: a controller must notify Personuvernd without undue delay, and where feasible within 72 hours of becoming aware of a personal data breach, unless the breach is unlikely to result in a risk to natural persons' rights and freedoms, and must notify affected individuals without undue delay where the breach is likely to result in a high risk.
No Icelandic-specific timeline departure was found; this dimension rests on secondary commentary corroborating the Act's GDPR-mirroring structure rather than a direct read of the breach-notification section itself.
What it asks of an app →
Comprehensive regime
cite Log nr. 90/2018 um personuvernd og vinnslu personuupplysinga (Act No. 90/2018), passed by Althingi 27 June 2018, in force 15 July 2018
stage In effect
since 2018-07-15
source Althingi official consolidated-law database, fetched and read directly
Iceland is not an EU member, so the General Data Protection Regulation (GDPR) does not apply directly. GDPR reaches Iceland through EEA Joint Committee Decision No. 154/2018, incorporating it into the EEA Agreement, and Act No. 90/2018 gives that incorporation domestic legal force. The Act's own Article 2, read directly, names Decision No. 154/2018 as the incorporation mechanism, and the Act reproduces the GDPR text itself as an appendix. Persoonuvernd (the Icelandic Data Protection Authority) is the supervisory authority.
Privacy law is a settled, fully in-force regime in Iceland since 2018, distinct from Iceland's AI-law posture, where the EU AI Act's own EEA incorporation was still pending as of the derived candidate list's 2026-08-12 as-of-date.
What it asks of an app →
Cross border transfer
cite Log nr. 90/2018, Art. 16
stage In effect
since 2018-07-15
source Althingi official consolidated-law database, fetched and read directly, Article 16
Article 16 of Act No. 90/2018, read directly, provides that a European Commission adequacy decision under General Data Protection Regulation (GDPR) Article 45 applies in Iceland only in accordance with the EEA Joint Committee's own decision, and requires the Minister to confirm such decisions and publish notice in the Law Gazette before they take domestic effect. This is a genuinely distinctive two-step mechanism: an adequacy decision does not apply automatically the moment the Commission adopts it.
Otherwise, a transfer outside the EEA requires appropriate safeguards such as Standard Contractual Clauses or Binding Corporate Rules, or a narrow Article 49-equivalent derogation; transfers within the EEA, including to Norway and Liechtenstein, move freely.
What it asks of an app →
Data subject rights
cite Log nr. 90/2018 (data subject rights provisions)
stage In effect
since 2018-07-15
source Althingi official consolidated-law database
Act No. 90/2018 carries the General Data Protection Regulation (GDPR) data subject rights, access, rectification, erasure, restriction, portability, and objection, into Icelandic law, including the qualified Article 22-equivalent right against a decision based solely on automated processing. Rights are exercisable against the controller, with Personuvernd as the escalation path for a complaint. No Icelandic-specific timeline departure from GDPR's one-month response window was found.
What it asks of an app →
Enforcement supervision
cite Log nr. 90/2018 (enforcement provisions)
stage In effect
since 2018-07-15
source DLA Piper and Recording Law secondary trackers for the ISK fine figures, not independently confirmed against the Act's own fine-setting section this pass
Persoonuvernd holds investigative and corrective powers and administrative-fine authority.
Because General Data Protection Regulation (GDPR) reaches Iceland through national legislation rather than direct EU regulation applicability, Act No. 90/2018 sets Iceland's fine ceiling in Icelandic krona rather than by direct reference to the EUR-denominated GDPR figures; two independent secondary sources converge on a lower tier around ISK 1.2 billion or 2 percent of global turnover and a higher tier around ISK 2.4 billion or 4 percent, mirroring the GDPR Article 83(4)/(5) structure, alongside daily compulsion fines and a criminal-penalty track for deliberate breaches.
The specific ISK figures were not independently confirmed against the Act's own fine-setting section this pass. Individuals may seek compensation for material or non-material damage, mirroring GDPR Article 82.
What it asks of an app →
Sensitive categories
cite Log nr. 90/2018, Art. 3(14), Art. 9
stage In effect
since 2018-07-15
source Althingi official consolidated-law database, fetched and read directly, Articles 3(14) and 9
Act No. 90/2018 Article 3, item 14, read directly, defines biometric data as personal data obtained through specific technical processing relating to a person's physical, physiological or behavioural characteristics that allow or confirm unique identification, and gives facial images and fingerprint data as illustrative examples using a non-exhaustive such as construction. It does not name voiceprints or voice data anywhere in this definition.
Article 9 prohibits processing biometric data for the purpose of uniquely identifying a natural person absent an Article 9(2)-style exception such as explicit consent, mirroring General Data Protection Regulation (GDPR) Article 9 with no Iceland-specific narrowing or widening found.
What it asks of an app →