Law / Iceland

Iceland

privacy

Iceland is not an EU member; the General Data Protection Regulation (GDPR) reaches it through EEA Joint Committee Decision No. 154/2018, given domestic effect by Act No. 90/2018 on Data Protection and the Processing of Personal Data, which is the controlling instrument recorded here rather than the EU Regulation directly.

Read directly from the Act's own consolidated text, Article 3(14) defines biometric data with an illustrative, non-exhaustive example list naming facial images and fingerprint data but not voiceprints, Article 9 prohibits processing biometric data for unique identification absent an explicit-consent-style exception, and Article 16 requires its own EEA Joint Committee decision plus ministerial confirmation before a European Commission adequacy decision takes effect in Iceland. As at 2026-08-24; later amendment to Act No. 90/2018 is not independently confirmed.

11 instruments named 6 researched in detail As of 2026-08-24

Instruments

Each one links to its LexLint note, which carries what it requires and what it flags on.

Breach notification

Act No. 90/2018, Breach Notification in Iceland

cite Log nr. 90/2018 (breach notification provisions) stage In effect since 2018-07-15 source DLA Piper and Recording Law secondary trackers, corroborating the Act's GDPR-mirroring breach-notification structure

Act No. 90/2018 carries the General Data Protection Regulation (GDPR) breach-notification duties into Icelandic law: a controller must notify Personuvernd without undue delay, and where feasible within 72 hours of becoming aware of a personal data breach, unless the breach is unlikely to result in a risk to natural persons' rights and freedoms, and must notify affected individuals without undue delay where the breach is likely to result in a high risk.

No Icelandic-specific timeline departure was found; this dimension rests on secondary commentary corroborating the Act's GDPR-mirroring structure rather than a direct read of the breach-notification section itself.

What it asks of an app

Comprehensive regime

Act No. 90/2018 on Data Protection and the Processing of Personal Data

cite Log nr. 90/2018 um personuvernd og vinnslu personuupplysinga (Act No. 90/2018), passed by Althingi 27 June 2018, in force 15 July 2018 stage In effect since 2018-07-15 source Althingi official consolidated-law database, fetched and read directly

Iceland is not an EU member, so the General Data Protection Regulation (GDPR) does not apply directly. GDPR reaches Iceland through EEA Joint Committee Decision No. 154/2018, incorporating it into the EEA Agreement, and Act No. 90/2018 gives that incorporation domestic legal force. The Act's own Article 2, read directly, names Decision No. 154/2018 as the incorporation mechanism, and the Act reproduces the GDPR text itself as an appendix. Persoonuvernd (the Icelandic Data Protection Authority) is the supervisory authority.

Privacy law is a settled, fully in-force regime in Iceland since 2018, distinct from Iceland's AI-law posture, where the EU AI Act's own EEA incorporation was still pending as of the derived candidate list's 2026-08-12 as-of-date.

What it asks of an app

Cross border transfer

Act No. 90/2018 Article 16, Cross-Border Transfer of Personal Data from Iceland

cite Log nr. 90/2018, Art. 16 stage In effect since 2018-07-15 source Althingi official consolidated-law database, fetched and read directly, Article 16

Article 16 of Act No. 90/2018, read directly, provides that a European Commission adequacy decision under General Data Protection Regulation (GDPR) Article 45 applies in Iceland only in accordance with the EEA Joint Committee's own decision, and requires the Minister to confirm such decisions and publish notice in the Law Gazette before they take domestic effect. This is a genuinely distinctive two-step mechanism: an adequacy decision does not apply automatically the moment the Commission adopts it.

Otherwise, a transfer outside the EEA requires appropriate safeguards such as Standard Contractual Clauses or Binding Corporate Rules, or a narrow Article 49-equivalent derogation; transfers within the EEA, including to Norway and Liechtenstein, move freely.

What it asks of an app

Data subject rights

Act No. 90/2018, Data Subject Rights in Iceland

cite Log nr. 90/2018 (data subject rights provisions) stage In effect since 2018-07-15 source Althingi official consolidated-law database

Act No. 90/2018 carries the General Data Protection Regulation (GDPR) data subject rights, access, rectification, erasure, restriction, portability, and objection, into Icelandic law, including the qualified Article 22-equivalent right against a decision based solely on automated processing. Rights are exercisable against the controller, with Personuvernd as the escalation path for a complaint. No Icelandic-specific timeline departure from GDPR's one-month response window was found.

What it asks of an app

Enforcement supervision

Act No. 90/2018, Persoonuvernd Enforcement in Iceland

cite Log nr. 90/2018 (enforcement provisions) stage In effect since 2018-07-15 source DLA Piper and Recording Law secondary trackers for the ISK fine figures, not independently confirmed against the Act's own fine-setting section this pass

Persoonuvernd holds investigative and corrective powers and administrative-fine authority.

Because General Data Protection Regulation (GDPR) reaches Iceland through national legislation rather than direct EU regulation applicability, Act No. 90/2018 sets Iceland's fine ceiling in Icelandic krona rather than by direct reference to the EUR-denominated GDPR figures; two independent secondary sources converge on a lower tier around ISK 1.2 billion or 2 percent of global turnover and a higher tier around ISK 2.4 billion or 4 percent, mirroring the GDPR Article 83(4)/(5) structure, alongside daily compulsion fines and a criminal-penalty track for deliberate breaches.

The specific ISK figures were not independently confirmed against the Act's own fine-setting section this pass. Individuals may seek compensation for material or non-material damage, mirroring GDPR Article 82.

What it asks of an app

Sensitive categories

Act No. 90/2018 Articles 3(14) and 9, Special Categories in Iceland

cite Log nr. 90/2018, Art. 3(14), Art. 9 stage In effect since 2018-07-15 source Althingi official consolidated-law database, fetched and read directly, Articles 3(14) and 9

Act No. 90/2018 Article 3, item 14, read directly, defines biometric data as personal data obtained through specific technical processing relating to a person's physical, physiological or behavioural characteristics that allow or confirm unique identification, and gives facial images and fingerprint data as illustrative examples using a non-exhaustive such as construction. It does not name voiceprints or voice data anywhere in this definition.

Article 9 prohibits processing biometric data for the purpose of uniquely identifying a natural person absent an Article 9(2)-style exception such as explicit consent, mirroring General Data Protection Regulation (GDPR) Article 9 with no Iceland-specific narrowing or widening found.

What it asks of an app

This summary covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted above and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.