EnglishIS
Iceland flag

Iceland

Iceland Data Privacy Laws: GDPR via EEA, Act No. 90/2018, and Persónuvernd (2026 Guide)

By Recording Law Editorial TeamReviewed September 9, 202621 min read
Iceland Data Privacy Laws: GDPR via EEA, Act No. 90/2018, and Persónuvernd (2026 Guide)

Frequently Asked Questions

Does the GDPR apply in Iceland?

Yes. Iceland applies the GDPR through the EEA Agreement. The EEA Joint Committee incorporated the GDPR into the EEA Agreement by Decision No. 154/2018, adopted on 6 July 2018, and the regulation entered into force in Iceland on 20 July 2018. Act No. 90/2018 simultaneously implemented the GDPR in domestic law. The regulation applies in Iceland with the same substantive effect as in EU Member States.

What is Persónuvernd and what powers does it have?

Persónuvernd is Iceland's independent data protection supervisory authority, established under Act No. 90/2018. It investigates complaints, conducts audits, issues binding orders, and imposes administrative fines of up to ISK 2.4 billion or 4% of global annual turnover for serious violations. It also imposes daily compulsion fines to enforce compliance with its orders and can refer serious cases for criminal prosecution, where imprisonment of up to three years is possible.

What fines can Iceland's data protection authority impose?

For serious violations of core GDPR principles, data subject rights, and transfer restrictions (Article 83(5)), Persónuvernd can impose fines from ISK 100,000 to ISK 2.4 billion, or 4% of global annual turnover, whichever is higher. For lesser violations of controller and processor obligations (Article 83(4)), fines range from ISK 100,000 to ISK 1.2 billion, or 2% of turnover. Daily fines of up to ISK 200,000 may also be imposed for non-compliance with authority orders.

Can personal data flow freely between Iceland and EU countries?

Yes. As an EEA member, Iceland is part of the EU/EEA free data flow zone. Personal data may be transferred between Iceland and all 27 EU Member States, and between Iceland and Norway and Liechtenstein, without any additional transfer mechanism under GDPR Chapter V. Transfers to countries outside the EEA require adequacy decisions, standard contractual clauses, binding corporate rules, or an Article 49 derogation.

When must a data breach be reported to Persónuvernd?

Controllers must notify Persónuvernd of a personal data breach without undue delay and, where feasible, not later than 72 hours after becoming aware of the breach. Notification is not required only where the breach is unlikely to result in any risk to individuals' rights and freedoms. Where notification is delayed beyond 72 hours, the controller must explain the reasons. High-risk breaches must also be communicated directly to affected individuals.

What is Iceland's age of digital consent?

Iceland set the age of digital consent at 13, the minimum permitted under GDPR Article 8. Article 10(5) of Act No. 90/2018 provides that children aged 13 and over may give valid consent for information society services. For children under 13, a parent or legal guardian must provide or authorise consent.

Does Iceland have to apply the EU AI Act?

Not yet as of mid-2026. The EU AI Act entered into force on 1 August 2024 for EU Member States, but it has not been incorporated into the EEA Agreement by a Joint Committee Decision. Iceland, Norway, and Liechtenstein participate in EU AI Board meetings as observers. Until a formal EEA Joint Committee Decision is adopted, the AI Act does not apply as binding domestic law in Iceland. Icelandic organisations deploying AI systems on the EU market remain subject to the AI Act for their EU-connected operations.

Who needs to appoint a Data Protection Officer in Iceland?

Under Act No. 90/2018, a DPO is mandatory for: (1) all public authorities and bodies, (2) controllers and processors whose core activities require regular and systematic monitoring of data subjects on a large scale, and (3) controllers and processors whose core activities consist of large-scale processing of special category data or criminal conviction data. Iceland did not extend mandatory DPO requirements beyond these GDPR Article 37 categories.

Updates

AI Act dates updated for the July 2026 Digital Omnibus: high-risk obligations now apply 2 December 2027 (Annex III) and 2 August 2028 (Annex I); the 2 August 2026 transparency date is unchanged.

Full refresh: expanded coverage of EEA incorporation mechanics, constitutional basis, DPO requirements, Electronic Communications Act No. 70/2022, Rules No. 50/2023 on electronic surveillance, 2024-2025 Persónuvernd enforcement actions (Heilsugæsla höfuðborgarsvæðisins, Heilsuvera breach, Google Workspace for Education fines), EU AI Act EEA status, updated 2024 caseload statistics.

Initial publication.

Sources and References

  1. GDPR Incorporated into EEA Agreement - EFTA(efta.int).gov
  2. Scope of the Data Protection Act - Ísland.is(island.is).gov
  3. Icelandic SA Fine - Primary Health Care Capital Area 2025 - EDPB(edpb.europa.eu).gov
  4. Reykjavik Municipality Fined for Google Workspace for Education - EDPB(edpb.europa.eu).gov
  5. Reykjavik Municipality Fined for Seesaw Educational System - EDPB(edpb.europa.eu).gov
  6. Nordic DPA Cooperation 2024 - Datatilsynet(datatilsynet.no).gov
  7. Iceland Data Protection Laws - DLA Piper(dlapiperdataprotection.com)
  8. Iceland Key Data and Cybersecurity Laws - Baker McKenzie(resourcehub.bakermckenzie.com)
  9. Act No. 90/2018 on Data Protection - WIPO Lex(wipo.int).gov
  10. Kópavogur Municipality Fined for Google Workspace for Education 2024 - EDPB(edpb.europa.eu)
  11. GDPR Guide to National Implementation Iceland - White and Case(whitecase.com)
  12. Iceland Breach Notification - DLA Piper Data Protection Laws of the World(dlapiperdataprotection.com)
  13. Regulation (EU) 2026/1744 of 8 July 2026 amending Regulation (EU) 2024/1689 (Digital Omnibus on AI), OJ L 2026/1744, 24.7.2026(eur-lex.europa.eu).gov
Share: