#
GDPR is directly incorporated and actively enforced by a functioning DPA with a multi-year enforcement track record.
Sub-modules (5)
Regulator And AuthorityGreen
Persónuvernd is the independent statutory DPA supervising GDPR/Act 90/2018 compliance.
Claims: CLM-IS-4f2a1001
Act And InstrumentsGreen
Act No. 90/2018 is the operative implementing statute, cited jointly with GDPR articles in all enforcement decisions.
Claims: CLM-IS-4f2a1002
Material ScopeGreen
Material scope mirrors GDPR via EEA Agreement Annex XI incorporation.
Claims: CLM-IS-4f2a1003
Territorial ScopeGreen
Comprehensive implementation gives Icelandic data subjects protection equivalent to EU Member States.
Claims: CLM-IS-4f2a1004
Regulator Registration And FilingAmber
No general upfront registration regime; Persónuvernd instead operates an online breach-notification portal/form.
Claims: CLM-IS-4f2a1005
Sources and claims (5)
- ConfirmedDataGuidance — Persónuvernd is Iceland's independent Data Protection Authority responsible for supervising compliance with Act No. 90/2018 and the GDPR as incorporated into Icelandic law, with powers to investigate and issue administrative fines against controllers and processors.
- ConfirmedPersónuvernd (official translation) — Act No. 90/2018 on Data Protection and the Processing of Personal Data is Iceland's primary data protection statute, giving domestic effect to the GDPR and forming the joint legal basis cited alongside GDPR articles in Persónuvernd enforcement decisions.
- ConfirmedEDPS — The GDPR was incorporated into the EEA Agreement (Annex XI) and applies comprehensively in Iceland as an EEA EFTA state, covering the same material scope of personal data processing as within the EU.
- ConfirmedEDPS — As an EEA EFTA state, Iceland has implemented EU data protection rules comprehensively such that individuals in Iceland benefit from the same level of protection as individuals in EU Member States.
- ProbableEuropean Data Protection Board — Persónuvernd operates a dedicated online notification portal/form through which controllers submit mandatory personal data breach notifications, rather than requiring general upfront processing-notification registration filings.