🔒 Data Protection Regulatory Intelligence
GDPRI · dataprotection.gi
IS · run data-protection-2026-08-05 v13-gdpri-1.0.0
content: ai_generated 16 sources retrieved model claude-sonnet-5 ·

Iceland

IS schema gdpri-v2 trajectory: not recorded

Last updated · 10 categories · 57 claims · 16 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
57Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

No content recorded at this JID path.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

GDPR is directly incorporated and actively enforced by a functioning DPA with a multi-year enforcement track record.

Primary frameworkAct No. 90/2018 on Data Protection and the Processing of Personal Data (GDPR (EU) 2016/679 as incorporated into the EEA Agreement, Annex XI)
Traffic-light rationale — GreenGDPR is directly incorporated and actively enforced by a functioning DPA with a multi-year enforcement track record.

Sub-modules (5)

Regulator And AuthorityGreen

Persónuvernd is the independent statutory DPA supervising GDPR/Act 90/2018 compliance.

Claims: CLM-IS-4f2a1001

Act And InstrumentsGreen

Act No. 90/2018 is the operative implementing statute, cited jointly with GDPR articles in all enforcement decisions.

Claims: CLM-IS-4f2a1002

Material ScopeGreen

Material scope mirrors GDPR via EEA Agreement Annex XI incorporation.

Claims: CLM-IS-4f2a1003

Territorial ScopeGreen

Comprehensive implementation gives Icelandic data subjects protection equivalent to EU Member States.

Claims: CLM-IS-4f2a1004

Regulator Registration And FilingAmber

No general upfront registration regime; Persónuvernd instead operates an online breach-notification portal/form.

Claims: CLM-IS-4f2a1005

Category narrative47 words

Iceland is an EEA/EFTA state that has incorporated the GDPR into its domestic legal order via Act No. 90/2018 on Data Protection and the Processing of Personal Data, giving Persónuvernd (the Icelandic Data Protection Authority) enforcement powers materially equivalent to those of an EU Member State DPA.

Sources and claims (5)
  1. ConfirmedDataGuidancePersónuvernd is Iceland's independent Data Protection Authority responsible for supervising compliance with Act No. 90/2018 and the GDPR as incorporated into Icelandic law, with powers to investigate and issue administrative fines against controllers and processors.
  2. ConfirmedPersónuvernd (official translation)Act No. 90/2018 on Data Protection and the Processing of Personal Data is Iceland's primary data protection statute, giving domestic effect to the GDPR and forming the joint legal basis cited alongside GDPR articles in Persónuvernd enforcement decisions.
  3. ConfirmedEDPSThe GDPR was incorporated into the EEA Agreement (Annex XI) and applies comprehensively in Iceland as an EEA EFTA state, covering the same material scope of personal data processing as within the EU.
  4. ConfirmedEDPSAs an EEA EFTA state, Iceland has implemented EU data protection rules comprehensively such that individuals in Iceland benefit from the same level of protection as individuals in EU Member States.
  5. ProbableEuropean Data Protection BoardPersónuvernd operates a dedicated online notification portal/form through which controllers submit mandatory personal data breach notifications, rather than requiring general upfront processing-notification registration filings.

#

Directly enforced GDPR provisions with documented Icelandic case law across multiple sectors.

Primary frameworkAct No. 90/2018 (Arts. 6-9, 18) read with GDPR Arts. 5-9
Supervisory authorityPersónuvernd
Traffic-light rationale — GreenDirectly enforced GDPR provisions with documented Icelandic case law across multiple sectors.

Sub-modules (4)

Lawful BasesGreen

Article 6 GDPR lawfulness requirements actively enforced.

Claims: CLM-IS-4f2a1006

Special CategoriesGreen

Article 8 of Act 90/2018 provides enhanced protection for special-category and children's data.

Claims: CLM-IS-4f2a1008

Pseudonymisation And AnonymisationAmber

Article 18(1) of Act 90/2018 provides research-purpose derogations conditioned on separation/pseudonymisation safeguards.

Claims: CLM-IS-4f2a1009

Category narrative29 words

Lawful bases, consent standards, and special-category protections apply directly under GDPR Articles 5-9 as incorporated via Act No. 90/2018, with Iceland-specific research derogations under Article 18(1) of the Act.

Sources and claims (4)
  1. ConfirmedDataGuidancePersónuvernd enforcement decisions confirm that lawfulness of processing under Article 6 GDPR (as applied via Act No. 90/2018) is directly enforceable, including in the City of Reykjavík Seesaw decision where Article 6 GDPR was found violated.
  2. ConfirmedEuropean Data Protection BoardPersónuvernd applies GDPR Article 7 consent-validity conditions directly, as demonstrated in its fine against the Ministry of Industries and Innovation and YAY ehf. for the digital gift-card app, which cited Article 7 (conditions for consent) among the infringements.
  3. ConfirmedDataGuidanceArticle 8 of Act No. 90/2018 provides enhanced protections for special categories of personal data, including children's data, as applied in Persónuvernd's fine against the City of Reykjavík for violations of Article 8(1) subparagraphs of the Act concerning student data in the Seesaw system.
  4. ProbableEuropean Data Protection BoardArticle 18(1) of Act No. 90/2018 permits derogations from certain GDPR data-subject rights where personal data are processed solely for research or statistical purposes, subject to pseudonymisation/separation safeguards.

#

Rights are directly incorporated; EDPB coordinated actions (access 2025, erasure 2025-26) evidence active supervisory engagement in the EEA, including Iceland.

Primary frameworkGDPR Arts. 12-22 as incorporated via Act No. 90/2018
Supervisory authorityPersónuvernd
Traffic-light rationale — GreenRights are directly incorporated; EDPB coordinated actions (access 2025, erasure 2025-26) evidence active supervisory engagement in the EEA, including Iceland.

Sub-modules (5)

Access RightGreen

Article 15 access right enforced; EEA-wide 2025 CEF action examined right-of-access implementation.

Claims: CLM-IS-4f2a1010

Rectification And ErasureAmber

Article 17 GDPR erasure right subject to 2025-26 EDPB coordinated action across EEA DPAs.

Claims: CLM-IS-4f2a1011

Restriction And ObjectionAmber

Article 18(1) Act 90/2018 disapplies restriction/objection rights for research-only processing, subject to safeguards.

Claims: CLM-IS-4f2a1012

Data PortabilityAmber

Article 20 GDPR portability applies without a documented Icelandic-specific derogation.

Claims: CLM-IS-4f2a1013

Deadlines And Response WindowsAmber

Standard one-month (extendable) GDPR response window applies; no Iceland-specific modification found.

Claims: CLM-IS-4f2a1014

Category narrative36 words

Access, rectification/erasure, restriction/objection, and portability rights apply per GDPR Arts. 13-22 via Act No. 90/2018, subject to a research-purpose carve-out under Article 18(1) of the Act; no Iceland-specific deviation from GDPR's standard response deadlines was located.

Sources and claims (5)
  1. ProbableEuropean Data Protection BoardPersónuvernd participates as an EEA supervisory authority within the EDPB's Coordinated Enforcement Framework, which ran a 2025 action examining controllers' implementation of the right of access under Article 15 GDPR.
  2. ProbableEuropean Data Protection BoardThe EDPB launched a coordinated action in 2025-2026 on the right to erasure (Article 17 GDPR) applicable to participating EEA supervisory authorities, with a report on outcomes expected to be adopted in the coming months.
  3. ProbableEuropean Data Protection BoardArticle 18(1) of Act No. 90/2018 disapplies the rights to access, rectification, restriction of processing, and objection where personal data are processed exclusively for research or statistical purposes, subject to safeguards.
  4. ProbablePersónuvernd (official translation)The right to data portability under GDPR Article 20 applies directly in Iceland via incorporation of the GDPR through Act No. 90/2018, without a documented Icelandic-specific derogation identified in available sources.
  5. ProbablePersónuvernd (official translation)Controllers in Iceland must respond to data subject rights requests within the GDPR's standard one-month period (extendable by up to two further months for complex requests), incorporated without modification via Act No. 90/2018.

#

Core obligations are enforced (multiple fines), but repeated findings of DPIA, DPO-independence, and security failures (Reykjavík, InfoMentor, ice-cream-parlour cases) indicate persistent compliance gaps among controllers.

Primary frameworkGDPR Arts. 24-35 / Act No. 90/2018 Arts. 24-35
Supervisory authorityPersónuvernd
Traffic-light rationale — AmberCore obligations are enforced (multiple fines), but repeated findings of DPIA, DPO-independence, and security failures (Reykjavík, InfoMentor, ice-cream-parlour cases) indicate persistent compliance gaps among controllers.

Sub-modules (7)

Accountability And DpiaAmber

DPIA (Art. 35) failures found in the Reykjavík Seesaw case.

Claims: CLM-IS-4f2a1015

Dpo RequirementsAmber

DPO independence/involvement failures found against City of Reykjavík.

Claims: CLM-IS-4f2a1016

Ropa RequirementsGreen

Article 30 ROPA duties apply via incorporation; Persónuvernd has published ROPA/DPA templates.

Claims: CLM-IS-4f2a1017

Joint Controller ArrangementsAmber

Processor-contract (Art. 28(3)) obligations enforced in the YAY ehf. case.

Claims: CLM-IS-4f2a1018

Security MeasuresAmber

Security/transparency failures fined in the employee-surveillance case.

Claims: CLM-IS-4f2a1019

Breach NotificationAmber

Dedicated breach-notification portal exists; InfoMentor fined for a breach affecting 424 children.

Claims: CLM-IS-4f2a1020

Retention And DisposalAmber

Retention/erasure (Art. 17(1) of the Act) violation found in the Seesaw case.

Claims: CLM-IS-4f2a1021

Category narrative34 words

Accountability, DPIA, DPO, ROPA, security, breach-notification, and retention duties under GDPR Arts. 24-35 apply directly via Act No. 90/2018, with a substantial and growing Persónuvernd enforcement record across education, health, employment, and public-sector processing.

Sources and claims (7)
  1. ConfirmedDataGuidancePersónuvernd found the City of Reykjavík in violation of Article 35(1) GDPR (DPIA obligation) and Article 25(1)/(3) (data protection by design) in its use of the Seesaw educational system, resulting in a fine of ISK 5 million.
  2. ConfirmedDataGuidancePersónuvernd found that the City of Reykjavík's DPO failed to be involved in an appropriate and timely manner, lacked adequate independence, and had unresolved conflicts of interest, in violation of Article 35(3) of Act No. 90/2018 and Articles 38 and 39 GDPR.
  3. ProbableEuropean Data Protection BoardRecords-of-processing obligations under GDPR Article 30 apply to controllers and processors in Iceland via direct incorporation through Act No. 90/2018, and Persónuvernd has published templates for data processing agreements and records of processing to support compliance.
  4. ConfirmedEuropean Data Protection BoardPersónuvernd's enforcement action against the Ministry of Industries and Innovation and YAY ehf. addressed processor-contract obligations under Article 28(3) GDPR in the context of a government-vendor digital gift-card processing arrangement.
  5. ConfirmedEuropean Data Protection BoardPersónuvernd fined a company operating ice cream parlours for failing to implement adequate security and transparency measures around employee video surveillance, finding infringements of Article 13 GDPR and related security/transparency provisions.
  6. ConfirmedDataGuidancePersónuvernd operates a dedicated online breach-notification form and fined InfoMentor ISK 3.5 million for a security failure resulting in a breach affecting 424 children's personal data on an education platform.
  7. ConfirmedDataGuidancePersónuvernd's decision against the City of Reykjavík found violations of Article 17(1) of Act No. 90/2018 (data retention/erasure obligations) in connection with the Seesaw educational system.

#

Framework is fully harmonised (green) but enforcement shows recurring onward-transfer risk findings (amber) in ed-tech/cloud processing.

Primary frameworkGDPR Arts. 44-49 as incorporated via Act No. 90/2018 and EEA Agreement Annex XI
Supervisory authorityPersónuvernd
Traffic-light rationale — AmberFramework is fully harmonised (green) but enforcement shows recurring onward-transfer risk findings (amber) in ed-tech/cloud processing.

Sub-modules (6)

Transfer MechanismsAmber

Chapter V transfer mechanisms apply directly; onward-transfer risk actively scrutinised.

Claims: CLM-IS-4f2a1022

Adequacy ReceivedGreen

EU-to-Iceland transfers are not third-country transfers due to EEA incorporation.

Claims: CLM-IS-4f2a1023

Adequacy GrantedGreen

Iceland relies on EU Commission adequacy decisions incorporated into the EEA Agreement rather than issuing independent adequacy findings.

Claims: CLM-IS-4f2a1024

Sccs And BcrsGreen

SCCs/BCRs approved under GDPR are directly available to Icelandic controllers/processors.

Claims: CLM-IS-4f2a1025

Transfer Impact AssessmentAmber

Persónuvernd's Seesaw decision reflects TIA-style expectations for onward transfer risk to the US.

Claims: CLM-IS-4f2a1026

Data LocalisationAmber

No dedicated Icelandic data-localisation mandate identified beyond GDPR Chapter V.

Claims: CLM-IS-4f2a1027

Category narrative40 words

Iceland applies GDPR Chapter V transfer rules directly via EEA Agreement incorporation; it neither issues nor requires separate third-country adequacy decisions relative to the EU/EEA, and its DPA has actively scrutinised onward transfers (notably to the US) in enforcement decisions.

Sources and claims (6)
  1. ConfirmedDataGuidancePersónuvernd found that the City of Reykjavík's use of the Seesaw system created a high risk of personal data being transferred to the United States and processed without adequate protection, in violation of Articles 32, 35(1), and 46 GDPR.
  2. ConfirmedEDPSBecause the GDPR and its related adequacy decisions are incorporated into the EEA Agreement, transfers of personal data from EU Member States to Iceland are not treated as third-country transfers and do not require a separate adequacy decision.
  3. ProbableEDPSAs an EEA EFTA state applying the GDPR directly, Iceland does not issue independent third-country adequacy decisions of its own; it relies on European Commission adequacy decisions incorporated into the EEA Agreement.
  4. ProbableEDPSStandard Contractual Clauses and Binding Corporate Rules approved under the GDPR are directly available as transfer mechanisms for Icelandic controllers and processors by virtue of the GDPR's incorporation into the EEA Agreement.
  5. ProbableDataGuidanceThe Reykjavík Seesaw decision shows Persónuvernd expects controllers to assess and mitigate the risk of onward transfer to third countries such as the United States, consistent with a transfer-impact-assessment style analysis under GDPR Article 46.
  6. UncertainPersónuvernd (official translation)No general data-localisation mandate beyond the GDPR's Chapter V cross-border transfer restrictions was identified for Iceland in available sources.

#

Strong evidence in education and health; gaps in financial, telecoms, credit, and insurance sub-modules necessitate primary-source escalation.

Primary frameworkGDPR/Act No. 90/2018 general framework; no distinct sectoral statutes identified beyond education/health case law
Supervisory authorityPersónuvernd
Traffic-light rationale — AmberStrong evidence in education and health; gaps in financial, telecoms, credit, and insurance sub-modules necessitate primary-source escalation.

Sub-modules (7)

Financial Sector OverlayRed

No Iceland-specific financial-sector DP overlay identified.

Claims: CLM-IS-4f2a1028

Health Sector OverlayAmber

Genetic/health research processing scrutinised in the Landspítali/Íslensk erfðagreining case.

Claims: CLM-IS-4f2a1029

Telecoms And EprivacyRed

No Iceland-specific ePrivacy enforcement decision identified.

Claims: CLM-IS-4f2a1030

Employment DataAmber

Employee surveillance enforcement documented (ice-cream-parlour case).

Claims: CLM-IS-4f2a1031

Credit And ScoringRed

No Iceland-specific credit-scoring DP finding identified.

Claims: CLM-IS-4f2a1032

EducationAmber

Sustained enforcement against ed-tech/cloud vendors and municipalities.

Claims: CLM-IS-4f2a1033

InsuranceRed

No Iceland-specific insurance-sector DP finding identified.

Claims: CLM-IS-4f2a1034

Category narrative34 words

The clearest sectoral overlay evidenced is education (repeated ed-tech/cloud-services fines) and health/genetic research (COVID-19 sample processing); financial, telecoms/ePrivacy, credit-scoring, and insurance overlays were not evidenced by dedicated Icelandic enforcement or guidance in available sources.

Sources and claims (7)
  1. UncertainPersónuvernd (official translation)Financial-sector personal data processing in Iceland appears to be governed by the general GDPR/Act No. 90/2018 framework without a distinct financial-sector data protection overlay identified in available guidance to date.
  2. ConfirmedDataGuidancePersónuvernd found that Landspítali, Icelandic Genetics ehf., and Íslensk erfðagreining unlawfully processed COVID-19 patients' samples and data for genetic research without proper authorisation, in violation of Article 8 of Act No. 90/2018 and Article 5 GDPR.
  3. UncertainPersónuvernd (official translation)The ePrivacy framework for electronic communications applies in Iceland as an EEA state, though no Iceland-specific ePrivacy/cookie enforcement decision was identified in available sources.
  4. ConfirmedEuropean Data Protection BoardPersónuvernd's fine against an ice-cream-parlour operator for unlawful employee video surveillance demonstrates active enforcement of employment-context data protection obligations, including transparency and proportionality requirements.
  5. SpeculativePersónuvernd (official translation)No Iceland-specific credit-scoring or automated creditworthiness-assessment data protection finding was identified in available sources.
  6. ConfirmedIAPPPersónuvernd fined five municipalities a combined ISK 12.8 million over alleged improper processing of primary-school student data through Google Cloud's education technology services.
  7. SpeculativePersónuvernd (official translation)No Iceland-specific insurance-sector data protection finding or overlay was identified in available sources.

#

Framework exists in principle (GDPR incorporation) but no dedicated Icelandic enforcement or guidance evidence found for most adtech sub-modules.

Primary frameworkGDPR consent/legitimate-interest and Art. 21 objection rights as incorporated via Act No. 90/2018
Supervisory authorityPersónuvernd
Traffic-light rationale — RedFramework exists in principle (GDPR incorporation) but no dedicated Icelandic enforcement or guidance evidence found for most adtech sub-modules.

Sub-modules (6)

Cookies And TrackersAmber

General consent standards apply; no Iceland-specific cookie enforcement located.

Claims: CLM-IS-4f2a1035

Dark PatternsRed

No Iceland-specific dark-pattern finding identified.

Claims: CLM-IS-4f2a1036

Opt Out SignalsRed

No Iceland-specific opt-out-signal (e.g., GPC) guidance identified.

Claims: CLM-IS-4f2a1037

Clean Rooms And DcrRed

No Iceland-specific clean-room/DCR guidance identified.

Claims: CLM-IS-4f2a1038

Cross Context AdvertisingRed

No Iceland-specific cross-context advertising finding identified.

Claims: CLM-IS-4f2a1039

Direct MarketingAmber

General Art. 21 objection right applies; no Iceland-specific direct-marketing enforcement located.

Claims: CLM-IS-4f2a1040

Category narrative38 words

General GDPR consent and objection standards apply to cookies, direct marketing, and commercial profiling in Iceland via Act No. 90/2018, but no Iceland-specific enforcement decisions on cookies/trackers, dark patterns, opt-out signals, clean rooms, or cross-context advertising were located.

Sources and claims (6)
  1. UncertainPersónuvernd (official translation)Cookie and tracker consent requirements in Iceland derive from GDPR consent standards under Act No. 90/2018 operating alongside the ePrivacy framework, though no Iceland-specific cookie-enforcement decision was located in available sources.
  2. SpeculativePersónuvernd (official translation)No Iceland-specific dark-pattern prohibition or enforcement decision was identified in available sources.
  3. SpeculativePersónuvernd (official translation)No Iceland-specific guidance on opt-out signals such as Global Privacy Control was identified in available sources.
  4. SpeculativePersónuvernd (official translation)No Iceland-specific guidance on data clean rooms or data-collaboration-room arrangements was identified in available sources.
  5. SpeculativePersónuvernd (official translation)No Iceland-specific cross-context advertising or 'sale'/'share' of personal data finding was identified in available sources.
  6. UncertainPersónuvernd (official translation)Direct marketing processing in Iceland is subject to GDPR consent/legitimate-interest standards and the right to object under Article 21 GDPR as incorporated via Act No. 90/2018; no Iceland-specific direct-marketing enforcement decision was identified.

#

Genetic data and emerging AI-related engagement are evidenced; biometric regime and surveillance carve-outs remain gaps requiring primary-source escalation.

Primary frameworkGDPR Arts. 9, 22 as incorporated via Act No. 90/2018
Supervisory authorityPersónuvernd
Traffic-light rationale — AmberGenetic data and emerging AI-related engagement are evidenced; biometric regime and surveillance carve-outs remain gaps requiring primary-source escalation.

Sub-modules (6)

Profiling RestrictionsAmber

Article 22 GDPR applies directly; no Iceland-specific ADM/profiling enforcement decision located.

Claims: CLM-IS-4f2a1041

Automated Decision Making TransparencyAmber

General GDPR transparency duties apply; no dedicated Icelandic ADM transparency case identified.

Claims: CLM-IS-4f2a1042

Ai Risk AssessmentsAmber

Persónuvernd co-signed a February 2026 multilateral joint statement on AI-generated imagery risks.

Claims: CLM-IS-4f2a1043

Biometric RegimeRed

No Iceland-specific biometric-data regime or enforcement decision identified.

Claims: CLM-IS-4f2a1044

Genetic DataAmber

Genetic/biological sample processing scrutinised in the COVID-19 research case.

Claims: CLM-IS-4f2a1045

State Surveillance CarveoutsRed

No Iceland-specific national-security/surveillance carve-out analysis identified.

Claims: CLM-IS-4f2a1046

Category narrative44 words

Article 22 GDPR profiling/ADM restrictions and genetic-data protections apply via Act No. 90/2018, evidenced concretely in the Landspítali genetic-research case; Persónuvernd has also co-signed a 2026 multilateral statement on AI-generated imagery risks. Biometric-specific regime detail and state-surveillance carve-outs were not evidenced in available sources.

Sources and claims (6)
  1. UncertainPersónuvernd (official translation)Article 22 GDPR profiling/automated-decision-making restrictions apply directly in Iceland via Act No. 90/2018, though no Iceland-specific Persónuvernd enforcement decision addressing Article 22 was located in available sources.
  2. UncertainPersónuvernd (official translation)General GDPR transparency duties regarding automated decision-making apply via Act No. 90/2018, though no dedicated Icelandic ADM-transparency enforcement case was identified in available sources.
  3. ConfirmedEuropean Data Protection Supervisor / signatory authoritiesPersónuvernd, together with other data protection and privacy authorities, co-signed a February 2026 joint statement on AI-generated imagery emphasising that AI content-generation systems must be developed and used in accordance with applicable data protection and privacy rules, with specific attention to risks facing children and vulnerable groups.
  4. SpeculativePersónuvernd (official translation)No Iceland-specific biometric-data (facial recognition, fingerprint, gait) regime or enforcement decision was identified in available sources.
  5. ConfirmedDataGuidancePersónuvernd's decision regarding Landspítali, Icelandic Genetics, and Íslensk erfðagreining addressed unlawful processing of genetic/biological sample data for COVID-19 research, finding breaches of Article 8 of Act No. 90/2018 (special categories) and Article 5 GDPR.
  6. SpeculativePersónuvernd (official translation)No Iceland-specific analysis of national-security or state-surveillance carve-outs from GDPR/Act No. 90/2018 was identified in available sources.

#

Strong, repeated education-sector enforcement (green signal) offset by gaps in age-verification, minor-profiling, and dependent-adult sub-modules (red signal), yielding an overall amber rating.

Primary frameworkGDPR Art. 8 / Act No. 90/2018 special-category provisions on children's data
Supervisory authorityPersónuvernd
Traffic-light rationale — AmberStrong, repeated education-sector enforcement (green signal) offset by gaps in age-verification, minor-profiling, and dependent-adult sub-modules (red signal), yielding an overall amber rating.

Sub-modules (5)

Age VerificationRed

No Iceland-specific age-verification mechanism or enforcement identified.

Claims: CLM-IS-4f2a1047

Minor Profiling BansRed

No Iceland-specific minor-profiling ban or enforcement identified.

Claims: CLM-IS-4f2a1049

Education SettingsAmber

Persónuvernd has repeatedly fined education-sector controllers/processors over children's data.

Claims: CLM-IS-4f2a1050

Dependent AdultsRed

No Iceland-specific dependent-adult/elderly protection finding identified.

Claims: CLM-IS-4f2a1051

Category narrative41 words

Children's data receives heightened protection under Act No. 90/2018, evidenced by a consistent Persónuvernd enforcement pattern targeting education-sector processors (Seesaw, InfoMentor, Google Cloud in schools) and underage employees (ice-cream-parlour surveillance). Age-verification thresholds, minor-profiling bans, and dependent-adult protections were not independently evidenced.

Sources and claims (5)
  1. SpeculativePersónuvernd (official translation)No Iceland-specific age-verification mechanism or Persónuvernd enforcement decision on age verification was identified in available sources.
  2. UncertainPersónuvernd (official translation)Act No. 90/2018 and the GDPR require parental consent for information-society services offered directly to children below the relevant age threshold, applied in Iceland via direct GDPR incorporation, though no Iceland-specific enforcement decision on the parental-consent threshold itself was located.
  3. SpeculativePersónuvernd (official translation)No Iceland-specific ban or enforcement decision on profiling of minors was identified in available sources.
  4. ConfirmedDataGuidancePersónuvernd fined InfoMentor ISK 3.5 million after unauthorised parties accessed the personal data of 424 children through the company's education platform, treating children's data as meriting special protection under Act No. 90/2018.
  5. SpeculativePersónuvernd (official translation)No Iceland-specific dependent-adult (elderly/mentally incapacitated) data protection finding was identified in available sources.

#

Active enforcement and appeal pathways exist (green signal) but self-reported capacity constraints and unresolved collective-redress/private-right-of-action gaps (amber/red signals) temper the overall rating.

Primary frameworkGDPR Arts. 77-84 / Act No. 90/2018 enforcement provisions
Supervisory authorityPersónuvernd
Traffic-light rationale — AmberActive enforcement and appeal pathways exist (green signal) but self-reported capacity constraints and unresolved collective-redress/private-right-of-action gaps (amber/red signals) temper the overall rating.

Sub-modules (6)

Regulator Powers And PenaltiesGreen

Persónuvernd exercises investigative and fining powers analogous to GDPR Art. 83.

Claims: CLM-IS-4f2a1052

Enforcement Activity IndexGreen

Multiple fines/findings across sectors documented over recent years.

Claims: CLM-IS-4f2a1053

Regulator Funding And CapacityAmber

Self-reported staffing constraints relative to caseload.

Claims: CLM-IS-4f2a1054

Collective Redress And Class ActionsRed

No Iceland-specific collective-redress/class-action mechanism for DP claims identified.

Claims: CLM-IS-4f2a1055

Private Right Of ActionAmber

Judicial review of Persónuvernd decisions is available, including Supreme Court review.

Claims: CLM-IS-4f2a1056

Recent Developments 180DAmber

February 2026 multilateral joint statement on AI-generated imagery co-signed by Persónuvernd.

Claims: CLM-IS-4f2a1057

Category narrative54 words

Persónuvernd has a sustained multi-year enforcement record (fines from ISK 1.5M to ISK 12.8M across education, health, employment, and public-sector cases) but operates under acknowledged resource constraints; judicial review of its decisions is available (Icelandic Supreme Court review reported), and it participates in cross-border EEA/international regulatory coordination including a February 2026 joint AI statement.

Sources and claims (6)
  1. ConfirmedIAPPPersónuvernd has issued multiple administrative fines under Act No. 90/2018 and the GDPR, ranging from ISK 1.5 million to ISK 12.8 million in identified cases, exercising investigative and sanctioning powers analogous to Article 83 GDPR's maximum-fine provisions.
  2. ConfirmedIAPPPersónuvernd's recent enforcement record includes fines against the City of Reykjavík (Seesaw), InfoMentor (education breach), an employer operating ice cream parlours (employee surveillance), the Ministry of Industries and Innovation/YAY ehf. (digital gift-card app), five municipalities (Google Cloud in schools), and an unlawfulness finding against Landspítali/Icelandic Genetics/Íslensk erfðagreining (COVID-19 genetic research).
  3. ConfirmedEuropean Data Protection BoardPersónuvernd has reported resource constraints, noting it is divided into sub-units of around 3-5 staff members each with limited backup capacity, while handling several hundred open cases (approximately 800 open registered cases as reported in its GDPR Article 97 evaluation questionnaire response).
  4. UncertainPersónuvernd (official translation)No Iceland-specific collective-redress or class-action mechanism for data protection claims was identified in available sources.
  5. UncertainDataGuidanceData subjects in Iceland may lodge complaints with Persónuvernd and seek judicial remedies before Icelandic courts, including appeal of Persónuvernd decisions; a reported Icelandic Supreme Court ruling partially confirmed a Persónuvernd decision, evidencing an available judicial-review pathway.
  6. ConfirmedEuropean Data Protection Supervisor / signatory authoritiesIn February 2026, Persónuvernd (represented by Data Protection Commissioner Helga Þórisdóttir and Head of International Affairs & Guidance Helga Sigríður Þórhallsdóttir) co-signed a multilateral joint statement with other data protection and privacy authorities addressing risks from AI-generated imagery, including harms to children and vulnerable groups.
No categories match.

Filters combine as OR inside a group and AND across groups.

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Iceland
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewernot recorded
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-05. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 57 claim(s), 16 source(s) in the cumulative register.