Skip to the content
Global Data RulesData governance rules, country by country

Compare countries

Two or three countries, side by side, one row per question. Pick up to 3.

Countries
IcelandChecked 18 August 2026
Depends on your industryWork: HighEnforcement: Active
In one paragraph
Iceland follows Europe's privacy rulebook, so personal data can leave the country once the right paperwork is in place. Two local rules surprise people: a company's accounting records must physically be kept in Iceland, and health record systems can only be hosted by a certified provider. The privacy regulator is small but genuinely busy, and it fines public bodies too.
The catch
The relaxed answer is true for personal data only. Iceland's bookkeeping law says a company's books, invoices and receipts must be kept in Iceland for seven years, and only lets you hold them abroad for up to six months — and breaking the bookkeeping law is a crime, not a fine from the privacy regulator. Health record hosting has its own certification wall. Separately, three European laws that people assume apply here — the Data Act, the cybersecurity law known as NIS2, and the Artificial Intelligence Act — have NOT yet been brought into Icelandic law, so the rights and deadlines they create do not exist in Iceland today.
Does this apply to me?
Yes, it reaches you with no office in Iceland. Iceland applies Europe's General Data Protection Regulation through the European Economic Area agreement, so the rules cover any organisation anywhere in the world that offers goods or services to people in Iceland, or that watches what they do. There is no size or revenue threshold to duck under. If your organisation has no establishment anywhere in Europe, you normally have to name a representative inside Europe who people and the regulator can contact.High confidence
Can the data leave the country?
For personal data, yes — it can leave once you have the right paperwork. Two Icelandic rules cut across that headline. First, your company's accounting books, invoices and receipts must be kept in Iceland for seven years; the law only lets you hold them abroad for up to six months. Second, a health record system can sit with an outside host only if that host holds a recognised security certificate and the normal rules for sending data out of Europe are met.Medium confidence
What do I have to do to send it abroad?
You use one of the standard European routes. Send the data to a country Europe has officially approved, or sign the European Commission's standard contract with the recipient, or use group-wide rules a regulator has approved. Narrow one-off exceptions exist, such as the person's explicit consent, but they are not for routine or bulk transfers. One Icelandic wrinkle catches people out: an approval of a foreign country only takes effect in Iceland once the Icelandic minister confirms it and publishes a notice in the official gazette.Medium confidence
Who enforces this — and are they actually working?
Persónuvernd, the Icelandic Data Protection Authority. It is genuinely operational, not a name on paper: it registered 2,124 new cases in 2025 and closed 2,232, it opens its own investigations without waiting for a complaint, and it fines public bodies as well as private companies. It is also small — about 17 staff and a budget of roughly 379 million krónur (about $2.8 million) — and it says in its own annual report that it cannot cover every task the law gives it.High confidence
How long must I keep it, and when must I delete it?
There is a floor and a ceiling, and they point in opposite directions. The floor: accounting books, invoices and receipts must be kept for seven years — and kept in Iceland. The ceiling: under the European rules you must delete personal data once you no longer need it for the purpose you collected it for. When the two clash, the keeping duty wins; a person cannot force you to delete records the bookkeeping and tax law requires you to hold.High confidence
What happens when something goes wrong?
Count at least two clocks, and three if you are a financial firm. You have 72 hours to report a personal data breach to Persónuvernd, and you must tell the people affected without delay where the risk to them is high. Separately, operators of critical services — banks, hospitals, energy, water, transport and digital infrastructure — must alert Iceland's national cyber security team as soon as possible under a 2019 law, and serious breaches of that law can lead to prosecution. Financial firms have a further, tighter reporting duty to the Central Bank under the European operational resilience rules.Medium confidence
What's the trap?
Five things that are not in the summary. (1) A child in Iceland is anyone under 13 for online consent, not 16 as in much of Europe — so a design built for a 16-year-old threshold is wrong here. (2) Your accounting records must sit in Iceland, and bookkeeping offences are criminal: fines, and up to six years in prison for serious cases, investigated by the district prosecutor and the tax investigators, not by the privacy regulator. (3) Public bodies can be fined in Iceland — the law says so expressly, unlike several European countries. (4) Some processing needs a licence from Persónuvernd before you start, which is unusual under the European regime. (5) Three European laws you may assume apply here do not yet: the Data Act, the cybersecurity law known as NIS2, and the Artificial Intelligence Act have not been brought into the European Economic Area agreement.High confidence
What's about to change?
The main thing to watch is not an Icelandic bill but the queue of European laws waiting to be pulled into Icelandic law. The Data Act, the cybersecurity law known as NIS2 and the Artificial Intelligence Act are all still outside the European Economic Area agreement as of 18 August 2026, and each will land when a joint committee decides — with no Icelandic public consultation and often at short notice. The financial resilience regulation already landed this way on 1 July 2025, more than five months after it started applying in the European Union.High confidence
Hardest industry wall
  • All industries Lög um bókhald
MaltaChecked 18 August 2026
Depends on your industryWork: MediumEnforcement: Active
In one paragraph
Malta runs on the European rulebook. Data may go abroad once the right paperwork is in place, and there is no general rule that it must stay on the island. Two things break that. Online gaming companies must keep their core systems inside Europe. And any Maltese company that keeps its books abroad must still keep a copy of its accounts in Malta.
The catch
The easy answer stops being true in three places. First, online gaming, which is Malta's biggest regulated industry: a licensed operator's 'key technical setup' — including the player database, the financial database and the control system — must sit in Malta or another European Economic Area country, unless the Malta Gaming Authority approves another location one case at a time. The same operator must also run a live mirror of its essential regulatory data that the Authority can reach at any moment, including physically. Second, company law: if a company keeps its accounting records outside Malta, it must still send to Malta, and keep in Malta, accounts and returns good enough to show the financial position at least every six months. Third, government: the public administration's own cloud policy says cloud services should as a rule be inside the European Union or European Economic Area, and anything classified must go on the government's own cloud. Banking, payments, insurance, securities, health, education and mapping have no storage-location rule that we could find, checked 18 August 2026.
Does this apply to me?
Yes. Malta's Data Protection Act reaches a company with no office in Malta if it offers goods or services to people in Malta, or watches their behaviour in Malta. There is no size or revenue threshold. There is no extra Maltese representative to appoint beyond the one the European rules already require of companies based outside Europe.High confidence
Can the data leave the country?
In general, yes. Malta has no law saying personal data must be stored on the island. It follows the European Union rules: send data outside Europe once you have an approved destination or the right contract. Three areas override that. Online gaming is the big one, and it is Malta's flagship industry.High confidence
What do I have to do to send it abroad?
Use the European toolkit. Send data to a country the European Commission has approved, or sign the European standard contract, or use approved group-wide rules. Malta adds nothing on top. Malta's own minister has a power to restrict transfers of named categories of data, but has never used it, so the list of Maltese restrictions is empty today.High confidence
Who enforces this — and are they actually working?
The Information and Data Protection Commissioner. It is real, staffed and issuing decisions: its public register shows around nineteen decisions published in 2026 and thirty-eight in 2025. The fines are small by European standards — most sit between about 2,000 and 20,000 euros (roughly $2,300 to $23,000). The gaming regulator is the harder one, and it cancels licences.High confidence
How long must I keep it, and when must I delete it?
There is a floor and a ceiling. The floor: company accounting records for ten years, tax and value-added-tax records for at least six years, and anti-money-laundering records for five years. The ceiling: the European rule that you delete personal data once you no longer need it. Where they clash, the specific Maltese law that orders you to keep something wins, because keeping it is then a legal duty.High confidence
What happens when something goes wrong?
Count three clocks, and they do not line up. Seventy-two hours to tell the privacy regulator about a personal data breach. Twenty-four hours to send a first warning about a serious cyber incident, then seventy-two hours for the full report and one month for the final one. Phone and internet companies have their own separate duty to report straight away.High confidence
What's the trap?
Five things that are not in the summary. A child in Malta is thirteen, not sixteen. Health and biometric research needs the regulator's written permission before you start, not just a risk assessment. Copying someone's identity card is restricted. Leaking a client secret can be a crime, not a fine. And the gaming regulator can keep personal data forever, in a law that says so out loud.High confidence
What's about to change?
Three dated changes. On 1 January 2027 a new law stops insurers, banks and employers asking about a cancer diagnosis once enough time has passed since treatment. On 12 January 2027 European rules make cloud switching and data export fees free. And Malta's artificial intelligence rules started phasing in on 2 August 2026, with the privacy regulator now policing the market.High confidence
Hardest industry wall
  • All industries Att dwar il-Kumpaniji (Kap. 386), artikolu 163