Skip to the content
Global Data RulesData governance rules, country by country

Iceland

Part of the EEA, so bloc-wide rules apply here too. Checked about 2 months ago, on 18 August 2026.

If you collect data about people in Iceland — customers, users, employees — these are the rules you have to follow. Here is the short version.

The short version

Depends on your industryWork: HighEnforcement: Active

Iceland follows Europe's privacy rulebook. Personal data can leave the country once you have the right paperwork. Two local rules surprise people. Your company's accounting records must physically be kept in Iceland. And health record systems can only be hosted by a certified provider. The privacy regulator is small but busy, and it fines public bodies too.

Data governance in Iceland

The eight things that decide how you handle data about people in Iceland. Same eight on every country page, so you can compare.

Who has to follow these rules

Yes, the law reaches you with no office in Iceland. Iceland applies Europe's General Data Protection Regulation through the European Economic Area agreement. So the rules cover any organisation anywhere in the world that offers goods or services to people in Iceland. They also cover anyone who watches what those people do. There is no size or revenue threshold to duck under. If you have no office anywhere in Europe, you normally have to name a representative inside Europe. People and the regulator contact that representative.

What you have to do here:
Appoint a representative

Where the data is allowed to live

Yes, personal data can leave once you have the right paperwork. Two Icelandic rules cut across that. First, your company's accounting books, invoices and receipts must be kept in Iceland for seven years. The law lets you hold them abroad for up to six months. Second, an outside company can host a health record system only if it holds a recognised security certificate. You must also meet the normal rules for sending data out of Europe.

What to do: Plan for a database inside Iceland: this data is not allowed to leave.

Not fully verified — see “What we're not sure about” below.

Sending data out of the country

You use one of the standard European routes. Send the data to a country Europe has officially approved as safe enough. Or sign the European Commission's standard contract with the receiver. Or use group-wide rules a regulator has approved. There are narrow one-off exceptions, such as the person's explicit consent. Those are not for routine or bulk transfers. One Icelandic detail catches people out. An approval of a foreign country only takes effect in Iceland once the Icelandic minister confirms it and publishes a notice in the official gazette.

Ways to send data out:
Official 'this country is safe' decision · Standard contract clauses · Approved group rules · Explicit consent · Needed for a contract

What to do: Check the destination against the approved list first. Anywhere that is not on it needs the standard contract clauses signed before data leaves.

Not fully verified — see “What we're not sure about” below.

The regulator, and whether it actually acts

Persónuvernd, the Icelandic Data Protection Authority, enforces the rules. It is fully up and running. It registered 2,124 new cases in 2025 and closed 2,232. It opens its own investigations without waiting for a complaint. It fines public bodies as well as private companies. It is also small. It has about 17 staff and a budget of roughly 379 million krónur (about 2.8 million US dollars). It says in its own annual report that it cannot cover every task the law gives it.

How long you must keep it — and when to delete it

There is a minimum keeping time and a duty to delete, and they point in opposite directions. You must keep accounting books, invoices and receipts for seven years, and keep them in Iceland. Under the European rules you must delete personal data once you no longer need it for the purpose you collected it for. When the two clash, keeping wins. A person cannot force you to delete records that the bookkeeping and tax law require you to hold.

What you have to do here:
Keep data for a minimum period · Delete data after a period

What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.

If something goes wrong

There are at least two deadlines, and three if you are a financial firm. You have 72 hours to report a personal data breach to Persónuvernd. You must tell the people affected without delay where the risk to them is high. Separately, operators of critical services must alert Iceland's national cyber security team as soon as possible under a 2019 law. Those services are banks, hospitals, energy, water, transport and digital infrastructure. Serious breaches of that law can lead to prosecution. Financial firms have a further, tighter reporting duty to the Central Bank under the European operational resilience rules.

What you have to do here:
Report breaches to the regulator · Tell affected people · Report cyber incidents

What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.

Not fully verified — see “What we're not sure about” below.

What catches people out

Five things the summary does not cover. (1) For online consent, a child in Iceland is anyone under 13. Much of Europe uses 16. A product built for a 16-year-old threshold is wrong here. (2) Your accounting records must sit in Iceland. Bookkeeping breaches are crimes: fines, and up to six years in prison for serious cases. The district prosecutor and the tax investigators handle them, not the privacy regulator. (3) Public bodies can be fined in Iceland. The law says so directly, unlike in several European countries. (4) Some uses of data need a licence from Persónuvernd before you start. That is unusual under the European rules. (5) Three European laws do not yet apply here. The Data Act, the cybersecurity law known as NIS2, and the Artificial Intelligence Act have not been brought into the European Economic Area agreement.

What you have to do here:
Get a parent's consent for children
What it costs if you get it wrong:
Criminal liability

What's changing next

The main thing to watch is the queue of European laws waiting to be pulled into Icelandic law. It is not an Icelandic bill. Three laws were still outside the European Economic Area agreement on 18 August 2026. They are the Data Act, the cybersecurity law known as NIS2, and the Artificial Intelligence Act. Each will land when a joint committee decides. There is no Icelandic public consultation, and often little notice. The financial resilience regulation landed this way on 1 July 2025. That was more than five months after it started applying in the European Union.

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries3 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Health and social care

Health data rules

Official name: Reglugerð um sjúkraskrár · Nr. 550/2015, issued under the Health Records Act no. 55/2009 · Directly binding regulation

In forceYes, with paperwork

An outside supplier may host Icelandic health record systems, and that supplier may sit abroad. Two conditions apply. The supplier must hold a recognised security certification such as ISO 27001. And you must meet the normal conditions for sending personal data out of the country. The Directorate of Health oversees the national electronic health record.

In force since 15 June 2015

Enforced by Directorate of Health

How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Certification scheme

Finance

Payment data rules

Official name: Reglugerð (ESB) 2022/2554 um stafrænt rekstrarþol fjármálageirans (DORA), incorporated into the EEA Agreement · EEA Joint Committee Decision No. 40/2025 of 20 February 2025 · Directly binding regulation

In forceYes, with paperwork

Europe's financial operational resilience regulation reached Iceland on 1 July 2025. That was more than five months after it started applying in the European Union. It does not make banks, insurers, payment firms or investment firms keep data in the country. It does require four things. Your contract must name where data will be held and used. You must keep a register of supplier arrangements. You need exit plans. And you must report incidents.

In force since 1 July 2025

Enforced by Central Bank of Iceland (Financial Supervision)

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Government

Cyber security rules

Official name: Lög um öryggi net- og upplýsingakerfa mikilvægra innviða · Nr. 78/2019 · Act of parliament

In forceYes — store it anywhere

Iceland's cybersecurity law for critical infrastructure: energy, water, transport, health, banking and digital infrastructure. You must report incidents to the national cyber team as fast as possible. There is no fixed deadline. Breaking it can be a crime. This is the older European standard. The replacement law known as NIS2 has not yet been brought into the European Economic Area agreement. So this is still what binds you in Iceland.

In force since 1 September 2020

Enforced by CERT-IS — national cyber security team

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Applies to every company2 rules

These bind you whatever business you are in, once the country's rules reach you.

Children's data rules

Official name: Lög um persónuvernd og vinnslu persónuupplýsinga · Nr. 90/2018 · Act of parliament

In forceYes, with paperwork

Iceland's national data protection act. It carries the European rules into Icelandic law and adds three local twists. Children give their own consent from age 13. Fines can be imposed on government bodies as well as companies. And some uses of data need a licence from the regulator before you begin.

In force since 15 July 2018

Enforced by Icelandic Data Protection Authority

How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Explicit consent, Needed for a contract

Personal data needs a copy kept in the country

Official name: Lög um bókhald · Nr. 145/1994, 20. gr. · Act of parliament

In forceA copy must stay

The real Icelandic rule about keeping data in the country, and the one most trackers miss. Every company's accounting books, vouchers and supporting data must be kept inside Iceland for seven years. You may store them abroad for six months at most. Breaches are crimes, not administrative matters. The district prosecutor and the tax investigation authority handle them.

In force since 1 January 1995

Enforced by Iceland Revenue and Customs

How this country controls where data goes: Approval each time

Applies across the EEA2 rules

Written once for the whole bloc, and in force in every member country.

Europe's main privacy law

Official name: Reglugerð (ESB) 2016/679 (General Data Protection Regulation), incorporated into the EEA Agreement · EEA Joint Committee Decision No. 154/2018 of 6 July 2018 · Directly binding regulation

In forceYes, with paperwork

Europe's General Data Protection Regulation applies in Iceland through the European Economic Area agreement, not through European Union membership. It does not require data to stay in Iceland or in Europe. It sets conditions for sending data out. Nothing in it forces you to keep data in the country.

In force since 20 July 2018

Enforced by Icelandic Data Protection Authority

How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims

Cloud and outsourcing rules

Official name: Reglugerð (ESB) 2023/2854 (Data Act) — adopted in the European Union, NOT yet incorporated into the EEA Agreement · Regulation (EU) 2023/2854; no EEA Joint Committee Decision as of 18 August 2026 · Directly binding regulation

Passed, not yet fully in forceYes — store it anywhere

The European Data Act does not apply in Iceland. It has applied in the European Union since 12 September 2025. From 12 January 2027 it bans cloud switching charges and charges for moving your data out. It is still outside the European Economic Area agreement, so it creates no rights and no duties in Iceland today. A single joint committee decision can switch it on, with no Icelandic consultation.

Enforced by Icelandic Data Protection Authority

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Who you would hear from

  • Persónuvernd

    General data protection law, licensing of certain processing, electronic monitoring

    Fully up and running, and busy. It registered 2,124 new cases in 2025 and concluded 2,232. It has roughly 17 full-time staff and a budget of ISK 378.7 million (about 2.8 million US dollars). It issues fines, including against public bodies. It runs audits it starts itself, most recently of the prosecution service in June 2026. Its own annual report says its resources do not stretch to every task the law gives it.

  • Seðlabanki Íslands — Fjármálaeftirlitið

    Banks, insurers, payment firms, investment firms; digital operational resilience

    Financial supervision was merged into the Central Bank in 2020. It supervises DORA compliance in Iceland from 1 July 2025. So we could not confirm any outsourcing or cloud conditions beyond DORA.

  • Embætti landlæknis

    Health records, national electronic health record oversight

    Has nationwide oversight of the electronic health record under Regulation 550/2015.

  • Netöryggissveitin CERT-IS

    Cyber incident reporting and response for critical infrastructure and the wider Icelandic internet

    Operates a national security operations centre with 24-hour monitoring and an open incident reporting channel.

  • Fjarskiptastofa

    Telecoms regulation and digital infrastructure security

    Named as the supervisory authority for digital infrastructure under Act 78/2019.

  • Skatturinn

    Tax and bookkeeping records; the tax investigation function enforces the Bookkeeping Act alongside the district prosecutor

    The district prosecutor (héraðssaksóknari) and the tax investigation authority investigate bookkeeping breaches. They can be prosecuted as crimes.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.

  • Whether the Electronic Communications Act No. 70/2022 still requires telecom operators to retain traffic and location data, for how long, and whether any part of that duty has been disapplied following European court rulings

    We could not confirm the current position on keeping telecom traffic data. The full law on the parliament's own site is too long for automated retrieval. Every attempt stopped at around Article 31 to 36, well before Chapter XIII on privacy in electronic communications. We can confirm only that Article 109 of the 2022 Act repealed the previous Act No. 81/2003. Treat Icelandic telecom retention as unresearched, not as absent. If you run a telecoms service, check before you rely on this.

  • The detailed conditions in rules no. 1155/2022 on the transfer of personal data to other countries

    These rules are listed on Persónuvernd's own page of laws. The text sits on the official gazette site, which refused automated access. It is not in the island.is regulation database under that number. So we could not confirm its conditions.

  • Whether the six-month allowance for holding accounting records abroad permits ongoing use of a foreign cloud accounting system, and whether the tax authority has published guidance on it

    The law is clear that records must be kept in Iceland, with six months' tolerance abroad. We found no official guidance on how that applies to cloud bookkeeping that syncs continuously. This is the most commercially important open question in this record. Check with the tax authority before you rely on a cloud setup.

  • That annual accounts must be retained for 25 years

    This figure appeared in one automated reading of the Bookkeeping Act but not in a second reading. We confirmed the seven-year general period twice. We could not confirm the 25-year figure.

  • Whether the Central Bank of Iceland imposes outsourcing, cloud or data-location conditions on financial firms beyond the European operational resilience regulation

    We could not read the Central Bank's rules and guidelines pages. Several likely paths returned 404. Check with the Central Bank before you rely on this.

  • Whether Iceland has a binding public-sector cloud or where data has to be stored policy for government systems

    We found no such rule on the government portal, checked 18 August 2026. We could not confirm it either way, because the Government Offices site (stjornarradid.is) refused automated access. Check before you rely on this.

  • Whether any localisation rule exists for mapping and geospatial data, education, online gaming or defence

    We found no rule, checked 18 August 2026, medium confidence. We had no working general web search, so we could not cover these industries as thoroughly as the others. If you work in one of them, check before you rely on this.

  • The exact incident-reporting deadlines that apply to Icelandic financial firms under the European operational resilience regulation

    We confirmed that the regulation is in force in Iceland from 1 July 2025. We did not confirm the specific hour counts as applied by the Central Bank of Iceland. Check with the Central Bank before you rely on a deadline.

  • Whether rules no. 811/2019 on processing subject to authorisation are still current and which categories they cover

    These rules are listed on the regulator's own page of laws, and the regulator runs an application route for licensed uses of data. The rules text sits on the official gazette site, which blocked automated access. So we could not confirm the detail.

  • Whether any Persónuvernd fine has been issued between 1 January 2026 and 18 August 2026

    We could read the 2025 annual report and 2026 news items, but not the decision list itself. We may have missed a 2026 fine. Its absence from this record does not mean none was issued.

Freshness and refresh

Freshness

Checked about 2 months ago, on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.