Iceland
Part of the EEA, so bloc-wide rules apply here too. Checked today.
The answer
Iceland follows Europe's privacy rulebook, so personal data can leave the country once the right paperwork is in place. Two local rules surprise people: a company's accounting records must physically be kept in Iceland, and health record systems can only be hosted by a certified provider. The privacy regulator is small but genuinely busy, and it fines public bodies too.
Eight questions about Iceland
The questions a team asks when they are deciding where to store their users' data. Every country on this site answers the same eight, in the same order.
Do Iceland's rules apply to my company?
Yes, it reaches you with no office in Iceland. Iceland applies Europe's General Data Protection Regulation through the European Economic Area agreement, so the rules cover any organisation anywhere in the world that offers goods or services to people in Iceland, or that watches what they do. There is no size or revenue threshold to duck under. If your organisation has no establishment anywhere in Europe, you normally have to name a representative inside Europe who people and the regulator can contact.
Article 7 of Act No. 90/2018 sets the territorial reach: the Act applies to processing by a controller or processor established in Iceland regardless of where the processing physically happens, and to processing relating to people in Iceland by organisations with no establishment in the European Economic Area where they offer goods or services to those people or monitor their behaviour. The General Data Protection Regulation itself was incorporated into the EEA Agreement by EEA Joint Committee Decision No. 154/2018 of 6 July 2018 and entered into force in the EEA on 20 July 2018; Act No. 90/2018 gives it effect in Iceland from 15 July 2018. The in-Europe representative duty comes from Article 27 of the Regulation, not from a separate Icelandic rule.
Sources
- Official sourceAlþingi (Icelandic Parliament) — consolidated statute bookLög um persónuvernd og vinnslu persónuupplýsinga nr. 90/2018, 7. gr. (territorial scope)
althingi.is
Link checked 18 August 2026
- Official sourceEFTA SecretariatEEA-Lex factsheet: Regulation (EU) 2016/679 incorporated by Joint Committee Decision 154/2018, in force in the EEA from 20 July 2018
efta.int
Link checked 18 August 2026
Can I store my users' data outside Iceland?
For personal data, yes — it can leave once you have the right paperwork. Two Icelandic rules cut across that headline. First, your company's accounting books, invoices and receipts must be kept in Iceland for seven years; the law only lets you hold them abroad for up to six months. Second, a health record system can sit with an outside host only if that host holds a recognised security certificate and the normal rules for sending data out of Europe are met.
Sector by sector, checked 18 August 2026. ACCOUNTING AND TAX RECORDS (every registered company, all industries): Article 20 of the Bookkeeping Act No. 145/1994 says all books, accounting data and vouchers shall be preserved 'hér á landi' — here in the country — securely for seven years from the end of the financial year, with a narrow permission to keep them abroad for up to six months, and the authorities may demand them back in Iceland within a reasonable time. Rated mirror. HEALTH: Regulation No. 550/2015 on health records allows third-party hosting only with a provider holding ISO 27001 certification or equivalent, and allows foreign hosting only where the conditions for transferring personal data out of the country under the data protection law are met. Rated conditional. FINANCE (banking, payments, insurance, securities): the European operational resilience regulation known as DORA has applied in Iceland since 1 July 2025 and imposes no localisation — but it does force you to state in the contract where data will be processed, keep a register of arrangements and hold exit plans. Rated conditional. TELECOM: we could not verify whether a traffic-data retention duty survives in the Electronic Communications Act No. 70/2022 (see the unconfirmed list); the old Act No. 81/2003 was repealed by Article 109 of the 2022 Act. GOVERNMENT CLOUD, EDUCATION, GAMING, MAPPING AND GEOSPATIAL, DEFENCE: no localisation rule found, checked 18 August 2026, medium confidence.
Sources
- Official sourceAlþingi — consolidated statute bookLög um bókhald nr. 145/1994, 20. gr. — accounting records must be preserved in Iceland for seven years
althingi.is
“Allar bækur, sem fyrirskipaðar eru í lögum þessum, ásamt bókhaldsgögnum og fylgiskjölum ... skulu varðveittar hér á landi á tryggan og öruggan hátt í sjö ár frá lokum viðkomandi reikningsárs.”
Link checked 18 August 2026
- Official sourceIcelandic regulation database, island.isReglugerð nr. 550/2015 um sjúkraskrár — hosting of health record systems
island.is
“Hýsing sjúkraskrárkerfis hjá erlendum aðila er því aðeins heimil að fullnægt sé skilyrðum fyrir flutningi persónuupplýsinga úr landi samkvæmt lögum um persónuvernd”
Link checked 18 August 2026
- Official sourceEFTA SecretariatEEA-Lex factsheet: Regulation (EU) 2022/2554 (DORA) incorporated by Joint Committee Decision 40/2025, in force in the EEA from 1 July 2025
efta.int
Link checked 18 August 2026
- Official sourceAlþingi — consolidated statute bookFjarskiptalög nr. 81/2003 — marked repealed by Act 70/2022, Article 109
althingi.is
Link checked 18 August 2026
What do I need in place before data leaves Iceland?
You use one of the standard European routes. Send the data to a country Europe has officially approved, or sign the European Commission's standard contract with the recipient, or use group-wide rules a regulator has approved. Narrow one-off exceptions exist, such as the person's explicit consent, but they are not for routine or bulk transfers. One Icelandic wrinkle catches people out: an approval of a foreign country only takes effect in Iceland once the Icelandic minister confirms it and publishes a notice in the official gazette.
Article 16 of Act No. 90/2018 makes European Commission adequacy decisions operative in Iceland, but requires the minister to confirm the decision and publish notice of it in Stjórnartíðindi, the official gazette. In practice this has been done, so the destinations Europe has approved are available from Iceland — but the confirmation step is a real dependency and a naive reading of the European list alone is wrong. The model is best described as an allowlist with safeguards: approved destinations need nothing extra, everything else needs an instrument. The 2021 Standard Contractual Clauses remain the operative set. There is also an Icelandic instrument specifically on transfers abroad, rules No. 1155/2022 on the transfer of personal data to other countries, listed on the regulator's own page of laws; we could not retrieve its text (the gazette site refused automated access), so its detailed conditions are unverified.
Sources
- Official sourceAlþingi — consolidated statute bookLög nr. 90/2018, 16. gr. — transfers to third countries; ministerial confirmation and gazette publication of adequacy decisions
althingi.is
Link checked 18 August 2026
- Official sourcePersónuvernd (Icelandic Data Protection Authority)Persónuvernd — laws and regulations, listing rules no. 1155/2022 on transfer of personal data to other countries
island.is
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionCommission Implementing Decision (EU) 2021/914 — Standard Contractual Clauses
eur-lex.europa.eu
Who enforces the rules in Iceland, and what can they do?
Persónuvernd, the Icelandic Data Protection Authority. It is genuinely operational, not a name on paper: it registered 2,124 new cases in 2025 and closed 2,232, it opens its own investigations without waiting for a complaint, and it fines public bodies as well as private companies. It is also small — about 17 staff and a budget of roughly 379 million krónur (about $2.8 million) — and it says in its own annual report that it cannot cover every task the law gives it.
Evidence of live enforcement in the 2025 annual report: a 5 million króna fine (about $36,000) on the Capital Area Primary Health Care service for unlawful sharing inside a health records system, and a 12 million króna fine (about $88,000) reduced to 8 million (about $58,000) after a court challenge. In June 2026 the authority completed own-initiative audits of the National Prosecutor, district prosecutors and police commissioners, found that security measures had not been fully implemented, closed the audits with formal guidance rather than orders, and said it will re-examine compliance a year later. Sector regulators enforce alongside it: the Central Bank of Iceland supervises financial firms including under the European operational resilience regulation, the Directorate of Health oversees health records, the Electronic Communications Office of Iceland and its national cyber team CERT-IS handle cyber incidents, and — importantly — bookkeeping offences are investigated by the district prosecutor and the tax investigation authority, not by the privacy regulator.
Sources
- Official sourcePersónuverndÁrsskýrsla Persónuverndar 2025 (annual report announcement, 5 May 2026)
island.is
Link checked 18 August 2026
- Official sourcePersónuverndPersónuvernd completes audits of personal data processing by the prosecution service, 4 June 2026
island.is
“öryggisráðstafanir hafi ekki að öllu leyti verið innleiddar með viðunandi hætti”
Link checked 18 August 2026
- Secondary sourcePersónuverndPersónuvernd annual report 2025 (full PDF) — 2,124 new cases, 2,232 concluded, 17 staff, ISK 378.7m budget, fines listed
assets.ctfassets.net
Link checked 18 August 2026
How long do I have to keep the data?
There is a floor and a ceiling, and they point in opposite directions. The floor: accounting books, invoices and receipts must be kept for seven years — and kept in Iceland. The ceiling: under the European rules you must delete personal data once you no longer need it for the purpose you collected it for. When the two clash, the keeping duty wins; a person cannot force you to delete records the bookkeeping and tax law requires you to hold.
Bookkeeping Act No. 145/1994, Article 20: seven years from the end of the financial year, preserved in Iceland, with only a six-month tolerance for holding the records abroad. Cash register records run three years. There is no general statutory maximum retention period in Icelandic law; the ceiling comes from the storage limitation principle in the European Regulation, applied case by case, plus the individual's right to erasure. The right to erasure does not apply where processing is necessary to comply with a legal obligation, which is how the conflict resolves. Health records have their own preservation regime under the Health Records Act No. 55/2009, which requires records to be kept securely in a health record system and passed to the Director of Health if a system closes. Telecom traffic-data retention could not be verified — see the unconfirmed list.
Sources
- Official sourceAlþingi — consolidated statute bookLög um bókhald nr. 145/1994, 20. gr. — seven-year retention in Iceland, six months abroad
althingi.is
“Þrátt fyrir ákvæði 1. mgr. hafa félög skv. 1. gr. heimild til að varðveita gögn skv. 1. mgr. erlendis í allt að sex mánuði. Yfirvöld geta þó krafist aðgangs að þeim hér á landi og skal þeim þá skilað innan hæfilegs tíma.”
Link checked 18 August 2026
- Official sourceAlþingi — consolidated statute bookLög um sjúkraskrár nr. 55/2009 — secure preservation of health records and transfer of records when a system closes
althingi.is
Link checked 18 August 2026
What happens if there is a breach?
Count at least two clocks, and three if you are a financial firm. You have 72 hours to report a personal data breach to Persónuvernd, and you must tell the people affected without delay where the risk to them is high. Separately, operators of critical services — banks, hospitals, energy, water, transport and digital infrastructure — must alert Iceland's national cyber security team as soon as possible under a 2019 law, and serious breaches of that law can lead to prosecution. Financial firms have a further, tighter reporting duty to the Central Bank under the European operational resilience rules.
The 72-hour clock is the standard European one, applied in Iceland through Act No. 90/2018. Act No. 78/2019 on the security of network and information systems of critical infrastructure entered into force on 1 September 2020 and requires operators to notify the cyber security unit 'svo fljótt sem verða má' — as quickly as possible — about serious incidents or risks. It sets no fixed hour count, which is unusual and means the practical deadline is judged after the fact. That Act carries daily penalties up to 500,000 krónur (about $3,600), administrative fines up to 10 million krónur (about $73,000) or 3% of annual turnover, and imprisonment of up to two years for intentional breaches. The financial-sector clock comes from Regulation (EU) 2022/2554, in force in Iceland since 1 July 2025; we did not verify its exact Icelandic reporting hours in this run. Any telecom-specific breach notification duty in the Electronic Communications Act No. 70/2022 is unverified.
Sources
- Official sourceAlþingi — consolidated statute bookLög nr. 78/2019 um öryggi net- og upplýsingakerfa mikilvægra innviða, 8. gr. — incident notification to the cyber security unit
althingi.is
“Mikilvægir innviðir skulu tilkynna netöryggissveit ... svo fljótt sem verða má um alvarleg atvik eða áhættu”
Link checked 18 August 2026
- Official sourceCERT-ISCERT-IS — Iceland's national cyber security team and incident reporting portal
cert.is
Link checked 18 August 2026
- Official sourceAlþingi — consolidated statute bookLög nr. 90/2018 — data protection breach duties and enforcement powers
althingi.is
Link checked 18 August 2026
What trips people up in Iceland?
Five things that are not in the summary. (1) A child in Iceland is anyone under 13 for online consent, not 16 as in much of Europe — so a design built for a 16-year-old threshold is wrong here. (2) Your accounting records must sit in Iceland, and bookkeeping offences are criminal: fines, and up to six years in prison for serious cases, investigated by the district prosecutor and the tax investigators, not by the privacy regulator. (3) Public bodies can be fined in Iceland — the law says so expressly, unlike several European countries. (4) Some processing needs a licence from Persónuvernd before you start, which is unusual under the European regime. (5) Three European laws you may assume apply here do not yet: the Data Act, the cybersecurity law known as NIS2, and the Artificial Intelligence Act have not been brought into the European Economic Area agreement.
The 13-year threshold is in Article 10 of Act No. 90/2018: 'Sé barnið undir 13 ára aldri telst vinnslan aðeins lögmæt að því marki sem forsjáraðili þess heimilar samþykki.' Fines on public authorities are expressly authorised by Article 46(4): 'Heimilt er að leggja sektir á einstaklinga og lögaðila, þar á meðal stjórnvöld og stofnanir sem falla undir gildissvið stjórnsýslulaga.' Licensed processing is governed by rules No. 811/2019 on processing subject to authorisation, and Persónuvernd runs an application route for it. Bookkeeping penalties sit in Articles 36 to 41 of the Bookkeeping Act: fines for ordinary breaches, imprisonment of up to six years for serious ones, corporate liability regardless of individual fault, and investigation by the district prosecutor and the tax investigation authority. The practical consequence of trap 5 is concrete: the European right to switch cloud provider with no egress charges from 12 January 2027 is not an Icelandic right today, because the Data Act is not part of Icelandic law.
Sources
- Official sourceAlþingi — consolidated statute bookLög nr. 90/2018, 10. gr. (age 13) and 46. gr. (fines, including on public authorities)
althingi.is
“Sé barnið undir 13 ára aldri telst vinnslan aðeins lögmæt að því marki sem forsjáraðili þess heimilar samþykki.”
Link checked 18 August 2026
- Official sourceAlþingi — consolidated statute bookLög um bókhald nr. 145/1994, 36.–41. gr. — criminal penalties, up to six years' imprisonment, prosecuted by the district prosecutor and tax investigators
althingi.is
Link checked 18 August 2026
- Official sourcePersónuverndPersónuvernd — laws and rules, including rules no. 811/2019 on processing subject to authorisation
island.is
Link checked 18 August 2026
- Official sourceEFTA SecretariatEEA-Lex factsheet: Regulation (EU) 2023/2854 (Data Act) — not yet incorporated into the EEA Agreement
efta.int
“EU legal act marked as EEA relevant by the EU and under scrutiny for incorporation into the EEA Agreement by Iceland, Liechtenstein and Norway.”
Link checked 18 August 2026
What is changing soon in Iceland?
The main thing to watch is not an Icelandic bill but the queue of European laws waiting to be pulled into Icelandic law. The Data Act, the cybersecurity law known as NIS2 and the Artificial Intelligence Act are all still outside the European Economic Area agreement as of 18 August 2026, and each will land when a joint committee decides — with no Icelandic public consultation and often at short notice. The financial resilience regulation already landed this way on 1 July 2025, more than five months after it started applying in the European Union.
Dormant switches, which matter more than pending bills. (1) The EEA Joint Committee can incorporate any of the three pending acts at a single meeting; the effect in Iceland then follows quickly, and the Data Act in particular would switch on cloud-switching and egress-fee rights that do not exist here today. (2) Under Article 16 of Act No. 90/2018 the minister controls whether and when a European approval of a foreign country is confirmed and published in the Icelandic gazette — a lever that operates without legislation. (3) Persónuvernd's authorisation rules let it decide which categories of processing need a licence before you start. (4) The six-month tolerance for holding accounting records abroad is a statutory allowance, not a right, and the authorities can demand the records back in Iceland at any time. At European level the pressure on the EU-US Data Privacy Framework carries through to Iceland: the framework remains in force and valid on 18 August 2026, but the European Data Protection Board wrote to the Commission on 31 July 2026 asking it to examine whether recent US changes affect the decision's validity. Do not build a single-mechanism transfer architecture on it.
Sources
- Official sourceEFTA SecretariatEEA-Lex factsheet: Directive (EU) 2022/2555 (NIS2) — under scrutiny, no Joint Committee Decision adopted
efta.int
Link checked 18 August 2026
- Official sourceEFTA SecretariatEEA-Lex factsheet: Regulation (EU) 2024/1689 (Artificial Intelligence Act) — not yet incorporated into the EEA Agreement
efta.int
Link checked 18 August 2026
- Official sourceEFTA SecretariatEEA-Lex factsheet: DORA in force in the EEA from 1 July 2025 (Joint Committee Decision 40/2025 of 20 February 2025)
efta.int
Link checked 18 August 2026
The rules, layer by layer
Rules stack in layers. Knowing which layer a rule sits in tells you whether your industry, your state, or a contract can override it.
Layer 1
Bloc rules
Made by a group of countries together. Applies inside every member country.
2 rules here
Layer 2
National rules
Added by this country on top of any bloc rules.
2 rules here
Layer 3
Industry rules
Made by an industry regulator. These usually beat the general position.
3 rules here
Read the stack from the top down. Anything lower normally wins: an industry rule beats the national position, and the national position sits on top of the bloc rules.
Bloc rules2 rules
Reglugerð (ESB) 2016/679 (General Data Protection Regulation), incorporated into the EEA Agreement
Directly binding regulation · EEA Joint Committee Decision No. 154/2018 of 6 July 2018
Europe's General Data Protection Regulation applies in Iceland through the European Economic Area agreement, not through European Union membership. It does not require data to stay in Iceland or in Europe; it sets conditions for sending it out. Nothing in it forces localisation.
Enforced by Icelandic Data Protection Authority
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims
What it makes you do
- Tell people what you do
- Let people see their data
- Let people correct their data
- Let people delete their data
- Let people take their data elsewhere
- Let people object
- Secure the data
- Keep records of processing
- Assess high-risk projects
- Put a transfer safeguard in place
- Written vendor contract
- Appoint a local representativeOnly where the organisation has no establishment in the European Economic Area.
- Report breaches to the regulator — within 72 hours
- Tell affected peopleWhere the breach is likely to result in a high risk to the people affected.
What it costs if you get it wrong
- Percentage of global turnover: 4% of worldwide group turnoverBreach of basic principles, individual rights or transfer rules
- Order to stopOrder to stop processing or suspend flows to a third country
- Claims by individualsCompensation claims by individuals
Sources
- Official sourceEFTA SecretariatEEA-Lex: GDPR incorporated by Joint Committee Decision 154/2018, in force in the EEA 20 July 2018
efta.int
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionRegulation (EU) 2016/679 (General Data Protection Regulation)
eur-lex.europa.eu
Reglugerð (ESB) 2023/2854 (Data Act) — adopted in the European Union, NOT yet incorporated into the EEA Agreement
Directly binding regulation · Regulation (EU) 2023/2854; no EEA Joint Committee Decision as of 18 August 2026
A rule people wrongly assume applies. The European Data Act has applied in the European Union since 12 September 2025 and bans cloud switching and egress fees from 12 January 2027 — but it is still outside the European Economic Area agreement, so it creates no rights and no duties in Iceland today. It can be switched on by a single joint committee decision with no Icelandic consultation.
Enforced by Icelandic Data Protection Authority
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Make switching cloud provider possibleNOT in force in Iceland. In the European Union all cloud switching charges and data egress fees must be zero from 12 January 2027. That right does not exist in Iceland unless and until the EEA Joint Committee incorporates the Data Act.
Sources
- Official sourceEFTA SecretariatEEA-Lex factsheet: Regulation (EU) 2023/2854 (Data Act) — under scrutiny, Joint Committee Decision pending
efta.int
“EU legal act marked as EEA relevant by the EU and under scrutiny for incorporation into the EEA Agreement by Iceland, Liechtenstein and Norway.”
Link checked 18 August 2026
National rules2 rules
Lög um persónuvernd og vinnslu persónuupplýsinga
Act of parliament · Nr. 90/2018
Iceland's national data protection act. It carries the European rules into Icelandic law and adds three local twists: children give their own consent from age 13, fines can be imposed on government bodies as well as companies, and some kinds of processing need a licence from the regulator before you begin.
Enforced by Icelandic Data Protection Authority
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Explicit consent, Needed for a contract
What it makes you do
- Get a parent's consent for children — applies at: under 13Iceland chose the lowest age Europe allows. A product built for a 16-year-old threshold is misconfigured here.
- Register or notifyCertain categories of processing require a prior licence from Persónuvernd under rules no. 811/2019.
- Appoint a data protection officer
- Put a transfer safeguard in placeA European approval of a destination country takes effect in Iceland only after the minister confirms it and publishes notice in the official gazette.
- Report breaches to the regulator — within 72 hours
What it costs if you get it wrong
- Fixed maximum fine: ISK 2.4 billion — about $18 millionHigher-tier breaches; the lower tier is ISK 1.2 billion (about $8.8 million)
- Percentage of global turnover: 4% of worldwide annual turnoverHigher-tier breaches, whichever is higher
- Claims by individualsCompensation claims by individuals
Sources
- Official sourceAlþingi — consolidated statute bookLög um persónuvernd og vinnslu persónuupplýsinga nr. 90/2018 (consolidated text)
althingi.is
“Heimilt er að leggja sektir á einstaklinga og lögaðila, þar á meðal stjórnvöld og stofnanir sem falla undir gildissvið stjórnsýslulaga.”
Link checked 18 August 2026
- Official sourcePersónuverndPersónuvernd — the laws, regulations and rules it administers
island.is
Link checked 18 August 2026
Lög um bókhald
Act of parliament · Nr. 145/1994, 20. gr.
The real Icelandic data residency rule, and the one most trackers miss. Every company's accounting books, vouchers and supporting data must be kept inside Iceland for seven years. Storage abroad is allowed for six months at most. Breaches are criminal, not administrative, and are investigated by the district prosecutor and the tax investigation authority.
Enforced by Iceland Revenue and Customs
Transfer model: Approval each time
What it makes you do
- Keep the data in the countryBooks, accounting data and vouchers must be preserved in Iceland. Holding them abroad is permitted for up to six months only, and the authorities may demand their return to Iceland within a reasonable time.
- Keep data for a minimum period — 7 yearsSeven years from the end of the financial year. Cash register records: three years.
What it costs if you get it wrong
- Criminal liability: Up to 6 years' imprisonment for serious breachesFailure to keep, secure or preserve accounting records; falsifying accounts
- Fixed maximum fineOrdinary breaches; legal entities are liable regardless of individual fault
Sources
- Official sourceAlþingi — consolidated statute bookLög um bókhald nr. 145/1994, 20. gr. (preservation) and 36.–41. gr. (penalties and investigation)
althingi.is
“Allar bækur, sem fyrirskipaðar eru í lögum þessum, ásamt bókhaldsgögnum og fylgiskjölum ... skulu varðveittar hér á landi á tryggan og öruggan hátt í sjö ár frá lokum viðkomandi reikningsárs.”
Link checked 18 August 2026
Industry rules3 rules
Reglugerð um sjúkraskrár
Directly binding regulation · Nr. 550/2015, issued under the Health Records Act no. 55/2009 · Health and social care
Icelandic health record systems may be hosted by an outside supplier, and that supplier may sit abroad, but only if the supplier holds a recognised security certification such as ISO 27001 and the normal conditions for sending personal data out of the country are satisfied. The Directorate of Health oversees the national electronic health record.
Enforced by Directorate of Health
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Certification scheme
What it makes you do
- Hold a security certificateA third-party host of a health record system must hold ISO 27001 certification or an equivalent recognised certification.
- Put a transfer safeguard in placeForeign hosting is permitted only if the conditions for transferring personal data out of the country under the data protection law are met.
- Written vendor contract
Sources
- Official sourceIcelandic regulation database, island.isReglugerð nr. 550/2015 um sjúkraskrár — hosting and certification requirements
island.is
“sjúkraskrárkerfið er hýst hjá þriðja aðila skal það einungis gert hjá viðurkenndum þjónustuaðila, þ.e. aðila sem annaðhvort hefur vottað gæðakerfi skv. ISO-27001”
Link checked 18 August 2026
- Official sourceAlþingi — consolidated statute bookLög um sjúkraskrár nr. 55/2009 — enabling act, custodianship and ministerial power to regulate electronic health records
althingi.is
Link checked 18 August 2026
Reglugerð (ESB) 2022/2554 um stafrænt rekstrarþol fjármálageirans (DORA), incorporated into the EEA Agreement
Directly binding regulation · EEA Joint Committee Decision No. 40/2025 of 20 February 2025 · Finance
Europe's financial operational resilience regulation reached Iceland on 1 July 2025 — more than five months after it started applying in the European Union. It imposes no data localisation on banks, insurers, payment firms or investment firms, but it does require the contract to name where data will be processed, a register of supplier arrangements, exit plans and incident reporting.
Enforced by Central Bank of Iceland (Financial Supervision)
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Written vendor contractThe contract with a technology supplier must state the locations where data will be processed and stored, and give audit and access rights.
- Keep records of processingRegister of information on all contractual arrangements with technology suppliers.
- Report cyber incidents
- Independent audit
What it costs if you get it wrong
- Order to stopSupervisory measures by the Central Bank of Iceland's financial supervision
Sources
- Official sourceEFTA SecretariatEEA-Lex factsheet: Regulation (EU) 2022/2554 (DORA), Joint Committee Decision 40/2025, in force in the EEA 1 July 2025
efta.int
“Incorporated into the EEA Agreement and in force”
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionRegulation (EU) 2022/2554 on digital operational resilience for the financial sector
eur-lex.europa.eu
Lög um öryggi net- og upplýsingakerfa mikilvægra innviða
Act of parliament · Nr. 78/2019 · Government
Iceland's cybersecurity law for critical infrastructure — energy, water, transport, health, banking and digital infrastructure. It requires incident reports to the national cyber team as fast as possible, with no fixed deadline, and carries criminal liability. It is the older European standard: the replacement law known as NIS2 has not yet been brought into the European Economic Area agreement, so this is still what binds in Iceland.
Enforced by CERT-IS — national cyber security team
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Report cyber incidentsSerious incidents and risks must be reported to the national cyber security unit as quickly as possible. The Act sets no fixed hour count.
- Secure the data
What it costs if you get it wrong
- Criminal liability: Up to 2 years' imprisonmentIntentional breach
- Fixed maximum fine: ISK 10 million — about $73 thousandAdministrative fine; alternatively up to 3% of annual turnover
- Daily fine until fixed: ISK 500,000 per day — about $4 thousandContinuing non-compliance
Sources
- Official sourceAlþingi — consolidated statute bookLög nr. 78/2019 um öryggi net- og upplýsingakerfa mikilvægra innviða
althingi.is
“Mikilvægir innviðir skulu tilkynna netöryggissveit ... svo fljótt sem verða má um alvarleg atvik eða áhættu”
Link checked 18 August 2026
- Official sourceEFTA SecretariatEEA-Lex factsheet: NIS2 Directive (EU) 2022/2555 still under scrutiny, not incorporated
efta.int
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.
Whether the Electronic Communications Act No. 70/2022 still requires telecom operators to retain traffic and location data, for how long, and whether any part of that duty has been disapplied following European court rulings
The consolidated statute on the parliament's own site is too long for automated retrieval — every attempt truncated at around Article 31 to 36, well before Chapter XIII on privacy in electronic communications. The regulator's own site renders only with JavaScript, and the official gazette refused automated access. We can confirm only that the previous Act No. 81/2003 was repealed by Article 109 of the 2022 Act. Treat Icelandic telecom retention as unresearched, not as absent.
The detailed conditions in rules no. 1155/2022 on the transfer of personal data to other countries
Listed on Persónuvernd's own page of laws, but the text sits on the official gazette site, which returned an access-denied response to automated fetching, and it is not in the island.is regulation database under that number.
Whether the six-month allowance for holding accounting records abroad permits ongoing use of a foreign cloud accounting system, and whether the tax authority has published guidance on it
The statute is clear that records must be preserved in Iceland with a six-month tolerance abroad, but we found no official guidance on how that applies to continuously-synchronised cloud bookkeeping. This is the single most commercially important open question in this record.
That annual accounts must be retained for 25 years
Appeared in one automated reading of the Bookkeeping Act but was not reproduced on a second reading. The seven-year general period was confirmed twice; the 25-year figure was not.
Whether the Central Bank of Iceland imposes outsourcing, cloud or data-location conditions on financial firms beyond the European operational resilience regulation
The Central Bank's rules and guidelines pages could not be read — the site is a JavaScript application and returned no content to automated fetching, and several plausible paths returned 404.
Whether Iceland has a binding public-sector cloud or data-residency policy for government systems
No such instrument found on the government portal, checked 18 August 2026. The Government Offices site (stjornarradid.is) refused automated access during this run, so this is a gap in coverage rather than a confirmed absence.
Whether any localisation rule exists for mapping and geospatial data, education, online gaming or defence
No rule found, checked 18 August 2026, medium confidence. Without a working general web search in this run we could not sweep these sectors as thoroughly as the others.
The exact incident-reporting deadlines that apply to Icelandic financial firms under the European operational resilience regulation
We verified that the regulation is in force in Iceland from 1 July 2025 but did not verify the specific hour counts as applied by the Central Bank of Iceland.
Whether rules no. 811/2019 on processing subject to authorisation are still current and which categories they cover
Listed on the regulator's own page of laws and the regulator operates an application route for licensed processing, but the rules text is on the official gazette site, which blocked automated access.
Whether any Persónuvernd fine has been issued between 1 January 2026 and 18 August 2026
The decisions database on island.is renders only with JavaScript, so we could read the 2025 annual report and 2026 news items but not the decision list itself. Absence of a 2026 fine in this record is a gap in our reading, not evidence that none was issued.
60-day cadence. Iceland's biggest volatility is not domestic legislation but the EEA incorporation queue: the Data Act, NIS2 and the Artificial Intelligence Act can each be switched on by a single Joint Committee decision with no Icelandic consultation, and the DORA precedent shows the gap between EU application and Icelandic effect can be five months or more. The ministerial gazette-confirmation lever over adequacy decisions is a second switch that operates without legislation.
Freshness and refresh
Freshness
Checked today — on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.
Compare with
- Iceland versus Argentina
- Iceland versus Armenia
- Iceland versus Australia
- Iceland versus Austria
- Iceland versus Azerbaijan
- Iceland versus Brazil
- Iceland versus Bulgaria
- Iceland versus Cambodia
- Iceland versus Canada
- Iceland versus China
- Iceland versus Croatia
- Iceland versus Cyprus
- Iceland versus Estonia
- Iceland versus France
- Iceland versus Georgia
- Iceland versus Germany
- Iceland versus Greece
- Iceland versus Hong Kong SAR
- Iceland versus Hungary
- Iceland versus India
- Iceland versus Indonesia
- Iceland versus Ireland
- Iceland versus Israel
- Iceland versus Italy
- Iceland versus Japan
- Iceland versus Latvia
- Iceland versus Lithuania
- Iceland versus Luxembourg
- Iceland versus Malta
- Iceland versus Mexico
- Iceland versus Mongolia
- Iceland versus Nepal
- Iceland versus Netherlands
- Iceland versus Poland
- Iceland versus Russia
- Iceland versus Saudi Arabia
- Iceland versus Serbia
- Iceland versus Singapore
- Iceland versus Slovakia
- Iceland versus Slovenia
- Iceland versus South Korea
- Iceland versus Spain
- Iceland versus Sri Lanka
- Iceland versus Sweden
- Iceland versus Switzerland
- Iceland versus Taiwan
- Iceland versus Thailand
- Iceland versus Turkey
- Iceland versus Ukraine
- Iceland versus United Arab Emirates
- Iceland versus United Kingdom
- Iceland versus United States
- Iceland versus Uzbekistan