Skip to the content
Global Data RulesData governance rules, country by country

Iceland

Part of the EEA, so bloc-wide rules apply here too. Checked today.

The answer

Depends on your industryWork: HighEnforcement: Active

Iceland follows Europe's privacy rulebook, so personal data can leave the country once the right paperwork is in place. Two local rules surprise people: a company's accounting records must physically be kept in Iceland, and health record systems can only be hosted by a certified provider. The privacy regulator is small but genuinely busy, and it fines public bodies too.

Eight questions about Iceland

The questions a team asks when they are deciding where to store their users' data. Every country on this site answers the same eight, in the same order.

Do Iceland's rules apply to my company?

Yes, it reaches you with no office in Iceland. Iceland applies Europe's General Data Protection Regulation through the European Economic Area agreement, so the rules cover any organisation anywhere in the world that offers goods or services to people in Iceland, or that watches what they do. There is no size or revenue threshold to duck under. If your organisation has no establishment anywhere in Europe, you normally have to name a representative inside Europe who people and the regulator can contact.

High confidenceBloc rulesNational rulesAppoint a local representative

Can I store my users' data outside Iceland?

For personal data, yes — it can leave once you have the right paperwork. Two Icelandic rules cut across that headline. First, your company's accounting books, invoices and receipts must be kept in Iceland for seven years; the law only lets you hold them abroad for up to six months. Second, a health record system can sit with an outside host only if that host holds a recognised security certificate and the normal rules for sending data out of Europe are met.

Medium confidenceDepends on your industryA copy must stayYes, with paperworkAllowlist

What do I need in place before data leaves Iceland?

You use one of the standard European routes. Send the data to a country Europe has officially approved, or sign the European Commission's standard contract with the recipient, or use group-wide rules a regulator has approved. Narrow one-off exceptions exist, such as the person's explicit consent, but they are not for routine or bulk transfers. One Icelandic wrinkle catches people out: an approval of a foreign country only takes effect in Iceland once the Icelandic minister confirms it and publishes a notice in the official gazette.

Medium confidenceAllowlistOfficial 'this country is safe' decisionStandard contract clausesApproved group rulesExplicit consentNeeded for a contract

Who enforces the rules in Iceland, and what can they do?

Persónuvernd, the Icelandic Data Protection Authority. It is genuinely operational, not a name on paper: it registered 2,124 new cases in 2025 and closed 2,232, it opens its own investigations without waiting for a complaint, and it fines public bodies as well as private companies. It is also small — about 17 staff and a budget of roughly 379 million krónur (about $2.8 million) — and it says in its own annual report that it cannot cover every task the law gives it.

High confidenceActive

How long do I have to keep the data?

There is a floor and a ceiling, and they point in opposite directions. The floor: accounting books, invoices and receipts must be kept for seven years — and kept in Iceland. The ceiling: under the European rules you must delete personal data once you no longer need it for the purpose you collected it for. When the two clash, the keeping duty wins; a person cannot force you to delete records the bookkeeping and tax law requires you to hold.

High confidenceKeep data for a minimum periodDelete data after a periodKeep the data in the country

What happens if there is a breach?

Count at least two clocks, and three if you are a financial firm. You have 72 hours to report a personal data breach to Persónuvernd, and you must tell the people affected without delay where the risk to them is high. Separately, operators of critical services — banks, hospitals, energy, water, transport and digital infrastructure — must alert Iceland's national cyber security team as soon as possible under a 2019 law, and serious breaches of that law can lead to prosecution. Financial firms have a further, tighter reporting duty to the Central Bank under the European operational resilience rules.

Medium confidenceReport breaches to the regulatorTell affected peopleReport cyber incidents

What trips people up in Iceland?

Five things that are not in the summary. (1) A child in Iceland is anyone under 13 for online consent, not 16 as in much of Europe — so a design built for a 16-year-old threshold is wrong here. (2) Your accounting records must sit in Iceland, and bookkeeping offences are criminal: fines, and up to six years in prison for serious cases, investigated by the district prosecutor and the tax investigators, not by the privacy regulator. (3) Public bodies can be fined in Iceland — the law says so expressly, unlike several European countries. (4) Some processing needs a licence from Persónuvernd before you start, which is unusual under the European regime. (5) Three European laws you may assume apply here do not yet: the Data Act, the cybersecurity law known as NIS2, and the Artificial Intelligence Act have not been brought into the European Economic Area agreement.

High confidenceGet a parent's consent for childrenRegister or notifyKeep the data in the countryCriminal liability

What is changing soon in Iceland?

The main thing to watch is not an Icelandic bill but the queue of European laws waiting to be pulled into Icelandic law. The Data Act, the cybersecurity law known as NIS2 and the Artificial Intelligence Act are all still outside the European Economic Area agreement as of 18 August 2026, and each will land when a joint committee decides — with no Icelandic public consultation and often at short notice. The financial resilience regulation already landed this way on 1 July 2025, more than five months after it started applying in the European Union.

High confidencePassed, not yet fully in forceProposed

The rules, layer by layer

Rules stack in layers. Knowing which layer a rule sits in tells you whether your industry, your state, or a contract can override it.

  1. Layer 1

    Bloc rules

    Made by a group of countries together. Applies inside every member country.

    2 rules here

  2. Layer 2

    National rules

    Added by this country on top of any bloc rules.

    2 rules here

  3. Layer 3

    Industry rules

    Made by an industry regulator. These usually beat the general position.

    3 rules here

Read the stack from the top down. Anything lower normally wins: an industry rule beats the national position, and the national position sits on top of the bloc rules.

Bloc rules2 rules

Reglugerð (ESB) 2016/679 (General Data Protection Regulation), incorporated into the EEA Agreement

Directly binding regulation · EEA Joint Committee Decision No. 154/2018 of 6 July 2018

In forceYes, with paperwork

Europe's General Data Protection Regulation applies in Iceland through the European Economic Area agreement, not through European Union membership. It does not require data to stay in Iceland or in Europe; it sets conditions for sending it out. Nothing in it forces localisation.

In force since 20 July 2018

Enforced by Icelandic Data Protection Authority

Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims

High confidence

Reglugerð (ESB) 2023/2854 (Data Act) — adopted in the European Union, NOT yet incorporated into the EEA Agreement

Directly binding regulation · Regulation (EU) 2023/2854; no EEA Joint Committee Decision as of 18 August 2026

Passed, not yet fully in forceYes — store it anywhere

A rule people wrongly assume applies. The European Data Act has applied in the European Union since 12 September 2025 and bans cloud switching and egress fees from 12 January 2027 — but it is still outside the European Economic Area agreement, so it creates no rights and no duties in Iceland today. It can be switched on by a single joint committee decision with no Icelandic consultation.

Enforced by Icelandic Data Protection Authority

Transfer model: No restriction · Accepted routes: Nothing required

High confidence

National rules2 rules

Lög um persónuvernd og vinnslu persónuupplýsinga

Act of parliament · Nr. 90/2018

In forceYes, with paperwork

Iceland's national data protection act. It carries the European rules into Icelandic law and adds three local twists: children give their own consent from age 13, fines can be imposed on government bodies as well as companies, and some kinds of processing need a licence from the regulator before you begin.

In force since 15 July 2018

Enforced by Icelandic Data Protection Authority

Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Explicit consent, Needed for a contract

High confidence

Lög um bókhald

Act of parliament · Nr. 145/1994, 20. gr.

In forceA copy must stay

The real Icelandic data residency rule, and the one most trackers miss. Every company's accounting books, vouchers and supporting data must be kept inside Iceland for seven years. Storage abroad is allowed for six months at most. Breaches are criminal, not administrative, and are investigated by the district prosecutor and the tax investigation authority.

In force since 1 January 1995

Enforced by Iceland Revenue and Customs

Transfer model: Approval each time

High confidence

Industry rules3 rules

Reglugerð um sjúkraskrár

Directly binding regulation · Nr. 550/2015, issued under the Health Records Act no. 55/2009 · Health and social care

In forceYes, with paperwork

Icelandic health record systems may be hosted by an outside supplier, and that supplier may sit abroad, but only if the supplier holds a recognised security certification such as ISO 27001 and the normal conditions for sending personal data out of the country are satisfied. The Directorate of Health oversees the national electronic health record.

In force since 15 June 2015

Enforced by Directorate of Health

Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Certification scheme

High confidence

Reglugerð (ESB) 2022/2554 um stafrænt rekstrarþol fjármálageirans (DORA), incorporated into the EEA Agreement

Directly binding regulation · EEA Joint Committee Decision No. 40/2025 of 20 February 2025 · Finance

In forceYes, with paperwork

Europe's financial operational resilience regulation reached Iceland on 1 July 2025 — more than five months after it started applying in the European Union. It imposes no data localisation on banks, insurers, payment firms or investment firms, but it does require the contract to name where data will be processed, a register of supplier arrangements, exit plans and incident reporting.

In force since 1 July 2025

Enforced by Central Bank of Iceland (Financial Supervision)

Transfer model: No restriction · Accepted routes: Nothing required

High confidence

Lög um öryggi net- og upplýsingakerfa mikilvægra innviða

Act of parliament · Nr. 78/2019 · Government

In forceYes — store it anywhere

Iceland's cybersecurity law for critical infrastructure — energy, water, transport, health, banking and digital infrastructure. It requires incident reports to the national cyber team as fast as possible, with no fixed deadline, and carries criminal liability. It is the older European standard: the replacement law known as NIS2 has not yet been brought into the European Economic Area agreement, so this is still what binds in Iceland.

In force since 1 September 2020

Enforced by CERT-IS — national cyber security team

Transfer model: No restriction · Accepted routes: Nothing required

High confidence

Who you would hear from

  • Persónuvernd

    General data protection law, licensing of certain processing, electronic monitoring

    Fully operational and busy. 2,124 new cases registered in 2025 and 2,232 concluded, roughly 17 full-time staff and a budget of ISK 378.7 million (about $2.8 million). Issues administrative fines including against public bodies, and runs own-initiative audits — most recently of the prosecution service in June 2026. Its own annual report says resources do not stretch to every statutory task. Note that its website now sits on the central government portal island.is; personuvernd.is redirects there.

  • Seðlabanki Íslands — Fjármálaeftirlitið

    Banks, insurers, payment firms, investment firms; digital operational resilience

    Financial supervision was merged into the Central Bank in 2020. Supervises DORA compliance in Iceland from 1 July 2025. We could not read its rules pages in this run — the site renders only with JavaScript — so any outsourcing or cloud conditions beyond DORA are unverified.

  • Embætti landlæknis

    Health records, national electronic health record oversight

    Has nationwide oversight of the electronic health record under Regulation 550/2015.

  • Netöryggissveitin CERT-IS

    Cyber incident reporting and response for critical infrastructure and the wider Icelandic internet

    Operates a national security operations centre with 24-hour monitoring and an open incident reporting channel.

  • Fjarskiptastofa

    Telecoms regulation and digital infrastructure security

    Named as the supervisory authority for digital infrastructure under Act 78/2019. Its public site could not be read by automated fetch in this run.

  • Skatturinn

    Tax and bookkeeping records; the tax investigation function enforces the Bookkeeping Act alongside the district prosecutor

    Bookkeeping offences are investigated by the district prosecutor (héraðssaksóknari) and the tax investigation authority, and can be prosecuted as crimes.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.

  • Whether the Electronic Communications Act No. 70/2022 still requires telecom operators to retain traffic and location data, for how long, and whether any part of that duty has been disapplied following European court rulings

    The consolidated statute on the parliament's own site is too long for automated retrieval — every attempt truncated at around Article 31 to 36, well before Chapter XIII on privacy in electronic communications. The regulator's own site renders only with JavaScript, and the official gazette refused automated access. We can confirm only that the previous Act No. 81/2003 was repealed by Article 109 of the 2022 Act. Treat Icelandic telecom retention as unresearched, not as absent.

  • The detailed conditions in rules no. 1155/2022 on the transfer of personal data to other countries

    Listed on Persónuvernd's own page of laws, but the text sits on the official gazette site, which returned an access-denied response to automated fetching, and it is not in the island.is regulation database under that number.

  • Whether the six-month allowance for holding accounting records abroad permits ongoing use of a foreign cloud accounting system, and whether the tax authority has published guidance on it

    The statute is clear that records must be preserved in Iceland with a six-month tolerance abroad, but we found no official guidance on how that applies to continuously-synchronised cloud bookkeeping. This is the single most commercially important open question in this record.

  • That annual accounts must be retained for 25 years

    Appeared in one automated reading of the Bookkeeping Act but was not reproduced on a second reading. The seven-year general period was confirmed twice; the 25-year figure was not.

  • Whether the Central Bank of Iceland imposes outsourcing, cloud or data-location conditions on financial firms beyond the European operational resilience regulation

    The Central Bank's rules and guidelines pages could not be read — the site is a JavaScript application and returned no content to automated fetching, and several plausible paths returned 404.

  • Whether Iceland has a binding public-sector cloud or data-residency policy for government systems

    No such instrument found on the government portal, checked 18 August 2026. The Government Offices site (stjornarradid.is) refused automated access during this run, so this is a gap in coverage rather than a confirmed absence.

  • Whether any localisation rule exists for mapping and geospatial data, education, online gaming or defence

    No rule found, checked 18 August 2026, medium confidence. Without a working general web search in this run we could not sweep these sectors as thoroughly as the others.

  • The exact incident-reporting deadlines that apply to Icelandic financial firms under the European operational resilience regulation

    We verified that the regulation is in force in Iceland from 1 July 2025 but did not verify the specific hour counts as applied by the Central Bank of Iceland.

  • Whether rules no. 811/2019 on processing subject to authorisation are still current and which categories they cover

    Listed on the regulator's own page of laws and the regulator operates an application route for licensed processing, but the rules text is on the official gazette site, which blocked automated access.

  • Whether any Persónuvernd fine has been issued between 1 January 2026 and 18 August 2026

    The decisions database on island.is renders only with JavaScript, so we could read the 2025 annual report and 2026 news items but not the decision list itself. Absence of a 2026 fine in this record is a gap in our reading, not evidence that none was issued.

60-day cadence. Iceland's biggest volatility is not domestic legislation but the EEA incorporation queue: the Data Act, NIS2 and the Artificial Intelligence Act can each be switched on by a single Joint Committee decision with no Icelandic consultation, and the DORA precedent shows the gap between EU application and Icelandic effect can be five months or more. The ministerial gazette-confirmation lever over adequacy decisions is a second switch that operates without legislation.

Freshness and refresh

Freshness

Checked today — on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

Compare with

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.