Iceland
Part of the EEA, so bloc-wide rules apply here too. Checked about 2 months ago, on 18 August 2026.
If you collect data about people in Iceland — customers, users, employees — these are the rules you have to follow. Here is the short version.
The short version
Iceland follows Europe's privacy rulebook. Personal data can leave the country once you have the right paperwork. Two local rules surprise people. Your company's accounting records must physically be kept in Iceland. And health record systems can only be hosted by a certified provider. The privacy regulator is small but busy, and it fines public bodies too.
Data governance in Iceland
The eight things that decide how you handle data about people in Iceland. Same eight on every country page, so you can compare.
Who has to follow these rules
Yes, the law reaches you with no office in Iceland. Iceland applies Europe's General Data Protection Regulation through the European Economic Area agreement. So the rules cover any organisation anywhere in the world that offers goods or services to people in Iceland. They also cover anyone who watches what those people do. There is no size or revenue threshold to duck under. If you have no office anywhere in Europe, you normally have to name a representative inside Europe. People and the regulator contact that representative.
- What you have to do here:
- Appoint a representative
Article 7 of Act No. 90/2018 sets out who the law covers. It covers any company established in Iceland that uses or stores personal data, wherever the work physically happens. It also covers companies with no office in the European Economic Area that handle data about people in Iceland. That applies where they offer those people goods or services, or watch what they do. The General Data Protection Regulation was brought into the EEA Agreement by EEA Joint Committee Decision No. 154/2018 of 6 July 2018. It entered into force in the EEA on 20 July 2018. Act No. 90/2018 gives it effect in Iceland from 15 July 2018. The duty to name a representative in Europe comes from Article 27 of the Regulation. It is not a separate Icelandic rule.
Sources
- Official sourceAlþingi (Icelandic Parliament) — consolidated statute bookLög um persónuvernd og vinnslu persónuupplýsinga nr. 90/2018, 7. gr. (territorial scope)
althingi.is
Link checked 18 August 2026
- Official sourceEFTA SecretariatEEA-Lex factsheet: Regulation (EU) 2016/679 incorporated by Joint Committee Decision 154/2018, in force in the EEA from 20 July 2018
efta.int
Link checked 18 August 2026
Where the data is allowed to live
Yes, personal data can leave once you have the right paperwork. Two Icelandic rules cut across that. First, your company's accounting books, invoices and receipts must be kept in Iceland for seven years. The law lets you hold them abroad for up to six months. Second, an outside company can host a health record system only if it holds a recognised security certificate. You must also meet the normal rules for sending data out of Europe.
Here is each industry, checked 18 August 2026. ACCOUNTING AND TAX RECORDS, for every registered company in every industry. Article 20 of the Bookkeeping Act No. 145/1994 says all books, accounting data and vouchers must be kept 'hér á landi', meaning here in the country. You must keep them securely for seven years from the end of the financial year. There is a narrow permission to keep them abroad for up to six months. The authorities may demand them back in Iceland within a reasonable time. We rate this a mirror rule. HEALTH. Regulation No. 550/2015 on health records allows an outside host only if it holds ISO 27001 certification or equivalent. It allows a host abroad only where you meet the conditions for sending personal data out of the country under the data protection law. We rate this conditional. FINANCE, covering banking, payments, insurance and securities. The European operational resilience regulation known as DORA has applied in Iceland since 1 July 2025. It does not require data to stay in the country. It does make you state in the contract where data will be held and used, keep a register of your arrangements, and hold exit plans. We rate this conditional. TELECOM. We could not confirm whether a duty to keep traffic data survives in the Electronic Communications Act No. 70/2022. See the unconfirmed list. Article 109 of the 2022 Act repealed the old Act No. 81/2003. GOVERNMENT CLOUD, EDUCATION, GAMING, MAPPING AND GEOSPATIAL, DEFENCE. We found no rule requiring data to stay in the country, checked 18 August 2026, medium confidence.
Sources
- Official sourceAlþingi — consolidated statute bookLög um bókhald nr. 145/1994, 20. gr. — accounting records must be preserved in Iceland for seven years
althingi.is
“Allar bækur, sem fyrirskipaðar eru í lögum þessum, ásamt bókhaldsgögnum og fylgiskjölum ... skulu varðveittar hér á landi á tryggan og öruggan hátt í sjö ár frá lokum viðkomandi reikningsárs.”
Link checked 18 August 2026
- Official sourceIcelandic regulation database, island.isReglugerð nr. 550/2015 um sjúkraskrár — hosting of health record systems
island.is
“Hýsing sjúkraskrárkerfis hjá erlendum aðila er því aðeins heimil að fullnægt sé skilyrðum fyrir flutningi persónuupplýsinga úr landi samkvæmt lögum um persónuvernd”
Link checked 18 August 2026
- Official sourceEFTA SecretariatEEA-Lex factsheet: Regulation (EU) 2022/2554 (DORA) incorporated by Joint Committee Decision 40/2025, in force in the EEA from 1 July 2025
efta.int
Link checked 18 August 2026
- Official sourceAlþingi — consolidated statute bookFjarskiptalög nr. 81/2003 — marked repealed by Act 70/2022, Article 109
althingi.is
Link checked 18 August 2026
What to do: Plan for a database inside Iceland: this data is not allowed to leave.
Not fully verified — see “What we're not sure about” below.Sending data out of the country
You use one of the standard European routes. Send the data to a country Europe has officially approved as safe enough. Or sign the European Commission's standard contract with the receiver. Or use group-wide rules a regulator has approved. There are narrow one-off exceptions, such as the person's explicit consent. Those are not for routine or bulk transfers. One Icelandic detail catches people out. An approval of a foreign country only takes effect in Iceland once the Icelandic minister confirms it and publishes a notice in the official gazette.
- Ways to send data out:
- Official 'this country is safe' decision · Standard contract clauses · Approved group rules · Explicit consent · Needed for a contract
Article 16 of Act No. 90/2018 makes European Commission approvals of foreign countries work in Iceland. But the minister must confirm each decision and publish notice of it in Stjórnartíðindi, the official gazette. This has been done, so the destinations Europe has approved are available from Iceland. Still, the confirmation step is a real dependency. Reading the European list alone is not enough. The model is this: you may only send data to approved countries, and everything else needs paperwork. Approved destinations need nothing extra. The 2021 Standard Contractual Clauses are still the ones to use. There is also an Icelandic rule specifically on sending data abroad, rules No. 1155/2022 on the transfer of personal data to other countries. It is listed on the regulator's own page of laws. We could not retrieve its text, because the gazette site refused automated access. So we could not confirm its detailed conditions.
Sources
- Official sourceAlþingi — consolidated statute bookLög nr. 90/2018, 16. gr. — transfers to third countries; ministerial confirmation and gazette publication of adequacy decisions
althingi.is
Link checked 18 August 2026
- Official sourcePersónuvernd (Icelandic Data Protection Authority)Persónuvernd — laws and regulations, listing rules no. 1155/2022 on transfer of personal data to other countries
island.is
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionCommission Implementing Decision (EU) 2021/914 — Standard Contractual Clauses
eur-lex.europa.eu
What to do: Check the destination against the approved list first. Anywhere that is not on it needs the standard contract clauses signed before data leaves.
Not fully verified — see “What we're not sure about” below.The regulator, and whether it actually acts
Persónuvernd, the Icelandic Data Protection Authority, enforces the rules. It is fully up and running. It registered 2,124 new cases in 2025 and closed 2,232. It opens its own investigations without waiting for a complaint. It fines public bodies as well as private companies. It is also small. It has about 17 staff and a budget of roughly 379 million krónur (about 2.8 million US dollars). It says in its own annual report that it cannot cover every task the law gives it.
The 2025 annual report shows live enforcement. It fined the Capital Area Primary Health Care service 5 million krónur (about 36,000 US dollars) for unlawful sharing inside a health records system. It also issued a 12 million króna fine (about 88,000 US dollars), reduced to 8 million (about 58,000 US dollars) after a court challenge. In June 2026 the authority finished audits it started itself, of the National Prosecutor, district prosecutors and police commissioners. It found security measures had not been fully put in place. It closed the audits with formal guidance rather than orders, and said it will check again a year later. Industry regulators enforce alongside it. The Central Bank of Iceland supervises financial firms, including under the European operational resilience regulation. The Directorate of Health oversees health records. The Electronic Communications Office of Iceland and its national cyber team CERT-IS handle cyber incidents. Bookkeeping crimes are investigated by the district prosecutor and the tax investigation authority, not by the privacy regulator.
Sources
- Official sourcePersónuverndÁrsskýrsla Persónuverndar 2025 (annual report announcement, 5 May 2026)
island.is
Link checked 18 August 2026
- Official sourcePersónuverndPersónuvernd completes audits of personal data processing by the prosecution service, 4 June 2026
island.is
“öryggisráðstafanir hafi ekki að öllu leyti verið innleiddar með viðunandi hætti”
Link checked 18 August 2026
- Secondary sourcePersónuverndPersónuvernd annual report 2025 (full PDF) — 2,124 new cases, 2,232 concluded, 17 staff, ISK 378.7m budget, fines listed
assets.ctfassets.net
Link checked 18 August 2026
How long you must keep it — and when to delete it
There is a minimum keeping time and a duty to delete, and they point in opposite directions. You must keep accounting books, invoices and receipts for seven years, and keep them in Iceland. Under the European rules you must delete personal data once you no longer need it for the purpose you collected it for. When the two clash, keeping wins. A person cannot force you to delete records that the bookkeeping and tax law require you to hold.
- What you have to do here:
- Keep data for a minimum period · Delete data after a period
Bookkeeping Act No. 145/1994, Article 20, sets seven years from the end of the financial year, kept in Iceland. It allows only six months' tolerance for holding the records abroad. Cash register records run three years. Icelandic law sets no general maximum keeping period. The limit comes from the storage limitation rule in the European Regulation, applied case by case, plus each person's right to erasure. The right to erasure does not apply where you need the data to meet a legal duty. That is how the conflict resolves. Health records have their own rules under the Health Records Act No. 55/2009. Records must be kept securely in a health record system. If a system closes, they pass to the Director of Health. We could not confirm the rules on keeping telecom traffic data. See the unconfirmed list.
Sources
- Official sourceAlþingi — consolidated statute bookLög um bókhald nr. 145/1994, 20. gr. — seven-year retention in Iceland, six months abroad
althingi.is
“Þrátt fyrir ákvæði 1. mgr. hafa félög skv. 1. gr. heimild til að varðveita gögn skv. 1. mgr. erlendis í allt að sex mánuði. Yfirvöld geta þó krafist aðgangs að þeim hér á landi og skal þeim þá skilað innan hæfilegs tíma.”
Link checked 18 August 2026
- Official sourceAlþingi — consolidated statute bookLög um sjúkraskrár nr. 55/2009 — secure preservation of health records and transfer of records when a system closes
althingi.is
Link checked 18 August 2026
What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.
If something goes wrong
There are at least two deadlines, and three if you are a financial firm. You have 72 hours to report a personal data breach to Persónuvernd. You must tell the people affected without delay where the risk to them is high. Separately, operators of critical services must alert Iceland's national cyber security team as soon as possible under a 2019 law. Those services are banks, hospitals, energy, water, transport and digital infrastructure. Serious breaches of that law can lead to prosecution. Financial firms have a further, tighter reporting duty to the Central Bank under the European operational resilience rules.
- What you have to do here:
- Report breaches to the regulator · Tell affected people · Report cyber incidents
The 72-hour deadline is the standard European one. Iceland applies it through Act No. 90/2018. Act No. 78/2019 covers the security of network and information systems in critical infrastructure. It entered into force on 1 September 2020. It requires operators to notify the cyber security unit 'svo fljótt sem verða má', meaning as quickly as possible, about serious incidents or risks. It sets no fixed hour count. That is unusual, and it means the real deadline is judged after the fact. That Act carries daily penalties up to 500,000 krónur (about 3,600 US dollars). It also carries fines up to 10 million krónur (about 73,000 US dollars), or 3 percent of annual turnover. Deliberate breaches carry up to two years in prison. The financial-sector deadline comes from Regulation (EU) 2022/2554, in force in Iceland since 1 July 2025. We did not confirm its exact Icelandic reporting hours. We could not confirm any telecom-specific breach notification duty in the Electronic Communications Act No. 70/2022.
Sources
- Official sourceAlþingi — consolidated statute bookLög nr. 78/2019 um öryggi net- og upplýsingakerfa mikilvægra innviða, 8. gr. — incident notification to the cyber security unit
althingi.is
“Mikilvægir innviðir skulu tilkynna netöryggissveit ... svo fljótt sem verða má um alvarleg atvik eða áhættu”
Link checked 18 August 2026
- Official sourceCERT-ISCERT-IS — Iceland's national cyber security team and incident reporting portal
cert.is
Link checked 18 August 2026
- Official sourceAlþingi — consolidated statute bookLög nr. 90/2018 — data protection breach duties and enforcement powers
althingi.is
Link checked 18 August 2026
What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.
Not fully verified — see “What we're not sure about” below.What catches people out
Five things the summary does not cover. (1) For online consent, a child in Iceland is anyone under 13. Much of Europe uses 16. A product built for a 16-year-old threshold is wrong here. (2) Your accounting records must sit in Iceland. Bookkeeping breaches are crimes: fines, and up to six years in prison for serious cases. The district prosecutor and the tax investigators handle them, not the privacy regulator. (3) Public bodies can be fined in Iceland. The law says so directly, unlike in several European countries. (4) Some uses of data need a licence from Persónuvernd before you start. That is unusual under the European rules. (5) Three European laws do not yet apply here. The Data Act, the cybersecurity law known as NIS2, and the Artificial Intelligence Act have not been brought into the European Economic Area agreement.
- What you have to do here:
- Get a parent's consent for children
- What it costs if you get it wrong:
- Criminal liability
The 13-year threshold is in Article 10 of Act No. 90/2018. Fines on public authorities are directly allowed by Article 46(4). Uses of data that need a licence are governed by rules No. 811/2019, and Persónuvernd runs an application route for them. Bookkeeping penalties sit in Articles 36 to 41 of the Bookkeeping Act. Ordinary breaches carry fines. Serious ones carry up to six years in prison. The company is liable whether or not any individual was at fault. The district prosecutor and the tax investigation authority investigate. Trap 5 has a concrete result. From 12 January 2027 Europe gives you the right to switch cloud provider with no charges for moving your data out. That is not an Icelandic right today, because the Data Act is not part of Icelandic law.
Sources
- Official sourceAlþingi — consolidated statute bookLög nr. 90/2018, 10. gr. (age 13) and 46. gr. (fines, including on public authorities)
althingi.is
“Sé barnið undir 13 ára aldri telst vinnslan aðeins lögmæt að því marki sem forsjáraðili þess heimilar samþykki.”
Link checked 18 August 2026
- Official sourceAlþingi — consolidated statute bookLög um bókhald nr. 145/1994, 36.–41. gr. — criminal penalties, up to six years' imprisonment, prosecuted by the district prosecutor and tax investigators
althingi.is
Link checked 18 August 2026
- Official sourcePersónuverndPersónuvernd — laws and rules, including rules no. 811/2019 on processing subject to authorisation
island.is
Link checked 18 August 2026
- Official sourceEFTA SecretariatEEA-Lex factsheet: Regulation (EU) 2023/2854 (Data Act) — not yet incorporated into the EEA Agreement
efta.int
“EU legal act marked as EEA relevant by the EU and under scrutiny for incorporation into the EEA Agreement by Iceland, Liechtenstein and Norway.”
Link checked 18 August 2026
What's changing next
The main thing to watch is the queue of European laws waiting to be pulled into Icelandic law. It is not an Icelandic bill. Three laws were still outside the European Economic Area agreement on 18 August 2026. They are the Data Act, the cybersecurity law known as NIS2, and the Artificial Intelligence Act. Each will land when a joint committee decides. There is no Icelandic public consultation, and often little notice. The financial resilience regulation landed this way on 1 July 2025. That was more than five months after it started applying in the European Union.
Four changes can happen without new legislation, and they matter more than pending bills. (1) The EEA Joint Committee can bring in any of the three pending acts at a single meeting. The effect in Iceland then follows quickly. The Data Act in particular would switch on rights to move cloud provider and to move your data out free of charge. Those rights do not exist here today. (2) Under Article 16 of Act No. 90/2018 the minister controls whether and when a European approval of a foreign country is confirmed and published in the Icelandic gazette. That works without legislation. (3) Persónuvernd's licensing rules let it decide which uses of data need a licence before you start. (4) The six-month tolerance for holding accounting records abroad is an allowance, not a right. The authorities can demand the records back in Iceland at any time. At European level, pressure on the EU-US Data Privacy Framework carries through to Iceland. It remained in force and valid on 18 August 2026. But the European Data Protection Board wrote to the Commission on 31 July 2026. It asked the Commission to examine whether recent United States changes affect the decision's validity. Do not build your transfers on that one route alone.
Sources
- Official sourceEFTA SecretariatEEA-Lex factsheet: Directive (EU) 2022/2555 (NIS2) — under scrutiny, no Joint Committee Decision adopted
efta.int
Link checked 18 August 2026
- Official sourceEFTA SecretariatEEA-Lex factsheet: Regulation (EU) 2024/1689 (Artificial Intelligence Act) — not yet incorporated into the EEA Agreement
efta.int
Link checked 18 August 2026
- Official sourceEFTA SecretariatEEA-Lex factsheet: DORA in force in the EEA from 1 July 2025 (Joint Committee Decision 40/2025 of 20 February 2025)
efta.int
Link checked 18 August 2026
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries3 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Health data rules
Official name: Reglugerð um sjúkraskrár · Nr. 550/2015, issued under the Health Records Act no. 55/2009 · Directly binding regulation
An outside supplier may host Icelandic health record systems, and that supplier may sit abroad. Two conditions apply. The supplier must hold a recognised security certification such as ISO 27001. And you must meet the normal conditions for sending personal data out of the country. The Directorate of Health oversees the national electronic health record.
Enforced by Directorate of Health
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Certification scheme
What you have to do
- Hold a security certificateA third-party host of a health record system must hold ISO 27001 certification or an equivalent recognised certification.
- Put a transfer safeguard in placeYou may use a host abroad only if you meet the conditions for sending personal data out of the country under the data protection law.
- Written vendor contract
Sources
- Official sourceIcelandic regulation database, island.isReglugerð nr. 550/2015 um sjúkraskrár — hosting and certification requirements
island.is
“sjúkraskrárkerfið er hýst hjá þriðja aðila skal það einungis gert hjá viðurkenndum þjónustuaðila, þ.e. aðila sem annaðhvort hefur vottað gæðakerfi skv. ISO-27001”
Link checked 18 August 2026
- Official sourceAlþingi — consolidated statute bookLög um sjúkraskrár nr. 55/2009 — enabling act, custodianship and ministerial power to regulate electronic health records
althingi.is
Link checked 18 August 2026
Payment data rules
Official name: Reglugerð (ESB) 2022/2554 um stafrænt rekstrarþol fjármálageirans (DORA), incorporated into the EEA Agreement · EEA Joint Committee Decision No. 40/2025 of 20 February 2025 · Directly binding regulation
Europe's financial operational resilience regulation reached Iceland on 1 July 2025. That was more than five months after it started applying in the European Union. It does not make banks, insurers, payment firms or investment firms keep data in the country. It does require four things. Your contract must name where data will be held and used. You must keep a register of supplier arrangements. You need exit plans. And you must report incidents.
Enforced by Central Bank of Iceland (Financial Supervision)
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Written vendor contractYour contract with a technology supplier must state where data will be held and used. It must also give you audit and access rights.
- Keep records of how you use dataRegister of information on all contractual arrangements with technology suppliers.
- Report cyber incidents
- Independent audit
What it costs if you get it wrong
- Order to stopSupervisory measures by the Central Bank of Iceland's financial supervision
Sources
- Official sourceEFTA SecretariatEEA-Lex factsheet: Regulation (EU) 2022/2554 (DORA), Joint Committee Decision 40/2025, in force in the EEA 1 July 2025
efta.int
“Incorporated into the EEA Agreement and in force”
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionRegulation (EU) 2022/2554 on digital operational resilience for the financial sector
eur-lex.europa.eu
Cyber security rules
Official name: Lög um öryggi net- og upplýsingakerfa mikilvægra innviða · Nr. 78/2019 · Act of parliament
Iceland's cybersecurity law for critical infrastructure: energy, water, transport, health, banking and digital infrastructure. You must report incidents to the national cyber team as fast as possible. There is no fixed deadline. Breaking it can be a crime. This is the older European standard. The replacement law known as NIS2 has not yet been brought into the European Economic Area agreement. So this is still what binds you in Iceland.
Enforced by CERT-IS — national cyber security team
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Report cyber incidentsSerious incidents and risks must be reported to the national cyber security unit as quickly as possible. The Act sets no fixed hour count.
- Secure the data
What it costs if you get it wrong
- Criminal liability: Up to 2 years' imprisonmentIntentional breach
- Fixed maximum fine: ISK 10 million — about $73 thousandAdministrative fine; alternatively up to 3% of annual turnover
- Daily fine until fixed: ISK 500,000 per day — about $4 thousandContinuing non-compliance
Sources
- Official sourceAlþingi — consolidated statute bookLög nr. 78/2019 um öryggi net- og upplýsingakerfa mikilvægra innviða
althingi.is
“Mikilvægir innviðir skulu tilkynna netöryggissveit ... svo fljótt sem verða má um alvarleg atvik eða áhættu”
Link checked 18 August 2026
- Official sourceEFTA SecretariatEEA-Lex factsheet: NIS2 Directive (EU) 2022/2555 still under scrutiny, not incorporated
efta.int
Link checked 18 August 2026
Applies to every company2 rules
These bind you whatever business you are in, once the country's rules reach you.
Children's data rules
Official name: Lög um persónuvernd og vinnslu persónuupplýsinga · Nr. 90/2018 · Act of parliament
Iceland's national data protection act. It carries the European rules into Icelandic law and adds three local twists. Children give their own consent from age 13. Fines can be imposed on government bodies as well as companies. And some uses of data need a licence from the regulator before you begin.
Enforced by Icelandic Data Protection Authority
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Explicit consent, Needed for a contract
What you have to do
- Get a parent's consent for children — applies at: under 13Iceland chose the lowest age Europe allows. A product built for a 16-year-old threshold is misconfigured here.
- Register or notifyCertain uses of data need a licence from Persónuvernd first, under rules no. 811/2019.
- Appoint a data protection officer
- Put a transfer safeguard in placeA European approval of a destination country takes effect in Iceland only after the minister confirms it and publishes notice in the official gazette.
- Report breaches to the regulator — within 72 hours
What it costs if you get it wrong
- Fixed maximum fine: ISK 2.4 billion — about $18 millionHigher-tier breaches; the lower tier is ISK 1.2 billion (about $8.8 million)
- Percentage of global turnover: 4% of worldwide annual turnoverHigher-tier breaches, whichever is higher
- Claims by individualsCompensation claims by individuals
Sources
- Official sourceAlþingi — consolidated statute bookLög um persónuvernd og vinnslu persónuupplýsinga nr. 90/2018 (consolidated text)
althingi.is
“Heimilt er að leggja sektir á einstaklinga og lögaðila, þar á meðal stjórnvöld og stofnanir sem falla undir gildissvið stjórnsýslulaga.”
Link checked 18 August 2026
- Official sourcePersónuverndPersónuvernd — the laws, regulations and rules it administers
island.is
Link checked 18 August 2026
Personal data needs a copy kept in the country
Official name: Lög um bókhald · Nr. 145/1994, 20. gr. · Act of parliament
The real Icelandic rule about keeping data in the country, and the one most trackers miss. Every company's accounting books, vouchers and supporting data must be kept inside Iceland for seven years. You may store them abroad for six months at most. Breaches are crimes, not administrative matters. The district prosecutor and the tax investigation authority handle them.
Enforced by Iceland Revenue and Customs
How this country controls where data goes: Approval each time
What you have to do
- Keep the data in the countryBooks, accounting data and vouchers must be preserved in Iceland. Holding them abroad is permitted for up to six months only, and the authorities may demand their return to Iceland within a reasonable time.
- Keep data for a minimum period — 7 yearsSeven years from the end of the financial year. Cash register records: three years.
What it costs if you get it wrong
- Criminal liability: Up to 6 years' imprisonment for serious breachesFailure to keep, secure or preserve accounting records; falsifying accounts
- Fixed maximum fineOrdinary breaches; legal entities are liable regardless of individual fault
Sources
- Official sourceAlþingi — consolidated statute bookLög um bókhald nr. 145/1994, 20. gr. (preservation) and 36.–41. gr. (penalties and investigation)
althingi.is
“Allar bækur, sem fyrirskipaðar eru í lögum þessum, ásamt bókhaldsgögnum og fylgiskjölum ... skulu varðveittar hér á landi á tryggan og öruggan hátt í sjö ár frá lokum viðkomandi reikningsárs.”
Link checked 18 August 2026
Applies across the EEA2 rules
Written once for the whole bloc, and in force in every member country.
Europe's main privacy law
Official name: Reglugerð (ESB) 2016/679 (General Data Protection Regulation), incorporated into the EEA Agreement · EEA Joint Committee Decision No. 154/2018 of 6 July 2018 · Directly binding regulation
Europe's General Data Protection Regulation applies in Iceland through the European Economic Area agreement, not through European Union membership. It does not require data to stay in Iceland or in Europe. It sets conditions for sending data out. Nothing in it forces you to keep data in the country.
Enforced by Icelandic Data Protection Authority
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims
What you have to do
- Tell people what you do
- Let people see their data
- Let people correct their data
- Let people delete their data
- Let people take their data elsewhere
- Let people object
- Secure the data
- Keep records of how you use data
- Assess high-risk projects
- Put a transfer safeguard in place
- Written vendor contract
- Appoint a representativeOnly where the organisation has no establishment in the European Economic Area.
- Report breaches to the regulator — within 72 hours
- Tell affected peopleWhere the breach is likely to result in a high risk to the people affected.
What it costs if you get it wrong
- Percentage of global turnover: 4% of worldwide group turnoverBreach of basic principles, individual rights or transfer rules
- Order to stopOrder to stop processing or suspend flows to a third country
- Claims by individualsCompensation claims by individuals
Sources
- Official sourceEFTA SecretariatEEA-Lex: GDPR incorporated by Joint Committee Decision 154/2018, in force in the EEA 20 July 2018
efta.int
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionRegulation (EU) 2016/679 (General Data Protection Regulation)
eur-lex.europa.eu
Cloud and outsourcing rules
Official name: Reglugerð (ESB) 2023/2854 (Data Act) — adopted in the European Union, NOT yet incorporated into the EEA Agreement · Regulation (EU) 2023/2854; no EEA Joint Committee Decision as of 18 August 2026 · Directly binding regulation
The European Data Act does not apply in Iceland. It has applied in the European Union since 12 September 2025. From 12 January 2027 it bans cloud switching charges and charges for moving your data out. It is still outside the European Economic Area agreement, so it creates no rights and no duties in Iceland today. A single joint committee decision can switch it on, with no Icelandic consultation.
Enforced by Icelandic Data Protection Authority
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Make switching cloud provider possibleNOT in force in Iceland. In the European Union, all cloud switching charges and charges for moving your data out must be zero from 12 January 2027. That right does not exist in Iceland unless the EEA Joint Committee brings the Data Act in.
Sources
- Official sourceEFTA SecretariatEEA-Lex factsheet: Regulation (EU) 2023/2854 (Data Act) — under scrutiny, Joint Committee Decision pending
efta.int
“EU legal act marked as EEA relevant by the EU and under scrutiny for incorporation into the EEA Agreement by Iceland, Liechtenstein and Norway.”
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.
Whether the Electronic Communications Act No. 70/2022 still requires telecom operators to retain traffic and location data, for how long, and whether any part of that duty has been disapplied following European court rulings
We could not confirm the current position on keeping telecom traffic data. The full law on the parliament's own site is too long for automated retrieval. Every attempt stopped at around Article 31 to 36, well before Chapter XIII on privacy in electronic communications. We can confirm only that Article 109 of the 2022 Act repealed the previous Act No. 81/2003. Treat Icelandic telecom retention as unresearched, not as absent. If you run a telecoms service, check before you rely on this.
The detailed conditions in rules no. 1155/2022 on the transfer of personal data to other countries
These rules are listed on Persónuvernd's own page of laws. The text sits on the official gazette site, which refused automated access. It is not in the island.is regulation database under that number. So we could not confirm its conditions.
Whether the six-month allowance for holding accounting records abroad permits ongoing use of a foreign cloud accounting system, and whether the tax authority has published guidance on it
The law is clear that records must be kept in Iceland, with six months' tolerance abroad. We found no official guidance on how that applies to cloud bookkeeping that syncs continuously. This is the most commercially important open question in this record. Check with the tax authority before you rely on a cloud setup.
That annual accounts must be retained for 25 years
This figure appeared in one automated reading of the Bookkeeping Act but not in a second reading. We confirmed the seven-year general period twice. We could not confirm the 25-year figure.
Whether the Central Bank of Iceland imposes outsourcing, cloud or data-location conditions on financial firms beyond the European operational resilience regulation
We could not read the Central Bank's rules and guidelines pages. Several likely paths returned 404. Check with the Central Bank before you rely on this.
Whether Iceland has a binding public-sector cloud or where data has to be stored policy for government systems
We found no such rule on the government portal, checked 18 August 2026. We could not confirm it either way, because the Government Offices site (stjornarradid.is) refused automated access. Check before you rely on this.
Whether any localisation rule exists for mapping and geospatial data, education, online gaming or defence
We found no rule, checked 18 August 2026, medium confidence. We had no working general web search, so we could not cover these industries as thoroughly as the others. If you work in one of them, check before you rely on this.
The exact incident-reporting deadlines that apply to Icelandic financial firms under the European operational resilience regulation
We confirmed that the regulation is in force in Iceland from 1 July 2025. We did not confirm the specific hour counts as applied by the Central Bank of Iceland. Check with the Central Bank before you rely on a deadline.
Whether rules no. 811/2019 on processing subject to authorisation are still current and which categories they cover
These rules are listed on the regulator's own page of laws, and the regulator runs an application route for licensed uses of data. The rules text sits on the official gazette site, which blocked automated access. So we could not confirm the detail.
Whether any Persónuvernd fine has been issued between 1 January 2026 and 18 August 2026
We could read the 2025 annual report and 2026 news items, but not the decision list itself. We may have missed a 2026 fine. Its absence from this record does not mean none was issued.
Freshness and refresh
Freshness
Checked about 2 months ago, on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.