Iceland Data Protection and Processing of Personal Data Act (Act No. 90/2018)
Iceland Act 90/2018 Chap 3 - Rights

Iceland Data Protection and Processing of Personal Data Act (Act No. 90/2018) ICELAND-Act90-Chap3-Transparency-DataSubjectRights-Access-Rectification-Erasure: Iceland Act 90/2018 - Chapter III Transparency + Data Subject Rights (Articles 14-23) - Access + Rectification + Erasure + Portability + Object + Automated Decisions

Chapter III (Articles 14-23) Rights of the Data Subject. Article 17 Information to Data Subjects (direct collection) - GDPR Article 13 transposition: identity + contact of controller + DPO + purposes + lawful basis + recipients + transfers + retention + rights + complaint to Personuvernd + automated decisions. Article 18 Information to Data Subjects (indirect collection) - GDPR Article 14 transposition (collection from third parties). Article 19 Right of Access - GDPR Article 15; 1 month response (3 months max complex); Personuvernd guidance on access procedure. Article 20 Rectification + Erasure + Restriction - GDPR Articles 16 + 17 + 18; right to be forgotten with Iceland-specific exceptions; restriction marking. Article 21 Right to Object + Automated Decisions - GDPR Articles 21 + 22; absolute right to object to direct marketing; profiling and automated decision-making restrictions. Article 22 Right to Data Portability - GDPR Article 20; machine-readable format. Article 23 Restrictions - Article 23 GDPR transposition: scientific research + statistical purposes + judicial independence + Iceland-specific (Section 23 Subsections 1-4) on legal advice + supervisory + parliamentary oversight + criminal investigation; restrictions must respect essence of rights. Personuvernd recommendation on language - notices + responses in Icelandic + English where appropriate. Iceland Act 90/2018 + Chapter III + Rights + 1-month response + Icelandic-language notices applies.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 122 controls across 44 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

GDPR · 6 controls

  • GDPR-Art.10 Processing of personal data relating to criminal convictions
  • GDPR-Art.11 Processing which does not require identification
  • GDPR-Art.15 Right of access by the data subject
  • GDPR-Art.19 Notification obligation regarding rectification, erasure or restriction
  • GDPR-Art.20 Right to data portability
  • GDPR-Art.9 Processing of special categories of personal data

APPI · 4 controls

  • APPI-A23 Security Control Measures
  • APPI-A24 Supervision of Employees
  • APPI-A27 Restriction on Provision to Third Parties
  • APPI-A33 Request for Disclosure of Retained Personal Data

Bahrain PDPL · 4 controls

  • UAE-PDPL-Art.10 Data Protection Officer (DPO) (UAE PDPL Article 10)
  • UAE-PDPL-Art.18_19_20_21 Security measures, controller/processor relationship, DPIA (UAE PDPL Articles 18-21)
  • UAE-PDPL-Art.4_5 Lawful basis and principles for processing personal data (UAE PDPL Articles 4-5)
  • UAE-PDPL-Art.8 Records of processing activities (UAE PDPL Article 8)
  • APP-1 APP 1 - Open and transparent management of personal information
  • APP-3 APP 3 - Collection of solicited personal information
  • APP-5 APP 5 - Notification of the collection of personal information
  • AT-DSG-11 Sections 42-45 - Data subject rights (law enforcement)
  • AT-DSG-13 Section 36 - Scope of law enforcement processing
  • AT-DSG-14 Section 38 - Lawfulness of law enforcement processing
  • AZ-DPA-12 Article 13 - Cross-border transfer
  • AZ-DPA-14 Article 16 - Liability for violations
  • AZ-DPA-15 Article 17 - Dispute resolution
  • BB-DPA-14 Section 15 - Right to Data Portability
  • BB-DPA-16 Section 22 - General Principle for Transfers
  • BB-DPA-21 Sections 61-69 - Data Privacy Officer

ISO/IEC 29100:2024 · 3 controls

  • 29100-6.10 Information security
  • 29100-6.5 Use, retention and disclosure limitation
  • 29100-6.9 Accountability

ISO/IEC 29134:2023 · 3 controls

  • 29134-1 Scope
  • 29134-3 Terms and definitions
  • 29134-9.1 PIA report structure
  • AUPRV-4 APP 10-11 Quality, Security of Personal Information
  • AUPRV-5 APP 12-13 Access and Correction of Personal Information
  • AUPRV-7 Notifiable Data Breaches (NDB) Scheme, Incident Response
  • LOPDP-EC-Data-Subject-Rights-Access-Rectification-Erasure-Object-Portability-Automated-Decisions-Articles-16-27 Ecuador LOPDP Data Subject Rights + Access + Rectification + Erasure + Articles 16-27
  • LOPDP-EC-Security-Processor-Breach-Notification-Articles-37-45-Encryption-72-Hour-SPDP-Notification-CSIRT Ecuador LOPDP Security + Processor + Breach Notification + Articles 37-45 + 72-Hour
  • FDBR-ControllerObligations-DPA-Notice Controller + Processor Obligations + Data Protection Assessments (Fla. Stat. 501.707, 501.708, 501.71, 501.711)
  • FDBR-Scope-Defs Scope, Applicability Thresholds and Definitions (Fla. Stat. 501.701, 501.702, 501.703, 501.704)

ISO/IEC 27400:2022 · 2 controls

  • 27400-5.4 Data and privacy risks
  • 27400-7.3 Data minimization and purpose limitation
  • 27557-3 Terms and definitions
  • 27557-4.3 Individual impact consideration
  • RBI-AA-ConsentArchitecture-ConsentArtefact-ExplicitConsent-PurposeLimitation-CustomerDashboard-ORS-CMP RBI AA Consent Architecture - Consent Artefact + Explicit Customer Consent + Purpose Limitation + Customer Consent Dashboard + Online Revocation Service + Consent Management Provider
  • RBI-AA-Ecosystem-FIPs-FIUs-Interoperability-Onboarding-Sahamati-DPI-IndiaStack RBI AA Ecosystem - Financial Information Providers (FIPs) + Financial Information Users (FIUs) + Interoperability + Sahamati SRO Onboarding + DPI India Stack + Cross-Sector Regulators

India DPDP Act · 2 controls

  • INCDPA-ConsumerRights-Access-Correction-Deletion-Portability-OptOut-TargetedAd-Sale-Profiling-Appeal-45Day Indiana CDPA Consumer Rights - Access + Correction + Deletion + Portability + Opt-Out of Targeted Advertising/Sale/Profiling + 45-Day Response + 45-Day Extension + Authorised Agent + Appeal Process
  • INCDPA-Controller-PrivacyNotice-PurposeLimitation-DataMinimisation-Transparency-LawfulBasis Indiana CDPA Controller Obligations - Privacy Notice + Purpose Limitation + Data Minimisation + Transparency + Lawful Basis + Reasonable + Adequate + Relevant + Limited to What is Necessary

Indonesia PDP Law · 2 controls

  • ItalyCodice-Garante-Enforcement-AdministrativeSanctions-Criminal-Art166-167-170-20MEUR-Coord-EDPB Italy Codice Garante Authority + Article 140-bis + Article 144 Complaints + Article 166 Administrative Sanctions up to EUR 20M/4% + Article 167 Criminal Offences + Article 170 Failure to Comply with Garante Orders + EDPB Coordination
  • ItalyCodice-SpecialCategories-Health-Workplace-Education-ScientificResearch-HistoricalResearch-Art75-92-96-99-101 Italy Codice Special Categories + Article 75 Administrative Fines + Article 92 Medical Records + Article 96 Education + Article 99 Scientific Research + Article 101 Historical Research + Workplace Privacy + Worker Monitoring Article 4 Workers Statute
  • DOM172-Data-Subject-ARCO-Rights-Habeas-Data-Action-Constitutional-Article-70-Access-Rectification-Cancellation-Opposition Dominican Republic Law 172-13 ARCO Rights + Habeas Data Action + Constitutional Article 70
  • DOM172-Lawful-Basis-Consent-Notice-Information-Duty-Articles-4-12-Quality-Principle-Purpose-Limitation-Minimisation Dominican Republic Law 172-13 Lawful Basis + Consent + Notice + Information Duty + Articles 4-12
  • PAKPDPB-3 Data Subject Rights
  • PAKPDPB-8 Enforcement, Penalties, Complaints, Retention, Training
  • RUSPD-1 Scope, Definitions, Principles under 152-FZ
  • RUSPD-4 Special Categories, Biometric Data
  • 502 Interoperability with Assistive Technology
  • 707 Real-Time Text Functionality
  • USMCADIGITAL-1 Cross-Border Data Flows and Localisation
  • USMCADIGITAL-2 Personal Information Protection and Consumer Protection
  • VERMONTAICDA-1 AI System Inventory and Risk Assessment
  • VERMONTAICDA-3 Bias Testing, Discrimination Prevention, Transparency
  • VIETNAMCYBER-2 Prohibited Acts (Access, Interception, Forgery, Content)
  • VIETNAMCYBER-4 Incident Reporting and Cooperation
  • AL-DPA-12 International Data Transfers
  • DS-2 Ensure software supply chain security
  • CA-10 Selects and Develops Control Activities
  • CTDPA-1 Definitions
  • DIQ-1 Data Integration and Interoperability
  • FTC-Safeguards-Scope-Defs Scope, Definitions and Financial Institution Applicability (16 CFR 314.1, 314.2)

IEEE 7000 · 1 control

  • IEEE7000-Values-Elicitation-Prioritisation-IEEE7000Family-Bias-Privacy-Transparency IEEE 7000 Clauses 6 + 6.1 - Ethical Values Elicitation + Prioritisation + IEEE 7000 Family Integration (Bias + Privacy + Transparency + Wellbeing)
  • NISTPF-1 Identify-P - Business Environment, Data Processing Inventory, Ecosystem, and Risk Assessment
  • RIDTPPA-2 Consumer Rights (Access, Correction, Deletion, Portability, Opt-Out)
  • IM8-DAT.3 Data Sharing and Transfer

South Korea PIPA · 1 control

  • PIPA-Pseudonymisation-Article-28-2-3-Enforcement-PIPC-Investigation-Surcharges-3-Percent-Revenue-Article64-2 Korea PIPA Pseudonymisation + Article 28-2 + Enforcement + PIPC + Surcharges 3% + Article 63 + 64-2
  • TEFCAREC-1 Common Agreement Conformance and Onboarding
  • CPSC-STD.4 Interoperability Safety

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 122 it maps to, and the evidence behind each claim, over MCP and REST.