Iceland Data Protection and Processing of Personal Data Act (Act No. 90/2018)
Iceland Act 90/2018 Chap 5 - Cross-Border

Iceland Data Protection and Processing of Personal Data Act (Act No. 90/2018) ICELAND-Act90-Chap5-CrossBorder-EEA-AdequacyDecisions-SCC-BCR: Iceland Act 90/2018 - Chapter V Cross-Border Transfer of Personal Data + EEA + Adequacy + SCCs + BCRs + Article 30 Privacy Policy

Chapter V (Articles 27-30) Transfer of Personal Data Abroad. Articles 27 + 28 + 29 + 30 govern cross-border transfers per GDPR Articles 44-49 transposition. EEA internal transfers: free flow between Iceland + Norway + Liechtenstein + EU 27 Member States (no transfer mechanism needed; equivalent protection). Adequacy decisions: EU Commission adequacy decisions apply via EEA Agreement (UK + Switzerland + Canada + Japan + Israel + New Zealand + Argentina + Uruguay + Faroe Islands + Isle of Man + Jersey + Guernsey + Andorra + South Korea); Iceland may issue own adequacy decisions for territories not covered by EU. Standard Contractual Clauses (SCCs): EU Commission Decision (EU) 2021/914 applies; Personuvernd may issue Iceland-specific SCCs. Binding Corporate Rules (BCRs): approved per Iceland or EU lead authority. Specific situation derogations (Article 49 GDPR): consent + contract performance + public interest + legal claims + vital interests + register + compelling legitimate interests one-time. Transfer Impact Assessment (TIA) per Schrems II + EDPB Guidance + Personuvernd 2022 supplement. Article 30 Privacy Policy (Iceland-specific in Chapter V context) - publication of controller privacy policy + cross-border transfer disclosure + recipient countries + safeguards. Coordinates with EDPB + EU Commission + Iceland-Norway-Liechtenstein EEA EFTA Surveillance Authority (ESA) for EEA EFTA + national CSIRT (CERT-IS). Iceland Act 90/2018 + Chapter V + Cross-Border + EEA + Adequacy + SCCs + BCRs applies.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 55 controls across 27 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • EHDS-HOLD-3 Dataset Descriptions and Catalogues
  • EHDSREG-1 Mandatory Requirements for EHR Systems (Articles 14-29)
  • EHDSREG-4 Digital Health Authorities, Governance, MyHealth@EU
  • EHDSREG-5 Cross-Border Health Data Flows

Bahrain PDPL · 3 controls

  • UAE-PDPL-Art.18_19_20_21 Security measures, controller/processor relationship, DPIA (UAE PDPL Articles 18-21)
  • UAE-PDPL-Art.22_23_24 Cross-border data transfers (UAE PDPL Articles 22-24)
  • UAE-PDPL-FreeZones Coordination with DIFC, ADGM and sectoral data protection regimes
  • AUPRV-3 APP 6-9 Use/Disclosure, Direct Marketing, Cross-Border, Government Identifiers
  • AUPRV-6 Sensitive Information, PIA, Privacy by Design, Children
  • AUPRV-8 OAIC Cooperation, Vendor Management, Training, Complaints, Enforcement
  • AL-DPA-14 Direct Marketing
  • AL-DPA-7 Right of Access
  • DIQ-2 Data Quality Management
  • DIQ-3 Metadata Management
  • LOPDP-EC-Cross-Border-Transfers-Articles-59-65-Adequacy-SCC-BCR-EU-Schrems-LatAm-CBPR-Andean-Community Ecuador LOPDP Cross-Border + Articles 59-65 + Adequacy + Andean Community + LatAm
  • LOPDP-EC-Governance-DPO-ROPA-DPIA-Privacy-by-Design-Training-Articles-46-58-Compliance-Monitoring Ecuador LOPDP Governance + DPO + ROPA + DPIA + Privacy by Design + Training

IEEE 7000 · 2 controls

  • IEEE7000-Operations-Lifecycle-OngoingMonitoring-Incident-Decommissioning IEEE 7000 - Operations + Lifecycle + Ongoing AI Risk Monitoring + Data Provenance + Retention + Privacy + Safe Deployment + Decommissioning + Disposal
  • IEEE7000-Values-Elicitation-Prioritisation-IEEE7000Family-Bias-Privacy-Transparency IEEE 7000 Clauses 6 + 6.1 - Ethical Values Elicitation + Prioritisation + IEEE 7000 Family Integration (Bias + Privacy + Transparency + Wellbeing)

India DPDP Act · 2 controls

  • INCDPA-Processor-Contracts-DPA-Subprocessor-Audit-Confidentiality-EndOfContract Indiana CDPA Processor Contracts - Data Processing Agreement (DPA) + Required Provisions + Subprocessor Approval + Confidentiality + End of Contract Deletion + Audit Rights + Assistance
  • INCDPA-Security-ReasonablePractices-Breach-Notification-Records-Encryption-Pseudonymisation Indiana CDPA Security + Reasonable Practices + Breach Notification + Indiana Breach Notification Law (IC 24-4.9) + Records + Encryption + Pseudonymisation + De-Identification
  • DOM172-Cross-Border-Transfer-Article-80-Vendor-Processor-Management-Marketing-Direct-Communications-Article-23-24-26 Dominican Republic Law 172-13 Cross-Border Transfer + Vendor Management + Marketing + Articles 23-24-26-80
  • DOM172-Supervisory-Authority-Cooperation-Sanctions-Penalties-Articles-77-79-Awareness-Training-Retention-DPO-Designation Dominican Republic Law 172-13 Supervisory Authority + Sanctions + Articles 77-79 + DPO + Awareness
  • APP-8 APP 8 - Cross-border disclosure of personal information
  • AZ-DPA-12 Article 13 - Cross-border transfer
  • BB-DPA-17 Section 24 - Appropriate Safeguards

GDPR · 1 control

  • GDPR-Art.45 Transfers on the basis of an adequacy decision
  • ICP-25 Supervisory Cooperation and Coordination

Indonesia PDP Law · 1 control

  • PAKPDPB-6 Cross-Border Transfer and Data Localization
  • RUSPD-4 Special Categories, Biometric Data
  • AIGF-1.3 Data Management
  • IM8-CLD.4 Cloud Data Sovereignty
  • USMCADIGITAL-1 Cross-Border Data Flows and Localisation
  • VIETNAMCYBER-3 Data Localization and Cross-Border

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 55 it maps to, and the evidence behind each claim, over MCP and REST.