Iceland Data Protection and Processing of Personal Data Act (Act No. 90/2018)
Iceland's Act on Data Protection and the Processing of Personal Data (Act No. 90/2018) implements the EU GDPR into Icelandic law via the EEA Agreement. The Icelandic Data Protection Authority (Persónuvernd) oversees enforcement. The Act includes national provisions for processing of national identification numbers (kennitala), processing for journalistic purposes, research and statistics, the age of digital consent (13 years), and health data processing. Iceland applies the GDPR framework fully as an EEA member state.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (21)
Accountability
| Code | Title |
|---|---|
| ACT90-ART24 | Controller Responsibility and Privacy by Design |
| ACT90-ART26 | Records of Processing Activities |
Breach response
| Code | Title |
|---|---|
| ACT90-ART28 | Notification to Data Subjects |
Chapter I — General Provisions
| Code | Title |
|---|---|
| Art. 1 | Open Finance Implementation |
| Art. 2 | Consent Definition |
| Art. 3 | Objectives of Open Finance |
| Art. 4 | Participating Institutions |
| Art. 5 | Prohibited AI Practices |
| Art.1 | Purpose of the Law |
| Art.2 | Scope |
| Art.3 | Definitions |
| Art.4 | Principles for Data Processing |
| Art.8 | Rights of Data Subjects |
| HUN-1 | Purpose and Scope |
| HUN-2 | Definitions |
| HUN-3 | Fundamental Rules |
| URY-1 | Fundamental Right (Article 1) |
| URY-2 | Scope and Definitions (Article 2–4) |
Chapter II — Conditions for Processing
| Code | Title |
|---|---|
| Art. 11 | Technical Documentation |
| Art. 12 | Record-Keeping |
| Art. 14 | Human Oversight |
| Art. 15 | Accuracy, Robustness and Cybersecurity |
| Art. 9 | Risk Management System |
Chapter III — Rights of Data Subjects
| Code | Title |
|---|---|
| Art. 14 | Human Oversight |
| Art. 16 | Obligations of Providers of High-Risk AI Systems |
| Art. 17 | Quality Management System |
| Art. 18 | Documentation Keeping |
| Art. 19 | Automatically Generated Logs |
| Art. 20 | Corrective Actions and Duty of Information |
| Art. 21 | Cooperation with Competent Authorities |
| Art. 23 | Transitional Provisions |
| Art. 25 | Criminal Penalties |
| URY-7 | Right of Access (Article 13) |
| URY-8 | Right of Rectification (Article 15) |
| URY-9 | Right of Deletion (Article 15) |
Chapter IV — Obligations of Controllers and Processors
| Code | Title |
|---|---|
| Art. 22 | Authorised Representatives of Providers of High-Risk AI Systems |
| Art. 24 | Restrictions on Processing Unique Identification Information |
| Art. 25 | Criminal Penalties |
| Art. 26 | Obligations of Deployers of High-Risk AI Systems |
Chapter V — Transfer of Personal Data
| Code | Title |
|---|---|
| Art. 29 | Application of a Conformity Assessment Body for Notification |
| Art. 30 | Privacy Policy |
| Art. 50 | Transparency Obligations for Providers and Deployers of Certain AI Systems |
| Art. 52 | Procedure |
Chapter VI — Data Protection Authority (Persónuvernd)
| Code | Title |
|---|---|
| Art. 35 | Right of Access |
| Art. 38 | Processing in Employment Context |
| Art. 39 | Compensation for Damages |
| Art. 41 | Exemptions from Certain GDPR Provisions |
Consent
| Code | Title |
|---|---|
| ACT90-ART10 | Conditions for Consent |
Criminal data
| Code | Title |
|---|---|
| ACT90-ART12 | Processing of Criminal Conviction Data |
Definitions
| Code | Title |
|---|---|
| ACT90-ART3 | Definitions and Roles |
Governance
| Code | Title |
|---|---|
| ACT90-ART35 | Designation of Data Protection Officer |
Lawful basis
| Code | Title |
|---|---|
| ACT90-ART9 | Lawfulness of Processing |
Principles
| Code | Title |
|---|---|
| ACT90-ART8 | Principles Relating to Processing |
Rights
| Code | Title |
|---|---|
| ACT90-ART19 | Right of Access |
| ACT90-ART20 | Rectification, Erasure, and Restriction |
| ACT90-ART21 | Right to Object and Automated Decisions |
| ACT90-ART22 | Right to Data Portability |
Risk assessment
| Code | Title |
|---|---|
| ACT90-ART29 | Data Protection Impact Assessment |
Scope
| Code | Title |
|---|---|
| ACT90-ART2 | Scope and Material Application |
Security and breach
| Code | Title |
|---|---|
| ACT90-ART27 | Security of Processing and Breach Notification |
Sensitive data
| Code | Title |
|---|---|
| ACT90-ART11 | Special Categories of Personal Data |
Third parties
| Code | Title |
|---|---|
| ACT90-ART25 | Processor and Sub-Processor Arrangements |
Transparency
| Code | Title |
|---|---|
| ACT90-ART17 | Information to Data Subjects (Collection) |
| ACT90-ART18 | Information to Data Subjects (Indirect Collection) |
Your Compliance Coverage
If you comply with Iceland Data Protection and Processing of Personal Data Act (Act No. 90/2018), you already cover:
EU AI Act
34%
21 controls mapped
Compare →BS 65000:2014 — Guidance on Organizational Resilience
32%
20 controls mapped
Compare →Law 1581 of 2012 - Statutory Framework for the Protection of Personal Data
32%
20 controls mapped
Compare →+ 631 more: Albania Law on Protection of Personal Data (Law No. 9887, 2008, amended 2014) (31%), EU Network Code on Cybersecurity for the Electricity Sector (31%)
See all 634 mapped frameworks ↓Maps to 634 other frameworks
Frequently Asked Questions
What is Iceland Data Protection and Processing of Personal Data Act (Act No. 90/2018)?
Iceland Data Protection and Processing of Personal Data Act (Act No. 90/2018) is a compliance framework from Iceland with 21 domains and 64 controls. Iceland's Act on Data Protection and the Processing of Personal Data (Act No. 90/2018) implements the EU GDPR into Icelandic law via the EEA Agreement. The Icelandic Data Protection Authority (Persónuvernd) oversees enforcement. The Act includes national provisions for processing of national identification numbers (kennitala), processing for journalistic purposes, research and statistics, the age of digital consent (13 years), and health data processing. Iceland applies the GDPR framework fully as an EEA member state. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does Iceland Data Protection and Processing of Personal Data Act (Act No. 90/2018) have?
Iceland Data Protection and Processing of Personal Data Act (Act No. 90/2018) has 64 controls organised across 21 domains. The largest domains are Chapter I — General Provisions (15 controls), Chapter III — Rights of Data Subjects (12 controls), Chapter II — Conditions for Processing (5 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does Iceland Data Protection and Processing of Personal Data Act (Act No. 90/2018) map to?
Iceland Data Protection and Processing of Personal Data Act (Act No. 90/2018) maps to 634 other compliance frameworks. The top mapping partners are EU AI Act (34% coverage), BS 65000:2014 — Guidance on Organizational Resilience (32% coverage), Law 1581 of 2012 - Statutory Framework for the Protection of Personal Data (32% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with Iceland Data Protection and Processing of Personal Data Act (Act No. 90/2018) compliance?
Start your Iceland Data Protection and Processing of Personal Data Act (Act No. 90/2018) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Iceland Data Protection and Processing of Personal Data Act (Act No. 90/2018) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 64 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 718 frameworks.
Get Started Free →Free forever — no credit card required