Iceland Data Protection and Processing of Personal Data Act (Act No. 90/2018)
Iceland's Act on Data Protection and the Processing of Personal Data (Act No. 90/2018) implements the EU GDPR into Icelandic law via the EEA Agreement. The Icelandic Data Protection Authority (Persónuvernd) oversees enforcement. The Act includes national provisions for processing of national identification numbers (kennitala), processing for journalistic purposes, research and statistics, the age of digital consent (13 years), and health data processing. Iceland applies the GDPR framework fully as an EEA member state.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (6)
Chapter I — General Provisions
| Code | Title |
|---|---|
| Art. 1 | Open Finance Implementation |
| Art. 2 | Consent Definition |
| Art. 3 | Objectives of Open Finance |
| Art. 4 | Participating Institutions |
| Art. 5 | Legal Recognition of Data Messages |
| Art.1 | Purpose |
| Art.2 | Definitions |
| Art.3 | Cybersecurity Policy |
| Art.4 | Credit Information Business Licensing |
| Art.8 | Prohibited Acts |
| HUN-1 | Purpose and Scope |
| HUN-2 | Definitions |
| HUN-3 | Fundamental Rules |
| URY-1 | Fundamental Right (Article 1) |
| URY-2 | Scope and Definitions (Article 2–4) |
Chapter II — Conditions for Processing
| Code | Title |
|---|---|
| Art. 11 | Consent Revocation |
| Art. 12 | Data Ownership |
| Art. 14 | Direct Data Flows |
| Art. 15 | Cybersecurity Requirements |
| Art. 9 | Free Data Sharing |
Chapter III — Rights of Data Subjects
| Code | Title |
|---|---|
| Art. 14 | Direct Data Flows |
| Art. 16 | Data Quality |
| Art. 17 | Governance Structure |
| Art. 18 | Central Bank Supervision |
| Art. 19 | Consent Management Controls |
| Art. 20 | Executive Accountability |
| Art. 21 | Administrative Sanctions |
| Art. 23 | Transitional Provisions |
| Art. 25 | Criminal Penalties |
| URY-7 | Right of Access (Article 13) |
| URY-8 | Right of Rectification (Article 15) |
| URY-9 | Right of Deletion (Article 15) |
Chapter IV — Obligations of Controllers and Processors
| Code | Title |
|---|---|
| Art. 22 | Suspension and Revocation |
| Art. 24 | Restrictions on Processing Unique Identification Information |
| Art. 25 | Criminal Penalties |
| Art. 26 | Outsourcing of Personal Information Processing |
Chapter V — Transfer of Personal Data
| Code | Title |
|---|---|
| Art. 29 | Safety Measures |
| Art. 30 | Privacy Policy |
| Art. 50 | Right to Compensation |
| Art. 52 | Appropriate Safeguards |
Chapter VI — Data Protection Authority (Persónuvernd)
| Code | Title |
|---|---|
| Art. 35 | Right of Access |
| Art. 38 | Processing in Employment Context |
| Art. 39 | Compensation for Damages |
| Art. 41 | Exemptions from Certain GDPR Provisions |
Maps to 608 other frameworks
Frequently Asked Questions
What is Iceland Data Protection and Processing of Personal Data Act (Act No. 90/2018)?
Iceland Data Protection and Processing of Personal Data Act (Act No. 90/2018) is a compliance framework from Iceland with 6 domains and 44 controls. Iceland's Act on Data Protection and the Processing of Personal Data (Act No. 90/2018) implements the EU GDPR into Icelandic law via the EEA Agreement. The Icelandic Data Protection Authority (Persónuvernd) oversees enforcement. The Act includes national provisions for processing of national identification numbers (kennitala), processing for journalistic purposes, research and statistics, the age of digital consent (13 years), and health data processing. Iceland applies the GDPR framework fully as an EEA member state. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does Iceland Data Protection and Processing of Personal Data Act (Act No. 90/2018) have?
Iceland Data Protection and Processing of Personal Data Act (Act No. 90/2018) has 44 controls organised across 6 domains. The largest domains are Chapter I — General Provisions (15 controls), Chapter III — Rights of Data Subjects (12 controls), Chapter II — Conditions for Processing (5 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does Iceland Data Protection and Processing of Personal Data Act (Act No. 90/2018) map to?
Iceland Data Protection and Processing of Personal Data Act (Act No. 90/2018) maps to 608 other compliance frameworks. The top mapping partners are BS 65000:2014 — Guidance on Organizational Resilience (48% coverage), Albania Law on Protection of Personal Data (Law No. 9887, 2008, amended 2014) (45% coverage), EU Network Code on Cybersecurity for the Electricity Sector (45% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with Iceland Data Protection and Processing of Personal Data Act (Act No. 90/2018) compliance?
Start your Iceland Data Protection and Processing of Personal Data Act (Act No. 90/2018) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Iceland Data Protection and Processing of Personal Data Act (Act No. 90/2018) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 44 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 692 frameworks.
Get Started Free →Free forever — no credit card required