Act No. 90/2018, Persoonuvernd Enforcement in Iceland
Log nr. 90/2018 (enforcement provisions)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 15 July 2018.
An enforcement supervision rule binding public and private bodies.
As of 2 September 2026.
What it requires
- Expect Persoonuvernd to have jurisdiction and fining power, denominated in Icelandic krona at a level converging with the General Data Protection Regulation (GDPR) Article 83 tiers, over your processing of personal data of a person in Iceland.
- Expect any person who suffered material or non-material damage from an infringement to have a right to compensation from you as controller or processor, under Act No. 90/2018.
If you get it wrong
Criminal exposureYes
Private right of actionYes
Criminal exposure note
Article 48 punishes an aggravated individual offense, committed intentionally and for profit in a particularly reprehensible manner, resulting in the personal data of a large number of registered individuals that must by law or by its nature be kept confidential reaching a third party or being made public, with imprisonment of up to three years. A representative or employee of a legal entity who commits this offense in the course of the entity's activities may be punished alongside the administrative fine imposed on the entity under Article 46. A separate individual breach of the confidentiality duties in Articles 36 and 44 is punishable by fines or imprisonment of up to one year, rising to imprisonment of up to three years where committed to obtain an unlawful gain for the offender or another person.
Penalty structure
Article 46 sets two administrative-fine tiers, each with a floor of ISK 100,000. This entry records the higher tier: ISK 100,000 to 2.4 billion, or up to 4 percent of worldwide annual turnover in the preceding financial year, whichever is higher, for infringement of the Regulation's basic processing principles and consent conditions (Articles 5, 6, 7 and 9), the data subject rights (Articles 12 to 22), the cross-border transfer conditions (Articles 44 to 49), and two Act-specific triggers: refusing Personuvernd access to data and premises under Article 41, and disregarding a Personuvernd order restricting or banning processing, correcting or erasing data, or halting a data flow under Article 42. A lower tier, ISK 100,000 to 1.2 billion, or up to 2 percent of worldwide annual turnover, whichever is higher, covers the controller and processor obligations in Articles 8, 25 to 39, 42 and 43 of the Regulation, the certification-body obligations in Articles 42 and 43, and the monitoring-body obligations in Article 41(4). Where a controller or processor infringes more than one provision in the same or related processing operations, Article 46 caps the total fine at the amount set for the most serious infringement, and the fining power lapses five years after the conduct ended.
- Rule
- Higher of
- As of
- 2 September 2026
- Minimum
- 100,000
- Currency
- ISK
- Fixed cap
- 2,400,000,000
- Turnover percentage cap
- 4
Who enforces it
Enforcement body
Personuvernd, Iceland's independent data protection authority, designated the supervisory authority under Act No. 90/2018 Article 39 and empowered to impose administrative fines under Article 46.
What it reaches
Obligation class
Governance
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Persoonuvernd holds investigative and corrective powers and administrative-fine authority. Because General Data Protection Regulation (GDPR) reaches Iceland through national legislation rather than direct EU regulation applicability, Act No. 90/2018 sets Iceland's fine ceiling in Icelandic krona rather than by direct reference to the EUR-denominated GDPR figures.
Article 46 of the Act itself confirms a lower tier of ISK 100,000 to 1.2 billion or 2 percent of worldwide annual turnover and a higher tier of ISK 100,000 to 2.4 billion or 4 percent, mirroring the GDPR Article 83(4)/(5) structure, alongside daily compulsion fines under Article 45 and a criminal-penalty track for deliberate breaches. Individuals may seek compensation for material or non-material damage, mirroring GDPR Article 82.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbothigh_risk_decisionsprocesses_biometricsprocesses_voice
Read the law
DLA Piper and Recording Law secondary trackers for the ISK fine figures
not independently confirmed against the Act's own fine-setting section
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.