Law / Iceland

Iceland

13 of 16 named instruments researched to a stage, across all six areas of law we track: 13 in force. As of 15 September 2026.

When they take effect12 of 13 carry a date, 1 does not. Earlier is before 2014.
Before 2014: 1 instrument (1 in force) earlier 2014: 0 instruments 2015: 0 instruments ’15 2016: 0 instruments 2017: 0 instruments 2018: 6 instruments (6 in force) 2019: 0 instruments 2020: 2 instruments (2 in force) ’20 2021: 1 instrument (1 in force) 2022: 1 instrument (1 in force) 2023: 0 instruments 2024: 1 instrument (1 in force) 2025: 0 instruments 2026: 0 instruments ’26 today

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

  1. AI law 1
  2. Privacy law 6
  3. Scraping law 2
  4. Cybersecurity law 2
  5. Age gating law 1
  6. News aggregation law 1

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

AI law1 instrument, 1 in force

Research summary (203 words)

Iceland has no AI-transparency, output-labelling, or AI risk-obligation statute of the kind this topic tracks.

Its one enacted AI-relevant criminal provision is Article 210.a of the General Penal Code, which extends the child sexual abuse material ban to image material showing a person 18 years of age or older acting sexually while playing the role of a child, or to a depiction of a child in such material even though it is not real, such as a cartoon or other simulated image, reaching AI-generated and other synthetic depictions on the same terms as a hand-drawn one.

The government's AI Action Plan, published 2 July 2025 by the Ministry of Culture, Innovation and Higher Education, is a non-binding strategy of 25 measures for 2025-2027 covering public-sector AI use, competitiveness, and education; it creates no enforceable duty on a private or public actor and is not recorded as an instrument here.

As an EEA state rather than an EU member, Iceland applies an EU regulation such as the AI Act (Regulation (EU) 2024/1689) only once it is incorporated into the EEA Agreement by an EEA Joint Committee decision and, where required, Iceland's own constitutional procedure is completed; no source located establishes that incorporation has occurred.

AI prohibited practices

Almenn hegningarlög nr. 19/1940, Art. 210.a, Simulated and Non-Real Child Sexual Abuse Material

Almenn hegningarlög nr. 19/1940 (General Penal Code), 210. gr. a, 5. mgr., eins og henni var breytt með lögum nr. 29/2022Althingi official consolidated-law database

In force since 9 June 2022. Binds public and private bodies.

What this law does

Article 210.a punishes whoever produces, imports, acquires for himself or others, distributes, or possesses image material showing the sexual abuse of a child, or showing a child in a sexual manner, with fines or imprisonment of up to six years, and imposes the same penalty on whoever views such material online or through other information or telecommunications technology.

A separate paragraph, added by Act No. 29/2022, punishes whoever produces, imports, acquires, distributes, or possesses image material showing persons 18 years of age or older acting sexually while playing the role of a child, or a depiction of a child in such material even though it is not real, such as in a cartoon or another simulated image, with fines or imprisonment of up to two years; this paragraph binds a synthetic or AI-generated depiction on the same terms as a hand-drawn one, since it turns on the image showing what is not real rather than on how the image was produced.

The article separately exempts consensual, close-in-age sexting among 15-to-17-year-olds and a 15-to-17-year-old's own self-distributed material from both the abuse and viewing offenses.

What it requires

Privacy law6 instruments, 6 in force

Research summary (124 words)

Iceland is not an EU member; the General Data Protection Regulation (GDPR) reaches it through EEA Joint Committee Decision No. 154/2018, given domestic effect by Act No. 90/2018 on Data Protection and the Processing of Personal Data, which is the controlling instrument recorded here rather than the EU Regulation directly.

Drawn from the Act's own consolidated text, Article 3(14) defines biometric data with an illustrative, non-exhaustive example list naming facial images and fingerprint data but not voiceprints, Article 9 prohibits processing biometric data for unique identification absent an explicit-consent-style exception, and Article 16 requires its own EEA Joint Committee decision plus ministerial confirmation before a European Commission adequacy decision takes effect in Iceland. As at 24 August 2026; later amendment to Act No. 90/2018 is not independently confirmed.

Breach notification

Act No. 90/2018, Breach Notification in Iceland

Log nr. 90/2018 (breach notification provisions)DLA Piper and Recording Law secondary trackers, corroborating the Act's GDPR-mirroring breach-notification structure

In force since 15 July 2018. Binds public and private bodies.

What this law does

Act No. 90/2018 carries the General Data Protection Regulation (GDPR) breach-notification duties into Icelandic law: a controller must notify Personuvernd without undue delay, and where feasible within 72 hours of becoming aware of a personal data breach, unless the breach is unlikely to result in a risk to natural persons' rights and freedoms, and must notify affected individuals without undue delay where the breach is likely to result in a high risk.

No Icelandic-specific timeline departure was found; this dimension rests on secondary commentary corroborating the Act's GDPR-mirroring structure rather than the breach-notification section's own text.

What it requires

Comprehensive regime

Act No. 90/2018 on Data Protection and the Processing of Personal Data

Log nr. 90/2018 um personuvernd og vinnslu personuupplysinga (Act No. 90/2018), passed by Althingi 27 June 2018, in force 15 July 2018Althingi official consolidated-law database

In force since 15 July 2018. Binds public and private bodies.

What this law does

Iceland is not an EU member, so the General Data Protection Regulation (GDPR) does not apply directly. GDPR reaches Iceland through EEA Joint Committee Decision No. 154/2018, incorporating it into the EEA Agreement, and Act No. 90/2018 gives that incorporation domestic legal force. The Act's own Article 2 names Decision No. 154/2018 as the incorporation mechanism, and the Act reproduces the GDPR text itself as an appendix. Persoonuvernd (the Icelandic Data Protection Authority) is the supervisory authority.

Privacy law is a settled, fully in-force regime in Iceland since 2018, distinct from Iceland's AI-law posture, where the EU AI Act's own EEA incorporation was still pending as of August 2026.

What it requires

Cross border transfer

Act No. 90/2018 Article 16, Cross-Border Transfer of Personal Data from Iceland

Log nr. 90/2018, Art. 16Althingi official consolidated-law database, Article 16

In force since 15 July 2018. Binds public and private bodies.

What this law does

Article 16 of Act No. 90/2018 provides that a European Commission adequacy decision under General Data Protection Regulation (GDPR) Article 45 applies in Iceland only in accordance with the EEA Joint Committee's own decision, and requires the Minister to confirm such decisions and publish notice in the Law Gazette before they take domestic effect. This is a genuinely distinctive two-step mechanism: an adequacy decision does not apply automatically the moment the Commission adopts it.

Otherwise, a transfer outside the EEA requires appropriate safeguards such as Standard Contractual Clauses or Binding Corporate Rules, or a narrow Article 49-equivalent derogation; transfers within the EEA, including to Norway and Liechtenstein, move freely.

What it requires

Data subject rights

Act No. 90/2018, Data Subject Rights in Iceland

Log nr. 90/2018 (data subject rights provisions)Althingi official consolidated-law database

In force since 15 July 2018. Binds public and private bodies.

What this law does

Act No. 90/2018 carries the General Data Protection Regulation (GDPR) data subject rights, access, rectification, erasure, restriction, portability, and objection, into Icelandic law, including the qualified Article 22-equivalent right against a decision based solely on automated processing. Rights are exercisable against the controller, with Personuvernd as the escalation path for a complaint. No Icelandic-specific timeline departure from GDPR's one-month response window was found.

What it requires

Enforcement supervision

Act No. 90/2018, Persoonuvernd Enforcement in Iceland

Log nr. 90/2018 (enforcement provisions)DLA Piper and Recording Law secondary trackers for the ISK fine figures

In force since 15 July 2018. Binds public and private bodies.

What this law does

Persoonuvernd holds investigative and corrective powers and administrative-fine authority. Because General Data Protection Regulation (GDPR) reaches Iceland through national legislation rather than direct EU regulation applicability, Act No. 90/2018 sets Iceland's fine ceiling in Icelandic krona rather than by direct reference to the EUR-denominated GDPR figures.

Article 46 of the Act itself confirms a lower tier of ISK 100,000 to 1.2 billion or 2 percent of worldwide annual turnover and a higher tier of ISK 100,000 to 2.4 billion or 4 percent, mirroring the GDPR Article 83(4)/(5) structure, alongside daily compulsion fines under Article 45 and a criminal-penalty track for deliberate breaches. Individuals may seek compensation for material or non-material damage, mirroring GDPR Article 82.

What it requires

Sensitive categories

Act No. 90/2018 Articles 3(14) and 9, Special Categories in Iceland

Log nr. 90/2018, Art. 3(14), Art. 9Althingi official consolidated-law database, Articles 3(14) and 9

In force since 15 July 2018. Binds public and private bodies.

What this law does

Act No. 90/2018 Article 3, item 14 defines biometric data as personal data obtained through specific technical processing relating to a person's physical, physiological or behavioural characteristics that allow or confirm unique identification, and gives facial images and fingerprint data as illustrative examples using a non-exhaustive such as construction. It does not name voiceprints or voice data anywhere in this definition.

Article 9 prohibits processing biometric data for the purpose of uniquely identifying a natural person absent an Article 9(2)-style exception such as explicit consent, mirroring General Data Protection Regulation (GDPR) Article 9 with no Iceland-specific narrowing or widening found.

What it requires

Scraping law2 instruments, 2 in force

Research summary (201 words)

Iceland has no scraping-specific statute, so general law governs each dimension separately. The General Penal Code's Article 229 criminalises obtaining access to another's computer-stored data or programs without authorization, with no carve-out for a public, unauthenticated page, so a scraper who defeats no technical control falls outside a plain reading of the provision.

No Icelandic court decision on the enforceability of a browsewrap or clickwrap terms-of-service against a scraper, and no Icelandic-specific unfair-competition, misappropriation, or trespass doctrine addressing scraping, or statute assigning legal weight to a robots.txt directive or an AI-training-specific rule, were located in the sources reviewed.

The Copyright Act confers a sui generis database-producer right on the maker of a database representing a substantial investment, barring repeated and systematic extraction or re-utilisation of an insubstantial part that conflicts with normal exploitation, for 15 years from creation or publication; the Act contains no text-and-data-mining exception, since the EU Digital Single Market Copyright Directive that would add one has not yet been incorporated into the EEA Agreement in a form binding Iceland.

Personal data scraped from an Icelandic public website remains subject to Act No. 90/2018's General Data Protection Regulation (GDPR)-equivalent duties without a general publicly-available-data exemption, as already established in this jurisdiction's privacy-topic research.

Computer misuse

Almenn hegningarlög nr. 19/1940, Art. 229, Unauthorized Access to Computer-Stored Data

Almenn hegningarlög nr. 19/1940 (General Penal Code), 229. gr., eins og henni var breytt með lögum nr. 8/2021Althingi official consolidated-law database

In force since 22 February 2021. Binds public and private bodies.

What this law does

Article 229 punishes whoever without authorization obtains access to data or programs of others stored in computer-readable form, with fines or imprisonment of up to one year, unless the conduct is justified by reference to public or private interests.

The provision is not limited to defeating a technical access control, but it does not by its own terms reach merely reading a page that carries no such control; no reported Icelandic decision has applied it to open-web scraping of a public, unauthenticated page.

This text replaced an earlier version of Article 229 by Act No. 8/2021, which took effect on the date of the Act's own publication; an earlier English translation of the Code (via a secondary legislation-tracking site) attributed similarly worded unauthorized-access language to Article 228, which the same 2021 amendment rewrote into a separate privacy-intrusion offense, so a citation to "Article 228" for this duty predates the current numbering.

What it requires

Database right

Höfundalög nr. 73/1972, Art. 50, Sui Generis Database Producer Right

Höfundalög nr. 73/1972 (Copyright Act), 50. gr., eins og henni var breytt með lögum nr. 60/2000Althingi official consolidated-law database

In force since 19 May 2000. Binds public and private bodies.

What this law does

Article 50 gives the maker of a catalogue, table, form, database, or similar work containing a substantial collection of information, or that is the result of a substantial investment, the exclusive right to reproduce or publish the work in whole or in a substantial part.

Repeated and systematic extraction or re-utilisation of an insubstantial part of the database is prohibited where it conflicts with the database's normal exploitation or unreasonably prejudices the producer's legitimate interests. The right lasts 15 years from the turn of the year following the database's creation, or, if published within that period, 15 years from the turn of the year following publication.

A person entitled to use a database has a separate statutory right to the actions necessary to access and make normal use of its content, and the right runs alongside, rather than displacing, any copyright the database's contents separately carry.

This article implements the EU Database Directive (96/9/EC); the Act carries no text-and-data-mining exception, since the later Digital Single Market Copyright Directive (2019/790), which would add one, has not been incorporated into the EEA Agreement in a form binding Iceland.

What it requires

Cybersecurity law2 instruments, 2 in force

Research summary (517 words)

Iceland's product-security and cyber-resilience law rests on Act No. 78/2019 on the Security of the Network and Information Systems of Critical Infrastructure, Iceland's transposition of the EU's original NIS Directive (2016/1148), in force since 1 September 2020.

The Act binds an operator of essential services in banking and financial-market infrastructure, transport, health services, and energy, heating and water utilities, and, separately, an operator of essential services in the digital-infrastructure sector (an internet exchange point, a domain-name-system service provider, or a top-level domain registry) and a provider of digital services operating an online marketplace, an online search engine, or a cloud computing service, excluding a provider that qualifies as a micro-enterprise.

Article 7 sets a documented risk-management and preparedness duty and Article 8 a duty to notify Iceland's national cybersecurity incident-response team of a serious incident or risk as soon as may be, carrying no fixed hour-based reporting clock of its own; a breach of either duty draws an administrative fine of up to ISK 10,000,000, capped at 3 percent of turnover for a legal entity, a separate daily coercive fine of up to ISK 500,000 for ignoring a supervisory order, and an intentional breach is separately punishable by up to two years' imprisonment.

Fjarskiptastofa, the Post and Telecom Administration, supervises the digital-infrastructure sector and every digital-service provider; the other essential-service sectors each answer to their own regulator (the Financial Supervisory Authority for banking and financial-market infrastructure, the Transport Authority for transport, the Directorate of Health for health services, and the Environment and Energy Agency for energy, heating and water utilities), a population no declared LexLint activity expresses, so it is described here without a coded row.

Iceland's national cybersecurity incident-response team moved from Fjarskiptastofa to the Ministry for Foreign Affairs under Act No. 51/2025, in force 22 July 2025, which also separated the response team from the supervisory authority by law.

The EU's NIS2 Directive (2022/2555), which would replace this Act's scope and reporting clock with a broader sector list and a tiered 24-hour, 72-hour and one-month clock, had not been incorporated into the EEA Agreement or transposed into Icelandic law as of 15 September 2026: the government's own EEA-incorporation database records the directive as still under review by Iceland, Liechtenstein and Norway, with domestic implementation work not begun and Althingi's own assessment not yet complete.

The Cyber Resilience Act (Regulation (EU) 2024/2847) sits at the same pre-incorporation status in the same database, so no EU-level requirement for a manufacturer placing a product with digital elements on the market yet binds in Iceland.

Regulation (EU) 2022/2554 (DORA) is the one EU cyber-resilience instrument already incorporated and implemented, through Act No. 78/2025, in force 1 January 2026, which routes banking and financial-market-infrastructure incident notification to DORA instead of Article 8 of this Act; DORA's financial-entity duty-bearer is a role no declared LexLint activity expresses, so it is recorded here rather than coded as an instrument.

No general reasonable-security or information-security-programme statute outside this Act and outside the Data Protection Act's own security-of-processing clause (Act No. 90/2018, documented as this jurisdiction's privacy-topic instrument rather than repeated here) was found.

Sector security regimes

Minimum Risk-Management and Preparedness Requirements for Critical Infrastructure

Log nr. 78/2019, Art. 7Official consolidated text, Althingi Lagasafn (Icelandic Law Database)

In force since 1 September 2020. Binds public and private bodies.

What this law does

Article 7 requires an operator of essential services or a provider of digital services within the Act's scope to maintain a documented policy and processes to assess, manage and minimise the risk to the security of its network and information systems, including risk from rare events with serious consequences, to set a security policy, perform regular risk assessments, and determine and re-assess security measures, both technical and organisational, on that basis, with access control and regular testing against current international best-practice benchmarks.

It also requires a documented incident-response plan and a business-continuity plan to limit damage from a serious operational disruption, covering incident logging, root-cause analysis, restoration of normal operation, and prevention of recurrence, backed by an active internal-control system. The duty binds an operator of essential services in the digital-infrastructure sector, defined as an internet exchange point, a domain-name-system service provider, or a top-level domain registry.

It also binds a provider of digital services operating an online marketplace, an online search engine, or a cloud computing service, other than a provider that qualifies as a micro-enterprise under the Act on Annual Accounts. The Act's other essential-service sectors, banking and financial-market infrastructure, transport, health services, and energy, heating and water utilities, carry the same duty but are gated by sector and criticality criteria this vocabulary does not express.

What it requires

Vulnerability and incident reporting

Notification of Serious Incidents and Risk to the National Cybersecurity Incident-Response Team

Log nr. 78/2019, Art. 8Official consolidated text, Althingi Lagasafn (Icelandic Law Database)

In force since 1 September 2020. Binds public and private bodies.

What this law does

Article 8 requires an operator of essential services or a provider of digital services within the Act's scope to notify Iceland's national cybersecurity incident-response team of a serious incident or risk threatening the security of its network and information systems as soon as may be, with severity assessed by the number of users affected, the duration of the incident, its geographic spread and scale, and its possible effect on other critical infrastructure or on economic and social activity or digital services; the notification must also disclose any outsourcing arrangement the operator relies on and any possible cross-border contagion effect.

The duty carries no fixed reporting-clock deadline of its own, unlike the tiered 24-hour, 72-hour and one-month clock of the EU's NIS2 Directive. An operator in banking and financial-market infrastructure instead notifies under Regulation (EU) 2022/2554 (DORA) and Iceland's implementing act. The duty binds the same digital-infrastructure and digital-service-provider population as Article 7, and the same broader, sector-gated essential-service categories that this vocabulary cannot express.

What it requires

Age gating law1 instrument, 1 in force

Research summary (128 words)

Iceland has no adult-content age-verification statute distinct from its general media-content regime, no social-media-specific minor-access restriction, and no app-store age-verification duty.

The closest instrument is the Media Act (Lög um fjölmiðla nr. 38/2011), whose Article 28 bars a media service provider from distributing content, including pornography or gratuitous violence, that could harm a child's physical, mental, or moral development, subject to watershed-hour and technical-measure exceptions for linear broadcasting.

Since Act No. 27/2024 transposed the revised EU Audiovisual Media Services Directive as incorporated into the EEA Agreement, a video-sharing platform provider (mynddeiliveita) must additionally establish and operate an age-verification system for content that could harm a child's development, alongside flagging, parental-control, and media-literacy measures. The Media Commission (Fjölmiðlanefnd) enforces both duties with administrative fines of up to ISK 10,000,000.

Adult content age verification (AV)

Lög um fjölmiðla nr. 38/2011, Protection of Minors and Video-Sharing Platform Age Verification

Lög um fjölmiðla nr. 38/2011 (Media Act), 28. gr. og V. kafli A (36. gr. a-d), eins og þeim var breytt með lögum nr. 27/2024Althingi official consolidated-law database

In force since 23 March 2024. Binds private bodies.

What this law does

Article 28 bars a media service provider that distributes audio or video content from distributing content, including commercial audio or video communications, that could have a harmful effect on a child's physical, mental, or moral development, in particular pornography or gratuitous violence, subject to watershed-hour, technical-restriction, and news-content exceptions for linear programming.

Since Act No. 27/2024 transposed the revised Audiovisual Media Services Directive as incorporated into the EEA Agreement by EEA Joint Committee Decision No. 337/2022 of 9 December 2022, a video-sharing platform provider established in Iceland or directing content to the Icelandic public must, under the new Article 36.a, take appropriate measures to protect children from content, user-generated content, and commercial communications that could harm their physical, mental, or moral development, and, under Article 36.d, must among other things establish and operate an age-verification system for users with regard to content that could harm a child's physical, mental, or moral development, alongside a flagging system, a user-controlled parental-control system, and media-literacy measures.

The Media Commission enforces both duties with administrative fines of up to ISK 10,000,000, and may not process a child's personal data collected under the parental-control or age-verification measures for commercial purposes such as direct marketing or profiling.

Note and primary source

News aggregation law1 instrument, 1 in force

Research summary (196 words)

Iceland has no press-publisher neighbouring right and no compelled platform-to-publisher bargaining regime; the general quotation exception in the Copyright Act is the only provision reaching an aggregator's reproduction of another's text.

Article 14 permits quoting a published literary, film, or musical work for criticism, science, general presentation, or another recognised purpose, within reasonable limits and with the material correctly represented; it carries no headline-length or short-extract cap distinct from this fair-practice test and is not restricted to press content.

The EU's Digital Single Market Copyright Directive (2019/790), which creates the press-publisher neighbouring right at Article 15 and a text-and-data-mining opt-out exception at Articles 3-4, was adopted for EEA incorporation by an EEA Joint Committee decision of 8 December 2023, but its entry into force in Iceland remained conditional on Iceland, Liechtenstein, and Norway completing their own constitutional steps as of the most recent tracking available, and the Copyright Act's own text contains neither a press-publisher right nor a text-and-data-mining opt-out exception.

No hot-news or misappropriation doctrine distinct from ordinary copyright law, and no statute or reported case addressing whether a hyperlink or framed display is a communication to the public, were located in the sources reviewed.

Snippet reproduction

Höfundalög nr. 73/1972, Art. 14, Quotation Exception

Höfundalög nr. 73/1972 (Copyright Act), 14. gr.Althingi official consolidated-law database

In force. Binds private bodies.

What this law does

Article 14 permits, without the copyright owner's consent, a quotation from a published literary work, including a stage work, and a published film work or musical work, where the quotation is made in connection with criticism, science, general presentation, or another recognised purpose, provided it is made within reasonable limits and the material quoted is correctly represented.

The same conditions permit publishing images and drawings of published works of art. The provision carries no headline-length or short-extract cap distinct from this fair-practice test, is not restricted to press or news content, and no reported Icelandic decision applies it to a systematic news aggregator rather than an individual quoting a published work.

The Act's own consolidated text carries no separate press-publisher neighbouring right and no text-and-data-mining opt-out exception of the kind the EU's Digital Single Market Copyright Directive would add once incorporated into the EEA Agreement. The provision's own commencement date is not stated in the consolidated text or in the sources checked, and it carries no amendment footnote in the current text, indicating it is original to the 1972 Act.

Note and primary source

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.