Skip to content

Evidence request lists

Iceland Data Protection and Processing of Personal Data Act (Act No. 90/2018)

Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Iceland Act 90/2018 Chap 1 - Scope + EEA + GDPR

ICELAND-Act90-Chap1-Scope-Definitions-EEA-GDPR-Personuvernd
Iceland Act No. 90/2018 - Chapter I Scope + Definitions + EEA Agreement + GDPR Application + Personuvernd Authority

Act No. 90/2018 on Data Protection and the Processing of Personal Data (Log um personuvernd og vinnslu personuupplysinga nr. 90/2018) is the foundational Icelandic data protection law administered by Personuvernd (Icelandic Data Protection Authority). Enacted 27 June 2018; effective 15 July 2018. Implements GDPR (Regulation (EU) 2016/679) into Icelandic law via the EEA Agreement (European Economic Area) - Iceland is EEA Member State + applies EU acquis on data protection but is NOT a full EU Member State. EEA Joint Committee Decision 154/2018 incorporated GDPR into EEA Agreement on 6 July 2018 (with effect 20 July 2018). The Act + GDPR apply directly in Iceland; Iceland-specific provisions augment GDPR rather than replicate it. Chapter I (Articles 1-7) General Provisions: Article 1 Purpose (protect privacy + personal data + fundamental rights and freedoms); Article 2 Scope and Material A

Artefacts an auditor will ask for
  • Act 90/2018 applicability assessment per controller + Iceland-establishment + extraterritorial assessment
  • GDPR + Act 90/2018 + EEA Agreement coordination matrix + Iceland-specific provision register
  • Personuvernd engagement + registration + reporting + EDPB EEA participation
  • Article 4 deceased persons 5-year protection mapping (Iceland-specific)
  • Definitions glossary aligned with GDPR + Iceland-specific (national ID + biometric + genetic)
Where this commonly fails
  • Treating Iceland as EU Member (it is EEA non-EU)
  • Missing 5-year deceased persons protection (Iceland-specific)
  • Personuvernd engagement only after incident (no routine)
  • National identification number treated as ordinary data (heightened expectations)
  • GDPR alone without Iceland Act 90/2018 supplemental

Iceland Act 90/2018 Chap 2 - Principles + Lawful Basis

ICELAND-Act90-Chap2-Principles-LawfulBasis-Consent-Sensitive-Criminal
Iceland Act 90/2018 - Chapter II Principles + Lawful Basis + Consent + Special Categories + Criminal Data (Articles 8-13)

Chapter II (Articles 8-13) Conditions for Processing. Article 8 Principles Relating to Processing - GDPR Article 5 principles transposed: lawfulness + fairness + transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; accountability. Article 9 Lawfulness of Processing - 6 GDPR Article 6 grounds: data subject consent; contract performance; legal obligation; vital interests; public interest task; legitimate interests (controller / third party balanced against data subject rights and freedoms; Iceland-specific guidance from Personuvernd). Article 10 Conditions for Consent - GDPR Article 7 transposition: freely given + specific + informed + unambiguous + withdrawable + demonstrable; Iceland-specific child consent age 13 (lower than GDPR Art 8 default 16, exercising Article 8(1) discretion). Article 11 Special Categories of Personal Da

Artefacts an auditor will ask for
  • Lawful basis register per processing activity + Article 9 ground + Personuvernd legitimate interests guidance
  • Consent management platform + Iceland age 13 child consent + parental consent verification
  • Special category register + Iceland additions (national ID + ethnic + health + biometric)
  • Criminal data register + Article 12 restrictions + authority basis + disclosure controls
  • National ID number processing register per Act 21/1989 separate handling
Where this commonly fails
  • GDPR age 16 child consent applied (Iceland law is 13)
  • National ID number treated as ordinary personal data (Iceland-specific heightened)
  • Criminal data processed under general lawful basis (Article 12 restriction ignored)
  • Consent demonstrability weak (no record of how/when given)
  • Special category data inventory incomplete

Iceland Act 90/2018 Chap 3 - Rights

ICELAND-Act90-Chap3-Transparency-DataSubjectRights-Access-Rectification-Erasure
Iceland Act 90/2018 - Chapter III Transparency + Data Subject Rights (Articles 14-23) - Access + Rectification + Erasure + Portability + Object + Automated Decisions

Chapter III (Articles 14-23) Rights of the Data Subject. Article 17 Information to Data Subjects (direct collection) - GDPR Article 13 transposition: identity + contact of controller + DPO + purposes + lawful basis + recipients + transfers + retention + rights + complaint to Personuvernd + automated decisions. Article 18 Information to Data Subjects (indirect collection) - GDPR Article 14 transposition (collection from third parties). Article 19 Right of Access - GDPR Article 15; 1 month response (3 months max complex); Personuvernd guidance on access procedure. Article 20 Rectification + Erasure + Restriction - GDPR Articles 16 + 17 + 18; right to be forgotten with Iceland-specific exceptions; restriction marking. Article 21 Right to Object + Automated Decisions - GDPR Articles 21 + 22; absolute right to object to direct marketing; profiling and automated decision-making restrictions. A

Artefacts an auditor will ask for
  • Privacy notices per processing point (direct + indirect collection) + Icelandic-language
  • DAR intake + tracking + 1-month SLA + complex extension to 3 months + records
  • Rectification + erasure + restriction decision register + recipient notification (GDPR Article 19)
  • Direct marketing absolute opt-out + automated decisions + profiling impact assessment
  • Article 23 restriction decision register + legal basis + research exemption + Personuvernd liaison
Where this commonly fails
  • Privacy notices only in English (no Icelandic for Iceland-facing)
  • DAR 1-month SLA missed without complex extension
  • Erasure refused without Iceland-specific exception documentation
  • Direct marketing opt-out not absolute (still receiving)
  • Article 23 restriction applied without legal basis documented

Iceland Act 90/2018 Chap 4 - Controller Obligations + DPO

ICELAND-Act90-Chap4-ControllerObligations-PrivacyByDesign-Processor-RoPA-DPO
Iceland Act 90/2018 - Chapter IV Controller Obligations + Privacy by Design + Processor + RoPA + DPO (Articles 24-26 + 35)

Chapter IV (Articles 24-26 + 35) Obligations of Controllers. Article 24 Controller Responsibility + Privacy by Design - GDPR Article 25 transposition: technical + organisational measures + integration of data protection by design + by default into processing activities + lifecycle; default settings respect data minimisation + purpose limitation + retention + accessibility limitation. Article 25 Processor and Sub-Processor Arrangements - GDPR Article 28 transposition: written contract with processor (Article 28(3) mandatory clauses) + sufficient guarantees + audit right + breach notification + return/destruction + sub-processor approval + Iceland-specific contract template; flow-down to sub-processors. Article 26 Records of Processing Activities (RoPA) - GDPR Article 30 transposition: controller maintains records per processing activity including name + contact + DPO + purposes + categori

Artefacts an auditor will ask for
  • Privacy by Design + by Default integration + system lifecycle + design review evidence
  • Processor + sub-processor contracts with Article 28(3) clauses + Iceland-specific template
  • RoPA register + controller + processor + SME exemption assessment
  • DPO designation + mandatory trigger assessment + role description + reporting line
  • Personuvernd DPO registration + contact published + Article 39 task coverage
Where this commonly fails
  • Privacy by Design only at IT layer (not at business process)
  • Processor contracts missing Iceland-specific clauses
  • RoPA only for IT systems (incomplete processing inventory)
  • DPO not appointed despite Article 35 trigger met
  • Personuvernd DPO registration absent or contact not published

Iceland Act 90/2018 Chap 4 - Security + Breach + DPIA

ICELAND-Act90-Chap4-Security-BreachNotification-DPIA-Personuvernd-72hr
Iceland Act 90/2018 - Chapter IV Security of Processing + Breach Notification + DPIA (Articles 27-29)

Chapter IV (Articles 27-29) Security and Risk. Article 27 Security of Processing - GDPR Article 32 transposition: appropriate technical + organisational measures considering state of the art + costs + nature + scope + context + purposes + risk; specific measures: pseudonymisation + encryption + confidentiality + integrity + availability + resilience + ability to restore + regular testing + assessment + evaluation; risk-based approach; Personuvernd 2022 Guidance on Security of Processing + 2024 supplement; coordination with Iceland Cybersecurity Act + national CSIRT (CERT-IS); financial sector + healthcare + critical infrastructure heightened expectations. Article 28 Notification of Breach to Personuvernd + Data Subjects - GDPR Articles 33 + 34 transposition: 72-hour notification to Personuvernd of personal data breach from awareness; without undue delay to data subjects if high risk; Per

Artefacts an auditor will ask for
  • Information security policies + standards + procedures aligned to Personuvernd 2022/2024 Guidance + Iceland Cybersecurity Act
  • Breach notification playbook + 72-hour Personuvernd online form + affected data subject notification template + breach register
  • DPIA methodology + register + Personuvernd List of Processing trigger mapping + completed DPIAs
  • Prior consultation register + Personuvernd 8-week response + advice + ban + conditions
  • Sectoral heightened security (financial + healthcare + critical infrastructure) per Iceland Cybersecurity Act
Where this commonly fails
  • 72-hour breach SLA missed or notification incomplete
  • DPIA absent for Personuvernd-listed high-risk processing
  • Prior consultation skipped despite high residual risk
  • Security baseline generic (not adjusted per Personuvernd guidance)
  • Sectoral heightened security treated as ordinary

Iceland Act 90/2018 Chap 5 - Cross-Border

ICELAND-Act90-Chap5-CrossBorder-EEA-AdequacyDecisions-SCC-BCR
Iceland Act 90/2018 - Chapter V Cross-Border Transfer of Personal Data + EEA + Adequacy + SCCs + BCRs + Article 30 Privacy Policy

Chapter V (Articles 27-30) Transfer of Personal Data Abroad. Articles 27 + 28 + 29 + 30 govern cross-border transfers per GDPR Articles 44-49 transposition. EEA internal transfers: free flow between Iceland + Norway + Liechtenstein + EU 27 Member States (no transfer mechanism needed; equivalent protection). Adequacy decisions: EU Commission adequacy decisions apply via EEA Agreement (UK + Switzerland + Canada + Japan + Israel + New Zealand + Argentina + Uruguay + Faroe Islands + Isle of Man + Jersey + Guernsey + Andorra + South Korea); Iceland may issue own adequacy decisions for territories not covered by EU. Standard Contractual Clauses (SCCs): EU Commission Decision (EU) 2021/914 applies; Personuvernd may issue Iceland-specific SCCs. Binding Corporate Rules (BCRs): approved per Iceland or EU lead authority. Specific situation derogations (Article 49 GDPR): consent + contract performan

Artefacts an auditor will ask for
  • Cross-border transfer register + destination country + transfer mechanism + safeguards
  • EEA internal transfer evidence (Norway + Liechtenstein + EU 27) without transfer mechanism
  • EU + Iceland adequacy decision register + EU Commission + Personuvernd Iceland-specific
  • EU SCC 2021/914 modular clauses + signed agreements + sub-processor flow-down + Iceland adaptations
  • Transfer Impact Assessment per Schrems II + EDPB 01/2020 + Personuvernd 2022 supplement
Where this commonly fails
  • EEA internal transfers treated as third country (over-restriction)
  • Stale adequacy decisions used (post-Schrems II)
  • SCCs without TIA in high-risk destinations
  • BCRs adopted without Personuvernd or lead authority approval
  • Onward transfers from third country not subject to TIA

Iceland Act 90/2018 Chap 6 - Personuvernd + Enforcement

ICELAND-Act90-Chap6-Personuvernd-Enforcement-AdminFines-AAB-Appeals-CriminalPenalties
Iceland Act 90/2018 - Chapter VI Personuvernd Authority + Investigation + Administrative Fines + Penal Code Section 228 + Court Appeals

Chapter VI (Articles 30+) Data Protection Authority + Enforcement. Personuvernd (Icelandic Data Protection Authority) - independent statutory regulator established 2000 + reorganised 2018 under Act 90/2018; statutory powers per GDPR Articles 51-59 + Iceland-specific: investigation (own-motion + complaint) + audit + inspection + Compliance Review + access to data + premises + systems; Information Sharing with other supervisory authorities (EDPB + EEA EFTA Surveillance + ESA + Nordic privacy authorities); Personuvernd Board (5 members appointed by Iceland Minister for 4 years); Commissioner + staff. Article 38 Processing in Employment Context - Iceland-specific employment data: monitoring + email + camera + GPS + biometric + drug testing + Personuvernd 2017 + 2021 + 2024 Guidance + employee notice obligations + works council consultation; Iceland Labour Code + Privacy Act intersection. Art

Artefacts an auditor will ask for
  • Personuvernd cooperation playbook + legal liaison + investigation response + evidence preservation
  • Employment monitoring procedures per Personuvernd 2017/2021/2024 Guidance + works council consultation + notice
  • Article 41 journalistic exemption application + balancing free expression vs privacy
  • Administrative fine risk register + tier 1/2 calculation + insurance + global turnover
  • Penal Code Section 228 criminal risk + corporate liability + officer personal liability + insurance
Where this commonly fails
  • No Personuvernd cooperation playbook or Icelandic counsel
  • Employment monitoring without works council consultation (Iceland labour requirement)
  • Journalistic exemption over-applied to marketing
  • Fine calculation using company turnover not global turnover (under-estimate)
  • Criminal exposure under Section 228 ignored (corporate + individual)

Iceland Act 90/2018 Sectoral

ICELAND-Act90-Sectoral-Employment-Children-DirectMarketing-AutomatedDecisions-Cookies
Iceland Act 90/2018 - Sectoral - Employment + Children + Direct Marketing + Automated Decisions + Cookies + Cybersecurity

Sectoral application of Act 90/2018 with Iceland-specific implementing guidance. Employment (Article 38 + Personuvernd Guidance 2017 + 2021 + 2024) - employee monitoring + email + camera + GPS + biometric + medical + drug testing + DNA testing limited; notice obligations + works council consultation + transparency; Iceland Labour Code + Act on Working Environment intersection. Children: Article 10 sets consent age 13 (lower than GDPR Article 8(1) default 16); Personuvernd Guidance on Children's Data + EdTech operator due diligence + parental consent verification + school context. Direct Marketing: Act on Electronic Commerce No 30/2002 transposing EU Directive on Electronic Commerce + opt-in for new consents + opt-out via easy mechanism + Personuvernd register. Automated Decision-Making + Profiling: Article 21 + GDPR Article 22 transposition; restrictions on legal or similarly significant

Artefacts an auditor will ask for
  • Employee monitoring procedures + Personuvernd 2017/2021/2024 Guidance + works council consultation + notice + drug testing limits
  • Children data consent (age 13 Iceland) + parental verification + EdTech operator due diligence
  • Direct marketing register + opt-in + opt-out + cookie consent + Personuvernd 2023 cookie guidance
  • Automated decision + profiling assessment + Personuvernd Generative AI 2024 + ChatGPT/LLM controls
  • Sectoral health/financial/telecom + Iceland Cybersecurity Act 2024 NIS2 + CERT-IS coordination
Where this commonly fails
  • Employee monitoring without works council consultation
  • GDPR age 16 used for children consent (Iceland is 13)
  • Cookies opt-out default (Iceland requires opt-in for non-essential)
  • Generative AI deployed without Personuvernd 2024 guidance
  • Iceland Cybersecurity Act NIS2 breach reporting parallel to Personuvernd Article 28 missed
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.