The Data Protection Authority
Information in English
The Icelandic Data Protection Authority
Rauðarárstígur 10, 105 Reykjavík, Iceland.
General Introduction concerning Act no. 77/2000 on The Protection of Privacy as regards the Processing of Personal Data as well as on the functions of the Data Protection Authority.
The Personal Data Act and other relevant acts and rules:
Rules no. 698/2004 on The Obligation to Notify and Processing which requires a Permit (repealed)
Act no. 77/2000 on The Protection of Privacy as regards the Processing of Personal Data; as amended
Biobanks Act no. 110/2000
Act on the Schengen Information System in Iceland, no. 16/2000.
Directive 95/46/EC of the European Parliament and of the Council of 24 October 1995 on the protection of individuals with regard to the processing of personal data and on the free movement of such data. (EUR-Lex)
Rules no. 837/2006 on Electronic Surveillance.
Translations are un-official and non-verified, unless otherwise stated.
Information on the General Data Protection Reform (GDPR)
The Data Protection Authority has published information on the GDPR under the column "Ný persónuverndarlöggjöf 2018". There you can find brochures for data controllers and individuals as well was presentations the DPA has given on the subject. Useful information and guidelines from third parties can also be found under "Annað áhugavert efni".
Unfortunately some of the information is only available in Icelandic.
Information on the Schengen Information system
General overview on the conduct of audits
Monitoring data controllers and ensuring that they take appropriate security measures, in accordance with law, is an important part of the DPA´s work on law-enforcement. Further information on the subject can be found here.
The audits are conducted within the framework of rules no. 299/2001, on security of personal data, which incorporate, in a very simplified form, the methodology of the International Standard ISO/IEC 17799 "Information Tecnhology - Code of Practice for information security management".
Miscellaneous; answers to inquiries, opinions, rulings e.tc.:
The Data Protection Authority has given the following answers to a questionnaire from the International Bioethics Committee (UNESCO), concerning the Revised Outline of the International Declaration on Human Genetic Data.
The Data Protection Authority´s reply of May 14, to a JSB-Europol questionnaire "Data Protection and the Police".
Excerpt from the JSA-Schengen quide for exercising the right of access (Iceland).
For further information regarding the Schengen Information System, see the website of EU Migration and Home affairs
The Data Protection Authority's answers to a questionnaire on the processing of medical data by pharmaceutical companies, mainly concerning conditions under which clinical trials, safety surveys and post-market studies are allowed.
Information / Documents concerning the Icelandic Health Sector Database:
An excerpt from a judgement by the Supreme Court of Iceland, of November 27, 2003, concerning The Health Sector Database (HSD)
Act on a Health Sector Database no. 139/1998 in Icelandic (repealed in 2014)
Governmental Regulation on the Health Sector Database
General security terms set by the Icelandic Data Protection Commission
The Icelandic Data Protection Authority (DPA) strives to ensure that information supplied on this website and references to laws, regulations and information databases are accurate and right. However the DPA cannot be held responsible for any errors or omissions. Under no circumstances can the DPA be held responsible for any damage resulting from the use of information presented on this site.
Legal disclaimer regarding e-mails from the Data Protection Authority and its staff.