Key Facts
Overview
Iceland implements the GDPR through Act 90/2018 as part of its EEA obligations. While Iceland follows EU data protection standards, its penalty structure differs, capped at 2% of turnover rather than the EU's 4%. Persónuvernd can impose both one-time fines and daily penalty fines for ongoing non-compliance.
What This Means for Your Website
- Informed consent is required before placing non-essential cookies on Icelandic visitors
- Visitors must be informed about cookie usage and provided an option to refuse
- Daily fines of up to ISK 200,000 can accumulate for ongoing non-compliance
- Administrative fines range from ISK 100,000 to ISK 1.2 million, or up to 2% of worldwide turnover
Key Requirements
Persónuvernd enforces Act 90/2018 with both one-time administrative fines and daily penalty fines. The penalty cap of 2% of turnover is lower than the EU's 4%, reflecting Iceland's EEA (rather than EU) membership. Persónuvernd has particularly focused enforcement on protecting children's data.
How ConsentStack Handles This
ConsentStack detects Icelandic visitors and presents a GDPR-compliant opt-in consent banner with clear information and refusal options, meeting Act 90/2018 requirements.
Penalties
Daily fines up to ISK 200,000. Administrative fines ISK 100,000 to ISK 1.2 million, or up to 2% of total worldwide annual turnover.
Key Requirements
- Informed consent before placing non-essential cookies
- Users must be informed about cookie use
- Option to refuse cookies must be provided
- Strictly necessary exemption for essential cookies
- Consent must align with GDPR standards
Notable Provisions
- Lower maximum penalty cap (2% turnover vs EU 4%)
- Daily fines up to ISK 200,000 for ongoing non-compliance
- EEA member but not EU member state
- Persónuvernd focused on protecting children's data
Other ePrivacy Directive Related Regulations
Other Europe Regulations
Frequently Asked Questions
Stay compliant with Icelandic DPA
ConsentStack helps you implement Opt-in consent for Iceland automatically.