Iceland
Non-EU EEA state hooked into Schengen, Prüm and a Europol operational agreement and party to the Council of Europe conventions, a Tier B CNE partner whose every submarine cable crosses a documented cable-tapping nation
Overview
Iceland ranks #1 globally for internet freedom (Freedom House) and has among the strictest internet privacy laws. Full GDPR implementation through the EEA, criminal penalties up to 3 years imprisonment for data protection violations, constitutional privacy under Article 71, and the IMMI (Icelandic Modern Media Initiative) framework designed to create a “journalistic safe haven.”[1]
However, Iceland is not a Five/Nine/Fourteen Eyes member but participates as a Tier B third-party contributor on computer network exploitation with Five Eyes nations. Its submarine cables (DANICE, CANTAT-3, Greenland Connect) transit through Denmark and the UK, both with documented cable-tapping programmes (FE/XKeyscore, GCHQ/Tempora), meaning Icelandic traffic is subject to interception before reaching its destination. In November 2025, Iceland presented its first formal defense and security policy, including deployment of an unmanned surveillance submarine to monitor submarine cables.[2][3]
Iceland’s outward data-sharing runs through its alliances and treaties, each detailed below. Though not an EU member, it is a NATO founding member (1949) and an NSA Tier B CNE partner, a Schengen and Prüm associate, and cooperates with Europol under an operational agreement and across the Nordic-Baltic Eight (Denmark, Estonia, Finland, Iceland, Latvia, Lithuania, Norway, and Sweden);[17] it is a party to the 1959 Council of Europe Mutual Assistance Convention and the Budapest Convention on Cybercrime. Iceland has no bilateral MLAT with the United States, relying instead on the Council of Europe conventions. These are the channels through which the domestic protections described above are, in practice, bypassed.[12][13][14][15][16]
Surveillance and Intelligence
Intelligence: Modest Apparatus
GRLS (National Security Agency, established 2007): Internal intelligence, monitoring threats to constitutional order. A military intelligence service (GVSÍ) also operates. Current legal powers “severely limit” police ability to counter espionage. Iceland is among nations where the NSA has authority to intercept communications of overseas targets through US companies.[7]
Cable Transit Exposure
All of Iceland’s submarine cables transit through countries with documented cable-tapping programmes. DANICE (to Denmark, where FE/XKeyscore operates), CANTAT-3 (to Canada/UK/Denmark/Germany), and Greenland Connect (through Denmark) expose Icelandic traffic to interception at every transit point. The IRIS cable (operational 2023, 145 Tbps, to Ireland) provides a newer route but still transits through UK-controlled waters. Iceland has no independent capability to monitor, regulate, or detect such interception.[3]
Police Surveillance Powers Bill (2024–2025)
The Justice Minister introduced a bill granting police warrantless surveillance authority over individuals suspected of connections to criminal organisations, even if they have not committed a crime. An internal steering group (not a court) would approve each measure. Pirate Party MP criticised the bill for lacking independent oversight: “the police are being given authority to monitor ordinary citizens who have done nothing wrong.”[8]
Data Retention
The Electronic Communications Act requires 6-month retention of browsing history, phone numbers, IP addresses, usernames, connection data, and transfer amounts. Access requires a court order, restricted to police and prosecutors for criminal cases or public safety. Expert committees have drafted bills to remove retention entirely (IMMI-aligned), but these have not been implemented.[9]
International Cooperation
Tier B focused cooperation on computer network exploitation with Five Eyes nations, alongside Austria, Belgium, Germany, Japan, and others. Iceland does not have a formal bilateral MLAT with the United States: mutual legal assistance operates through Council of Europe conventions and EEA frameworks, with no sharing of user data without a valid Icelandic court order.[2]
European Convention on Mutual Assistance in Criminal Matters (1959, ETS 30): This Council of Europe instrument and its Additional Protocols are Iceland’s primary MLA framework in the absence of a US treaty, applying between Iceland and all other parties. As of July 2026 it has 51 parties: all 46 Council of Europe member states (Albania, Andorra, Armenia, Austria, Azerbaijan, Belgium, Bosnia and Herzegovina, Bulgaria, Croatia, Cyprus, Czechia, Denmark, Estonia, Finland, France, Georgia, Germany, Greece, Hungary, Iceland, Ireland, Italy, Latvia, Liechtenstein, Lithuania, Luxembourg, Malta, Moldova, Monaco, Montenegro, the Netherlands, North Macedonia, Norway, Poland, Portugal, Romania, San Marino, Serbia, Slovakia, Slovenia, Spain, Sweden, Switzerland, Türkiye, Ukraine, and the United Kingdom) plus five non-members (Chile, Israel, Mongolia, the Republic of Korea, and the Russian Federation).[12]
Convention on Cybercrime (the Budapest Convention, 2001, ETS 185): Iceland is a party to the Council of Europe’s cybercrime convention, which governs the expedited preservation and cross-border disclosure of stored computer and subscriber data. As of July 2026 it has 82 parties: 45 Council of Europe member states (every one of the 46 except Ireland, which has signed but not ratified), namely Albania, Andorra, Armenia, Austria, Azerbaijan, Belgium, Bosnia and Herzegovina, Bulgaria, Croatia, Cyprus, Czechia, Denmark, Estonia, Finland, France, Georgia, Germany, Greece, Hungary, Iceland, Italy, Latvia, Liechtenstein, Lithuania, Luxembourg, Malta, Moldova, Monaco, Montenegro, the Netherlands, North Macedonia, Norway, Poland, Portugal, Romania, San Marino, Serbia, Slovakia, Slovenia, Spain, Sweden, Switzerland, Türkiye, Ukraine, and the United Kingdom; together with 37 non-member states: Argentina, Australia, Benin, Brazil, Cabo Verde, Cameroon, Canada, Chile, Colombia, Costa Rica, Côte d’Ivoire, the Dominican Republic, Ecuador, Fiji, Ghana, Grenada, Israel, Japan, Kiribati, Mauritius, Morocco, New Zealand, Nigeria, Panama, Papua New Guinea, Paraguay, Peru, the Philippines, Rwanda, São Tomé and Príncipe, Senegal, Sierra Leone, Sri Lanka, Tonga, Tunisia, the United States, and Vanuatu.[13]
Schengen and Prüm (as a non-EU associate): Iceland applies the Schengen acquis and queries SIS II across the Schengen Area (29 states: Austria, Belgium, Bulgaria, Croatia, Czechia, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Iceland, Italy, Latvia, Liechtenstein, Lithuania, Luxembourg, Malta, the Netherlands, Norway, Poland, Portugal, Romania, Slovakia, Slovenia, Spain, Sweden, and Switzerland).[14] It is also one of the four non-EU associates of the Prüm framework (automated DNA, fingerprint, and vehicle-registration exchange), which binds 31 states (all 27 EU members plus Iceland, Liechtenstein, Norway, and Switzerland).[15]
Europol: As a non-EU state, Iceland is not a Europol member but is one of the 17 non-EU states holding an operational agreement permitting personal-data exchange with Europol (Albania, Australia, Bosnia and Herzegovina, Canada, Colombia, Georgia, Iceland, Liechtenstein, Moldova, Monaco, Montenegro, North Macedonia, Norway, Serbia, Switzerland, Ukraine, and the United States), which is constituted by its 27 EU member states and cooperates with US law enforcement including the FBI. Icelandic person data flowing through Europol is therefore reachable onward. Iceland’s treaties are published in the C-deild of the official gazette, Stjórnartíðindi.[16]
Recent Developments
First Defense and Security Policy (November 2025): Iceland’s first formal policy, acknowledging its North Atlantic location as its primary vulnerability. Deploys an unmanned surveillance submarine to monitor submarine cables and ports. NATO Secretary General Rutte welcomed the policy during a November 2025 visit.[10]
Police Warrantless Surveillance Bill: Proposed authority to monitor individuals connected to criminal organisations without a crime being committed and without judicial oversight.[8]
Digital Infrastructure Boom: Data centre market valued at USD 170M (2024), projected USD 375M by 2030, driven by AI workloads and 100% renewable energy. The IRIS cable (145 Tbps to Ireland) enhanced connectivity. New AI data centre with associated submarine cable announced for 2026.[11]
Healthcare Records Fine: Persónuvernd imposed ISK 5M on Primary Health Care of the Capital Area for unlawful integration of ~450,000 medical records with multiple parties including the Transport Authority.[5]
Privacy Framework
Persónuvernd enforces GDPR through the EEA with fines and criminal prosecution (up to 3 years). Notable: fined five municipalities for using Google Cloud/Workspace in schools (Schrems II violations), and ISK 5M fine against Primary Health Care of the Capital Area for unlawful integration of ~450,000 medical records. Disputes fall under the EFTA Court, not CJEU. Act No. 90/2018 implements the GDPR with national derogations for public interest processing, research, and journalism. National security processing is governed under separate classified frameworks exempt from the Act.[4][5]
IMMI (Icelandic Modern Media Initiative)
Passed unanimously by the Althing on June 16, 2010, IMMI inverts the “tax haven” concept by combining the strongest transparency and press freedom laws from various jurisdictions. Key protections include whistleblower protection modelled on the best international standards, source protection, intermediary liability limitations, and prior restraint restrictions. WikiLeaks helped propose the legislation but hosted servers in Sweden, not Iceland. Implementation has been partial: whistleblower protection was enacted in 2020 (Act 40/2020), but source protection and intermediary liability reforms remain pending.[6]
Pending Legislation
- Police warrantless surveillance bill (warrant requirements): proposed authority to monitor individuals connected to criminal organisations without a crime being committed and without judicial oversight, a significant expansion criticised by civil-liberties groups; not yet enacted.[8]
- NIS2 transposition: Iceland intends to implement NIS2 by amending the existing Cyber-Security Act (Act 78/2019), expanding scope from roughly 350 to 3,000–4,000 entities; obligations apply once the EEA Joint Committee incorporates the directive, with compliance phasing toward 2028.
- AI governance: measures under the AI Action Plan 2024–2026 and EEA incorporation of the EU AI Act are pending, with no standalone Icelandic AI statute yet.
