Iceland

Non-EU EEA state hooked into Schengen, Prüm and a Europol operational agreement and party to the Council of Europe conventions, a Tier B CNE partner whose every submarine cable crosses a documented cable-tapping nation

← Back to Privacy Law Directory

Overview

Iceland ranks #1 globally for internet freedom (Freedom House) and has among the strictest internet privacy laws. Full GDPR implementation through the EEA, criminal penalties up to 3 years imprisonment for data protection violations, constitutional privacy under Article 71, and the IMMI (Icelandic Modern Media Initiative) framework designed to create a “journalistic safe haven.”[1]

However, Iceland is not a Five/Nine/Fourteen Eyes member but participates as a Tier B third-party contributor on computer network exploitation with Five Eyes nations. Its submarine cables (DANICE, CANTAT-3, Greenland Connect) transit through Denmark and the UK, both with documented cable-tapping programmes (FE/XKeyscore, GCHQ/Tempora), meaning Icelandic traffic is subject to interception before reaching its destination. In November 2025, Iceland presented its first formal defense and security policy, including deployment of an unmanned surveillance submarine to monitor submarine cables.[2][3]

Iceland’s outward data-sharing runs through its alliances and treaties, each detailed below. Though not an EU member, it is a NATO founding member (1949) and an NSA Tier B CNE partner, a Schengen and Prüm associate, and cooperates with Europol under an operational agreement and across the Nordic-Baltic Eight (Denmark, Estonia, Finland, Iceland, Latvia, Lithuania, Norway, and Sweden);[17] it is a party to the 1959 Council of Europe Mutual Assistance Convention and the Budapest Convention on Cybercrime. Iceland has no bilateral MLAT with the United States, relying instead on the Council of Europe conventions. These are the channels through which the domestic protections described above are, in practice, bypassed.[12][13][14][15][16]

Surveillance and Intelligence

Intelligence: Modest Apparatus

GRLS (National Security Agency, established 2007): Internal intelligence, monitoring threats to constitutional order. A military intelligence service (GVSÍ) also operates. Current legal powers “severely limit” police ability to counter espionage. Iceland is among nations where the NSA has authority to intercept communications of overseas targets through US companies.[7]

Cable Transit Exposure

All of Iceland’s submarine cables transit through countries with documented cable-tapping programmes. DANICE (to Denmark, where FE/XKeyscore operates), CANTAT-3 (to Canada/UK/Denmark/Germany), and Greenland Connect (through Denmark) expose Icelandic traffic to interception at every transit point. The IRIS cable (operational 2023, 145 Tbps, to Ireland) provides a newer route but still transits through UK-controlled waters. Iceland has no independent capability to monitor, regulate, or detect such interception.[3]

Police Surveillance Powers Bill (2024–2025)

The Justice Minister introduced a bill granting police warrantless surveillance authority over individuals suspected of connections to criminal organisations, even if they have not committed a crime. An internal steering group (not a court) would approve each measure. Pirate Party MP criticised the bill for lacking independent oversight: “the police are being given authority to monitor ordinary citizens who have done nothing wrong.”[8]

Data Retention

The Electronic Communications Act requires 6-month retention of browsing history, phone numbers, IP addresses, usernames, connection data, and transfer amounts. Access requires a court order, restricted to police and prosecutors for criminal cases or public safety. Expert committees have drafted bills to remove retention entirely (IMMI-aligned), but these have not been implemented.[9]

International Cooperation

Tier B focused cooperation on computer network exploitation with Five Eyes nations, alongside Austria, Belgium, Germany, Japan, and others. Iceland does not have a formal bilateral MLAT with the United States: mutual legal assistance operates through Council of Europe conventions and EEA frameworks, with no sharing of user data without a valid Icelandic court order.[2]

European Convention on Mutual Assistance in Criminal Matters (1959, ETS 30): This Council of Europe instrument and its Additional Protocols are Iceland’s primary MLA framework in the absence of a US treaty, applying between Iceland and all other parties. As of July 2026 it has 51 parties: all 46 Council of Europe member states (Albania, Andorra, Armenia, Austria, Azerbaijan, Belgium, Bosnia and Herzegovina, Bulgaria, Croatia, Cyprus, Czechia, Denmark, Estonia, Finland, France, Georgia, Germany, Greece, Hungary, Iceland, Ireland, Italy, Latvia, Liechtenstein, Lithuania, Luxembourg, Malta, Moldova, Monaco, Montenegro, the Netherlands, North Macedonia, Norway, Poland, Portugal, Romania, San Marino, Serbia, Slovakia, Slovenia, Spain, Sweden, Switzerland, Türkiye, Ukraine, and the United Kingdom) plus five non-members (Chile, Israel, Mongolia, the Republic of Korea, and the Russian Federation).[12]

Convention on Cybercrime (the Budapest Convention, 2001, ETS 185): Iceland is a party to the Council of Europe’s cybercrime convention, which governs the expedited preservation and cross-border disclosure of stored computer and subscriber data. As of July 2026 it has 82 parties: 45 Council of Europe member states (every one of the 46 except Ireland, which has signed but not ratified), namely Albania, Andorra, Armenia, Austria, Azerbaijan, Belgium, Bosnia and Herzegovina, Bulgaria, Croatia, Cyprus, Czechia, Denmark, Estonia, Finland, France, Georgia, Germany, Greece, Hungary, Iceland, Italy, Latvia, Liechtenstein, Lithuania, Luxembourg, Malta, Moldova, Monaco, Montenegro, the Netherlands, North Macedonia, Norway, Poland, Portugal, Romania, San Marino, Serbia, Slovakia, Slovenia, Spain, Sweden, Switzerland, Türkiye, Ukraine, and the United Kingdom; together with 37 non-member states: Argentina, Australia, Benin, Brazil, Cabo Verde, Cameroon, Canada, Chile, Colombia, Costa Rica, Côte d’Ivoire, the Dominican Republic, Ecuador, Fiji, Ghana, Grenada, Israel, Japan, Kiribati, Mauritius, Morocco, New Zealand, Nigeria, Panama, Papua New Guinea, Paraguay, Peru, the Philippines, Rwanda, São Tomé and Príncipe, Senegal, Sierra Leone, Sri Lanka, Tonga, Tunisia, the United States, and Vanuatu.[13]

Schengen and Prüm (as a non-EU associate): Iceland applies the Schengen acquis and queries SIS II across the Schengen Area (29 states: Austria, Belgium, Bulgaria, Croatia, Czechia, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Iceland, Italy, Latvia, Liechtenstein, Lithuania, Luxembourg, Malta, the Netherlands, Norway, Poland, Portugal, Romania, Slovakia, Slovenia, Spain, Sweden, and Switzerland).[14] It is also one of the four non-EU associates of the Prüm framework (automated DNA, fingerprint, and vehicle-registration exchange), which binds 31 states (all 27 EU members plus Iceland, Liechtenstein, Norway, and Switzerland).[15]

Europol: As a non-EU state, Iceland is not a Europol member but is one of the 17 non-EU states holding an operational agreement permitting personal-data exchange with Europol (Albania, Australia, Bosnia and Herzegovina, Canada, Colombia, Georgia, Iceland, Liechtenstein, Moldova, Monaco, Montenegro, North Macedonia, Norway, Serbia, Switzerland, Ukraine, and the United States), which is constituted by its 27 EU member states and cooperates with US law enforcement including the FBI. Icelandic person data flowing through Europol is therefore reachable onward. Iceland’s treaties are published in the C-deild of the official gazette, Stjórnartíðindi.[16]

Recent Developments

First Defense and Security Policy (November 2025): Iceland’s first formal policy, acknowledging its North Atlantic location as its primary vulnerability. Deploys an unmanned surveillance submarine to monitor submarine cables and ports. NATO Secretary General Rutte welcomed the policy during a November 2025 visit.[10]

Police Warrantless Surveillance Bill: Proposed authority to monitor individuals connected to criminal organisations without a crime being committed and without judicial oversight.[8]

Digital Infrastructure Boom: Data centre market valued at USD 170M (2024), projected USD 375M by 2030, driven by AI workloads and 100% renewable energy. The IRIS cable (145 Tbps to Ireland) enhanced connectivity. New AI data centre with associated submarine cable announced for 2026.[11]

Healthcare Records Fine: Persónuvernd imposed ISK 5M on Primary Health Care of the Capital Area for unlawful integration of ~450,000 medical records with multiple parties including the Transport Authority.[5]

Privacy Framework

Persónuvernd enforces GDPR through the EEA with fines and criminal prosecution (up to 3 years). Notable: fined five municipalities for using Google Cloud/Workspace in schools (Schrems II violations), and ISK 5M fine against Primary Health Care of the Capital Area for unlawful integration of ~450,000 medical records. Disputes fall under the EFTA Court, not CJEU. Act No. 90/2018 implements the GDPR with national derogations for public interest processing, research, and journalism. National security processing is governed under separate classified frameworks exempt from the Act.[4][5]

IMMI (Icelandic Modern Media Initiative)

Passed unanimously by the Althing on June 16, 2010, IMMI inverts the “tax haven” concept by combining the strongest transparency and press freedom laws from various jurisdictions. Key protections include whistleblower protection modelled on the best international standards, source protection, intermediary liability limitations, and prior restraint restrictions. WikiLeaks helped propose the legislation but hosted servers in Sweden, not Iceland. Implementation has been partial: whistleblower protection was enacted in 2020 (Act 40/2020), but source protection and intermediary liability reforms remain pending.[6]

Pending Legislation

Sources

[2] Electrospaces: NSA Foreign Partnerships – Iceland Tier B, CNE cooperation with Five Eyes
[3] Submarine Cable Map – DANICE, CANTAT-3, Greenland Connect, IRIS cable transit routes
[4] Persónuvernd: Official Website – GDPR enforcement, EFTA Court jurisdiction
[5] GDPRhub: Persónuvernd (Iceland) – Healthcare fine, Google Cloud school cases
[6] IMMI: The IMMI Resolution – Unanimous passage June 2010, partial implementation
[7] Wikipedia: GRLS – Established 2007, limited espionage powers
[8] Reykjavík Grapevine: Police Surveillance Bill – Warrantless monitoring, no court approval, Pirate Party criticism
[9] Althing: Electronic Communications Act – 6-month retention, court order access
[10] Government of Iceland: First Defense and Security Policy (November 2025) – Surveillance submarine, cable monitoring
[11] Arizton: Iceland Data Center Market – USD 170M to USD 375M by 2030, IRIS cable, AI workloads
[12] Council of Europe Treaty Office: European Convention on Mutual Assistance in Criminal Matters (ETS No. 30) – Chart of signatures and ratifications; 51 parties as of July 2026 (all 46 Council of Europe member states plus Chile, Israel, Mongolia, the Republic of Korea and Russia), Iceland among them
[13] Council of Europe Treaty Office: Convention on Cybercrime (ETS No. 185) – Chart of signatures and ratifications; 82 parties as of July 2026 (45 Council of Europe member states plus 37 non-member states), Iceland among them
[14] European Commission: Schengen Area – The 29 states of the Schengen Area (all EU members except Ireland and Cyprus, plus the non-EU associates Iceland, Liechtenstein, Norway and Switzerland; Bulgaria and Romania became full members January 1, 2025), Iceland a non-EU associate
[15] Wikipedia: Prüm Convention – The Prüm framework for automated DNA, fingerprint and vehicle-data exchange; binds all 27 EU member states plus the non-EU Schengen associates Iceland, Liechtenstein, Norway and Switzerland (31 in all); Prüm II (2024) adds facial images and police records
[16] Europol: Operational Agreements – Europol is constituted by the 27 EU member states and maintains operational cooperation agreements permitting exchange of personal data with 17 non-EU states (Albania, Australia, Bosnia and Herzegovina, Canada, Colombia, Georgia, Iceland, Liechtenstein, Moldova, Monaco, Montenegro, North Macedonia, Norway, Serbia, Switzerland, Ukraine, the United States) – Iceland among them – plus Denmark under a separate agreement, and with Eurojust, Frontex and Interpol
[17] Wikipedia: Nordic-Baltic Eight (NB8) – Regional cooperation format of the eight Nordic and Baltic states: Denmark, Estonia, Finland, Iceland, Latvia, Lithuania, Norway and Sweden
← Back to Privacy Law Directory