CCTV Privacy Law Mapper
Laws

CCTV privacy laws in Iceland: what we map and name

What CCTV Privacy Law Mapper maps for a camera at a site in Iceland, what it names without mapping, and what it leaves out. This is not every law that applies there. The EU AI Act is not placed here: it is placed for EU member states. Whether it applies to this site is a question for your lawyer.

Jurisdiction
Iceland
Laws placed
GDPR (the EU General Data Protection Regulation), on every camera at the site
Date last read
Held and read 29 Sep 2026
Named, not quoted
EDPB Guidelines 3/2019
Read from a list as
iceland, is, isl

Coverage here

Laws mapped and checked
Mapped
GDPR (the EU General Data Protection Regulation)
Named, not mapped
EDPB Guidelines 3/2019
The national or state layer
The state adds a national layer we do not map: its data protection act and its supervisory authority's video guidance. Only GDPR is mapped here.

Findings a camera here can raise

14 of the 18 can arise here

Named, not quoted

These are named so you know to open them. We do not hold their text in full and the page does not state what they require beyond the one line above.

The clauses cited here

12 clauses
GDPR Art. 5Principles relating to processing of personal data

Principles relating to processing of personal data. Process personal data lawfully, fairly and in a transparent manner; collect it for specified, explicit and legitimate purposes and do not process it further in a way incompatible with those purposes; keep it adequate, relevant and limited to what the purpose needs; keep it accurate and up to date, erasing or rectifying inaccurate data without delay; keep it in a form permitting identification no longer than the purpose requires; and secure it against unauthorised or unlawful processing and against accidental loss, destruction or damage using appropriate technical or organisational measures. The controller is responsible for all six principles and must be able to demonstrate compliance with them.

What a reviewer asks to see: The purpose recorded for each processing activity, stated specifically enough that a later use can be tested against it; Retention schedule per data category with the criteria that set each period, and deletion evidence showing the schedule actually runs; Minimisation analysis per collection point showing why each field is necessary for the stated purpose; Accuracy controls: how inaccurate data is detected, and records of rectification or erasure carried out without delay; The compatibility assessment for any further processing carried out for a new purpose; Assurance output that demonstrates compliance rather than asserts it, such as control testing, internal audit or DPO reporting
Where camera lists usually fall short: Purposes written so broadly, for example business purposes or service improvement, that no later use could ever be incompatible with them; Retention periods published in a policy but implemented in no system, so data is in fact kept indefinitely; Accountability treated as holding the documents rather than being able to show the principles were applied; Minimisation never revisited after launch, so fields added for a discontinued feature keep being collected
Source: GDPR (the EU General Data Protection Regulation), read 29 Sep 2026
GDPR Art. 6Lawfulness of processing

Lawfulness of processing. Process personal data only where at least one lawful basis applies: the data subject's consent, necessity for a contract with the data subject or pre-contractual steps at their request, compliance with a legal obligation, protection of vital interests, performance of a public interest task or exercise of official authority, or legitimate interests that are not overridden by the data subject's interests, rights and freedoms. Public authorities cannot rely on legitimate interests for processing carried out in performance of their tasks. Where the basis is legal obligation or public task, that basis must be laid down in Union or Member State law and the purpose must be determined in it. Before processing for a purpose other than the one collected for, without consent or a legal mandate, assess compatibility against the link between the purposes, the context of collection, the nature of the data, the consequences for the data subject and the safeguards in place.

What a reviewer asks to see: A lawful basis recorded per processing activity, not per system or per department; Legitimate interests assessments showing the interest pursued, the necessity test and the balancing against the data subject's rights; The Union or Member State provision cited where the basis is legal obligation or public task; Compatibility assessments for each secondary use, covering the five factors Article 6(4) names; Evidence that the basis stated to the data subject in the privacy information matches the one recorded internally
Where camera lists usually fall short: Consent recorded as the basis where the processing would happen regardless of the answer, which makes it neither free nor the real basis; Legitimate interests asserted with no balancing test on file, or a balancing test that never reaches an adverse conclusion for any activity; One lawful basis applied to a whole system that covers several distinct processing purposes; The basis switched after the fact when the first one fails, rather than settled before processing began
Source: GDPR (the EU General Data Protection Regulation), read 29 Sep 2026
GDPR Art. 9Processing of special categories of personal data

Processing of special categories of personal data. Do not process personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs or trade union membership, nor genetic data, biometric data processed to uniquely identify a person, data concerning health, or data concerning a person's sex life or sexual orientation, unless one of the Article 9(2) conditions applies: explicit consent, employment and social security law obligations, vital interests where the data subject cannot consent, the legitimate activities of a not-for-profit body, data manifestly made public by the data subject, legal claims or courts acting judicially, substantial public interest under Union or Member State law, preventive or occupational medicine and health or social care under an obligation of professional secrecy, public health, or archiving, research and statistics under Article 89(1). The condition applies in addition to an Article 6 lawful basis, never in place of it.

What a reviewer asks to see: An inventory identifying where special category data is held, including where it is inferred rather than collected; The Article 9(2) condition recorded per activity alongside its separate Article 6 basis; The Union or Member State law relied on where the condition requires one, cited to the provision; Explicit consent records showing the consent was explicit and specific to the special category processing; Professional secrecy or equivalent confidentiality obligations evidenced for staff handling health data under point (h)
Where camera lists usually fall short: Special category data inferred from behaviour, purchases or free text and never recognised as in scope; An Article 6 basis recorded with no Article 9 condition, or the two conflated into a single entry; Explicit consent asserted from the same tick box used for ordinary consent; Substantial public interest claimed without identifying the Union or Member State law that authorises it
Source: GDPR (the EU General Data Protection Regulation), read 29 Sep 2026
GDPR Art. 13Information to be provided where personal data are collected

Information to be provided where personal data are collected. Where personal data is collected from the data subject, provide at the time it is obtained the identity and contact details of the controller and any representative, the contact details of the data protection officer, the purposes and the legal basis, the legitimate interests where that is the basis, the recipients or categories of recipient, and any intention to transfer to a third country with the existence or absence of an adequacy decision and, for Article 46, 47 or 49(1) transfers, reference to the safeguards and how to obtain a copy. Provide in addition the storage period or the criteria used to determine it, the existence of the rights of access, rectification, erasure, restriction, objection and portability, the right to withdraw consent where consent is the basis, the right to lodge a complaint with a supervisory authority, whether providing the data is a statutory or contractual requirement and the consequences of not providing it, and the existence of automated decision-making including profiling with meaningful information about the logic involved and its significance and envisaged consequences. Before further processing for a new purpose, provide that purpose and the further information first.

What a reviewer asks to see: The privacy notice mapped item by item against every information element Article 13 lists; Evidence of the point and timing at which the notice is presented for each collection channel, including forms, telephone and in person; The storage periods or criteria as published, reconciled against the actual retention schedule; The published description of automated decision-making logic, and the reasoning for why it is meaningful to a data subject; Records showing new purpose information was given before the further processing started, with dates
Where camera lists usually fall short: Recipients described only as third parties or trusted partners, which names neither a recipient nor a category; Retention shown as for as long as necessary, which is neither a period nor a criterion; The notice linked from a page footer but not presented at the point of collection, so it is not provided at the time the data is obtained; Automated decision-making logic described in terms that would fit any system, leaving the data subject nothing to contest
Source: GDPR (the EU General Data Protection Regulation), read 29 Sep 2026
GDPR Art. 26Joint controllers

Joint controllers. Where two or more controllers jointly determine the purposes and means of processing, determine their respective responsibilities for compliance in a transparent manner by an arrangement between them, unless those responsibilities are already determined by Union or Member State law, covering in particular the exercise of the data subject's rights and each party's duty to provide the Article 13 and 14 information. The arrangement may designate a contact point for data subjects. It must duly reflect the parties' respective roles and relationships towards data subjects, and its essence must be made available to the data subject. Irrespective of the terms of the arrangement, a data subject may exercise their rights in respect of and against each of the controllers.

What a reviewer asks to see: The joint controllership assessment identifying every relationship where purposes and means are jointly determined; The Article 26 arrangement for each, allocating responsibility for rights handling, transparency, security and breach response; The essence of the arrangement as published or otherwise made available to data subjects; Evidence the allocation reflects the real roles, such as which party holds the data and which faces the data subject; The operating process showing a rights request is honoured whichever joint controller receives it
Where camera lists usually fall short: A controller to processor agreement used where the relationship is in substance joint controllership; An arrangement signed but its essence never made available to data subjects, which is a separate obligation; Rights requests passed back and forth between joint controllers, when the data subject may exercise them against either; The allocation written to suit the commercial balance of power rather than the actual roles towards data subjects
Source: GDPR (the EU General Data Protection Regulation), read 29 Sep 2026
GDPR Art. 28Processor

Processor. Use only processors providing sufficient guarantees to implement appropriate technical and organisational measures such that the processing meets the Regulation's requirements and protects the rights of the data subject. A processor must not engage another processor without the controller's prior specific or general written authorisation, and under a general authorisation must inform the controller of intended additions or replacements so the controller can object. The processing must be governed by a written contract or other legal act binding the processor to the controller, setting out the subject matter and duration, the nature and purpose, the type of personal data, the categories of data subjects and the controller's obligations and rights, and stipulating that the processor processes only on documented controller instructions including as to transfers, ensures persons authorised to process are under a duty of confidentiality, takes all Article 32 measures, respects the sub-processor conditions, assists the controller in responding to data subject rights requests, assists with Articles 32 to 36, deletes or returns all personal data at the controller's choice at the end of the service and deletes existing copies unless law requires retention, and makes available all information needed to demonstrate compliance and allows for and contributes to audits and inspections. The processor must immediately inform the controller if it considers an instruction infringes data protection law. The same obligations must be imposed on any sub-processor, and the initial processor remains fully liable for the sub-processor's performance. A processor that determines purposes and means is a controller for that processing.

What a reviewer asks to see: A processor inventory reconciled against the vendor register or accounts payable, so no processor is missing from it; The Article 28(3) contract for each processor, checked clause by clause against the eight stipulations the Article names; Due diligence evidence gathered before appointment showing sufficient guarantees, distinct from the signed contract; The sub-processor authorisation position for each processor, the current sub-processor list, and evidence changes were notified; Audit or assurance rights exercised in practice, such as a report reviewed with findings tracked, and end of service deletion certificates
Where camera lists usually fall short: The processor's own standard terms accepted, which commonly omit the audit right, the deletion choice and the instruction infringement notice; A processor inventory that misses tools adopted directly by individual teams, which is where undocumented processing usually sits; Sufficient guarantees evidenced only by the existence of the contract, with no assessment carried out before appointment; Sub-processor lists published by the processor and never actually reviewed, so the right to object is theoretical
Source: GDPR (the EU General Data Protection Regulation), read 29 Sep 2026
GDPR Art. 30Records of processing activities

Records of processing activities. Maintain a written, including electronic, record of processing activities under the controller's responsibility containing the name and contact details of the controller, any joint controller, the representative and the data protection officer, the purposes of the processing, a description of the categories of data subjects and of personal data, the categories of recipients including those in third countries and international organisations, any transfers to a third country or international organisation with that destination identified and, for transfers under the second subparagraph of Article 49(1), the documentation of suitable safeguards, the envisaged time limits for erasure of each category where possible, and a general description of the Article 32(1) technical and organisational security measures where possible. A processor must maintain an equivalent record of the categories of processing carried out on behalf of each controller. Make the record available to the supervisory authority on request. The obligation does not apply to an organisation employing fewer than 250 persons unless the processing is likely to result in a risk to the rights and freedoms of data subjects, is not occasional, or includes special category or criminal offence data.

What a reviewer asks to see: The record of processing activities in full, checked against the seven controller elements, or the four processor elements, the Article lists; Version history showing when each entry was last reviewed and by whom; Reconciliation of the record against a system inventory or data flow map, to show nothing is missing rather than that the entries read well; The transfer entries with the third country identified and the safeguard documentation referenced; Where the fewer than 250 persons exemption is claimed, the assessment against all three disqualifying conditions
Where camera lists usually fall short: Records written once during the implementation project and never updated against reality, so they describe systems long replaced and omit those adopted since; Entries written at the level of a department or a system rather than a processing activity, which loses the purpose that everything else hangs off; Erasure time limits left blank throughout on the where possible qualifier, while a retention schedule exists elsewhere in the organisation; The small organisation exemption claimed on headcount alone, ignoring that regular non-occasional processing disqualifies it
Source: GDPR (the EU General Data Protection Regulation), read 29 Sep 2026
GDPR Art. 32Security of processing

Security of processing. Implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, the nature, scope, context and purposes of processing, and the risk of varying likelihood and severity for the rights and freedoms of natural persons. Those measures include, as appropriate, the pseudonymisation and encryption of personal data, the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services, the ability to restore the availability of and access to personal data in a timely manner after a physical or technical incident, and a process for regularly testing, assessing and evaluating the effectiveness of the technical and organisational measures. Assess the appropriate level of security against the risks presented by the processing, in particular accidental or unlawful destruction, loss, alteration, unauthorised disclosure of or access to personal data transmitted, stored or otherwise processed. Take steps to ensure that any person acting under the controller's or processor's authority who has access to personal data processes it only on instructions.

What a reviewer asks to see: The security risk assessment per processing activity, expressed as risk to the rights and freedoms of individuals rather than only as risk to the organisation; Encryption and pseudonymisation coverage at rest, in transit and in backup, with the decision recorded where either was judged not appropriate; Restoration testing results showing personal data was actually recovered inside the intended timeframe, with the date and outcome; The regular testing programme Article 32(1)(d) requires: penetration tests, vulnerability scanning and control effectiveness reviews, with findings closed out; Evidence the measures were reassessed after material change in processing, technology or threat
Where camera lists usually fall short: Risk assessed as impact to the business, so processing that is low risk to the organisation and high risk to individuals attracts weak measures; Backups taken and never restore tested, so the ability to restore in a timely manner is assumed rather than demonstrated; Article 32(1)(d) treated as satisfied by an annual perimeter penetration test, with the organisational measures never evaluated at all; Encryption stated as in place while key management, backup copies and third party copies sit outside its scope
Source: GDPR (the EU General Data Protection Regulation), read 29 Sep 2026
GDPR Art. 35Data protection impact assessment

Data protection impact assessment. Where a type of processing, in particular using new technologies and taking account of the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data before the processing begins; a single assessment may address a set of similar operations presenting similar risks. An assessment is required in particular for systematic and extensive evaluation of personal aspects based on automated processing, including profiling, on which decisions producing legal or similarly significant effects are based, for large scale processing of special category or criminal offence data, and for systematic monitoring of a publicly accessible area on a large scale. Seek the advice of the data protection officer where one is designated, and where appropriate seek the views of data subjects or their representatives. The assessment must contain at least a systematic description of the envisaged operations and purposes including any legitimate interest pursued, an assessment of the necessity and proportionality of the operations in relation to the purposes, an assessment of the risks to the rights and freedoms of data subjects, and the measures envisaged to address those risks including safeguards, security measures and mechanisms to protect personal data and demonstrate compliance. Carry out a review where necessary and at least when the risk represented by the processing operations changes.

What a reviewer asks to see: The screening or threshold process applied to new and changed processing, with its outcomes recorded including the negative ones; Completed assessments checked against the four minimum content elements Article 35(7) requires; The data protection officer's advice sought and given on each assessment, recorded as advice rather than as approval; Where the views of data subjects were sought, the record of what was asked and what came back, or the reasoning for not seeking them; Review records showing assessments were revisited when the processing or its risk changed, with the date and the trigger
Where camera lists usually fall short: An assessment opened at project start and never revisited, so its residual risk conclusion is never tested against how the processing actually turned out; Necessity and proportionality asserted in a sentence, with all the substance of the assessment sitting in the security measures; Risk assessed to the organisation rather than to the rights and freedoms of the individuals the processing affects; Screening applied only to new projects, so material change to existing high risk processing never triggers an assessment; The data protection officer asked to approve the assessment rather than to advise on it, which compromises the independence Article 38(3) requires
Source: GDPR (the EU General Data Protection Regulation), read 29 Sep 2026
GDPR Art. 44General principle for transfers

General principle for transfers. Transfer personal data undergoing processing, or intended for processing after transfer, to a third country or an international organisation only where the conditions laid down in Chapter V are complied with by the controller and the processor, including for onward transfers from that third country or international organisation to another third country or international organisation. Apply all the provisions of Chapter V so that the level of protection of natural persons guaranteed by the Regulation is not undermined.

What a reviewer asks to see: A transfer register listing every transfer with the destination country, the recipient, the data categories and the Chapter V mechanism relied on; The onward transfer position for each recipient, showing what the recipient may do with the data and under which mechanism; Evidence that remote access from a third country was assessed as a transfer alongside physical movement of data; The reasoning that the level of protection is not undermined by the arrangement as a whole, not only by the chosen instrument
Where camera lists usually fall short: Remote support access, cloud administration and follow the sun operations from third countries never recognised as transfers at all; The transfer register recording the contracting entity's location rather than the locations the data can actually be accessed from; Onward transfers by the recipient left uncovered, so the chain breaks one step beyond the direct relationship; A mechanism recorded per vendor rather than per transfer, so several distinct transfers share one unexamined justification
Source: GDPR (the EU General Data Protection Regulation), read 29 Sep 2026
GDPR Art. 45Transfers on the basis of an adequacy decision

Transfers on the basis of an adequacy decision. Personal data may be transferred to a third country, a territory, one or more specified sectors within a third country, or an international organisation where the Commission has decided that it ensures an adequate level of protection, and such a transfer requires no specific authorisation. Adequacy decisions carry a defined territorial and sectoral scope, provide for periodic review at least every four years, and may be repealed, amended or suspended by the Commission. Relying on adequacy therefore requires confirming that the specific recipient and data fall inside the scope of a decision that is in force at the time of the transfer, and monitoring for amendment, suspension or repeal of that decision.

What a reviewer asks to see: Per transfer, the adequacy decision relied on identified by instrument, with confirmation the recipient and the data fall inside its territorial and sectoral scope; A monitoring process for changes to adequacy decisions, with a named owner and evidence it has actually been run; The fallback plan for each adequacy based transfer should the decision be suspended or repealed, tested against the Article 46 and 49 options; Where a decision covers only certified or listed recipients, evidence the recipient's current status was verified
Where camera lists usually fall short: Adequacy assumed for a whole country where the decision covers only a sector or only listed recipients, with the recipient's listing never verified; No monitoring for suspension or invalidation, so a transfer continues on a decision that has since been struck down; Adequacy relied on for the direct transfer with no consideration of onward transfers out of the adequate country; The decision recorded at contract signature and never rechecked at the periodic review point
Source: GDPR (the EU General Data Protection Regulation), read 29 Sep 2026
GDPR Art. 46Transfers subject to appropriate safeguards

Transfers subject to appropriate safeguards. In the absence of an adequacy decision, transfer personal data to a third country or an international organisation only where the controller or processor has provided appropriate safeguards and on condition that enforceable data subject rights and effective legal remedies are available. Safeguards requiring no specific authorisation are a legally binding and enforceable instrument between public authorities or bodies, binding corporate rules under Article 47, standard data protection clauses adopted by the Commission, standard clauses adopted by a supervisory authority and approved by the Commission, an approved code of conduct together with binding and enforceable commitments from the recipient to apply the safeguards including as to data subject rights, or an approved certification mechanism with the same commitments. Subject to authorisation from the competent supervisory authority, safeguards may also be provided by contractual clauses between the parties or by provisions inserted into administrative arrangements between public authorities that include enforceable and effective data subject rights.

What a reviewer asks to see: The executed instrument for each transfer, with the modules, annexes and schedules of technical and organisational measures actually completed rather than left blank; The transfer risk assessment examining the destination's law and practice, in particular public authority access, and the conclusion on whether the safeguards are effective there; The supplementary measures adopted where that assessment found the instrument alone insufficient, and evidence they are in place; Supervisory authority authorisation where ad hoc contractual clauses or administrative arrangements are relied on; Evidence that data subjects can in practice exercise the rights the instrument confers, such as an operable third party beneficiary route
Where camera lists usually fall short: Standard clauses signed with the annexes unfilled, so the data, the purposes and the security measures the clauses are meant to bind are left undefined; No assessment of destination law and practice, so the clauses are relied on in a jurisdiction whose law makes them unenforceable; Supplementary measures identified in the assessment and never implemented, leaving open the gap the assessment found; The instrument signed with the contracting entity while group companies that actually access the data are never brought inside it
Source: GDPR (the EU General Data Protection Regulation), read 29 Sep 2026

See the specimen list run Map your own list