The framework
Iceland's framework rests on the GDPR (via EEA) + Act 90/2018, with Personuvernd as the supervisory authority.
That puts Iceland in the global opt-in majority, where permission comes before processing and marketing waits for consent.
Key instruments
GDPR (via EEA) + Act 90/2018
Full GDPR jurisdiction through the EEA; enforcement is proportionate to the small market but the rules are identical to the EU's.
Marketing and advertising
GDPR applies through the EEA Agreement; ePrivacy consent for cookies. That single sentence decides most channel plans here.
Cross-border transfers
GDPR Chapter V applies in full, so personal data leaves the EEA only under an adequacy decision, standard contractual clauses, binding corporate rules or a narrow derogation, with a transfer impact assessment expected where the destination has surveillance-law exposure. The mechanics are identical across the bloc, so a transfer stack built for one member state travels to all of them.
Enforcement and penalties
The GDPR's ceiling applies, with fines up to EUR 20M or 4% of global annual turnover, whichever is higher, levied by the national supervisory authority, and the EDPB can force a harder line through the dispute mechanism. Member states share the ceiling and differ in enforcement appetite.