Frequently Asked Questions

Filter on
Filter on topic

How can my processing operations or my organisation become GDPR certified?

Under the GDPR, certification is conducted by national certification bodies or by the competent national data protection authorities (Art. 42(5) GDPR).

For further information, we recommend contacting the relevant national DPA for your organisation. You can find a overview of all EEA DPAs here.

You can find further information regarding certification in the EDPB guidelines on the topic: Guidelines 1/2018 on certification and identifying certification criteria in accordance with Articles 42 and 43 of the Regulation - version adopted after public consultation

I think my data protection rights have been violated, what can I do?

If you believe your data protection rights have been violated you can contact the organisation holding your data, contact your national data protection authority (DPA), or go to a national court.

DPAs can conduct investigations and impose sanctions where necessary. You can find the contact details for all EEA DPAs here.

How can I apply for the European Data Protection Seal?

Controllers should formally submit their EU-wide certification criteria to:

  1. the competent data protection authority (DPA) in the EEA country where the scheme owners have their headquarters;
  2. the competent data protection authority (DPA) in the EEA country where a certification body operating the certification mechanism have their headquarters, considering the member state in which the most certificates are likely to be issued.

Ætti ég að tilnefna persónuverndarfulltrúa (DPO)?

Skylt er að tilnefna gagnaverndarfulltrúa í eftirfarandi þremur tilvikum:

  • stofnunin er opinbert yfirvald,
  • grunnstarfsemi fyrirtækisins felur í sér reglubundið og kerfisbundið eftirlit með einstaklingum í stórum stíl, t.d. landfræðilegri staðsetningu með farsímaforriti, eða eftirliti með verslunarmiðstöðvum og opinberum rýmum í gegnum CCTV,
  • grunnstarfsemi fyrirtækisins felst í umfangsmikilli vinnslu viðkvæmra upplýsinga eða persónuupplýsinga í tengslum við sakfellingar í refsimálum og brot.

Þú getur alltaf tilnefnt DPO að eigin frumkvæði, jafnvel þótt þess sé ekki krafist samkvæmt lögum. Vinsamlegast athugaðu að í því tilviki verður þú að fara að öllum ákvæðum GDPR varðandi verkefni og stöðu persónuverndarfulltrúa.

Frekari upplýsingar:

Þarf ég að gera skrá mína yfir vinnslu opinberlega?

Nei, það er ekki nauðsynlegt að gera skrá yfir vinnslu opinberlega. Þú verður þó að geta gert skrána aðgengilega gagnaverndaryfirvöldum sé þess óskað.

Frekari upplýsingar:

Is your message about enforcing the GDPR or other rules?

Are you asking the EDPB to investigate and take action against an organisation that you consider is infringing EU legislation, including through specific technologies, such as AI, social media, or messaging services?

In the context of data protection rules, you can lodge a complaint with your data protection authority (DPA) (please find a list of them on our website: Our members). Enforcement of data protection rules is the responsibility of the DPAs. You can contact the data protection authority where you live or work, or where the alleged infringement took place, for instance.

Another alternative is to go to national courts where you live or where the controller or processor is established. 

If the GDPR applies in your situation but you're not based in Europe, you can still complain to a DPA in Europe and/or go to court.

The EDPB has no competence to handle specific individual requests or complaints, nor to provide individual consultancy services. The EDPB is not a supranational body that can investigate complaints.

Finally, if you want to complain about how an EU institution, agency or body is using your personal data, you can lodge a complaint with the European Data Protection Supervisor (please see contact details on our website: Our members).

Please note that we do not forward your message to the national DPAs or to the EDPS. Therefore, you should contact them directly.

What is the purpose of the dispute resolution mechanism of Art. 65.1 (a) and (b) GDPR?

The dispute resolution mechanism triggered under Art.65.1 (a) and (b) GDPR contributes to the good functioning of the cooperation mechanism by addressing any disagreements Concerned Supervisory Authorities (CSAs) may have in a given case or if there are conflicting views as to which authority is the Lead Supervisory Authority (LSA).
The EDPB will act as a dispute resolution body. It must adopt a decision to address the conflict between the involved Data Protection Authorities (DPAs), which is binding on them (Art. 65 GDPR). The decision is adopted by a two-thirds majority of the members of the Board, and in case a decision cannot be adopted within 2 months, the decision is adopted within the next 2 weeks by a simple majority.

Hvernig get ég fengið gilt samþykki?

Til að samþykki teljist gilt verður það að vera:

  • gefið af frjálsum vilja,
  • sértækt,
  • upplýst, og
  • ótvírætt.

Þetta þýðir að einstaklingar verða að hafa raunverulega frjálst val um hvort þeir séu sammála um vinnslu persónuupplýsinga um sig eða ekki, þeir þurfa nægar upplýsingar til að þeir geti skilið hvaða gögn eru unnin, í hvaða tilgangi og hvernig það er gert; þeir þurfa einnig nægilega korn í samþykki beiðnir.

Að auki ætti að vera skýr jákvæð aðgerð frá einstaklingnum (án kassa sem eru formerktir og gerðir aðskilið frá gildandi almennum skilyrðum).

Að auki þurfa einstaklingar að geta afturkallað samþykki sitt af fúsum og frjálsum vilja (án neikvæðra afleiðinga) ef þeir skipta um skoðun síðar.

Frekari upplýsingar:

Hvenær á að deila þessum upplýsingum?

Ef fyrirtækið þitt safnar persónuupplýsingum beint frá einstaklingum verður það að veita nauðsynlegar upplýsingar við söfnun.

Ef um er að ræða óbeina söfnun persónuupplýsinga verður fyrirtækið að veita upplýsingarnar eigi síðar en einum mánuði eftir að persónuupplýsingarnar voru upphaflega fengnar. Hægt er að stytta þennan hámarkstíma um einn mánuð:

  • ef persónuupplýsingarnar eru notaðar í þeim tilgangi að eiga samskipti við hinn skráða. Í því tilviki verður þú að tilkynna hinum skráða um það í síðasta lagi þegar fyrsta tilkynning til hins skráða fer fram;
  • ef upplýsingarnar eru sendar öðrum viðtakanda upplýsir fyrirtækið skráða aðilann um það í síðasta lagi þegar persónuupplýsingarnar eru fluttar. 

Frekari upplýsingar:

Þarf fyrirtækið mitt að vera í samræmi við GDPR?

Allar stofnanir, óháð stærð eða geira, með staðfestu á Evrópska efnahagssvæðinu (EES) eða bjóða einstaklingum á Evrópska efnahagssvæðinu vörur eða þjónustu, vinna persónuupplýsingar hvort sem þær þurfa að fara eftir GDPR eða ekki. Jafnvel þótt GDPR tengist aðallega sjálfvirkri vinnslu persónuupplýsinga mun vinnsla sem fer fram handvirkt einnig falla undir GDPR frá því að pappírsskrár eru skipulagðar á kerfisbundinn hátt, t.d. raðað í stafrófsröð í skjalaskáp. 

Dæmi um vinnsluaðgerðir eru að safna, skrá, skipuleggja, nota, breyta, geyma, birta, breyta, breyta og eyða persónuupplýsingum einstaklinga.

Engu að síður er beiting GDPR mótuð eftir eðli, samhengi, tilgangi og áhættu vinnsluaðgerða sem framkvæmdar eru. Að því er varðar lítil og meðalstór fyrirtæki þar sem kjarnastarfsemi er ekki vinnsla persónuupplýsinga geta skyldurnar verið vægari en fyrir stórt fyrirtæki.

Frekari upplýsingar:

What are the tasks of the Data Protection Officer (DPO)?

The task of the DPO include, among others:

  • to inform and advise the organisation and its employees on data protection compliance;
  • to monitor data protection compliance;
  • to provide advice on requests concerning the data protection impact assessment (DPIA);
  • to act as a contact point for the data protection authority (DPA) and to cooperate with that DPA;
  • to act as a contact point for individuals.

In addition, the DPO’s presence is generally recommended where decisions with data protection implications are taken. The DPO should also be promptly consulted once a data breach or another incident has occurred.

More information:

Hverjar eru skyldur mínar samkvæmt GDPR?

GDPR leggur skyldur á öll fyrirtæki sem vinna persónuupplýsingar, óháð því hvort um er að ræða ábyrgðaraðila gagna eða vinnsluaðila.

Einkum ættir þú að:

  • Spyrja sjálfan þig hvort tilgangurinn með söfnun persónuupplýsinga sé réttlætanlegur og að safna aðeins persónuupplýsingum sem eru nauðsynlegar í þeim tiltekna tilgangi sem fyrirhugað er að nota,
  • Halda persónuupplýsingum einstaklinga nákvæmum og uppfærðum og eyða þeim þegar þær eru ekki lengur nauðsynlegar,
  • Virða réttindi einstaklinga með því að upplýsa þá um hvernig og hvers vegna gögn þeirra eru unnin og leyfa þeim að neyta réttar síns;
  • Athugaðu hvort þú hafir viðeigandi lagagrundvöll fyrir vinnslu persónuupplýsinga. Ef þú ætlar að reiða þig á samþykki einstaklinga skaltu biðja um samþykki þeirra áður en þú vinnur persónuupplýsingar þeirra;
  • Tryggja að persónuupplýsingar einstaklinga séu meðhöndlaðar á öruggan hátt,
  • Halda skrá yfir vinnsluaðgerðir.

Gagnavinnsluaðilar verða að fylgja þeim ábyrgðum sem settar eru fram í ábyrgðaraðila-örgjörva samningnum, og þeir mega ekki vinna gögnin á annan hátt en samkvæmt leiðbeiningum ábyrgðaraðila.

Frekari upplýsingar:

What are the basic processing principles under the GDPR?

  • Any processing of personal data must be lawful, fair and transparent.
  • Only collect personal data for specified, explicit and legitimate purposes. The processing of an individual’s data must be strictly limited to the purpose(s) initially established, and therefore not processed for subsequent or other purpose(s) that are incompatible with the initial purposes.
  • Only process personal data that is necessary and proportionate in light of the purpose envisaged.
  • All personal data you process must be accurate and kept up to date. Inaccurate personal data must be rectified or erased.
  • The storage of individuals’ personal data must be limited in time, in light of the purpose for which this data was collected and processed. As such, individuals’ personal data must be deleted or anonymised once this data is no longer necessary.
  • The processing of individuals’ data must be done in a secure way. In this sense, robust cybersecurity controls, must be put in place to ensure that individuals’ data is adequately protected.

Finally, the controller is accountable. This means it is responsible for and must be able to demonstrate compliance with the principles above.

More information:

Who are the members of the Board?

The EDPB brings together the EU DPAs and the European Data Protection Supervisor (EDPS). The EEA EFTA countries (Iceland, Liechtenstein and Norway) are also members with regard to GDPR-related matters and without the rights to vote and to be elected as chair or deputy chair. The European Commission and - with regard to GDPR-related matters - the EFTA Surveillance Authority have the right to participate in the activities and meetings of the Board without voting rights.

You can find an overview of the EEA DPAs here.

Are you writing because you are unhappy with the way your DPA has handled your request or complaint?

The EDPB does not have the competence to exercise oversight over the DPAs activities at the request of individuals.

Please note that the competence to issue general guidance cannot be understood as a mechanism for the EDPB to exercise oversight on how DPAs handle your individual case.

If you believe that GDPR has been infringed and you are not satisfied with the DPA’s response, the remaining solution is for you to initiate legal proceedings.

What is the dispute resolution mechanism of Art. 65 GDPR?

When a Lead Supervisory Authority (LSA) issues a draft decision, it consults the Concerned Supervisory Authorities (CSAs), which can express their disagreement with the draft decision by submitting relevant and reasoned objections (RRO) within a period of four weeks (Art. 60.4 GDPR).
When none of the CSAs objects, the LSA may proceed to adopt the decision.

In case at least one of the CSAs has expressed an RRO, and if the LSA intends to follow the objection, it shall submit a revised draft decision to all the CSAs. The CSAs then have a period of two weeks (Art. 60.5 GDPR) to express their RROs to the revised draft decision.

However, if the LSA does not intend to follow the objection(s), since no consensus can be reached, the consistency mechanism is triggered. This means that the LSA is obliged to refer the case to the European Data Protection Board (EDPB) and the dispute resolution role of the EDPB is activated (Art. 65.1(a) GDPR).

The dispute resolution mechanism can be triggered in two further cases:

  • there is a disagreement as to which authority is the LSA (Art. 65.1(b) GDPR);
  • an SA does not seek the opinion of the EDPB as obliged under Art. 64.1 GDPR or does not follow such an opinion (Art. 64.1 - 2 GDPR) (Art. 65.1(c) GDPR).

Hversu lengi get ég geymt persónuupplýsingar?

Ekki er hægt að geyma persónuupplýsingar að eilífu.

Að jafnaði er einungis hægt að geyma persónuupplýsingar eins lengi og nauðsynlegt er í ljósi tilgangs vinnslu persónuupplýsinga.

Í sumum tilvikum er hægt að ákvarða geymslutímabilið með sérstökum lögum, t.d. að vinnureglur ákvarða geymslutíma fyrir launaskrár.

Fyrirtæki/stofnanir ættu að setja reglur um varðveislu gagna til að tryggja að persónuupplýsingar séu ekki geymdar lengur en nauðsynlegt er. Eyða skal persónuupplýsingum einstaklinga eða gera þær nafnlausar þegar þær eru ekki lengur nauðsynlegar í þeim tilgangi sem unnið var með þær. 

Frekari upplýsingar:

Þarf ég skrá yfir vinnslu?

Almennt séð ættu allar stofnanir að halda skrá yfir vinnslustarfsemi sína. Þetta er skrá yfir allar vinnsluaðgerðir og getur hjálpað þér að gera réttar forsendur um ábyrgð þína samkvæmt GDPR og hugsanlega áhættu.

Lýsa skal hverri þessara vinnsluaðgerða í skránni með eftirfarandi upplýsingum:

  • tilgangur vinnslunnar (t.d. tryggð viðskiptavina),
  • flokkar gagna sem unnin eru (t.d. fyrir launaskrá: nafn, eiginnafn, fæðingardagur og -ár, laun o.s.frv.),
  • hver hefur aðgang að gögnunum (viðtakendur — t.d.: deildin sem ber ábyrgð á ráðningu, upplýsingatækniþjónustu, stjórnun, þjónustuveitendum, samstarfsaðilum...);
  • eftir atvikum, upplýsingar sem tengjast flutningi persónuupplýsinga út fyrir Evrópska efnahagssvæðið (EES),
  • ef unnt er, geymslutímabilið (tímabilið sem gögnin eru gagnleg frá rekstrarlegu sjónarmiði og frá sjónarhóli skjalavistunar).
  • ef unnt er, almenn lýsing á verndarráðstöfununum.

Skrá yfir vinnslustarfsemi er á ábyrgð stjórnanda fyrirtækis þíns.

Þessi skrá verður að vera aðgengileg gagnaverndaryfirvöldum þess EES-lands þar sem þú starfar, sé þess óskað.

Þess er ekki krafist að fyrirtæki, sem hafa færri en 250 starfsmenn hjá færri en 250 starfsmönnum, komi eingöngu fram í skrá sinni (t.d. gögn sem unnin eru fyrir einstaka viðburði, s.s. opnun verslunar).

Frekari upplýsingar:

What constitutes a conflict of interest for a Data Protection Officer (DPO)?

DPOs can fulfil other tasks within the organisation, but this cannot result in a conflict of interest. This implies that the DPO cannot have a position in which they determine the purposes and means of the processing activities. Conflicting functions include mainly management positions (chief executive, chief operating, chief financial officer, Head of HR, Head of IT, managing director) but may also involve other functions if they lead to the determination of purposes and means of processing.

The DPO must be able to perform their duties and tasks in an independent manner. This means that your organisation:

  • may not give instructions to the DPO with regard to the performance of their DPO duties;
  • may not penalise or dismiss the DPO for performing their tasks.

More information: