Is Google Analytics Legal in Iceland? Persónuvernd, the Google Fines, and Schrems II

Is Google Analytics legal in Iceland? Yes, for now, and for the same conditional reason it's legal everywhere else in Europe: a transatlantic data deal that has survived one court challenge and is now fighting an appeal at the EU's highest court. Iceland's own regulator has never ruled on GA. Persónuvernd promised guidance on Google Analytics in January 2022 and never published it. Instead, it fined five municipalities for handing schoolchildren's data to Google, and then, in 2026, it had to give the money back.
That reversal is the strangest story in this whole country series. I'll walk you through all of it.
- Google Analytics has never been ruled on in Iceland. Persónuvernd promised guidance on analytics tools in January 2022, right after Austria's ruling against GA, and has never published it.
- On 28 November 2023 Persónuvernd fined five municipalities a combined ISK 12.8 million (about EUR 85,000) for how their primary schools handed student data to Google Workspace.
- In March 2026 the fines were revoked after Iceland's Supreme Court found the regulator hadn't proven the sensitive data was in fact processed. The underlying GDPR violation findings still stand.
- GDPR applies in full in Iceland through the EEA Agreement as Act No. 90/2018. Cookies need consent under the Electronic Communications Act, with only a strictly-necessary exemption and no French-style analytics carve-out.
- The EU-US Data Privacy Framework, the deal that keeps GA legal in Europe, only reached Iceland on 6 July 2024, a year after the EU, via a separate EEA decision. GA's legal cover in Iceland is younger and just as fragile.
Does the GDPR even apply in Iceland?
Yes, in full. Iceland isn't in the EU, but it's in the European Economic Area, the agreement that lets Iceland, Norway and Liechtenstein join the EU's single market in exchange for adopting its rules. Privacy rules included. The GDPR is written into Icelandic law as Act No. 90/2018, and Persónuvernd enforces it.
So if you assumed Iceland sits outside European privacy law, you assumed wrong. The obligations you'd face in Berlin or Paris follow you to Reykjavík.
The cookie side works the same way. The EU's ePrivacy Directive, the rule that says storing or reading anything on a visitor's device needs consent unless it's strictly necessary, reaches Iceland through the Electronic Communications Act, Fjarskiptalög nr. 70/2022. That law contains an entire chapter titled "Persónuvernd í fjarskiptum". In plain English: privacy in electronic communications.
DLA Piper's data protection handbook describes Iceland's cookie rule the way you'd expect from that lineage: cookies count as access to the user's equipment, informed consent is required, and the only exemption is for cookies that are strictly necessary to deliver the service. Analytics cookies aren't strictly necessary. They need consent.
And consent means the GDPR's version of consent. It must be freely given, specific, informed and unambiguous, which in practice means a real choice offered before any cookie loads. Silence doesn't count. Scrolling doesn't count. A pre-ticked box doesn't count.
That's the standard you sign up for the moment your analytics depends on cookies.
Here's what Iceland doesn't have: an analytics exemption. France runs a formal framework where privacy-respecting audience measurement can skip the consent banner entirely. Iceland has nothing like it. Persónuvernd hasn't published dedicated cookie guidance at all, let alone a carve-out for analytics tools.
So the Icelandic baseline is the strict European default. Consent first. A narrow strictly-necessary exemption. No published shortcut.
The five Google fines: Iceland's signature privacy case
On 28 November 2023, Persónuvernd fined five municipalities a combined ISK 12,800,000, which means roughly EUR 85,000, for how their primary schools used Google Workspace for Education. The regulator's biggest enforcement action ever wasn't aimed at a corporation. It was aimed at schools. And the data at stake belonged to children.
The audit started on 25 February 2022. Persónuvernd wanted answers to two questions. Did Google process student data beyond what the municipalities had instructed? And were the transfers of that data to the US lawful, given that this was before the EU-US adequacy decision existed?
The answers didn't look good for the municipalities. Here's what each one was fined.
The violations read like a checklist of everything the GDPR asks a data controller to do before trusting a cloud vendor. The municipalities hadn't done a proper data protection impact assessment, which means the risk analysis you're required to run before processing children's data at scale. Their processing agreement with Google was deficient. They couldn't show data minimization, the principle that you only collect what you need. And student data flowed to the US before the 10 July 2023 adequacy decision made such transfers lawful again. That last one is a Schrems II problem. The same legal defect that got Google Analytics ruled unlawful in Austria and France.
Persónuvernd's then-director Helga Þórisdóttir didn't mince words. She told the Icelandic outlet Vísir that Google had in effect been handed Icelandic elementary schoolchildren's personal data "on a silver platter", and that this isn't acceptable today.
One dating note, because almost every international article gets it wrong. You'll see these called "the 2024 Google fines" all over the web. That's because the EDPB, the umbrella body of European data protection authorities, published its English summaries on 26 April 2024, five months after the decisions. Put another way: the fines are from November 2023, and the English-speaking world found out in 2024.
And notice what this case is not. It's not a Google Analytics case. It's a cloud-services and international-transfer case about student data. Plenty of articles blur the two together. The distinction matters, and I'll come back to it.
Then Iceland took the fines back
This is the part nobody covering the fines in 2024 saw coming. The fines didn't survive. Iceland's Supreme Court ruled in December 2024 that Persónuvernd had never proven the children's data was actually processed, and by spring 2026 the regulator had revoked the fines and refunded the money with interest, close to ISK 15 million in all.
Kópavogur appealed, and on 9 December 2024 Iceland's Supreme Court ruled in case 18/2024 that Persónuvernd hadn't established a sufficient factual basis for its harshest finding. The court's own text isn't published in a linkable form, so I'm citing it through Persónuvernd's recall decision, which quotes and applies the ruling. In plain English: the regulator showed there was a real risk that children's sensitive data ended up inside Google's platform, but it never proved that this had happened as a matter of fact. Risk isn't proof. And you can't base a fine on it.
On 19 March 2026, Persónuvernd followed through. It issued a decision revoking Kópavogur's fine, writing that the investigation "did not unequivocally show that such information had actually been processed". The money goes back, with interest. Reykjavík's fine was revoked the same day in a parallel decision. Reporting indicates the same pattern extended to the other three municipalities, and the Icelandic broadcaster RÚV put the total refund at close to ISK 15 million once interest was added. That means the reversal roughly wiped out the original ISK 12.8 million, and then some.
But here's the nuance that makes this story useful instead of just strange. Only the fines were revoked. The violation findings were not.
The Kópavogur recall decision says it in so many words: the municipality's violations of data protection legislation "remain unaffected by this decision". The deficient processing agreement, the missing impact assessment, the minimization failures, the unlawful transfers. All of it stays on the record. Only the price tag came off.
So if you're tempted to read the 2026 reversal as "Iceland decided Google is fine", don't. The regulator lost on the standard of proof, not on the law. Every structural finding about how those municipalities used Google survived the appeal.
Where Google Analytics stands in Iceland
Persónuvernd has never issued a ruling on Google Analytics. Not in 2022, when its European peers did. Not since. What it did do, on 26 January 2022, was publish a note reacting to the Austrian DPA's ruling that GA violated the GDPR, saying it would study the decision, watch its peer authorities, and publish "a summary and guidelines on the use of analytics tools such as Google Analytics" at the first opportunity.
That was four and a half years ago. The guidance has never appeared.
I find that gap genuinely revealing. Iceland's regulator saw the Austrian ruling, considered it important enough to announce a formal response, and then went quiet on GA while pouring its energy into the Google Workspace audit instead. If you run a website in Iceland, you're left to read the European tea leaves yourself. So let me read them with you.
The short version of the Europe-wide story: in 2022, the Austrian and French authorities ruled that Google Analytics violated the GDPR, because it moved visitor data to US servers where American intelligence agencies could reach it. That's the Schrems II problem, named after the court case that struck down the previous EU-US data deal. In July 2023 the European Commission adopted the EU-US Data Privacy Framework, a new deal that gives certified US companies, Google included, a legal basis for those transfers. The 2022 rulings weren't overturned. The ground under them changed.
Iceland adds its own twist here, and it's one almost nobody mentions. EU adequacy decisions don't apply to Iceland automatically. They have to be extended through the EEA machinery, and for the Data Privacy Framework that extension only took effect on 6 July 2024, per the framework's documented adoption history. Which means Google Analytics' current legal cover arrived in Iceland a full year later than in the EU. For nearly a year, an Icelandic site using GA was relying on a transfer basis its own legal order hadn't adopted yet.
One more Icelandic data point. When noyb, the privacy group founded by Max Schrems, filed its famous 101 complaints against European websites using Google Analytics and Facebook Connect in August 2020, the campaign reached all 30 EU and EEA states, which on paper includes Iceland. But in the part of the case list that renders, no Icelandic case appears. Norway, Iceland's closest EEA peer, shows up with named targets. Iceland doesn't. I'll be careful with that: it's an absence in what I could check, not a certified one. What I can say is that no Icelandic GA complaint, test case or ruling has ever surfaced publicly. That's a big part of why Persónuvernd never had to show its hand.
So where does that leave Google Analytics in Iceland today? Legal, in the same conditional way it's legal in the rest of Europe. The DPF covers the US transfers, and it has already survived one direct attack: in September 2025 the EU's General Court dismissed the Latombe challenge (case T-553/23) and upheld the framework on the merits. That's not the end of the story, though. A narrower appeal on points of law is now pending at the EU's highest court, and the framework's two predecessors were both struck down at that same court. I've covered that full saga in the main legality guide, and every word of it applies to Iceland with a one-year lag built in. If the DPF falls, the 2022 problem comes straight back. And Iceland would inherit it without ever having published its own position.
What about GA4? Switching versions doesn't change any of this. The 2022 European rulings were never about a version number. They were about personal data moving to US servers, and GA4 still sends your visitors' data to Google. Iceland hasn't published a word suggesting it sees GA4 differently, because it hasn't published a word about Google Analytics at all.
Meanwhile the cookie layer doesn't care about any of this. GA needs consent in Iceland regardless, because analytics cookies aren't strictly necessary and Iceland has no exemption. The transfer question decides whether GA can be lawful at all. The cookie question decides whether you need a banner. With GA you need both answers to go your way, and you only control one of them.
What Persónuvernd actually enforces
Iceland has 389,444 people, going by Statistics Iceland's 2025 count. That means the entire country is smaller than a mid-sized European city, and its data protection authority is sized to match. You shouldn't expect a CNIL-style enforcement machine issuing dozens of cookie fines a year. There isn't one.
In my research for this article, the Google Workspace case is the only major enforcement action touching cloud transfers or Google that I could find. I couldn't find a single Persónuvernd decision about cookie banners or web trackers specifically. I want to be careful with that claim: it's "not found", not "doesn't exist". Iceland's case-law coverage in English is thin, and the main European case database blocked automated access while I was researching.
But don't read the quiet as permission. Look at what the Workspace case tells you instead.
It tells you the regulator will run a multi-year audit when it decides something matters. It tells you children's data is where Iceland draws its hardest line. It tells you Persónuvernd applies the same Schrems II transfer logic that drove the Google Analytics rulings elsewhere in Europe. And the 2026 reversal tells you Icelandic courts will hold the regulator to a strict standard of proof, which cuts both ways: fines are harder to make stick, and the ones that stick will be well-founded.
There's also a proportionality point worth making. ISK 12.8 million sounds small next to the hundreds of millions in French cookie fines. Scale it to a country of 389,444 people and it's a different picture. Five public bodies, all fined on the same day, over the country's dominant cloud platform in schools. In practice, that's about as loud as a regulator this size can get.
So what do you do with a regulator that's quiet on your exact question? You don't treat the silence as a safe harbor. You look at the nearest thing it has ruled on, and in Iceland that's a four-year Schrems II transfer case against a Google product. If I ran Google Analytics on an Icelandic site, I wouldn't find that precedent comforting.
Your cookie banner still costs you most of your data
Here's the part that has nothing to do with courts and everything to do with your numbers being wrong. Wherever compliant banners have been measured in Europe, most visitors decline analytics cookies, and Iceland's unusually Apple-heavy browser mix takes a second bite on top. A cookie-based setup on an Icelandic site is likely blind to more than half of its real traffic.
I couldn't find a published cookie-consent acceptance rate for Iceland. Nobody seems to have measured one. But the European pattern is consistent wherever it has been measured: in France, fewer than a quarter of visitors accept analytics cookies on a compliant banner, and German benchmark studies put average data loss around 60%. There's no reason to think Icelanders behave differently. Which means a cookie-based analytics setup on an Icelandic site is likely blind to well over half of its real traffic.
Then the browser layer takes another bite. Iceland is unusually Apple-heavy.
Safari holds 28.15% of the Icelandic market per StatCounter, and its Intelligent Tracking Prevention caps or blocks the cookies GA-style tools depend on. In plain English: more than a quarter of Icelandic visitors degrade your cookie analytics before they've even seen your banner. Ad blockers take their own cut on top, because analytics scripts are exactly what they block. Stack consent rejection over all of it and the picture gets grim fast.
None of this is a legal risk. It's worse. It's your data quietly lying to you, every day, while you make decisions with it.
And this is a country where the audience is genuinely all online. DataReportal's 2025 digital report counts 392,000 internet users, a 99.0% penetration rate. In other words, essentially every Icelander you could want to reach is reachable, and your cookie-based analytics can't see most of them.
This is the problem cookieless analytics exists to solve. Clickport measures visits without cookies and without storing anything on the visitor's device, so there's no consent banner to reject and nothing for Safari to throttle. You see every visit, the data stays in the EU, and the whole US-transfer question this article is about simply doesn't apply. If you first want to know whether your current setup needs a banner at all, start with the flowchart.
What's coming next
Three things are worth watching if your site serves Icelandic or European visitors: the EU's Digital Omnibus proposal, which would make consent-free audience measurement the European default; the court appeal over the transfer framework that keeps Google Analytics legal; and whether Persónuvernd finally publishes the analytics guidance it promised back in 2022.
The Digital Omnibus. In November 2025 the European Commission proposed a reform package that would, among other things, let privacy-respecting audience measurement run without consent across the EU. It's still a proposal. If it passes, it would turn the French-style exemption into the European default, and Iceland would eventually pick it up the way it picks up all EU digital law, through the EEA. Note the word eventually. The DPF took a year to make that trip. I've broken the proposal down in the Digital Omnibus explainer.
The DPF appeal. The legal deal keeping Google Analytics lawful in Europe has won round one. In September 2025 the EU's General Court dismissed the challenge brought by French MP Philippe Latombe and upheld the framework. Round two is live: Latombe appealed to the EU's highest court (case C-703/25 P), an appeal limited to points of law, and Microsoft was admitted in June 2026 as an intervener on the Commission's side. So the DPF is standing on firmer ground than a bare "under challenge" suggests. But its two predecessors both died at that same court, and if this one falls too, Iceland has no national ruling, no guidance, and no exemption to fall back on. Icelandic sites would be exposed to the same uncertainty as everyone else, with less local precedent to navigate by.
Persónuvernd's missing guidance. The promise from January 2022 is still open. A regulator that just spent four years litigating Google transfers, and got burned on proof standards, has every reason to finally publish its analytics position. When it does, I'd expect it to look like its peers': strict on US transfers, strict on consent. I wouldn't expect a carve-out Iceland has never signaled.
My honest read: nothing on this list makes Google Analytics safer in Iceland, and two of the three could make it materially worse. The one genuinely good development, the Omnibus, only rewards tools that don't need consent in the first place.
What this means for your website
Here's where you stand, depending on your setup.
If you're using Google Analytics on an Icelandic site: you're legal today under the Data Privacy Framework, but your legal basis arrived in Iceland a year late, is under challenge at the EU's highest court, and has no local guidance behind it. You also still need a compliant cookie banner, because Iceland has no analytics exemption. And that banner costs you a large share of your data before you measure a single visit.
If you're a public body or handle children's data: the Workspace saga is your case study. The fines vanished, the findings didn't. Run the impact assessment before you adopt the tool, get the processing agreement right, and treat US transfers as the thing Persónuvernd has proven it will audit for years. The municipalities won on proof, not on compliance. That's not a playbook you want to rely on.
If you want to see all your traffic and skip the whole question: use analytics that doesn't touch the visitor's device and doesn't send data to the US. No cookies means no consent banner for analytics, no Safari throttling, no DPF dependency, and nothing for a future ruling to break. A whole ecosystem of European alternatives exists for exactly this, and here's how the cookieless approach works under the hood.
A closing note, because this is a legal topic: I'm not a lawyer and this article isn't legal advice. It's a founder's map of the terrain, with every claim linked to the decision or report it came from. If your setup is complicated, show this to your DPO or lawyer. And if you're weighing an Icelandic analytics decision and something here doesn't match what you're seeing, email me.
If you'd rather stop reading court dockets to keep your analytics legal, you can try Clickport free for 30 days. And switching from Google Analytics takes one snippet, so the move is smaller than the research you just did.

Comments
Loading comments...
Leave a comment