Policy of the Central Bank of Iceland regarding the processing of personal data
1. General
The objective of the Central Bank of Iceland is to conduct the processing of personal data on behalf of the bank in accordance with the fundamental principles and rules regarding personal data protection and privacy. The Central Bank is responsible for monitoring that the processing of personal data complies with laws and regulations and for taking appropriate measures to ensure it is done.
This Personal Data Protection Policy is founded on the provisions of Act no. 90/2018 on Data Protection and the Processing of Personal Data and on the provisions of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data.
This Personal Data Protection Policy applies to all of the Central Bank’s processing of personal data and covers all natural persons whose personal data may be processed by the bank, including employees of customers and regulated entities, consultants or contractors who work for or on behalf of the bank, parties that have any kind of contact with the bank, visit it or its website, as well as employees of the bank itself, etc.
The policy applies both to personal data that individuals have provided to the Central Bank, and to personal data acquired by the Bank from third parties. Personal data on natural persons can be stored electronically or on paper, but the Personal Data Protection Policy applies equally to the electronic and manual processing of personal data.
This Personal Data Protection Policy only applies to natural persons and not to legal entities.
2. Processing in accordance with the fundamental principles and rules on personal data protection
Personal data is to be understood as any data that can be used to identify individuals directly or indirectly. The processing of personal data refers to an operation or set of operations which are performed on personal data, whether or not by automated means, such as the collection, registration, storage, transmission and dissemination of data or other methods used to make data available, or connect, combine, restrict or erase them.
The Central Bank places emphasis on processing personal data with care and ensuring that it is reliable and accurate.
In most cases, the Central Bank is considered to be the Controller in accordance with Act no. 90/2018 when it comes to the processing of personal data. This means that in most cases the Central Bank determines, alone or in consultation with others, in most cases the Processor, the purposes and methods applied to the processing of personal data.
The Central Bank receives data and information from both individuals themselves and external parties, e.g. public authorities, regulatory bodies, the bank's customers, regulated entities, etc., for its processing of personal data, and the information is received either by regular mail, e-mail, by telephone, through IT systems, the bank's web portals, etc.
The Central Bank makes every effort to uphold the principles of Act no. 90/2018:
The rule of law: personal data must be processed in a lawful, fair and transparent manner in relation to the data subject.
The purpose principle: personal data must be collected for specified, explicit, legitimate and objective purposes and not be further processed in a manner that is incompatible with those purposes.
The principle of proportionality: personal data shall be sufficient, relevant and not exceed what is necessary for the purpose of the processing.
The principle of reliability: personal data must be reliable and updated as necessary.
The principle of conservation: personal data must be stored in such a way that it is not possible to identify data subjects for longer than is necessary based on the purpose of processing.
The principle of security: personal data must be processed in such a way that the appropriate security of the personal data is ensured.
Moreover, as the Controller, the bank must always be able to demonstrate that its processing of personal data meets the requirements of Act no. 90/2018.
3. Tasks of the Central Bank that entail the processing of personal data:
Pursuant to Act no. 92/2019 on the Central Bank of Iceland, the bank shall, among other things, promote price stability, financial stability and sound and secure financial activities. The bank shall also undertake tasks consistent with its role as central bank, such as maintaining currency reserves and promoting an efficient and sound financial system, including domestic and cross-border payment intermediation. The execution of these statutory tasks of the Central Bank requires some processing of personal data, including the reception, storage, analysis and processing of data. However, this processing shall never exceed what is considered necessary and appropriate for the purpose of the processing.
The processing of personal data may also entail monitoring and follow-up by the Central Bank on the basis of Act no. 92/2019, Foreign Exchange Act no. 70/2021, Act No. 87/1998 on the Official Supervision of Financial Activities, Act no. 161/2002 on Financial Undertakings and rules issued on the basis thereof.
Other tasks of the Central Bank which may entail the processing of personal data, are the reception and processing of issues that have been submitted to it, communication with the Central Bank's customers, regulated entities and public authorities, the recording of phone calls for business and security reasons, surveillance cameras used by security guards, recruitment processes, registration of external parties on the bank’s mailing list, use of social media and web tracking, etc.
The Central Bank processes certain personal data on its employees, i.a. in connection with the conclusion of employment contracts, salary processing, the presence of employees on the premises, the management of access to the bank's premises, compliance, the recording of phone calls and video surveillance, cf. above, operation of the intranet, online security, storage of e-mails and chats, operation of employees’ mobile devices, career development and retirement.
4. Technical measures and security
The Central Bank places a great deal of emphasis on security in the processing of personal data and takes appropriate technical and operational measures that take into account the nature, scope, context and purpose of the processing and the risk to the rights and freedoms of data subjects to ensure and demonstrate that the processing of personal data meets the requirements of the law. These measures pertain to, among other things, data security and stability in the operation of online and IT systems at the bank.
The Central Bank ensures that the bank's processing of personal data, including its storage and other safekeeping, is in accordance with the provisions of Act no. 90/2018. Personal data is either stored in the bank's IT systems, hosted by service providers, on paper in locked filing cabinets, on the bank's mail servers and databases, or on tapes for backup.
5. Transfer of personal data to third parties
The Central Bank does not provide personal data to third parties, e.g. public authorities, regulators, law enforcement authorities, the bank's customers, regulated entities, processors in the bank's service or others except in exceptional cases when the bank deems it necessary and has the right to do so, i.a. for the purpose of responding to requests and inquiries, to protect and secure the activities of the Central Bank and to carry out supervision in accordance with the law.
In connection with the employment agreement between the Central Bank and employees, it is necessary for the bank to share some personal information about employees with third parties, e.g. the commercial banks of employees, trade unions and pension funds.
The Central Bank neither shares nor sells personal data to third parties for marketing-related purposes.
6. Individual rights
7. Custody of personal data
8. Confidentiality and non-disclosure obligations
9. Data Protection Officer
10. Cooperation with the Data Protection Authority
11. Amendments to the data protection policy
The Central Bank reserves all rights to make amendments to this privacy policy as needed.
Amendments to this data protection policy must be advertised separately on the Central Bank's website (www.sedlabanki.is) and also on the intranet of the bank's employees.