# Iceland

> Iceland (Seðlabanki Íslands · EFTA Surveillance Authority · Persónuvernd): MiCA a year late, the travel rule not yet switched on. Region: Europe. Confidential with disclosure: Confidentiality is workable so long as the regulated firm can identify the parties and disclose on demand. Encrypted amounts are not the thing being restricted.

Part of the Soda Labs Privacy Hub regulation map, which reads the instruments
themselves rather than summarising the summaries: https://www.sodalabs.xyz/privacy-hub/regulation

## Key facts

- Entry type: Jurisdiction
- Region: Europe
- Subject: MiCA a year late, the travel rule not yet switched on
- Authority: Seðlabanki Íslands · EFTA Surveillance Authority · Persónuvernd
- Stance on on-chain confidentiality: Confidential with disclosure. Confidentiality is workable so long as the regulated firm can identify the parties and disclose on demand. Encrypted amounts are not the thing being restricted.
- Tags: MiCA late adopter, travel rule gap, AMLR not incorporated, two-pillar supervision
- Canonical page: https://www.sodalabs.xyz/privacy-hub/regulation/jur-iceland

## What it actually says

Iceland is worth a card mainly for what it reveals about the EEA route into EU financial law. It adopted the European crypto framework a full year behind the union, shifting the internal dates forward so the transitional architecture still worked. More consequentially, the two instruments that matter most for confidentiality have arrived at different speeds. The travel rule was incorporated into the EEA agreement in June 2025 but the government's own database still records implementation as not begun, so the obligation exists in principle without national machinery. The EU anti-money-laundering regulation, which carries the 2027 prohibition on anonymous accounts, has not been incorporated at all. For now the binding rule here is the narrower trading-platform test.

## The instruments that matter

- **Act No. 101/2025 on markets in crypto-assets, 24 December 2025**: Article 16 brings it into force on 1 January 2026, a year behind the EU
- **Dates shifted to preserve the transition**: MiCA references to 30 December 2024 read as 1 January 2026, and references to 30 July 2024 read as 1 February 2026
- **Article 3 names the authorities**: the Central Bank of Iceland is the competent authority, with the financial supervisory function inside it and the EFTA Surveillance Authority exercising the powers MiCA gives ESMA
- **The travel rule is incorporated but not implemented**: the EU transfer of funds regulation entered into force through the EEA on 24 June 2025, yet the government's own EEA database records implementation as not begun, with a national regulation still required
- **The EU anti-money-laundering regulation is not incorporated**: it remains under examination by Iceland, Liechtenstein and Norway, so the EU prohibition on anonymous crypto accounts does not currently reach them

## Sources

- [Act No. 101/2025](https://www.althingi.is/lagas/nuna/2025101.html)
- [Icelandic EEA database entry for MiCA](https://gagnagrunnur.ees.is/32023r1114)

## Related entries

- [Austria](https://www.sodalabs.xyz/privacy-hub/regulation/jur-austria): EU baseline, with an early transition close
- [Belgium](https://www.sodalabs.xyz/privacy-hub/regulation/jur-belgium): EU baseline, with no national layer on confidentiality
- [Czechia](https://www.sodalabs.xyz/privacy-hub/regulation/jur-czechia): EU baseline, supervised by the central bank
- [Denmark](https://www.sodalabs.xyz/privacy-hub/regulation/jur-denmark): EU baseline, with tax as the historic pressure point
- [Estonia](https://www.sodalabs.xyz/privacy-hub/regulation/jur-estonia): The licence cull that reshaped the European market
- [France](https://www.sodalabs.xyz/privacy-hub/regulation/jur-france): Hardest against anonymity, most literate about privacy tech
