Privacy policy.
In the operations of SIF Lögmenn slf., strong emphasis is placed on data and information protection. The firm seeks to ensure the reliability, confidentiality and security of the personal data processed in its operations. Below you will find information on what personal data is collected in the firm's operations, how it is obtained and for what reasons, how it is used, and who has access to it. It also explains how the retention and processing of personal data by the firm complies with the Icelandic Act on Data Protection and the Processing of Personal Data No. 90/2018 (the Data Protection Act) and Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (the General Data Protection Regulation).
1. What is personal data?
Personal data means any information relating to an identified or identifiable natural person. This includes information that can be traced directly or indirectly to a particular individual. Data that cannot be linked to an individual is not considered personal data.
2. Responsibility and processing of personal data
SIF Lögmenn slf. is the controller when a decision is taken on its behalf as to how particular personal data provided to it on the basis of its operations is to be processed. Where the firm is entrusted with the processing of personal data on behalf of others, the firm may be regarded as a processor of that personal data on the basis of a data processing agreement with the controller. If information is shared with service providers (third parties) in the firm's operations, such sharing and processing takes place on the basis of a data processing agreement, and the firm then remains the controller itself.
3. What personal data is collected and where does it come from?
SIF Lögmenn slf. collects various necessary personal data about its clients and their contacts in order to be able to provide the relevant services. Different personal data may be collected depending on whether the data subject is themselves in a business relationship with the firm or acts on behalf of another party, including a legal entity, in a business relationship with the firm. The information processed on behalf of the firm concerning parties in a business relationship with the firm and their contacts includes, for example: - Names, national ID numbers, address or place of residence, telephone number, email address or other contact information - Photographs, audio and/or video recordings - Billing information, including VAT numbers and special invoicing requests - Information from communications - Sensitive personal data where the processing is necessary for the firm's operations, i.e. information on racial or ethnic origin, political opinions, religion, philosophical beliefs or trade union membership, health data, information on sex life or sexual orientation, genetic data and biometric data The information processed on behalf of the firm concerning parties who contact the firm and their contacts includes, for example: - Names, national ID numbers, address or place of residence, telephone number, email address or other contact information - Information from communications The firm may also collect and process other information that clients themselves provide to the firm, together with information that is necessary for the firm's operations. As a general rule, information is obtained directly from the client or their contact. Information may, however, also come from third parties, for example public authorities, courts, service providers, counterparties, online databases, websites and other such sources.
4. What is the purpose of collecting and processing the information?
The collection and processing of personal data by SIF Lögmenn slf. takes place primarily in order to be able to perform service agreements with the firm's clients in a satisfactory manner and to fulfil other obligations arising from them. Processing may also take place on the basis of a legal obligation, independently of the services the firm has undertaken to provide to a client, for example under anti-money laundering rules or accounting obligations.
5. How and for how long is information retained?
In the operations of SIF Lögmenn slf., personal data is retained securely and in accordance with applicable laws and rules. Appropriate technical and organisational measures are taken to protect personal data, taking into account its nature, with the aim of ensuring its retention and preventing unauthorised access to it, copying, use or disclosure. Examples of such security measures include access controls in the firm's systems. In the firm's operations, personal data is retained only for as long as is necessary to achieve the purpose of its collection and retention. Information is not retained in personally identifiable form for longer than is necessary. Information falling under the Icelandic Bookkeeping Act is retained for 7 years from the end of the relevant financial year. Information relating to actual legal services provided by the firm may be retained for longer where its processing may prove necessary to establish, exercise or defend legal claims, in which case the retention period is generally based on the limitation period for claims.
6. Is information shared with third parties?
In the operations of SIF Lögmenn slf., personal data is not shared with third parties without the unambiguous consent of the data subject or in order to fulfil obligations under a contract or law. The firm may also share personal data with third parties that provide the firm with information technology services or other services relating to the processing or retention of the information in its operations. This takes place on the basis of a data processing agreement, subject to conditions regarding confidentiality and the security of the information and in compliance with the rules of data protection legislation. A third party may be located outside Iceland. The firm will not transfer personal data to third parties outside the EEA unless permitted under the relevant data protection legislation.
7. What rights do I have?
A data subject is, as applicable, entitled to the following in connection with the retention and processing of personal data concerning them by SIF Lögmenn slf.: - Confirmation of processing - Access and, in certain cases, a copy - Information about the arrangements for processing - Transfer to a third party in certain circumstances - To request rectification, erasure or restriction of processing - To object to processing - Withdrawal of consent The above rights of data subjects are not absolute. Thus, legislation may oblige the firm to refuse a request for erasure or access to data. The firm may also refuse a request from a data subject on the basis of the rights of the firm or of other parties where the firm considers those rights to outweigh the request. Should circumstances arise in which the firm cannot accede to a request from a data subject as set out above, the firm will endeavour to explain the reasons for this, taking into account limitations based on legal obligations. If a data subject wishes to obtain further information about the above rights, exercise them, or raise questions regarding this privacy policy or how the firm processes personal data concerning them, they are advised to contact the firm's data protection officer as set out in section 8 of this policy. If a data subject considers that the firm has not respected their rights in its handling of personal data, they may submit a complaint to the Icelandic Data Protection Authority (Persónuvernd).
8. Data protection officer
SIF Lögmenn slf. has appointed a person responsible for monitoring compliance with this privacy policy:
Dagný Sif Sigurbjörnsdóttir, attorney, dagny@siflogmenn.is.
If you are unsure how this policy applies to you, please contact the data protection officer for
further information.
9. Review and amendments
SIF Lögmenn slf. reserves the right to amend this privacy policy in order to ensure that it meets the requirements of the Data Protection Act and the General Data Protection Regulation. All amendments to the policy take effect upon publication of an updated version on the firm's website.
Last updated: 14 September 2026.