Straumurinn X-Road
Terms of Service of the Straumurinn (X-Road)
General
Digital Iceland, on behalf of the Ministry of Finance and Economic Affairs, is the operator of Straumurinn. Straumurinn, which is based on X-Road, is a data exchange layer for secure communication between information systems and is subject to the central governance of the Operator. This governance includes evaluating and approving Service Recipients’ applications for membership of Straumurinn and establishing rules and criteria for its use. The Operator also maintains a Central Server and issues authentication certificates for Service Recipients’ Security Servers.
Each Service Recipient operates its own Security Server for authenticated and encrypted communication within Straumurinn. The Operator’s Central Server verifies connections, facilitates encrypted communication between parties, and records the timing of and responses to communication requests.
These Terms constitute an agreement between the Service Recipient and the Operator regarding quality requirements, access and maintenance in connection with the use of Straumurinn.
1. Definitions
In these Terms, where the context so permits, the following terms shall have the meanings set out below:
Audit Log: A chronological record of actions carried out in connection with data processing.
Operator: Digital Iceland, acting on behalf of the Ministry of Finance and Economic Affairs.
Certificate: An electronic authentication certificate issued by the Operator to a Service Recipient, which installs and renews the certificate before it expires.
Registry: A central registry of Straumurinn members, their subsystems and Security Servers.
Straumurinn: A data exchange layer for secure and traceable electronic communication between Service Recipients. Straumurinn is based, among other things, on the X-Road solution.
Technical Documentation: The current technical and security guidance for Straumurinn, available at docs.devland.is.
Data Exchange: The transfer of data from an Information Provider to an Information Recipient.
Central Server: A server that maintains the registration of members, subsystems and Security Servers and publishes signed central configuration and trust information. Data is exchanged directly between the parties’ Security Servers and does not pass through the Central Server.
Service Recipient: A party whose connection to Straumurinn has been approved and which acts as an Information Provider, an Information Recipient, or both.
Web Service: A Service Recipient’s service that connects its Security Server to the relevant information system.
Service: The exchange of information.
Information Provider: A Service Recipient that provides information to members of Straumurinn.
Information Recipient: A Service Recipient that retrieves information from an Information Provider through Straumurinn.
Security Server: One or more X-Road servers operated by a Service Recipient that connect to other Security Servers within Straumurinn with the assistance of Straumurinn’s Central Server.
X-Road: Open-source software developed by the Nordic Institute for Interoperability Solutions (NIIS). X-Road is a centrally managed data exchange layer for information systems and comprises both a technical environment and an organisational framework that ensures secure data exchange between information systems.
2. Access
A Service Recipient shall apply to the Operator for membership of Straumurinn. By submitting an application, the Service Recipient agrees to be bound by these Terms.
The Operator may reject an application for access to Straumurinn if the Operator considers, among other things, that the nature of the applicant’s activities is inconsistent with the scope or purpose of Straumurinn or that the applicant does not have sufficient technical infrastructure to use Straumurinn. The applicant may withdraw its application without providing a reason.
Once the parties have agreed that the Service Recipient may access Straumurinn, the Service Recipient shall install a Security Server and notify the Operator, which shall register the Security Server in Straumurinn’s central Registry.
Once the Service Recipient has installed a Security Server, it shall request the necessary certificates from the Operator so that requests sent to and from the Security Server can be authenticated. Straumurinn may not be used with certificates other than those issued by the Operator. Identifiers and information relating to members, subsystems and Security Servers shall be recorded in Straumurinn’s central Registry.
3. Members' responsibilities
3.1 Central Operator
The Operator shall ensure the functionality of Straumurinn’s central components and shall be responsible for their operation. The Operator shall maintain a Registry of Service Recipients, subsystems and Security Servers, publish central configuration and maintain Straumurinn’s common trust framework. The Operator shall also provide common monitoring and support for the central components, as further specified in the Technical Documentation.
The Operator shall not have access to the content of data exchanged between Service Recipients unless such processing has been agreed separately. The Operator is not responsible for monitoring or operating the Web Services or backend systems of individual Service Recipients.
The Operator shall notify Service Recipients of planned changes or restrictions affecting the use of Straumurinn as soon as reasonably possible. The Operator shall define and publish maintenance windows for minor maintenance and shall provide Service Recipients with reasonable advance notice of larger updates that may cause a service interruption.
3.2 Service recipient
The Service Recipient shall install a Security Server and register the Security Server and the necessary certificates with the Operator.
The Service Recipient shall monitor and ensure that the information held about it by the Operator is correct at all times. The Service Recipient shall follow all instructions issued by the Operator concerning the installation and use of Straumurinn and applicable security measures, as specified in the Technical Documentation.
The Service Recipient is responsible for updating its Security Server. The Security Server shall at all times run a version of X-Road supported by NIIS. Within the same major version, the Security Server may be no more than two minor versions behind the version used by Straumurinn’s central servers. The Service Recipient shall use the latest supported patch version within the minor version that it operates.
The Service Recipient is responsible for updating its Security Server. The X-Road version of the Security Server shall never be more than two versions behind the version of the Central Server.
The Service Recipient is responsible for renewing its certificates and shall renew them at least once every two years.
The Service Recipient is responsible for the use of its Security Server.
The Service Recipient shall maintain an Audit Log. The Service Recipient shall appoint a service representative who has access to the Audit Log and monitors the Service Recipient’s use of and communication through Straumurinn.
The Service Recipient shall implement the necessary physical and technical security measures to ensure the security of its information systems. Such security measures shall take account of internationally recognised best practices.
When using Straumurinn as an Information Provider, the Service Recipient is responsible for ensuring:
(i) that information is provided only in response to a request or under an applicable agreement;
(ii) that the scope of the information provided is consistent with the applicable data description;
(iii) that the Service Recipient is authorised to provide the information concerned.
The Service Recipient is responsible for ensuring that it is authorised to retrieve the information concerned, that access controls within its own systems are adequate and that its processing of the information following receipt complies with the laws applicable at any given time.
3.2.1 Third party - subcontractor
If a Service Recipient contracts with a third party for the operation of a Security Server or for access to X-Road as a service, the Service Recipient shall ensure that the third party is familiar with and acts in accordance with these Terms. The Service Recipient shall notify the Operator of changes to its operating arrangements resulting from an agreement with a third party at least 30 days in advance. If a change is necessary because of an urgent security incident, it shall be reported as soon as possible.
An agreement with a third party shall be made in writing and shall clearly define the parties’ roles and obligations in relation to Straumurinn. The agreement shall clearly specify the services provided to the Service Recipient and the systems and equipment used in connection with Straumurinn.
Notwithstanding any outsourcing under this provision, the Service Recipient shall remain responsible for ensuring compliance with these Terms and Straumurinn’s minimum requirements.
4. Functional tests and/or the provision of services
The timing of functional tests and/or the issuance of service in the production environment on Ísland.is is organized in cooperation between the service provider and the relevant service recipient, but shall not take place on Fridays, on weekends or on public holidays.
5. Responsibility
The Operator shall not be liable for damage resulting from a Service Recipient’s lack of knowledge, misunderstanding or misuse. The Operator shall furthermore not be liable for damage caused by the failure of the Service Recipient’s equipment to operate correctly.
The Operator shall not be liable for damage resulting from unauthorised use, including where an unauthorised party has gained access to the Service Recipient’s account or where the Operator has not been notified of misuse or suspected misuse of a Web Service.
The Operator shall not be directly or indirectly liable for damage resulting from the unplanned suspension of Straumurinn, including failures attributable to a loss of connectivity, disruption of telecommunications or other interruptions affecting the operation of a Web Service that are unforeseeable or unavoidable because of circumstances beyond the Operator’s control (force majeure). If errors, interruptions or delays in Straumurinn result from such circumstances, the Operator’s responsibility shall be limited to rectifying them as soon as reasonably possible.
The Operator shall only be liable for damage suffered by a Service Recipient where such damage is attributable to wilful misconduct or gross negligence by the Operator’s employees. In such cases, the Operator’s liability shall be limited to direct damage and shall not extend to indirect or consequential damage, such as business interruption, loss of business or reputational damage.
The Service Recipient shall indemnify and hold the Operator harmless against any damage, claims by recipients, proceedings, liabilities, fines, penalties and costs, including legal costs, incurred by the Operator as a result of or in connection with the acts or omissions of the Service Recipient, whether arising from negligence, wilful misconduct or other fault in connection with the use of Straumurinn or from a breach of the agreement between the parties. This indemnity shall not limit any other contractual or statutory rights available to the Operator against the Service Recipient. The payment of compensation or an indemnity shall not justify or remedy a breach of the Service Recipient’s duties and obligations.
Liability for damage resulting from breaches of Act No. 90/2018 on Data Protection and the Processing of Personal Data shall be governed by Article 51 of that Act and Article 82 of Regulation (EU) 2016/679 of the European Parliament and of the Council, as amended from time to time.
6. Payments
Digital Iceland’s services relating to the operation of the Central Server within Straumurinn, the certificate service provided by the Operator and the X-Road software shall be available to Service Recipients free of charge. Each Service Recipient shall bear the costs of its own Security Server, hosting, operations, integrations and third-party services.
7. Operational security
The parties undertake to contribute to the secure operation of Straumurinn and to work together to resolve operational disruptions.
The Service Recipient and the Operator shall notify each other without delay if there is reason to suspect accidental, unauthorised or unlawful processing of information or any security breach affecting information exchanged through Straumurinn. The notification shall be sent to the relevant party’s general email address. In the case of the Operator, the notification shall be sent to island@island.is. The notification shall describe the nature of the breach, including the estimated number of data subjects affected and the relevant use of the information. The notifying party shall also describe the likely consequences of the breach and the measures it has taken or intends to take in response.
The Operator shall notify the Service Recipient of failures or necessary updates affecting Straumurinn. If Straumurinn becomes unavailable because of circumstances beyond the Operator’s control, the Operator shall also notify the Service Recipient. The Operator generally provides its services during normal office hours, but if connectivity to Straumurinn is interrupted, the Operator shall respond to the notification as soon as possible.
The Operator may temporarily suspend a Service Recipient’s access to the Service without prior notice if there is reasonable suspicion of unauthorised processing, a security breach or if the Operator considers it clear that the Service Recipient’s equipment does not comply with the Operator’s requirements for the use of Straumurinn.
If the Operator or a Service Recipient encounters circumstances beyond its reasonable control that prevent it from fulfilling its obligations to the other party under the agreement, the affected obligations shall be suspended for as long as those circumstances continue and until the parties are able to fulfil their agreed obligations.
8. Amendments to the terms
The Operator reserves the unilateral right to amend these Terms. Amendments shall be notified electronically to the Service Recipient at least 30 days before new or amended provisions take effect. The notification shall be delivered in a verifiable manner. New or amended Terms shall also be published on the Operator’s website.
The Operator may, however, amend the Terms on shorter notice if the amendments are required by law or because of a risk of a security breach. Where a shorter notice period applies, the Operator shall endeavour to notify the amendments as soon as possible.
These terms were last updated: 16.09.2029
This text was translated from Icelandic using a machine translation. Be advised that content generated by machine translation can be inaccurate or flawed.
