Ali Zuweid's Political Programme
Personal Data Protection and Digital Privacy Law
A proposed law establishing a comprehensive Iraqi framework for personal data processing, translating the constitutional right to privacy into rights, duties and oversight and enforcement mechanisms applicable to the State, private sector and digital environment.
Executive summary
Iraq has a clear constitutional basis for privacy protection: Article (17) recognises individual personal privacy, while Article (40) guarantees communications and correspondence confidentiality, permitting monitoring, interception or disclosure only for legal and security necessity and by judicial decision. Yet this foundation does not itself define data life-cycle rules, rights of access, rectification, erasure and objection, controller and processor responsibilities, or a general system for breach notification, international transfers or independent oversight.
As of preparation of this document, available official sources have not established the existence of a comprehensive federal personal data protection law in force. Fragmented rules have nevertheless emerged: Electronic Signature and Electronic Transactions Law No. (78) of 2012 and its 2025 implementing instructions, E-Commerce Regulation No. (4) of 2025, and Communications and Media Commission regulations and policies concerning user and data protection on digital platforms, .iq domains and fifth-generation networks. This sectoral development is useful but does not replace a unified general framework.
The proposal adopts a risk-based approach: it establishes lawfulness, transparency, data minimisation and accountability principles; six principal processing grounds; enhanced protection for sensitive, children's and biometric data; practical individual rights; safeguards for automated decisions, profiling and digital tracking; and duties concerning security, breach notification, impact assessment and data protection officers.
Institutionally, it creates an independent federal data protection and digital privacy authority. Independence is justified by protection extending beyond telecommunications into health, employment, banking, elections, identity and government services. Assigning the task to a sectoral body that is also a regulator, operator or beneficiary of data flows is therefore insufficient.
International transfers are addressed through adequacy, contractual safeguards and narrow exceptions rather than blanket prohibition or absolute localisation. Localisation may be imposed on specific sovereign or security-related categories where necessity and proportionality are demonstrated. The aim is to protect rights without isolating Iraq's digital economy or unjustifiably increasing service costs.
First — Constitutional and legal context
The proposal rests on personal privacy under Article (17) of the Constitution and communications and correspondence confidentiality under Article (40). Iraq has also been a party to the International Covenant on Civil and Political Rights since 1971. Article (17) of the Covenant protects individuals against arbitrary or unlawful interference with privacy, family, home or correspondence and unlawful attacks on honour and reputation.
Within the existing digital framework, Electronic Signature and Electronic Transactions Law No. (78) of 2012 provides legal recognition of electronic transactions within its scope, and the Ministry of Justice issued implementing instructions in 2025. E-Commerce Regulation No. (4) of 2025 was also published. In sectoral regulation, the Communications and Media Commission issued rules for digital platforms and services, a policy protecting registration data for .iq domain names, and fifth-generation network requirements containing privacy and data security provisions.
Taken together, these texts do not establish a unified general system for data subject rights, controller and processor liability, breach notification, international transfers or independent oversight. The proposal therefore addresses a horizontal legislative gap without replacing more specialised sectoral rules that provide greater protection and are compatible with it.
Second — Legislative gap and proposed policy
| Gap | Legislative solution |
|---|---|
| A general constitutional right without detailed operational rights | Rights of access, rectification, erasure, restriction, portability, objection, complaint and compensation. |
| Fragmented sectoral rules | A single horizontal law establishing common minimum standards while retaining more protective sectoral rules. |
| Expansion of government and biometric databases | Purpose limitation, data minimisation, access logs, impact assessments and controls on database linkage. |
| No general data breach rule | Notify the authority within 72 hours where risk exists, and individuals where risk is high. |
| Algorithmic decisions and profiling | Rights to human intervention, objection, transparency about influential factors and protection against discrimination. |
| International transfers lacking horizontal regulation | Adequacy, contractual safeguards, narrow exceptions and proportionate localisation for sovereign categories. |
| No specialised independent cross-sector supervisory body | A federal data protection and digital privacy authority with investigative, corrective and enforcement powers. |
Third — Draft Personal Data Protection and Digital Privacy Law
Enactment formula
In the name of the people
Presidency of the Republic
Pursuant to the enactment of the Council of Representatives and ratification by the President of the Republic, and under item (First) of Article (61) and item (Third) of Article (73) of the Constitution, the following Law is issued:
Law No. ( ) of ( ) — Personal Data Protection and Digital Privacy Law
Chapter One — General provisions
Article (1) — Definitions
For the purposes of this Law, the following words and expressions shall have the meanings assigned to them, unless the context otherwise requires:
- Personal data: Any information, regardless of form or source, relating to an identified natural person or one identifiable directly or indirectly, alone or combined with other information reasonably likely to be available.
- Sensitive personal data: Data whose use or misuse presents high risks to rights and freedoms, including in particular health, genetic and biometric data used for unique identification, political opinions and affiliations, religious or philosophical beliefs, trade union membership, sex life, criminal records, highly sensitive financial verification data and any other category specified by law.
- Processing: Any operation or set of operations performed on personal data by automated or non-automated means, including collection, recording, organisation, classification, storage, alteration, retrieval, consultation, use, linkage, disclosure, transfer, publication, restriction, erasure and destruction.
- Data subject: The natural person to whom personal data relate.
- Controller: A public or private natural or legal person determining, alone or jointly, the purposes and essential means of processing.
- Processor: A natural or legal person processing personal data on behalf of and on the instructions of a controller.
- Recipient: Any person or body to whom personal data are disclosed, whether or not a third party. A public body receiving data in a specific lawful investigation shall not thereby alone be regarded as a separate recipient.
- Consent: A freely given, specific, informed, clear and unambiguous indication of a data subject's wishes, expressed by demonstrable affirmative action and withdrawable as easily as it was given.
- Breach: Any security incident resulting in accidental or unlawful destruction, loss, alteration, unauthorised disclosure of or access to personal data.
- Anonymisation: Processing that makes data incapable of association with an identified or identifiable person by means reasonably likely to be used, in a manner practically irreversible.
- Pseudonymisation: Processing data so that they can no longer be attributed to a specific person without additional information kept separately and subject to technical and organisational safeguards.
- Profiling: Any automated processing intended to evaluate personal aspects of an individual, particularly work performance, economic situation, health, preferences, interests, reliability, behaviour, location or movements.
- Automated decision: A decision resulting entirely from automated processing, including profiling, producing legal or similarly significant effects on the data subject.
- Public body: Ministries, bodies not affiliated with a ministry, independent authorities, public companies, local authorities and any person entrusted by law or contract with a public function or service, within the scope of that function or service.
- Authority: The Federal Personal Data Protection and Digital Privacy Authority established under this Law.
- Data protection officer: A qualified, functionally independent person assigned to monitor an entity's compliance with this Law and liaise with the Authority and data subjects.
- Large-scale processing: Processing whose volume, geographical scope, number of data subjects, duration or sensitivity makes its potential effects significant, under criteria issued by the Authority.
- Digital tracking: Collection or linkage of device identifiers, cookies, technical fingerprints, location or behaviour for identification, analysis, advertising or measurement beyond what is technically necessary to provide a user-requested service.
Article (2) — Objectives
This Law aims to protect individual dignity and privacy; regulate personal data processing according to lawfulness, necessity and proportionality; give individuals practical, enforceable rights; strengthen trust in government services and the digital economy; harmonise minimum duties for public and private bodies; and ensure lawful, secure data flows within and across Iraq's borders without turning data protection into an instrument of surveillance, obstruction of innovation or restriction of lawful public information.
Article (3) — Territorial and material scope
First — This Law applies to personal data processing by a controller or processor established in the Republic of Iraq, wherever the processing actually occurs.
Second — It applies to controllers or processors not established in Iraq where processing relates to offering goods or services to persons in Iraq, monitoring their behaviour within Iraq, or regularly processing their data in activities substantially directed at the Iraqi market.
Third — It applies to automated processing and to non-automated processing where data form or are intended to form part of a structured filing system.
Fourth — Application shall respect the constitutional distribution of powers between federal, regional and governorate authorities. It shall directly bind authorities and entities subject to federal competence and processing related to federal powers. No local or regional regulation may fall below constitutional privacy safeguards.
Article (4) — Exemptions and their limits
First — This Law does not apply to a natural person's processing within purely personal or household activities unrelated to professional or commercial activities and not making data available to an indefinite public.
Second — Genuinely anonymised data are not personal data. Pseudonymised data remain subject to this Law where they can be linked back to the person.
Third — This Law creates no new power to intercept or monitor communications, search devices or covertly access data. Such measures remain subject to the Constitution, specific laws and required judicial oversight.
Fourth — No general exemption for a body or sector may be created by administrative decision. Every restriction of data subject rights must rest on a specific legal provision respecting necessity, proportionality and safeguards.
Article (5) — Processing principles
Controllers and processors, according to their roles, shall observe lawfulness, fairness and transparency; purpose limitation and prohibition of incompatible use; data minimisation; accuracy and updating; storage limitation; integrity and confidentiality; accountability and demonstrability; data protection by design and by default; and prevention of discrimination or unlawful harm from processing. Controllers shall demonstrate compliance with these principles.
Chapter Two — Lawful processing and sensitive data
Article (6) — Legal bases for processing
Personal data processing shall be lawful if based on at least one of the following grounds and limited to what that ground requires:
- The data subject's consent.
- Performance of a contract to which the data subject is a party or steps taken at their request before entering it.
- Compliance with a legal obligation binding the controller.
- Protection of the vital interests of the data subject or another person where a suitable basis cannot be relied upon in time.
- Performance of a public-interest task or exercise of official authority established by law.
- Pursuit of a controller's or third party's legitimate interest, balanced against the data subject's rights and reasonable expectations. Public bodies shall not rely on this ground when performing official duties.
The legal basis shall be identified and documented before processing begins and shall not be changed retrospectively to justify unlawful processing.
Article (7) — Conditions for consent
First — Consent shall be separate from conditions unnecessary to provide the service, expressed in clear, accessible language, and distinguishable from other matters.
Second — Consent shall not be freely given where contract performance or service provision is conditional on unnecessary processing, or a power imbalance makes refusal unrealistic, particularly in employment or public authority relationships, unless safeguards ensure genuinely free choice.
Third — The controller bears the burden of proving consent. Data subjects may withdraw it at any time without affecting the lawfulness of earlier processing.
Article (8) — Sensitive personal data
First — Sensitive personal data processing is prohibited unless one of the following applies with appropriate safeguards: explicit consent; a duty or right under employment or social security law; protection of a vital interest; lawful activities of a non-profit association or foundation concerning its members; data manifestly made public by the subject; establishment, exercise or defence of legal claims; a substantial public interest defined by law; healthcare or health-system management by professionals bound by confidentiality; public health; or public-interest archiving, scientific or historical research or statistics with minimisation and pseudonymisation safeguards.
Second — The Authority shall not create a new sensitive category merely through administrative expansion. Its role is limited to interpreting statutory categories and proposing legislative amendment where necessary.
Article (9) — Children's and minors' data
First — Information about processing a child's or minor's data shall be worded appropriately to their age and understanding.
Second — Where consent is the basis for processing data of a minor lacking full legal capacity, consent shall be obtained from their legal representative under applicable laws, taking account of the minor's views, maturity and best interests.
Third — Commercial advertising profiling of minors using sensitive data or extended behavioural tracking is prohibited, as is interface design exploiting their vulnerability to induce excessive disclosure.
Fourth — Child protection shall be ensured without age verification causing excessive collection of identity or biometric data.
Article (10) — Public-body processing
First — Public-body processing shall rest on clear legal competence and a defined public purpose. Administrative convenience or a desire to aggregate data is insufficient.
Second — Public bodies shall document data sources, uses, legal bases, retention periods and sharing recipients, publishing what can be disclosed in a public processing register without revealing legitimate secrets or security risks.
Third — Citizens shall not be required to provide identical data to multiple public bodies where lawful, secure exchange is possible, provided that the 'once-only' principle does not become blanket permission for unspecified database exchanges.
Article (11) — National identifiers and biometric data
First — National numbers or unified government identifiers shall not be used beyond legally defined purposes or purposes necessarily and proportionately connected to them.
Second — Establishing a general central biometric database or linking independent biometric databases without specific legislation defining purposes, authorised bodies, retention periods, auditing and appeal mechanisms is prohibited.
Third — Large-scale biometric identification systems shall undergo mandatory impact assessment and prior Authority approval unless regulated by a specific law, subject to national security and law enforcement provisions.
Chapter Three — Transparency and data subject rights
Article (12) — Information when collecting from the subject
When collecting data directly, controllers shall clearly explain their identity and contact details; data protection officer details where appointment is required; processing purposes and legal bases; any legitimate interest relied upon; recipient categories; intended transfers outside Iraq and safeguards; retention periods or criteria; data subject rights; complaint rights; whether provision is mandatory and consequences of refusal; and any automated decision or profiling, with meaningful information about its logic and anticipated effects.
Article (13) — Information when obtaining data elsewhere
Where data are not obtained directly from the subject, the controller shall provide the information under Article (12), data categories and sources within a reasonable period not exceeding thirty days, at first contact or before first disclosure, whichever is earlier. Exceptions apply where the subject already knows the information; notification is impossible or involves disproportionate effort for archiving, research or statistics, with alternative transparency measures; or collection or disclosure is expressly prescribed by law with appropriate safeguards.
Article (14) — Right of access
Data subjects may obtain confirmation of whether their data are processed, a copy of their data, and information on purposes, categories, recipients, retention, rights, sources where not collected directly, and automated decisions and relevant safeguards. Providing copies shall not prejudice others' rights or secrets. Partial redaction may replace total refusal.
Article (15) — Rectification and completion
Data subjects may request correction of inaccurate data and completion of incomplete data. Controllers shall notify recipients of material corrections where possible and reasonable, and identify those recipients to the subject on request.
Article (16) — Right to erasure
Data subjects may request erasure where data are no longer needed for their original purpose; consent is withdrawn with no other legal basis; processing is opposed with no overriding legitimate grounds; processing is unlawful; or erasure is required by law. The right does not apply to the extent processing is necessary for freedom of expression and information, a legal obligation, a public task, public health, safeguarded archiving, research or statistics, or the establishment, exercise or defence of legal claims.
Article (17) — Right to restriction
Data subjects may request restriction while contested accuracy is verified; where processing is unlawful but restriction is preferred to erasure; where the controller no longer needs data but the subject needs them for a legal claim; or pending verification of overriding controller interests following an objection. During restriction, processing other than storage requires consent, a specific legal purpose, protection of another person's rights or a substantial public interest.
Article (18) — Data portability
Where automated processing rests on consent or contract, data subjects may obtain data they provided in a structured, commonly used, machine-readable format and transfer them to another controller where technically feasible without prejudicing others' rights or system integrity. This right does not apply to processing needed for a public task or official authority.
Article (19) — Right to object
Data subjects may object, on grounds specific to their circumstances, to processing based on public or legitimate interests, including related profiling. Controllers shall cease processing unless they demonstrate compelling legitimate grounds overriding the person's rights or necessity for a legal claim. Objection to direct marketing shall be absolute for that purpose.
Article (20) — Direct marketing and digital tracking
First — Direct electronic marketing communications and tracking unnecessary for service provision require a valid legal basis and an easy, cost-free means of refusal.
Second — Storing or reading identifiers on a user's device, including non-essential tracking cookies, requires clear prior consent, except where strictly necessary to transmit communications, provide a requested service or ensure its basic security.
Third — Deceptive design patterns making refusal harder than acceptance or inducing unnecessary data disclosure are prohibited.
Article (21) — Automated decisions and profiling
First — Data subjects shall have the right not to be subject to solely automated decisions, including profiling, producing legal or similarly significant effects, unless necessary for a contract, authorised by a specific law with appropriate safeguards, or based on explicit consent.
Second — In permissible cases, controllers shall ensure effective human intervention, the right to express views, understand principal factors influencing the decision without revealing legitimate secrets, contest the outcome and request reconsideration.
Third — Significant automated decisions based on sensitive data are permitted only in exceptional cases defined by law with enhanced anti-discrimination safeguards.
Article (22) — Rights procedures and deadlines
First — Controllers shall facilitate rights through reasonable electronic and non-electronic channels.
Second — Controllers shall respond within thirty days of receipt. Complex or numerous requests may justify a further thirty days, provided the subject is informed of reasons before the initial period expires.
Third — Exercising rights shall be free. A reasonable actual cost may be charged or a request refused if manifestly excessive in repetition or vexatious, with the burden of proof on the controller.
Fourth — Refusals shall state reasons and the person's rights to complain to the Authority and seek judicial review.
Article (23) — Identity verification and representation
Controllers may request necessary, reasonable additional information to verify requesters' identities without collecting excessive data. Subjects may exercise rights through agents or legal representatives under general rules. Verification shall not be a pretext to obstruct rights or demand a copy of an official document where less intrusive verification is possible.
Chapter Four — Controller and processor obligations
Article (24) — Accountability and controller responsibility
Controllers are responsible for the basis, purpose, scope, retention and security of data and selection of processors capable of compliance. They shall adopt proportionate policies and procedures, document material decisions, train staff, periodically review controls and demonstrate compliance to the Authority on request.
Article (25) — Processing activity records
First — Controllers and processors shall maintain records of their processing activities, specifying purposes, categories of persons, data and recipients, international transfers, retention periods and general security measures.
Second — The Authority may exempt small enterprises from some record requirements where processing is occasional, low-risk and involves neither sensitive data nor regular monitoring, without waiving substantive duties.
Article (26) — Controller–processor relationship
Controllers shall appoint processors only with sufficient safeguards, through contracts or binding legal instruments specifying processing subject matter, duration, nature, purpose, data and person categories and controller rights. Processors shall follow documented instructions, confidentiality and security requirements, subprocessor rules, assist with rights, breaches and impact assessments, delete or return data at service end, and provide what is needed to demonstrate compliance and permit audits.
Article (27) — Joint controllers
Two or more persons jointly determining processing purposes and essential means shall transparently agree in writing on responsibilities, particularly rights, notices and security. Internal arrangements shall not prevent subjects exercising rights against any joint controller to the extent permitted by the nature of shared responsibility.
Article (28) — Protection by design and by default
Before and during processing, controllers shall integrate technical and organisational measures proportionate to risk, cost and the state of technology, including minimisation, pseudonymisation, separation and access controls. Default settings shall limit collection, availability and retention to what each purpose requires; data shall not be available by default to an indefinite number of people.
Article (29) — Data security
Controllers and processors shall adopt risk-appropriate security measures, including as needed encryption, pseudonymisation, identity and access management, logs, backups, recovery, control testing, incident response and supplier and vulnerability management. Appropriate security levels shall account for data nature, volume and context and the effects on individuals of losing confidentiality, integrity or availability.
Article (30) — Breach notification to the Authority
First — Controllers shall notify the Authority of any personal data breach likely to risk individuals' rights and freedoms without undue delay and, where feasible, within seventy-two hours of becoming aware.
Second — Late notification shall include reasons. Notices shall describe the breach, data and person categories and approximate numbers where possible, likely consequences and measures taken or proposed.
Third — Processors shall notify controllers without undue delay. Controllers shall document all breaches so the Authority can verify compliance.
Article (31) — Breach notification to subjects
Where a breach is likely to pose high risk to a subject's rights, controllers shall notify them without undue delay in clear language, describing its nature, likely consequences, measures and available protective steps. Individual notification is unnecessary if measures render data unintelligible to unauthorised persons, the high risk is subsequently removed, or individual notification entails disproportionate effort, in which case effective public communication shall be used.
Article (32) — Data protection impact assessment
Before processing likely to create high risk to individuals' rights, controllers shall conduct a written data protection impact assessment, particularly for systematic large-scale monitoring, large-scale sensitive data processing, new technologies in significant decisions, large-scale linkage of independent databases, remote biometric identification in public places or large-scale children's data processing. Assessments shall describe processing, necessity, proportionality, risks and proposed mitigation measures.
Article (33) — Prior consultation
Where an assessment shows residual high risk that reasonable measures cannot reduce, controllers shall consult the Authority before processing. Within a period specified by regulations, without unjustifiably disrupting public services, the Authority may provide legally bounded binding advice or exercise preventive powers against imminent, serious threats to rights.
Article (34) — Appointing a data protection officer
A data protection officer shall be appointed by public bodies conducting regular processing, except courts exercising judicial functions; entities whose core activities require systematic large-scale monitoring; entities whose core activities involve large-scale sensitive data processing; and other cases identified by the Authority based on risk rather than sector alone. A group may appoint a shared officer effectively accessible to each entity.
Article (35) — Officer independence and duties
Data protection officers shall be involved promptly in protection matters and have resources, access to senior management and professional independence. They shall receive no instructions concerning compliance opinions and suffer no penalty for performing duties. They shall advise, monitor, raise awareness, address impact assessments and cooperate with the Authority. Other duties are permissible without conflicts of interest.
Article (36) — Codes of conduct and certification
The Authority may approve sectoral codes of conduct, certification mechanisms and voluntary compliance seals to help enterprises, especially small and medium-sized ones, implement the Law. Certification or codes shall not exempt liability or prevent investigation or rights exercise. Criteria, withdrawal procedures and scope shall be published.
Chapter Five — Special processing contexts
Article (37) — Video surveillance and remote biometric identification
First — Video surveillance in public places or workplaces shall have a defined lawful purpose and limit coverage, retention and access to what is necessary, with visible notice unless prohibited by law for a legitimate reason.
Second — Large-scale real-time remote biometric identification in publicly accessible places is prohibited except under specific legislation defining serious situations and targeted serious crimes, with prior judicial authorisation wherever possible, limited duration and scope, complete search logging and independent review.
Third — Facial or biometric recognition shall not be used merely to classify persons by sensitive characteristics or infer such characteristics for discrimination or political or commercial targeting.
Article (38) — Scientific research, statistics and archiving
Processing for scientific or historical research, statistics or public-interest archiving is permissible where anonymised data cannot achieve the purpose, subject to appropriate safeguards including minimisation, pseudonymisation, separation, access restriction and prohibition of harmful individual decisions based on research outputs without an independent legal basis. Certain rights may be restricted as necessary where their exercise would make the research or archival purpose impossible or seriously impair it and law or regulation provides alternative safeguards.
Article (39) — Freedom of expression and journalism
Processing for journalistic, literary, artistic or academic purposes shall balance privacy with freedom of expression and the public's right to know. Certain duties may be exempted where materially incompatible with a legitimate public-interest journalistic purpose, subject to accuracy, harm minimisation and prohibition of using the exemption for commercial circumvention, extortion or malicious publication of data unrelated to the public interest.
Article (40) — Workers' data
Processing workers' and job applicants' data shall comply with necessity, proportionality and purpose limitation. Consent alone shall not be relied upon where the employment relationship makes refusal practically unfree. Continuous covert surveillance is prohibited except in exceptional cases authorised by law or justified by a specific serious necessity after less intrusive means are exhausted, protecting private communications and activities under the Constitution and laws.
Article (41) — Health and medical data
Health data shall be processed only for lawful purposes by or under the supervision of persons bound by confidentiality, with precise access controls and audit logs. Insurers, employers and commercial platforms shall not request or use health or genetic data beyond what specific legislation permits. Digital health systems shall enable lawful clinical access without expanding unnecessary administrative access.
Article (42) — Political and electoral data
First — Political opinions and affiliations are sensitive data. Purchasing electoral or commercial databases containing them, or inferring them through profiling for political microtargeting, is prohibited without an explicit legal basis, transparency and safeguards.
Second — Parties, candidates and campaign operators shall comply with this Law. Government, service or social assistance data shall not be used for campaigning or constructing political profiles.
Third — In coordination with the Independent High Electoral Commission, the Authority shall establish specific transparency rules for campaign data use without affecting the Commission's independence or powers.
Article (43) — Public registers and open data
Data protection shall not be interpreted as nullifying transparency or legally established access-to-information rights. When publishing registers or open government data, bodies shall balance public interest and privacy and use anonymisation, partial redaction or aggregation where these achieve the purpose without unnecessary identification. Public availability alone does not justify reuse for any new purpose without compliance with this Law.
Article (44) — Government data sharing and interoperability
First — Public-body data sharing shall have a specific legal basis and an agreement or exchange record defining purpose, data categories, authorised bodies, retention, security and audit controls.
Second — No data lake or federal platform may link multiple databases for open-ended or unspecified future purposes. Interoperability shall follow need-based access, minimisation, separation of permissions, tamper-proof logs and periodic audit.
Third — This provision does not prevent sharing needed for integrated government services where purposes are known to citizens, lawful and foreseeable, with appropriate safeguards.
Article (45) — Retention and destruction
Controllers shall set and periodically review retention periods for each data category based on purpose, legal obligations and actual need. At expiry, data shall be erased, destroyed or genuinely anonymised unless legally required to be kept, needed for pending proceedings or lawfully archived. Public bodies shall issue retention schedules consistent with records and archives laws.
Chapter Six — Transfers outside Iraq
Article (46) — General transfer principle
Personal data may be transferred outside Iraq where protection is practically equivalent in substance to this Law's principles and subject rights, an approved safeguard applies, or a limited exception is met. International transfer rules shall not force all data into local storage without risk assessment or a sectoral legal basis.
Article (47) — Adequacy decisions
Following a public assessment, the Authority may determine that a country, territory or specified sector provides adequate protection, considering the rule of law, rights, enforcement, supervisory independence and international obligations. Decisions shall be reviewed periodically and may be suspended or withdrawn as circumstances change, without retrospective effects on previously lawful transfers unless risk persists.
Article (48) — Appropriate transfer safeguards
Without an adequacy decision, transfers may rely on Authority-approved standard contractual clauses, binding corporate rules, an effective international agreement, public-authority arrangements with enforceable rights, or certification and an appropriate contractual mechanism. Controllers shall assess whether receiving-country laws or practices materially undermine safeguards and adopt supplementary measures where needed.
Article (49) — Limited transfer exceptions
Where neither adequacy nor appropriate safeguards exist, specific transfers may occur with explicit informed consent after risk disclosure; necessity for a contract with or benefiting the subject; a legally established substantial public interest; a legal claim; vital interests; or from a legally open public register within its conditions. These exceptions shall not support large-scale, repeated or structural transfers.
Article (50) — Sovereign data and proportionate localisation
A law or regulation grounded in law may require local storage or additional transfer restrictions for specified government, security or critical infrastructure data where risk assessment demonstrates necessity and proportionality for a legitimate purpose unattainable through less restrictive safeguards. Localisation does not replace encryption, access management or security and shall not be imposed indiscriminately on private-sector or individual data merely because they are personal.
Chapter Seven — Federal Personal Data Protection and Digital Privacy Authority
Article (51) — Establishment
A body named the Federal Personal Data Protection and Digital Privacy Authority shall be established under this Law with legal personality and financial and administrative independence, performing its duties independently and impartially and subject to parliamentary, financial and judicial oversight under the Constitution and law. Its headquarters shall be in Baghdad, with regional offices as needed, respecting the federal structure.
Article (52) — Board and independence safeguards
First — The Authority shall be governed by a chair and four members experienced in law, data protection, technology, cybersecurity, economics or public administration, ensuring diverse expertise.
Second — Nomination procedures shall be public and competitive, with qualifications and conflicts of interest disclosed. Appointments shall follow the constitutional and legal mechanism for independent authorities after Council of Representatives approval.
Third — Membership shall last five years without immediate renewal. The Authority's law or regulations shall provide staggered terms to prevent simultaneous replacement of the entire board.
Fourth — The chair or members may be removed early only on specified legal grounds through procedures guaranteeing defence and appeal. During service, membership shall not be combined with employment or interests conflicting with independence.
Article (53) — Authority functions
The Authority shall monitor implementation; receive and investigate complaints; issue guidance and general interpretive decisions within the Law; approve contractual clauses, codes and certification; issue transfer adequacy decisions; list processing requiring impact assessment; advise on draft legislation significantly affecting data; conduct awareness campaigns; cooperate with courts, regulators and counterpart authorities; publish annual compliance reports; and issue corrective orders and statutory administrative sanctions.
Article (54) — Investigatory and inspection powers and safeguards
First — The Authority may request information, records and documents needed for investigations, conduct technical and administrative audits and summon entity representatives to give statements.
Second — Compulsory entry into non-public premises, seizure of devices or copying private content requires judicial authorisation under applicable procedural laws.
Third — The Authority shall respect commercial, security and professional confidentiality and use obtained data only for its statutory duties.
Fourth — Investigated entities may examine and respond to allegations and receive reasoned decisions.
Article (55) — Complaints and settlement
Any person may complain to the Authority about processing believed to violate this Law, without exhausting internal complaints where burdensome or futile. The Authority may seek a consensual settlement preserving rights, investigate or close the complaint by reasoned decision. Regulations shall define complaint deadlines, notification and confidentiality procedures and whistleblower protection against retaliation, with judicial review of final decisions or unjustified delay.
Chapter Eight — Enforcement, remedies and coordination
Article (56) — Corrective measures and administrative sanctions
First — Depending on severity, the Authority may warn, order time-limited compliance, require rectification, erasure or restriction, suspend a specific data flow, temporarily stop high-risk processing, suspend certification or impose an administrative fine.
Second — Fines shall reflect the violation's nature, duration and scope, affected numbers, data sensitivity, intent or negligence, mitigation, cooperation, history, benefits gained and economic capacity.
Third — Fines on private persons and entities shall be: (a) one million to fifty million dinars for procedural record, notice, officer or cooperation failures not causing serious harm; (b) ten million to two hundred and fifty million dinars for breaches of subject rights, security or notification duties, or processor, marketing and tracking rules; (c) fifty million to one billion dinars, or up to two per cent of an economic enterprise's total Iraqi revenue in the preceding financial year, whichever is higher, capped at five billion dinars, for processing without a legal basis, unlawful sensitive-data processing, unlawful international transfers, failure to comply with a final Authority order or repeated serious violations.
Fourth — Ministries and budget-funded government bodies shall not face financial fines for institutional breaches. Corrective orders, supervisory disclosure and referral of personal or disciplinary responsibility where established shall replace them. This exemption excludes public companies conducting market economic activities.
Fifth — Fines shall accrue to the general treasury, not the Authority's own revenues, to avoid conflicting incentives.
Article (57) — Appeals and judicial oversight
Final Authority decisions may be appealed before the competent judiciary under general rules. Review shall cover legality, competence, procedure, proportionality and reasoning. Appeals shall not automatically suspend urgent preventive measures where delay threatens serious harm to rights; courts may stay enforcement where justified.
Article (58) — Compensation and civil liability
Anyone suffering material or non-material damage through violation of this Law may seek compensation under general rules. Controllers are liable for damage from unlawful processing; processors are liable where they breach duties directed to them or act outside lawful controller instructions. Each party's contribution shall be considered. Compensation shall not preclude administrative or criminal measures where their conditions are met.
Article (59) — Criminal liability for independent offences
This Law's administrative measures and sanctions shall not prevent application of the Penal Code or specific criminal legislation to independently criminal acts, including unlawful access, extortion, forgery, fraud, disclosure of secrets or evidence destruction where legal elements are established. Criminal provisions shall not be expansively interpreted merely because an administrative data protection breach exists.
Article (60) — Regulatory coordination
The Authority shall coordinate with the Communications and Media Commission, Central Bank, ministries of Health, Planning, Interior and Communications, and other oversight bodies within their powers. This Law does not abolish sectoral cybersecurity, communications confidentiality, consumer or professional protection powers. The more protective data rule applies unless specific legislation provides a necessary, proportionate rule for a legitimate purpose. Duplicate administrative punishment for the same act under the same rule shall be avoided.
Chapter Nine — National security, transition and final provisions
Article (61) — National security and law enforcement
First — Processing for national security, defence, intelligence, crime prevention and investigation shall be governed by clear specific laws. Certain rights may be restricted only as necessary, proportionate and legally specified to protect a legitimate purpose and prevent compromising a lawful investigation or security operation.
Second — Restrictions do not exempt purpose limitation, minimisation, accuracy, security, access logs, retention limits or accountability, and do not authorise indiscriminate mass surveillance.
Third — Monitoring or disclosing communications remains subject to Article (40) of the Constitution and judicial decision requirements where imposed by the Constitution and law.
Fourth — Specific legislation shall establish effective judicial or independent oversight of covert processing. Individual notification may be delayed only as long and to the extent necessary because it threatens the legitimate purpose.
Article (62) — Existing processing and transition
First — Public and private bodies shall review and align existing processing within eighteen months of publication, prioritising sensitive data and large-scale processing during the first twelve months.
Second — Existing contracts and systems may continue during transition as needed for service continuity. No new high-risk project may begin without applying impact assessment and security provisions.
Third — Continued retention of data collected before entry into force is not an independent basis for continued use. Controllers shall establish a lawful basis and reasonable retention periods.
Article (63) — Regulations and instructions
On the Authority's proposal and after appropriate public consultation, the Council of Ministers shall issue implementing regulations in expressly authorised matters; the Authority shall issue technical and procedural instructions within its powers. No regulation or instruction may create a new sensitive-data processing basis, expand security exceptions, diminish data subject rights or introduce a sanction not prescribed by law.
Article (64) — Alignment with applicable legislation
First — Within one year of entry into force, the Council of Ministers shall submit necessary legislative amendments to align related laws and regulations, particularly telecommunications, electronic transactions, e-commerce, identity, health records, banking, employment, archiving, information access, elections and digital evidence.
Second — More protective sectoral provisions remain effective unless incompatible with this Law. Conflicting lower-ranking provisions shall be repealed or amended through the appropriate alignment instrument.
Article (65) — Entry into force
This Law shall be published in the Official Gazette and take effect twelve months after publication, except provisions establishing the Authority, appointing its board and issuing foundational regulations, effective upon publication for institutional preparation. Before commencement, the Authority may issue non-binding compliance guidance to facilitate transition.
Fourth — Reasons for enactment
To ensure effective protection of constitutional personal privacy and communications confidentiality; address expanding personal data collection and processing in government services, telecommunications, e-commerce, health, banking, employment and elections; harmonise individual rights and public and private duties; regulate security, breach notification, automated decisions, sensitive data and international transfers; and establish independent, specialised oversight balancing rights, digital transformation, innovation and national security, this Law is enacted.
Fifth — Explanatory memorandum
1. Nature of the proposal
This is a general horizontal law. Its function is not to operate a government platform, build a data centre or prescribe the State's technical architecture, but to establish rules for all personal data processing. It therefore distinguishes data protection from cybersecurity: cybersecurity protects systems and information from threats, whereas data protection governs lawful collection, use, sharing and retention of information about people and their rights over it. The fields complement rather than replace each other.
2. Constitutional basis and intervention limits
Necessity and proportionality are governing principles because Iraqi constitutional provisions protect privacy and communications confidentiality. 'State interests' or 'service improvement' alone cannot justify unlimited collection. The Law nevertheless allows lawful governmental and security processing, requiring a legal basis, clear purpose, bounded scope and duration, and oversight.
3. Why is consent insufficient?
Consent matters but is not the only processing basis. In taxation, passports, public health, contracts and employment it is not always appropriate or freely given. The proposal therefore uses multiple modern legal bases: contract, legal obligation, vital interests, public tasks and legitimate interests subject to balancing. This prevents 'click agree' from becoming a merely formal substitute for responsibility.
4. Supervisory authority
An independent authority is established rather than assigning the entire task to the Communications and Media Commission or a government data centre. The institutional reason is that a telecommunications regulator has valuable technical expertise but not necessarily comprehensive competence in health, employment, banking, government records and elections. Government data controllers should not be their own sole adjudicators. The proposal adopts coordination rather than displacement: the Central Bank, Communications and Media Commission, ministries and regulators retain sectoral powers, while the Authority becomes the general data protection reference.
5. Transfers and digital sovereignty
The proposal avoids a general prohibition on hosting data outside Iraq because absolute localisation may raise costs and reduce options without ensuring security. Instead, transfers are permitted with adequate protection or enforceable safeguards, while specific sovereign or security categories may be localised after risk assessment. This distinguishes data sovereignty as legal and security control from the mere location of a server.
6. Biometrics and linkage of state databases
Expanding biometric identity and linking government records may provide administrative and security benefits, but also creates high risks if identifiers become a universal key to every detail of an individual's life. The proposal therefore requires legal authority, purpose limitation, access logs and impact assessment, and prohibits open-ended linkage. It does not prohibit national identity or lawful security uses.
7. Automated decisions and artificial intelligence
The proposal does not wait for an artificial intelligence law to address the most serious direct effect on individuals: rejection of an application, credit, service or opportunity by an automated decision the person cannot understand or contest. It therefore establishes human intervention, expression of views and reconsideration rights for legally or materially significant decisions. Broader regulation of high-risk AI models remains within POL-90.
8. Sanctions
The proposal separates administrative sanctions from crime. The Authority can issue corrective orders and graduated administrative fines, but final fine amounts must be fixed by law, not instructions, after an economic assessment considering enterprise size, inflation and Iraqi market capacity. Crimes should not be created through vague data protection provisions. Serious intentional acts are therefore referred to existing criminal legislation or a balanced information technology crimes law when adopted, with explicit offence elements and penalties.
Sixth — Alignment with existing legislation and institutions
| Area | Current position | Required after adoption |
|---|---|---|
| Electronic signatures and transactions | Law No. (78) of 2012 and 2025 implementing instructions | Align identity and authentication data collection and trust-service provider records with minimisation, security and retention principles. |
| E-commerce | Regulation No. (4) of 2025 | Explicit references to consumer data rights, direct marketing, tracking and platform transparency. |
| Telecommunications and digital platforms | Sectoral regulation by the Communications and Media Commission | Coordinate powers; more protective communications confidentiality and sectoral localisation rules remain effective unless incompatible. |
| Identity and biometrics | Fragmented identity and public-service rules | Impact assessments, legally justified linkage and prohibition of the national number as a universal key beyond its purposes. |
| Health | Professional confidentiality and sectoral health legislation | Digital access standards, audit logs and safeguards for health research and clinical exchange. |
| Employment | General labour rules | Control workplace surveillance, biometrics and algorithmic recruitment. |
| Banking and payments | Central Bank oversight and financial confidentiality rules | Coordinate identity checks and anti-money-laundering requirements with minimisation, retention and rights. |
| Elections and parties | Electoral, financing and campaign rules | Prevent political targeting based on government databases or unlawfully processed sensitive data. |
| Security and law enforcement | Specific laws and judicial procedures | Define covert processing purposes, duration, logs and oversight; prohibit indiscriminate mass surveillance. |
| Information access and open data | A legislative framework requiring completion | A balancing rule preventing privacy from becoming a pretext for withholding public information and transparency from exposing unnecessary data. |
Seventh — Financial and implementation impact
The proposal's principal fiscal impact lies in establishing the Authority, building public-institution compliance functions and updating security controls and records and breach management. Public sources lack sufficient data for a reliable nationwide estimate without an inventory of existing systems, human resources and technology contracts. The proposal therefore avoids a falsely precise estimate.
Mandatory costing method before financial referral: The Ministry of Finance, with the Ministry of Planning and the Authority once established, shall prepare an estimate within ninety days separating establishment costs, annual operating costs, alignment of high-risk government systems, reusable existing resources, training costs and savings from reduced database duplication and incidents.
| Period | Priority |
|---|---|
| 0–6 months from publication | Establish the Authority, prepare foundational regulations, inventory high-risk government processing and develop notification and rights templates. |
| 6–12 months | Begin compliance in public bodies and sensitive sectors, appoint data protection officers and issue transfer and assessment rules. |
| 12 months | General commencement of the Law, opening complaints and phased enforcement. |
| 12–18 months | Complete alignment of existing processing, prioritising sensitive and biometric data and large-scale processing. |
Eighth — Brief international comparison
Drafting draws on shared principles rather than copying one law. The European Union's General Data Protection Regulation offers an advanced model of accountability, individual rights, impact assessment, breach notification and international transfers. Jordan's Personal Data Protection Law No. (24) of 2023 offers a regional Arab model closer in legal and administrative context, establishing data subject rights, data protection officers and supervisory structures. OECD privacy guidelines and Council of Europe Convention 108/108+ also inform general principles and cross-border data flows.
The proposal does not adopt every detail of any foreign model. Universal registration requirements were reduced in favour of risk-based registration, and final fines were separated from the current text pending an Iraqi economic assessment. Explicit safeguards were added for federalism, national security, freedom of expression and government data.
Ninth — Sources and references
- Constitution of the Republic of Iraq, 2005 — Iraqi Council of Representatives
- Electronic Signature and Electronic Transactions Law No. (78) of 2012 — Iraqi Official Gazette/Ministry of Justice
- Instructions No. (1) of 2025 facilitating implementation of the Electronic Signature and Electronic Transactions Law — Ministry of Justice
- E-Commerce Regulation No. (4) of 2025 — Iraqi Official Gazette/Ministry of Justice
- Framework Regulation for Digital Platforms and Services — Communications and Media Commission
- Data Protection Policy for Domain Names Registered under .iq — Communications and Media Commission
- Requirements for Fifth-Generation Mobile Networks in Iraq — Communications and Media Commission
- International Covenant on Civil and Political Rights — Iraq's status in the United Nations Treaty Collection
- Jordanian Personal Data Protection Law No. (24) of 2023 — Ministry of Digital Economy and Entrepreneurship
- General Data Protection Regulation (GDPR) — EUR-Lex
- Convention 108 and Convention 108+ — Council of Europe
- OECD Privacy Guidelines — OECD
- Personal Data Protection — Iraqi Ministry of Justice, 14 December 2025
POL-85 · Ali Zuweid's Political Programme · 5 October 2026