Skip to content
POL-85

This is a proposal for discussion, not an enacted law.

Ali Zuweid's Political Programme

Personal Data Protection and Digital Privacy Law

A proposed law establishing a comprehensive Iraqi framework for personal data processing, translating the constitutional right to privacy into rights, duties and oversight and enforcement mechanisms applicable to the State, private sector and digital environment.

Document number
POL-85
Version
1.0
Axis
Digital State, Data, Artificial Intelligence and Cybersecurity
Document type
Proposed draft law
Publication/last updated
5 October 2026
Scope
Republic of Iraq

Executive summary

Iraq has a clear constitutional basis for privacy protection: Article (17) recognises individual personal privacy, while Article (40) guarantees communications and correspondence confidentiality, permitting monitoring, interception or disclosure only for legal and security necessity and by judicial decision. Yet this foundation does not itself define data life-cycle rules, rights of access, rectification, erasure and objection, controller and processor responsibilities, or a general system for breach notification, international transfers or independent oversight.

As of preparation of this document, available official sources have not established the existence of a comprehensive federal personal data protection law in force. Fragmented rules have nevertheless emerged: Electronic Signature and Electronic Transactions Law No. (78) of 2012 and its 2025 implementing instructions, E-Commerce Regulation No. (4) of 2025, and Communications and Media Commission regulations and policies concerning user and data protection on digital platforms, .iq domains and fifth-generation networks. This sectoral development is useful but does not replace a unified general framework.

The proposal adopts a risk-based approach: it establishes lawfulness, transparency, data minimisation and accountability principles; six principal processing grounds; enhanced protection for sensitive, children's and biometric data; practical individual rights; safeguards for automated decisions, profiling and digital tracking; and duties concerning security, breach notification, impact assessment and data protection officers.

Institutionally, it creates an independent federal data protection and digital privacy authority. Independence is justified by protection extending beyond telecommunications into health, employment, banking, elections, identity and government services. Assigning the task to a sectoral body that is also a regulator, operator or beneficiary of data flows is therefore insufficient.

International transfers are addressed through adequacy, contractual safeguards and narrow exceptions rather than blanket prohibition or absolute localisation. Localisation may be imposed on specific sovereign or security-related categories where necessity and proportionality are demonstrated. The aim is to protect rights without isolating Iraq's digital economy or unjustifiably increasing service costs.

Second — Legislative gap and proposed policy

The problem and proposed legal instrument
GapLegislative solution
A general constitutional right without detailed operational rightsRights of access, rectification, erasure, restriction, portability, objection, complaint and compensation.
Fragmented sectoral rulesA single horizontal law establishing common minimum standards while retaining more protective sectoral rules.
Expansion of government and biometric databasesPurpose limitation, data minimisation, access logs, impact assessments and controls on database linkage.
No general data breach ruleNotify the authority within 72 hours where risk exists, and individuals where risk is high.
Algorithmic decisions and profilingRights to human intervention, objection, transparency about influential factors and protection against discrimination.
International transfers lacking horizontal regulationAdequacy, contractual safeguards, narrow exceptions and proportionate localisation for sovereign categories.
No specialised independent cross-sector supervisory bodyA federal data protection and digital privacy authority with investigative, corrective and enforcement powers.

Third — Draft Personal Data Protection and Digital Privacy Law

Enactment formula

In the name of the people

Presidency of the Republic

Pursuant to the enactment of the Council of Representatives and ratification by the President of the Republic, and under item (First) of Article (61) and item (Third) of Article (73) of the Constitution, the following Law is issued:

Law No. ( ) of ( ) — Personal Data Protection and Digital Privacy Law

Fourth — Reasons for enactment

To ensure effective protection of constitutional personal privacy and communications confidentiality; address expanding personal data collection and processing in government services, telecommunications, e-commerce, health, banking, employment and elections; harmonise individual rights and public and private duties; regulate security, breach notification, automated decisions, sensitive data and international transfers; and establish independent, specialised oversight balancing rights, digital transformation, innovation and national security, this Law is enacted.

Fifth — Explanatory memorandum

1. Nature of the proposal

This is a general horizontal law. Its function is not to operate a government platform, build a data centre or prescribe the State's technical architecture, but to establish rules for all personal data processing. It therefore distinguishes data protection from cybersecurity: cybersecurity protects systems and information from threats, whereas data protection governs lawful collection, use, sharing and retention of information about people and their rights over it. The fields complement rather than replace each other.

2. Constitutional basis and intervention limits

Necessity and proportionality are governing principles because Iraqi constitutional provisions protect privacy and communications confidentiality. 'State interests' or 'service improvement' alone cannot justify unlimited collection. The Law nevertheless allows lawful governmental and security processing, requiring a legal basis, clear purpose, bounded scope and duration, and oversight.

3. Why is consent insufficient?

Consent matters but is not the only processing basis. In taxation, passports, public health, contracts and employment it is not always appropriate or freely given. The proposal therefore uses multiple modern legal bases: contract, legal obligation, vital interests, public tasks and legitimate interests subject to balancing. This prevents 'click agree' from becoming a merely formal substitute for responsibility.

4. Supervisory authority

An independent authority is established rather than assigning the entire task to the Communications and Media Commission or a government data centre. The institutional reason is that a telecommunications regulator has valuable technical expertise but not necessarily comprehensive competence in health, employment, banking, government records and elections. Government data controllers should not be their own sole adjudicators. The proposal adopts coordination rather than displacement: the Central Bank, Communications and Media Commission, ministries and regulators retain sectoral powers, while the Authority becomes the general data protection reference.

5. Transfers and digital sovereignty

The proposal avoids a general prohibition on hosting data outside Iraq because absolute localisation may raise costs and reduce options without ensuring security. Instead, transfers are permitted with adequate protection or enforceable safeguards, while specific sovereign or security categories may be localised after risk assessment. This distinguishes data sovereignty as legal and security control from the mere location of a server.

6. Biometrics and linkage of state databases

Expanding biometric identity and linking government records may provide administrative and security benefits, but also creates high risks if identifiers become a universal key to every detail of an individual's life. The proposal therefore requires legal authority, purpose limitation, access logs and impact assessment, and prohibits open-ended linkage. It does not prohibit national identity or lawful security uses.

7. Automated decisions and artificial intelligence

The proposal does not wait for an artificial intelligence law to address the most serious direct effect on individuals: rejection of an application, credit, service or opportunity by an automated decision the person cannot understand or contest. It therefore establishes human intervention, expression of views and reconsideration rights for legally or materially significant decisions. Broader regulation of high-risk AI models remains within POL-90.

8. Sanctions

The proposal separates administrative sanctions from crime. The Authority can issue corrective orders and graduated administrative fines, but final fine amounts must be fixed by law, not instructions, after an economic assessment considering enterprise size, inflation and Iraqi market capacity. Crimes should not be created through vague data protection provisions. Serious intentional acts are therefore referred to existing criminal legislation or a balanced information technology crimes law when adopted, with explicit offence elements and penalties.

Sixth — Alignment with existing legislation and institutions

Priority alignment matrix
AreaCurrent positionRequired after adoption
Electronic signatures and transactionsLaw No. (78) of 2012 and 2025 implementing instructionsAlign identity and authentication data collection and trust-service provider records with minimisation, security and retention principles.
E-commerceRegulation No. (4) of 2025Explicit references to consumer data rights, direct marketing, tracking and platform transparency.
Telecommunications and digital platformsSectoral regulation by the Communications and Media CommissionCoordinate powers; more protective communications confidentiality and sectoral localisation rules remain effective unless incompatible.
Identity and biometricsFragmented identity and public-service rulesImpact assessments, legally justified linkage and prohibition of the national number as a universal key beyond its purposes.
HealthProfessional confidentiality and sectoral health legislationDigital access standards, audit logs and safeguards for health research and clinical exchange.
EmploymentGeneral labour rulesControl workplace surveillance, biometrics and algorithmic recruitment.
Banking and paymentsCentral Bank oversight and financial confidentiality rulesCoordinate identity checks and anti-money-laundering requirements with minimisation, retention and rights.
Elections and partiesElectoral, financing and campaign rulesPrevent political targeting based on government databases or unlawfully processed sensitive data.
Security and law enforcementSpecific laws and judicial proceduresDefine covert processing purposes, duration, logs and oversight; prohibit indiscriminate mass surveillance.
Information access and open dataA legislative framework requiring completionA balancing rule preventing privacy from becoming a pretext for withholding public information and transparency from exposing unnecessary data.

Seventh — Financial and implementation impact

The proposal's principal fiscal impact lies in establishing the Authority, building public-institution compliance functions and updating security controls and records and breach management. Public sources lack sufficient data for a reliable nationwide estimate without an inventory of existing systems, human resources and technology contracts. The proposal therefore avoids a falsely precise estimate.

Mandatory costing method before financial referral: The Ministry of Finance, with the Ministry of Planning and the Authority once established, shall prepare an estimate within ninety days separating establishment costs, annual operating costs, alignment of high-risk government systems, reusable existing resources, training costs and savings from reduced database duplication and incidents.

Proposed transition stages
PeriodPriority
0–6 months from publicationEstablish the Authority, prepare foundational regulations, inventory high-risk government processing and develop notification and rights templates.
6–12 monthsBegin compliance in public bodies and sensitive sectors, appoint data protection officers and issue transfer and assessment rules.
12 monthsGeneral commencement of the Law, opening complaints and phased enforcement.
12–18 monthsComplete alignment of existing processing, prioritising sensitive and biometric data and large-scale processing.

Eighth — Brief international comparison

Drafting draws on shared principles rather than copying one law. The European Union's General Data Protection Regulation offers an advanced model of accountability, individual rights, impact assessment, breach notification and international transfers. Jordan's Personal Data Protection Law No. (24) of 2023 offers a regional Arab model closer in legal and administrative context, establishing data subject rights, data protection officers and supervisory structures. OECD privacy guidelines and Council of Europe Convention 108/108+ also inform general principles and cross-border data flows.

The proposal does not adopt every detail of any foreign model. Universal registration requirements were reduced in favour of risk-based registration, and final fines were separated from the current text pending an Iraqi economic assessment. Explicit safeguards were added for federalism, national security, freedom of expression and government data.

Ninth — Sources and references

  1. Constitution of the Republic of Iraq, 2005 — Iraqi Council of Representatives
  2. Electronic Signature and Electronic Transactions Law No. (78) of 2012 — Iraqi Official Gazette/Ministry of Justice
  3. Instructions No. (1) of 2025 facilitating implementation of the Electronic Signature and Electronic Transactions Law — Ministry of Justice
  4. E-Commerce Regulation No. (4) of 2025 — Iraqi Official Gazette/Ministry of Justice
  5. Framework Regulation for Digital Platforms and Services — Communications and Media Commission
  6. Data Protection Policy for Domain Names Registered under .iq — Communications and Media Commission
  7. Requirements for Fifth-Generation Mobile Networks in Iraq — Communications and Media Commission
  8. International Covenant on Civil and Political Rights — Iraq's status in the United Nations Treaty Collection
  9. Jordanian Personal Data Protection Law No. (24) of 2023 — Ministry of Digital Economy and Entrepreneurship
  10. General Data Protection Regulation (GDPR) — EUR-Lex
  11. Convention 108 and Convention 108+ — Council of Europe
  12. OECD Privacy Guidelines — OECD
  13. Personal Data Protection — Iraqi Ministry of Justice, 14 December 2025

POL-85 · Ali Zuweid's Political Programme · 5 October 2026

What are you looking for?

Search content published on the website.