Ali Zuweid's Political Programme
Proposed draft law · Digital State, Data, Artificial Intelligence and Cybersecurity
Digital Government, Interoperability and Open Government Data Law
A legislative framework for connected digital government built not on duplicate platforms and data, but on unified services, trusted base registries, controlled interoperability and usable public data, protecting privacy, security and non-digital access.
Executive summary
Iraq now has practical infrastructure on which to build: the 'Ur' portal operates as the unified government gateway and, in the website snapshot taken when this document was prepared, lists more than a thousand services in total and millions of registered accounts. The state also provides an open government data portal, and instructions were issued in 2025 to facilitate implementation of Electronic Signature and Electronic Transactions Law No. 78 of 2012. In 2026, the Council of Representatives and executive bodies continued discussing electronic interconnection, national databases and government digital infrastructure.
The legislative question is no longer 'should we digitalize?' but 'how can the state avoid digitalizing fragmentation itself?' A digital service may remain slow if it reproduces every paper requirement; databases may become new islands without an interoperability framework; and privacy risks may increase if data exchange becomes an end in itself. The proposal therefore establishes a horizontal law requiring common national service standards, a legally grounded once-only data principle, a national catalogue of services and registries, an interoperability framework, rules for base registries and APIs, and controls for shared infrastructure, procurement and portability.
The proposal also regulates open government data under the principle 'open by default unless legally restricted', with clear exceptions for personal data, security and legitimate secrets, and requirements for machine-readable formats, open licensing, metadata and interfaces where needed. It does not authorize unrestricted data sharing: each exchange is tied to the Personal Data Protection and Digital Privacy Law, with minimization and audit logs built into the design.
First — Constitutional and legal context
The Constitution provides a dual basis for this proposal. Article (80) gives the executive power to plan and implement public policy and supervise ministries. Digital transformation must also respect rights and freedoms, especially freedom of electronic communications under Article (40) and Article (46)'s rule that rights may be restricted only by law without impairing their essence. Interoperability cannot therefore rest on the idea that 'every government body can access all government data'; it must define purpose, jurisdiction and legal basis.
Iraq also has an electronic transactions and signature framework under Law No. (78) of 2012. The Ministry of Justice published Instructions No. (1) of 2025 facilitating its implementation in Iraqi Gazette issue 4826. This file must complement POL-87 on digital identity and trust services, rather than duplicate signature or identity regulation.
Institutionally, the Ur portal describes itself as Iraq's official digital services platform and single access point, supervised by the National Centre for Digital Transformation in the Prime Minister's Office. A national open government portal publishes downloadable datasets. During 2026, parliamentary committees and institutions discussed inter-ministerial electronic connections, digital infrastructure, data centres and national databases. These elements make the principal legislative need common rules for connections, services and data, rather than a new government platform built from scratch.
Second — The legislative gap
| Gap | Impact | Legislative response |
|---|---|---|
| Separate sectoral platforms and systems | Duplicated accounts, data, purchases and integrations | Enterprise architecture, shared components and a national catalogue |
| Repeated requests for the same citizen document | Time, cost and opportunities for error and corruption | Once-only principle with a legal basis |
| No common interoperability rules | Bespoke, costly connections between each pair of systems | National framework, base registries and documented interfaces |
| Technology procurement without portability | Vendor lock-in and difficult system replacement | Mandatory requirements for data, documentation and an exit plan |
| Digitalizing procedures without simplifying them | Electronic bureaucracy instead of reform | Review procedures before digitalization and apply a common service standard |
| Confusing open data with personal data exchange | Risks to privacy and trust | Strict legal separation between open publication and restricted exchange |
| Publishing non-reusable files | Limited value for transparency, research and the economy | Machine-readable formats, open licences, metadata and interfaces |
Third — Proposed legislative policy
The proposal adopts 'government as a platform'. This does not mean centralizing every database, but establishing shared rules and components allowing ministries, governorates and bodies to retain sectoral responsibility while interacting through common standards. The text therefore distinguishes the registry owner, receiving body and intermediary exchange infrastructure and requires a separate legal basis for every data use.
The existing National Centre for Digital Transformation is selected as the executive coordination point rather than creating a parallel authority. A government digital governance council at Council of Ministers level resolves cross-ministerial issues and approves standards. This limits institutional expansion and gives standards horizontal force that an isolated technical body cannot impose across the state without governmental and legal backing.
The proposal is 'digital first, not digital only'. Digitalization must not disadvantage people without smartphones, reliable connectivity or digital skills, or those needing accessibility arrangements. Assisted access remains part of public service design.
Fourth — Text of the draft law
A proposed draft law within Ali Zuweid's Political Programme.
Chapter One — General provisions and principles
Article (1) — Title and substantive scope
This Law is titled the 'Digital Government, Interoperability and Open Government Data Law'. It establishes the general legal framework for public bodies' digital transformation, digital government services, system and registry connections, data exchange and publication of open government data, without prejudice to laws on personal data protection, cybersecurity, digital identity, electronic signatures and transactions, and access to information.
Article (2) — Objectives
This Law aims to: First—make government services simpler, more consistent and accessible. Second—move from digitalizing paper forms and procedures to redesigning processes from the ground up. Third—prevent repeated requests for data or documents lawfully held by a public body and eligible for exchange. Fourth—establish binding legal, organizational, semantic and technical interoperability rules. Fifth—support data-informed decisions while protecting rights and freedoms. Sixth—make unrestricted government data available for use and reuse in open, machine-readable formats. Seventh—reduce duplicate spending on government systems and platforms and strengthen reusable shared digital components. Eighth—ensure continuity of in-person and assisted channels for people unable to use digital ones.
Article (3) — Definitions
For this Law: 1. 'Public body' means any ministry, entity not affiliated with a ministry, independent body, governorate, administrative unit, public enterprise or publicly funded institution insofar as it performs a public function. 2. 'Digital government service' means a public service that can be requested, completed or tracked wholly or partly electronically. 3. 'Interoperability' means bodies' and systems' ability to exchange, understand and use data and information in a coordinated manner under common legal, organizational, semantic and technical requirements. 4. 'Base registry' means an approved government register serving as the authoritative source for a defined data category. 5. 'Reference data' means common values, codes or classifications used by more than one body. 6. 'Application programming interface' means a documented technical means of controlled automated exchange between systems. 7. 'Open government data' means legally unrestricted data published by a public body in an accessible, usable and reusable format. 8. 'Open licence' means standard legal terms permitting use, reuse, modification and distribution with the minimum necessary restrictions. 9. 'Shared government digital infrastructure' means common national components such as service portals, government connections, notification, payment, verification and exchange services, and government cloud or hosting, under applicable laws. 10. 'Centre' means the National Centre for Digital Transformation in the Prime Minister's Office or its lawful successor. 11. 'National catalogue' means a central register of services, data, registries, integration interfaces and approved standards.
Article (4) — Application
First—This Law applies when public bodies design, procure, operate or develop a digital service, information system, register, platform or data integration, or publish open government data. Second—Relevant technical and contractual obligations apply to contractors and service providers insofar as they work for public bodies. Third—This Law does not apply to classified operational activities of armed forces, security or intelligence bodies to the extent secrecy is legally necessary; security, accountability, recordkeeping and proportionality requirements under special laws remain. Fourth—The Law does not prejudice Kurdistan Region and local authorities' constitutional powers; federal integration with them rests on constitutional jurisdiction and lawful technical and legal agreements.
Article (5) — Digital government principles
Public bodies shall observe: user-centred services; digital by design rather than later addition; once-only provision where data exchange is lawful; data minimization; compatibility and portability; technology neutrality; security and privacy by design; accessibility for persons with disabilities; transparency and auditability; continuity and resilience; reuse of shared components; openness and open standards where appropriate; and no exclusion of those unable to use digital channels.
Article (6) — No unjustified paper requirement
A public body may not require a paper copy of a document or information where it has lawful, secure access to the authoritative government source, unless digital verification is unavailable, a special law requires the original, or a justified evidential need exists. Recurrent exceptions must be documented and the underlying technical or legal cause addressed.
Article (7) — Once-only principle
First—A person shall not be asked to provide the same data repeatedly to different public bodies where it exists in a base registry and can lawfully be shared. Second—This principle is not a general authorization for data exchange; exchange requires a lawful purpose and the legal basis and limits prescribed by the Personal Data Protection and Digital Privacy Law and other applicable laws. Third—Where possible, users must be able to identify the source of data used for their service and correct errors through the competent body.
Article (8) — Legal equivalence of digital services
Electronically completed applications, notices, decisions, records and correspondence have legal effect when they meet this Law and laws governing electronic transactions, digital identity and trust services. A transaction may not be refused merely because it is electronic where approved legal and technical requirements are met.
Chapter Two — Digital government services and access
Article (9) — Unified national portal
First—The state shall adopt a unified national government services portal, with 'Ur' serving as the national gateway unless a law or the Council of Ministers designates a successor. Second—Public bodies may provide specialized channels integrated with the portal and its standards without unnecessary parallel identities or accounts. Third—The portal shall publish service descriptions, conditions, fees, completion times, steps, responsible authorities and grievance or complaint channels, and allow application tracking where the service permits.
Article (10) — Government service catalogue
The Centre shall establish a mandatory national catalogue for all public services, recording the service owner, legal basis, beneficiaries, inputs, outputs, fees, timeframe, channels, digitalization level, connected systems and registries, and usage and quality indicators. No new digitalization project for a listed service may begin before its procedures are reviewed and duplicate requirements or requirements lacking legal grounds are removed.
Article (11) — Digital service standard
On the Centre's proposal, the Council of Ministers shall issue a national digital service standard defining minimum requirements for user experience, accessibility, language, account management, notifications, journey documentation, usability testing, performance measurement, outage management, support and recordkeeping. Compliance is required for approval of new national services or substantial renewals.
Article (12) — Non-digital and assisted channels
First—Public bodies shall provide suitable assisted channels for people unable to use digital self-service because of disability, limited digital literacy, poor connectivity or other legitimate reasons. Second—No additional fee may be imposed merely for assistance in using a digital government service. Third—In-person centres may be consolidated into unified service centres provided actual access is not reduced.
Article (13) — Accessibility
Government websites, applications and services must observe recognized international digital accessibility standards for persons with disabilities, provide suitable text and functional alternatives, and undergo periodic testing with users of diverse needs. The Centre shall coordinate with competent bodies to issue binding digital accessibility guidance.
Chapter Three — Governance, enterprise architecture and interoperability
Article (14) — Central governance
First—A 'Government Digital Governance Council' shall be established, chaired by the Prime Minister or a delegate and comprising senior representatives of relevant bodies, to approve national policies and common standards and resolve cross-ministerial conflicts. Second—The Centre shall serve as technical secretariat, prepare standards, monitor implementation and operate or manage shared national components designated by the Council of Ministers. Third—Ministries' and bodies' substantive powers over their records and services do not transfer to the Council or Centre except by law.
Article (15) — Institutional digital transformation officer
Each public body shall appoint a digital transformation officer with appropriate rank and powers, responsible for the map of systems, services and data, national standards compliance, avoiding duplication and coordinating with cybersecurity, data protection, procurement and internal audit officers.
Article (16) — Government enterprise architecture
The Centre shall adopt a national enterprise architecture framework defining layers, roles and reference standards for processes, data, applications and technology. Each body must update its map of systems, dependencies, interfaces and data sources before a major digital project is approved.
Article (17) — National interoperability framework
First—The Council of Ministers shall issue a national interoperability framework on the Centre's proposal. Second—It shall cover legal, organizational, semantic and technical interoperability and define common data models, national codes, exchange standards, documentation, version management, backward compatibility and integration-interface availability. Third—Compliance is a condition for funding or procuring a new government system requiring interaction with other bodies.
Article (18) — Interoperability assessment
Before approving a major project or change affecting data exchange or shared service delivery, the body shall assess interoperability, identifying affected systems and bodies, legal and organizational constraints, reusable national standards or components, lock-in risks, and security and privacy effects. A summary shall be lodged with the Centre.
Chapter Four — Registries, data and exchange
Article (19) — Base registries
First—A reasoned Council of Ministers decision shall designate national base registries, their legal owners and scope. A parallel base registry for the same data category is prohibited except by law or temporary technical necessity with an integration plan. Second—The registry owner is responsible for data quality, updating, documenting its dictionary and providing lawful verification or exchange. Third—Designation as a base registry does not expand permissible data uses beyond their legal basis.
Article (20) — Reference data and common codes
Working with competent bodies, the Centre shall adopt a national dictionary of reference data, common codes and classifications, including identifiers for bodies, administrative units, addresses, services, documents and procedural statuses. Conflicting codes in new systems are prohibited except for a documented sectoral need with a clear mapping mechanism.
Article (21) — Government data exchange platform
The state shall establish or adopt secure infrastructure for exchange among public bodies, without necessarily creating a central data store. The default is minimal data exchange through documented, auditable interfaces specifying the requesting body, purpose, legal basis, data type, access duration, access logs and revocation controls.
Article (22) — Government APIs
Bodies managing integrable systems shall provide documented, secure APIs where exchange is legally required and technically feasible. Documentation must include field specifications, validation rules, request rates, error handling, service levels, change and version policies, and pre-production testing.
Article (23) — Prohibition of uncontrolled data exchange
General sharing rules or permanent bulk copies of another body's data may not be created merely for easier access without a legal basis and demonstrated operational need. Targeted queries, real-time verification or exchange of necessary attributes should be preferred to entire database copies wherever possible.
Article (24) — Access and audit logs
Shared systems and base registries shall retain sufficient technical logs to identify who requested data, when, for which service or purpose and the result, without unnecessary content. Logs shall be protected against tampering and made available to competent audit and oversight bodies under the law.
Chapter Five — Shared digital infrastructure, procurement and continuity
Article (25) — Shared digital infrastructure
The state shall designate shared digital components for public-sector reuse where they meet the need, including as laws and policies determine: the national portal, verification and identity, notifications, payments, data exchange, digital correspondence, signatures and trust services, reference maps and addresses, government hosting and monitoring tools. A body may create a parallel component only after demonstrating that the national component is unsuitable or unavailable.
Article (26) — Government hosting and cloud
The Council of Ministers shall establish a classification and hosting policy defining which systems and data may be hosted in government infrastructure or public, private or hybrid clouds, according to sensitivity, sovereignty, security, continuity and cost. Server location alone is not sufficient to determine security or sovereignty; legal control, encryption, key management, supply chains and portability must be assessed.
Article (27) — Portability and prevention of vendor lock-in
Government system contracts shall establish clear state rights to access and export its data in standard formats and obtain documentation, interfaces, schemas and configuration components needed for continuity. Terms effectively withholding data or obstructing service migration to another provider without a legitimate technical justification are prohibited.
Article (28) — Open-source software and open standards
Where solutions are equivalent in functionality, security, total cost and maintainability, bodies shall prefer open-standard or reusable solutions. Open-source software may be preferred where it reduces lock-in and enables audit and reuse. Openness does not replace security, support or contractual responsibility requirements.
Article (29) — Digital procurement
No major government system contract may be concluded before reviewing compatibility with the national catalogue, enterprise architecture, interoperability framework, and security, privacy and portability requirements. Procurement documents must include measurable acceptance criteria, documentation, testing and audit rights, service levels, and an exit and transition plan.
Article (30) — Identity and access management
Where identity or status verification is needed, government services shall integrate with the national digital identity and trust-services system under the relevant legislation. Bodies shall not maintain separate sensitive credential stores where an approved national service meets the purpose. Staff and system accounts shall apply least privilege and separation of duties.
Article (31) — Digital payments and receipts
Where a fee or service charge is imposed by law, the digital service must offer approved electronic payment methods where infrastructure is available and issue a verifiable receipt linked to the transaction without disclosing unnecessary financial data. Applicable Central Bank, financial and accounting rules shall be respected.
Article (32) — Digital government notifications and correspondence
Government notices may be sent electronically where a reliable means of proving dispatch or receipt exists according to the procedure and its governing law. Judicial or administrative service with serious legal consequences is not presumed merely from an ordinary message unless special service requirements are met. Users must be able to manage non-mandatory communication channels.
Article (33) — Digital records management and archiving
Bodies shall manage digital records throughout their lifecycle from creation to retention or destruction, ensuring authenticity, integrity, searchability, auditability and portability. The competent national archival authority shall coordinate with the Centre on long-term preservation, formats, signatures and timestamps.
Article (34) — Service continuity
Each body shall identify critical digital services, required continuity levels, outage and disaster recovery plans, recovery points and acceptable downtime, and test them periodically with competent cybersecurity and disaster-risk bodies. Reliance on a single centre or supplier is prohibited where it creates an unacceptable single point of failure.
Article (35) — Security and privacy by design
Services must be designed and operated with cybersecurity and personal data protection requirements from the outset, including risk and impact assessments required by relevant laws. This Law does not authorize additional data collection for service improvement or analytics without a defined lawful purpose.
Chapter Six — Data governance and open government data
Article (36) — Data quality
The data-owning body shall establish rules for quality, completeness, accuracy, timeliness and consistency, and error correction and reporting mechanisms. Inter-agency sharing must not spread a known error or make it a permanent reference without a correction route.
Article (37) — Government data governance
The Council of Ministers shall issue a national policy defining responsibilities for administrative ownership, quality, classification, catalogues, access, sharing, retention and publication, clearly distinguishing an agency's ownership of a registry from individuals' legal rights in their personal data or third parties' intellectual property rights.
Article (38) — Open-by-default principle for public data
Unrestricted government data shall be candidates for open publication by default, subject to prior legal, rights and security review. Openness excludes personal, confidential, classified or legally non-disclosable data and does not replace individual information-request procedures under access-to-information law.
Article (39) — Exceptions to open publication
Publication shall be withheld or restricted as necessary where it would unlawfully expose personal data; harm national security, defence or public safety; breach investigation or judicial confidentiality; reveal legitimate trade secrets or intellectual property the state cannot license; threaten critical infrastructure; or breach another legal prohibition. Exceptions must not conceal data merely because it could expose administrative failings or invite criticism.
Article (40) — National open data portal
The state shall continue operating a national open government data portal, with technical coordination by the Centre or another body designated by the Council of Ministers. Each body shall publish open data through the portal or connect its repository so it is searchable and accessible from one national point.
Article (41) — Publication formats and metadata
Open data shall use machine-readable and, where possible, non-proprietary formats, with metadata identifying the body, source, coverage, update frequency, last update, field definitions, data quality, licence and contact method. Publishing an image-based PDF of structured tables does not fully meet open-data obligations where the structured original can be published.
Article (42) — Licensing and reuse
Open government data shall carry a national open licence permitting copying, analysis, combination, redistribution and commercial and non-commercial use, requiring source attribution where appropriate and no implication of government endorsement of derived products. Additional conditions are permitted only where authorized by law, necessary and proportionate.
Article (43) — Open data fees
Open data shall normally be free. Actual marginal costs for special delivery or a value-added service outside basic publication may be charged under a published scheme. Fees may not prevent reuse or protect a public body's information monopoly.
Article (44) — High-value datasets
Following public consultation, the Council of Ministers shall identify data categories of high economic, social, environmental or research value and prioritize their quality, updating and automated access. Subject to legal restrictions, they may include maps, administrative boundaries, budgets, expenditure, contracts, transport, environment, energy, statistics and non-personal economic registers.
Article (45) — Open data interfaces
For high-demand or rapidly changing datasets, the body shall publish an API or suitable regular download channel, with reasonable usage limits protecting stability and security. Material changes to data structure or discontinuation of an interface shall be announced with appropriate notice wherever possible.
Article (46) — Requests to open data
The national portal shall provide a mechanism to propose new datasets or improvements. The owner must respond with publication, a reasonable publication timetable, or legal or technical reasons for not publishing. Non-sensitive requests and responses shall be published to support accountability and prioritization.
Article (47) — Prevention of re-identification
Before publishing de-identified or aggregate data, the body shall assess the risk of re-identifying individuals through reasonably available data and apply appropriate aggregation, masking or perturbation where necessary. Data may not be described as 'anonymous' where practically linkable to individuals at an unacceptable risk level.
Chapter Seven — Transparency, oversight, accountability and capacity
Article (48) — Transparency of service performance
Bodies shall periodically publish non-personal performance indicators for major digital services, including usage, actual completion time, completion rates, outages, complaints, availability and user satisfaction where measured. Promotional figures may not be published without defining the measurement method.
Article (49) — Cost and benefit measurement
For major transformation projects, the body shall establish a baseline covering current costs, expected capital and operating costs, measurable benefits, implementation risks, and replacement and maintenance costs. Reduced paper use alone is insufficient justification for a project that neither redesigns procedures nor delivers a clear public benefit.
Article (50) — Oversight and audit
Implementation is subject to the Federal Board of Supreme Audit and competent oversight and judicial bodies, each within its remit. The Centre may assess technical and organizational compliance and issue binding corrective plans for common standards after approval by the Government Digital Governance Council, without replacing statutory oversight bodies' authority.
Article (51) — Digital project accountability
Each major government digital project must have a named executive owner, scope, budget, timetable, success indicators, risk plan and exit plan. It shall report periodically to the funding body and Centre and be stopped or redesigned if persistent material failure or rising costs without proportionate benefit are established.
Article (52) — Publication of contracts and specifications
Subject to legitimate commercial and security secrets, bodies shall publish basic information on major government digital contracts: project name, body, contractor, value, duration, purpose and delivery indicators. General specifications and standards whose disclosure does not harm security may be published to strengthen competition and reuse.
Article (53) — Resolving inter-agency conflicts
Where public bodies dispute responsibility for a registry, standard, integration or data sharing, the Centre shall seek a technical and legal resolution within a reasonable time. Disputes over statutory or constitutional powers beyond its authority shall go to the Council of Ministers or competent judicial or constitutional body as appropriate.
Article (54) — Digital service grievances
A digital channel does not prevent statutory grievances, appeals or complaints. Services issuing individual decisions must identify the decision-making body, legal basis and challenge mechanism; user interfaces or automation must not obstruct exercise of rights.
Article (55) — Automated decisions and artificial intelligence
Where a public body uses an automated or AI system to assess, rank or decide a matter affecting a right or legal status, AI governance and algorithmic accountability provisions apply, including transparency, documentation and human review required by the relevant law. This Law itself provides no legal basis for using AI in decision-making.
Article (56) — Cooperation with business and universities
Public bodies may cooperate with companies, universities and civil society on digital government and open-data solutions within competition, procurement, data protection, security and intellectual property rules. Sovereign powers, administrative decisions and government data remain subject to law and public oversight.
Article (57) — Capacity and skills
Bodies shall maintain programmes developing staff skills in service design, data, enterprise architecture, security, privacy, digital procurement and product and project management. Specialist public-service career paths may attract digital expertise under civil service law and applicable regulations.
Article (58) — Controlled experimentation
Time-limited test environments or pilots may trial a service, standard or technology before wider adoption, provided scope, users, risks, rights and data protection, and termination plans are defined. Experimentation may not suspend a law or bypass a judicial requirement or constitutional right.
Article (59) — Annual reports
The Centre shall submit a public annual report to the Council of Ministers and Council of Representatives on digital transformation, interoperability and open data, with verifiable indicators, shared-component status, agencies' compliance, stalled projects and legislative and funding obstacles. It shall be published except for legally protected material.
Chapter Eight — Funding, transition and final provisions
Article (60) — Financial impact and funding
Obligations under this Law shall be funded within public and investment budget appropriations and other lawful resources. Priority goes to reusing existing infrastructure and systems and consolidating duplication before new platforms are created. This Law creates no specific capital expenditure commitment unless duly included in the budget.
Article (61) — Review of existing systems
Within twelve months of entry into force, each body shall inventory its systems, services, databases and technology contracts, identify what to retain, merge, update or discontinue, and identify systems lacking interfaces, documentation, portability or adequate access controls.
Article (62) — Transitional period
First—The interoperability framework, service standard and data governance policy shall be issued within twelve months of publication. Second—New projects shall comply when the standards take effect; existing systems receive up to twenty-four months for alignment according to risk and cost. Third—Priority goes to base registries, high-demand services and integrations eliminating repeated document submission.
Article (63) — Legislative alignment
Within eighteen months of entry into force, the Council of Ministers shall submit amendments aligning laws, regulations and instructions that require only paper, physical presence or traditional stamps where safe and lawful digital alternatives exist, preserving special evidential requirements and substantive safeguards. This package shall be coordinated with data protection, digital identity, trust services, cybersecurity, telecommunications, administrative procedure and public procurement laws.
Article (64) — Regulations and instructions
The Council of Ministers shall issue implementing regulations. The Centre shall issue technical and organizational standards and guidance within its remit after consulting affected bodies and publishing final versions. A technical standard may not create an obligation affecting a right or expand data-collection powers without legislative authority.
Article (65) — Penalties and responsibility
This Law creates no new technology offences. Applicable laws govern embezzlement, forgery, unlawful access, record tampering and abuse of office. Staff are disciplinarily accountable for deliberately bypassing access controls, obstructing lawful interoperability, concealing project failure or repeatedly requesting prohibited documents after warning, under state employee disciplinary law and relevant legislation.
Article (66) — Relationship to other legislation
First—Personal data protection, cybersecurity, digital identity, trust services, telecommunications, access to information, procurement and archiving rules apply in their respective fields. Second—A specific provision prevails over a general one within its scope, but this Law must not diminish constitutional privacy, communications confidentiality, appeal rights or judicial safeguards. Third—Open data is not synonymous with publishable personal data.
Article (67) — Repeal
Any lower-ranking provision conflicting with this Law is repealed from the effective date of the competent legal instrument repealing or amending it. This provision does not authorize administrative repeal of an applicable law.
Article (68) — Commencement
This Law shall be published in the Official Gazette and take effect six months after publication. Provisions establishing the Government Digital Governance Council and preparing frameworks and standards apply from publication for preparatory purposes.
Fifth — Reasons for enactment
To build connected digital government centred on citizens and businesses; reduce duplicate documents, data and platforms; establish legal, organizational, semantic and technical interoperability rules among public bodies; regulate base registries, shared infrastructure, procurement and portability; ensure purpose-limited data exchange subject to privacy and security protection; establish a national open government data policy in usable and reusable formats; and strengthen transparency, efficiency, service continuity and digital inclusion, this Law is enacted.
Sixth — Explanatory memorandum
1. Why a horizontal law?
Each ministry can digitalize independently, but the result may be dozens of duplicate platforms, accounts and databases. A horizontal law does not take services away from the responsible ministry; it requires shared rules when dealing with citizens or other bodies. As with financial management or procurement laws, ministerial powers remain while common working rules become uniform.
2. Interoperability is more than a technical connection
Two systems may connect technically while lawful use of their data is impossible, the same field means different things, or no one is responsible for updating it. The proposal therefore addresses four layers: legal, organizational, semantic and technical. This prevents reform from being reduced to purchasing interfaces or a service bus while underlying conflicts remain.
3. The once-only principle and its limits
Citizens benefit directly when they need not carry a document between departments if the state already holds it. The principle becomes dangerous if interpreted as unlimited permission to share. The proposal therefore requires exchange to be necessary for the service and grounded in law, prohibiting wholesale copying where real-time verification or a specific attribute suffices.
4. Ur as the national access point
Rather than create a new portal, the proposal establishes a single national gateway and recognizes Ur as the existing platform, with flexibility for future replacement without amending the Law. Bodies retain specialized channels provided they integrate with the national system and do not unnecessarily recreate accounts, identities or shared services.
5. Open data does not mean publishing everything
Open publication differs both from an individual's right to request information and from inter-agency data sharing. Open data must be suitable for public dissemination and non-discriminatory reuse, excluding personal and security data and legitimate secrets. Internal data another body needs to deliver a service may be entirely non-open yet lawfully exchanged under a controlled legal basis.
6. Preventing vendor lock-in
One of public technology's most serious forms of waste occurs when the state cannot change a supplier or system because it lacks its data schema, documentation or extraction capability. The proposal therefore turns portability and exit planning from 'best practice' into core digital procurement contract requirements.
7. No new offences
Digital government law concerns governance and public administration, not criminal law. It therefore does not duplicate unlawful access, data tampering or forgery offences, which belong in relevant criminal legislation, and limits itself to disciplinary responsibility and references to applicable laws.
Seventh — Alignment with existing legislation
| Area | Relationship | Legislative action required |
|---|---|---|
| Personal data protection | Determines lawfulness of exchange, rights and restrictions | Mutual references and common terminology with POL-85 |
| Electronic signatures and transactions | Provides legal effect for digital transactions | Alignment with Law 78 of 2012 and future provisions under POL-87 |
| Cybersecurity | Protects infrastructure, services, registries and integrations | Common critical-service classification, reporting and continuity rules with POL-88 |
| Right to information | Regulates requests and access to information | Separate request rights from proactive open-data publication |
| Administrative procedures | Regulates decisions, grievances and service of notices | Recognize digital equivalence without removing notice and appeal safeguards |
| Public procurement | Regulates contracting and expenditure | Include interoperability, portability and exit-plan requirements in procurement documents |
| Archiving and records | Defines retention, destruction and authenticity | Update rules to accommodate long-term digital records |
Eighth — Financial and implementation impact
Before major projects, bodies must establish a baseline and lifecycle costs covering development, licences, hosting, security, maintenance, staff, transition and exit. Preventing duplicate platforms and reusing national components becomes a cost-reduction policy, not merely a technical preference. Later capital expansion must be duly budgeted, preventing this Law from creating unfunded obligations.
Likely transitional costs include system inventories; data and service catalogues; documentation of legacy interfaces; contract updates; a new or expanded data exchange layer; open-data portal improvements; training; and security and accessibility tests. Savings may arise from retiring duplicate platforms and reducing data entry, paper, in-person visits and bespoke bilateral integrations, but no savings value should be fixed before actual measurement.
Ninth — Relevant international comparison
The proposal reflects six established dimensions of modern digital-government frameworks: digital by design, a data-driven public sector, government as a platform, open by default, user-driven services and proactiveness. These appear in the OECD Digital Government Policy Framework. It also draws on 'digital public infrastructure', emphasizing identity, payments, data exchange and base registries as secure, interoperable shared components.
For interoperability, the European Interoperable Europe Act of 2024 offers a useful model of interoperability impact assessments before major decisions and projects, legal, organizational, semantic and technical interoperability, and reusable solutions and open standards. The draft does not copy the European model verbatim; it uses principles suited to a federal state with multiple public bodies.
Tenth — Sources and references
- Constitution of the Republic of Iraq — Iraqi Council of Representatives
Constitutional reference, particularly rights, freedoms, separation of powers and Council of Ministers powers. - Ur Electronic Portal — Prime Minister's Office / National Centre for Digital Transformation
Existing unified national government services platform and source of published service and user operational data. - About the Ur Electronic Portal
Explains Ur's status as the official digital services platform and unified access point, supervised by the National Centre for Digital Transformation. - National Open Government Portal — Ur Portal Data
An existing Iraqi example of downloadable government data published through an open government portal. - Ministry of Justice — Electronic Signature and Electronic Transactions Law No. 78 of 2012
Iraq's existing electronic transaction and signature law. - Ministry of Justice — Instructions No. 1 of 2025 Facilitating Implementation of Law 78 of 2012
An official update to the implementing framework for electronic transactions and signatures. - Iraqi Council of Representatives — Telecommunications Development and Digital Transformation Pathways, 8 June 2026
Addresses government connectivity, national databases and e-governance. - Iraqi Council of Representatives — Transport and Communications Committee and Electronic Interconnection, 27 August 2026
A recent reference on connecting ministries and state institutions, digital infrastructure and the data centre. - OECD — The OECD Digital Government Policy Framework
A comparative digital government framework: digital by design, a data-driven public sector, government as a platform, openness, user-driven services and proactiveness. - OECD — Digital public infrastructure for digital governments
Reference for shared digital infrastructure, identity, payments, data exchange, base registries and safeguards. - European Union — Interoperable Europe Act, Regulation (EU) 2024/903
Comparative reference for interoperability, assessments, standards and reusable solutions. - World Bank — Iraq Economic Monitor: Digital Transformation
An early assessment of Iraq's digital gaps and foundations, used for context rather than as a replacement for current government data.
Public sources were consulted through 5 October 2026. External links are provided for documentation and may change structure at their publishers.