Ali Zuweid’s Political Programme
Proposed draft law · Digital State, Data, Artificial Intelligence and Cybersecurity
Digital Identity, Trust Services, Electronic Signatures and Transactions Law
A unified legislative framework for digital identity and trust services, developing the 2012 Electronic Signatures and Electronic Transactions Law into a modern interoperable system supporting cross-border recognition while protecting rights, privacy and security.
Executive Summary
Iraq has had Electronic Signatures and Electronic Transactions Law No. (78) since 2012, but practical implementation took more than a decade before Instructions No. (1) of 2025 were issued. During 2026, government bodies began joining the national electronic-signature certification system. These important steps operate within a law drafted before modern digital identity, multiple trust services, cross-border recognition, digital wallets, attestations of attributes, electronic delivery and archiving developed.
The proposal replaces the 2012 Law with modern legislation extending beyond signature certificates. It establishes digital identity and assurance levels, recognises diverse trust services, distinguishes ordinary and qualified services, regulates licensing, the national trusted list and national public key infrastructure, and specifies legal effects of electronic signatures, seals, timestamps, delivery and archiving, with recognition of foreign services based on substantive equivalence.
The Law does not turn digital identity into a new central database collecting all information. It connects identity to authoritative registers and promotes selective disclosure and data minimisation. It separates regulation from commercial or government service operation and preserves existing certificates and licences during transition to avoid interrupting transactions begun under the current framework.
First — Constitutional and Legal Context
The Iraqi Constitution protects individual privacy and confidentiality of communications and correspondence, making constitutional rights and freedoms constraints on digital regulation. Electronic transactions also require certainty about identity, attribution of documents, data integrity, sending and receipt times and admissible proof in court. Technical infrastructure alone is therefore insufficient: the law must clearly establish effects, rights and liabilities.
Electronic Signatures and Electronic Transactions Law No. (78) of 2012 remains the federal framework in force, published in Iraqi Gazette Issue 4256 on 5 November 2012. It recognised the evidentiary force of electronic signatures, documents and contracts, regulated certification bodies, and assigned licensing, standards and supervision to a Ministry of Communications company. On 19 May 2025, the Ministry of Justice published Instructions No. (1) of 2025 in Issue 4826 to facilitate implementation, incorporating updated technical concepts such as public and private keys and electronic seals.
In 2026 the framework moved significantly towards implementation. The Securities Commission announced adoption of electronic signatures within the national certification system on 3 May 2026. The Ministry of Finance’s Financial and Accounting Training Centre announced completion of NPKI registration on 19 June 2026. In December 2025, the government also directed development of the unified national card as a unified national electronic reference, increasing the urgency of regulating links among civil registration, digital identity and trust services.
Second — Legislative Gap
The existing Law was drafted when electronic signatures and certification certificates were central. Today’s digital environment also includes digital identity, multiple assurance levels, wallets, electronic seals for legal persons, timestamps, registered electronic delivery, trustworthy archiving, website authentication certificates and attestations of attributes. Cross-border recognition is now integral to digital commerce and services.
Combining regulatory and operational roles also creates an institutional problem. The current framework assigns licensing, standards and monitoring to a Ministry of Communications state company, while modern governance requires functional separation between market regulation and service provision or competition with providers. This becomes more important as NPKI develops into national infrastructure relied on by public and private sectors.
Another gap is the absence of a comprehensive legal system for digital identity itself: who issues foundational identity, what assurance levels apply, how company representation or agency is established, how credentials are recovered after a phone is lost, what minimum data may be disclosed, and how foreign identities or signatures are recognised. The proposal addresses these without turning legislation into a rigid technical specification.
Third — Proposed Legislative Policy
| Issue | Proposed choice | Purpose |
|---|---|---|
| Existing Law | Repeal and replace Law No. 78 of 2012 with an orderly transition | Prevent two conflicting frameworks |
| Foundational identity | Use the national card and authoritative registers, without a parallel civil register | Preserve responsibilities and prevent data duplication |
| Trust levels | Assurance levels proportionate to transaction risks | Avoid excessive requirements for simple services |
| Trust services | Regulate a broad range beyond signature certificates | Support modern digital government and economy |
| Regulation | A specialised Ministry of Communications regulatory directorate functionally separate from operators | Reduce conflicts without a new independent authority |
| International recognition | Substantive equivalence rather than technical identity | Cross-border commerce and services |
| Privacy | Data minimisation, selective disclosure and reference to data protection legislation | Prevent digital identity becoming a tool for universal tracking |
Fourth — Draft Law
Chapter One — General Provisions
Article (1) — Title and Purpose
This Law shall be called the ‘Digital Identity, Trust Services, Electronic Signatures and Transactions Law’. It establishes a unified, technology-neutral legal framework for proving identity and capacity digitally; giving legal effect to electronic transactions, records, signatures and seals; and regulating trust services, providers, supervision and recognition within Iraq and across borders.
It shall promote trust in the digital economy and public services while preserving constitutional rights, privacy and security. Electronic means shall not become mandatory for individuals except under a specific provision ensuring a reasonable alternative where digital access is unavailable.
Article (2) — Definitions
For this Law: ‘digital identity’ means data and electronic credentials enabling reliable proof of a natural or legal person’s identity or representative capacity; ‘electronic identification means’, a tangible or intangible tool containing identification data and used for authentication; ‘authentication’, an electronic process verifying a person’s identity or data origin and integrity; and ‘digital identity wallet’, a secure application or means enabling its holder to manage credentials and attributes and present or share them selectively.
‘Trust service’ means an electronic service assuring identity or data origin, integrity, timing, delivery or preservation, including electronic signatures, seals, timestamps, registered electronic delivery, archiving, website authentication, attestations of attributes and other services specified by regulation. A ‘trust service provider’ is a legal person providing such services under this Law. A service is ‘qualified’ if it meets enhanced statutory and regulatory requirements and appears on the national trusted list.
An ‘electronic signature’ is electronic data linked to other data and used by a signatory to sign. An ‘advanced electronic signature’ is uniquely linked to and identifies the signatory, created using means under their control with a high degree of confidence, and linked to data so subsequent changes are detectable. A ‘qualified electronic signature’ is an advanced signature created by a qualified signature-creation device and based on a qualified certificate. An ‘electronic seal’ is created by a legal person to establish data origin and integrity, with analogous levels where applicable.
An ‘electronic record’ is information created, sent, received or stored electronically and accessible for subsequent use. An ‘electronic transaction’ is any legal act, procedure or communication performed wholly or partly electronically. An ‘electronic timestamp’ links other data to a specified time, establishing their existence then. ‘Registered electronic delivery’ transfers data between parties, provides evidence of sending and receipt, and protects against loss or unauthorised alteration. An ‘electronic attestation of attributes’ is authenticated data establishing a fact, right or capacity concerning a person, such as agency, qualification, licence or representative capacity.
Article (3) — Governing Principles
This Law rests on technological neutrality, non-discrimination against electronic form, functional equivalence between paper and electronic forms where the required legal function is achieved, proportionality between trust level and transaction risk, interoperability, open standards, privacy and security by design, data minimisation, auditability and avoidance of vendor or technology lock-in.
No provision shall be interpreted to create an unjustified technological monopoly or require a particular technology where another achieves the legally required trust and assurance.
Article (4) — Scope
This Law applies to electronic transactions and identity-management and trust services within Iraq, providers established there, and services from abroad regularly targeting persons or entities in Iraq or seeking legal recognition there.
National digital identity provisions apply to federal authorities and matters connected with civil registration, nationality, the national card and federal services, respecting regions’ constitutional powers and coordination and mutual-recognition mechanisms.
Article (5) — Exceptions and Limits
This Law does not itself abolish personal attendance, official notarisation or special form required by substantive law for a material reason. Nor does it turn a negotiable document or instrument into an electronic transferable record without legislation establishing specific control, singularity and integrity requirements.
Within existing laws, competent bodies may adopt electronic procedures achieving the same purpose as attendance or notarisation where identity, intent, authority and record integrity can be established to an equivalent or higher level.
Article (6) — Choice of Electronic Means
No person shall be compelled to accept an electronic transaction with another unless law or contract requires it. Consent may be established by express agreement or conduct leaving no reasonable doubt of acceptance of electronic dealings.
A public body may not refuse an application or instrument merely because it is electronic if it meets this Law and the service’s particular regulations.
Chapter Two — Electronic Transactions and Records
Article (7) — Non-discrimination Against Electronic Records
A record, message, contract or evidence shall not lose legal effect or admissibility merely because it is electronic. Evidentiary weight shall depend on reliability of creation, preservation, attribution and integrity and all surrounding circumstances.
Article (8) — Writing Requirement
A statutory writing requirement is satisfied by an electronic record whose information remains intelligibly accessible for subsequent reference, unless a special law expressly prohibits it.
Article (9) — Original Requirement
A requirement to present an original may be satisfied electronically where reliable means assure information integrity since first creation and its display on request, considering the document’s nature and the purpose of requiring an original.
Article (10) — Signature Requirement
A statutory signature requirement may be met electronically through a method identifying the signatory and indicating intent to approve the information, reliable and appropriate to the purpose. A qualified electronic signature has the legal effect of a handwritten signature unless a special law provides otherwise for a constitutional or substantive reason.
Article (11) — Time and Place of Sending and Receipt
An electronic record is sent when it leaves an information system controlled by the originator or representative and received when it enters the recipient’s designated system, or, absent a designated system, when made available for retrieval.
Unless otherwise agreed, sending occurs at the originator’s place of business and receipt at the recipient’s place of business. Server or provider location does not alter this rule.
Article (12) — Acknowledgement of Receipt
Electronic acknowledgement of receipt may be required. Where the originator makes the message’s effect conditional on acknowledgement, the agreed effect does not arise beforehand, subject to good faith and prohibition of abuse.
Article (13) — Attribution and Automated Messages
A record is attributable to its originator if sent personally, by an authorised representative or by an information system programmed to act on their behalf. Automation does not prevent contract formation or procedural validity where attribution is possible and legally required error-correction mechanisms are available.
Article (14) — Retention and Archiving
A retention duty is fulfilled by electronic preservation ensuring access, integrity and retention of origin, destination, date and time data where necessary for the statutory period, under archiving and data-protection standards.
Article (15) — Evidentiary Value of Electronic Documents
Courts or competent bodies shall assess evidentiary value through reliability of creation, transmission and storage, integrity, identification of the originator, use of trust services and other technical evidence. Evidence may not be excluded merely for lacking ‘qualified’ status.
Article (16) — Electronic Contracts
Offer, acceptance and other contractual acts may be expressed electronically. Electronic or automated systems alone do not invalidate a contract; capacity, consent, lawful cause and subject matter, consumer protection and special substantive requirements remain applicable.
Article (17) — Correction of Input Errors
Where a person transacts through an automated system lacking a reasonable opportunity to correct a material input error, they may request correction or cancellation without undue delay, provided they have not received an irreversible benefit, without prejudice to special consumer-protection rules.
Chapter Three — Digital Identity and Attribute Management
Article (18) — National Digital Identity System
A national digital identity system shall be established, based for Iraqi natural persons on official national-card and civil-status registers within legal limits, enabling digital verification without copying complete registry data into every relying body.
Digital identity creates no nationality, civil status or new right and does not replace the register establishing an attribute. It is a means of proving identity or capacity electronically to the extent needed for a transaction.
Article (19) — Foundational Identity Authority
Through its national-card and civil-registry body, the Ministry of Interior shall issue or confirm natural persons’ foundational identity data and securely connect them to the national system. Bodies responsible for legal-person registers shall confirm their identities and representatives’ capacities within their remits.
Article (20) — Identity Management and Intermediary Services
Accredited public or private bodies may provide identity-management and authentication services, provided they neither create a parallel civil identity nor alter official-register data. They may issue credentials or wallets linked to reliable data at a specified assurance level.
Article (21) — Identity Assurance Levels
The competent authority shall establish by regulation assurance levels reflecting impersonation risks and consequences of error, with registration, verification, credential issuance, authentication and recovery requirements for each. The highest assurance level may not be imposed on low-risk transactions without justification.
Article (22) — Enrolment and Identity Proofing
Enrolment shall be proportionate, documented and auditable, using trustworthy sources to verify identity and capacity. Remote enrolment is permitted if approved technical and organisational means, including secure matching, video communication or other regulated methods, provide assurance equivalent to attendance.
Article (23) — Issuing Electronic Identification Means
Identification means shall be issued only after appropriate verification of identity and capacity and bound to their holder to prevent unauthorised use proportionate to assurance level. Providers shall clearly explain conditions, risks and suspension, revocation and recovery procedures.
Article (24) — Attributes and Representation
Digital identity may connect to separate attestations of agency, employment, membership, licence, qualification or other attributes, sourced from the responsible register or authority. An identity provider may not independently create a legal attribute; its continuing validity shall be checked where necessary.
Article (25) — Selective Disclosure and Data Minimisation
Identity systems shall, where possible, prove a particular fact without excessive disclosure, such as age, eligibility or capacity without revealing the full record. Relying parties shall request only attributes necessary for their purpose.
Article (26) — Digital Wallet
The state may approve a national digital identity wallet or multiple compatible means for secure credential and attribute management. Design shall not lock users into one provider or make the wallet the sole condition of essential services where a person cannot use it.
Article (27) — Recovery, Suspension and Revocation
Fast, secure procedures shall address recovery of identity or credentials after device loss, changed contact number, suspected compromise, holder death or loss of capacity. Recovery shall prevent account takeover through independent verification proportionate to assurance level.
Article (28) — National Credential and Status Register
The system shall provide reliable and, as far as possible, immediate verification of identification means, certificate or attestation status—valid, suspended or revoked—without exposing information unnecessary to the relying party.
Article (29) — Identity-system User Rights
Holders may know which bodies requested identity or attribute verification within legal limits, correct data at their original source, suspend suspected credentials and receive non-discriminatory assistance. Personal Data Protection and Digital Privacy Law provisions apply to all processing.
Article (30) — Non-discrimination and Universal Access
No person may lose a right or essential service merely for lacking a smartphone, disability, poor connectivity or inability to use a particular means. Assistance and reasonable alternative verification shall be provided, respecting accessibility for persons with disabilities and older persons.
Chapter Four — Trust Services and Their Legal Effects
Article (31) — Types of Trust Services
Regulated trust services include electronic signatures, seals, timestamps, registered electronic delivery, trustworthy archiving, website authentication certificates, electronic attestations of attributes, record- or ledger-based services performing a defined trust function, and other services designated by regulation consistently with this Law.
Article (32) — Ordinary and Qualified Services
Non-qualified trust services may operate under general rules without claiming qualification. ‘Qualified’ status or the national trust mark may be used only for a service and provider on the national trusted list after conformity and licensing or accreditation requirements are met.
Article (33) — Electronic Signatures
An electronic signature shall not be denied legal effect merely because it is electronic or unqualified. Its effect depends on reliability. Qualified signatures enjoy a rebuttable statutory presumption of attribution to the signatory and integrity of associated data.
Article (34) — Qualified Signature-creation Devices
A qualified device shall provide high confidence in creation-data confidentiality, practical resistance to derivation and protection from non-holder use, and shall neither alter data to be signed nor prevent their display before signing. Regulations shall set conformity and technical-assessment requirements.
Article (35) — Qualified Signature Certificates
Qualified certificates shall identify their qualified status, provider details, signatory’s name or legally permitted pseudonym, signature-verification data, validity period, unique identifier, provider signature or seal, location for status checking and any material use restrictions.
Article (36) — Electronic Seals
Electronic seals establish that data originate from a legal person and ensure origin and integrity. A qualified seal creates a presumption of integrity and the origin stated in its certificate. A seal alone does not prove a natural person’s intent to undertake a legal act unless law or circumstances establish it.
Article (37) — Electronic Timestamps
Timestamps shall not be rejected as evidence merely because they are electronic. Qualified timestamps create a presumption of date and time accuracy and associated-data integrity within the service standard. Time shall be linked to a trustworthy, calibrated source.
Article (38) — Registered Electronic Delivery
Data transmitted through registered electronic delivery shall not be denied legal effect. Qualified services provide evidence of sender and recipient identity where appropriate and sending and receipt dates and times, protecting data from undetected alteration under regulatory requirements.
Article (39) — Trustworthy Electronic Archiving
Trustworthy archiving preserves readability, integrity and verifiability of origin and attributes throughout retention despite technological change. Timestamps may be renewed or formats converted through a documented preservation chain without undermining evidentiary value.
Article (40) — Website Authentication Certificates
Trusted website and domain authentication certificates may establish and link the responsible entity’s identity. They do not guarantee content or legality of all activities and shall not be displayed as implying broader guarantees.
Article (41) — Electronic Attestations of Attributes
Electronic attestations may establish attributes, rights or facts derived from reliable sources, identifying source, issuance date, validity and verification mechanism. Responsibility for correctness shall follow the respective roles of source, provider and relying party under this Law.
Article (42) — Electronic Record-based Services
A trust service using electronic records or distributed-ledger technology may be recognised if it reliably and auditably performs a defined legal function, without assuming technology itself guarantees legal truth. Regulations shall establish accreditation without favouring a particular architecture.
Article (43) — Provider Obligations
Providers shall follow clear published policies, verify subscribers’ identities according to service level, use qualified systems and staff, protect keys and secrets, manage incidents and vulnerabilities, retain necessary records, provide certificate and service status, manage complaints, maintain termination plans and comply with data-protection and cybersecurity rules.
Article (44) — Subscriber Obligations
Subscribers shall provide accurate information, protect credentials and signature-creation data from others’ use, immediately report suspected loss, misuse or substantive data changes, and respect published certificate restrictions.
Article (45) — Relying-party Obligations
A relying party shall, where reasonable, verify certificate status, scope, restrictions and service level and shall not disregard a clear warning or revocation notice. Liability shall reflect risk, transaction type and availability of verification means.
Article (46) — Suspension and Revocation
Providers shall immediately suspend or revoke certificates or credentials on legal or security grounds, particularly an authenticated holder request, established loss of control over creation data, inaccurate material information or an authority or court order. Status shall be available reliably without delay.
Article (47) — Termination and Continuity
Qualified providers shall maintain approved plans for termination or total or partial cessation, including subscriber and authority notification, transfer or preservation of records, continued status availability, secure key invalidation and continued verification of past services throughout statutory periods.
Chapter Five — Regulation, Licensing and Supervision
Article (48) — Competent Authority
A ‘Digital Identity and Trust Services Regulatory Directorate’ shall be established within the Ministry of Communications to regulate, license and technically supervise identity-management and trust services. Licensing and supervisory decisions shall be functionally independent of any company or government body operating services.
Licensing and supervision of a provider may not be assigned to the operating unit competing with it or providing the same service. Regulations shall govern institutional and financial separation and conflicts of interest.
Article (49) — Authority Functions
The authority shall establish technical standards and policies; license or accredit qualified services; manage the national trusted list; accredit or recognise conformity-assessment bodies; inspect and audit; receive incident reports and regulatory complaints; issue corrective orders; coordinate with identity, civil-register, data-protection, cybersecurity, banking and communications bodies; and conclude mutual-recognition arrangements within its powers.
Article (50) — National Public Key Infrastructure
NPKI shall be managed with clear separation among the national or approved roots, regulator and providers. Regulations shall specify certificate policies, key management, backups, generation and revocation ceremonies, audit and business continuity. Sole individual access to critical root keys is prohibited.
Article (51) — National Trusted List
The authority shall publish an updated, digitally signed list of qualified providers and their specified services, status, and qualification start and end dates. It shall be freely accessible to systems and the public in machine-verifiable formats.
Article (52) — Licensing Qualified Providers
No service may be offered as qualified without a licence. Licensing requires legal eligibility, financial and technical capacity, governance, competent staff, security and privacy policies, proportionate insurance or financial security, continuity and termination plans, and an independent conformity-assessment report.
Article (53) — Conformity Assessment
Qualified services shall undergo initial and periodic independent assessment by a recognised body against published national or international standards appropriate to the service. A report does not remove authority or provider responsibility. Additional testing may be required for material risk or a major incident.
Article (54) — Technical Standards and Neutrality
With national standardisation and cybersecurity bodies, the authority shall adopt internationally compatible standards, open wherever possible. Regulations shall specify protective functions and assurance levels rather than a commercial product or single algorithm, permitting updates without amending the Law.
Article (55) — Audit and Record Retention
Providers shall retain sufficient records of operations, security decisions, identity verification and certificate issuance, suspension and revocation for service-specific regulatory periods, protected from tampering and unauthorised access. Audit logs themselves shall follow data minimisation.
Article (56) — Security Incidents
Qualified providers shall notify the authority and national cybersecurity body without undue delay of incidents materially compromising service security, key integrity or user trust, and take containment, recovery and notification measures. Affected individuals shall be informed where the incident is likely to pose high risk to their rights.
Article (57) — Confidentiality and Data Protection
Credential, identity and operational records are confidential according to their nature and may be used only for legally or contractually specified purposes. Providers are subject to Personal Data Protection and Digital Privacy Law provisions. Authentication logs may not create behavioural or commercial profiles beyond the original purpose without an independent legal basis.
Article (58) — Fees and Pricing
Licence and government-service fees shall be set by lawful decision or regulation under published rules proportionate to cost and regulatory purpose. Basic digital identity necessary for public services may not be conditional on exclusionary fees. Optional added-value services may be charged.
Chapter Six — Cross-border Recognition
Article (59) — Recognition of Foreign Services
Foreign identity-management or trust services shall not be rejected merely for foreign origin. Recognition may follow demonstrated substantive equivalence in reliability and safeguards to the corresponding domestic level, through assessment, agreement or a recognition mechanism adopted by law or the authority.
Article (60) — Mutual-recognition Mechanisms
Cross-border recognition may use a general decision for a defined class, international agreement or authorised implementing memorandum, assessment of a particular provider or service, or reliance on a trusted foreign list. Scope, effects, duration and suspension or termination procedures shall be specified.
Article (61) — Foreign Certificates and Signatures
Foreign signatures, seals or timestamps may receive legal effect equivalent to domestic counterparts if substantively equivalent. Technical architecture and server location need not exactly match Iraq’s where required trust and protection functions are achieved.
Article (62) — Foreign and Cross-border Digital Identity
Foreign identification means may be accepted for Iraqi services or transactions according to assurance level, subject to entry, residence, anti-money-laundering, sanctions and sector-specific obligations. Acceptance does not recognise nationality, residence or substantive status not established under Iraqi law.
Chapter Seven — Government Use and User Rights
Article (63) — Digital Identity in Public Bodies
Under a Council of Ministers timetable, public bodies shall accept national digital identity and recognised identification means for electronically performable transactions and refrain from requesting paper copies of data verifiable directly from lawful official sources.
Article (64) — Government Institutional Signatures and Seals
Public bodies shall use authorised individuals’ electronic signatures and institutional electronic seals according to assigned powers. Seals shall not conceal the official responsible for decisions requiring individual accountability. Audit logs shall identify who authorised the procedure.
Article (65) — Electronic Notices and Service
Registered electronic delivery may serve administrative notices where special law permits, the recipient consents or an official digital account is adopted for that purpose. Ordinary email alone does not replace lawful service where reliable delivery proof is required.
Article (66) — Government Procurement of Identity and Trust Services
Procurement shall ensure interoperability, open standards, state ownership of its data and critical keys, and supplier-transition plans. Contracts may not prevent transfer of data, administrative keys or records needed for continuity upon expiry, while protecting legitimate trade secrets.
Article (67) — Privacy and Security by Design
All identity and trust components shall apply privacy and security by design and default, including data minimisation, separate identifiers where possible, encryption, risk-based multi-factor authentication, audit logs, periodic testing and limits on cross-service user tracking.
Article (68) — User Transparency
Users shall be informed clearly of the identity means or service, assurance level, provider, required data and purpose, material restrictions, and procedures for challenge or reporting loss or misuse. Material legal effects may not be hidden in lengthy or obscure terms.
Article (69) — Right to Review and Assistance
Everyone may complain to a provider and receive a reasoned response within a reasonable period and challenge licensing or service decisions before the authority within its remit, without prejudice to recourse to courts, data-protection bodies or other competent regulators.
Chapter Eight — Liability, Measures and Appeal
Article (70) — Provider Liability
Identity or trust providers are liable for damage caused by intentional or negligent breach of mandatory legal or technical duties, considering the roles of the injured party, relying party and data source. A qualified provider bears the burden of proving absence of intent and negligence when requirements directly under its control fail.
Article (71) — Published Liability Limits
Providers may restrict certificate or service use, transaction value or type where restrictions are clear and verifiable before reliance. Unpublished or ambiguous limits cannot be invoked. Liability for fraud, gross negligence or breach of fundamental security duties may not be excluded by agreement.
Article (72) — Regulatory Orders and Measures
After allowing representations except in urgent cases, the authority may warn, order correction or service restriction, suspend qualified status or a licence, revoke a licence, or require publication of a correction or user notification where necessary for protection. Measures shall be reasoned, proportionate and appealable.
Article (73) — Financial Administrative Penalties
Administrative fines may address serious regulatory violations specified by law or regulation, considering severity, duration, persons affected, benefit obtained, cooperation, compliance history and economic capacity. No monetary penalty may be imposed without a provision defining its scope and maximum under the legality principle.
Article (74) — Criminal Conduct
Without prejudice to the Penal Code and Information Technology Crimes Law, relevant criminal provisions shall punish intentional falsification of certificates or credentials; appropriation of signature-creation or digital-identity data for impersonation; unauthorised issuance of qualified services or a national trust mark; or destruction of trust records to conceal evidence. Mere technical error or civil breach does not create criminal liability without the elements of an expressly defined offence.
Article (75) — Judicial Appeal
Final authority decisions may be appealed before competent administrative courts under statutory periods and procedures. Appeal does not prevent an application to stay enforcement where conditions are met. Civil, commercial and compensation disputes remain with competent courts.
Chapter Nine — Transitional and Final Provisions
Article (76) — Existing Licences and Certificates
Licences, certificates and certification services issued under Electronic Signatures and Electronic Transactions Law No. (78) of 2012 and Instructions No. (1) of 2025 retain their effects until expiry or no more than twenty-four months after commencement, whichever is earlier, unless the authority permits continuation after this Law’s requirements are met.
Article (77) — Provider Transition
Existing certification and trust providers shall align their status within eighteen months. The authority shall maintain verification of past signatures and certificates, revocation records and archives through a transition plan. Transition shall not remove evidentiary force from a valid transaction made under the law applicable at the time.
Article (78) — Regulations and Instructions
The Council of Ministers shall issue implementing regulations within twelve months of publication. The Minister of Communications and competent bodies may issue instructions and standards within their remits, particularly on identity assurance levels, trusted lists, conformity assessment, qualified devices, incidents, fees and cross-border recognition, publishing them and allowing appropriate technical consultation where possible.
Article (79) — Legislative Alignment
Within eighteen months, the Council of Ministers shall submit amendments harmonising references to signatures, documents, seals, attendance and service in existing laws, permitting functional equivalence where no substantive barrier exists. The package shall coordinate with evidence, procedure, commerce, companies, banking, notarial, property registration, national-card, digital-government, data-protection and cybersecurity legislation.
Article (80) — Repeal
Electronic Signatures and Electronic Transactions Law No. (78) of 2012 is repealed at commencement. Its regulations, instructions and decisions remain effective insofar as consistent until replaced, without exceeding this Law’s transitional periods.
Article (81) — Commencement
This Law enters into force ninety days after publication in the Official Gazette. Provisions needing regulations or transitional infrastructure become mandatory under the specified periods. Fundamental rights and safeguards may not be postponed because instructions are delayed.
Fifth — Statement of Reasons
To modernise Iraq’s electronic-transactions framework more than a decade after Law No. (78) of 2012; accommodate digital identity, trust services and national public key infrastructure; provide clear legal effects for electronic signatures, seals, timestamps, delivery, archiving and attestations of attributes; regulate and supervise providers and separate regulation from operation; enable recognition of foreign services through substantive equivalence; and protect privacy, security and universal access, this Law is enacted.
Sixth — Explanatory Memorandum
1. Why repeal and replace?
The 2012 Law emerged in a different legal and technical environment, primarily addressing signatures, documents and certification bodies. The 2025 instructions improved implementation but cannot alone create legal effects in areas the Law never regulated. Replacement is therefore more coherent than accumulating partial amendments to a conceptually limited law.
2. Why no new independent authority?
Regulation requires functional independence from providers, not necessarily a new constitutionally independent or costly institution. The proposal therefore creates a specialised Ministry of Communications directorate and prohibits combining licensing, oversight and competitive operation in one unit. Its functions could later transfer to a broader regulator if telecommunications and digital services are reorganised under POL-91.
3. Digital identity and the national card
Digital identity is not a new population register. Names, dates of birth, nationality and civil status originate from the competent register. Digital identity enables electronic proof of identity or attributes at an appropriate assurance level. This separation reduces inconsistent databases and prevents every body creating its own copy of citizens’ identities.
4. Assurance levels
Transactions need different assurance. Reading public-service information or submitting a complaint may need simple verification, while opening a financial account, signing a high-value contract or accessing a sensitive record needs greater assurance. Technical details remain in regulations and standards for updating without repeated statutory amendment.
5. Legal effect of signatures
The proposal distinguishes electronic signatures generally from advanced and qualified signatures. Unqualified signatures retain evidentiary value assessed through circumstances and evidence; qualified signatures gain a stronger legal presumption, balancing innovation and certainty.
6. Broader trust services
Government and commercial transactions need more than an individual’s signature. Institutions need electronic seals; contracts and records may need time evidence; notices need proof of dispatch and receipt; long-term documents need archiving that preserves verifiability; and platforms need proof linking a website to a responsible entity. A single framework prevents fragmentation and lowers integration costs.
7. User protection
Digitalisation does not mean forcing everyone to use smartphones. The proposal requires reasonable alternatives and accessibility, limits requested data, encourages selective disclosure and lets users know which body verified their identity where law permits. General data-protection rules govern the whole system.
8. Cross-border recognition
Substantive equivalence follows UNCITRAL approaches: a foreign country need not use the same algorithm or institutional structure, but its service must provide reliability and protection equivalent to the Iraqi legal purpose. This matters for trade, contracts, companies, investors, consular and cross-border services.
Seventh — Alignment with Existing Legislation
| Legislation / area | Relationship | Required action |
|---|---|---|
| Electronic Signatures and Electronic Transactions Law No. 78 of 2012 | Fully overlaps with the proposal | Repeal with transition of licences, certificates and records |
| Instructions No. 1 of 2025 | Contain modern technical and operational arrangements | Temporary continuation where consistent, followed by replacement regulations |
| National Card Law No. 3 of 2016 | Source of foundational civil identity | Legal and technical connection without a parallel register |
| Evidence, procedural, civil and commercial transaction laws | Determine evidentiary force, form and procedures | Amend exclusively paper or handwritten-signature references where functional equivalence is possible |
| Proposed Personal Data Protection and Digital Privacy Law POL-85 | Governs identity and trust data processing | Express reference and coordination on incidents, records and rights |
| Proposed Digital Government Law POL-86 | Regulates public-sector use of digital components | Integrate identity, signatures and seals with the Ur Portal and interoperability |
| Proposed Cybersecurity Law POL-88 | Governs risks, incidents and critical infrastructure | Coordinate reports and security requirements without duplicate supervision |
| Sectoral laws: banking, companies, taxation, notaries and property registration | Contain specific identity and form requirements | Sectoral review without assuming automatic repeal of substantive conditions |
Eighth — Financial and Implementation Impact
The proposal does not logically require building a digital system from scratch: Iraq has begun operating NPKI and has national-card infrastructure, the Ur Portal, providers and bodies already using electronic signatures. Spending should therefore focus on governance reorganisation, standards and conformity assessment, stronger national-root and continuity arrangements, register integration, secure verification interfaces and support for existing entities’ transition.
The principal administrative effect is moving regulation into a unit functionally separate from operation and reassessing existing licences against uniform requirements. Legislative transition lasts 18–24 months to avoid undermining trust in currently used certificates.
Ninth — Useful International Comparison
UNCITRAL: its 2022 Model Law on the Use and Cross-border Recognition of Identity Management and Trust Services is the proposal’s principal international reference. It focuses on functional equivalence and reliability of identification methods or trust services, enabling cross-border recognition without requiring one institutional model. The proposal also draws on the 2001 Model Law on Electronic Signatures and electronic-commerce principles.
European Union: eIDAS, amended in 2024 to establish the European Digital Identity Framework, demonstrates the value of unified legal effects for signatures, seals, timestamps, delivery, archiving and attestations of attributes, with trusted lists and qualified providers. The proposal adapts that legal structure to Iraq rather than copying the European model verbatim.
United Arab Emirates: Federal Decree-Law No. 46 of 2021 on Electronic Transactions and Trust Services offers a regional model combining transactions, identity and trust services, regulating trusted lists and acceptance of digital identity. It is useful given the regional legal environment and future mutual-recognition needs.
Estonia: its Electronic Identification and Trust Services for Electronic Transactions Act illustrates separation of competent authority and providers, trusted lists, conformity assessment and service-termination plans. Strong digital identity needs continuity and liability rules, not merely a card or application.
World Bank ID4D: identification-for-development principles emphasise universal coverage, removing access barriers, open standards, vendor and technology neutrality, privacy and control by design, accountability and oversight. The proposal therefore avoids mandatory smartphone ownership and adopts data minimisation and selective disclosure.
Tenth — Sources and References
- Constitution of the Republic of Iraq — Iraqi Council of Representatives
Constitutional reference for rights, freedoms and federal powers. - Ministry of Justice — Iraqi Gazette Issue 4256 of 2012
Contains publication of Electronic Signatures and Electronic Transactions Law No. 78 of 2012. - Electronic Signatures and Electronic Transactions Law No. 78 of 2012 — Published Legislative Text
For the existing Law’s provisions and Ministry of Communications and certification-body functions. - Ministry of Justice — Iraqi Gazette Issue 4826, 19 May 2025
Publication of Instructions No. 1 of 2025 Implementing Law No. 78 of 2012. - Iraqi News Agency — Securities Commission Adopts Electronic Signatures, 3 May 2026
Evidence of government use of the national certification system. - Iraqi News Agency — Financial and Accounting Training Centre Joins NPKI, 19 June 2026
Recent reference for actual implementation and national certification infrastructure. - Iraqi News Agency — Directive on Governing the National Card as a Unified Electronic Reference, 14 December 2025
Reference for the state’s move towards a unified official identity source. - UNCITRAL — Model Law on the Use and Cross-border Recognition of Identity Management and Trust Services (2022)
Principal international reference for identity management, trust services and cross-border recognition. - UNCITRAL Model Law on Electronic Signatures (2001)
Reference for technological neutrality, functional equivalence and reliability. - UNCITRAL — Model Law on Electronic Transferable Records (2017)
Reference distinguishing transferable records from general electronic-document rules. - European Union — eIDAS Regulation No. 910/2014, Consolidated Text
Comparative reference for trust services, legal effects and electronic identity. - European Union — Regulation 2024/1183 on the European Digital Identity Framework
Recent reference for wallets, attestations of attributes and expanded trust services. - United Arab Emirates — Federal Decree-Law No. 46 of 2021 on Electronic Transactions and Trust Services
Regional model for transactions, digital identity and trusted lists. - Estonia — Electronic Identification and Trust Services for Electronic Transactions Act
Reference for governance, licensing, trusted lists and provider continuity. - World Bank ID4D — Principles on Identification for Sustainable Development
Reference for inclusion, open standards, privacy and governance.
Public sources were consulted through 5 October 2026. External links document sources; publishers may change their structure.
Ali Zuweid’s Political Programme · POL-87