Skip to content
POL-87

This is a proposal for discussion, not an enacted law.

Ali Zuweid’s Political Programme

Proposed draft law · Digital State, Data, Artificial Intelligence and Cybersecurity

Digital Identity, Trust Services, Electronic Signatures and Transactions Law

A unified legislative framework for digital identity and trust services, developing the 2012 Electronic Signatures and Electronic Transactions Law into a modern interoperable system supporting cross-border recognition while protecting rights, privacy and security.

Document number
POL-87
Version
1.0
Publication / last update date
5 October 2026
Scope
Republic of Iraq

Executive Summary

Iraq has had Electronic Signatures and Electronic Transactions Law No. (78) since 2012, but practical implementation took more than a decade before Instructions No. (1) of 2025 were issued. During 2026, government bodies began joining the national electronic-signature certification system. These important steps operate within a law drafted before modern digital identity, multiple trust services, cross-border recognition, digital wallets, attestations of attributes, electronic delivery and archiving developed.

The proposal replaces the 2012 Law with modern legislation extending beyond signature certificates. It establishes digital identity and assurance levels, recognises diverse trust services, distinguishes ordinary and qualified services, regulates licensing, the national trusted list and national public key infrastructure, and specifies legal effects of electronic signatures, seals, timestamps, delivery and archiving, with recognition of foreign services based on substantive equivalence.

The Law does not turn digital identity into a new central database collecting all information. It connects identity to authoritative registers and promotes selective disclosure and data minimisation. It separates regulation from commercial or government service operation and preserves existing certificates and licences during transition to avoid interrupting transactions begun under the current framework.

Second — Legislative Gap

The existing Law was drafted when electronic signatures and certification certificates were central. Today’s digital environment also includes digital identity, multiple assurance levels, wallets, electronic seals for legal persons, timestamps, registered electronic delivery, trustworthy archiving, website authentication certificates and attestations of attributes. Cross-border recognition is now integral to digital commerce and services.

Combining regulatory and operational roles also creates an institutional problem. The current framework assigns licensing, standards and monitoring to a Ministry of Communications state company, while modern governance requires functional separation between market regulation and service provision or competition with providers. This becomes more important as NPKI develops into national infrastructure relied on by public and private sectors.

Another gap is the absence of a comprehensive legal system for digital identity itself: who issues foundational identity, what assurance levels apply, how company representation or agency is established, how credentials are recovered after a phone is lost, what minimum data may be disclosed, and how foreign identities or signatures are recognised. The proposal addresses these without turning legislation into a rigid technical specification.

Third — Proposed Legislative Policy

Principal Legislative Choices
IssueProposed choicePurpose
Existing LawRepeal and replace Law No. 78 of 2012 with an orderly transitionPrevent two conflicting frameworks
Foundational identityUse the national card and authoritative registers, without a parallel civil registerPreserve responsibilities and prevent data duplication
Trust levelsAssurance levels proportionate to transaction risksAvoid excessive requirements for simple services
Trust servicesRegulate a broad range beyond signature certificatesSupport modern digital government and economy
RegulationA specialised Ministry of Communications regulatory directorate functionally separate from operatorsReduce conflicts without a new independent authority
International recognitionSubstantive equivalence rather than technical identityCross-border commerce and services
PrivacyData minimisation, selective disclosure and reference to data protection legislationPrevent digital identity becoming a tool for universal tracking

Fourth — Draft Law

Fifth — Statement of Reasons

To modernise Iraq’s electronic-transactions framework more than a decade after Law No. (78) of 2012; accommodate digital identity, trust services and national public key infrastructure; provide clear legal effects for electronic signatures, seals, timestamps, delivery, archiving and attestations of attributes; regulate and supervise providers and separate regulation from operation; enable recognition of foreign services through substantive equivalence; and protect privacy, security and universal access, this Law is enacted.

Sixth — Explanatory Memorandum

1. Why repeal and replace?

The 2012 Law emerged in a different legal and technical environment, primarily addressing signatures, documents and certification bodies. The 2025 instructions improved implementation but cannot alone create legal effects in areas the Law never regulated. Replacement is therefore more coherent than accumulating partial amendments to a conceptually limited law.

2. Why no new independent authority?

Regulation requires functional independence from providers, not necessarily a new constitutionally independent or costly institution. The proposal therefore creates a specialised Ministry of Communications directorate and prohibits combining licensing, oversight and competitive operation in one unit. Its functions could later transfer to a broader regulator if telecommunications and digital services are reorganised under POL-91.

3. Digital identity and the national card

Digital identity is not a new population register. Names, dates of birth, nationality and civil status originate from the competent register. Digital identity enables electronic proof of identity or attributes at an appropriate assurance level. This separation reduces inconsistent databases and prevents every body creating its own copy of citizens’ identities.

4. Assurance levels

Transactions need different assurance. Reading public-service information or submitting a complaint may need simple verification, while opening a financial account, signing a high-value contract or accessing a sensitive record needs greater assurance. Technical details remain in regulations and standards for updating without repeated statutory amendment.

5. Legal effect of signatures

The proposal distinguishes electronic signatures generally from advanced and qualified signatures. Unqualified signatures retain evidentiary value assessed through circumstances and evidence; qualified signatures gain a stronger legal presumption, balancing innovation and certainty.

6. Broader trust services

Government and commercial transactions need more than an individual’s signature. Institutions need electronic seals; contracts and records may need time evidence; notices need proof of dispatch and receipt; long-term documents need archiving that preserves verifiability; and platforms need proof linking a website to a responsible entity. A single framework prevents fragmentation and lowers integration costs.

7. User protection

Digitalisation does not mean forcing everyone to use smartphones. The proposal requires reasonable alternatives and accessibility, limits requested data, encourages selective disclosure and lets users know which body verified their identity where law permits. General data-protection rules govern the whole system.

8. Cross-border recognition

Substantive equivalence follows UNCITRAL approaches: a foreign country need not use the same algorithm or institutional structure, but its service must provide reliability and protection equivalent to the Iraqi legal purpose. This matters for trade, contracts, companies, investors, consular and cross-border services.

Seventh — Alignment with Existing Legislation

Principal Alignment Pathways
Legislation / areaRelationshipRequired action
Electronic Signatures and Electronic Transactions Law No. 78 of 2012Fully overlaps with the proposalRepeal with transition of licences, certificates and records
Instructions No. 1 of 2025Contain modern technical and operational arrangementsTemporary continuation where consistent, followed by replacement regulations
National Card Law No. 3 of 2016Source of foundational civil identityLegal and technical connection without a parallel register
Evidence, procedural, civil and commercial transaction lawsDetermine evidentiary force, form and proceduresAmend exclusively paper or handwritten-signature references where functional equivalence is possible
Proposed Personal Data Protection and Digital Privacy Law POL-85Governs identity and trust data processingExpress reference and coordination on incidents, records and rights
Proposed Digital Government Law POL-86Regulates public-sector use of digital componentsIntegrate identity, signatures and seals with the Ur Portal and interoperability
Proposed Cybersecurity Law POL-88Governs risks, incidents and critical infrastructureCoordinate reports and security requirements without duplicate supervision
Sectoral laws: banking, companies, taxation, notaries and property registrationContain specific identity and form requirementsSectoral review without assuming automatic repeal of substantive conditions

Eighth — Financial and Implementation Impact

The proposal does not logically require building a digital system from scratch: Iraq has begun operating NPKI and has national-card infrastructure, the Ur Portal, providers and bodies already using electronic signatures. Spending should therefore focus on governance reorganisation, standards and conformity assessment, stronger national-root and continuity arrangements, register integration, secure verification interfaces and support for existing entities’ transition.

Financing approach: no aggregate numerical cost should be enshrined before a technical inventory of existing assets, contracts, systems, keys and data centres. Before major expansion, the Council of Ministers shall prepare a five-year estimate separating regulation and supervision, shared national infrastructure, register integration, public-body support and recurring operations. Qualified-service fees may recover some oversight costs while basic citizen identity remains financially accessible.

The principal administrative effect is moving regulation into a unit functionally separate from operation and reassessing existing licences against uniform requirements. Legislative transition lasts 18–24 months to avoid undermining trust in currently used certificates.

Ninth — Useful International Comparison

UNCITRAL: its 2022 Model Law on the Use and Cross-border Recognition of Identity Management and Trust Services is the proposal’s principal international reference. It focuses on functional equivalence and reliability of identification methods or trust services, enabling cross-border recognition without requiring one institutional model. The proposal also draws on the 2001 Model Law on Electronic Signatures and electronic-commerce principles.

European Union: eIDAS, amended in 2024 to establish the European Digital Identity Framework, demonstrates the value of unified legal effects for signatures, seals, timestamps, delivery, archiving and attestations of attributes, with trusted lists and qualified providers. The proposal adapts that legal structure to Iraq rather than copying the European model verbatim.

United Arab Emirates: Federal Decree-Law No. 46 of 2021 on Electronic Transactions and Trust Services offers a regional model combining transactions, identity and trust services, regulating trusted lists and acceptance of digital identity. It is useful given the regional legal environment and future mutual-recognition needs.

Estonia: its Electronic Identification and Trust Services for Electronic Transactions Act illustrates separation of competent authority and providers, trusted lists, conformity assessment and service-termination plans. Strong digital identity needs continuity and liability rules, not merely a card or application.

World Bank ID4D: identification-for-development principles emphasise universal coverage, removing access barriers, open standards, vendor and technology neutrality, privacy and control by design, accountability and oversight. The proposal therefore avoids mandatory smartphone ownership and adopts data minimisation and selective disclosure.

Tenth — Sources and References

  1. Constitution of the Republic of Iraq — Iraqi Council of Representatives
    Constitutional reference for rights, freedoms and federal powers.
  2. Ministry of Justice — Iraqi Gazette Issue 4256 of 2012
    Contains publication of Electronic Signatures and Electronic Transactions Law No. 78 of 2012.
  3. Electronic Signatures and Electronic Transactions Law No. 78 of 2012 — Published Legislative Text
    For the existing Law’s provisions and Ministry of Communications and certification-body functions.
  4. Ministry of Justice — Iraqi Gazette Issue 4826, 19 May 2025
    Publication of Instructions No. 1 of 2025 Implementing Law No. 78 of 2012.
  5. Iraqi News Agency — Securities Commission Adopts Electronic Signatures, 3 May 2026
    Evidence of government use of the national certification system.
  6. Iraqi News Agency — Financial and Accounting Training Centre Joins NPKI, 19 June 2026
    Recent reference for actual implementation and national certification infrastructure.
  7. Iraqi News Agency — Directive on Governing the National Card as a Unified Electronic Reference, 14 December 2025
    Reference for the state’s move towards a unified official identity source.
  8. UNCITRAL — Model Law on the Use and Cross-border Recognition of Identity Management and Trust Services (2022)
    Principal international reference for identity management, trust services and cross-border recognition.
  9. UNCITRAL Model Law on Electronic Signatures (2001)
    Reference for technological neutrality, functional equivalence and reliability.
  10. UNCITRAL — Model Law on Electronic Transferable Records (2017)
    Reference distinguishing transferable records from general electronic-document rules.
  11. European Union — eIDAS Regulation No. 910/2014, Consolidated Text
    Comparative reference for trust services, legal effects and electronic identity.
  12. European Union — Regulation 2024/1183 on the European Digital Identity Framework
    Recent reference for wallets, attestations of attributes and expanded trust services.
  13. United Arab Emirates — Federal Decree-Law No. 46 of 2021 on Electronic Transactions and Trust Services
    Regional model for transactions, digital identity and trusted lists.
  14. Estonia — Electronic Identification and Trust Services for Electronic Transactions Act
    Reference for governance, licensing, trusted lists and provider continuity.
  15. World Bank ID4D — Principles on Identification for Sustainable Development
    Reference for inclusion, open standards, privacy and governance.

Public sources were consulted through 5 October 2026. External links document sources; publishers may change their structure.

Ali Zuweid’s Political Programme · POL-87

What are you looking for?

Search content published on the website.