Ali Zuweid's Political Programme
Proposed legislation · Digital state, data, artificial intelligence and cybersecurity
Information Technology Crime, Digital Evidence and Rights and Freedoms Safeguards Law
An integrated criminal and procedural framework defining technical offences, digital-evidence collection, preservation and examination, and judicial limits on surveillance, search and interception.
Executive summary
The proposal coincides with active legislation: Parliament completed the Information Technology Crime Bill's first reading on 6 July 2026, deferred its second reading on 21 September for further hearings and expertise, and the Security and Defence Committee continued discussion on 4 October 2026, agreeing a specialist workshop.[2][3][4] Legislative need is therefore concrete, but lawmakers must combat technical attacks without vague offences usable against criticism, journalism or legitimate internet use.
The proposal distinguishes three frequently conflated matters: genuine technical crime such as unlawful access, system/data damage, interception, fraud and ransomware; digital procedures such as preservation, search, seizure, traffic-data collection and content interception; and digital-evidence rules governing authenticity, custody and testability. Separation improves precision and prevents criminalising expression or merely using dual-purpose tools.
It addresses practical gaps identified by Iraqi courts. The Supreme Judicial Council has noted reliance on Criminal Procedure Law Article (213) for ‘other evidence recognised by law’ and the need for specialist rules on digital evidence, custody/documentation, rapid deletion, falsification and synthetic technologies.[5][6][7]
The proposed balance defines harmful conduct, grades judicially supervised powers, prohibits general retention, mass surveillance and universally weakened encryption, protects good-faith research and establishes national evidentiary standards. It draws on Budapest Convention distinctions and the United Nations Convention against Cybercrime adopted in 2024, without assuming either binds Iraq before constitutional procedures are completed.[8][9]
First — Constitutional and legal context
Constitutional Article (17) protects privacy, Article (38) expression, press and publication, and Article (40) electronic communications/correspondence, permitting monitoring, interception or disclosure only for legal/security necessity and by judicial decision.[1] These are design foundations, not formal restrictions: private-content powers require specificity, proportionality and courts; expression-related offences require precision without punishing mere opinions or criticism.
Penal Code No. (111) of 1969 covers general fraud, threats, secrecy violations and other conduct. Criminal Procedure Law No. (23) of 1971 frames searches, seizure and evidence in pre-digital terms. The Supreme Judicial Council explains that Article (213/A) permits diverse evidence and courts already use recordings/electronic data, but specialist admissibility, extraction and custody rules remain needed.[5][10]
At this document's date, the bill remains in parliamentary discussion after first reading and deferred second reading, with official calls to involve judiciary, Communications and Media Commission, experts and civil society.[2][3][4] A comprehensive new law is therefore preferable to patching old provisions alone, retaining general rules and clarifying their relation to special legislation.
The Budapest Convention distinguishes access, interception, data/system interference and tool misuse from expedited preservation, production orders, searches, real-time collection and content interception.[8] On 24 December 2024, the UN General Assembly adopted the Convention against Cybercrime, which had not entered into force by 30 September 2026; it offers a newer cooperation framework for crime and electronic evidence.[9] The Human Rights Committee requires expression restrictions to be legally prescribed, necessary, proportionate and sufficiently precise against arbitrariness.[11]
Second — Legislative gap
The first is the technical-criminalisation gap. General offences can cover some modern conduct, but data integrity/availability and account/system attacks without traditional physical theft remain uncertain. Specific conduct, not the internet as a public space, should be criminalised.
The second is the procedural gap. Searching phones, servers or clouds differs from drawers or papers: millions of files, third-party information, privileged communications and overseas storage may be involved. Preservation, access and interception require graduated, bounded rather than general orders.
The third is the evidentiary gap. Rapid change/deletion, intangible copying, time differences, encryption, deepfakes and forensic/algorithmic outputs mean screenshots or printed conversations are not always sufficient. Courts need authenticity, integrity and repeat-examination standards.
The fourth is the rights gap. Conflating fraud/hacking with vague ‘offence’, ‘damage to prestige’ or ‘false information’ creates constitutional/practical risks and turns cybercrime bodies into speech regulators. Expressive content is separated from technical offences; legitimate speech restrictions require specific independent rules tested for legality, necessity and proportionality.
Third — Proposed legislative policy
| Issue | Chosen approach | Effect |
|---|---|---|
| Criminalisation scope | Specific technical offences plus traditional offences materially enabled by technology | Legal certainty without general content regulation |
| Surveillance | Graduated preservation-to-interception powers with stronger judicial authority as intrusion grows | Effective investigations protecting constitutional Article (40) |
| Data retention | Targeted preservation of existing data, not population-wide retention under this Law | Reduced privacy risk and unnecessary mass databases |
| Encryption | No general backdoors; institution-controlled data/keys may be sought in specific cases | Preserves economic/service security while enabling lawful investigations |
| Digital evidence | Custody chains, forensic copies, validation, retesting and synthetic-media standards | More reliable judgments and fewer technical challenges |
| Security research | Legal safe harbour for good-faith authorised or disclosure-policy testing | No criminalisation merely for dual-purpose tools |
| International cooperation | 24/7 contact and lawful channels, without unilateral cross-border intrusion | Faster cooperation respecting sovereignty/international law |
Fourth — Draft law
Chapter One — General provisions
Article (1) — Title and legislative operation
This Law is entitled the ‘Information Technology Crime, Digital Evidence and Rights and Freedoms Safeguards Law’, commencing under its final chapter. It is special legislation for expressly regulated conduct and procedural powers; penal, criminal-procedure and other laws apply to unregulated matters insofar as consistent with its safeguards.
Article (2) — Objectives
The Law shall criminalise specified attacks on system/data confidentiality, integrity and availability; combat technology-enabled fraud, extortion and exploitation; precisely regulate digital-evidence collection, preservation, examination and presentation; enable transnational investigation; and prevent cybercrime enforcement becoming a basis for general surveillance, criminalisation of lawful expression or violations of privacy and communications secrecy.
Article (3) — Governing principles
Interpretation/application shall observe legality, necessity, proportionality, precise offences/penalties, presumed innocence, defence, privacy/communications, expression/press/research freedom, verifiable evidence, non-discrimination and only necessary data intrusion for specific crimes. Expansive interpretations shall not create unlegislated criminal or procedural powers.
Article (4) — Subject scope
This Law governs offences targeting systems, computer data, accounts or digital identities or materially using information technology, and electronic-evidence procedures in any crime where necessary for investigation/trial. Digital use does not preclude a more serious statutory classification where elements are met, without double punishment for identical conduct.
Article (5) — Territorial jurisdiction
The Law applies to crimes wholly/partly in Iraq, with substantial Iraqi effects, targeting systems/services/persons there, committed abroad by Iraqis where punishable locally or local law cannot apply, or affecting Iraqi governmental interests/critical infrastructure. International law, judicial cooperation and lawful double-jeopardy protection shall govern jurisdiction.
Article (6) — Definitions
Information system means devices performing automated processing. Computer data means processable representations of facts, information or concepts. Traffic data means source, destination, route, time, volume, duration and service type, excluding substance. Content data means transmitted/stored meaning or messages. Subscriber information means identifying/contractual data connecting services to persons/entities. Service provider means providers of communications, processing, hosting, storage or digital platforms to the public or others. Digital evidence means electronic data with potential evidentiary value. Preservation means preventing alteration/deletion while data remain with holders. Seizure means investigative control of evidence or forensic copies. Encryption means methods protecting confidentiality/integrity. Critical information infrastructure means digital systems/services whose serious disruption substantially harms security, health, the economy or essential services.
Chapter Two — Offences against systems and data
Article (7) — Unlawful access
Intentional unauthorised access to all or part of systems by bypassing safeguards or fraudulent means attracts detention up to one year, fines of five to twenty million dinars, or both. Merely receiving publicly available data or unexploited accidental technical errors is not an offence.
Article (8) — Aggravated access
Unlawful access intended to obtain/alter protected data or enable others, targeting governmental, health, financial, electoral or critical systems, or using stolen/impersonated credentials attracts one to three years' detention and ten to thirty million dinars. Actual harm aggravates sentencing.
Article (9) — Unlawful interception
Intentional unauthorised technical interception of non-public data travelling to, from or within systems, including data-bearing electromagnetic emissions, attracts one to three years' detention and ten to thirty million dinars, or either. Lawful participant recording or judicially authorised monitoring remains unaffected.
Article (10) — Data damage
Unauthorised destruction, deletion, distortion, alteration, concealment, disabling or rendering others' data unusable with harmful or unlawful-gain intent attracts one to three years' detention and ten to forty million dinars. Extensive loss, public-service stoppage or serious financial harm aggravates punishment.
Article (11) — System damage
Intentional unauthorised serious obstruction/disruption through input, transmission, destruction, deletion, suppression, flooding or similar technical means attracts imprisonment up to five years and twenty to fifty million dinars, considering severity, duration and affected numbers.
Article (12) — Critical infrastructure attacks
Access, interception or data/system damage targeting critical infrastructure and capable of seriously endangering life, public safety, national security or essential-service continuity attracts five to ten years' imprisonment and at least fifty million dinars, without prejudice to harsher classifications elsewhere.
Article (13) — Misuse of technical tools/data
Producing, selling, distributing or possessing programmes, devices, passwords, access codes or credentials primarily designed/prepared for chapter offences with criminal-use intent attracts detention up to three years and ten to thirty million dinars. Lawful cybersecurity, testing, research, education or administration tools with reasonable precautions are excluded.
Article (14) — Good-faith security research
Authorised security testing, published-disclosure-policy research or testing in owned/managed environments attracts no criminal liability if limited to proving vulnerabilities, data are used only for protection, no intentional harm occurs and responsible reporting is prompt. Gross-negligence or scope-exceeding civil liability remains.
Article (15) — Accounts and credentials
Unauthorised account takeover/control, credential changes, owner lockout or control transfer for fraud, extortion, espionage or harm attracts one to three years' detention and ten to thirty million dinars. Sensitive financial, governmental or professional accounts attract harsher punishment.
Article (16) — Digital impersonation
Intentional use of others' digital identity, identifiers or credentials for gain, harm or misleading public/private bodies attracts detention up to three years and ten to thirty million dinars. Pseudonyms, parody and unverified accounts are excluded absent specific criminal intent meeting offence elements.
Chapter Three — Technology-enabled offences
Article (17) — Computer-related forgery
Intentional unauthorised data input, alteration, deletion or concealment to make false data treated as genuine for legal, financial or administrative effects attracts imprisonment up to five years and twenty to fifty million dinars, including forged records, documents, signatures or certificates with fraudulent intent.
Article (18) — Computer-related fraud
Intentional financial loss or unlawful gain through data input/change/deletion, system interference, impersonation or digital deception attracts three to seven years' imprisonment and twenty to one hundred million dinars, with restitution/compensation under general rules.
Article (19) — Phishing and credential deception
Intentionally creating, operating or sending deceptive digital means imitating trusted services to obtain passwords, verification codes, payment data or unauthorised-access information attracts one to three years' detention and ten to thirty million dinars. Actual financial/account appropriation aggravates punishment.
Article (20) — Electronic extortion
Digitally threatening private-data/image/recording publication, data destruction, system disruption or unlawful acts to compel money, benefits, action or omission attracts three to seven years' imprisonment and twenty to fifty million dinars, aggravated for child victims or extreme harm.
Article (21) — Ransomware
Using or distributing technical means to encrypt/suppress others' data or disable systems, then demanding money/benefits for access restoration or non-publication, attracts five to ten years' imprisonment and at least fifty million dinars. Critical infrastructure, healthcare or foreseeable death/serious injury aggravates punishment within general limits.
Article (22) — Electronic appropriation of money/services
Unauthorised acquisition of money, credit, paid services or economically valuable digital assets using others' payment data, accounts, identities or systems attracts computer-fraud penalties, with harsher banking/payment/anti-money-laundering provisions where elements are met.
Article (23) — Unlawful private-data disclosure
Unlawfully obtaining private personal data or non-public correspondence then intentionally disclosing it for harm, extortion or gain attracts detention up to two years, five to twenty million dinars, or both. Journalism, research or wrongdoing reports grounded in legitimate public interest and relevant law are excluded.
Article (24) — Non-consensual intimate content
Publishing or threatening identifiable persons' real/synthetic intimate images or recordings without consent for harm, humiliation or extortion attracts one to three years' detention and ten to thirty million dinars. Consent to recording/private sending is not publication consent. Courts shall urgently restrict circulation and protect identity while preserving evidence.
Article (25) — Online child sexual exploitation
Using systems to produce, display, distribute, request or possess child sexual exploitation material or groom children sexually attracts the harsher applicable statutory penalties. Protection/privacy take priority; child victims shall not be criminalised for material arising from exploitation.
Article (26) — Digital stalking and serious threats
Intentional repeated digital monitoring, contact, location tracking or threats objectively causing reasonable physical-safety fear or serious continuing privacy intrusion attracts detention up to two years or five to twenty million dinars. Criticism, argument, incidental contact and lawful journalism are excluded.
Article (27) — Falsifying digital evidence
Intentionally creating, altering or deleting evidence, metadata or logs to mislead investigators/courts, incriminate innocent persons or conceal perpetrators attracts imprisonment up to five years and twenty to fifty million dinars, including synthetic media/deepfakes with that intent.
Article (28) — Obstructing digital investigations
Destroying, concealing or changing data after knowledge of valid preservation/production/seizure orders, or deliberately supplying false data in response, attracts detention up to three years and ten to thirty million dinars. Silence or refusal of self-incriminating statements alone is not punishable.
Chapter Four — Common liability and penalties
Article (29) — Attempts
Attempts at imprisonment-punishable offences follow general rules. Voluntary abandonment before harm and effective prevention may mitigate, unless an independent offence is already complete.
Article (30) — Participation
Penal Code principal, accomplice, instigator and assistance rules apply. Providers, developers, researchers and publishers are not accomplices merely for general lawful-use tools/services absent specific knowledge and intentional contribution to criminal plans.
Article (31) — Legal-person liability
Without prejudice to individuals, entities may be liable for crimes committed in their name/interest by authorised managers/representatives or through gross supervision failure. Penalties comprise fines, confiscation, compensation and compliance; dissolution requires exceptional primarily criminal purpose and reasoned judgment.
Article (32) — General aggravation
Aggravating factors include organised groups, numerous victims, public-office/administrative/confidential-data abuse, child/vulnerable victims, serious loss/disruption, critical infrastructure and repetition. Punishment remains proportionate to conduct, harm and intent.
Article (33) — Mitigation and cooperation
Courts may consider early voluntary reporting, stopping harm, restoring money/data, substantial detection assistance and effective compliance within legal limits, without unjustified exemption for serious harm or victim-rights violations.
Article (34) — Confiscation
Courts shall confiscate criminal proceeds and offender-owned tools primarily used in offences, protecting good-faith third parties. Entire devices, servers or platforms shall not be confiscated where relevant data/tools can be separated, nor disproportionately disrupt public services or innocent users' rights.
Article (35) — Compensation and restoration
Criminal judgments do not prejudice compensation for directly connected material/moral harm and response/recovery costs. Courts may restore accounts, money or data or reverse unlawful technical effects where feasible without compromising evidence or third-party rights.
Chapter Five — Preservation and production orders
Article (36) — Graduated procedures
Investigators shall use the least intrusive adequate lawful means. Preservation, stored-data production, search/seizure, real-time traffic collection and content interception are distinct; lighter powers shall not disguise access requiring stronger safeguards.
Article (37) — Expedited preservation
On reasoned request, investigating judges may order persons/providers to preserve specified existing controlled data reasonably at risk of loss/change and necessary to specific investigations. Orders last ninety days, renewable once with reasons, without authorising inspection/use before appropriate legal powers are obtained.
Article (38) — Preservation confidentiality
Judges may temporarily prohibit order disclosure for genuine investigative risk, proportionately and reviewably. Confidential legal/compliance consultation or mandatory competent-regulator disclosure remains permitted.
Article (39) — Partial traffic-route disclosure
Where needed to trace specific communications, judges may require preserving providers to disclose only necessary next-provider/route information, documenting every disclosure without unnecessary data.
Article (40) — Subscriber information
Judges may order specified investigation-relevant subscriber information, identifying account/service, period and purpose. It excludes content and cannot expansively encompass messages or detailed browsing histories.
Article (41) — Stored-data production
Compelled private files/content require reasoned judicial orders specifying type, account/system, period, crime and expected relevance. Requests shall be as specific as possible; undefined general or broad unrelated-person collection orders are prohibited.
Article (42) — Public bodies
Government-held data receive identical safeguards. Government ownership does not remove judicial requirements for correspondence, personal data or protected information. Professional secrecy/national security rules shall permit independent judicial review.
Article (43) — No general retention
This Law does not authorise indiscriminate retention of all communications/internet users merely for possible future need. Duties concern targeted existing specified data unless separate express constitutional legislation establishes necessary, proportionate, judicially supervised retention.
Chapter Six — Search, seizure and digital forensics
Article (44) — Search authorisation
Private systems/media searches require investigating-judge orders identifying crime, data/categories, system/place and scope. Statutory flagrante-delicto exceptions require immediate judicial presentation and do not authorise unlimited digital searches.
Article (45) — Scope limits
Searches shall minimise irrelevant exposure using time, account, subject or technical filters. Search shall stop when required categories exceed authority, obtaining additional orders where needed.
Article (46) — Forensic copies and originals
Where possible, documented forensic images shall replace originals for examination, with hashes or equivalent checks before/after. Technical/operational impossibility requires recorded reasons and alternatives preserving integrity and retestability.
Article (47) — Connected systems
Where authorised data reside on another system lawfully accessible from the searched system, judges may urgently extend orders. This does not authorise territorial overreach or foreign intrusion without treaties or lawful international cooperation.
Article (48) — Data rather than devices
Seizure shall cover necessary data/media only. Work devices, production servers or whole institutions shall not be seized where reliable specified copies suffice, unless devices themselves are criminal tools/targets or evidence cannot technically separate. Detention periods shall be minimised and lawful data copies provided where possible.
Article (49) — Technical assistance
Judges may require reasonably knowledgeable persons to assist access, copying or structural interpretation without compelling accused persons' self-incriminating mental testimony. Memorised secrets shall not be compelled where essentially testimonial against their holder.
Article (50) — Encryption and no general backdoors
Providers/manufacturers shall not be required to weaken all users' encryption, create backdoors or general surveillance capabilities absent originally. Specific judicial orders may require intelligible available data or institution-controlled keys/decryption without new systemic weaknesses.
Article (51) — Professionally protected data
Likely lawyer-client, confidential journalistic, highly sensitive medical or privileged material requires independent judicial filtering before investigators access it. Judges, independent experts or separation teams may perform review.
Article (52) — Journalistic materials and sources
Searches to identify confidential journalistic sources require serious-crime investigations, demonstrated necessity, unavailable less intrusive means and special reasoned judicial orders. Embarrassing/leaked public-interest publication alone shall not trigger investigation absent intentional participation in independent offences.
Article (53) — Out-of-scope evidence
New-offence data beyond orders may be examined only as needed to stop imminent life danger or preserve evidence, then require fresh judicial permission before substantive use in another investigation.
Chapter Seven — Real-time collection and interception
Article (54) — Real-time traffic data
For crimes punishable by at least three years' imprisonment, investigating judges may authorise targeted real-time traffic collection for specified communications, accounts or devices where necessary and less intrusive means insufficient. Orders specify scope/provider and last no more than thirty days unless judicially extended with reasons.
Article (55) — Content interception
Content interception/listening requires special judicial orders in serious-felony investigations, serious grounds for material evidence and inadequate alternatives. Orders shall identify persons/accounts/devices, communication type, minimisation and periods up to thirty days, renewable while conditions persist.
Article (56) — Minimisation and irrelevant conversations
Implementers shall stop/minimise clearly irrelevant recording and separate professionally confidential/privileged communications. Irrelevant material shall be promptly deleted when legal need ends unless judges specifically preserve it for challenge/accountability.
Article (57) — Mass surveillance prohibited
Interception/real-time orders shall not target broad populations, areas or entire services without judicially reviewable investigative subjects and individual/technical targets. Cybercrime enforcement alone does not justify comprehensive or continuous secret surveillance of all communications.
Article (58) — Recording and audit
Protected logs shall record judicial-order identifiers, executing bodies, start/end times, systems, result access counts and scope departures, accessible to competent judges and authorised oversight.
Article (59) — Subsequent notification
After covert interception ends and investigative danger passes, affected persons shall receive enough notice to challenge legality, unless judges defer for specified serious ongoing-investigation or protection reasons. Deferral shall not become permanent without periodic judicial review.
Article (60) — Imminent danger
For specific imminent threats to life or serious bodily safety, authorities may request immediate preservation and voluntary lawful subscriber/traffic information locating danger. Content interception or compulsory acquisition still requires courts, with judicial duty arrangements enabling urgency.
Chapter Eight — Digital-evidence admissibility and custody
Article (61) — Admissibility
Relevant lawfully collected/preserved digital evidence is admissible where courts can assess authenticity, integrity, provenance and extraction. Electronic form alone neither excludes it nor confers automatic weight through platforms, seals or hashes.
Article (62) — Evidentiary weight
Courts shall consider relevant system integrity, custody, hashes, creation/change logs, extraction reliability, retesting, timestamp consistency, expert reports and manipulation/synthetic-generation risks. Not every factor is required where evidence nature does not demand it.
Article (63) — Chain of custody
From seizure/copying, every receipt, transfer, storage, duplication and examination shall log person, time, purpose and action. Unexplained gaps affect weight and may justify exclusion for material integrity doubt; minor formal errors alone do not exclude otherwise authenticated evidence.
Article (64) — Technical documentation
Reports shall appropriately describe sources/devices, tools/versions, material settings, hashes, extraction, timezone, conversion/recovery/decryption and known errors/limits. Parties shall receive retesting information without unrelated technical secrets.
Article (65) — Synthetic media and deepfakes
Serious disputes over AI-generated/modified recordings, images, audio or documents require independent examination where necessary and assessment of provenance, context, metadata and custody. Unexplainable/untestable automated indicators alone shall not convict.
Article (66) — Automated/algorithmic outputs
Forensic, matching, classification and identification outputs require methods, error rates and limitations. Parties may examine experts and challenge tools. Algorithmic recommendations alone do not establish intent, identity or criminal responsibility.
Article (67) — Platform/provider data
Provider records may be used with proven attribution, retention and delivery methods, without presumed infallibility. Defence may seek information testing completeness, changes, automated inferences and third-party inputs.
Article (68) — Copies, translations and extracts
Reliable copies, extracts or readable conversions may be submitted where conformity is proven/verifiable. Encrypted, foreign-language or technical evidence requires translations/explanations, preserving originals and disputed examination access.
Article (69) — Unlawful evidence
Courts may exclude evidence obtained through serious constitutional violations, beyond judicial scope or in ways undermining fairness or reliability. They shall weigh violation severity, evidentiary connection and less intrusive remedies without legitimising unlawful surveillance.
Article (70) — Defence copies/examination
Under judicial supervision and third-party privacy safeguards, defence may receive copies or suitable access to prosecution evidence and necessary reports, tools and data. Security/privacy barriers to copies require effective independent-testing alternatives.
Chapter Nine — Providers and platforms
Article (71) — Lawful cooperation
Providers shall reasonably promptly execute valid scoped orders and judicial confidentiality, with court challenges for technical impossibility, overbreadth, legal conflicts or disproportionate effects on unrelated persons.
Article (72) — No general monitoring duty
Providers need not monitor all transmitted/stored content or actively seek illegality. Lawful hosting, transport or caching alone creates no criminal liability absent intentional participation in specific crimes or deliberate non-compliance with valid orders.
Article (73) — Government-request transparency
Providers may periodically disclose aggregate request/order numbers, types and compliance/refusal rates without investigative harm. Competent courts shall annually publish aggregate preservation, production and interception statistics unless specific security considerations prevent.
Article (74) — Compliance staff and whistleblowers
Good-faith execution of believed-valid orders or refusal of unlawful action attracts no staff criminal liability absent intentional concealment, evidence destruction or overreach. Reports of illegal requests/surveillance abuse receive whistleblower/public-service safeguards.
Article (75) — Cross-border orders
Foreign-controlled/stored data require effective legal-assistance, treaty or international mechanisms. Technical accessibility alone does not override sovereignty. Publicly available or validly consensual access is excepted only within international law.
Chapter Ten — Accused/victim rights and freedoms
Article (76) — Legality and lawful expression
Opinions, criticism, news, rumours, erroneous information, satire and religious/political/social content alone are not offences unless conduct meets specific elements herein or other constitutional legislation. Vague state-prestige, public-interest or inappropriate-content labels shall not independently punish.
Article (77) — Press and research freedom
Access, possession or disclosure offences shall not criminalise legitimate journalistic/research receipt of source information without participation in unlawful acquisition. Applicable privacy/protected-secret laws remain where substantive conditions are met.
Article (78) — Silence and self-incrimination
Accused persons may remain silent and shall not be compelled to testify against themselves. Refusal to reveal memorised passwords alone does not establish guilt. Lawful seizure, technical methods or institutional non-personal keys/data production under orders remain possible.
Article (79) — Counsel
Persons directly affected by questioning, search or seizure may obtain counsel under criminal procedure. Covert technical measures preventing presence shall be fully recorded for later legality/scope challenge.
Article (80) — Victim data
Authorities/courts shall prevent republication of private/sensitive criminal material, restrict access to professional need and redact published decisions where possible. Evidence collection shall not unnecessarily increase victim harm.
Article (81) — Limited judicial removal/blocking
Courts may remove or disable specified material proven a criminal tool/proceed or direct continuing harm, identifying URLs/accounts/files wherever possible, allowing challenge and time limits where appropriate. Whole-platform/site blocking for separable material requires unavailable less restrictive means and proven necessity.
Article (82) — Proportionate detention/restrictions
Electronic character alone does not justify detention, travel bans or all-device confiscation. Criminal-procedure necessity, flight, evidence-tampering and repetition risks apply, preferring adequate less restrictive measures.
Article (83) — Vulnerable groups
Investigations/trials shall accommodate children, disability, extortion and gender-based violence victims and others at special risk, with confidential reporting, psychological/legal support and avoidance of unnecessary confrontation, preserving defence rights.
Chapter Eleven — Institutional competence and cooperation
Article (84) — Existing-institution specialist units
Competent decisions shall establish/designate cybercrime/evidence units within existing enforcement, prosecution and technical staffing, without new independent security agencies. Investigating judges supervise within constitutional/statutory competence.
Article (85) — Laboratories and experts
National published accreditation standards shall cover staff competence, tool validation, records, evidence and quality. Lawfully registered independent experts may assist; no monopoly shall prevent defence counter-examination.
Article (86) — Judicial training
Judicial/technical bodies shall continually train judges, prosecutors, investigators and experts in evidence, custody, encryption, transnational crime, synthetic media, privacy and expression, periodically updating guidance.
Article (87) — Round-the-clock contact
The Council of Ministers, Supreme Judicial Council, Interior and Foreign Affairs shall designate national continuous contact for preservation, urgent assistance and international coordination, without extra-legal seizure/interception powers.
Article (88) — International legal assistance
Collection, transfer and preservation assistance shall follow effective treaties, judicial-assistance law and national rules, respecting speciality, data and procedural safeguards. Requests may be refused for fundamental-rights violations, purely political character or missing legal grounds.
Article (89) — International networks
Authorities shall use lawful police/judicial and rapid-response networks and prepare for international obligations, without treating treaties not effective for Iraq as direct domestic duties before constitutional completion.
Chapter Twelve — Oversight, accountability and statistics
Article (90) — Annual statistics
Courts, Interior and relevant bodies shall publish aggregate case numbers/types/outcomes, preservation/search/interception orders and cooperation requests, protecting secrecy/data. Reports assess legislation, resources and safeguards rather than create personal watchlists.
Article (91) — Interception register
A confidential central judicial register shall record traffic/content orders, extensions, refusals and reviews, enabling authorised oversight of proportionality/time limits. Public reports shall not identify persons.
Article (92) — Abuse accountability
Officials/public-service persons intentionally misusing powers, disclosing occupationally obtained data or intercepting without judicial authority face existing criminal penalties, with official status aggravating where appropriate and victim compensation/challenge rights.
Article (93) — Data destruction
Courts shall set post-case evidence/interception retention by case and appeal types. Irrelevant or restored data from forensic copies shall be destroyed after legal need ends, documenting destruction to prevent unofficial copies.
Article (94) — Periodic review
Every three years, government shall report to Parliament on crime trends, procedural effectiveness, rights effects, technical/international developments and amendments. Reports cannot administratively expand offence elements/powers; material expansion requires legislation.
Chapter Thirteen — Transitional and final provisions
Article (95) — Penal Code relationship
Penal Code No. (111) of 1969, as amended, continues for digitally committed general offences where elements are met; this Law governs specific technical attacks/procedures. Overlapping provisions follow concurrence/connection rules and the harsher penalty without duplication.
Article (96) — Criminal Procedure relationship
These special digital procedures supplement Criminal Procedure Law No. (23) of 1971, as amended. General safeguards remain and shall not be interpreted downward from statutory or constitutional protection.
Article (97) — Data protection and cybersecurity
Implementation shall observe personal-data/privacy, cybersecurity, critical infrastructure, communications and electronic-transaction legislation. Cybersecurity duties do not prevent judicial evidence preservation; investigations do not displace minimisation/limited retention.
Article (98) — Existing proceedings
Valid pre-commencement procedures remain under then-effective rules. New procedures apply subsequently where more protective without invalidating prior acts. More favourable criminal provisions follow general rules.
Article (99) — Regulations and instructions
Within one hundred and eighty days of publication, competent bodies shall technically regulate custody, forensic imaging, preservation/production coordination, statistics and contact points, without creating new offences, penalties or surveillance powers.
Article (100) — Judicial guidance
The Supreme Judicial Council and technical bodies shall issue digital-evidence guidance covering forms, standards and practical procedures. Guidance shall neither bind judicial evidentiary discretion nor replace legislation.
Article (101) — Legislative harmonisation
Within one year of commencement, the Council of Ministers shall draft relevant amendments, especially paper/place-only search/seizure provisions or gaps in digital-communications confidentiality, submitting them constitutionally to Parliament.
Article (102) — Conflicting provisions
Express conflicts are repealed only to their extent, without abolishing other statutory rights/safeguards. Overlapping penal texts shall preserve certainty and avoid duplicate criminalisation.
Article (103) — Commencement
The Law takes effect one hundred and eighty days after Official Gazette publication. Instructions, training and technical-unit preparation provisions apply from publication; new investigative powers shall not be used before substantive commencement.
Fifth — Explanatory reasons
This Law is proposed for rapid information/communications growth and increasing system/data/account attacks, fraud and extortion; because traditional criminal/procedural rules alone cannot adequately address transient transnational data; to unify digital-evidence collection, preservation, examination and judicial presentation; and to subject search, preservation and surveillance to legality, necessity, proportionality, judicial review, privacy, communications and expression safeguards.
Sixth — Explanatory memorandum
1. Why a new law?
The Penal Code and Criminal Procedure Law remain Iraqi criminal justice's foundation. The proposal addresses conduct/procedures absent from their original technical environment. Traditional fraud/threat offences do not precisely answer system disruption, data change, traffic interception or account takeover, nor searches of devices holding ten years of hundreds of people's data.
2. Separating crime from content
Online opinions, news or criticism shall not become ‘cybercrime’ merely through technology. Legitimate reputation or anti-violence-incitement rules must be independent, precise and constitutional rather than hidden in vague technical legislation. This reduces abuse and focuses police/courts on actual attacks.
3. Graduated powers
Preservation prevents deletion without disclosure. Subscriber/stored-data orders, search/seizure, real-time traffic collection and finally content interception progressively increase intrusion, each requiring clearer conditions. This enables oversight and prevents indiscriminate all-at-once demands.
4. Digital evidence is more than screenshots
Practical criteria—source, system integrity, custody, hashes, metadata, extraction and retesting—replace rigid rules. Minor errors are assessed for real consequences rather than automatic exclusion. Synthetic content, deepfakes and algorithmic forensic outputs are expressly included, reflecting Iraqi judicial discussions in 2026.[6]
5. Encryption and compliance
Encryption secures banking, government and personal communications; it is not inherently criminal obstruction. General backdoors are prohibited, while courts may require existing institution-controlled data/decryption in specific cases, avoiding permanent weaknesses in national infrastructure.
6. No new authority
Investigation remains within courts and existing enforcement bodies, supported by specialist units, laboratories, experts and quality standards rather than independent new security agencies. This reduces overlap/cost, leaving preventive cybersecurity/risk management to its institutions and focusing here on crime, procedure and evidence.
7. International cooperation
Digital crimes cross borders in seconds. Continuous national contact, expedited preservation and judicial assistance support cooperation without unilateral foreign-system intrusion, respecting sovereignty and treaty-accession procedures.
Seventh — Legislative harmonisation
| Legislation/area | Position | Proposed alignment |
|---|---|---|
| Penal Code No. 111 of 1969, as amended | General offences, participation, concurrence and penalties remain. | Retain, treating this Law as specific to defined technical attacks. |
| Criminal Procedure Law No. 23 of 1971, as amended | General investigation, search and evidence. | Add specific preservation, digital search, interception and custody rules. |
| Electronic Signature and Electronic Transactions Law No. 78 of 2012 | Evidentiary validity and electronic transactions within its scope. | Avoid conflicts; distinguish transactional validity from digital criminal evidence. |
| Data/privacy legislation | Lawful data processing. | Purpose-limited justice processing with minimisation and limited retention. |
| Cybersecurity legislation | Prevention, resilience and incident management. | Separate technical response from criminal investigation with referral/preservation channels. |
| Communications and digital services | Providers and communications infrastructure. | Judicial compliance without general monitoring or permanent content-inspection duties. |
Eighth — Implementation and transition
Effective commencement requires limited but specialised preparation: standard digital orders, confidential judicial registers, laboratories capable of imaging/validation/modern-device handling, judicial/investigator training and continuous contact. Most can occur within existing institutions.
| Time from publication | Action | Bodies |
|---|---|---|
| 0–90 days | Designate contact, prepare preservation/production/search forms and inventory laboratories. | Supreme Judicial Council, Interior, Foreign Affairs and technical bodies |
| 0–180 days | Technical instructions, initial training and custody updates. | Competent bodies within their powers |
| At 180 days | New powers/offences substantively commence. | All bodies |
| Within one year | Submit related harmonisation amendments. | Council of Ministers to Council of Representatives |
| Annually | Publish aggregate case, order and cooperation statistics. | Competent judicial/executive bodies |
| Every three years | Review legislative effects and technical/rights trends. | Government and Parliament |
Ninth — Financial and implementation impact
No new independent authority or broad administrative network is required. Costs concern forensic laboratories, secure storage, examination licences, training, contact-point duty staffing and order registries. Public laboratory, readiness and caseload data do not support reliable costing; no falsely precise figure is provided.
Before substantive commencement, executive costing shall distinguish reusable capacity, storage/analysis gaps, licensing/maintenance, training, repository security and duty personnel. Budgets should compare national-laboratory investment with excessive outsourcing or technically caused case delays.
Tenth — Relevant international comparison
Budapest Convention: Its value lies in offence/procedure architecture, not copied penalties: unlawful access, interception, data/system interference, tool misuse, expedited preservation, production, search, real-time collection and interception. Iraqi constitutional safeguards are more explicit; effectiveness for Iraq is not presumed before accession proposed separately.[8]
United Nations Convention against Cybercrime: It offers a newer global cooperation/electronic-evidence framework. The UN treaty record as of 30 September 2026 showed it not internationally effective because required ratifications had not been reached.[9] It is therefore a future-alignment reference, not an automatically binding obligation.
Human-rights standards: Expression restrictions must be precise, no broader than necessary, and justified by state-proven necessity/proportionality. General ‘electronic offence’ or absolute false-information crimes are excluded in favour of defined fraud, threats, extortion and forgery.[11]
Eleventh — Sources and references
- Iraqi Council of Representatives — Constitution of the Republic of Iraq, 2005. Especially Articles 17, 38 and 40. Official source.
- Iraqi Council of Representatives, 6 July 2026. First reading of the Information Technology Crime Bill completed. Source.
- Iraqi Council of Representatives, 21 September 2026. Second reading deferred; judiciary, authorities and civil-society hearings requested. Source.
- Parliamentary Security and Defence Committee, 4 October 2026. Bill discussion and specialist-workshop decision. Source.
- Supreme Judicial Council, 17 September 2025. ‘Electronic Evidence in Criminal Proof’, discussing Criminal Procedure Article 213 and specialist legislation. Source.
- Supreme Judicial Council, 16 September 2026. Meeting on electronic-extortion evidence and falsification-capable algorithms. Source.
- Judicial Development Institute, 24 May 2026. Digital evidence, custody, documentation and cross-border challenges workshop. Source.
- Council of Europe — Convention on Cybercrime (Budapest), ETS No. 185. Offences, procedures and international cooperation. Source.
- United Nations — Convention against Cybercrime, General Assembly Resolution 79/243 and treaty-status record. Convention text; Signature and ratification status.
- Supreme Judicial Council, 13 February 2020. ‘Audio Recordings in Criminal Evidence’, referencing Criminal Procedure Articles 74, 75 and 213. Source.
- Human Rights Committee — General Comment No. 34 on International Covenant on Civil and Political Rights Article 19. Clarity, necessity and proportionality in expression restrictions. Arabic text.
Proposed legislative document within Ali Zuweid's Political Programme · POL-89