Skip to content
POL-89

This is a proposal for discussion, not an enacted law.

Ali Zuweid's Political Programme

Proposed legislation · Digital state, data, artificial intelligence and cybersecurity

Information Technology Crime, Digital Evidence and Rights and Freedoms Safeguards Law

An integrated criminal and procedural framework defining technical offences, digital-evidence collection, preservation and examination, and judicial limits on surveillance, search and interception.

Document number
POL-89
Version
1.0
Publication/latest update
7 October 2026
Scope
Republic of Iraq

Executive summary

The proposal coincides with active legislation: Parliament completed the Information Technology Crime Bill's first reading on 6 July 2026, deferred its second reading on 21 September for further hearings and expertise, and the Security and Defence Committee continued discussion on 4 October 2026, agreeing a specialist workshop.[2][3][4] Legislative need is therefore concrete, but lawmakers must combat technical attacks without vague offences usable against criticism, journalism or legitimate internet use.

The proposal distinguishes three frequently conflated matters: genuine technical crime such as unlawful access, system/data damage, interception, fraud and ransomware; digital procedures such as preservation, search, seizure, traffic-data collection and content interception; and digital-evidence rules governing authenticity, custody and testability. Separation improves precision and prevents criminalising expression or merely using dual-purpose tools.

It addresses practical gaps identified by Iraqi courts. The Supreme Judicial Council has noted reliance on Criminal Procedure Law Article (213) for ‘other evidence recognised by law’ and the need for specialist rules on digital evidence, custody/documentation, rapid deletion, falsification and synthetic technologies.[5][6][7]

The proposed balance defines harmful conduct, grades judicially supervised powers, prohibits general retention, mass surveillance and universally weakened encryption, protects good-faith research and establishes national evidentiary standards. It draws on Budapest Convention distinctions and the United Nations Convention against Cybercrime adopted in 2024, without assuming either binds Iraq before constitutional procedures are completed.[8][9]

Second — Legislative gap

The first is the technical-criminalisation gap. General offences can cover some modern conduct, but data integrity/availability and account/system attacks without traditional physical theft remain uncertain. Specific conduct, not the internet as a public space, should be criminalised.

The second is the procedural gap. Searching phones, servers or clouds differs from drawers or papers: millions of files, third-party information, privileged communications and overseas storage may be involved. Preservation, access and interception require graduated, bounded rather than general orders.

The third is the evidentiary gap. Rapid change/deletion, intangible copying, time differences, encryption, deepfakes and forensic/algorithmic outputs mean screenshots or printed conversations are not always sufficient. Courts need authenticity, integrity and repeat-examination standards.

The fourth is the rights gap. Conflating fraud/hacking with vague ‘offence’, ‘damage to prestige’ or ‘false information’ creates constitutional/practical risks and turns cybercrime bodies into speech regulators. Expressive content is separated from technical offences; legitimate speech restrictions require specific independent rules tested for legality, necessity and proportionality.

Third — Proposed legislative policy

Core design choices
IssueChosen approachEffect
Criminalisation scopeSpecific technical offences plus traditional offences materially enabled by technologyLegal certainty without general content regulation
SurveillanceGraduated preservation-to-interception powers with stronger judicial authority as intrusion growsEffective investigations protecting constitutional Article (40)
Data retentionTargeted preservation of existing data, not population-wide retention under this LawReduced privacy risk and unnecessary mass databases
EncryptionNo general backdoors; institution-controlled data/keys may be sought in specific casesPreserves economic/service security while enabling lawful investigations
Digital evidenceCustody chains, forensic copies, validation, retesting and synthetic-media standardsMore reliable judgments and fewer technical challenges
Security researchLegal safe harbour for good-faith authorised or disclosure-policy testingNo criminalisation merely for dual-purpose tools
International cooperation24/7 contact and lawful channels, without unilateral cross-border intrusionFaster cooperation respecting sovereignty/international law

Fourth — Draft law

Fifth — Explanatory reasons

This Law is proposed for rapid information/communications growth and increasing system/data/account attacks, fraud and extortion; because traditional criminal/procedural rules alone cannot adequately address transient transnational data; to unify digital-evidence collection, preservation, examination and judicial presentation; and to subject search, preservation and surveillance to legality, necessity, proportionality, judicial review, privacy, communications and expression safeguards.

Sixth — Explanatory memorandum

1. Why a new law?

The Penal Code and Criminal Procedure Law remain Iraqi criminal justice's foundation. The proposal addresses conduct/procedures absent from their original technical environment. Traditional fraud/threat offences do not precisely answer system disruption, data change, traffic interception or account takeover, nor searches of devices holding ten years of hundreds of people's data.

2. Separating crime from content

Online opinions, news or criticism shall not become ‘cybercrime’ merely through technology. Legitimate reputation or anti-violence-incitement rules must be independent, precise and constitutional rather than hidden in vague technical legislation. This reduces abuse and focuses police/courts on actual attacks.

3. Graduated powers

Preservation prevents deletion without disclosure. Subscriber/stored-data orders, search/seizure, real-time traffic collection and finally content interception progressively increase intrusion, each requiring clearer conditions. This enables oversight and prevents indiscriminate all-at-once demands.

4. Digital evidence is more than screenshots

Practical criteria—source, system integrity, custody, hashes, metadata, extraction and retesting—replace rigid rules. Minor errors are assessed for real consequences rather than automatic exclusion. Synthetic content, deepfakes and algorithmic forensic outputs are expressly included, reflecting Iraqi judicial discussions in 2026.[6]

5. Encryption and compliance

Encryption secures banking, government and personal communications; it is not inherently criminal obstruction. General backdoors are prohibited, while courts may require existing institution-controlled data/decryption in specific cases, avoiding permanent weaknesses in national infrastructure.

6. No new authority

Investigation remains within courts and existing enforcement bodies, supported by specialist units, laboratories, experts and quality standards rather than independent new security agencies. This reduces overlap/cost, leaving preventive cybersecurity/risk management to its institutions and focusing here on crime, procedure and evidence.

7. International cooperation

Digital crimes cross borders in seconds. Continuous national contact, expedited preservation and judicial assistance support cooperation without unilateral foreign-system intrusion, respecting sovereignty and treaty-accession procedures.

Seventh — Legislative harmonisation

Principal alignment needs
Legislation/areaPositionProposed alignment
Penal Code No. 111 of 1969, as amendedGeneral offences, participation, concurrence and penalties remain.Retain, treating this Law as specific to defined technical attacks.
Criminal Procedure Law No. 23 of 1971, as amendedGeneral investigation, search and evidence.Add specific preservation, digital search, interception and custody rules.
Electronic Signature and Electronic Transactions Law No. 78 of 2012Evidentiary validity and electronic transactions within its scope.Avoid conflicts; distinguish transactional validity from digital criminal evidence.
Data/privacy legislationLawful data processing.Purpose-limited justice processing with minimisation and limited retention.
Cybersecurity legislationPrevention, resilience and incident management.Separate technical response from criminal investigation with referral/preservation channels.
Communications and digital servicesProviders and communications infrastructure.Judicial compliance without general monitoring or permanent content-inspection duties.

Eighth — Implementation and transition

Effective commencement requires limited but specialised preparation: standard digital orders, confidential judicial registers, laboratories capable of imaging/validation/modern-device handling, judicial/investigator training and continuous contact. Most can occur within existing institutions.

Minimum implementation schedule
Time from publicationActionBodies
0–90 daysDesignate contact, prepare preservation/production/search forms and inventory laboratories.Supreme Judicial Council, Interior, Foreign Affairs and technical bodies
0–180 daysTechnical instructions, initial training and custody updates.Competent bodies within their powers
At 180 daysNew powers/offences substantively commence.All bodies
Within one yearSubmit related harmonisation amendments.Council of Ministers to Council of Representatives
AnnuallyPublish aggregate case, order and cooperation statistics.Competent judicial/executive bodies
Every three yearsReview legislative effects and technical/rights trends.Government and Parliament

Ninth — Financial and implementation impact

No new independent authority or broad administrative network is required. Costs concern forensic laboratories, secure storage, examination licences, training, contact-point duty staffing and order registries. Public laboratory, readiness and caseload data do not support reliable costing; no falsely precise figure is provided.

Before substantive commencement, executive costing shall distinguish reusable capacity, storage/analysis gaps, licensing/maintenance, training, repository security and duty personnel. Budgets should compare national-laboratory investment with excessive outsourcing or technically caused case delays.

Tenth — Relevant international comparison

Budapest Convention: Its value lies in offence/procedure architecture, not copied penalties: unlawful access, interception, data/system interference, tool misuse, expedited preservation, production, search, real-time collection and interception. Iraqi constitutional safeguards are more explicit; effectiveness for Iraq is not presumed before accession proposed separately.[8]

United Nations Convention against Cybercrime: It offers a newer global cooperation/electronic-evidence framework. The UN treaty record as of 30 September 2026 showed it not internationally effective because required ratifications had not been reached.[9] It is therefore a future-alignment reference, not an automatically binding obligation.

Human-rights standards: Expression restrictions must be precise, no broader than necessary, and justified by state-proven necessity/proportionality. General ‘electronic offence’ or absolute false-information crimes are excluded in favour of defined fraud, threats, extortion and forgery.[11]

Eleventh — Sources and references

  1. Iraqi Council of Representatives — Constitution of the Republic of Iraq, 2005. Especially Articles 17, 38 and 40. Official source.
  2. Iraqi Council of Representatives, 6 July 2026. First reading of the Information Technology Crime Bill completed. Source.
  3. Iraqi Council of Representatives, 21 September 2026. Second reading deferred; judiciary, authorities and civil-society hearings requested. Source.
  4. Parliamentary Security and Defence Committee, 4 October 2026. Bill discussion and specialist-workshop decision. Source.
  5. Supreme Judicial Council, 17 September 2025. ‘Electronic Evidence in Criminal Proof’, discussing Criminal Procedure Article 213 and specialist legislation. Source.
  6. Supreme Judicial Council, 16 September 2026. Meeting on electronic-extortion evidence and falsification-capable algorithms. Source.
  7. Judicial Development Institute, 24 May 2026. Digital evidence, custody, documentation and cross-border challenges workshop. Source.
  8. Council of Europe — Convention on Cybercrime (Budapest), ETS No. 185. Offences, procedures and international cooperation. Source.
  9. United Nations — Convention against Cybercrime, General Assembly Resolution 79/243 and treaty-status record. Convention text; Signature and ratification status.
  10. Supreme Judicial Council, 13 February 2020. ‘Audio Recordings in Criminal Evidence’, referencing Criminal Procedure Articles 74, 75 and 213. Source.
  11. Human Rights Committee — General Comment No. 34 on International Covenant on Civil and Political Rights Article 19. Clarity, necessity and proportionality in expression restrictions. Arabic text.

Proposed legislative document within Ali Zuweid's Political Programme · POL-89

What are you looking for?

Search content published on the website.