Data Sovereignty and Cybersecurity
From storing data to a national capacity to govern and protect them
Data sovereignty does not mean keeping every byte inside Iraq; it means knowing what the state holds, who is entitled to use it, and how to protect, audit, recover and move it to an alternative when a shock occurs, within a clear legal framework and with enforceable rights.
Chapter Overview
| Item | Substance |
|---|---|
| Code | V3-D06-C06 |
| Location | Volume Three — Part Six — Chapter Six |
| Purpose | Build practical data sovereignty that enables Iraq to classify, govern, store, process, transfer, share, protect and recover its data in accordance with the law and the national interest, reducing critical digital dependencies without isolating itself from global technologies and markets. |
| Connection to the previous chapter | Builds on “Public Digital Infrastructure”: after establishing identity, platforms, interoperability, payments and services, the question becomes who governs the data moving through this infrastructure, where they are processed, who controls their keys and access rights, and how services continue after a breach or provider failure. |
| Connection to the next chapter | Prepares the way for “Advanced Manufacturing”: smart manufacturing, robotics and technology value chains cannot be built on ungoverned data, fragile cyber infrastructure or technological dependency with no exit. |
| Data freeze | 7 October 2026; using the latest official Iraqi information published up to that date. |
| Mandatory topics | Protecting national data; data storage and processing; cybersecurity; preventing digital dependency. |
1. Executive Summary
During 2025–2026, Iraq moved from a stage in which government digital infrastructure was distributed among separate initiatives and centres to a more clearly defined institutional arrangement: the National Centre for Digital Transformation leads digital transformation and manages government infrastructure and data; the national cloud provides central government hosting inside Iraq; and the secure government network connects more than 500 entities. These assets demonstrate that the state no longer starts from a technological vacuum, but do not by themselves demonstrate complete data sovereignty or mature cybersecurity.1
According to the National Centre for Digital Transformation, by 19 August 2026 the X-Data platform connected 37 government institutions and 1,412 institutions and branches, managed approximately 48.29 million records and data entries, and provided 205 digital services. Greater integration increases the value of governance, because an error in permissions, quality or backup affects more entities and services.2
In cybersecurity, the International Telecommunication Union places Iraq in Tier 4, “Evolving”, in the Global Cybersecurity Index 2024. The National Cybersecurity Centre displays a national readiness indicator of 53.07, alongside declared responsibilities covering strategy, standards, compliance, risks, critical infrastructure and incident response. This is an important institutional maturity value, but it does not directly measure breach detection time, service restoration time or the recovery capability of each institution.3
The legal gap remains. The Constitution protects privacy and the confidentiality of communications, and the Ministry of Justice publishes practical guidance on data protection; however, an official meeting in August 2026 listed “personal data protection” among laws still under study and review. This Vision therefore does not assume that a comprehensive federal law equivalent to modern frameworks is in force unless it has been officially published in the Iraqi Official Gazette.4
The central decision is that Iraq does not need to “localise everything”. Some data and services can use commercial clouds or international providers more efficiently and securely, while other categories require stronger national control, domestic hosting or encryption keys controlled by an Iraqi entity. The selection criteria are data sensitivity, the impact of service interruption, the law, portability, dependency risks and the cost of an alternative.
By 2045, the state moves through four interconnected shifts: inventory and classify data and assets and assign owners; establish a legal, rights-based and operational framework for data protection and sharing; turn clouds and networks into resilient infrastructure capable of recovery and movement between providers; then use data as a productive asset for the state, the economy and artificial intelligence without reducing citizens to raw material or turning security into unrestricted surveillance.
2. The Central Question and the Chapter’s Scope
The central question is: what legal, institutional, technical and operational framework does Iraq need to govern and benefit from its national data, protect personal and sensitive data, ensure continuity of digital services and infrastructure, and reduce critical dependencies on foreign suppliers and platforms, without closing the market, obstructing innovation or repeating the cybersecurity and digital service issues addressed in earlier chapters?
2.1 What the Chapter Resolves
- Define data sovereignty as the capacity to govern, control, audit and provide alternatives, rather than simply the storage location.
- Classify data and link the level of protection, retention and sharing to each category.
- Identify decision-making ownership over data and the roles of owner, steward, operator, processor and auditor.
- Safeguards for national hosting, public and hybrid clouds and cross-border flows.
- Connect data protection to cybersecurity, business continuity and recovery.
- Procurement rules that prevent Vendor Lock-in from becoming a dependency in decision-making.
2.2 What This Chapter Does Not Repeat
- It does not redesign the Ur portal, digital identity or the service journey.
- It does not rebuild the incident response system from scratch; it uses the conclusions of the security part.
- It does not design the economic strategy for artificial intelligence; it addresses only training data and high-impact systems.
- It does not turn every external reliance into dependency; reliance becomes a risk when it weakens the right to audit, continue, transfer or exit.
3. Operational Vocabulary and Measurement Rules
| Concept | Operational definition | What it does not mean |
|---|---|---|
| Data sovereignty | The ability of the state and the owning entity to set rules for collecting, classifying, accessing, processing, transferring, deleting and retaining data, with the capacity to audit, continue operating and move to an alternative. | It is not a ban on hosting all data outside Iraq. |
| Data residency | The geographic location where data are stored or processed at a particular stage. | It does not equal sovereignty if keys and administration are outside one’s control. |
| Data localisation | A requirement to keep a category of data, or a copy of it, within a geographic area. | It is not a general objective for all data. |
| Data owner | The entity with the purpose, mandate and ultimate responsibility for use, quality and availability. | It is not necessarily the server operator. |
| Critical data | Data whose loss, manipulation or unavailability disrupts a national function or has a wide impact. | They may be non-confidential but critical to availability. |
| Cyber resilience | Prevention, detection, containment, continuity, recovery and learning. | It does not mean zero breaches. |
| Vendor lock-in | A dependency that makes moving data, systems or operations to another provider unreasonably costly or slow. | Not every foreign product creates dependency. |
4. Iraq’s Baseline: From Data Islands to Interconnected National Assets
Iraq now has central digital assets that did not exist with this clarity a few years ago. The National Centre for Digital Transformation, established under the 2025 instructions for the organisational units of the Prime Minister’s Office, states that it is responsible for data integration, the national data centre and related infrastructure, and digital transformation strategies.5
The secure government network began in 2018 and has connected more than 500 government entities in Baghdad and the governorates, excluding the Kurdistan Region according to the Centre’s description. It supports government email, the Ur portal, data exchange and data-centre connectivity. It is an important asset for operational sovereignty because it provides a government communications route that does not rely exclusively on the public internet.6
The national cloud provides a central government hosting environment, which the Centre describes as designed to keep data inside Iraq with high availability, redundancy and automatic failover. Yet sovereign-cloud maturity cannot be established from the server location alone; backup, recovery, keys, identity and exit must be measured.7
The X-Data platform reflects a shift from exchanging official letters to exchanging data under defined permissions. The August 2026 figures indicate growing institutional adoption and should not be interpreted as an invitation to combine all state databases in a single repository. The better strategy is controlled integration that enables queries and exchange according to purpose, while ownership remains with the competent entities.8
| Asset | Declared status | Implication | Gap |
|---|---|---|---|
| National Centre for Digital Transformation | Central authority for transformation, data and infrastructure | Unify policy and integration | Establish data-owner roles and binding standards |
| Secure government network | More than 500 entities | Protected government communications route | Measure availability and route redundancy |
| National cloud | Hosting inside Iraq with HA | Shared hosting capability | Independent recovery and exit tests |
| X-Data | 48.3 million records and 205 services | Actual integration and sharing | Governance of purpose, quality and the audit trail |
| National Cybersecurity Centre | Governance, standards, compliance and response | Central security authority | Raise operational and sectoral maturity |
5. Sovereignty Over Data: Control, Not Closure
The two most dangerous simplifications are: “everything local is sovereign” and “everything foreign creates dependency”. An Iraqi entity may host data in Baghdad on a platform whose keys it does not control, whose architecture it does not know, and whose records it cannot export in a standard format; residency is local, but control is weak. Conversely, it may use a global cloud service with encryption under Iraqi-controlled keys, contractual audit rights, independent backups and portability; a high degree of control exists even though some processing is cross-border.
The Vision adopts a five-part sovereignty test for every system or database: applicable law; decision owner; access and encryption keys; auditability; and continuity and exit capability. If a system fails at more than one link, describing it as locally hosted is insufficient.
| Test | Governing question | Sign of maturity |
|---|---|---|
| Law | Which law and jurisdiction apply? | Predetermined categories and cross-border cases |
| Decision-making | Who grants or revokes access? | A competent Iraqi entity and clear responsibility |
| Keys | Who controls encryption and secrets? | Direct control or governed separation of permissions |
| Audit | Can who accessed the data and what they did be established? | Reliable logs and independent review |
| Departure | Can the system be moved to an alternative? | A tested exit plan and open formats |
6. The Legal Framework: Privacy Is Protected, but the Legislative Gap Remains
The Constitution provides an initial basis for rights: Article 17 protects personal privacy, while the Constitution also protects the confidentiality of correspondence and communications within legal safeguards. But a general constitutional right does not replace a detailed law defining the legal basis for processing, data-subject rights, entities’ obligations, breach notification, data transfers, retention periods, children, sensitive data, penalties and oversight.9
In August 2026, the Ministry of Justice stated that personal data protection was among a group of laws being examined and reviewed. The Vision therefore records the situation as it is: constitutional protection, official awareness and sectoral practices exist, but a comprehensive federal law in force cannot be assumed to be complete unless officially published.10
6.1 Components of the Required Framework
- Clear definitions of personal, sensitive and biometric data and children’s data.
- Multiple legal bases for processing; consent must not be the only basis for a government service.
- Rights of access, correction, objection and erasure where the law permits.
- Privacy by design, data minimisation, purpose limitation and retention periods.
- Impact assessment for high-risk systems and automated decisions with broad effects.
- Breach notification rules proportionate to the severity of the risk.
- Safeguards for cross-border flows and third-party processing.
- A supervisory body with functional independence and access to grievance procedures and the courts.
7. Data Classification: Not All Data Are Protected in the Same Way
Protecting everything at the highest level increases costs and slows the state, while protecting everything at the same level leaves sensitive records exposed. What is needed is a relatively simple national classification system applied to data rather than institutional names, separating confidentiality from criticality.
| Group | Examples | Hosting and processing | Controls |
|---|---|---|---|
| Open | Published statistics, maps and expenditure data | May be published and hosted on trusted infrastructure | Source integrity, archival copies and licensing |
| Internal | Non-sensitive operational correspondence | Government hosting or an approved commercial cloud | Identity, permissions and access logs |
| Restricted | Employee files and citizen transactions | Inside Iraq by default, or under a controlled exception | Encryption, MFA, least privilege and retention |
| Highly sensitive | Health, biometric and investigation data | A tightly controlled environment and controlled keys | Segmentation, monitoring, DLP and review |
| Nationally critical | Identity, payment, command and core records | Resilient sovereign architecture and independent backups | Strict RTO/RPO, recovery and alternatives |
8. Ownership and Responsibility: Who Controls Decisions About Data?
Responsibility is lost when the IT department is said to be responsible for data. The technology department may operate the platform, but it does not own the purpose and does not always know the quality of the record or the legality of retaining it. This chapter therefore adopts a role model that allocates decision-making and accountability.
| Role | Primary responsibility | What cannot be fully delegated |
|---|---|---|
| Data owner | Purpose, legality, quality, sharing and retention | Decisions on use and opening data to another entity |
| Data steward | The data dictionary, quality and inconsistencies | Changing definitions without approval |
| Technical operator | Hosting, backup, monitoring and performance | Determining the legal purpose |
| Data protection officer | Rights, assessments, notification and advice | Becoming subordinate to those being reviewed, without functional independence |
| Security officer | Controls, risks and incidents | Solely determining functional entitlement to data |
| Audit | Testing compliance, evidence and logs | Operating the system being audited |
9. The National Cloud and Data Centres: Residency Is Not the Whole of Sovereignty
The national cloud is an important asset because it gives the state a shared capability instead of dozens of small environments. The Centre states that it is designed for high availability, redundancy and automatic failover, and to keep government data inside Iraq. But sovereign-cloud maturity cannot be established from the server location alone. Physical and virtual infrastructure, identity, keys, operations, backups and recovery must be assessed.11
The 2045 recommendation is a Cloud-Smart model, not Cloud-Only: nationally critical workloads in sovereign or hybrid environments with strong control; routine government workloads on the national cloud or approved providers according to cost and resilience; and low-sensitivity public workloads that can benefit from global services under exit contracts and data controls.
| Question before hosting | Design decision |
|---|---|
| Would system failure disrupt a critical national function? | High availability, an independent recovery site and regular testing. |
| Are the data personal or highly sensitive? | Restrict location, keys, access and logging according to classification. |
| Does the service require global capabilities that are difficult to reproduce locally? | Controlled hybrid/external use with portability and independent backups. |
| Is there a documented export format? | An essential condition before long-term adoption. |
| Can a minimum service operate when the provider is unavailable? | If not, the relationship is a critical dependency requiring an alternative. |
10. Data Exchange and Interoperability: Sharing Under Safeguards
X-Data is a practical step towards interoperability, but good connectivity does not mean that every entity sees everything. The Vision adopts “purpose-based sharing”: a system sends the minimum data needed to perform a defined function and records who requested them, why, and how long they will be retained.
Integration gradually moves from sharing full copies to lower-risk patterns: yes/no verification; specific attributes; tokens; scoped APIs; or internal matching that returns the result without exposing the full record. Fewer transferred copies mean less scope for leakage and inconsistency.
| Sharing pattern | When preferred | Risk |
|---|---|---|
| Full copy | An exception where a clear legal need exists | Multiplication of copies and loss of control |
| API for specific attributes | Everyday services | Requires identity and permission management |
| Yes/no verification | Eligibility and document authenticity | Less disclosure of data |
| Internal matching | Cross-matching records | Sensitivity of matching logic and auditing |
| Anonymised/aggregated | Planning and research | Re-identification risk |
11. Personal Data Protection and Individual Rights
When the state uses digital identity, a unified register, automated verification and artificial intelligence, citizens become more dependent on the accuracy of the data recorded about them. They must therefore have a practical channel to learn what core data were used in a decision, request correction of errors and know which entity processed their data, within the limits permitted by law.
This does not mean fully revealing security records, investigation secrets or sensitive algorithms. Rights may be restricted on a legitimate, necessary and proportionate legal basis. The difference between a digital state that respects rights and an overreaching digital state is that exceptions are defined, reasoned and reviewable, rather than permanent secrecy being the default.
12. Cybersecurity: From Protection to Resilience
This chapter builds on a conclusion established in the security part: zero breaches do not exist. The role of sovereignty is to ensure that a technical incident does not become a loss of control or a shutdown of the state. Data governance is therefore linked to the security cycle: know the asset, classify it, minimise permissions, monitor, detect, contain, recover and review the cause.
The National Cybersecurity Centre declares responsibilities for strategy, standards, compliance, risks, critical infrastructure and incident response, and reports continuous monitoring and more than 500 protected institutions. These are indicators of institutional coverage, whereas Iraq Vision 2045 needs outcome indicators: mean time to detect (MTTD), containment time, mean time to restore (MTTR), the share of systems with tested backups, and the proportion of critical vulnerabilities remediated within a service-level agreement.12
The ITU 2024 index places Iraq in Tier 4. This is used as an external baseline for general maturity, not operational performance. The Vision does not set a numerical target for an index cycle that has not yet been released; the aim is continuous movement to higher levels, backed by domestic evidence of resilience and compliance.13
12.1 Required Security Architecture
- Gradual Zero Trust: no implicit trust based solely on network location.
- Privileged identity management for administrative and sensitive accounts.
- Network segmentation and isolation of critical systems from ordinary user routes.
- Central tamper-resistant logging and event correlation within SIEM/SOC according to purpose.
- Vulnerability management with SLAs based on severity and exposure, rather than counts.
- Purple Team exercises, recovery tests and supply-chain incident exercises.
13. Critical Infrastructure and Critical Data
Protecting critical infrastructure does not begin with a secret list of facilities; it begins by identifying functions whose interruption society and the state cannot tolerate: electricity, water, payments, communications, health, transport, borders, identity, government command, and certain security and defence functions. The data and systems supporting those functions are then identified.
A national register of critical operators and services is required, with mandatory minimum requirements for security, backups, reporting and testing, separating a public general framework from confidential technical details. Requirements must include key suppliers, because a breach of a provider or an update may disrupt several entities simultaneously.
| Layer | 2045 requirement |
|---|---|
| Governance | Critical service owner and senior leadership accountability |
| Architecture | Segmentation, least privilege and development/production separation |
| Suppliers | Security requirements, notification, vulnerabilities, audit rights and an exit plan |
| Monitoring | Logging, event correlation, retention and detection testing |
| Response | Sectoral and national exercises and an escalation protocol |
| Recovery | RTO/RPO, immutable backups and independent sites |
14. Backup, Recovery and State Continuity
An untested backup is not a capability. Nor do backups at the same centre protect against fire, a simultaneous administrative error or a breach extending into the backup environment. The Vision adopts a modified 3-2-1 rule for critical systems: multiple copies, different environments and at least one copy outside the operational failure domain, immutable for a defined period.
Continuity is measured through two simple indicators: RTO, the acceptable time to restore a service; and RPO, the acceptable amount of data loss measured in time. Values are defined according to the service. National payments may require minutes, whereas a non-operational archive may tolerate hours or days.
15. Encryption, Trust Keys and Secrets Management
Encryption is not a product added at the end of a project. Design must determine what is encrypted in transit and at rest, who owns the key, how keys are rotated, what happens when an employee or provider leaves, and how permission to operate the server is separated from permission to read the data.
For sovereign and critical systems, the entity or a trusted national service should preferably retain control over core keys, using HSMs or key-management services with separation of duties and auditing. But a “key inside Iraq” is insufficient if administrative access is uncontrolled or backups are unprotected.
Secrets management is also unified: database passwords, API keys, TLS certificates, software-signing keys and CI/CD secrets. Many breaches do not require breaking encryption if secrets are exposed in files, code or shared accounts.
16. Digital Procurement and Supplier Dependency
Digital dependency often begins not with a political decision, but with a procurement contract that says nothing about export formats, exit fees, ownership of logs, version support, audit rights or delivery of the materials required to keep operations running. Years later, exit costs exceed the entity’s capacity to change.
The Vision introduces an “exit capability test” into major digital procurements: before contracting, the supplier provides an export and migration plan; during operations, an annual exercise restores a copy and operates part of the service in an alternative environment; and at contract expiry, the exit period, cooperation and fees have been defined in advance.
| Item | Minimum standard |
|---|---|
| Data ownership | Remain with the Iraqi entity; secondary use is prohibited except under an explicit provision and for a legitimate purpose |
| Portability | Documented formats and open standards wherever possible |
| Logs | Access rights to the logs needed for audits and investigations |
| Incidents | Time-bound notification according to severity and cooperation in investigations |
| Keys | A clear ownership and management model |
| Continuity | SLA, recovery and tests |
| Departure | Data handover, documented deletion and a fee ceiling |
| Subcontracting | Disclosure and controls for subcontractors and processing locations |
17. Cross-Border Flows and Global Cloud Services
A modern digital economy cannot entirely prevent cross-border data transfers. Email, platforms, trade, research, software and cloud services all depend on international flows. What is needed is a framework that distinguishes categories and purposes and requires appropriate safeguards, instead of a blanket ban or unrestricted openness.
The Vision proposes three channels: ordinary transfers for non-sensitive categories under contracts and standards; restricted transfers for personal and sensitive data after legal and technical assessment; and prohibition or tightly limited exceptions for specified critical data requiring control to remain inside Iraq. The law must allow safeguarded exceptions for research, health, emergencies and international cooperation.
18. Open Data and Public Value
Sovereignty does not mean state secrecy. Non-personal, non-sensitive data acquire value when published in machine-readable formats under a clear licence. The national open-government portal offers a foundation to build on, but success is not measured by file counts; it is measured by data freshness, completeness of descriptions, reusability, availability of APIs and entities’ responses to errors.14
An “open safely” policy applies: every dataset is assessed before publication for privacy, re-identification, security and intellectual property, then published by default unless a valid reason prevents it. This turns data into infrastructure for research, innovation and business, and reduces the institution’s internal monopoly on information.
19. Artificial Intelligence: Data Sovereignty in the Age of Models
The earlier chapter addressed computing, talent and use. A different question is added here: what happens to data when they enter model training, fine-tuning or operation? The entity must record the source, purpose and rights associated with training data, prevent sensitive data from being entered into unapproved public services, and use institutional gateways that prevent secrets from leaking.
For high-impact systems, Iraq must retain the ability to explain data provenance, test bias and errors, trace model versions and stop use when risks emerge. Sovereignty here is not owning every model from scratch, but controlling decisions, data, evaluation, usage logs and the possibility of replacement.
20. International Comparisons: Transfer the Mechanism, Not the State
| Case | Mechanism useful for Iraq | What is not copied |
|---|---|---|
| Estonia | Distributed interoperability, audit trails, the once-only principle and trust infrastructure | The country’s size and development path cannot be transferred unchanged |
| European Union | Data rights, processor accountability, transfer rules and Privacy by Design | GDPR is not copied verbatim without adaptation |
| India | Broad public digital infrastructure, identity, payments and consent layers | No concentration of data is transferred without local safeguards |
| Singapore | Cloud governance, classification, risks and skills | Its administrative and financial capacity differs |
| United Arab Emirates | Government clouds, data and AI policies and rapid investment | Continuous importing must not replace local capacity-building |
The shared lesson is not “buy a platform”. More mature countries build a common layer of rules, roles and standards, then allow distributed implementation. This is what Iraq needs: a small number of decisive national rules—classification, identity and permissions, encryption, sharing, retention, incidents, recovery and exit—followed by sectoral freedom to choose the details within those boundaries.
21. Iraq’s Digital Landscape in 2045
By 2045, data must become a governed national asset rather than a scattered stockpile. Citizens do not resubmit documents the state already holds; employees do not load complete databases onto personal devices to perform matching; ministries do not retain data without a time limit or purpose; and projects do not begin without classification, a data owner and a security and recovery plan.
The target architecture is “distributed sovereignty”: a national centre sets policies and shared infrastructure; the National Cybersecurity Centre sets and measures protection and response controls; sectoral entities own their data and are accountable for the quality of their use; and legal oversight protects rights. Authority and data are not all concentrated in one entity in the name of efficiency.
22. Transition Stages, 2027–2045
| Phase | Objective | Conditions for progression |
|---|---|---|
| 2027–2030 | Establish governance | Data inventory and classification, data protection law, data owners, a cybersecurity minimum, and exit and recovery plans | Complete the central systems inventory, classify critical systems and publish standards |
| 2031–2035 | Unify controls | Expand cloud and hybrid use, audit trails, key management and supplier assessment | Annual tests and coverage of major entities by the privacy and security framework |
| 2036–2040 | Operational resilience | Provider switching capability, independent recovery centres and compliance automation | Successful exit tests and reduced single-provider dependencies |
| 2041–2045 | Mature data state | High-quality data, risk-based security and sovereignty over keys and critical assets | Regular measurement, independent review and continuity capability demonstrated through exercises |
23. Indicator and Target Dashboard
The following targets are proposed policy commitments, not automatic forecasts. Values without a unified national baseline begin with a foundational measurement in 2027 and are not filled with estimates.
| Indicator | 2026 baseline | 2030 | 2035 | 2040 | 2045 |
|---|---|---|---|---|---|
| Entities with an approved inventory and classification | No unified published baseline | ≥80% | 100% | 100% + review | 100% + audit |
| Critical systems with RTO/RPO and a recovery test | Unpublished | ≥70% | ≥90% | ≥95% | 100% |
| Critical systems with a tested exit plan | Unpublished | ≥40% | ≥70% | ≥90% | 100% |
| Entities with a data protection function | Unpublished | ≥70% | ≥90% | 100% | 100% |
| Serious incidents closed with root-cause analysis | Unpublished | ≥80% | ≥90% | ≥95% | ≥95% |
| High-value open data through APIs where needed | 2027 baseline | +50% | +100% | Widespread automated updating | Quality before quantity |
| National cybersecurity maturity | ITU 2024: Tier 4 / 53.07 | Improvement demonstrated in the next cycle | Continuous improvement | Advanced level | Sustained |
Operational indicators are added that do not require disclosure of sensitive details: average detection time for high-severity incidents, average restoration time, the percentage of backups that pass a restoration test, the proportion of privileged accounts under PAM, and the share of critical assets with identified data and service owners.
24. The Implementation Programme Package
Programme 1 — National Data and Asset Register
Inventory systems, databases, interfaces and owners, creating a data dictionary and flow diagram for every critical service. Begin with shared national assets, then ministries and governorates.
Programme 2 — Data Classification and Labelling Framework
A simple common classification, with metadata specifying sensitivity, criticality, owner, retention period, hosting location and sharing rules.
Programme 3 — Data Protection Law and Rights System
Adopt a balanced legal framework and establish a supervisory function, correction and grievance routes, breach notification and impact assessment.
Programme 4 — Resilient Government Cloud
Expand the national cloud according to Cloud-Smart principles, with multiple failure domains, key management, immutable backups and a migration policy.
Programme 5 — Secure Government Data Network
Develop the secure network, redundant routes, SD-WAN, monitoring and availability measurement.
Programme 6 — Data Sharing and API Policy
Gradually replace exchanges of full copies with controlled queries, attributes and interfaces, with a record of purpose and authorisation.
Programme 7 — National Data Resilience
RTO/RPO, recovery exercises, alternative centres, restoration tests and national exercises for critical functions.
Programme 8 — Key Management and Digital Trust
PKI/KMS/HSM infrastructure compatible with identity, signatures and services, with separation of permissions, rotation and revocation.
Programme 9 — Digital Procurement Against Vendor Lock-In
Standard clauses for ownership, transfer, logs, keys, incidents, subcontracting and exit.
Programme 10 — Supplier and Supply-Chain Risks
Supplier classification, SBOM where appropriate, security assessments, vulnerability tracking and replacement plans.
Programme 11 — High-Value Open Data
A national list of high-value datasets and APIs, quality standards, update frequency and protection against re-identification.
Programme 12 — AI Data Sovereignty
Training-data policies, safe-use gateways, leakage prevention and Dataset/Model lineage tracking for high-impact systems.
25. Implementation, Cost and Financing Matrix
| Programme | Proposed lead | Partners | 2027–2030 | Cost | Financing |
|---|---|---|---|---|---|
| Register and classification | National Centre for Digital Transformation | Ministries, statistics and oversight | Inventory and classification of central assets | Medium | Operating expenditure/digital transformation |
| Data protection | Council of Ministers/Justice/Parliament | Judiciary, digital entities and civil society | Legislation, regulations and organisation | Low–medium | Public budget |
| Resilient cloud | Digital transformation | Communications, cybersecurity and suppliers | Expansion + DR + KMS | High | Government investment/service |
| Cyber resilience | Cybersecurity | Critical sectors | Standards, tests and exercises | Medium–high | Entities + national level |
| Keys and trust | Digital transformation/trust authority | Security, Finance and Interior | PKI/KMS/HSM | Medium | Digital investment |
| Procurement and exit | Council of Ministers/Planning/Finance | Contracts and oversight | Mandatory templates | Low | Administrative |
| Open data | Open government/Planning | Ministries and universities | High-value list + APIs | Low–medium | Budgets/partnerships |
| AI data governance | National Centre for Artificial Intelligence | Digital transformation, security and universities | Policy and secure environments | Medium | Research and development/digitisation |
The chapter does not set an aggregate national financial figure because costs depend on an inventory not yet published: the number of data centres, workloads, service levels, contracts, capacities, recovery locations and the extent to which existing assets can be used. The rule is not to fund “sovereignty” as an equipment procurement project, but as a capability programme extending to operations, testing, maintenance and skills.
26. Risks and Safeguards
| Risk | Likelihood / Impact | Early Warning | Mitigation |
|---|---|---|---|
| Turning sovereignty into costly blanket localisation | Medium / high | Rising costs and delayed services | Risk-based classification and Cloud-Smart |
| Excessive data centralisation | Medium / high | Requests for wholesale consolidation without a purpose | Distributed integration, minimum data and separation of permissions |
| Lock-in to a single supplier | High / high | No export capability and rising exit fees | Exit clauses and annual testing |
| Data protection law that obstructs services | Medium/medium | Every processing operation requires individual consent | Multiple legal bases and proportionality assessment |
| Cyber law that expands surveillance | Medium / high | Vague definitions of content | Separate security from regulation of expression and ensure judicial safeguards |
| The national cloud as a point of failure | Medium/critical | Backups and recovery within a single domain | Independent domains and immutable backups |
| Skills shortage | High / high | Permanent reliance on the supplier | Internal teams, training and knowledge transfer |
| Excessive secrecy | High/medium | Classifying most data as secret | Classification review and Open by Default |
| Leakage into public AI tools | High / high | Personal accounts and no gateway | AI policy, DLP and approved environments |
27. The Bridge to Advanced Manufacturing
This chapter established that digital sovereignty is more than owning servers: it is the ability to govern data, keys, contracts and risks, and cybersecurity is an outcome of resilience and continuity, not of tool counts. It also established that openness to global providers does not automatically create dependency, and blanket localisation does not automatically create sovereignty.
Notes and references
Documentary Notes
- National Centre for Digital Transformation, “About the Centre”, the Centre’s responsibilities under Instructions No. (1) of 2025 on the Organisational Units of the Prime Minister’s Office,Original link; and National Centre for Digital Transformation, services page,Link 2(accessed: 7 October 2026).↩
- National Centre for Digital Transformation, “X-Data Smart Data Management Platform”, indicators last updated 19 August 2026: 37 government institutions, 1,412 institutions and branches, 48,285,956 records and 205 digital services,Original link.↩
- International Telecommunication Union, Global Cybersecurity Index 2024: Iraq is listed in Tier 4 (Evolving). The National Cybersecurity Centre displays a value of 53.07 on its website.Original link;Link 2.↩
- Iraqi Ministry of Justice, “Deputy Minister of Justice for Administrative and Financial Affairs Chairs a Meeting to Follow Up Amendments to Laws Governing Justice Departments”, 16 August 2026; lists personal data protection among the laws under examination and review.Original link.↩
- National Centre for Digital Transformation, “About the Centre”, Article (20) of Instructions No. (1) of 2025 on the Organisational Units of the Prime Minister’s Office; its duties include data integration, undertaking the functions of the national data centre and managing related infrastructure.Original link.↩
- National Centre for Digital Transformation, “Secure Government Network”; reports connecting more than 500 government entities since the project began in 2018, excluding the Kurdistan Region according to the published text.Original link.↩
- National Centre for Digital Transformation, “National Cloud”; describes government hosting inside Iraq, high availability, redundancy, automatic failover and load balancing.Original link.↩
- National Centre for Digital Transformation, “X-Data Smart Data Management Platform”,Original link(updated 19 August 2026).↩
- Iraqi Council of Representatives, Constitution of the Republic of Iraq of 2005, particularly Article (17) on privacy and the provisions concerning confidentiality of correspondence and communications.Original link.↩
- Iraqi Ministry of Justice, meeting to follow up legal amendments, 16 August 2026, previously cited; and Ministry of Justice, “Personal Data Protection”, 14 December 2025,Original link.↩
- National Centre for Digital Transformation, “National Cloud”, previously cited.↩
- National Cybersecurity Centre, official website and Centre responsibilities page; reports continuous monitoring and more than 500 protected institutions, and sets out its responsibilities for strategy, compliance, risks and response.Original link and Link 2.↩
- International Telecommunication Union, Global Cybersecurity Index 2024, previously cited.↩
- Iraq National Open Government Portal, the official platform for making government data available,Original link(accessed: 7 October 2026).↩
Core References
- National Centre for Digital Transformation — About the Centre and its responsibilities under Instructions No. (1) of 2025 on the Organisational Units of the Prime Minister’s Office.
- National Centre for Digital Transformation — X-Data Smart Data Management Platform, indicators updated 19 August 2026.
- International Telecommunication Union — Global Cybersecurity Index 2024.
- Iraqi Ministry of Justice — Personal data protection; and the meeting to follow up laws, 2025–2026.
- Iraqi Council of Representatives — Constitution of the Republic of Iraq of 2005, provisions on rights, privacy and communications.
- National Centre for Digital Transformation — Secure Government Network.
- National Centre for Digital Transformation — National Cloud.
- National Cybersecurity Centre — Official website, responsibilities, policies and security advisories, 2026.
- Iraq National Open Government Portal.
- NIST — Cybersecurity Framework (CSF) 2.0, 2024.
- OECD / World Bank — Frameworks for data governance, digital government, cloud and privacy by design.