Skip to content
V3-D06-C06
Iraq Vision 2045· Part Six: Science, Technology and the Future
V3-D06-C06

Data Sovereignty and Cybersecurity

From storing data to a national capacity to govern and protect them

Data freeze: 7 October 2026 · Version 1.0 · Strategic horizon: 2027–2045

Data sovereignty does not mean keeping every byte inside Iraq; it means knowing what the state holds, who is entitled to use it, and how to protect, audit, recover and move it to an alternative when a shock occurs, within a clear legal framework and with enforceable rights.

48.3 millionRecords/data entries on X-Data — August 2026
+500Entities connected to the secure government network
Tier 4Iraq’s classification in the Global Cybersecurity Index 2024
53.07National readiness value published on the National Cybersecurity Centre website

Chapter Overview

ItemSubstance
CodeV3-D06-C06
LocationVolume Three — Part Six — Chapter Six
PurposeBuild practical data sovereignty that enables Iraq to classify, govern, store, process, transfer, share, protect and recover its data in accordance with the law and the national interest, reducing critical digital dependencies without isolating itself from global technologies and markets.
Connection to the previous chapterBuilds on “Public Digital Infrastructure”: after establishing identity, platforms, interoperability, payments and services, the question becomes who governs the data moving through this infrastructure, where they are processed, who controls their keys and access rights, and how services continue after a breach or provider failure.
Connection to the next chapterPrepares the way for “Advanced Manufacturing”: smart manufacturing, robotics and technology value chains cannot be built on ungoverned data, fragile cyber infrastructure or technological dependency with no exit.
Data freeze7 October 2026; using the latest official Iraqi information published up to that date.
Mandatory topicsProtecting national data; data storage and processing; cybersecurity; preventing digital dependency.

1. Executive Summary

During 2025–2026, Iraq moved from a stage in which government digital infrastructure was distributed among separate initiatives and centres to a more clearly defined institutional arrangement: the National Centre for Digital Transformation leads digital transformation and manages government infrastructure and data; the national cloud provides central government hosting inside Iraq; and the secure government network connects more than 500 entities. These assets demonstrate that the state no longer starts from a technological vacuum, but do not by themselves demonstrate complete data sovereignty or mature cybersecurity.1

According to the National Centre for Digital Transformation, by 19 August 2026 the X-Data platform connected 37 government institutions and 1,412 institutions and branches, managed approximately 48.29 million records and data entries, and provided 205 digital services. Greater integration increases the value of governance, because an error in permissions, quality or backup affects more entities and services.2

In cybersecurity, the International Telecommunication Union places Iraq in Tier 4, “Evolving”, in the Global Cybersecurity Index 2024. The National Cybersecurity Centre displays a national readiness indicator of 53.07, alongside declared responsibilities covering strategy, standards, compliance, risks, critical infrastructure and incident response. This is an important institutional maturity value, but it does not directly measure breach detection time, service restoration time or the recovery capability of each institution.3

The legal gap remains. The Constitution protects privacy and the confidentiality of communications, and the Ministry of Justice publishes practical guidance on data protection; however, an official meeting in August 2026 listed “personal data protection” among laws still under study and review. This Vision therefore does not assume that a comprehensive federal law equivalent to modern frameworks is in force unless it has been officially published in the Iraqi Official Gazette.4

The central decision is that Iraq does not need to “localise everything”. Some data and services can use commercial clouds or international providers more efficiently and securely, while other categories require stronger national control, domestic hosting or encryption keys controlled by an Iraqi entity. The selection criteria are data sensitivity, the impact of service interruption, the law, portability, dependency risks and the cost of an alternative.

By 2045, the state moves through four interconnected shifts: inventory and classify data and assets and assign owners; establish a legal, rights-based and operational framework for data protection and sharing; turn clouds and networks into resilient infrastructure capable of recovery and movement between providers; then use data as a productive asset for the state, the economy and artificial intelligence without reducing citizens to raw material or turning security into unrestricted surveillance.

2. The Central Question and the Chapter’s Scope

The central question is: what legal, institutional, technical and operational framework does Iraq need to govern and benefit from its national data, protect personal and sensitive data, ensure continuity of digital services and infrastructure, and reduce critical dependencies on foreign suppliers and platforms, without closing the market, obstructing innovation or repeating the cybersecurity and digital service issues addressed in earlier chapters?

2.1 What the Chapter Resolves

  • Define data sovereignty as the capacity to govern, control, audit and provide alternatives, rather than simply the storage location.
  • Classify data and link the level of protection, retention and sharing to each category.
  • Identify decision-making ownership over data and the roles of owner, steward, operator, processor and auditor.
  • Safeguards for national hosting, public and hybrid clouds and cross-border flows.
  • Connect data protection to cybersecurity, business continuity and recovery.
  • Procurement rules that prevent Vendor Lock-in from becoming a dependency in decision-making.

2.2 What This Chapter Does Not Repeat

  • It does not redesign the Ur portal, digital identity or the service journey.
  • It does not rebuild the incident response system from scratch; it uses the conclusions of the security part.
  • It does not design the economic strategy for artificial intelligence; it addresses only training data and high-impact systems.
  • It does not turn every external reliance into dependency; reliance becomes a risk when it weakens the right to audit, continue, transfer or exit.

3. Operational Vocabulary and Measurement Rules

ConceptOperational definitionWhat it does not mean
Data sovereigntyThe ability of the state and the owning entity to set rules for collecting, classifying, accessing, processing, transferring, deleting and retaining data, with the capacity to audit, continue operating and move to an alternative.It is not a ban on hosting all data outside Iraq.
Data residencyThe geographic location where data are stored or processed at a particular stage.It does not equal sovereignty if keys and administration are outside one’s control.
Data localisationA requirement to keep a category of data, or a copy of it, within a geographic area.It is not a general objective for all data.
Data ownerThe entity with the purpose, mandate and ultimate responsibility for use, quality and availability.It is not necessarily the server operator.
Critical dataData whose loss, manipulation or unavailability disrupts a national function or has a wide impact.They may be non-confidential but critical to availability.
Cyber resiliencePrevention, detection, containment, continuity, recovery and learning.It does not mean zero breaches.
Vendor lock-inA dependency that makes moving data, systems or operations to another provider unreasonably costly or slow.Not every foreign product creates dependency.

4. Iraq’s Baseline: From Data Islands to Interconnected National Assets

Iraq now has central digital assets that did not exist with this clarity a few years ago. The National Centre for Digital Transformation, established under the 2025 instructions for the organisational units of the Prime Minister’s Office, states that it is responsible for data integration, the national data centre and related infrastructure, and digital transformation strategies.5

The secure government network began in 2018 and has connected more than 500 government entities in Baghdad and the governorates, excluding the Kurdistan Region according to the Centre’s description. It supports government email, the Ur portal, data exchange and data-centre connectivity. It is an important asset for operational sovereignty because it provides a government communications route that does not rely exclusively on the public internet.6

The national cloud provides a central government hosting environment, which the Centre describes as designed to keep data inside Iraq with high availability, redundancy and automatic failover. Yet sovereign-cloud maturity cannot be established from the server location alone; backup, recovery, keys, identity and exit must be measured.7

The X-Data platform reflects a shift from exchanging official letters to exchanging data under defined permissions. The August 2026 figures indicate growing institutional adoption and should not be interpreted as an invitation to combine all state databases in a single repository. The better strategy is controlled integration that enables queries and exchange according to purpose, while ownership remains with the competent entities.8

AssetDeclared statusImplicationGap
National Centre for Digital TransformationCentral authority for transformation, data and infrastructureUnify policy and integrationEstablish data-owner roles and binding standards
Secure government networkMore than 500 entitiesProtected government communications routeMeasure availability and route redundancy
National cloudHosting inside Iraq with HAShared hosting capabilityIndependent recovery and exit tests
X-Data48.3 million records and 205 servicesActual integration and sharingGovernance of purpose, quality and the audit trail
National Cybersecurity CentreGovernance, standards, compliance and responseCentral security authorityRaise operational and sectoral maturity

5. Sovereignty Over Data: Control, Not Closure

The two most dangerous simplifications are: “everything local is sovereign” and “everything foreign creates dependency”. An Iraqi entity may host data in Baghdad on a platform whose keys it does not control, whose architecture it does not know, and whose records it cannot export in a standard format; residency is local, but control is weak. Conversely, it may use a global cloud service with encryption under Iraqi-controlled keys, contractual audit rights, independent backups and portability; a high degree of control exists even though some processing is cross-border.

The Vision adopts a five-part sovereignty test for every system or database: applicable law; decision owner; access and encryption keys; auditability; and continuity and exit capability. If a system fails at more than one link, describing it as locally hosted is insufficient.

TestGoverning questionSign of maturity
LawWhich law and jurisdiction apply?Predetermined categories and cross-border cases
Decision-makingWho grants or revokes access?A competent Iraqi entity and clear responsibility
KeysWho controls encryption and secrets?Direct control or governed separation of permissions
AuditCan who accessed the data and what they did be established?Reliable logs and independent review
DepartureCan the system be moved to an alternative?A tested exit plan and open formats

6. The Legal Framework: Privacy Is Protected, but the Legislative Gap Remains

The Constitution provides an initial basis for rights: Article 17 protects personal privacy, while the Constitution also protects the confidentiality of correspondence and communications within legal safeguards. But a general constitutional right does not replace a detailed law defining the legal basis for processing, data-subject rights, entities’ obligations, breach notification, data transfers, retention periods, children, sensitive data, penalties and oversight.9

In August 2026, the Ministry of Justice stated that personal data protection was among a group of laws being examined and reviewed. The Vision therefore records the situation as it is: constitutional protection, official awareness and sectoral practices exist, but a comprehensive federal law in force cannot be assumed to be complete unless officially published.10

6.1 Components of the Required Framework

  • Clear definitions of personal, sensitive and biometric data and children’s data.
  • Multiple legal bases for processing; consent must not be the only basis for a government service.
  • Rights of access, correction, objection and erasure where the law permits.
  • Privacy by design, data minimisation, purpose limitation and retention periods.
  • Impact assessment for high-risk systems and automated decisions with broad effects.
  • Breach notification rules proportionate to the severity of the risk.
  • Safeguards for cross-border flows and third-party processing.
  • A supervisory body with functional independence and access to grievance procedures and the courts.

7. Data Classification: Not All Data Are Protected in the Same Way

Protecting everything at the highest level increases costs and slows the state, while protecting everything at the same level leaves sensitive records exposed. What is needed is a relatively simple national classification system applied to data rather than institutional names, separating confidentiality from criticality.

GroupExamplesHosting and processingControls
OpenPublished statistics, maps and expenditure dataMay be published and hosted on trusted infrastructureSource integrity, archival copies and licensing
InternalNon-sensitive operational correspondenceGovernment hosting or an approved commercial cloudIdentity, permissions and access logs
RestrictedEmployee files and citizen transactionsInside Iraq by default, or under a controlled exceptionEncryption, MFA, least privilege and retention
Highly sensitiveHealth, biometric and investigation dataA tightly controlled environment and controlled keysSegmentation, monitoring, DLP and review
Nationally criticalIdentity, payment, command and core recordsResilient sovereign architecture and independent backupsStrict RTO/RPO, recovery and alternatives

8. Ownership and Responsibility: Who Controls Decisions About Data?

Responsibility is lost when the IT department is said to be responsible for data. The technology department may operate the platform, but it does not own the purpose and does not always know the quality of the record or the legality of retaining it. This chapter therefore adopts a role model that allocates decision-making and accountability.

RolePrimary responsibilityWhat cannot be fully delegated
Data ownerPurpose, legality, quality, sharing and retentionDecisions on use and opening data to another entity
Data stewardThe data dictionary, quality and inconsistenciesChanging definitions without approval
Technical operatorHosting, backup, monitoring and performanceDetermining the legal purpose
Data protection officerRights, assessments, notification and adviceBecoming subordinate to those being reviewed, without functional independence
Security officerControls, risks and incidentsSolely determining functional entitlement to data
AuditTesting compliance, evidence and logsOperating the system being audited

9. The National Cloud and Data Centres: Residency Is Not the Whole of Sovereignty

The national cloud is an important asset because it gives the state a shared capability instead of dozens of small environments. The Centre states that it is designed for high availability, redundancy and automatic failover, and to keep government data inside Iraq. But sovereign-cloud maturity cannot be established from the server location alone. Physical and virtual infrastructure, identity, keys, operations, backups and recovery must be assessed.11

The 2045 recommendation is a Cloud-Smart model, not Cloud-Only: nationally critical workloads in sovereign or hybrid environments with strong control; routine government workloads on the national cloud or approved providers according to cost and resilience; and low-sensitivity public workloads that can benefit from global services under exit contracts and data controls.

Question before hostingDesign decision
Would system failure disrupt a critical national function?High availability, an independent recovery site and regular testing.
Are the data personal or highly sensitive?Restrict location, keys, access and logging according to classification.
Does the service require global capabilities that are difficult to reproduce locally?Controlled hybrid/external use with portability and independent backups.
Is there a documented export format?An essential condition before long-term adoption.
Can a minimum service operate when the provider is unavailable?If not, the relationship is a critical dependency requiring an alternative.

10. Data Exchange and Interoperability: Sharing Under Safeguards

X-Data is a practical step towards interoperability, but good connectivity does not mean that every entity sees everything. The Vision adopts “purpose-based sharing”: a system sends the minimum data needed to perform a defined function and records who requested them, why, and how long they will be retained.

Integration gradually moves from sharing full copies to lower-risk patterns: yes/no verification; specific attributes; tokens; scoped APIs; or internal matching that returns the result without exposing the full record. Fewer transferred copies mean less scope for leakage and inconsistency.

Sharing patternWhen preferredRisk
Full copyAn exception where a clear legal need existsMultiplication of copies and loss of control
API for specific attributesEveryday servicesRequires identity and permission management
Yes/no verificationEligibility and document authenticityLess disclosure of data
Internal matchingCross-matching recordsSensitivity of matching logic and auditing
Anonymised/aggregatedPlanning and researchRe-identification risk

11. Personal Data Protection and Individual Rights

When the state uses digital identity, a unified register, automated verification and artificial intelligence, citizens become more dependent on the accuracy of the data recorded about them. They must therefore have a practical channel to learn what core data were used in a decision, request correction of errors and know which entity processed their data, within the limits permitted by law.

This does not mean fully revealing security records, investigation secrets or sensitive algorithms. Rights may be restricted on a legitimate, necessary and proportionate legal basis. The difference between a digital state that respects rights and an overreaching digital state is that exceptions are defined, reasoned and reviewable, rather than permanent secrecy being the default.

12. Cybersecurity: From Protection to Resilience

This chapter builds on a conclusion established in the security part: zero breaches do not exist. The role of sovereignty is to ensure that a technical incident does not become a loss of control or a shutdown of the state. Data governance is therefore linked to the security cycle: know the asset, classify it, minimise permissions, monitor, detect, contain, recover and review the cause.

The National Cybersecurity Centre declares responsibilities for strategy, standards, compliance, risks, critical infrastructure and incident response, and reports continuous monitoring and more than 500 protected institutions. These are indicators of institutional coverage, whereas Iraq Vision 2045 needs outcome indicators: mean time to detect (MTTD), containment time, mean time to restore (MTTR), the share of systems with tested backups, and the proportion of critical vulnerabilities remediated within a service-level agreement.12

The ITU 2024 index places Iraq in Tier 4. This is used as an external baseline for general maturity, not operational performance. The Vision does not set a numerical target for an index cycle that has not yet been released; the aim is continuous movement to higher levels, backed by domestic evidence of resilience and compliance.13

12.1 Required Security Architecture

  • Gradual Zero Trust: no implicit trust based solely on network location.
  • Privileged identity management for administrative and sensitive accounts.
  • Network segmentation and isolation of critical systems from ordinary user routes.
  • Central tamper-resistant logging and event correlation within SIEM/SOC according to purpose.
  • Vulnerability management with SLAs based on severity and exposure, rather than counts.
  • Purple Team exercises, recovery tests and supply-chain incident exercises.

13. Critical Infrastructure and Critical Data

Protecting critical infrastructure does not begin with a secret list of facilities; it begins by identifying functions whose interruption society and the state cannot tolerate: electricity, water, payments, communications, health, transport, borders, identity, government command, and certain security and defence functions. The data and systems supporting those functions are then identified.

A national register of critical operators and services is required, with mandatory minimum requirements for security, backups, reporting and testing, separating a public general framework from confidential technical details. Requirements must include key suppliers, because a breach of a provider or an update may disrupt several entities simultaneously.

Layer2045 requirement
GovernanceCritical service owner and senior leadership accountability
ArchitectureSegmentation, least privilege and development/production separation
SuppliersSecurity requirements, notification, vulnerabilities, audit rights and an exit plan
MonitoringLogging, event correlation, retention and detection testing
ResponseSectoral and national exercises and an escalation protocol
RecoveryRTO/RPO, immutable backups and independent sites

14. Backup, Recovery and State Continuity

An untested backup is not a capability. Nor do backups at the same centre protect against fire, a simultaneous administrative error or a breach extending into the backup environment. The Vision adopts a modified 3-2-1 rule for critical systems: multiple copies, different environments and at least one copy outside the operational failure domain, immutable for a defined period.

Continuity is measured through two simple indicators: RTO, the acceptable time to restore a service; and RPO, the acceptable amount of data loss measured in time. Values are defined according to the service. National payments may require minutes, whereas a non-operational archive may tolerate hours or days.

15. Encryption, Trust Keys and Secrets Management

Encryption is not a product added at the end of a project. Design must determine what is encrypted in transit and at rest, who owns the key, how keys are rotated, what happens when an employee or provider leaves, and how permission to operate the server is separated from permission to read the data.

For sovereign and critical systems, the entity or a trusted national service should preferably retain control over core keys, using HSMs or key-management services with separation of duties and auditing. But a “key inside Iraq” is insufficient if administrative access is uncontrolled or backups are unprotected.

Secrets management is also unified: database passwords, API keys, TLS certificates, software-signing keys and CI/CD secrets. Many breaches do not require breaking encryption if secrets are exposed in files, code or shared accounts.

16. Digital Procurement and Supplier Dependency

Digital dependency often begins not with a political decision, but with a procurement contract that says nothing about export formats, exit fees, ownership of logs, version support, audit rights or delivery of the materials required to keep operations running. Years later, exit costs exceed the entity’s capacity to change.

The Vision introduces an “exit capability test” into major digital procurements: before contracting, the supplier provides an export and migration plan; during operations, an annual exercise restores a copy and operates part of the service in an alternative environment; and at contract expiry, the exit period, cooperation and fees have been defined in advance.

ItemMinimum standard
Data ownershipRemain with the Iraqi entity; secondary use is prohibited except under an explicit provision and for a legitimate purpose
PortabilityDocumented formats and open standards wherever possible
LogsAccess rights to the logs needed for audits and investigations
IncidentsTime-bound notification according to severity and cooperation in investigations
KeysA clear ownership and management model
ContinuitySLA, recovery and tests
DepartureData handover, documented deletion and a fee ceiling
SubcontractingDisclosure and controls for subcontractors and processing locations

17. Cross-Border Flows and Global Cloud Services

A modern digital economy cannot entirely prevent cross-border data transfers. Email, platforms, trade, research, software and cloud services all depend on international flows. What is needed is a framework that distinguishes categories and purposes and requires appropriate safeguards, instead of a blanket ban or unrestricted openness.

The Vision proposes three channels: ordinary transfers for non-sensitive categories under contracts and standards; restricted transfers for personal and sensitive data after legal and technical assessment; and prohibition or tightly limited exceptions for specified critical data requiring control to remain inside Iraq. The law must allow safeguarded exceptions for research, health, emergencies and international cooperation.

18. Open Data and Public Value

Sovereignty does not mean state secrecy. Non-personal, non-sensitive data acquire value when published in machine-readable formats under a clear licence. The national open-government portal offers a foundation to build on, but success is not measured by file counts; it is measured by data freshness, completeness of descriptions, reusability, availability of APIs and entities’ responses to errors.14

An “open safely” policy applies: every dataset is assessed before publication for privacy, re-identification, security and intellectual property, then published by default unless a valid reason prevents it. This turns data into infrastructure for research, innovation and business, and reduces the institution’s internal monopoly on information.

19. Artificial Intelligence: Data Sovereignty in the Age of Models

The earlier chapter addressed computing, talent and use. A different question is added here: what happens to data when they enter model training, fine-tuning or operation? The entity must record the source, purpose and rights associated with training data, prevent sensitive data from being entered into unapproved public services, and use institutional gateways that prevent secrets from leaking.

For high-impact systems, Iraq must retain the ability to explain data provenance, test bias and errors, trace model versions and stop use when risks emerge. Sovereignty here is not owning every model from scratch, but controlling decisions, data, evaluation, usage logs and the possibility of replacement.

20. International Comparisons: Transfer the Mechanism, Not the State

CaseMechanism useful for IraqWhat is not copied
EstoniaDistributed interoperability, audit trails, the once-only principle and trust infrastructureThe country’s size and development path cannot be transferred unchanged
European UnionData rights, processor accountability, transfer rules and Privacy by DesignGDPR is not copied verbatim without adaptation
IndiaBroad public digital infrastructure, identity, payments and consent layersNo concentration of data is transferred without local safeguards
SingaporeCloud governance, classification, risks and skillsIts administrative and financial capacity differs
United Arab EmiratesGovernment clouds, data and AI policies and rapid investmentContinuous importing must not replace local capacity-building

The shared lesson is not “buy a platform”. More mature countries build a common layer of rules, roles and standards, then allow distributed implementation. This is what Iraq needs: a small number of decisive national rules—classification, identity and permissions, encryption, sharing, retention, incidents, recovery and exit—followed by sectoral freedom to choose the details within those boundaries.

21. Iraq’s Digital Landscape in 2045

By 2045, data must become a governed national asset rather than a scattered stockpile. Citizens do not resubmit documents the state already holds; employees do not load complete databases onto personal devices to perform matching; ministries do not retain data without a time limit or purpose; and projects do not begin without classification, a data owner and a security and recovery plan.

The target architecture is “distributed sovereignty”: a national centre sets policies and shared infrastructure; the National Cybersecurity Centre sets and measures protection and response controls; sectoral entities own their data and are accountable for the quality of their use; and legal oversight protects rights. Authority and data are not all concentrated in one entity in the name of efficiency.

22. Transition Stages, 2027–2045

PhaseObjectiveConditions for progression
2027–2030 | Establish governanceData inventory and classification, data protection law, data owners, a cybersecurity minimum, and exit and recovery plansComplete the central systems inventory, classify critical systems and publish standards
2031–2035 | Unify controlsExpand cloud and hybrid use, audit trails, key management and supplier assessmentAnnual tests and coverage of major entities by the privacy and security framework
2036–2040 | Operational resilienceProvider switching capability, independent recovery centres and compliance automationSuccessful exit tests and reduced single-provider dependencies
2041–2045 | Mature data stateHigh-quality data, risk-based security and sovereignty over keys and critical assetsRegular measurement, independent review and continuity capability demonstrated through exercises

23. Indicator and Target Dashboard

The following targets are proposed policy commitments, not automatic forecasts. Values without a unified national baseline begin with a foundational measurement in 2027 and are not filled with estimates.

Indicator2026 baseline2030203520402045
Entities with an approved inventory and classificationNo unified published baseline≥80%100%100% + review100% + audit
Critical systems with RTO/RPO and a recovery testUnpublished≥70%≥90%≥95%100%
Critical systems with a tested exit planUnpublished≥40%≥70%≥90%100%
Entities with a data protection functionUnpublished≥70%≥90%100%100%
Serious incidents closed with root-cause analysisUnpublished≥80%≥90%≥95%≥95%
High-value open data through APIs where needed2027 baseline+50%+100%Widespread automated updatingQuality before quantity
National cybersecurity maturityITU 2024: Tier 4 / 53.07Improvement demonstrated in the next cycleContinuous improvementAdvanced levelSustained

Operational indicators are added that do not require disclosure of sensitive details: average detection time for high-severity incidents, average restoration time, the percentage of backups that pass a restoration test, the proportion of privileged accounts under PAM, and the share of critical assets with identified data and service owners.

24. The Implementation Programme Package

Programme 1 — National Data and Asset Register

Inventory systems, databases, interfaces and owners, creating a data dictionary and flow diagram for every critical service. Begin with shared national assets, then ministries and governorates.

Programme 2 — Data Classification and Labelling Framework

A simple common classification, with metadata specifying sensitivity, criticality, owner, retention period, hosting location and sharing rules.

Programme 3 — Data Protection Law and Rights System

Adopt a balanced legal framework and establish a supervisory function, correction and grievance routes, breach notification and impact assessment.

Programme 4 — Resilient Government Cloud

Expand the national cloud according to Cloud-Smart principles, with multiple failure domains, key management, immutable backups and a migration policy.

Programme 5 — Secure Government Data Network

Develop the secure network, redundant routes, SD-WAN, monitoring and availability measurement.

Programme 6 — Data Sharing and API Policy

Gradually replace exchanges of full copies with controlled queries, attributes and interfaces, with a record of purpose and authorisation.

Programme 7 — National Data Resilience

RTO/RPO, recovery exercises, alternative centres, restoration tests and national exercises for critical functions.

Programme 8 — Key Management and Digital Trust

PKI/KMS/HSM infrastructure compatible with identity, signatures and services, with separation of permissions, rotation and revocation.

Programme 9 — Digital Procurement Against Vendor Lock-In

Standard clauses for ownership, transfer, logs, keys, incidents, subcontracting and exit.

Programme 10 — Supplier and Supply-Chain Risks

Supplier classification, SBOM where appropriate, security assessments, vulnerability tracking and replacement plans.

Programme 11 — High-Value Open Data

A national list of high-value datasets and APIs, quality standards, update frequency and protection against re-identification.

Programme 12 — AI Data Sovereignty

Training-data policies, safe-use gateways, leakage prevention and Dataset/Model lineage tracking for high-impact systems.

25. Implementation, Cost and Financing Matrix

ProgrammeProposed leadPartners2027–2030CostFinancing
Register and classificationNational Centre for Digital TransformationMinistries, statistics and oversightInventory and classification of central assetsMediumOperating expenditure/digital transformation
Data protectionCouncil of Ministers/Justice/ParliamentJudiciary, digital entities and civil societyLegislation, regulations and organisationLow–mediumPublic budget
Resilient cloudDigital transformationCommunications, cybersecurity and suppliersExpansion + DR + KMSHighGovernment investment/service
Cyber resilienceCybersecurityCritical sectorsStandards, tests and exercisesMedium–highEntities + national level
Keys and trustDigital transformation/trust authoritySecurity, Finance and InteriorPKI/KMS/HSMMediumDigital investment
Procurement and exitCouncil of Ministers/Planning/FinanceContracts and oversightMandatory templatesLowAdministrative
Open dataOpen government/PlanningMinistries and universitiesHigh-value list + APIsLow–mediumBudgets/partnerships
AI data governanceNational Centre for Artificial IntelligenceDigital transformation, security and universitiesPolicy and secure environmentsMediumResearch and development/digitisation

The chapter does not set an aggregate national financial figure because costs depend on an inventory not yet published: the number of data centres, workloads, service levels, contracts, capacities, recovery locations and the extent to which existing assets can be used. The rule is not to fund “sovereignty” as an equipment procurement project, but as a capability programme extending to operations, testing, maintenance and skills.

26. Risks and Safeguards

RiskLikelihood / ImpactEarly WarningMitigation
Turning sovereignty into costly blanket localisationMedium / highRising costs and delayed servicesRisk-based classification and Cloud-Smart
Excessive data centralisationMedium / highRequests for wholesale consolidation without a purposeDistributed integration, minimum data and separation of permissions
Lock-in to a single supplierHigh / highNo export capability and rising exit feesExit clauses and annual testing
Data protection law that obstructs servicesMedium/mediumEvery processing operation requires individual consentMultiple legal bases and proportionality assessment
Cyber law that expands surveillanceMedium / highVague definitions of contentSeparate security from regulation of expression and ensure judicial safeguards
The national cloud as a point of failureMedium/criticalBackups and recovery within a single domainIndependent domains and immutable backups
Skills shortageHigh / highPermanent reliance on the supplierInternal teams, training and knowledge transfer
Excessive secrecyHigh/mediumClassifying most data as secretClassification review and Open by Default
Leakage into public AI toolsHigh / highPersonal accounts and no gatewayAI policy, DLP and approved environments

27. The Bridge to Advanced Manufacturing

This chapter established that digital sovereignty is more than owning servers: it is the ability to govern data, keys, contracts and risks, and cybersecurity is an outcome of resilience and continuity, not of tool counts. It also established that openness to global providers does not automatically create dependency, and blanket localisation does not automatically create sovereignty.

Next Chapter: Advanced Manufacturing

The next chapter, “Advanced Manufacturing”, faces a harder question: if the state can govern its data, computing and security, what industrial capabilities should it build locally in robotics, smart manufacturing, high technology, value chains and semiconductors, and what should it purchase or develop through partnerships rather than attempt to localise? Here, building digital sovereignty ends and turning it into productive technological capability begins.

Notes and references

Documentary Notes

  1. National Centre for Digital Transformation, “About the Centre”, the Centre’s responsibilities under Instructions No. (1) of 2025 on the Organisational Units of the Prime Minister’s Office,Original link; and National Centre for Digital Transformation, services page,Link 2(accessed: 7 October 2026).↩
  2. National Centre for Digital Transformation, “X-Data Smart Data Management Platform”, indicators last updated 19 August 2026: 37 government institutions, 1,412 institutions and branches, 48,285,956 records and 205 digital services,Original link.↩
  3. International Telecommunication Union, Global Cybersecurity Index 2024: Iraq is listed in Tier 4 (Evolving). The National Cybersecurity Centre displays a value of 53.07 on its website.Original link;Link 2.↩
  4. Iraqi Ministry of Justice, “Deputy Minister of Justice for Administrative and Financial Affairs Chairs a Meeting to Follow Up Amendments to Laws Governing Justice Departments”, 16 August 2026; lists personal data protection among the laws under examination and review.Original link.↩
  5. National Centre for Digital Transformation, “About the Centre”, Article (20) of Instructions No. (1) of 2025 on the Organisational Units of the Prime Minister’s Office; its duties include data integration, undertaking the functions of the national data centre and managing related infrastructure.Original link.↩
  6. National Centre for Digital Transformation, “Secure Government Network”; reports connecting more than 500 government entities since the project began in 2018, excluding the Kurdistan Region according to the published text.Original link.↩
  7. National Centre for Digital Transformation, “National Cloud”; describes government hosting inside Iraq, high availability, redundancy, automatic failover and load balancing.Original link.↩
  8. National Centre for Digital Transformation, “X-Data Smart Data Management Platform”,Original link(updated 19 August 2026).↩
  9. Iraqi Council of Representatives, Constitution of the Republic of Iraq of 2005, particularly Article (17) on privacy and the provisions concerning confidentiality of correspondence and communications.Original link.↩
  10. Iraqi Ministry of Justice, meeting to follow up legal amendments, 16 August 2026, previously cited; and Ministry of Justice, “Personal Data Protection”, 14 December 2025,Original link.↩
  11. National Centre for Digital Transformation, “National Cloud”, previously cited.↩
  12. National Cybersecurity Centre, official website and Centre responsibilities page; reports continuous monitoring and more than 500 protected institutions, and sets out its responsibilities for strategy, compliance, risks and response.Original link and Link 2.↩
  13. International Telecommunication Union, Global Cybersecurity Index 2024, previously cited.↩
  14. Iraq National Open Government Portal, the official platform for making government data available,Original link(accessed: 7 October 2026).↩

Core References

  1. National Centre for Digital Transformation — About the Centre and its responsibilities under Instructions No. (1) of 2025 on the Organisational Units of the Prime Minister’s Office.
  2. National Centre for Digital Transformation — X-Data Smart Data Management Platform, indicators updated 19 August 2026.
  3. International Telecommunication Union — Global Cybersecurity Index 2024.
  4. Iraqi Ministry of Justice — Personal data protection; and the meeting to follow up laws, 2025–2026.
  5. Iraqi Council of Representatives — Constitution of the Republic of Iraq of 2005, provisions on rights, privacy and communications.
  6. National Centre for Digital Transformation — Secure Government Network.
  7. National Centre for Digital Transformation — National Cloud.
  8. National Cybersecurity Centre — Official website, responsibilities, policies and security advisories, 2026.
  9. Iraq National Open Government Portal.
  10. NIST — Cybersecurity Framework (CSF) 2.0, 2024.
  11. OECD / World Bank — Frameworks for data governance, digital government, cloud and privacy by design.
Iraq Vision 2045 · Part Six · Chapter SixPrepared by: Ali Zuweid

What are you looking for?

Search content published on the website.