I. Introduction

Iraq is digitalizing faster than its law can follow. Mobile penetration now exceeds 90 percent, financial services are migrating onto platforms supervised by the Central Bank of Iraq (CBI), and the country’s oil and gas sector, the backbone of the economy, increasingly runs on connected operational technology. None of this is controlled by a dedicated cybersecurity or data protection statute. The state’s primary legal tool against digital intrusion remains the Penal Code No. 111 of 1969, a text written for a world without networks, stretched by judges to cover conduct its drafters could not have anticipated.

This gap is not merely academic. Iraq ranks 129th of 194 states on the ITU Global Cybersecurity Index and implements roughly 24 percent of recommended safeguards. Regional incidents, including the 2024 cyber-triggered disruptions in Lebanon, have shown how a digital vulnerability can become a physical security crisis. For a state whose critical infrastructure is majority privately owned, the absence of binding standards is not a regulatory footnote; it is an exposure that private companies currently absorb without legal recourse.

This article takes the position that Iraq should move from its current “Security-First” posture, built on criminalization and surveillance, toward a “Resilience-First” legal and institutional framework: a narrowly drafted cybercrime law, a dedicated data protection statute, an independent national cybersecurity authority operating on a risk-based, tiered model, and explicit constitutional rights safeguards. The argument draws on the European Union’s NIS2 and GDPR regime, the United States’ sector-specific model, and the prescriptive frameworks of Saudi Arabia and the United Arab Emirates, while testing each recommendation against Iraq’s own institutional constraints rather than assuming those models transplant without cost.

Section II sets out the factual and legal background: the scale of Iraq’s digital exposure and the legislative history that has produced the current vacuum. Section III examines where that history leaves the country today and what is at stake in leaving the open issue unresolved. Section IV develops the Resilience-First proposal, working through the arguments for and against it and testing the position against public policy, existing statutes, and comparative regulatory theory. Section V summarizes the practical consequences for companies operating under the current regime. Section VI concludes.

II. Legal Background

A. Factual History

Iraq’s digital exposure has grown considerably faster than its regulatory capacity. The following indicators describe the country’s current position.

MetricIraq Performance (2020–2025)
ITU Global Cybersecurity Index (GCI) rank129th of 194 (2021); 107th (2020); score 53.1/100 (2024)
National Cyber Security Index (NCSI) rank109th globally
Cybersecurity safeguard implementationApproximately 24% of recommended safeguards
UN E-Government Development Index rank148th of 193
Mobile penetration rateAbove 90%
Primary legal reference for cybercrimePenal Code No. 111 of 1969

 

The Cybersecurity Directorate, established within the Ministry of Interior and elevated from a Center to a full Directorate in 2025, reports having identified 166 vulnerabilities in government systems and tracked more than 330 online criminal activities. These figures indicate operational activity, but the Directorate holds no legal mandate to compel private-sector compliance, issue binding standards, or coordinate response across the federal government. The Kurdistan Region of Iraq operates a separate and outdated instrument, Law No. 6 of 2008 on the Prevention of Misuse of Information Technologies, which gives businesses in the north a local regulatory touchpoint that does not exist federally.

B. Legal History

Iraq has no comprehensive cybersecurity or cybercrime statute. In its absence, courts and regulators rely on four sources, none designed for digital conduct.

  • Penal Code No. 111 of 1969: provisions on forgery, fraud, blackmail, and extortion are applied by analogy to electronic conduct.
  • Civil Code No. 40 of 1951: used for tortious liability and contractual disputes arising from data breaches or service interruptions.
  • Central Bank of Iraq directives: the most developed sectoral regime, requiring banks and fintech operators to meet international standards such as PCI DSS and SWIFT’s customer security controls.
  • Communications and Media Commission, Law No. 65 of 2004: governs telecommunications licensing and spectrum management, with limited application to cybersecurity resilience.

Constitutional protection exists in principle. Article 17 of the 2005 Constitution guarantees personal privacy, and Article 40 protects the confidentiality of electronic, telephonic, and telegraphic correspondence, permitting interception only for legal and security necessity by judicial decision. Neither article is supported by implementing legislation defining “security necessity” or providing a remedy for its breach, so the guarantee is difficult to enforce against either state surveillance or private-sector misuse.

Legislative attempts to fill the gap have repeatedly failed on the same point. A 2011 draft Cybercrime Law, reintroduced with modest amendments in 2019 and again under debate in 2023, consistently pursued criminalization ahead of protection: draft provisions prescribed life imprisonment for online conduct deemed to threaten “national interests,” using terms broad enough to capture legitimate reporting and commentary alongside genuine security threats. International legal and human rights bodies, including Amnesty International and Article 19, assessed that this drafting fell short of international standards on legality and proportionality and risked deterring journalists and whistleblowers from reporting in the first place. A related instrument, CMC Regulation No. 1 of 2023 on indecent online content, drew similar criticism for its breadth.

Legislative MilestoneDescription and Critical Concerns
2011 / 2013 DraftFocused on criminalizing online speech; provided life imprisonment for undermining vaguely defined “national interests.”
2019 / 2020 ReintroductionA modestly amended version of the 2011 draft, retaining broad and undefined prohibited categories of speech.
2023 DraftUnder debate; continues to prioritize state security over data protection; assessed by rights organizations as disproportionate.
CMC Regulation No. 1 of 2023Directive on “indecent content” online; criticized for its breadth relative to freedom-of-expression protections.

 

This pattern, criminalization drafted without a corresponding protective framework, is the central legal-historical fact this article carries forward. It explains why the open issue in Section III is not simply “Iraq lacks a cybersecurity law” but more specifically “Iraq’s legislative attempts have consistently failed for the same structural reason, and any new proposal must account for that reason or repeat it.”

III. The Open Issue: Iraq’s Regulatory Choice Today

Where this leaves Iraq today is a state of enforced private governance. Courts classify cyber incidents as “consequential crimes,” focusing on the outcome, such as stolen funds, rather than the digital method used to achieve it. Judicial commentary confirms that hacking and AI-facilitated offenses are prosecuted, where they are prosecuted at all, under traditional categories such as defamation, blackmail, and forgery. Three structural obstacles compound this: a conceptual mismatch between theft (requiring physical removal) and data copying (which leaves the original in place); a judiciary that generally lacks specialized digital forensics training; and a Law of Evidence oriented toward paper documents and witness testimony, which makes authenticating IP logs and encrypted communications a recurring point of failure in prosecutions.

Institutionally, cybersecurity authority is currently divided among the Ministry of Interior, the Ministry of Defense, and separate intelligence agencies, each maintaining its own cybersecurity cell with limited coordination between them. A national incident-response function was nominally created in 2017 but carries no legal mandate to coordinate response across government or the private sector. The 2022–2025 National Cybersecurity Strategy exists on paper; its implementation has been constrained by underfunding and a shortage of qualified technical personnel, many of whom are drawn to better-compensated private-sector roles.

The ramifications of leaving this unresolved fall most heavily on the private sector, which owns most of the country’s digital infrastructure. Without a data protection law, there is no legal definition of personal or sensitive data and no breach notification obligation outside banking. Without a central regulator, there is no authority empowered to issue binding standards, conduct audits, or certify critical infrastructure equipment. Compliance, where it exists, is voluntary and driven by the demands of international counterparties rather than domestic law, a dynamic addressed further in Section V.

The legal history traced in Section II directly shapes how this open issue should be approached now. Because every prior legislative attempt failed on the same axis, criminalization without protection, any credible proposal must resolve that axis first rather than treat it as a drafting detail to be fixed later. That is the premise on which Section IV builds.

IV. Proposal: A Resilience-First Legal and Institutional Framework

This article proposes that Iraq adopt a Resilience-First framework consisting of four components: a narrowly drafted cybercrime law, a dedicated data protection statute, an independent national cybersecurity authority operating a risk-based, tiered supervisory model, and explicit constitutional rights safeguards. Each is examined below for its advantages and disadvantages before the position is tested against the case for maintaining the status quo.

A. Favorable Arguments

1. A Narrowly Drafted Cybercrime Law

Unauthorized access and related offenses should be defined narrowly and require both intent and demonstrable harm. This reverses the drafting pattern of the 2011, 2019, and 2023 drafts.

  • Advantage: restores the principle of legality, gives judges an explicit statutory basis rather than analogized Penal Code provisions, and shields ethical security researchers from prosecution under an overbroad definition of unauthorized access.
  • Disadvantage: narrow definitions may not reach genuinely novel conduct, and requiring proof of intent can slow prosecution where digital evidence is already difficult to authenticate under the current Law of Evidence.

The advantage outweighs the disadvantage. The current vagueness has already produced inconsistent judicial outcomes and, in the drafts examined above, created a real risk of criminalizing legitimate conduct; a narrower statute trades some prosecutorial reach for the legal certainty the current regime lacks entirely.

2. A Dedicated Data Protection Law

Modeled on the structure, though not necessarily the substantive thresholds, of the GDPR and the Saudi Personal Data Protection Law, this instrument would define personal and sensitive data, create a data subject’s right to be informed of a breach, and impose a notification obligation on regulated entities.

  • Advantage: closes the definitional vacuum described in Section III, gives Iraqi companies a domestic legal basis for the security investments international counterparties already demand of them, and creates the possibility of future data-adequacy recognition by trading partners.
  • Disadvantage: compliance costs fall on entities, particularly local startups, that currently operate without any such obligation; and a law without a funded enforcement body risks becoming symbolic, repeating the underfunding pattern already documented in the 2022–2025 strategy.

The advantage outweighs the disadvantage if, and only if, the statute is paired with a phased compliance timeline for small and medium enterprises and a ring-fenced funding line for the regulator described below. Absent that pairing, the disadvantage is real and is addressed directly in Section IV.B.

3. An Independent National Cybersecurity Authority

The existing Cybersecurity Directorate would be reconstituted as an independent authority reporting to the Council of Ministers rather than to a single security ministry, empowered to issue binding minimum-security standards, following the tiered model used in the EU’s NIS2 Directive and the prescriptive control catalogs used by Saudi Arabia’s National Cybersecurity Authority.

FeatureSaudi Arabia (NCA ECC)UAE (NESA IAS)
Mandatory statusMandatory for government and critical infrastructureMandatory for public and private sectors
Control count114 specific controlsComprehensive information assurance catalog
Workforce policyMandates full-time qualified professionals in key rolesFocuses on international alignment (GDPR/ISO)
Data residencyStrict local storage for critical dataGuidance on cross-border safeguards

 

  • Advantage: creates the single standard-setter Iraq currently lacks, ends the pattern of separate agencies operating uncoordinated cybersecurity cells, and provides the institutional home needed to run sector-specific frameworks of the kind the CBI has already proven viable in banking.
  • Disadvantage: establishing a fifth institutional actor without first resolving the mandate overlap among existing agencies could, in the near term, add to fragmentation rather than resolve it; and the funding risk that stalled the 2022–2025 strategy applies with equal force here.

The advantage outweighs the disadvantage only if the authority’s founding statute itself transfers, rather than merely supplements, the mandates currently held by the separate ministry-level cells, and only if its budget is set in the enabling legislation rather than left to annual appropriation. This is a genuine risk, not a rhetorical one, and is weighed against the status quo in Section IV.B.

4. Explicit Constitutional Rights Safeguards

Any cybercrime or surveillance provision should require a judicial warrant for interception, consistent with Article 40 of the Constitution, and should include express carve-outs protecting investigative journalism and whistleblowing.

  • Advantage: gives Articles 17 and 40 the implementing content they currently lack, directly answers the drafting failure identified across the 2011, 2019, and 2023 drafts, and is likely to be a precondition for the Iraqi Bar Association and civil society organizations to support passage at all.
  • Disadvantage: carve-outs drafted too broadly can be exploited by bad-faith actors claiming a journalistic or whistleblowing purpose, and “security necessity” as a warrant standard requires careful definition or it recreates the same vagueness problem it is meant to solve.

The advantage outweighs the disadvantage. A carve-out imprecisely drafted is a drafting risk that can be corrected in committee; a statute with no rights safeguard at all has already failed three times in the legislative process for exactly that omission.

Conclusion of favorable arguments: taken together, the four components respond directly to the specific legal-historical failure identified in Section II, namely that Iraq’s legislative attempts have criminalized conduct without ever pairing that criminalization with a protective framework. Each component’s advantages depend on implementation conditions, phased SME compliance, statutory mandate transfer, ring-fenced funding, and precise carve-out drafting, that are achievable but not automatic.

B. Arguments Against the Proposal

1. Capacity and Resource Constraints

Iraq’s own recent experience argues against the proposal. The 2022–2025 National Cybersecurity Strategy exists on paper and has been constrained by underfunding and a shortage of qualified personnel. A full EU- or Saudi-grade regulatory regime, layered onto an authority with the same funding exposure, risks producing law that cannot be enforced, which is arguably worse than no law because it creates an appearance of protection that does not exist in practice.

2. Economic Burden on Small and Medium Enterprises

Mandatory audits, certification requirements, and tiered supervision of the kind used in NIS2 and the Saudi ECC impose real compliance costs. Imposed prematurely on an economy still implementing only about 24 percent of recommended safeguards, these costs could suppress investment in Iraq’s nascent digital and fintech sectors rather than strengthen them, particularly for local startups without the compliance budgets of multinational counterparts.

3. Sequencing and Institutional Design Risk

Creating an independent authority before resolving the overlapping mandates currently held by separate ministry-level cybersecurity cells could add a fifth uncoordinated actor to an already fragmented field rather than consolidate it, unless the founding legislation includes an explicit and enforceable mandate-transfer mechanism.

 

4. Judicial Capacity Deficit

Legislative reform does not, by itself, solve the evidentiary and forensic-expertise gaps documented in Section III. A new statute changes the text judges apply; it does not train judges to authenticate digital logs or interpret encrypted communications. Without parallel investment in judicial training and forensic infrastructure, the reform changes the law without changing case outcomes.

Why the Advantages Outweigh the Disadvantages

Each disadvantage above is a sequencing and design problem, not a reason to preserve the status quo, and Iraq’s own comparative experience in banking shows a workable sequence already exists. The CBI’s directives, phased in around specific institutions with defined compliance deadlines, produced sector compliance without a general statute, evidence that a phased, sector-first rollout under the same authority avoids the funding and capacity failures of a single wholesale reform. Concretely: SME compliance thresholds can be phased by revenue or sector rather than applied uniformly on day one; the new authority’s founding statute can include an explicit, self-executing transfer of mandate from existing ministry cells rather than leaving coordination to inter-agency goodwill; its budget can be fixed in the enabling law itself, following the model used to insulate the CBI’s regulatory functions from annual appropriation risk; and judicial training and forensic-lab funding can be written into the same legislative package rather than treated as a separate, lower-priority initiative. None of this eliminates the risk identified in Section IV.B, Iraq’s institutional capacity remains genuinely constrained, but it converts an argument against reform into a set of drafting and implementation requirements for it. On balance, the cost of continuing the current regime, which Section III shows is already being paid by the private sector through externally imposed compliance obligations with no domestic legal support, exceeds the cost of a properly sequenced reform.

C. How the Proposal Supports

1. Public Policy

The proposal directly serves two policy interests already implicit in Iraq’s economic structure: protecting the operational technology underlying the oil and gas sector from sabotage and industrial espionage, and protecting the stability and consumer trust of the fintech sector the CBI has actively promoted. A framework that treats digital security as an economic enabler, rather than only a policing concern, aligns regulation with where the country’s growth is actually occurring.

2. Current Statutes

The proposal is not a departure from existing law but an extension of patterns already present in it. It gives operative content to Constitution Articles 17 and 40 rather than displacing them. It complements, rather than replaces, the general liability provisions of the Penal Code No. 111 of 1969 and the Civil Code No. 40 of 1951, which continue to apply to conduct outside the new statute’s specific scope. And it generalizes, rather than invents, the sectoral compliance model the CBI has already applied successfully to banking under PCI DSS and SWIFT-aligned directives.

3. Comparative and Scholarly Theory

The proposal follows the risk-based regulatory theory underlying the EU’s NIS2 framework, under which supervisory intensity scales with the criticality of the regulated entity rather than applying uniformly. It also reflects a law-and-development premise relevant to any transplant of a developed-economy regulatory model into a resource-constrained state: legal reform sequenced with institutional capacity-building outperforms legal reform pursued in isolation, a premise this article applies directly in the phased implementation set out in Section IV.B.

4. Prevailing Regulatory Discourse

Internationally, the live debate is not whether states should regulate cybersecurity but how: through a prescriptive, government-set control catalog, as in Saudi Arabia and the UAE, or through outcome-based, co-regulatory obligations placed on private entities, as in the EU and the United States. The proposal in this article does not resolve that debate in the abstract; it selects a hybrid suited to Iraq’s specific starting point, prescriptive enough to give a currently rule-less environment clear minimum standards, but sequenced and risk-tiered so smaller entities are not held to the same bar as critical infrastructure operators from the outset.

V. Practical Implications for Businesses Under the Current Regime

Whatever the pace of legislative reform, companies operating in Iraq are already managing the consequences of the gap described in Sections II and III. Three points of exposure recur across sectors.

  • Legal unpredictability: absent a clear statute, a company can be investigated under general Penal Code provisions, including Article 430, or under a still-unpassed draft law, for what is in substance a standard security breach. Executives face potential criminal exposure for “negligence” where a breach is characterized as causing social unrest or economic harm.
  • Contractual exposure: in the absence of state-imposed standards, international counterparties routinely impose demanding indemnity clauses on Iraqi partners, allocating close to full liability for breach costs to the local entity.
  • Operational exposure: ransomware remains the leading threat to oil and gas, education, and logistics firms, frequently targeting backups first; the convergence of operational and information technology in industrial settings expands the attack surface; and insider risk, particularly unauthorized data transfer by departing employees, remains a largely unaddressed vulnerability in corporate practice.

Until the framework proposed in Section IV is enacted, companies are advised to treat contract and internal governance as the operative law. Adopting ISO/IEC 27001 voluntarily, documenting cybersecurity decisions at board level, negotiating explicit breach-notification and data-return clauses into vendor agreements, and mapping data flows toward CBI-preferred local residency are not substitutes for regulation, but they are the closest functional equivalent available under the current regime, and they position a company to comply with minimal disruption once the proposal in Section IV is enacted.

VI. Conclusion

Iraq’s cybersecurity regulation sits at an early and consequential stage. The state relies on a mid-twentieth-century Penal Code to govern conduct its drafters never contemplated, its legislative attempts have failed three times for the same reason, criminalization without protection, and its private sector currently absorbs the cost of that gap through externally imposed, domestically unsupported compliance obligations.

This article has proposed a Resilience-First alternative: a narrowly drafted cybercrime law, a dedicated data protection statute, an independent risk-based cybersecurity authority, and explicit constitutional rights safeguards, sequenced through phased SME compliance, statutory mandate transfer, ring-fenced funding, and parallel judicial capacity-building. The case against this proposal, rooted in Iraq’s genuine resource and institutional constraints, is real, but it is an argument for careful sequencing, not for preserving a status quo that has already been shown, across three failed legislative attempts and a stalled national strategy, not to work. The stronger position is that Iraq adopts the framework proposed here, deliberately sequenced to its own institutional capacity, rather than wait for a comprehensive solution that its legislative history suggests will not arrive on its own.