World Watch/Iraq/Cybersecurity

Cybersecurity · Iraq

Cybersecurity regulation in Iraq (2026)

ProposedNo dedicated cybersecurity or cybercrime law in force; obligations derived from Iraqi Penal Code No. 111 of 1969 and Civil Code No. 40 of 1951, supplemented by sector-specific rules (Banking Law No. 94/2004; CPA Order 65/2004 for communications/CMC); National Cybersecurity Strategy 2022–2025 and Ministry of Interior Cybersecurity Directorate (established 2025) constitute the institutional frameworkCountry index 54 · C

Iraq shaded by its cybersecurity status

Iraq has no enacted cybercrime or comprehensive cybersecurity statute as of 2026. A Draft Cybercrime Law has been in circulation since 2011, was suspended by parliament in May 2021 over free-speech concerns, and remains unenacted despite repeated attempts at reintroduction. Institutional capacity has grown—the Ministry of Interior upgraded its Cybersecurity Centre to a full Cybersecurity Directorate in 2025—but mandatory breach-notification obligations and a general data-protection regime do not exist.

Key points

No enacted cybersecurity law

Iraq has no dedicated cybercrime or cybersecurity statute. Courts rely on Penal Code No. 111/1969 and Civil Code No. 40/1951, instruments not designed for digital offences that leave significant enforcement gaps.

Draft Cybercrime Law stalled

A Draft Information/Cybercrime Law (originated 2011, revised multiple times) was formally suspended by the Iraqi Parliament in May 2021 due to concerns it would restrict freedom of expression; reintroduced for a vote in 2022 but still not enacted as of 2026, with debate ongoing.

National Cybersecurity Strategy 2022–2025

The Ministry of Interior approved Iraq's first National Cybersecurity Strategy in December 2022, setting policy goals for cyber defence and establishing the basis for a dedicated Cybersecurity Centre under the ministry's authority.

Ministry of Interior Cybersecurity Directorate (2025)

The Ministry of Interior's Cybersecurity Centre was upgraded to a full Cybersecurity Directorate in 2025, described as 'a strategic response to the shifting digital threat landscape,' and works alongside a high-level inter-agency cybersecurity committee convened by the Prime Minister.

No breach-notification or data-protection obligations

Iraq has no general data-protection law and no Data Protection Authority. There is no statutory obligation to notify regulators or affected individuals of data breaches; notification is considered prudent but carries no legal mandate.

Sector-specific and CMC rules provide partial coverage

The Communications and Media Commission (CMC), established under CPA Order 65/2004, issues digital-content directives and a draft Data Classification Policy. Banking Law No. 94/2004 and Central Bank of Iraq regulations impose some cybersecurity-adjacent obligations on financial institutions.

Iraq - other topics

Last verified 5/24/2026 · Orientation, not legal advice - verify against the primary sources linked above. Explore the full world map →