Iraq - Cyber Crimes Regulation (RAI-IQ-NA-DRAFT20-2023)
Draft Informatics Crimes Law
مشروع قانون جرائم المعلوماتية
Iraq
RAI-IQ-NA-DRAFT20-2023Draft 2023
A proposed Iraqi law targeting cybercrime and digital activities, criticized for potential impacts on free speech and privacy.
Summary
Read full text ↗Plain English
Overview
The Iraq Draft Cybercrime Law 2023, officially known as the Informatics Crimes Bill, represents a significant and controversial attempt by the Iraqi Council of Representatives to regulate the nation's digital landscape. The legislative journey of this bill began as early as 2011, but it has faced repeated suspensions and withdrawals due to intense pressure from civil society, international human rights organizations, and digital rights advocates. The 2023 iteration was reintroduced to the Parliament with the stated objective of providing a legal framework to combat the rising tide of electronic fraud, blackmail, and cyber-terrorism. Proponents of the bill, including members of the Security and Defense Committee, argue that Iraq is currently operating in a legal vacuum regarding digital offenses, which leaves citizens and state infrastructure vulnerable to sophisticated technological threats. They emphasize that the law is necessary to modernize the Iraqi judiciary's ability to handle crimes that did not exist when the 1969 Penal Code was enacted. The bill's re-emergence in the legislative agenda reflects a broader regional trend where governments are seeking to assert greater sovereignty over digital spaces, often citing national security as the primary justification for increased oversight and control.
Definitions and Scope
The draft law provides a comprehensive, albeit broad, set of definitions intended to encompass all aspects of digital and electronic activity. It defines 'Informatics Crimes' as any act committed through the use of an information network, computer, or similar device that violates the provisions of this law. The term 'Information Network' is defined expansively to include any system for the transfer and exchange of data, effectively covering the entire internet, private intranets, and telecommunications infrastructure. This broad scope ensures that no digital platform—whether a global social media site or a local messaging app—is exempt from the law's jurisdiction. Furthermore, the bill defines 'Electronic Means' as any technology that uses electrical, digital, magnetic, or optical capabilities to process and store information, which includes everything from personal smartphones to industrial control systems. One of the more contentious aspects of the definitions section is how it categorizes 'Service Providers' and 'Users.' Service providers are defined as any entity, public or private, that provides subscribers with the ability to communicate via information technology or processes and stores electronic data on their behalf. This definition places significant legal burdens on Internet Service Providers (ISPs) and platform operators, potentially making them liable for the content transmitted through their systems. The bill also introduces definitions for 'Digital Content,' which includes any data, images, audio, or video produced or shared electronically. By defining content so broadly, the law sets the stage for the regulation of virtually all forms of online expression, from private messages to public broadcasts, without providing clear distinctions between different types of digital communication.
Governance and Institutional Framework
The governance of the Informatics Crimes Bill is centralized within several key state institutions, primarily the Ministry of Interior, the National Security Service, and the Communications and Media Commission (CMC). The Ministry of Interior is tasked with the primary enforcement of the law, utilizing its specialized cybercrime units to investigate and track digital offenses. These units are granted extensive powers to monitor information networks and seize electronic devices suspected of being involved in criminal activity. The bill also envisions a significant role for the National Security Service in cases where cybercrimes are deemed to threaten the 'supreme interests' of the state, such as digital espionage or attacks on critical infrastructure. This overlapping jurisdiction between civil police and national security agencies has raised concerns about the lack of clear oversight and the potential for extrajudicial surveillance. The Communications and Media Commission (CMC) serves as the regulatory backbone for the technical implementation of the law. Under the draft, the CMC is responsible for issuing licenses to service providers and ensuring their compliance with the law's data retention and monitoring requirements. The CMC also gains the authority to issue administrative orders for the removal of content or the blocking of websites that are found to violate the law's provisions. Judicial oversight is provided by the Iraqi High Judicial Council, which is expected to establish specialized courts or designate specific judges to handle informatics crimes. However, the draft has been criticized for not providing sufficient procedural safeguards to protect the rights of the accused, as the investigative powers granted to security agencies often bypass traditional judicial warrants in the interest of 'national security' or 'public order.'
Key Focus Areas and Prohibitions
The Informatics Crimes Bill focuses on three primary areas: national security, public morality, and financial integrity. In the realm of national security, the bill targets activities that 'undermine the independence, integrity, and safety of the country.' This includes the unauthorized access to government databases, the dissemination of state secrets, and the use of digital networks to organize or promote armed insurrection. Article 3 of the draft is particularly notable for prescribing life imprisonment for anyone found guilty of using the internet to harm the country's reputation or its supreme economic and political interests. These provisions are designed to protect the state from external cyber threats and internal subversion, but their broad phrasing allows for a wide range of interpretations that could encompass legitimate political criticism. The second focus area is the protection of 'public morals' and 'social values.' Articles 21 and 22 of the draft impose strict penalties on individuals who use digital platforms to share content that is deemed 'indecent' or that 'infringes on religious, moral, family, or social principles.' This section of the law is directly linked to the Iraqi government's ongoing efforts to regulate social media content and punish influencers or activists who challenge traditional societal norms. Finally, the bill addresses financial cybercrimes, such as electronic fraud, identity theft, and the unauthorized use of credit cards. These provisions are generally seen as the least controversial part of the law, as they provide a much-needed legal basis for prosecuting the growing number of digital scams and financial crimes that target Iraqi citizens and businesses. The inclusion of these financial protections is often used by the government to justify the more restrictive elements of the bill, presenting the legislation as a holistic solution to all digital challenges.
Implementation and Technical Requirements
The implementation framework of the Informatics Crimes Bill relies heavily on the cooperation of private sector entities, specifically Internet Service Providers (ISPs) and telecommunications companies. These entities are required to implement technical measures that allow for the monitoring of traffic and the retention of user data for specified periods, typically up to 90 days or more upon request by authorities. ISPs must also provide the security services with direct access to their systems during investigations, a requirement that has sparked significant privacy concerns. The bill mandates that service providers must report any suspicious activity or 'illicit content' discovered on their networks, effectively turning private companies into an extension of the state's surveillance apparatus. On the procedural side, the law outlines the steps for digital forensics and the collection of electronic evidence. It specifies that electronic data and metadata are admissible in court as primary evidence, provided they are collected according to the standards set by the Ministry of Interior. The bill also encourages the development of a national cybersecurity strategy that involves regular audits of government and private sector digital infrastructure. However, the implementation of these measures is hampered by Iraq's limited technical capacity and the lack of specialized training for judicial and law enforcement personnel. To address this, the bill suggests the creation of a national center for cybersecurity, which would coordinate implementation efforts and provide technical support to various state agencies. This center would also be responsible for international cooperation on technical matters, though its operational independence remains a point of contention among stakeholders.
Monitoring, Evaluation, and Public Reporting
Monitoring under the Informatics Crimes Bill is both proactive and reactive. Proactively, the Ministry of Interior and the CMC are authorized to monitor public information networks to detect potential violations of the law. This includes the use of automated tools to scan for keywords or content that might be deemed a threat to national security or public morals. Reactively, the government has introduced digital platforms like the 'Balaqh' (Report) application, which allows citizens to report 'offensive' or 'indecent' content directly to the authorities. This crowdsourced surveillance mechanism has already led to the arrest of several high-profile social media figures and is expected to be a primary tool for enforcing the law's morality provisions once the bill is enacted. Evaluation of the law's effectiveness is intended to be conducted through annual reports submitted by the Ministry of Interior and the CMC to the Council of Representatives. These reports are expected to detail the number of investigations launched, the types of crimes prosecuted, and the administrative actions taken against service providers. However, there is no provision in the current draft for an independent oversight body to evaluate the impact of the law on human rights and freedom of expression. The lack of a transparent evaluation mechanism means that the law could be applied inconsistently, with little recourse for those who believe their rights have been violated. International observers have called for the inclusion of a 'sunset clause' or a mandatory periodic review by a committee of legal experts and civil society representatives to ensure the law remains aligned with international standards and does not become a permanent fixture of state repression.
Penalties, Liability, and Judicial Recourse
The penalties prescribed in the Informatics Crimes Bill are among the most severe in the region for digital offenses. The law utilizes a tiered system of punishments, ranging from minor fines to life imprisonment. For crimes deemed to threaten the state's sovereignty or national security, such as those listed in Article 3, the penalty is life imprisonment and a fine of up to 50 million Iraqi Dinars (approximately $38,000). Crimes related to 'sectarian strife' or 'disturbing public order' under Article 6 also carry heavy prison sentences. Even relatively minor offenses, such as 'violating social values' under Article 21, can result in at least one year of imprisonment and substantial fines. The severity of these penalties has been described by human rights groups as disproportionate and likely to have a chilling effect on all forms of digital communication. Liability under the law extends beyond the primary offender to include anyone who 'assists, encourages, or facilitates' the commission of an informatics crime. This broad definition of secondary liability could potentially implicate web developers, platform moderators, and even individuals who share or 'like' controversial content. Service providers can also be held liable if they fail to comply with government take-down orders or data requests. Regarding appeals, the bill states that defendants have the right to challenge court rulings through the standard Iraqi appellate process. However, given the specialized and technical nature of informatics crimes, there are concerns that the appellate courts may lack the expertise to properly evaluate electronic evidence, potentially leading to the upholding of wrongful convictions based on flawed digital forensics or politically motivated investigations.
Impact on Civil Liberties and Digital Rights
The potential impact of the Informatics Crimes Bill on civil liberties in Iraq is profound. By criminalizing vaguely defined acts such as 'harming the national reputation' or 'violating social values,' the law provides the state with a powerful legal instrument to silence dissent and restrict the activities of journalists, human rights defenders, and political activists. The digital space, which has served as a critical platform for organizing protests and exposing corruption in Iraq, would be significantly curtailed under this legislative framework. Privacy rights are also at risk, as the law mandates extensive data retention and grants security agencies broad access to personal communications without robust judicial oversight. The requirement for ISPs to monitor traffic and report 'illicit content' creates a culture of self-censorship, where individuals may fear expressing their opinions online due to the risk of surveillance and prosecution. Furthermore, the law's focus on 'public morals' could be used to target marginalized communities, including LGBTQ+ individuals and religious minorities, whose online presence might be deemed 'indecent' by the authorities. Digital rights advocates argue that the bill fails to strike a necessary balance between security and freedom, prioritizing the protection of the state and traditional social structures over the fundamental rights of citizens. The lack of clear definitions for what constitutes a violation of 'social values' leaves the law open to arbitrary enforcement, which is a hallmark of authoritarian digital governance.
Relationship to Existing Legal Frameworks
The Informatics Crimes Bill is designed to complement and expand upon existing Iraqi legislation, most notably the Penal Code No. 111 of 1969. While the 1969 Code contains provisions for defamation, fraud, and threats to national security, it was written long before the advent of the internet and lacks the technical specificity required to address modern cybercrimes. The new bill serves as a 'lex specialis' (special law) that takes precedence over the general Penal Code in matters involving digital technology. However, where the Informatics Crimes Bill is silent, the provisions of the Penal Code and the Criminal Procedure Code No. 23 of 1971 still apply. This creates a complex legal environment where a single act could potentially be prosecuted under multiple statutes, leading to 'legal stacking' and even harsher cumulative sentences. The bill also interacts with the Iraqi Constitution of 2005, particularly Article 38, which guarantees freedom of expression, press, and assembly 'in a way that does not violate public order and morality.' The Informatics Crimes Bill essentially seeks to define the boundaries of these constitutional exceptions. Furthermore, the bill has a direct relationship with the Communications and Media Commission Law (CPA Order 65 of 2004), which provides the regulatory framework for the telecommunications sector. By integrating cybercrime enforcement with media regulation, the Iraqi government is creating a unified system for controlling both the infrastructure and the content of the nation's digital space. This integration is seen as a move toward a more centralized and controlled information environment, similar to models seen in other parts of the Middle East where digital sovereignty is prioritized over open internet principles.
International Alignment and Global Standards
The Iraq Draft Cybercrime Law has been criticized for its lack of alignment with international human rights standards and global cybercrime conventions. Most notably, the bill's provisions are seen as inconsistent with the International Covenant on Civil and Political Rights (ICCPR), to which Iraq has been a party since 1971. Article 19 of the ICCPR protects the right to hold opinions without interference and the freedom to seek, receive, and impart information of all kinds. The broad and vague restrictions on 'social values' and 'national reputation' in the Iraqi bill are viewed as failing the three-part test of legality, legitimacy, and necessity required by international law for any restriction on free speech. Furthermore, the bill does not align with the principles of the Budapest Convention on Cybercrime, the leading international treaty designed to harmonize national cybercrime laws. While the Budapest Convention focuses on technical crimes like hacking, data interference, and child pornography, it includes strict procedural safeguards to protect privacy and civil liberties. In contrast, the Iraqi bill prioritizes content regulation and state security over individual rights. While Iraq has expressed interest in international cooperation to combat cyber-terrorism, the current draft of the law may actually hinder such cooperation, as many democratic nations are reluctant to share data or extradite individuals under laws that carry life sentences for political speech or 'moral' offenses. This misalignment risks isolating Iraq from the global digital economy and the international legal community, as foreign tech companies may be hesitant to operate in a jurisdiction with such restrictive and unpredictable legal requirements.
Implementation Timeline
| Milestone | Date | Notes |
|---|---|---|
| Initial Draft Introduction | 2011-01-15 | First version of the bill introduced but later withdrawn due to protests. |
| Reintroduction to Parliament | 2022-11-21 | The bill was formally reintroduced by the Council of Ministers. |
| First Reading | 2023-01-12 | First formal reading in the Council of Representatives. |
| Second Reading and Debate | 2023-03-15 | Parliamentary debate involving the Security and Defense Committee. |
| Committee Review Phase | 2023-06-01 | Ongoing review by legal and security committees for potential amendments. |
| Anticipated Final Vote | 2025-12-31 | Expected timeframe for final vote, subject to political consensus. |
Compliance Checklist
| Check | Required Action |
|---|---|
| Data Retention Compliance | ISPs must retain traffic data and user logs for a minimum of 90 days. |
| Content Moderation | Platforms must remove content deemed 'indecent' or 'threatening to public order' within 24 hours of notice. |
| Identity Verification | Telecommunications providers must ensure all SIM cards and accounts are linked to verified national IDs. |
| Security Cooperation | Service providers must grant judicial and security authorities access to encrypted data upon legal request. |
| Reporting Obligations | Entities must report any detected cyber-terrorism or financial fraud to the Ministry of Interior immediately. |
| User Privacy Disclosure | Users must be notified of data collection practices, though this is often overridden by security mandates. |
Iraq's proposed Informatics Crimes Bill aims to regulate nearly all digital activity and combat cybercrime, applying broadly to anyone using information networks, computers, or electronic means within Iraq, including individuals, service providers, and platform operators. This draft legislation casts a wide net, defining 'informatics crimes' as any digital act violating its provisions, and broadly covering the entire internet, private networks, and all electronic devices from smartphones to industrial systems. It places significant legal burdens on 'service providers'—any entity offering digital communication or data storage—making them potentially liable for content transmitted through their systems.
At its core, the law focuses on three primary areas: national security, public morality, and financial integrity. - It prohibits activities that 'undermine the independence, integrity, and safety of the country,' including harming Iraq's reputation or economic interests, with penalties up to life imprisonment. - It also targets content deemed 'indecent' or infringing on 'religious, moral, family, or social principles,' carrying at least one year in prison. - For service providers, key obligations include retaining user data for at least 90 days, implementing monitoring measures, and granting security services direct access to their systems during investigations. They must also report suspicious activity or 'illicit content.'
Enforcement falls primarily to the Ministry of Interior and National Security Service, with the Communications and Media Commission able to order content removal or website blocking. Penalties are severe, ranging from substantial fines to life imprisonment for serious offenses. Liability extends beyond the direct perpetrator to anyone who 'assists, encourages, or facilitates' a digital crime, potentially including platform moderators or even individuals who share content.
This is a proposed law, not yet in effect. It was reintroduced to Parliament in late 2022, underwent a second reading in March 2023, and is currently in committee review, with a final vote anticipated by the end of 2025. The exact effective date after enactment is unknown. A significant practical pitfall for anyone operating in Iraq's digital space is the law's use of broad and vague terms, such as 'harming the country's reputation' or 'violating social values.' These undefined concepts allow for wide interpretation and potential arbitrary enforcement, creating a chilling effect on free speech and potentially leading to the prosecution of journalists, activists, or even ordinary users for legitimate online expression.
Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.
What you must do — compliance checklist
0 / 11 marked completePlain-English obligations under Iraq - Cyber Crimes Regulation (RAI-IQ-NA-DRAFT20-2023). Not legal advice — verify against the official text before relying on it.
- #1CriticalArticle 3⏰ Upon enactment
Applies to: Individuals and entities using information networks.
“Article 3... prescribing life imprisonment for anyone found guilty of using the internet to harm the country's reputation or its supreme economic and political interests.”
- #2CriticalArticles 21 and 22⏰ Upon enactment
Applies to: Individuals and entities using digital platforms.
“Articles 21 and 22... impose strict penalties on individuals who use digital platforms to share content that is deemed 'indecent' or that 'infringes on religious, moral, family, or social principles.'”
- #3Critical⏰ Upon enactment
Applies to: Individuals and entities using digital means.
“Finally, the bill addresses financial cybercrimes, such as electronic fraud, identity theft, and the unauthorized use of credit cards.”
- #4Critical⏰ Upon legal request
Applies to: Service providers.
“Service providers must grant judicial and security authorities access to encrypted data upon legal request.”
- #5Critical⏰ Immediately
Applies to: Entities operating information networks.
“Entities must report any detected cyber-terrorism or financial fraud to the Ministry of Interior immediately.”
- #6Critical⏰ Within 24 hours of notice
Applies to: Platform operators and service providers.
“Platforms must remove content deemed 'indecent' or 'threatening to public order' within 24 hours of notice.”
- #7Critical⏰ Upon enactment
Applies to: Any individual or entity.
“Liability under the law extends beyond the primary offender to include anyone who 'assists, encourages, or facilitates' the commission of an informatics crime.”
- #8Critical⏰ Upon enactment
Applies to: Internet Service Providers and telecommunications companies.
“ISPs must retain traffic data and user logs for a minimum of 90 days.”
- #9Important⏰ Upon enactment
Applies to: Telecommunications providers.
“Telecommunications providers must ensure all SIM cards and accounts are linked to verified national IDs.”
- #10Important⏰ Upon enactment
Applies to: Service providers.
“The CMC is responsible for issuing licenses to service providers and ensuring their compliance with the law's data retention and monitoring requirements.”
- #11Important⏰ Upon enactment
Applies to: Service providers.
“Users must be notified of data collection practices, though this is often overridden by security mandates.”
Related Regulations
لائحة تنظيم المحتوى الرقمي في العراق
Iraq92% similar
مشروع قانون حماية البيانات الشخصية
Republic of Iraq91% similar
Decree‑Law No. 2022‑54 on Combating Offences Relating to Information and Communication Systems
Tunisia86% similar
Iraqi National Strategy for Artificial Intelligence (INSAIN)
Iraq86% similar
Electronic Signature and Transactions Law No. 78 of 2012
Iraq86% similar
© Regulations.AI — created on 06-Jan-2026 using Gemini 3 Flash Preview