Compare countries
Two or three countries, side by side, one row per question. Pick up to 3.
IraqChecked 18 August 2026
Depends on your industryWork: MediumEnforcement: Dormant
- In one paragraph
- Iraq has no general law protecting personal data and no privacy regulator. In most industries nothing stops data going abroad. The real walls sit inside licensed industries: satellite internet, telephone and internet companies, and banks. Those walls come from licence conditions and from banking secrecy, and they are policed by industry regulators, not by a privacy watchdog.
- The catch
- The relaxed national picture stops the moment you touch a licensed industry. Satellite broadband providers must put ground stations in Iraq and must not sign up subscribers from outside the country. Banks are bound by a customer secrecy duty that follows the data wherever it is stored. Anyone selling a digital service into Iraq is expected to be approved by the communications regulator first, and that regulator cancelled a mobile operator's contract in August 2026.
- Does this apply to me?
- There is no general privacy law, so no privacy rule reaches a foreign company. What reaches you instead is licensing. The Communications and Media Commission, Iraq's telecoms and media regulator, expects anyone selling digital services to people in Iraq to be approved by it first. In August 2026 it approved Apple as a trusted digital service provider once Apple met its technical and legal requirements. No revenue or user-number threshold has been published.Medium confidence
- Can the data leave the country?
- In general, yes. We found no national rule stopping personal data from leaving Iraq, checked on 18 August 2026. The exceptions are industry by industry. Satellite internet providers must keep their ground stations in Iraq and must not register subscribers or switch on receivers from outside the country. Banks may not hand over customer information to anyone, at home or abroad, outside the narrow exceptions in the banking law.Medium confidence
- What do I have to do to send it abroad?
- Nothing to sign and nobody to ask. Iraq has no transfer approval process, no government standard contract, and no list of approved or banned destinations. So there is no list to check, because no list exists. The controls that do apply come from somewhere else: a bank's duty of secrecy, the record-keeping duties in the money-laundering law, and the conditions written into a telecoms or satellite licence.Medium confidence
- Who enforces this — and are they actually working?
- Nobody, for privacy. Iraq has no data protection authority, so there is no office to complain to, no fines and no decisions about personal data. On that measure enforcement is dormant. Industry regulators are a different story. The Communications and Media Commission is plainly active: in August 2026 it ended Korek Telecom's contract, ordered that customer and staff records be protected, and stopped prepaid top-up sales through agents across the Kurdistan region because subscriptions were being registered in people's names without permission. The Central Bank of Iraq licenses banks and payment companies, and the Iraq Securities Commission issues and updates market rules.Medium confidence
- How long must I keep it, and when must I delete it?
- The floor is much clearer than the ceiling. Banks, money changers and other reporting businesses must keep customer records, documents and transaction papers for five years after the relationship ends or the account closes. Banks must also keep proper accounting records under the banking law. In the other direction there is no general rule telling anyone when to delete personal data, because there is no general privacy law. If keeping and deleting ever pull against each other, keeping wins.Medium confidence
- What happens when something goes wrong?
- We found no general duty to report a data breach in Iraq, checked on 18 August 2026, and there is no privacy regulator to report one to. So there is no national clock in hours. A National Cybersecurity Centre exists and ran a national cyber exercise in January 2026, but we could not find published reporting rules or deadlines from it. In practice a licensed bank, payment company or telecoms operator answers to its own regulator, on that regulator's timetable.Low confidence
- What's the trap?
- Four things that catch people out. First, banking secrecy travels with the data: putting Iraqi customer records in an overseas cloud can breach the banking law even though no privacy law exists. Second, with no privacy rulebook, disputes get fought under licence conditions, secrecy duties and general law, which is far less predictable than a privacy code. Third, identity misuse in mobile sign-ups is a live regulator concern, and the regulator shut a whole sales channel over it in August 2026. Fourth, the exposure for a foreign digital business is approval, not privacy: the regulator publicly warns that people offering unlicensed services face legal action.Medium confidence
- What's about to change?
- Three things to watch in the next year. A draft rule published for consultation on 21 June 2026 would require every smartphone application offered in Iraq to be registered; it is a proposal with no legal force today. Satellite internet licensing is being organised under a framework the regulator says is approved, and no provider has been licensed yet, Starlink included, so the first licence will show how hard the local-infrastructure conditions really are. And Iraq still has no privacy law, so a first one could appear with little warning.Medium confidence
- Hardest industry wall
- Telecoms — اللائحة التنظيمية الخاصة بترخيص خدمات الإنترنت عريضة النطاق عبر أنظمة الأقمار الصناعية غير الثابتة (NGSO)
AlgeriaChecked 18 August 2026
Yes, with paperworkWork: HighEnforcement: Waking up
- In one paragraph
- Data can leave Algeria, but not freely. Every transfer abroad needs the national data protection authority's permission unless a listed exception applies, and breaking that rule is a crime carrying prison. Since July 2025 every organisation must have a data protection officer, a processing register and an automatic log of every operation. The regulator is staffed but has issued no known decisions.
- The catch
- The national rule is already strict, and three areas are stricter still. Online shops must run their site on servers inside Algeria under a .com.dz address. Electronic trust services, such as digital signatures and electronic identity, must host all the data they collect inside Algeria. Public bodies must exchange data only over a state-run network that is deliberately kept separate from the internet. Banking, insurance and securities have no storage rule that we could find, but the central bank's own website could not be reached, so treat that as unchecked rather than settled.
- Does this apply to me?
- Yes, it can reach a company with no office in Algeria, but the trigger is equipment, not customers. You are covered if you are set up in Algeria, or if you use any means of processing located in Algeria, such as servers or devices. In that second case you must tell the regulator the name of a representative based in Algeria, and that person takes on your rights and duties. There is no size or revenue threshold to fall below.High confidence
- Can the data leave the country?
- Yes, with permission or a listed excuse. The starting rule is that you may only send personal data to another country if the national data protection authority allows it and that country protects privacy well enough. There is a short list of exceptions that most businesses will rely on instead, such as the person's express consent or a transfer that is needed to carry out their contract. Two things are banned outright: transfers that could harm public safety or the state's vital interests, and any processing of sensitive data such as health, religion, politics or trade union membership unless a narrow exception applies.High confidence
- What do I have to do to send it abroad?
- The model is case by case. Before data goes abroad you need the national data protection authority to authorise it, and the destination country must protect privacy well enough in the authority's judgement. There is no published list of approved countries and no official standard contract you can sign instead. In practice most companies rely on the written exceptions: the person's express consent, a transfer needed for their contract, a court claim, saving someone's life, an important public interest, an international mutual legal assistance request, medical care, or a treaty Algeria has signed.High confidence
- Who enforces this — and are they actually working?
- The national data protection authority, and it does exist in real life. Fifteen members, including a president, were appointed by presidential decree on 18 May 2022 for five years, a new president was appointed in October 2023, and the authority has its own staff, pay scales, an executive secretariat, an official bulletin and internal committees. Its president was still signing published decisions in August 2025. What is missing is enforcement: in four years the official gazette shows only housekeeping texts from the authority, and no fine, order or filing procedure. Treat it as awake but not yet biting.High confidence
- How long must I keep it, and when must I delete it?
- There is a floor and a ceiling, and the floor is the one people miss. Accounting books and the paperwork behind them must be kept for ten years after the end of each financial year. Telephone and internet providers must keep the data that identifies users and their connections for one year. Online sellers must keep records of every transaction and send them to the national trade register centre. The ceiling is that personal data must not be kept in a form that identifies people for longer than the purpose needs, and keeping it too long is a crime.High confidence
- What happens when something goes wrong?
- There is no seventy-two hour clock here, and the five-day deadline people quote is not for ordinary businesses. If you provide a service over a public electronic communications network and data is destroyed, lost, altered, disclosed or accessed without permission, you must warn the authority and the affected person straight away, with no fixed number of hours. Failing to do that is a crime punishable by one to three years in prison. The five-day deadline added in July 2025 applies to police, prosecutors, courts and prison services, not to a normal company.High confidence
- What's the trap?
- Five things that cost people their weekend. One: this is a criminal regime. Sending data abroad in breach of the rule is punished by one to five years in prison and a fine of up to one million dinars, roughly seven thousand seven hundred US dollars, and prison can attach to individuals. Two: since 24 July 2025 every organisation must appoint a data protection officer, keep a written register of processing and keep an automatic log recording every collection, consultation, disclosure and deletion, with no exemption for small companies. Three: sensitive data is banned by default, and consent must be express, so silence or a pre-ticked box is worth nothing. Four: anything to do with national defence and security now sits completely outside the law, so there is no privacy protection to point to there. Five: a 2021 ordinance makes it a crime to disclose classified administrative documents, it reaches acts committed outside Algeria against the Algerian state, and it can force any person to hand over stored data.High confidence
- What's about to change?
- Three things to watch in the next twelve months. The five-year terms of the data protection authority's members, appointed on 18 May 2022, run out in May 2027, so appointments are due. The regional inspection and audit units created for the authority in July 2025 still need an implementing regulation before inspectors can appear at your door. And the rules that switch on the new government data framework, two reference documents on classifying data and cataloguing data sources, can be published by a single decision of the High Commission for Digitalisation, at which point every public body and every company running a public service must classify and catalogue its data.High confidence
- Hardest industry wall
- Telecoms — Loi n° 26-02 fixant les regles generales relatives aux services de confiance pour les transactions electroniques et a l'identification electronique
- E-commerce — Loi n° 18-05 relative au commerce electronique
- Government — Decret presidentiel n° 25-320 portant mise en place d'un dispositif national de gouvernance des donnees