Iraq
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.
If you collect data about people in Iraq — customers, users, employees — these are the rules you have to follow. Here is the short version.
The short version
Iraq has no general law protecting personal data and no privacy regulator. In most industries nothing stops data going abroad. The real limits sit inside licensed industries: satellite internet, telephone and internet companies, and banks. Those limits come from licence conditions and from banking secrecy. Industry regulators police them, not a privacy watchdog.
Data governance in Iraq
The eight things that decide how you handle data about people in Iraq. Same eight on every country page, so you can compare.
Who has to follow these rules
There is no general privacy law, so no privacy rule reaches a foreign company. Licensing reaches you instead. The Communications and Media Commission is Iraq's telecoms and media regulator. It expects anyone selling digital services to people in Iraq to get its approval first. In August 2026 it approved Apple as a trusted digital service provider, once Apple met its technical and legal requirements. No revenue or user-number threshold has been published.
- What you have to do here:
- Register or notify
The Commission works from a set of rules for digital platforms and services. The draft went out for public consultation in November and December 2024. By August 2026 the Commission was citing those rules as the basis for approving a foreign platform. There is a further part, a rule requiring smartphone applications to be registered in Iraq. It was still out for consultation in June 2026, so it is only a proposal. The Commission also polices the other direction. In August 2026 it warned publicly that nobody is an authorised agent for the satellite service Starlink in Iraq. It said people claiming otherwise face legal action.
Sources
- Official sourceCommunications and Media Commission of IraqApple approved as a trusted digital service provider in Iraq, 6 August 2026
cmc.iq
“استكمالها جميع المتطلبات والإجراءات المنصوص عليها في اللائحة الإطارية”
Link checked 18 August 2026
- Official sourceCommunications and Media Commission of IraqPublic consultation on the regulation for registering smart-device applications in Iraq, 21 June 2026
cmc.iq
Link checked 18 August 2026
Where the data is allowed to live
Yes, in general. We found no national rule stopping personal data from leaving Iraq, checked on 18 August 2026. The exceptions come industry by industry. Satellite internet providers must keep their ground stations in Iraq. They must not register subscribers or switch on receivers from outside the country. Banks may not hand over customer information to anyone, at home or abroad. The banking law lists a few narrow exceptions.
Here is each industry, checked 18 August 2026. BANKING: conditional. The banking law makes banks keep customer information secret, with listed exceptions. So using an overseas cloud is a secrecy question, not a transfer question. PAYMENTS: unknown. The central bank licenses payment companies and publishes lists of them. We could not open its library of instructions with an automated reader. So we can neither confirm nor rule out a storage rule. Treat this as the biggest open risk. SECURITIES: open. We read the securities regulator's rules on internet-based trading. They require reliable infrastructure and data security. They say nothing about where systems or data sit. INSURANCE: we found no rule. The insurance supervisor publishes no instructions online. TELECOM: conditional, through licence conditions and regulator orders rather than a published data law. SATELLITE BROADBAND: a copy has to stay in Iraq, because sign-up and ground infrastructure must be in Iraq. GOVERNMENT: unknown. The national e-services portal links to a privacy policy, but we could not read the text. HEALTH, EDUCATION, GAMING, MAPPING and DEFENCE: we found no rules about where data must sit on official sources.
Sources
- Official sourceCommunications and Media Commission of IraqRegulatory framework for licensing broadband services via non-geostationary satellite systems, sections 13.4.1, 13.4.2 and 13.4.5
cmc.iq
“teleport facilities are located within the territory of the Republic of Iraq”
Link checked 18 August 2026
- Official sourceIraq Securities CommissionRegulation No. 30 on trading securities over the internet — contains no requirement to keep systems or data in Iraq
uploads.isc.gov.iq
Link checked 18 August 2026
- Official sourceCentral Bank of IraqBanking Law No. 94 of 2004, articles 49 to 52 (banking secrecy and its exceptions)
cbi.iq
Link checked 18 August 2026
What to do: Check your own industry against the restricted list before you pick a hosting region.
Not fully verified — see “What we're not sure about” below.Sending data out of the country
There is nothing to sign and nobody to ask. Iraq has no approval process for sending data abroad. It has no government standard contract. It has no list of approved or banned destinations. So there is no list to check. The controls that do apply come from elsewhere. A bank's duty of secrecy. The record-keeping duties in the money-laundering law. And the conditions written into a telecoms or satellite licence.
- Ways to send data out:
- Nothing required · Explicit consent
There are no transfer rules, so the safeguards that matter are commercial and industry-specific. For a bank, the question is whether the customer consented, or whether one of the banking law's exceptions applies. Secrecy binds the bank whichever country the server is in. For money-laundering purposes, the financial intelligence unit may share information with foreign counterparts. The receiving body must keep it confidential. It may use it only for money laundering, terrorist financing and related offences. It needs permission from the Iraqi authority before passing it on. For a licensed communications or satellite operator, the licence and the regulator's orders are what bind you.
Sources
- Official sourceCentral Bank of IraqAnti-Money Laundering and Counter-Terrorism Financing Law No. 39 of 2015, articles 11, 29 and 53
cbi.iq
Link checked 18 August 2026
- Official sourceCentral Bank of IraqBanking Law No. 94 of 2004, articles 49 to 52
cbi.iq
Link checked 18 August 2026
The regulator, and whether it actually acts
Nobody enforces privacy. Iraq has no data protection authority. There is no office to complain to, no fines and no decisions about personal data. Industry regulators are a different story. The Communications and Media Commission is clearly active. In August 2026 it ended Korek Telecom's contract. It ordered that customer and staff records be protected. It also stopped prepaid top-up sales through agents across the Kurdistan region, because subscriptions were being registered in people's names without permission. The Central Bank of Iraq licenses banks and payment companies. The Iraq Securities Commission issues and updates market rules.
This difference matters when you size up your risk. No regulator will audit your privacy notice, your consent flows or your international transfers. No law creates those duties. But a regulator can suspend your sales channel, cancel your contract or refuse to approve your app. It did all three kinds of thing in 2026. A National Cybersecurity Centre also exists. It ran a national cyber exercise in January 2026, sponsored by the prime minister. We could not find its own website or any rules it publishes. So we cannot say that it supervises anyone.
Sources
- Official sourceCommunications and Media Commission of IraqCommission statements, August 2026: termination of Korek Telecom's contract under Order 65 of 2004, protection of subscriber and employee data, and suspension of agent top-up sales in the Kurdistan Region
cmc.iq
Link checked 18 August 2026
- Official sourceCommunications and Media Commission of IraqCyber Drill 2026 organised by the National Cybersecurity Centre under the Prime Minister's sponsorship
cmc.iq
“السيادة الرقمية ركيزة للأمن الوطني الشامل”
Link checked 18 August 2026
- Official sourceCentral Bank of IraqLicensed electronic payment service providers and collection companies
cbi.iq
Link checked 18 August 2026
How long you must keep it — and when to delete it
The minimum keeping times are much clearer than any duty to delete. Banks, money changers and other reporting businesses must keep customer records, documents and transaction papers for five years. The five years run from the end of the relationship or the closing of the account. Banks must also keep proper accounting records under the banking law. There is no general rule telling anyone when to delete personal data, because there is no general privacy law. If keeping and deleting ever pull against each other, keeping wins.
- What you have to do here:
- Keep data for a minimum period · Keep records of how you use data
The five-year duty sits in the money-laundering and terrorist-financing law. It applies to financial institutions, and to named non-financial businesses and professions. Tax and company-law keeping periods almost certainly exist in Iraq too. We could not open an official text stating them, so we list them as unconfirmed rather than state them. There is no published rule requiring these records to be stored inside Iraq. The duty is to have them and to produce them.
Sources
- Official sourceCentral Bank of IraqAnti-Money Laundering and Counter-Terrorism Financing Law No. 39 of 2015, article 11 (five-year record retention)
cbi.iq
Link checked 18 August 2026
- Official sourceCentral Bank of IraqBanking Law No. 94 of 2004, article 38 (records and accounts)
cbi.iq
Link checked 18 August 2026
What to do: Check the minimum keep-period before you delete anything.
Not fully verified — see “What we're not sure about” below.If something goes wrong
We found no general duty to report a data breach in Iraq, checked on 18 August 2026. There is no privacy regulator to report one to. So there is no national deadline in hours. A National Cybersecurity Centre exists and ran a national cyber exercise in January 2026. We could not find published reporting rules or deadlines from it. A licensed bank, payment company or telecoms operator answers to its own regulator, on that regulator's timetable.
- What you have to do here:
- Report cyber incidents
This is a real gap, not a light touch. There is no breach law, no regulator and no published deadlines. So after an incident your exposure is to your contracts, to your reputation and, if you are licensed, to your regulator. The communications regulator has shown it will act on misuse of subscriber records. That is the closest thing to an incident response you should plan for. Expect any future breach duty to arrive through licence conditions or a regulator circular rather than through a law. That is how the other digital rules have arrived.
Sources
- Official sourceCommunications and Media Commission of IraqCyber Drill 2026 — National Cybersecurity Centre conference, January 2026
cmc.iq
Link checked 18 August 2026
What catches people out
Four things catch people out. First, banking secrecy travels with the data. Putting Iraqi customer records in an overseas cloud can breach the banking law, even though no privacy law exists. Second, with no privacy rulebook, disputes get fought under licence conditions, secrecy duties and general law. That is far less predictable than a privacy code. Third, identity misuse in mobile sign-ups is a live regulator concern. The regulator shut a whole sales channel over it in August 2026. Fourth, the risk for a foreign digital business is approval, not privacy. The regulator publicly warns that people offering unlicensed services face legal action.
- What you have to do here:
- Extra vendor secrecy terms
- What it costs if you get it wrong:
- Loss of your licence
A fifth item to keep on the list. The Kurdistan Region runs its own institutions and its own digital transformation programme. The communications regulator's August 2026 order was aimed specifically at agents in the Kurdistan governorates. Assume regional practice can differ from Baghdad, and check locally. Also note this. No privacy law does not mean no criminal risk. It means the risk is scattered across many laws, and we could not verify all of them from official texts. That alone is a reason for caution.
Sources
- Official sourceCentral Bank of IraqBanking Law No. 94 of 2004, articles 49 to 52 — secrecy binds the bank regardless of where records are held
cbi.iq
Link checked 18 August 2026
- Official sourceCommunications and Media Commission of IraqCommission orders, 7 to 10 August 2026: unauthorised subscriptions registered in citizens' names, suspension of agent sales, and warning that no Starlink agent is authorised in Iraq
cmc.iq
Link checked 18 August 2026
What's changing next
Three things to watch in the next year. A draft rule published for consultation on 21 June 2026 would make every smartphone application offered in Iraq register. It is a proposal with no legal force today. Satellite internet licensing is being organised under rules the regulator says are approved. No provider has been licensed yet, Starlink included. The first licence will show how hard the local-infrastructure conditions really are. And Iraq still has no privacy law, so a first one could appear with little warning.
Changes the regulator can make alone matter more here than new laws. The communications regulator already holds the powers it needs. It can approve or refuse a foreign platform under its digital platform rules. It can add further parts to those rules. It can write conditions into licences. It can suspend a sales channel overnight. It can end an operator's contract. It did all of these between 2025 and August 2026 without any new law. The regulator also consulted on a cybersecurity rule in October 2024. It adopted rules for value-added services and for electronic games. Any of these can be extended to cover data handling without a public bill.
Sources
- Official sourceCommunications and Media Commission of IraqConsultation on the smart-device application registration regulation, annex 3 to the digital platforms framework, 21 June 2026
cmc.iq
Link checked 18 August 2026
- Official sourceCommunications and Media Commission of IraqPublic consultation on the satellite broadband licensing framework, 5 June 2025
cmc.iq
Link checked 18 August 2026
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries6 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Telecoms rules
Official name: اللائحة الإطارية للمنصات والخدمات الرقمية في جمهورية العراق (Framework Regulation for Digital Platforms and Services) · Directly binding regulation
The communications regulator's rulebook for digital platforms and services. It was consulted on in late 2024. In August 2026 it was used to approve Apple's services in Iraq. A further part covering smartphone application registration was still only a draft. It is partly in force: the approval process is real, but the published text is not complete.
Enforced by Communications and Media Commission of Iraq
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed
What you have to do
- Register or notifyApproval by the Commission as a recognised digital service provider before offering services in Iraq.
Sources
- Official sourceCommunications and Media Commission of IraqCommission approves Apple as a trusted digital service provider, 6 August 2026
cmc.iq
“ضمن إطار تنظيمي رسمي ينسجم مع القوانين واللوائح النافذة في جمهورية العراق”
Link checked 18 August 2026
- Official sourceCommunications and Media Commission of IraqLegal documents page, including Coalition Provisional Authority Order 65 of 2004 establishing the Commission
cmc.iq
Link checked 18 August 2026
Telecoms rules (Telecoms)
Official name: اللائحة التنظيمية الخاصة بترخيص خدمات الإنترنت عريضة النطاق عبر أنظمة الأقمار الصناعية غير الثابتة (NGSO) · Directly binding regulation
The strictest rule we found in Iraq about keeping things in the country. Satellite broadband providers must keep ground stations in Iraq. They must be registered as an Iraqi business. They must not sign up subscribers or switch on receivers from abroad. The regulator says the rules are approved, but no provider has been licensed yet. So this starts to matter with the first licence.
Enforced by Communications and Media Commission of Iraq
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed
What you have to do
- Keep the data in the countryGround stations must sit in Iraq. Subscribers may not be registered from outside Iraq, and receivers may not be switched on from outside Iraq. Traffic may have to route through Iraq's international gateways during a transition period.
- Register or notifyLicence required, plus proof of commercial registration showing the applicant is legally established in Iraq.
- Secure the dataSubscriber registration system must be linked to secure national infrastructure, and lawful interception must be supported.
Sources
- Official sourceCommunications and Media Commission of IraqRegulatory framework for licensing broadband via non-geostationary satellite systems, sections 10.4, 13.1.1, 13.4.1, 13.4.2, 13.4.5
cmc.iq
“registering subscriber information or activating receivers outside the Republic of Iraq”
Link checked 18 August 2026
- Official sourceCommunications and Media Commission of IraqPublic consultation announcement for the satellite broadband framework, 5 June 2025
cmc.iq
Link checked 18 August 2026
Banking rules
Official name: قانون المصارف رقم 94 لسنة 2004 (Banking Law No. 94 of 2004) · Law No. 94 of 2004, articles 38 and 49 to 52 · Act of parliament
What really limits moving bank customer data out of Iraq is secrecy, not a transfer rule. Banks must keep customer information confidential. They may disclose it only in the cases the law lists. Nothing says the data must stay in Iraq. But an overseas arrangement that exposes customer details can still breach the law.
Enforced by Central Bank of Iraq
How this country controls where data goes: No restriction · Accepted routes: Explicit consent, Legal claims
What you have to do
- Extra vendor secrecy termsA standard supplier contract is not enough. The bank's duty of secrecy follows the customer information to any service provider, in Iraq or abroad.
- Keep records of how you use dataBanks must keep accounting records and customer transaction documentation.
Sources
- Official sourceCentral Bank of IraqBanking Law No. 94 of 2004 — chapter on banking secrecy (articles 49 to 52) and records (article 38)
cbi.iq
Link checked 18 August 2026
Banking rules (Finance)
Official name: قانون مكافحة غسل الأموال وتمويل الإرهاب رقم 39 لسنة 2015 (Anti-Money Laundering and Counter-Terrorism Financing Law No. 39 of 2015) · Law No. 39 of 2015, articles 11, 29 and 53 · Act of parliament
The clearest minimum keeping time in Iraqi law. Banks, exchange houses and other reporting businesses keep five years of customer and transaction records. The law does not say where those records must be held. It does control how Iraq's financial intelligence unit shares information with other countries.
Enforced by Office of Combating Money Laundering and Terrorist Financing
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Keep data for a minimum period — 5 yearsRecords, documents and supporting papers kept for five years after the customer relationship ends or the account is closed.
- Keep records of how you use data
- Put a transfer safeguard in placeInformation that Iraq's financial intelligence unit shares with foreign counterparts stays confidential. It may be used only for money laundering, terrorist financing and related offences. It may not be passed on without permission from the Iraqi authority.
Sources
- Official sourceCentral Bank of IraqAnti-Money Laundering and Counter-Terrorism Financing Law No. 39 of 2015
cbi.iq
“تحتفظ المؤسسة المالية وأصحاب الأعمال والمهن غير المالية المحددة بالسجلات والوثائق والمستندات لمدة (5) خمس سنوات”
Link checked 18 August 2026
- Official sourceOffice of Combating Money Laundering and Terrorist FinancingIraq platform of the Office of Combating Money Laundering and Terrorist Financing
aml.iq
Link checked 18 August 2026
Internet and platform rules
Official name: الضوابط الخاصة بالتداول عبر الإنترنت رقم 30 (Regulation No. 30 on trading securities over the internet) · Directly binding regulation
A checked negative, which is worth as much as a rule. Iraq's securities regulator requires online brokers to run reliable, secure systems. Nothing in its internet-trading rules says where those systems or that data must be located. Securities firms have no duty to keep data in Iraq today.
Enforced by Iraq Securities Commission
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Secure the dataBroker systems must be suitable for uninterrupted internet trading and must protect client data.
Sources
- Official sourceIraq Securities CommissionRegulation No. 30 on trading securities over the internet, article 7
uploads.isc.gov.iq
“أن البنية التحتية للأنظمة لدى الوسيط ملائمة لإجراء عمليات التداول عبر الإنترنت بشكل سليم ودون انقطاع”
Link checked 18 August 2026
- Official sourceIraq Securities CommissionRegulations and rules index of the Iraq Securities Commission
isc.gov.iq
Link checked 18 August 2026
You must register with the regulator
Official name: اللائحة التنظيمية الخاصة بتسجيل تطبيقات الأجهزة الذكية في جمهورية العراق (Regulation on registering smart-device applications in Iraq) · Directly binding regulation
A draft rule published for a ten-day public consultation on 21 June 2026. It would make smartphone applications register before being offered in Iraq. It is a proposal with no legal force today. We could not download the draft text from the regulator's site.
Enforced by Communications and Media Commission of Iraq
What you have to do
- Register or notifyDraft only. Would require smartphone applications offered in Iraq to be registered with the Commission.
Sources
- Official sourceCommunications and Media Commission of IraqConsultation notice, annex 3 to the digital platforms and services framework, 21 June 2026
cmc.iq
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.
Whether the Central Bank of Iraq requires banking or payment data to be stored inside Iraq
This is the single biggest open question in this record. The central bank's library of instructions and controls is loaded by script, and returned no documents to an automated reader. Its site search covers only news. We could not find the 2014 electronic payment services regulation on any official Iraqi site. Treat payments as unknown, not as open. If you work in payments, check with the central bank first.
That Iraq has no comprehensive personal data protection law and no data protection authority
We found no such law or authority on any reachable Iraqi government site, checked on 18 August 2026. We could not confirm this either way. The official legislation database and the Council of Representatives site both refuse automated access. Check with an Iraqi lawyer before you rely on this.
Whether a personal data protection bill is currently before the Iraqi parliament
We could not confirm how far this has got. The parliament's website blocks automated access, and the state news agency blocks its search page. Check with the parliament before you rely on this.
The adopted text of the framework regulation for digital platforms and services
The regulator's site refers only to the November 2024 consultation draft, and its PDF link now returns an error. We know the rules are being applied, because the regulator cited them when approving Apple in August 2026. But we could not read the working text, including any conditions about data or hosting.
The final wording of the satellite broadband licensing framework
The clauses quoted here come from the June 2025 consultation draft published by the regulator. In June 2026 the regulator said licensing now runs under approved rules. That approved text is not published, so the final conditions may differ. Check with the regulator before you rely on this.
Any data rules for health, insurance, education, mapping, gaming or defence
We found no rules, checked 18 August 2026, and could not confirm this either way. The health ministry and interior ministry sites refuse automated access. The insurance supervisor's page under the finance ministry publishes no instructions at all. If you work in these industries, check before you rely on this.
Whether the National Cybersecurity Centre issues binding incident reporting rules
The centre is real. It ran a national cyber exercise in January 2026, sponsored by the prime minister. We could not find its own website or any rules it has published. So we cannot say what it requires, or who it requires it of.
Retention floors outside financial services, such as tax and company law periods
These almost certainly exist, but we could not open an official text stating the periods. Only the five-year money-laundering period and the banking law's record-keeping duty are backed by evidence here. Check with the tax authority before you rely on this.
Whether the Kurdistan Region applies separate data or hosting rules
The regional government's site shows a digital transformation programme and a terms page. We could not read any data law or hosting policy. The federal communications regulator does act inside the region, as its August 2026 order on agent sales shows.
Freshness and refresh
Freshness
Checked about 2 months ago, on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.