Iraq
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked yesterday.
The answer
Iraq has no general law protecting personal data and no privacy regulator. In most industries nothing stops data going abroad. The real walls sit inside licensed industries: satellite internet, telephone and internet companies, and banks. Those walls come from licence conditions and from banking secrecy, and they are policed by industry regulators, not by a privacy watchdog.
Data governance in Iraq
The eight things that decide how you handle data about people in Iraq. Same eight on every country page, so you can compare.
Who has to follow these rules
There is no general privacy law, so no privacy rule reaches a foreign company. What reaches you instead is licensing. The Communications and Media Commission, Iraq's telecoms and media regulator, expects anyone selling digital services to people in Iraq to be approved by it first. In August 2026 it approved Apple as a trusted digital service provider once Apple met its technical and legal requirements. No revenue or user-number threshold has been published.
The Commission works from a framework regulation for digital platforms and services. The draft went out for public consultation in November and December 2024, and by August 2026 the Commission was citing that framework as the basis for approving a foreign platform. A further annex, a regulation requiring smartphone applications to be registered in Iraq, was still out for consultation in June 2026 and is therefore only a proposal. The Commission also polices the other direction: in August 2026 it warned publicly that nobody is an authorised agent for the satellite service Starlink in Iraq and that people claiming otherwise face legal action.
Sources
- Official sourceCommunications and Media Commission of IraqApple approved as a trusted digital service provider in Iraq, 6 August 2026
cmc.iq
“استكمالها جميع المتطلبات والإجراءات المنصوص عليها في اللائحة الإطارية”
Link checked 18 August 2026
- Official sourceCommunications and Media Commission of IraqPublic consultation on the regulation for registering smart-device applications in Iraq, 21 June 2026
cmc.iq
Link checked 18 August 2026
Where the data is allowed to live
In general, yes. We found no national rule stopping personal data from leaving Iraq, checked on 18 August 2026. The exceptions are industry by industry. Satellite internet providers must keep their ground stations in Iraq and must not register subscribers or switch on receivers from outside the country. Banks may not hand over customer information to anyone, at home or abroad, outside the narrow exceptions in the banking law.
Sector by sector, checked 18 August 2026. BANKING: conditional. The banking law imposes customer secrecy with listed exceptions, so an offshore cloud arrangement is a secrecy question rather than a transfer question. PAYMENTS: unknown. The central bank licenses payment companies and publishes lists of them, but its instructions library could not be opened by an automated reader, so we cannot confirm or deny a storage rule; treat this as the biggest open risk. SECURITIES: open. We read the securities regulator's rules on internet-based trading and they require reliable infrastructure and data security but say nothing about where systems or data sit. INSURANCE: no rule found; the insurance supervisor publishes no instructions online. TELECOM: conditional, through licence conditions and regulator orders rather than a published data law. SATELLITE BROADBAND: a copy must stay, in effect, because sign-up and ground infrastructure must be in Iraq. GOVERNMENT: unknown; the national e-services portal publishes a privacy policy link but the text could not be read. HEALTH, EDUCATION, GAMING, MAPPING and DEFENCE: no data location rules found on official sources.
Sources
- Official sourceCommunications and Media Commission of IraqRegulatory framework for licensing broadband services via non-geostationary satellite systems, sections 13.4.1, 13.4.2 and 13.4.5
cmc.iq
“teleport facilities are located within the territory of the Republic of Iraq”
Link checked 18 August 2026
- Official sourceIraq Securities CommissionRegulation No. 30 on trading securities over the internet — contains no requirement to keep systems or data in Iraq
uploads.isc.gov.iq
Link checked 18 August 2026
- Official sourceCentral Bank of IraqBanking Law No. 94 of 2004, articles 49 to 52 (banking secrecy and its exceptions)
cbi.iq
Link checked 18 August 2026
Sending data out of the country
Nothing to sign and nobody to ask. Iraq has no transfer approval process, no government standard contract, and no list of approved or banned destinations. So there is no list to check, because no list exists. The controls that do apply come from somewhere else: a bank's duty of secrecy, the record-keeping duties in the money-laundering law, and the conditions written into a telecoms or satellite licence.
Because there is no transfer regime, the practical safeguards are commercial and sectoral. For a bank, the question is whether the customer consented or whether one of the banking law's exceptions applies, since secrecy binds the bank no matter which country the server is in. For money-laundering purposes, the financial intelligence unit may share information with foreign counterparts, but the receiving body must keep it confidential, may use it only for money laundering, terrorist financing and related offences, and needs the originating authority's permission before passing it on. For a licensed communications or satellite operator, the licence and the regulator's orders are the binding instrument.
Sources
- Official sourceCentral Bank of IraqAnti-Money Laundering and Counter-Terrorism Financing Law No. 39 of 2015, articles 11, 29 and 53
cbi.iq
Link checked 18 August 2026
- Official sourceCentral Bank of IraqBanking Law No. 94 of 2004, articles 49 to 52
cbi.iq
Link checked 18 August 2026
The regulator, and whether it actually acts
Nobody, for privacy. Iraq has no data protection authority, so there is no office to complain to, no fines and no decisions about personal data. On that measure enforcement is dormant. Industry regulators are a different story. The Communications and Media Commission is plainly active: in August 2026 it ended Korek Telecom's contract, ordered that customer and staff records be protected, and stopped prepaid top-up sales through agents across the Kurdistan region because subscriptions were being registered in people's names without permission. The Central Bank of Iraq licenses banks and payment companies, and the Iraq Securities Commission issues and updates market rules.
The distinction matters when you are sizing risk. There is no regulator that will audit your privacy notice, your consent flows or your international transfers, because no law creates those duties. There is a regulator that can suspend your sales channel, cancel your contract or refuse to approve your app, and it did all three kinds of thing in 2026. A National Cybersecurity Centre also exists and ran a national cyber exercise in January 2026 with the prime minister's sponsorship, but we could not find its own website or any published rules it issues, so we cannot say it supervises anyone.
Sources
- Official sourceCommunications and Media Commission of IraqCommission statements, August 2026: termination of Korek Telecom's contract under Order 65 of 2004, protection of subscriber and employee data, and suspension of agent top-up sales in the Kurdistan Region
cmc.iq
Link checked 18 August 2026
- Official sourceCommunications and Media Commission of IraqCyber Drill 2026 organised by the National Cybersecurity Centre under the Prime Minister's sponsorship
cmc.iq
“السيادة الرقمية ركيزة للأمن الوطني الشامل”
Link checked 18 August 2026
- Official sourceCentral Bank of IraqLicensed electronic payment service providers and collection companies
cbi.iq
Link checked 18 August 2026
How long you must keep it — and when to delete it
The floor is much clearer than the ceiling. Banks, money changers and other reporting businesses must keep customer records, documents and transaction papers for five years after the relationship ends or the account closes. Banks must also keep proper accounting records under the banking law. In the other direction there is no general rule telling anyone when to delete personal data, because there is no general privacy law. If keeping and deleting ever pull against each other, keeping wins.
The five-year duty sits in the money-laundering and terrorist-financing law and applies to financial institutions and to designated non-financial businesses and professions. Tax and company-law retention periods almost certainly exist in Iraq as well, but we could not open an official text stating them, so they are listed as unconfirmed rather than asserted. There is no published rule requiring these records to be stored inside Iraq; the duty is to have them and produce them.
Sources
- Official sourceCentral Bank of IraqAnti-Money Laundering and Counter-Terrorism Financing Law No. 39 of 2015, article 11 (five-year record retention)
cbi.iq
Link checked 18 August 2026
- Official sourceCentral Bank of IraqBanking Law No. 94 of 2004, article 38 (records and accounts)
cbi.iq
Link checked 18 August 2026
If something goes wrong
We found no general duty to report a data breach in Iraq, checked on 18 August 2026, and there is no privacy regulator to report one to. So there is no national clock in hours. A National Cybersecurity Centre exists and ran a national cyber exercise in January 2026, but we could not find published reporting rules or deadlines from it. In practice a licensed bank, payment company or telecoms operator answers to its own regulator, on that regulator's timetable.
This is a genuine gap rather than a light-touch regime: with no breach law, no regulator and no published deadlines, the exposure after an incident is contractual, reputational and, for licensed firms, supervisory. The communications regulator has shown it will act on the misuse of subscriber records, which is the closest thing to an incident response you should plan for. Expect any future breach duty to arrive through licence conditions or a regulator circular rather than through a statute, because that is how the other digital rules have arrived.
Sources
- Official sourceCommunications and Media Commission of IraqCyber Drill 2026 — National Cybersecurity Centre conference, January 2026
cmc.iq
Link checked 18 August 2026
What catches people out
Four things that catch people out. First, banking secrecy travels with the data: putting Iraqi customer records in an overseas cloud can breach the banking law even though no privacy law exists. Second, with no privacy rulebook, disputes get fought under licence conditions, secrecy duties and general law, which is far less predictable than a privacy code. Third, identity misuse in mobile sign-ups is a live regulator concern, and the regulator shut a whole sales channel over it in August 2026. Fourth, the exposure for a foreign digital business is approval, not privacy: the regulator publicly warns that people offering unlicensed services face legal action.
A fifth item to keep on the list: the Kurdistan Region runs its own institutions and its own digital transformation programme, and the communications regulator's August 2026 order was aimed specifically at agents in the Kurdistan governorates. Assume regional practice can differ from Baghdad and check locally. Note also that the absence of a privacy law does not mean the absence of criminal exposure; it means the exposure is scattered across instruments we could not all verify from official texts, which is itself a reason for caution.
Sources
- Official sourceCentral Bank of IraqBanking Law No. 94 of 2004, articles 49 to 52 — secrecy binds the bank regardless of where records are held
cbi.iq
Link checked 18 August 2026
- Official sourceCommunications and Media Commission of IraqCommission orders, 7 to 10 August 2026: unauthorised subscriptions registered in citizens' names, suspension of agent sales, and warning that no Starlink agent is authorised in Iraq
cmc.iq
Link checked 18 August 2026
What's changing next
Three things to watch in the next year. A draft rule published for consultation on 21 June 2026 would require every smartphone application offered in Iraq to be registered; it is a proposal with no legal force today. Satellite internet licensing is being organised under a framework the regulator says is approved, and no provider has been licensed yet, Starlink included, so the first licence will show how hard the local-infrastructure conditions really are. And Iraq still has no privacy law, so a first one could appear with little warning.
Dormant switches matter more here than pending legislation, because the communications regulator already holds the powers it needs. It can approve or refuse a foreign platform under its framework regulation, add annexes to that framework, write conditions into licences, suspend a sales channel overnight, and terminate an operator's contract, all of which it did between 2025 and August 2026 without new legislation. The regulator also consulted on a cybersecurity regulation in October 2024 and adopted regulations for value-added services and for electronic games; any of these can be extended to cover data handling without a public bill.
Sources
- Official sourceCommunications and Media Commission of IraqConsultation on the smart-device application registration regulation, annex 3 to the digital platforms framework, 21 June 2026
cmc.iq
Link checked 18 August 2026
- Official sourceCommunications and Media Commission of IraqPublic consultation on the satellite broadband licensing framework, 5 June 2025
cmc.iq
Link checked 18 August 2026
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries6 rules
If your product does one of these things, read this group first — industry rules beat the general position.
اللائحة الإطارية للمنصات والخدمات الرقمية في جمهورية العراق (Framework Regulation for Digital Platforms and Services)
Directly binding regulation
The communications regulator's rulebook for digital platforms and services. It was consulted on in late 2024 and used in August 2026 to approve Apple's services in Iraq, while a further annex covering smartphone application registration was still only a draft. Partly in force: the approval process is real, the published text is not complete.
Enforced by Communications and Media Commission of Iraq
Transfer model: Approval each time · Accepted routes: Government sign-off needed
What it makes you do
- Register or notifyApproval by the Commission as a recognised digital service provider before offering services in Iraq.
Sources
- Official sourceCommunications and Media Commission of IraqCommission approves Apple as a trusted digital service provider, 6 August 2026
cmc.iq
“ضمن إطار تنظيمي رسمي ينسجم مع القوانين واللوائح النافذة في جمهورية العراق”
Link checked 18 August 2026
- Official sourceCommunications and Media Commission of IraqLegal documents page, including Coalition Provisional Authority Order 65 of 2004 establishing the Commission
cmc.iq
Link checked 18 August 2026
اللائحة التنظيمية الخاصة بترخيص خدمات الإنترنت عريضة النطاق عبر أنظمة الأقمار الصناعية غير الثابتة (NGSO)
Directly binding regulation
The hardest localisation rule we found in Iraq. Satellite broadband providers must keep ground stations in the country, must be registered as an Iraqi business, and must not sign up subscribers or switch on receivers from abroad. The regulator says the framework is approved but no provider has been licensed yet, so it bites on the first licence.
Enforced by Communications and Media Commission of Iraq
Transfer model: Approval each time · Accepted routes: Government sign-off needed
What it makes you do
- Keep the data in the countryGround stations must sit in Iraq; subscribers may not be registered and receivers may not be activated from outside Iraq; traffic may be required to route through Iraq's international gateways during a transition period.
- Register or notifyLicence required, plus proof of commercial registration showing the applicant is legally established in Iraq.
- Secure the dataSubscriber registration system must be linked to secure national infrastructure, and lawful interception must be supported.
Sources
- Official sourceCommunications and Media Commission of IraqRegulatory framework for licensing broadband via non-geostationary satellite systems, sections 10.4, 13.1.1, 13.4.1, 13.4.2, 13.4.5
cmc.iq
“registering subscriber information or activating receivers outside the Republic of Iraq”
Link checked 18 August 2026
- Official sourceCommunications and Media Commission of IraqPublic consultation announcement for the satellite broadband framework, 5 June 2025
cmc.iq
Link checked 18 August 2026
قانون المصارف رقم 94 لسنة 2004 (Banking Law No. 94 of 2004)
Act of parliament · Law No. 94 of 2004, articles 38 and 49 to 52
Iraq's real constraint on moving bank customer data is secrecy, not a transfer rule. Banks must keep customer information confidential and may disclose it only in the cases the law lists. Nothing says the data must stay in Iraq, but an overseas arrangement that exposes customer details can still breach the law.
Enforced by Central Bank of Iraq
Transfer model: No restriction · Accepted routes: Explicit consent, Legal claims
What it makes you do
- Extra vendor secrecy termsA standard supplier contract is not enough: the bank's secrecy duty follows the customer information to any service provider, in Iraq or abroad.
- Keep records of processingBanks must keep accounting records and customer transaction documentation.
Sources
- Official sourceCentral Bank of IraqBanking Law No. 94 of 2004 — chapter on banking secrecy (articles 49 to 52) and records (article 38)
cbi.iq
Link checked 18 August 2026
قانون مكافحة غسل الأموال وتمويل الإرهاب رقم 39 لسنة 2015 (Anti-Money Laundering and Counter-Terrorism Financing Law No. 39 of 2015)
Act of parliament · Law No. 39 of 2015, articles 11, 29 and 53
The clearest retention floor in Iraqi law: five years of customer and transaction records for banks, exchange houses and other reporting businesses. The law does not say where those records must be held, but it does control how Iraq's financial intelligence unit shares information with other countries.
Enforced by Office of Combating Money Laundering and Terrorist Financing
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Keep data for a minimum period — 5 yearsRecords, documents and supporting papers kept for five years after the customer relationship ends or the account is closed.
- Keep records of processing
- Put a transfer safeguard in placeInformation shared by Iraq's financial intelligence unit with foreign counterparts stays confidential, may be used only for money laundering, terrorist financing and related offences, and may not be passed on without the originating authority's permission.
Sources
- Official sourceCentral Bank of IraqAnti-Money Laundering and Counter-Terrorism Financing Law No. 39 of 2015
cbi.iq
“تحتفظ المؤسسة المالية وأصحاب الأعمال والمهن غير المالية المحددة بالسجلات والوثائق والمستندات لمدة (5) خمس سنوات”
Link checked 18 August 2026
- Official sourceOffice of Combating Money Laundering and Terrorist FinancingIraq platform of the Office of Combating Money Laundering and Terrorist Financing
aml.iq
Link checked 18 August 2026
الضوابط الخاصة بالتداول عبر الإنترنت رقم 30 (Regulation No. 30 on trading securities over the internet)
Directly binding regulation
A checked negative, which is worth as much as a wall. Iraq's securities regulator requires online brokers to run reliable, secure systems, but nothing in its internet-trading rules says where those systems or that data must be located. Securities firms have no localisation duty today.
Enforced by Iraq Securities Commission
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Secure the dataBroker systems must be suitable for uninterrupted internet trading and must protect client data.
Sources
- Official sourceIraq Securities CommissionRegulation No. 30 on trading securities over the internet, article 7
uploads.isc.gov.iq
“أن البنية التحتية للأنظمة لدى الوسيط ملائمة لإجراء عمليات التداول عبر الإنترنت بشكل سليم ودون انقطاع”
Link checked 18 August 2026
- Official sourceIraq Securities CommissionRegulations and rules index of the Iraq Securities Commission
isc.gov.iq
Link checked 18 August 2026
اللائحة التنظيمية الخاصة بتسجيل تطبيقات الأجهزة الذكية في جمهورية العراق (Regulation on registering smart-device applications in Iraq)
Directly binding regulation
A draft rule, published for a ten-day public consultation on 21 June 2026, that would make smartphone applications register before being offered in Iraq. It is a proposal with no legal force today, and the draft text itself could not be downloaded from the regulator's site.
Enforced by Communications and Media Commission of Iraq
What it makes you do
- Register or notifyDraft only. Would require smartphone applications offered in Iraq to be registered with the Commission.
Sources
- Official sourceCommunications and Media Commission of IraqConsultation notice, annex 3 to the digital platforms and services framework, 21 June 2026
cmc.iq
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.
Whether the Central Bank of Iraq requires banking or payment data to be stored inside Iraq
This is the single biggest open question in this record. The central bank's instructions and controls library is loaded by script and returned no documents to an automated reader, its site search indexes only news, and we could not locate the 2014 electronic payment services regulation on any official Iraqi domain. Treat payments as unknown, not as open.
That Iraq has no comprehensive personal data protection law and no data protection authority
This is a negative, checked on 18 August 2026. We found no such law or authority on any reachable Iraqi government site, but the official legislation database and the Council of Representatives site both refused automated access, so we cannot prove the negative.
Whether a personal data protection bill is currently before the Iraqi parliament
The parliament's website blocked automated access and the state news agency blocked its search page. No official statement of legislative progress could be read.
The adopted text of the framework regulation for digital platforms and services
Only the November 2024 consultation draft is referenced on the regulator's site, and its PDF link now returns an error. We know the framework is being applied because the regulator cited it when approving Apple in August 2026, but we could not read the operative wording, including any data or hosting conditions.
The final wording of the satellite broadband licensing framework
The clauses quoted here come from the June 2025 consultation draft published by the regulator. The regulator said in June 2026 that licensing now proceeds under approved regulations, but the adopted text is not published, so the final conditions may differ.
Any data rules for health, insurance, education, mapping, gaming or defence
No rules found, checked 18 August 2026. The health ministry and interior ministry sites refused automated access, and the insurance supervisor's page under the finance ministry publishes no instructions at all.
Whether the National Cybersecurity Centre issues binding incident reporting rules
The centre is real — it ran a national cyber exercise in January 2026 under the prime minister's sponsorship — but we could not find its own website or any published instrument, so we cannot say what it requires or of whom.
Retention floors outside financial services, such as tax and company law periods
Almost certainly exist, but we could not open an official text stating the periods. Only the five-year money-laundering period and the banking law's record-keeping duty are evidenced here.
Whether the Kurdistan Region applies separate data or hosting rules
The regional government's site shows a digital transformation programme and a terms page, but no data law or hosting policy could be read. The federal communications regulator does act inside the region, as its August 2026 order on agent sales shows.
60-day cadence. The communications regulator is issuing regulations and enforcement orders every few weeks without legislation, its digital platforms framework has unpublished annexes in progress, and the first satellite broadband licence has not yet been granted. Any of these can change the picture without a bill or a consultation.
Freshness and refresh
Freshness
Checked yesterday — on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.
Put this next to another country
Iraq versus
Compare