Iraqis’ Data: Who Owns It, and Who Protects It? Privacy and Data Protection in the Digital State

A strategic analysis of Iraq’s data protection landscape, privacy risks, legislation, biometric data, children’s data, AI, and the roadmap toward stronger digital trust.

{"ar":"\u062d\u0645\u0627\u064a\u0629 \u0628\u064a\u0627\u0646\u0627\u062a \u0627\u0644\u0639\u0631\u0627\u0642\u064a\u064a\u0646 \u0648\u0627\u0644\u062e\u0635\u0648\u0635\u064a\u0629 \u0627\u0644\u0631\u0642\u0645\u064a\u0629 \u2013 \u0627\u0644\u0645\u0647\u0646\u062f\u0633\u0629 \u0633\u062c\u0649 \u0627\u0644\u0628\u064a\u0627\u062a\u064a","en":"Data Protection in Iraq \u2013 Eng. Saja Albayati on Digital Privacy and Data Governance"}
When Citizens’ Data Becomes Part of the State’s Infrastructure

Every electronic transaction completed by a citizen, every bank account opened, every card or digital wallet used, every fingerprint or facial image recorded, and every digital government service accessed leaves behind data.

In a digital state, these data points no longer remain isolated records.

They gradually become interconnected networks of information that can be used for identity verification, service delivery, fraud prevention, planning, analytics, and decision-making.

This is where the real issue begins.

The problem is not that governments and institutions hold data.

The challenge is that, as data becomes more interconnected and more valuable, it also becomes more sensitive.

A piece of information that appears harmless on its own may reveal a great deal when combined with other datasets.

A phone number linked to a name and address may be enough to enable a convincing social-engineering attack.

Location data collected over several months may reveal a person’s entire daily routine.

A health record may expose information that should be accessible only to specifically authorized individuals.

Biometric data is even more sensitive because the consequences of its exposure can be permanent.

For this reason, data should be treated as a national asset that requires governance, not merely as a growing digital repository that requires larger servers.

What Is Personal Data?

Personal data is any information relating to an identified individual, or information that can be used—on its own or in combination with other data—to identify that person.

In Iraq, this may include:

Names, addresses, national identification numbers, phone numbers, email addresses, photographs, bank-account information, payment histories, health records, education records, employee data, IP addresses, device identifiers, location data, and usage records from applications and digital platforms.

Some categories require a higher level of protection, including:

Biometric data such as fingerprints and facial images.
Health data.
Financial data.
Children’s data.
Precise location data.
Data linked to national identity.
Information capable of revealing sensitive aspects of a person’s life.

These categories should not all be protected at the same level.

The greater the potential harm caused by misuse or exposure, the stronger the protection requirements should be.

Who Collects Iraqis’ Data?

Today, Iraqi citizens’ data is distributed across a large number of entities.

Government institutions collect information relating to identity, residence, public services, education, employment, pensions, and social welfare.

Banks and payment companies hold financial information and customer-verification data.

Telecommunications companies collect subscriber and network-usage data.

Hospitals and laboratories maintain health records.

Universities and schools hold student and employee information.

Companies, applications, and e-commerce platforms collect additional user data.

In many cases, the information does not remain with the organization that originally collected it. It may be transferred to:

A software company, hosting provider, data center, cloud-service provider, technical-support company, or another contracted third party.

For this reason, asking “Who owns the data?” is not enough.

The more relevant questions are:

Who is the data subject?

Who is the Data Controller, responsible for determining why and how the data is collected?

Who is the Data Processor, processing information on behalf of the original organization?

And what obligations apply to each party?

Data Protection Is Not Only About Preventing Cyberattacks

One of the most common misconceptions is to treat data protection as synonymous with cybersecurity.

Cybersecurity focuses on protecting systems, networks, and information against unauthorized access, disruption, destruction, or disclosure.

Privacy asks broader questions.

Should the organization have collected this information in the first place?

Was it collected for a legitimate and clearly defined purpose?

Was only the minimum necessary amount collected?

Can it later be used for a different purpose?

Does the citizen know with whom the data is shared?

How long will it be retained?

Can the institution demonstrate that it handled the information responsibly?

NIST itself explains that cybersecurity-risk management contributes to privacy-risk management, but it is not sufficient on its own because privacy harms may occur even without a technical security incident.

A system can therefore be extremely resistant to intrusion and still be poor from a privacy perspective if it collects excessive data or uses information in ways that are not transparent.

Where Does Iraq Stand Today?

Iraq is not starting from zero.

On the contrary, the expansion of digital government services, electronic systems, and digital payments in recent years has made the issue of data more important than ever.

The Iraqi government’s Ur Portal, for example, publishes a privacy policy that explains certain types of information collected during the use of the platform, including IP addresses, browsing-related data, and geolocation information, as well as the reasons for collection and use. This is an important step toward greater transparency.

The Central Bank of Iraq is also operating in an environment that is increasingly dependent on digital payments and financial services. It has issued cyber-resilience controls for the financial and banking sector, along with instructions and regulatory requirements relating to electronic banking websites and applications, payment services, digital onboarding, customer registration, wallets, and cards.

At the broader government level, activities by the Ministry of Planning in 2026 demonstrate growing attention to digital governance, cybersecurity, and the adaptation of artificial intelligence to public-service delivery, while emphasizing that digital trust requires integrated institutional governance and cybersecurity.

These are all positive indicators.

But they do not eliminate an important gap:

The use of data is developing faster than the legal and institutional framework governing it.

Where Does Iraq Stand Legislatively?

The Iraqi Constitution provides the starting point by recognizing privacy as a right.

However, a general constitutional right is different from a specialized law that defines the full data lifecycle, the rights of individuals, and the obligations of organizations that collect and process personal information.

As of September 2026, the official legislative sources reviewed do not indicate the existence of a comprehensive and enforceable Iraqi personal data protection law with the level of detail found in modern specialized data-protection legislation.

At the same time, Iraq is moving forward legislatively in the field of cybercrime.

On 6 July 2026, the Iraqi Council of Representatives completed the first reading of the proposed Information Technology Crimes Law. The Parliamentary Security and Defence Committee continued discussing the proposal during July, August, and September, and it remained under legislative development in preparation for a second reading.

It is essential here to distinguish between two different legal fields.

A Cybercrime Law addresses criminal acts and digital attacks.

A Personal Data Protection Law governs the lawful, everyday use of data inside ministries, banks, hospitals, companies, and applications.

There does not need to be a hacker or cyberattack for a privacy violation to occur. Privacy can be compromised simply because data was collected unnecessarily, used for an undisclosed purpose, or shared without adequate controls.

Iraq therefore needs both frameworks.

Digital Government: A Major Opportunity, but Also a Greater Responsibility

Digital government can fundamentally improve the citizen experience.

Instead of repeatedly submitting the same documents to multiple institutions, systems can verify information electronically.

Instead of maintaining duplicate records, duplication can be reduced.

Instead of relying on fragmented files, data can support planning and decision-making.

But data integration does not mean unrestricted access.

If a ministry needs to verify a specific piece of information, that does not automatically mean it requires access to a citizen’s complete record.

Two core principles become especially important here:

Data Minimization

and

Least Privilege

The first means that an institution should not collect more data than it genuinely requires.

The second means that a user or employee should not receive more access privileges than their role actually requires.

Government Data Governance Must Precede Database Integration

Before Iraq discusses fully interconnected national platforms, every government institution should have a clear understanding of the data it already holds.

Any major institution should be able to answer:

What data do we hold?

Where is it stored?

Who can access it?

How is it classified?

How long is it retained?

With whom is it shared?

And what risks are associated with it?

This is the essence of Data Governance.

Strong government data governance should include:

Data classification.
A designated owner for each dataset.
Clearly defined responsibilities.
Access management.
Access logs.
Separation of databases based on sensitivity.
Retention and deletion policies.
Data encryption.
Backup management.
Periodic review of employee access.
Vendor and contractor management.
Privacy Impact Assessments for high-risk projects.

Without these elements, “government integration” can turn from an advantage into a broad point of exposure.

Biometric Data: More Sensitive Than Passwords

Biometric data requires special treatment.

If a password is compromised, it can be changed.

A face or fingerprint cannot be changed so easily.

Any expansion in the use of fingerprints, facial recognition, or biometric authentication should therefore be subject to strict questions:

Is biometric data truly necessary?

Where is it stored?

Is the original image retained, or only a derived biometric template?

Is the data encrypted?

Who controls the encryption keys?

Is a copy held by an external company?

Could the data later be used for a different purpose?

And how long will it be retained?

The question should not be:

Can we use the technology?

It should be:

Do we need it, and can we guarantee that it will be used responsibly?

Banks and Digital Payments

Every expansion of the digital economy increases the value of financial data.

As electronic wallets, cards, and mobile banking applications become more widely used, protecting the full customer journey becomes critical.

Security does not begin and end with the bank’s server.

It begins with:

Customer registration.

Identity verification.

The mobile application.

APIs.

Cloud services.

The payment provider.

The data center.

And any third-party company capable of accessing customer information.

Cyber-resilience controls issued by the Central Bank of Iraq provide an important foundation for strengthening readiness in the financial sector. However, protecting citizens also requires ensuring that protection standards do not decline when information moves from a bank to a provider, a payment company, or an external system.

What Happens When Data Is Breached?

The term Data Breach does not only mean that an entire database has been published online.

A breach may involve:

Unauthorized employee access.

Copying files to a personal device.

Sending information to the wrong recipient.

Exposed backup files.

Compromise of an administrator account.

A leak through a service provider.

Or even printed information being viewed by an unauthorized person.

The resulting harm may include:

Financial fraud.

Identity theft.

Social engineering.

Extortion.

Account compromise.

Tracking.

Or targeted attacks based on exposed personal information.

The more datasets are combined, the more convincing and sophisticated such attacks can become.

Who Is Responsible When a Breach Occurs?

It is not enough for an organization to say that “a hacker attacked us.”

We must ask:

Did the organization implement appropriate controls?

Were its systems up to date?

Was the information encrypted?

Were access privileges properly managed?

Were security tests performed?

Did the institution retain data that it no longer needed?

How long did it take to detect the incident?

Was it contained?

Were affected individuals informed?

This is Accountability.

A responsible organization does not merely claim that its data is protected.

It can demonstrate it.

Iraq Needs a National Data Breach Notification System

One of the most important components of any future Iraqi framework should be a clear Data Breach Notification mechanism.

Rules should determine:

When an organization must report an incident to the regulatory authority.

Within what timeframe.

What information must be disclosed.

And when affected citizens themselves must be notified.

If a breach exposes an individual to fraud or identity theft, that person has a legitimate interest in knowing so they can take protective action.

Children’s Data Requires Stronger Protection

Children’s data protection should not be a minor paragraph within a general law.

Children cannot always fully understand the consequences of sharing their information.

Schools, educational platforms, games, applications, phones, and health services may collect significant amounts of data about them.

This makes children’s data particularly sensitive when used for:

Tracking.

Advertising.

Profiling.

Behavioral prediction.

Or training artificial intelligence systems.

For this reason, future Iraqi legislation should impose stronger rules for children’s data, with privacy protection treated as the default rather than an optional feature.

Iraqi Children and Artificial Intelligence

The issue will become more complex as AI tools become more widespread.

A child may enter into a chatbot:

Their name.

Their school.

Their location.

A family issue.

Health information.

Or a personal image.

Without understanding where that information may go.

Digital literacy in Iraq therefore needs to expand to include AI Literacy.

Children, students, and employees should understand:

What information can be entered into AI tools?

And what information should never be entered?

Government AI Needs Rules Before Expansion

Artificial intelligence can help governments with analysis, forecasting, pattern detection, and service improvement.

But when used with citizens’ data, it creates new questions.

Where did the training data come from?

Is the data accurate?

Does it contain bias?

Can the system make decisions that affect an individual?

Can the citizen challenge the decision?

Who reviews it?

And where does the information entered into the system go?

For this reason, Privacy Impact Assessments should become part of high-impact government projects.

Citizens’ Data Should Not Be Entered into Public AI Tools

This requires immediate institutional policy.

A government employee, banker, or company employee should not copy a document containing names, national identification numbers, health records, or financial information and paste it into a public AI tool for summarization.

This is not simply a matter of convenience.

It may become an invisible channel through which sensitive data leaves the institution.

Organizations therefore need:

An approved list of AI tools.

Rules defining what information may be entered.

Anonymization requirements where appropriate.

And clear agreements with AI service providers.

Hosting Outside Iraq: Avoiding Both Extremes

It would be wrong to say that all Iraqi data must remain inside Iraq.

It would also be wrong to say that location does not matter.

The answer depends on the type of data.

Some public information may not require strict localization controls.

Sovereign, sensitive, or critical information requires stronger safeguards.

The first requirement is therefore a National Data Classification Framework.

Only then can Iraq determine:

What data may be hosted outside the country?

Under what conditions?

Which law governs the provider?

Is the data encrypted?

Who controls the encryption keys?

Can the data be transferred to another provider?

Is there a national backup copy?

What happens if the service fails or the contractual relationship ends?

This is digital sovereignty in practical terms.

The Private Sector Is Not Outside the Responsibility Framework

Data protection is not only a government responsibility.

E-commerce companies.

Delivery services.

Telecommunications providers.

Private healthcare institutions.

Universities and schools.

Software companies.

Platforms and applications.

All of them process personal information.

Their customers should know:

What information the company collects.

Why it is collected.

How long it is retained.

Whether it is sold or shared.

And what happens if the customer requests a correction.

Technology Vendors Are Part of the Responsibility Chain

If a ministry contracts a company to build a digital system, the ministry’s responsibility does not end there.

If the vendor can access the data, it becomes part of the risk chain.

Technology contracts should therefore include:

Security and privacy requirements.

Hosting location.

Access rules.

Incident-notification requirements.

Subcontractor management.

Deletion of data when the contract ends.

Audit rights.

And requirements for returning or exporting the data.

What Can Iraq Learn from GDPR, OECD, NIST, and ISO?

Iraq does not need an Arabic copy of the GDPR.

It needs an Iraqi system that learns from global principles and adapts them to local realities.

Some of the most important principles include:

Lawfulness and transparency.

Purpose limitation.

Data minimization.

Retention limitation.

Data security.

Institutional accountability.

The OECD identifies eight foundational privacy principles, including collection limitation, data quality, purpose specification, use limitation, security safeguards, openness, individual participation, and accountability. It also treats privacy as an essential element in building trust in the digital economy.

The NIST Privacy Framework provides a voluntary tool for helping organizations manage privacy risks within broader enterprise-risk management.

ISO/IEC 27701:2025 provides requirements and guidance for establishing, implementing, maintaining, and continually improving a Privacy Information Management System (PIMS) for organizations that control or process personal information.

These frameworks are highly useful for Iraq.

But they are tools.

They do not replace national legislation.

What Should an Iraqi Data Protection Law Include?

If Iraq is to build a comprehensive data-protection law, it should not focus solely on penalties.

It should regulate the entire data lifecycle.

At a minimum, it should include:

Clear Definitions

Personal data.

Sensitive data.

Biometric data.

Data subject.

Data Controller.

Data Processor.

Lawful Bases for Processing

When may data be collected?

Should processing rely on consent?

A legal obligation?

Public-service delivery?

Or another legitimate basis within clearly defined limits?

Citizens’ Rights

The right to be informed.

The right of access.

The right to correction.

The right to object where applicable.

The right to restrict processing.

The right to deletion where permitted by law.

And protections in relation to high-impact automated decisions.

Institutional Obligations

Data minimization.

Encryption.

Records of processing activities.

Retention periods.

Breach notification.

Privacy Impact Assessments.

Vendor management.

Cross-Border Data Transfers

Data transfers outside Iraq should be neither absolutely prohibited nor completely unrestricted.

They should depend on the sensitivity of the information and the safeguards available.

Children

Children’s information requires special and more stringent rules.

Biometric Data

Biometric information should be subject to independent safeguards due to the difficulty of replacing it after exposure.

Penalties

Accountability requires clear and proportionate sanctions, together with rights of appeal and complaint.

Iraq Needs a Clear National Data Protection Authority

A law cannot enforce itself.

Iraq therefore needs a clearly defined institution responsible for personal data protection.

The model could take the form of an independent authority or another regulatory structure determined by lawmakers.

What matters is that the institution is capable of:

Issuing guidance.

Receiving complaints.

Investigating breaches.

Enforcing compliance.

Coordinating with sector regulators.

And promoting public awareness.

Its relationship with the National Cybersecurity Center, the Central Bank of Iraq, and other sector regulators should also be clearly defined.

Practical Recommendations for the Iraqi Government

The government does not need to wait for comprehensive legislation before improving data governance.

It can begin immediately by:

Developing a National Data Classification Framework.
Establishing minimum data-protection requirements across government institutions.
Requiring high-risk government projects to conduct Privacy Impact Assessments.
Creating clear records of data flows between institutions.
Reducing internal access privileges.
Applying Multi-Factor Authentication to sensitive systems.
Regulating institutional use of AI tools.
Establishing a national data-breach notification mechanism.
Training public-sector employees in data security and privacy.
Defining special requirements for biometric, health, and children’s data.
Including data-protection obligations in government contracts.
Making Privacy by Design part of government procurement and system-development standards.
Recommendations for the Private Sector

Iraqi companies can also begin strengthening trust immediately.

Key steps include:

Understanding what data they hold.
Deleting information they no longer need.
Minimizing data collection.
Writing understandable privacy policies.
Encrypting sensitive information.
Reducing employee privileges.
Training staff.
Assessing vendors.
Preparing breach-response plans.
Avoiding the use of public AI tools for customer information without proper safeguards.
Applying Privacy by Design to new applications and services.

These measures should not be viewed merely as costs.

They can become a competitive advantage.

Privacy by Design Should Become a National Culture

One of the most important transformations Iraq needs is to treat privacy as part of system design.

We should not build a system first and ask later:

How do we add privacy?

The questions should begin at the first project meeting:

What information do we genuinely need?

Can the service be delivered with less data?

Do we really need to retain it for five years?

Can the information be anonymized?

Who needs access?

What happens when the original purpose has ended?

This approach reduces risk from the beginning.

Where Will Iraq Be in the Coming Years?

The next phase will be fundamentally different from the previous one.

Iraq will move from:

Separate databases to interconnected datasets.

Documents to digital identity.

Standalone websites to integrated service platforms.

Human-only file review to systems that recommend decisions.

Manual analysis to artificial intelligence.

Traditional data centers to cloud and hybrid infrastructure.

This means that every decision made today about data will have long-term consequences.

The current period therefore represents an important window for establishing sound rules before systems become larger and more difficult to change.

Eng. Saja Albayati’s Vision

In my view, Iraq’s objective should not be limited to “protecting the database.”

That concept is too narrow for the scale of the challenge.

The country needs to move toward governing the entire data lifecycle.

Protection begins before the data is collected.

It continues during processing.

Then during sharing.

Then storage.

Then use in analytics and artificial intelligence.

And finally when the data is deleted or archived.

I believe any Iraqi national framework should be built around four interconnected pillars:

Legislation.

Institutional Governance.

Technical Security.

Citizens’ Rights.

If we focus only on security, we may create protected systems that still use data in non-transparent ways.

If we focus only on law, we may create rules that are not technically enforced.

If we focus only on technology, we may accelerate digitization without building trust.

When these elements work together, Iraq can become a more mature, sovereign, and trusted digital state.

Conclusion and Vision for the Next Phase

There are five messages that should guide the next phase.

First: Data has become part of national infrastructure, not merely an administrative record.

Second: Iraq needs a comprehensive personal data protection law, distinct in purpose from cybercrime legislation while remaining complementary to it.

Third: Iraq needs a clearly defined national body to oversee data protection and governance.

Fourth: The use of artificial intelligence in government institutions must be preceded by a clear framework for data governance, privacy, and accountability.

Fifth: Children’s data and biometric data should be legislative priorities, not secondary details.

Iraq needs data in order to build a more efficient digital state.

It needs integration in order to deliver better public services.

It needs artificial intelligence in order to remain competitive and relevant.

But all of these paths depend on one essential element:

Trust.

Digital trust is not built through slogans.

It is built when citizens know that their data is not collected without necessity, not shared without rules, not used without accountability, and not left without protection.

Eng. Saja Albayati
Cybersecurity and Digital Transformation Consultant

<!-- SAJA_INTERNAL_LINKS_DATA_PROTECTION_FINAL --><p><strong>Related topics:</strong> Cybersecurity in Iraq, digital sovereignty, digital economy, and digital literacy.</p>