On August 24, 2026, Iraq's Council of Representatives Security and Defense Committee, chaired by MP Dr. Khaled al-Obaidi, discussed the draft Combating Information Technology Crimes Law in a formal committee session. The committee examined the proposal's main substance and how offences committed through modern technical means would be framed, and it decided to host the competent technical, legal and security authorities in upcoming meetings before any text is finalised. That procedural step does not enact obligations yet, but it moves a long-tracked cybercrime statute closer to a committee-ready draft.
Iraq still has no comprehensive cybercrime or personal-data-protection statute. Digital platforms and telecom operators already face the Communications and Media Commission (CMC) Framework Regulations for Digital Platforms and Services (in force from February 17, 2025). A parliamentary cybercrime law would sit beside that CMC layer and create criminal exposure that the framework alone does not.
What did the Security and Defense Committee actually decide on August 24?
According to the official Media Department release of August 24, 2026, the committee treated the cybercrime proposal in a separate track from its Traffic Law No. 8 of 2019 amendment discussion with the General Traffic Directorate. On the cybercrime file, members reviewed the main contents of the draft Combating Information Technology Crimes Law and the regulatory issues around offences carried out with modern technologies.
The operative decision is process, not substance: the committee stressed that concerned specialist bodies must be brought into the debate, that their technical, legal and security comments must be heard, and that those bodies will be hosted in forthcoming meetings so the articles can be matured into an integrated legislative text. No article text, penalty schedule or entry-into-force date was published from this sitting.
Who is exposed if this draft becomes Iraqi law?
Every digital platform, ISP, mobile operator and fintech serving users in Iraq is in scope of the compliance risk once a cybercrime Qanun is enacted and published in Al-Waqai' al-Iraqiya. Local carriers such as Asiacell, Zain Iraq and Korek, plus foreign platforms and AI or social services that process Iraqi user traffic, would need content-moderation, user-data handling and incident-response playbooks aligned to the final criminal definitions.
Public tracking of the bill (including the 32-article Informatics Crimes draft returned to the parliamentary agenda in July 2026) has flagged broad offence categories: privacy violations, publication of false information that undermines confidence in the financial system (with a reported 35 million IQD fine in earlier drafts), and content treated as harming public order or state interests, with maximum penalties reported up to life imprisonment. Those figures are not reconfirmed in the August 24 release; treat them as the live draft risk envelope until the committee publishes a consolidated text.
The CMC platform framework already imposes service and content duties. The cybercrime law would add personal and corporate criminal liability for online conduct, which is a different enforcement channel from CMC administrative measures.
| Stage | Status as of August 24, 2026 | What compliance teams should watch |
|---|---|---|
| Committee discussion | Underway (Security and Defense Committee) | Expert-hosting calendar; any leaked consolidated draft articles |
| First / second reading and vote | Not yet | Council of Representatives agenda and reading reports |
| Presidency signature and Gazette publication | Not yet | Al-Waqai' al-Iraqiya entry; stated entry-into-force date |
| CMC Framework Regulations (parallel) | In force since February 17, 2025 | Existing platform duties remain binding today |
What should compliance teams do now, and by when?
There is no new statutory deadline from August 24. The immediate work is readiness, not a filing clock. Map which of your Iraqi-facing products would fall under the offence categories already associated with the Informatics Crimes draft, and assign an owner for each: content moderation, trust and safety, legal, and security operations.
Ask local counsel or government-affairs contacts to flag the next Security and Defense Committee expert session and any circulated article set. Continuously recalibrate against the CMC framework so that when the Qanun lands you are not inventing a second control stack from scratch. Continuous, per-jurisdiction real-time monitoring surfaces this kind of parliamentary movement the moment the Council of Representatives publishes it.
Do not wait for Gazette publication to start gap analysis: Iraq's legislative path after committee work still requires readings, adoption, Presidency signature and Gazette publication before entry into force, and that window is when implementation programmes usually fall behind.
Take advantage of this real-time watch
Next steps for counsel and compliance leads: confirm whether your organisation serves Iraqi users or hosts Iraqi traffic; obtain the latest circulating draft once the committee's expert round completes; brief trust-and-safety and security teams on the difference between CMC administrative duties and future criminal exposure; and keep Obsidian monitoring on the Council of Representatives and CMC channels so enactment does not arrive as a surprise.


