Access Alert | Introducing Iraq’s Draft Data Classification Policy

Access Alert | Introducing Iraq’s Draft Data Classification Policy

On 20 June 2022, Iraq’s regulator, the Communications and Media Commission (CMC), announced the public consultation on the Draft Data Classification Policy. The policy aims to create a secure environment for the storing of data, ensure confidentiality of sensitive information, regulate access to data, process data in proportion to data classification levels, and protect data from loss or leakage.

Scope of application

The policy applies to both public and private sector stakeholders. More specifically, the scope applies to data that is stored, processed, modified, or transferred through a computer or smart device, created, collected, or maintained for the purpose of business functions or providing public services.

Different levels of data classification

In Article 1, the policy provides definitions of data, personal data, data owners, classification of data, encryption, and data breach. “Data” is defined as information that is edited, modified, printed, or stored on a computer in the form of files, text, audio, image, computer programs (or digital information in a language understood by a computer). Personal data is defined as any information through which it is possible to infer directly or indirectly the identity of the individual.

According to Article 5, data owners, such as government agencies and private companies, although excluding security or military entities, should classify data into at least four different levels. For data classified in level three and four of this policy, the data owner must encrypt all data classified in accordance with the third and fourth levels if the data is to be transferred from one entity to another.

The four different data classification levels are:

  • General data and information available to the public.
  • Non-sensitive personal data such as, but not limited to, a person’s names, gender age, and job title.
  • Sensitive personal data such as, but not limited to, criminal records, court decisions, and contact information.
  • Highly sensitive data such as, but not limited to, political documents or sensitive information from military or security entities.

According to provision 5.4 on “Duties and Responsibilities”, all public and private entities must take the above data classification levels into consideration. For senior management of the entity, this means disseminating this policy to all employees to ensure its implementation, adopt measures to address and correct any data breach, ensure compliance with this policy, and establish a data classification team headed by senior management, which will prepare quarterly reports about the implementation of this policy.

The Draft Data Classification Policy represent a significant development in Iraq’s regulatory ecosystem, which still is rather nascent, with little to no specific data protection regulations in place. With this policy, however, it is clear that the Iraqi regulator is currently working to expand its regulatory framework to keep pace with digital transformation development.

If you are interested in learning more about Iraq’s Draft Data Classification Policy, require support with submitting comments to the public consultation or engage the CMC, please contact Hussein Abul-Enein at hussein.abul-enein@accesspartnership.com, or Anja Engen at anja.engen@accesspartnership.com.

Related Articles

Access Alert | Introducing Iraq’s Cloud Computing Policy

Access Alert | Introducing Iraq’s Cloud Computing Policy

On 20 June 2022, the Iraqi Communications and Media Commission (CMC) published its Draft Cloud Computing Policy. The Policy aims...

24 Jun 2022 Opinion
Access Alert | Mexican ICT Regulator Green-Lights Government Rescue of Altán Redes

Access Alert | Mexican ICT Regulator Green-Lights Government Rescue of Altán Redes

Mexico’s Federal Telecommunication Institute (IFT) unanimously approved the financing plan set forth by telecommunications company Altán Redes proposing a public-private...

24 Jun 2022 Opinion
Access Alert | The U.K. Science Minister George Freeman announced a new Plan for Space Sustainability

Access Alert | The U.K. Science Minister George Freeman announced a new Plan for Space Sustainability

The U.K. Science Minister George Freeman announced a new Plan for Space Sustainability today at the 4th Summit for Space...

23 Jun 2022 Opinion
Access Alert | Japan Establishes Stablecoin Cryptocurrency Regulation

Access Alert | Japan Establishes Stablecoin Cryptocurrency Regulation

Japan’s parliament has passed a bill to regulate stablecoin cryptocurrencies. The “Bill to partially revise the Act on Fund Settlement...

23 Jun 2022 Opinion