Iran’s Right to Privacy
A legal analysis with a focus on surveillance


The Iranian digital environment is currently defined by an aggressive strategic pivot toward "Digital Sovereignty," a doctrine that seeks to subordinate individual privacy to the overarching interests of the state. Central to this objective is the "National Information Network" (NIN), a state-controlled intranet designed to ensure domestic self-sufficiency while effectively insulating Iranian cyberspace from the global commons. This shift prioritizes state security over the right to privacy, creating a systemic tension with international standards for digital life. This report evaluates the legal mechanisms and institutional architecture driving this transition, identifying a profound gap between domestic practice and Iran’s international obligations. By examining the move from elected oversight to unaccountable, security-led governance, we map a landscape where the right to privacy is no longer a fundamental guarantee, but a revocable privilege.
International Commitments vs. Domestic Law
The right to privacy is a fundamental human right recognized both internationally and within Iran’s domestic laws. Iran’s Constitution and statutes formally acknowledge certain privacy protections, yet the nation’s actual practices, especially in digital surveillance and data privacy, often clash with its international obligations. Iran is party to key global treaties, which guarantees freedom from arbitrary or unlawful interference in privacy. Under Iran’s Constitution, international treaties approved by parliament attain the force of domestic law. In addition, under the principle of continuity and the customary international law rule pacta sunt servanda, treaties ratified by a state remain binding despite internal political change even in the case of a regime change.
This following section analyses Iran’s international commitments on the right to privacy with a focus on data privacy and surveillance. The following section examines these obligations in the light of Iran’s domestic laws and actual practices, highlighting key conflicts and inconsistencies.
International Obligations Under Right to Privacy
Iran has ratified several international instruments that protect privacy rights. Foremost is the ICCPR, which Iran ratified in 1975 without reservations. As mentioned above, although Iran ratified the ICCPR in the former regime, in accordance with the Principle of Continuity, its treaty obligations, including the right to privacy, continue to be legally binding under Iranian law.
ICCPR Article 17 explicitly provides: “No one shall be subjected to arbitrary or unlawful interference with his privacy, family, home or correspondence…”. It also guarantees everyone legal protection against such interference. This imposes a duty on Iran to ensure any limitations on privacy are lawful, necessary, and not arbitrary. Likewise, as a United Nations member, Iran helped adopt the Universal Declaration of Human Rights (UDHR), whose Article 12 mirrors the ICCPR’s language by proclaiming freedom from arbitrary interference with privacy, family, home or correspondence.
The U.N. Human Rights Committee (which monitors ICCPR compliance) has clarified in its General Comment No. 16 that even if intrusions are authorized by domestic law, they still violate ICCPR Article 17 if the laws are overly broad or unjustified. In other words, surveillance and data collection must be strictly regulated by clear laws to avoid “arbitrary interference” with privacy. The United Nations has also affirmed that the same rights people have offline, including privacy, must be protected online. A series of U.N. resolutions on “the right to privacy in the digital age” urge all states to review surveillance laws to ensure they meet principles of legality, necessity, and proportionality in line with human rights standards. As a U.N. member, Iran is expected to uphold these standards.
However, one of the central shortcomings of the Iranian legal system is the absence of effective legal safeguards to protect individuals against excessive and arbitrary interference with their rights, including the right to privacy. Restrictions on the right to privacy and the highly invasive surveillance practices are typically justified solely on the basis of the principle of legality, namely the existence of laws permitting such measures. These laws, however, fail to incorporate essential safeguards, such as tests of necessity and proportionality, required to ensure compliance with international human rights standards.
The legality, necessity, and proportionality tests are commonly used together to assess whether a limitation on rights is justified in compliance with international standards. The legality test requires that any restriction on a right must be prescribed by law. This means the measure must have a clear legal basis. The law must be accessible and foreseeable and provide adequate safeguards against arbitrary interference. Without a proper legal foundation, a restriction will fail at the outset, regardless of its purpose or effects. This is the first shortcomings of the majority of the laws overseeing Iranian citizens’ civil and political rights, that is, the legal basis that allows interference with the right is deliberately designed to be overly broad and open to arbitrary interpretations.
A clear illustration of this flaw can be found in Article 32-36 of Iran’s Computer Crimes Law (2009), which authorizes the collection, retention, and access to traffic data and content of communications. The provision states that such measures may be ordered by a judicial authority “whenever deemed necessary” where “there is a strong suspicion of discovering a crime or identifying the accused or evidence of a crime.” These phrases are so vague and expansive that they impose virtually no meaningful limit on state surveillance powers. In practice, virtually any online activity and data can be accessed with no need for any probable cause but simply “suspicion of discovering a crime”. There is no precise definition of what type of crimes can make such an access to private data permissible; or what is the threshold of a “strong suspicions”. Considering the broad nature of other criminalised online or offline acts in Iranian Penal Code any activities can be construed as potentially ground for discovering a crime from posting political criticism and participating in protest-related chats to sharing satirical content, using certain hashtags, or even belonging to private messaging groups that discuss social or economic grievances.
Because the law does not require the authorities to identify a specific crime already committed, a concrete suspect, or a proportionate link between the data sought and an identifiable wrongdoing, the threshold for issuing surveillance orders is extraordinarily low. This structural ambiguity enables mass monitoring of practically any segments of the population, prolonged retention of personal metadata and content without time limits, and the use of bulk data collection for fishing expeditions rather than targeted investigations. Human rights organizations have repeatedly documented how this provision has facilitated the large-scale digital tracking of protesters, journalists, human rights defenders, and ordinary citizens during waves of nationwide demonstrations (notably in 2017–2018, 2019, and 2022).
By contrast, comparable legislation in jurisdictions that adhere more closely to rule-of-law and proportionality standards, such as Title III of the Omnibus Crime Control and Safe Streets Act of 1968 (the U.S. Wiretap Act, as amended by ECPA 1986), imposes far stricter and more precise constraints. Under the Wiretap Act, interception of the content of electronic communications requires a judicial warrant supported by probable cause to believe that a specifically enumerated serious crime has been, is being, or is about to be committed. The authorizing order must explicitly name the target individual(s), identify the particular offense, describe the communications facility or place to be monitored, and limit the duration of surveillance (normally to thirty days, with extensions granted only upon renewed justification). Crucially, minimization procedures mandate that agents collect and retain only material pertinent to the named crime, discarding irrelevant data, while annual reporting to Congress provides a measure of public and legislative oversight. This side-by-side comparison highlights how deliberate vagueness in Iranian law serves as a built-in mechanism for unchecked executive discretion, whereas the U.S. framework, while not immune to criticism, embeds objective criteria, judicial scrutiny, temporal boundaries, and accountability mechanisms that significantly reduce the risk of arbitrary or abusive application. The Iranian approach therefore exemplifies a systemic design choice: to craft legal authority in language so elastic that virtually any interference with privacy or freedom of expression can be retroactively justified, undermining the core requirement that restrictions on fundamental rights must be sufficiently precise and exceptionally enforced to allow individuals to foresee the circumstances in which their rights may lawfully be limited.
If the measure is lawful, it must also satisfy the necessity and proportionality tests. The necessity test asks whether the restriction is genuinely required to achieve a legitimate aim, such as public order, national security, or public health, and whether there are less restrictive means available that would achieve the same objective. Iranian laws affecting privacy law rely on such legitimate aim without obligating the state to prove a direct connection between the intrusive act and the legitimate aim. The scope of the legitimate aim such national security has also deliberately kept vague and overly broad to include almost any online activity.
The proportionality test then goes further by balancing the severity of the restriction against the importance of the aim pursued, ensuring that the benefits of the measure outweigh the harm caused to individual rights. The proportionality test also requires the state to always use the least restrictive measures, or in this case least intrusive methods, to pursue the legitimate aim. Together, these tests ensure that state interference with rights is lawful, justified, and carefully limited. Such safeguards are conspicuously absent from Iran’s legal framework, particularly in the areas of digital surveillance, data protection, and the protection of privacy rights, where broad discretionary powers are exercised without meaningful and precise judicial oversight or constraint.
In addition to ICCPT, Iran is party to the Convention on the Rights of the Child (CRC), whose Article 16 protects children’s privacy, home and correspondence from unlawful or arbitrary interference. CRC’s Article 1 defines child as a person under eighteen. UN interpretation of the Article 16 establishes that both digital and physical surveillance of children, including online monitoring, metadata collection, biometric data collection, school surveillance, AI profiling and the interception of communications must comply with strict standards of legality, necessity, and proportionality. It further implies that mass or indiscriminate surveillance affecting children is presumed to be incompatible with the CRC, and that children are entitled to heightened protection, requiring more rigorous scrutiny of surveillance measures than would apply in the case of adults.
This is particularly important in the context of Iran, where the state has demonstrated no restraint in resorting to vast and systematic practices of online monitoring and AI based profiling, school surveillance, and the interception of communications during the 2022–23 protests, a period in which the majority of protesters were under the age of 18.
Notably, under Articles 77 and 125 of the Iranian Constitution, international treaties approved by the Islamic Consultative Assembly (Parliament) automatically become part of domestic law. Therefore, the CRC, privacy protections (and other treaty obligations) are not only external commitments but also de jure domestic law in Iran. In principle, any Iranian legislation or government action that contradicts ICCPR Article 17 and CRC Article 16 would breach both international law and Iran’s own constitutional requirement to honor treaties.
Beyond these binding human rights treaties, Iran has endorsed additional international and regional privacy-related commitments. For example, Iran supported the Outcome Documents of the World Summit on the Information Society (WSIS), which call for protecting personal data and privacy in cyberspace. As a member of the International Telecommunication Union (ITU), Iran is subject to global telecommunications regulations that include respecting the privacy and security of communications. Moreover, Iran is part of the Organisation of Islamic Cooperation (OIC), which in 1990 issued the (non-binding) Cairo Declaration on Human Rights in Islam affirming a generalized right to privacy (albeit framed within Islamic law). While these are not treaties, they reflect international expectations that Iran will protect privacy, especially as technologies evolve.
Domestic Law: Privacy Protections on Paper
Constitutional Guarantees
Iran’s Constitution of 1979 (amended 1989) contains provisions intended to safeguard privacy and personal liberties. Article 22 declares the “dignity, life, property, [and] rights” of the people inviolable except as sanctioned by law. The term “rights” also extends to the right to privacy. More specifically, Article 25 enshrines a right to privacy of communications: “The inspection of letters, and the recording and disclosure of telephone conversations, the disclosure of telegraphic and telex communications, censorship, or failure to deliver them, eavesdropping, and all forms of covert investigation are forbidden, except as provided by law.” In effect, the Constitution bans government spying on private correspondence and other “covert investigation” into citizens’ communications unless a particular law explicitly authorizes it. This is a significant recognition of privacy in principle, mirroring the language of ICCPR Article 17 (which permits only non-arbitrary, lawful interference). Article 25’s broad reference to “all forms of covert investigation” would by its plain meaning extend to modern electronic surveillance methods, suggesting that without a clear legal basis, practices like electronic eavesdropping or data monitoring are unconstitutional.
However, one of the key problems with the Iranian legal framework is the lack of vertical effect for human rights. In human rights law, the concept of vertical effect, often referred to as a "vertical claim," enables individuals to directly invoke and enforce their fundamental rights against the state or public authorities through legal mechanisms, such as judicial review or constitutional challenges. This principle, prominent in systems like the European Convention on Human Rights or EU law, and on a domestic level it is evident in the UK legal system, which allows citizens to hold governments accountable for violations, ensuring that human rights obligations are not merely declarative but practically enforceable in domestic courts. It contrasts with horizontal effect, which applies between private parties, and underscores the state's primary duty to protect rights, providing remedies like compensation, injunctions, or policy changes when breaches occur.
Iran's legal system starkly lacks an effective vertical claim mechanism, rendering human rights protections largely illusory despite constitutional provisions and ratification of treaties like the ICCPR. The judiciary, heavily influenced by the executive authorities and intelligence agencies, lacks independence, leading to systemic impunity for state-perpetrated violations. More importantly, it is impossible for the citizens to challenge laws incompatible with the constitution or Iran’s international obligations. This has also resulted in a double standard regarding what constitutes an offence when committed by non-state actors, while rendering it effectively impossible to hold state actors accountable for engaging in the same conduct. For example, doxxing is criminalized under Article 17 of the Computer Crimes Law (Article 745 of the Islamic Penal Code) and is punishable by imprisonment ranging from ninety days to two years. However, when the same practice is carried out by websites affiliated with the IRGC Cyber Command Centre, such as publishing photographs of citizens who participated in protests for the purpose of identifying them, there is no effective legal mechanism through which victims can seek accountability or redress.
In the absence of vertical effect, the only way to seek accountability against public institutions in Iran is through the Administrative Justice Court (Divan-e-Edalat-e-Edari) (AJC), which operates as the primary judicial body tasked with overseeing administrative actions and ensuring accountability in public governance. Established under Article 173 of the Iranian Constitution of 1979, it was created to address grievances against government agencies, ministries, and public institutions, providing citizens with a mechanism to challenge unlawful or arbitrary decisions. Operating as a specialized tribunal within the judiciary, the court handles cases involving administrative disputes, such as violations of legality of administrative acts by state entities, improper implementation of laws, or abuse of power by officials. Its jurisdiction extends to reviewing regulations, decrees, and decisions issued by administrative bodies, with the authority to annul or amend them if they contravene constitutional principles, Islamic law, or statutory provisions. This institution theoretically serves as a safeguard for administrative justice, promoting transparency and the rule of law in a system where the executive branch holds significant influence.
Despite its foundational importance, the Administrative Justice Court's effectiveness in Iran's legal framework is constrained by structural and practical limitations. While it can issue binding rulings and enforce remedies like compensation or reinstatement, its decisions are subject to oversight by higher authorities, including the Supreme Leader's appointees in the judiciary, which raises concerns about independence and impartiality. More importantly, the jurisdiction of the AJC is expressly limited, as a number of powerful bodies and institutions are exempt from its review. These exemptions include the acts of parliament, and the decisions issued by the Head of the Judiciary, the Guardian Council, the Supreme Council of the Cultural Revolution, the Supreme Council of Cyberspace, and the Supreme Council of National Security. These are precisely the bodies that act as policymakers and regulators of cyberspace, and whose decisions have a direct and far-reaching impact on citizens’ digital privacy and data protection rights.
Statutory Privacy Protections:
The Islamic Penal Code
The Iranian Penal Code, that is known as the Islamic Penal Code, operates within a dual-source legal framework, drawing on both secular legislation and Islamic jurisprudence. This structure is reflected in Articles 4 and 167 of the Constitution, which establish Islamic Sharia not merely as a source of law, but as the supreme normative authority governing the legal system. Consequently, the concept of privacy in Iranian law is not formulated solely in accordance with its modern legal understanding; rather, it is also shaped by Islamic doctrinal principles, which inform both the scope and interpretation of privacy-related protections.
Framing privacy and digital data protection within a dual secular–Islamic legal formulation, creates several structural and practical problems. But the main difficulty arises from how indeterminate religious concepts become the supreme legal source without clear limiting principles.
Conceptual indeterminacy and legal uncertainty are the first issues caused by this dual-source legal framework. While modern data protection is formulated based on precise technical definitions such as consent, processing and purpose limitation, the concept of privacy derived from Shari sources is more contextual and moral in nature. In addition, the scope of limitation that a secular framework imposes on the authority is fundamentally different with that of the sharia establishes for the ruler of the Islamic State. As a result of combining these fundamentally different normative sources, significant uncertainty arises as to which forms of data collection, processing, or surveillance are permissible.
For instance, Article 745 of the Islamic Penal Code / Article 17 Computer Crimes Law criminalizes the unauthorized publication of “private or family audio, images, films, or other secrets” via computer or telecommunication systems, but does not define key terms such as what counts as “private” or “secret” data in that context, or when consent is absent. This creates ambiguity about the scope of protected information which comes from the vague concept of privacy in the Islamic family.
Expansion of state discretion through moralized standards is the second problem of such dual-source framework. When privacy is framed through religious doctrine, state authorities gain wide discretion to define the limits of privacy by reference to morality, religion, or national security. This enables broader surveillance and data monitoring to be justified as enforcing Islamic values, rather than being assessed against necessity and proportionality tests.
More importantly, the supremacy of religious sources grants the state impunity against what is criminalized for non-state actors. For example, while Article 745 criminalizes the publication of private family photos, films and correspondence, the State TV broadcasts the exact same material without the consent of their owners and in a distorted fashion as part of propaganda programs to justify the arrest and punishment of dissidents.
In the Iranian legal framework, privacy violations carried out through information and communication technologies are regulated under two distinct categories of digital and non-digital criminal law. The first consists of long-standing legal provisions that safeguard personal confidentiality more broadly, such as offences relating to the unauthorized disclosure of private information. The second category comprises more recent legislation specifically addressing privacy concerns arising from the use of computers, smartphones, and information and communication technologies.
Iranian law addresses the unauthorized disclosure of confidential information through Article 648 of the Islamic Penal Code. This provision imposes criminal liability on individuals who, by virtue of their profession or position, are entrusted with private information and disclose it outside legally permitted circumstances. Once, again Such conduct is punishable by a term of imprisonment ranging from just over three months to one year, or by a monetary fine within the statutory range. The scope of this offence extends to both public and private sector professionals whose occupational roles involve interaction with the public and access to sensitive personal information.
The offence is premised on a relationship of trust or functional access, whereby the offender acquires knowledge of confidential matters either because individuals voluntarily confide in them or because their professional duties inherently expose them to such information. Where disclosure is legally authorized, the information must be communicated exclusively to the competent authorities and only to the extent strictly required. Any disclosure beyond this necessity, or to unauthorized persons, constitutes an unlawful breach of confidentiality and triggers criminal responsibility under Article 648.
However, accountability significantly diminishes when the conduct in question is attributable to public authorities. For instance, when the Ministry of Intelligence transferred the content of detained British Iranian Nazanin Zaghari’s laptop and mobile phone including her private family photographs and videos to a state-owned television broadcaster to be shown on a defamatory propaganda program, no effective legal avenue existed through which she could seek accountability or obtain a remedy under Article 648.
Provisions relating to the protection of privacy and personal information are set out in the third chapter of the Islamic Penal Code, commonly referred to as the Computer Crimes Law (2018). Within this framework, Article 1, incorporated as Article 729 of the Penal Code and addressing “Unauthorized Access”, establishes criminal liability for any individual who accesses data or computer and telecommunications systems secured by protective measures without authorization. The offence carries penalties of imprisonment for a period ranging from ninety-one days to one year, a financial penalty between 66 million and 264 million Iranian rials, or the imposition of both sanctions. The provision applies broadly to all forms of unauthorized access, whether achieved directly or indirectly. Accordingly, Iranian law treats access to another person’s protected information without consent as inherently unlawful, categorizing such conduct as a strict or act-based offence that does not depend on proof of resulting harm or adverse consequences.
Article 2 criminalizes the unauthorized interception of private communications transmitted through computer-based or telecommunications networks. Any individual who unlawfully monitors or accesses the content of such communications is subject to criminal penalties, including imprisonment for a term ranging from six months to two years, a monetary fine between 82 million and 500 million Iranian rials, or the imposition of both sanctions. For the purposes of this provision, interception encompasses any method of obtaining data while it is being transmitted. Communications are considered private where they are of a personal nature and are not accessible or known to the general public.
The principal weakness of this provision lies not in the conduct it criminalizes, but in the regulatory gaps it leaves unaddressed. Although Article 2 appears to protect the confidentiality of private communications, it fails to define what constitutes “lawful” interception. The law does not specify which authorities may engage in surveillance, under what conditions such interception may occur, or what procedural safeguards, such as prior judicial authorization or independent oversight, are required. This absence of clarity creates a legal vacuum that enables state authorities to characterize intrusive surveillance practices as lawful without meaningful scrutiny.
In practice, the provision is applied asymmetrically. While private individuals may face criminal liability for intercepting non-public communications, surveillance carried out by intelligence or security agencies is generally treated as authorized activity. Because the law does not explicitly subject state interception powers to necessity, proportionality, or transparency requirements, public authorities enjoy de facto immunity from accountability. This results in a double standard whereby identical conduct is criminalized when undertaken by non-state actors but effectively exempt when performed by the state.
Furthermore, the law omits any requirement that interception measures be strictly necessary or proportionate to a legitimate aim. There are no limitations on the scope, duration, or scale of surveillance, nor any obligation to minimize data collection. The definitions provided, such as “eavesdropping” and “non-public communications”, remain technically underdeveloped and do not address modern surveillance practices, including metadata collection, bulk interception, or automated monitoring. As a result, the provision is ill-equipped to regulate contemporary forms of digital surveillance.
Finally, the law offers no meaningful remedies for individuals whose communications are intercepted. It does not provide for notification, avenues to challenge surveillance measures, or compensation for unlawful interference. Consequently, while Article 2 creates the appearance of protecting privacy, it ultimately functions as a narrow criminal prohibition that constrains private misconduct while leaving state surveillance largely unchecked, undermining effective protection of digital privacy rights.
A similar structural deficiency is evident in Article 17 of the Computer Crimes Law, particularly when applied to the conduct of security and intelligence agencies. Although the provision criminalizes the unauthorized disclosure of private family data, including images and recordings, it offers no effective protection when such acts are carried out by state authorities. In practice, when security agencies transfer private family photographs or video footage obtained from detained individuals to state-owned broadcasters for use in coercive or propagandistic programs without consent, the individuals concerned should be able to invoke Article 17 to seek accountability or redress. As with Article 2, the absence of clear limits on state authority, independent oversight, and enforceable remedies results in a legal framework that penalizes equivalent conduct by private actors while shielding state institutions from responsibility. This asymmetrical application further entrenches impunity and weakens the law’s capacity to function as a genuine safeguard for privacy and personal data.
The Law on Publication and Free Access to Information (LPFAI)
The LPFAI is primarily a transparency and freedom-of-information statute. While it contains references to privacy, it has serious structural shortcomings when assessed from the perspective of data protection, privacy rights, and protection against arbitrary surveillance.
The law is designed to regulate access to information held by institutions, not the collection, processing, retention, or sharing of personal data. Privacy appears mainly as an exception to disclosure rather than as an independent, enforceable right. As a result, the statute does not operate as a data protection law but as a disclosure-management framework.
Although Article 1 provides a definition of “personal information,” this definition is narrow and largely descriptive, concentrating on traditional identifiers such as an individual’s name, address, family circumstances, bank account details, and passwords. While these categories reflect conventional understandings of personal data, they do not adequately capture the complexity of information generated and processed in contemporary digital environments.
Notably, the definition does not clearly extend to metadata and traffic data, location information, device identifiers, behavioural patterns, inferred profiles, or the large-scale datasets produced by digital platforms. As a result, many forms of data that are central to modern surveillance, profiling, and data-driven decision-making remain either insufficiently protected or legally ambiguous, significantly weakening the law’s effectiveness as a safeguard for privacy in the digital age.
Iran’s Electronic Commerce Law (IECL)
The law’s primary objective is to facilitate “easy and secure” electronic exchanges in commercial contexts; however, in the absence of a comprehensive Personal Data Protection Act, it has been relied upon as a de facto rights-based framework for regulating data processing across the broader digital ecosystem. As a result, privacy protections are embedded within a transactional statute and do not clearly extend to the full range of contemporary data practices, including large-scale platform governance, algorithmic profiling, commercial data brokerage, or pervasive collection of behavioral and technical identifiers.
A central deficiency lies in the law’s narrow and uneven approach to the definition and regulation of personal data. While it defines “private data messages” as information relating to an identifiable natural person, its most explicit prohibitions concentrate on special categories of data, such as ethnic origin, religious or ideological views, moral characteristics, health, and sexual status, leaving the treatment of ordinary yet highly revealing data less clearly regulated. In modern digital environments, it is precisely such routine datasets, location data, device identifiers, browsing and communications metadata, contact lists, and platform activity logs, that enable extensive tracking, profiling, and interference with privacy. The statute’s emphasis on a limited set of “sensitive” categories therefore risks obscuring the privacy harms that arise from the aggregation and analysis of everyday personal data.
The IECL’s reliance on consent is also structurally weak. Article 59 permits the storage, processing, and distribution of personal data with the individual’s consent, but conditions this permission on conformity with other parliamentary legislation. In practice, this clause creates a broad override: where another statute authorizes data access or disclosure, particularly under expansive pretext such as security or public order, the individual’s consent and the protective logic of the e-commerce framework can easily be dismissed. This undermines legal certainty and leaves considerable discretion for public authorities to justify intrusions without having to satisfy rigorous safeguards.
More fundamentally, the statute lacks the institutional and procedural architecture associated with modern data protection systems. It does not establish an independent supervisory authority with powers to investigate, audit, issue binding orders, or sanction unlawful processing. Instead, key matters, such as exceptions, third-party disclosures, objections, safety requirements, and the dsignation of supervisory institutions, are trusted to implementing regulations.
These shortcomings are especially important in relation to arbitrary surveillance. The law does not effectively constrain state interception, intelligence access, or large-scale data collection, nor does it embed core safeguards such as prior judicial authorization, necessity and proportionality requirements, limits on scope and duration, transparency obligations, or post-surveillance notices. In effect, the statute may limit certain forms of misuse in private commercial settings, but it is largely silent on the most imortant risks to privacy: the ability of security institutions to obtain, retain, and repurpose personal data without independent oversight.
The Charter on Citizens’ Rights:
In recent years, Iranian officials have at least acknowledged the need for clearer data protection rules amid the growth of the digital economy. A notable (though non-binding) document is the Charter on Citizens’ Rights unveiled in 2016 by former President Hassan Rouhani. This charter devotes a section to the Right to Privacy, affirming that “Every citizen has a right to have their privacy respected. Residences, personal spaces, belongings and vehicles are immune from search and inspection, except pursuant to the law.” It also states that citizens’ dignity and privacy must be respected in the media and public discourse, with remedies provided for any violations. While the Charter has no enforcement, it illustrates an official recognition that privacy includes not only the home and correspondence but also personal data and honor in public forums.
However, the principal shortcoming of the Charter on Citizens’ Rights lies not only in its non-binding nature, but also in the institutional framework within which it situates the protection of privacy. By isuing the Charter as an executive policy initiative, responsibility for safeguarding privacy and personal data was implicitly placed within the remit of the executive branch, despite the fact that under Article 3 of the Constitution the executive branch’s responsibility is to respect and fulfil the “civil and political freedom” and such protection falls squarely within the constitutional mandate of the judiciary. Under Article 156 of the Constitution, the judiciary is expressly tasked with “protecting the public rights” and ensuring justice. The Charter therefore reflects a misallocation of institutional responsibility: it articulates normative commitments to privacy without embedding them in binding legal rules or judicially enforceable mechanisms. As a result, even the limited guarantees articulated in the Charter remain aspirational, lacking both legal force and a competent institutional authority capable of providing effective remedies for privacy violations.
Sectoral Regulations
Iran’s government points to various sector-specific regulations that supposedly protect privacy and data. In the telecommunications sector, for instance, operators by law and licensing rules are expected to keep subscriber information and communications confidential. In banking, strict secrecy of customer financial data is a longstanding norm (banking regulations forbid revealing clients’ account information without legal authorization). In March 2024, an Iranian representative at the U.N. Human Rights Council stated: “Iran has established laws and regulations pertaining to data protection and privacy, particularly within specific sectors such as telecommunications and banking.” This likely alludes to rules like the Central Bank’s customer privacy guidelines and the Communications Regulatory Authority’s requirements on telecom user data confidentiality. However, these sectoral rules are fragmented and often lack independent oversight or robust enforcement. Iran still does not have a single comprehensive personal data protection law, which leaves significant gaps.
Draft Personal Data Protection Act
Recognizing the legislative gap, Iran has for several years been developing a Personal Data Protection and Safeguarding Bill (first introduced around 2018). If enacted, this would be Iran’s first comprehensive data privacy statute, intended to regulate collection, processing, and storage of individuals’ data by both government and private entities. A 2019 legal analysis by the NGO Article 19 observed that the draft Personal Data Protection Act was “poorly drafted and inconsistent with the international legal obligations of Iran to adequately protect the privacy rights of its citizens.”
Although the draft purports to protect “personal data” and the dignity of data subjects, it lacks a clear articulation of foundational data protection principles in accordance with the international standards such as legality, necessity, proportionality, purpose limitation, data minimization, and accountability as autonomous rights frameworks. Without these core principles, the law risks being applied subjectively or subordinated to other legal mandates (such as security, public order, or administrative expediency).
The draft defines “personal data” and “sensitive personal data,” but does not clearly delineate the full scope of data types (e.g., metadata, behavioral profiling, inferred characteristics) that modern privacy norms protect. In addition, other key principles of modern data privacy law, such as clear consent and non-discrimination, were not fully or clearly incorporated in the draft[14]. For example, one version of the bill would have applied only to data on Iranian citizens, excluding stateless persons or possibly even some non-citizen residents, a discrimination that “violates Iran’s international human rights obligations” according to Article 19’s analysis. Moreover, the proposed oversight authority under the draft lacked independence, and individuals would have insufficient remedies for privacy breaches.
The draft allows extensive exceptions in the name of public order, security, and law enforcement. Processing may proceed without consent for “prevention or response to threats to public order, safety and security,” “crime detection,” and “enforcement of judicial and policing measures.”
This echoes Article 12 of the draft, granting broad state powers over data without stringent requirements like prior judicial authorization, necessity and proportionality tests, or independent oversight. This omission opens the door to arbitrary surveillance by security and intelligence bodies.
The same as any other Iranian laws and regulation regarding data protection there is no independent oversight structure to scrutinize any potential abuse of power. The draft creates a Commission for the Protection of Personal Data as the primary regulator, but its composition is dominated by senior government and security officials (e.g., ministers of ICT, intelligence, interior, justice, economy, judiciary representatives, and the National Cyberspace Center) some of which are the very entities that their potential abuse of power needs to be monitored.
As of late 2025, this data protection bill had not been passed into law. In the meantime, with legislation stalled, authorities have resorted to executive measures.
Executive Privacy Guidelines (2024)
In January 2024, the Supreme Council of Cyberspace, Iran’s top internet policy body, issued new Executive Guidelines for Improving User Privacy Protection and Data Handling in Cyberspace Platforms. This regulation (approved by the Supreme Regulatory Commission for Cyberspace) imposes certain privacy duties on online service providers.
The issuance of the Executive Guideline, first and foremost, highlights one of the most serious hazards within the Iranian legal system, that is, the deliberate proliferation of parallel legislative entities designed to bypass democratic parliamentary due process and concealing the chain of accountability. The most fundamental deficiency of the Guideline is that this instrument is not a statute enacted by Parliament, but an administrative instruction issued under the authority of the Supreme Council of Cyberspace and its regulatory bodies. As such, it lacks constitutional status, and democratic legitimacy of primary legislation. In the absence of a comprehensive data protection law, reliance on executive instructions creates a fragmented and unstable regulatory environment in which core privacy rights depend on policy documents that can be amended, suspended, or selectively enforced without a democratic due process and through entities fully exempt from scrutiny.
Aside from this principal problem, which will be examined in detail in the following section, the Guidelines, on their face, incorporate familiar data-protection concepts, such as transparency, consent, encryption, and account deletion, and impose binding obligations on domestic internet service providers and platforms. However, when examined through the lens of surveillance and access to personal data, the Guidelines reveal deep structural deficiencies that risk entrenching, rather than restraining, state control over digital information.
A central problem lies in the treatment of data deletion. Although the guidelines formally recognize users’ right to request the deletion of their accounts and associated data, this right is immediately neutralized by Article 1(3), which requires that deleted data be transferred to offline backup systems pursuant to Articles 667–670 of the Criminal Procedure Code. These provisions mandate the retention of extensive categories of user data, ranging from traffic metadata (origin, route, time, duration, and volume of communications) to identifying information such as IP addresses, telephone numbers, and geographical location, for a minimum of six months. As a result, “deletion” does not mean erasure, but rather relocation from online platforms to state-accessible repositories. This is by no means in accordance with the Article 669 which requires the access to the data to be provided only upon the request of the judicial authority. Instead, this approach effectively transforms private platforms into preliminary collection points feeding long-term state data retention systems, thereby hollowing out the substance of the right to erasure.
The invasive implications of this design on the right to privacy are significant. By requiring the systematic preservation of traffic and identity-related data regardless of user consent, the guidelines normalize the generalized data retention without individualized suspicion or judicial authorization. There is no requirement that access to retained data be limited by necessity, proportionality, or prior court approval. Instead, retention is justified by reference to broadly framed legal duties, which in practice enable security and law-enforcement agencies to access large volumes of personal data on a routine basis. In this respect, the guidelines function less as a privacy-protective instrument and more as a regulatory mechanism that standardizes data availability for surveillance purposes.
These concerns are further amplified by the guidelines’ introduction of a centralized identity verification infrastructure. Article 2 obliges platforms to integrate their authentication systems with the “valid identity ecosystem” administered by the Civil Registration Organization. While this measure is presented as a means of minimizing the amount of identity data collected by individual platforms, its systemic effect is to consolidate identity verification at the state level and to ensure that online activity can be reliably linked to officially verified real-world identities. This measure effectively eradicates the right to anonymity on the cyberspace for Iranian citizens. In the absence of robust safeguards, independent oversight, or limits on secondary use, this architecture significantly expands the state’s capacity for tracking, profiling, and monitoring users across digital services.
The exceptionally intrusive nature of these Guidelines which practically enables limitless surveillance and unprecedented interference with the right to privacy clearly explains why they were adopted outside the ordinary parliamentary due process.
Digital Panopticon: The Institutional Architecture and Legal Framework of Internet Governance and Surveillance in Iran
The Iranian digital landscape is defined by an aggressive strategic pivot toward the doctrine of "Digital Sovereignty," a framework that subordinates individual privacy to the overarching interests of state security. This doctrine finds its ultimate expression in the National Information Network (NIN), which is not merely an intranet, but represents the most advanced and comprehensive surveillance apparatus ever deployed by an authoritarian state. By insulating domestic cyberspace from the global commons, the NIN ensures state self-sufficiency while enabling centralized, granular monitoring of all data flows.
Underpinning this architecture is the "revocable privilege" model of digital rights. In this landscape, fundamental guarantees of privacy are treated not as inherent human rights, but as contingent permissions granted at the state's discretion. In gross breach of its obligations under international human rights law and its own Constitution, the state has engineered a technical environment where digital rights are systematically derogated in favour of "morality” or “national security" permitted and facilitated by an unaccountable hierarchy of institutional bodies. Within such a unique architecture of internet governance, the state has defined itself as the ultimate owner of all citizens’ public and private data. In this sense, the right to privacy has been wholly undermined and inverted, such that the state’s refraining from intercepting citizens’ data appears as an exception rather than a rule, and as a privilege rather than a right.
While at first sight the Iranian regime’s internet governance appears similar to that of other semi or quasi-democratic states, it is in fact a complex network of parallel governing and legislative entities, deliberately designed to misdirect responsibility and effectively disable transparency, democratic scrutiny, and accountability.
This section portrays a comprehensive map of the institutions that make up Iran’s internet governance and surveillance architecture. It also provides an analysis of how this apparatus is deployed and highlights its incompatibility with international human rights norms and Iranian regime’s own Constitution.
Mapping the Institutional Architecture of Internet Governance
Iran’s internet governance is orchestrated by a complex, multi-layered and overlapping hierarchy of high councils, committees, ministries, and security agencies that deliberately centralizes the highest authority in unelected bodies. Many of these bodies operate in parallel to or above the normal executive, legislative, and judicial mechanisms, ensuring that key decisions about cyberspace are kept within an unelected circle under direct supervision of the Supreme Leader. The diagram below (figure 1), derived from an official parliamentary report, provides an overview of the key institutions involved in internet and cyberspace governance, their complex hierarchical relationships and roles.
Supreme Leader and High Councils
At the apex of the internet governance structure sits the Supreme Leader, Ali Khamenei. who holds the ultimate authority and sets the strategic direction for control, censorship, and surveillance in cyberspace. As an unelected authority with full immunity to any scrutiny, he exercises decisive control through a network of supra-parliamentary institutions operating under his supervision. In practice, cyberspace governance is primarily channelled through three high councils that formulate binding policies, coordinate enforcement, and shape the legal and technical architecture of digital control.
Supreme Council of Cyberspace (SCC) (Shoray-e Aliye Fazay-e Majazi):
SCC is a body created by the Supreme Leader’s decree in 2012. The SCC is ostensibly chaired by the President, but in practice it operates as Supreme Leader’s unelected legislative arm in parallel to the parliament. The founding decree issued by the Supreme Leader, Ali Khamenei, establishes the SCC as a centralized policymaking authority in cyberspace and states that “all its resolutions must be given legal effect.” However, the decree does not specify the precise constitutional rank of SCC decisions within Iran’s hierarchy of norms. The SCC is neither mentioned in the Constitution nor clearly categorized as legislative, executive, or advisory. As a result, its acts occupy an ambiguous normative position: they are treated as binding across branches of government, yet they are not statutes enacted by the parliament nor regulations issued under ordinary executive delegation.
This ambiguity is even more pronounced in the Statute of the National Cyberspace Center (NCC), the SCC’s executive arm, which declares that the NCC holds “the highest sovereign level in cyberspace governance among all state institutions” within the framework of SCC decisions.. The NCC is responsible for drafting policy proposals, coordinating between government institutions, monitoring implementation, and following up on the execution of the SCC’s resolutions. In this sense, both SCC and NCC are parallel entities that effectively undermine the legislative and executive branches of the elected government in favour of unelected entities under direct control of the Supreme Leader.
The SCC is by effect the highest legislative authority for cyberspace and the NCC issues executive directives binding on all state institutions, thereby raising questions under the principle of legality and the requirement that administrative bodies act strictly within their delegated authority. The broad subject matter of cyberspace creates functional interference with the legislative authority of the Islamic Consultative Assembly and the executive competences of bodies such as the Ministry of Information and Communications Technology (ICT). In the absence of a comprehensive parliamentary statute clearly delineating competences, ambiguities concerning regulatory scope, hierarchy of norms, and enforcement mechanisms may give rise to institutional friction and constitutional distortions with deliberate aim of weakening the democratic oversight.
A clear illustration of the SCC’s capacity to circumvent Parliament can be found in its September 2019 resolution entitled “Valid Identity System in the National Cyberspace.” Framed as an initiative to establish “the necessary infrastructure for secure and reliable interactions in cyberspace,” the resolution in fact mandates the use of approved digital identifiers for all technical, economic, cultural, social, political, and administrative interactions conducted online. This resolution is the backbone of Iranian regime’s mass surveillance system.
By extending its regulatory reach across virtually every sphere of digital activity, the SCC effectively imposed a nationwide identity-verification regime without the enactment of a comprehensive parliamentary statute. In doing so, it assumed a legislative function of general and abstract norm-setting that would ordinarily fall within the competence of the elected legislature. This expansive assertion of authority not only consolidates regulatory power in an unelected body operating under yet another unelected authority, that is, the Supreme Leader but also reinforces the structural marginalisation of Parliament in the governance of cyberspace.
Supreme Council of the Cultural Revolution (SCCR)
Another high entity under direct control of the Supreme Leader is the SCCR, which, while formally focused on the cultural and educational domains, also asserts influence over digital content and emerging technologies in line with ideological objectives. In practice, the SCCR’s regulatory interventions overlap with, and at times interfere in, the functional domain of the SCC in regulating cyberspace. Both unelected bodies issue binding normative instruments that shape internet governance. This parallel norm-production not only blurs the hierarchy of competences but also further marginalises Parliament, as core aspects of digital regulation are determined through supra-parliamentary councils operating outside ordinary legislative procedures.
The SCCR’s early intervention in internet regulation illustrates this dynamic. In 2001, it adopted the “Regulations and Rules of Computer Information Networks,” one of the foundational instruments of cyber surveillance in Iran. Article 5 of the resolution required internet service providers to setup a filtering system and retain user activity data and submit it to the Ministry of Communications, to be made available to the Ministry of Intelligence and other intelligence organisations upon request and with judicial approval. Although formally framed within a procedural safeguard structure, as mentioned above, such procedural safeguard against unlawful breach of privacy right including the proportionality and necessity test does not exist with the legal system of Iran.
More importantly, subsequent disclosures, including materials revealed through the hacking of servers associated with the judiciary’s filtering committee, indicate that, in practice, many data requests were transmitted directly from prosecutorial authorities to internet companies. Through this regulatory framework, the SCCR established an early legal infrastructure for systematic data retention and state access to user information, laying yet another foundation for pervasive cyberspace surveillance outside the framework of parliamentary legislation and democratic oversight.

Supreme National Security Council (SNSC)
A further pivotal actor in this architecture is the SNSC, constitutionally established under Article 176 of the Constitution and formally mandated to safeguard national security and territorial integrity. Chaired by the President but operating within a framework whose decisions become effective upon confirmation by the Supreme Leader, the SNSC occupies a hybrid position at the intersection of executive authority and supra-constitutional oversight. While its remit is broadly defined in terms of defence nd security coordination, in practice it has assumed a decisive role in internet governance, particularly in moments framed as national security crises. Orders concerning nationwide internet shutdowns, traffic throttling, platform blocking, and emergency communications restrictions have frequently been attributed to the SNSC or bodies operating under its authority. Through its security mandate, the Council thus extends the logic of securitisation into the digital sphere, treating connectivity not merely as infrastructure but as a domain of strategic control.
The SNSC’s involvement further compounds the structural opacity already produced by the SCC and SCCR. As a constitutional body with vast authority, its decisions are shielded from public scrutiny and parliamentary review, particularly when classified as matters of national security. The coexistence of multiple high-level councils, each empowered to regulate, censor, or surveil cyberspace under distinct yet overlapping legal bases, generates profound ambiguity regarding competence, hierarchy of norms, and especially accountability. This multiplicity enables the diffusion of responsibility: restrictive measures can be justified alternately as cultural policy, cyberspace governance, or national security necessity. The result is a fragmented yet mutually reinforcing system in which elected legislative authority is systematically sidelined, and extraordinary controls over digital communication become normalised through parallel centres of unelected power.
As discussed in the previous chapter, all these three most powerful institutions shaping Iran’s internet and surveillance policies are explicitly exempt from the jurisdiction of the Administrative Justice Court. This exemption removes any possibility of legal challenge or accountability for decisions that profoundly affect digital rights, effectively placing the core of Iran’s cyber governance structure beyond judicial review.
Regulatory and Enforcement Apparatus
Beneath the ideological command of the Supreme Leader and Iran’s high councils lies a complex web of regulatory and executive institutions tasked with operationalizing digital control. This apparatus functions as the engine room of Iran’s internet governance regime. These bodies are responsible for drafting and enforcing technical standards, managing digital infrastructure, issuing filtering orders, allocating bandwidth, and coordinating with security agencies to execute surveillance mandates. More importantly they are the executive arms of the project of total detachments of Iranian citizens from the world web under the doctrine of Digital Sovereigty. While presented as civilian or technocratic entities, their operational arrangement with the state security and intelligence objectives and full subordination to unelected councils renders them central instruments of systemic censorship, surveillance and control. Their layered roles create a seamless interface between law, infrastructure, and repression, ensuring that digital governance in Iran remains tightly interwoven with political obedience and state security.
Supreme Regulatory Commission for Cyberspace (SRCC):
Positioned as the chief censorship authority under the SCC, the SRCC (sometimes called the Commission to Coordinate Cyberspace’s Regulation) oversees filtering and blocking of online content. Operating under the Supreme Leader-controlled SCC, 8 out of SRCC’s 12 members are likewise appointed directly or indirectly by the Supreme Leader, underscoring its lack of institutional independence. Updated in 2022, the SRCC’s mandate encompasses drafting, coordinating, and supervising regulatory frameworks across all domains of cyberspace including platforms, infrastructure, data governance, digital content, and emerging technologies. It holds wide-ranging powers to authorize digital service providers, enforce compliance, mediate jurisdictional disputes between sectoral regulators, and set national priorities for cyberspace legislation.
The SRCC controls both domestic and international internet gateways: it manages bandwidth allocation, enforces data localization requirements, and orders the blocking of platforms that refuse compliance with Iranian laws. In practice, the SRCC is the body that updates the national blacklist of banned websites and apps, instructing ISPs on what to filter. In addition, as analysed above, it has issued and overseen the only binding regulatory instrument governing personal digital data in the absence of a comprehensive personal data protection law. In effect, this binding Guideline mandates service providers to relocated users’ personal data, including data deleted by users, and to state-accessible repositories.
Iran’s Parliament, Islamic Consultative Assembly (Majles)
The legislative authority of the Majles has already been undermined by the existence of unelected supra-legislative bodies such the SCC and the SCCR. In practice, this means that even when the Majles engages in formal lawmaking, its authority is subordinated to parallel institutions that are unaccountable to the electorate. This structural marginalization reinforces the concentration of power in the hands of security-aligned bodies and erodes any meaningful legislative oversight over digital rights and surveillance practices.
Yet even when it engages in legislating, rather than acting as a check on executive and security overreach, Majles has usually served to facilitate the institutionalization of state surveillance. While it holds legislative authority, in practice the Parliament has often rubber-stamped security-driven internet governance measures and failed to protect digital rights. One of the most illustrative examples is its handling of the controversial "Regulatory System for Cyberspace Services" bill (commonly known as the Protection Bill). In 2021, parliamentary leaders attempted to pass the bill under Article 85 of the Constitution, which allows legislation to be approved by a specialized committee rather than through full parliamentary debate and public reading. This procedural move was widely condemned as an effort to circumvent public scrutiny and democratic deliberation in order to fast-track laws enabling deeper control over internet infrastructure, user data, and online platforms.
From a legal perspective, this tactic represents a serious deviation from the principles of transparency, participatory lawmaking, and public accountability enshrined in international norms. The bill itself, while not fully enacted, contained provisions that would force foreign platforms to cooperate with Iranian authorities, require real-name identification for internet use, and expand surveillance powers for security bodies. The Parliament’s willingness to use constitutional loopholes to avoid public debate, combined with its limited resistance to hardline oversight bodies like the SCC, underscores its complicity in eroding digital rights. Rather than acting as a venue for checks and balances, the legislative branch has played a procedural role in legitimizing surveillance, failing to fulfil its obligatons under Article 25 of the ICCPR, which guarantees the right of citizens to participate in public affairs and enjoy legal protections against arbitrary state action.
Ministry of Information and Communications Technology (ICT)
The Ministry of ICT is the main executive agency managing Iran’s telecommunications and internet infrastructure. It works closely with the SCC and implements the technical aspects of censorship and surveillance. Through agencies under it, the Ministry operates critical systems like SIAM (for telecom monitoring) and oversees the state-owned telecom operators. The Ministry also spearheads the development of the NIN. Its policy scope includes regulating ISPs, allocating spectrum, and ensuring that Iran’s internet architecture can facilitate state surveillance (for instance by maintaining so-called “lawful intercept” backdoors that exceed international standards.)
The suite of surveillance systems operated under Iran’s Ministry of ICT e.g. SIAM, SHAHKAR, HAMTA, HADA, SAMAVA, and SHAMSA, constitutes an integrated architecture of mass monitoring that fundamentally contradicts international human rights standards on privacy, data protection, and freedom of expression. Iran's monitoring and digital registration systems function in a legal environment devoid of any safeguards set forth by the international human rights instruments such as the ICCPR to which Iran is an state party. SIAM, for instance, offers real-time surveillance and telecom manipulation through over 40 APIs without any requirement for judicial authorization or independent audit. SHAHKAR and HAMTA eliminate anonymity by linking every SIM and mobile device to a state-verified identity, effectively criminalizing private communication. The combined effect of these systems transforms digital access into a state-monitored privilege rather than a protected right, institutionalizing disproportionate, indiscriminatory mass surveillance practices that violate both the spirit and letter of international law.
Further worsening the situation are systems like HODA, SAMAVA, and SHAMSA, which consolidate identity verification, behavioral tracking, and long-term data retention into centralized databases, enabling cross-platform profiling and lifelong surveillance. HODA’s “one identity, one profile” design entrenches the inability to act anonymously in any digital context, while SAMAVA turns authentication into an instrument of control, enabling mass behavioral monitoring and potential digital exclusion. SHAMSA, as a repository of all intercepted phone calls and SMS communications, ensures that deletion rights are functionally nonexistent, which is a direct affront to data minimization principles under instruments such as the General Comment No. 16 of the UN Human Rights Committee. It also demonstrates a marked deviation from internationally recognized standards such as those established by bodies such as the 3rd Generation Partnership Project (3GPP) and the European Telecommunications Standards Institute (ETSI). These global standards are designed to ensure that lawful intercept mechanisms operate most compatibility with human rights principles, typically requiring clear legal warrants, limited and temporary data access scopes, and the establishment of secure, auditable interfaces between telecom providers and authorized legal authorities. In contrast, leaked technical documents and investigative reports from 2023 reveal that Iran’s lawful intercept infrastructure does not adhere to these baseline safeguards.
The Iranian system bypasses the above-mentioned core procedural and legal checks that are integral to the concept of "lawful" intercept and It lacks mechanisms for ensuring independent oversight or accountability. Instead, the ICT has deeply integrated its surveillance apparatus into telecom business systems, enabling broad access to user content and metadata without any constraint. The technical architecture designed by the ICT facilitates full user data delivery during service activation and allows service manipulation, such as downgrading access or retrieving content, without user knowledge.
These systems operate without transparency, public consultation, or judicial challenge. Their opacity, permanence, and mandatory participation amount to a vast coercive surveillance regime fundamentally incompatible with the ICCPR’s requirements for necessity, legality, and proportionality, and severely undermine the individual's right to digital self-determination.
Information Technology Organization (ITO)
The ITO, under the Ministry of ICT, is responsible for digital services and e-government initiatives. It has taken on roles like building national authentication and access systems. For example, ITO manages SAMAVA, (Sāmanah-ye Modiriyat-e Ettelā‘āt-e Hoviyat va Dastresi), the Identity and Access Information Management System. SAMAVA functions as an identity provider within Iran’s “Valid Identity System” (Nezām-e Hoviyat-e Mo‘tabar) and is designed to centralize authentication processes across governmental and non-governmental digital platforms. According to official descriptions, the system integrates existing national infrastructure to enable identity verification through databases such as Shahkar (the centralized electronic government user account system) and SANA/Thana (the judiciary’s electronic registration system), and facilitates validation of identity documents. By consolidating authentication services into a single state-administered gateway, the ITO positions itself not merely as a technical coordinator of e-government services but as a structural intermediary between policy directives and their technological implementation across Iran’s digital ecosystem.
From a legal perspective, SAMAVA raises significant questions regarding proportionality, purpose limitation, and data minimization. While centralized authentication may enhance administrative efficiency and reduce fraud, the aggregation of identity credentials across multiple state databases creates the conditions for comprehensive cross-platform profiling. Because SAMAVA connects executive and judicial data infrastructures, it lowers institutional barriers that would otherwise categorise and separate parts of sensitive personal information. In the absence of robust, transparent safeguards, independent oversight, and strict statutory limits on data retention and secondary use, which is clearly lacking in Iran’s legal framework for privacy rights, such an architecture risks exceeding what is necessary for service delivery and veering into systemic surveillance.
Communications Regulatory Authority (CRA)
As a sub-body of the ICT Ministry, the CRA acts as Iran’s telecom regulator. It is the operational arm for censorship, distributing the SRC’s filtering directives to all telecommunications providers. In addition, the CRA also sits at the centre of a far more intrusive mobile “lawful intercept” architecture. The CRA’s framework requires mobile operators to provide direct, system-level integration with state-operated external platforms, including a web-services API called Integrated Telecommunications Inquiry System or SIAM (Sāmanah-ye Yekpārche-ye Este‘lāmāt-e Makhāberāti), which is designed to plug into operators’ core business and network systems. In the model documented by Citizen Lab, SIAM supports real-time query and control functions. Authorities can retrieve extensive subscriber identifiers and historical usage (voice/SMS call detail records and internet session/IP detail records), pull lists of users by geographic cell location, and issue commands that can suspend services, block data sessions for a period, change call-forwarding settings, or even force a user onto slower 2G service. In effect, the CRA is positioned not just as the executor of censorship orders, but as an administrative control point embedded in mobile network operations, enabling granular, on-demand surveillance and service denial capabilities across providers.
The combination of (i) pervasive data visibility (including metadata and user’s location) and (ii) administrative power to degrade/deny connectivity raises serious risks of arbitrary or disproportionate interference with the right to privacy and related rights (including that of expression, association, assembly), especially if access is not constrained by clear public laws, case by case necessity, time limits, and independent oversight. In practice, a system that can mass-query and selectively disable communications can function less like targeted interception and more like mass surveillance and coercive control, which is incompatible with necessity and proportionality requirements under international human rights law.
Telecommunication Company of Iran (TCI)
Once a state telecom monopoly, TCI still controls much of Iran’s telecom backbone (fixed-line and broadband infrastructure). In recent years, TCI and other major telecom operators have come under partial or full ownership by the Islamic Revolutionary Guard Corps (IRGC) and its affiliates. An IRGC-linked conglomerate (Khatam al-Anbia) has taken over many infrastructure projects. This militarization of infrastructure means the physical networks (fiber-optic cables, data centers, mobile towers) can be swiftly repurposed for repression and the repression apparatus can shut down or degrade services on command.
When a military institution like the IRGC gains operational control over national telecom infrastructure, it effectively eliminates any civilian oversight and entrenches a structure in which connectivity becomes a tool of coercion, not a public good. The ability to unilaterally disrupt or surveil communications, especially during protests or political unrest, constitutes a form of collective punishment and prior restraint, both of which are incompatible with Iran’s obligations under international law.
The Coercive Arm of Digital Tyranny
At the heart of Iran’s internet governance regime lies a constellation of security, judicial, and paramilitary institutions that serve as the coercive machinery of digital repression. Unlike regulatory or administrative bodies, these actors wield direct power to surveil, intimidate, detain, and punish citizens for their online behaviour. Entities such as the IRGC Cyber Command, FATA Cyber Police, and the Ministry of Intelligence operate alongside hardline judicial organs and censorship committees to enforce ideological conformity and eliminate dissent in cyberspace. This apparatus functions not merely as an enforcement arm, but as a core pillar of Iran’s authoritarian digital state, blending cyber operations, panopticon surveillance, physical policing, legal prosecution, and content control into a tightly integrated system of fear and domination. Their reach extends from backend surveillance infrastructure to street-level enforcement, forming a seamless bridge between digital monitoring and real-world repression.
Islamic Revolutionary Guard Corps (IRGC) Cyber Command Centre
The IRGC’s cyber unit is the regime’s offensive and covert operations arm in cyberspace. It runs a “cyber army” that conducts hacking campaigns against regime critics and foreign targets. The IRGC Cyber Command also engages in domestic surveillance and disinformation; for instance, it has developed fake “bait” applications to compromise users (such as sham Starlink satellite internet installers to entrap citizens seeking uncensored access. With direct backing from the IRGC’s vast resources, this Cyber Command has both the technology and impunity to penetrate accounts, spread propaganda, and disrupt online communications deemed threatening to the regime.
This impunity is exemplified by the IRGC-affiliated website Gerdaab, which has repeatedly published photographs and videos of protesters soliciting public assistance in identifying them. Many of these images appear to be sourced through Iran’s expanding facial recognition surveillance systems, raising further legal and ethical concerns about biometric data misuse. From a legal standpoint, such practices constitute a clear violation of the right to privacy under international human rights law and contradict even Iran’s own penal codes criminalizing unauthorized disclosure of personal data. Yet, when such violations are perpetrated by state-linked platforms, no judicial or administrative remedy is available, revealing a dual system of enforcement where the state weaponizes laws against citizens while exempting itself from their constraints. This selective application of the law not only erodes legal credibility but entrenches a climate of fear, coercion, and extrajudicial punishment within the digital sphere.
FATA (Cyber Police)
The Iranian cyber police, known by the Persian acronym FATA, serves as a front-line enforcer of internet control. FATA monitors social media for dissent or “criminal content” and tracks online speech that violates state red lines. Uniquely, FATA also has a physical presence: they conduct raids and set up checkpoints to search smartphones for prohibited content. During street protests, FATA officers have been known to stop people and demand access to their messaging apps and photo galleries, looking for evidence of protest organization. By combining online monitoring with on-the-ground policing, FATA links Iran’s virtual panopticon with real-world intimidation.
Working Group to Determine Instances of Criminal Content (WGDIIC)
Often referred to as the Committee for Determining Offensive Content (or the Filtering Committee), this 13-member body is the chief arbiter of what content is illegal online. It is chaired by the Prosecutor General, ensuring a hardline judicial stance. Critically, the WGDIIC’s composition guarantees that elected officials (from the administration) are a permanent minority on the panel. This structure prevents any liberalization: even if a more moderate president’s representatives seek to unblock services or ease restrictions, they can be outvoted by members representing the judiciary, security forces, and conservative institutions mainly controlled by the Supreme Leader. The WGDIIC meets regularly to review websites, social media platforms, and online publications, issuing orders to filter or criminalize content ranging from political dissent to “immoral” cultural material.
In addition to its role in censorship, the WGDIIC also plays a direct role in enabling surveillance and privacy violations. Instead of supervising and scrutinising the scope of intrusive monitoring by the intelligence and law enforcement bodies, the WGDIIC functions as a facilitator for their excessive use of surveillance by criminalising whatever deemed undesirable by these bodies, hence, effectively turning content regulation into a gateway for state surveillance. By labellig certain digital expressions as criminal or subversive, the committee facilitates the targeting of individuals for investigation, prosecution, or coercive action, often without clear legal thresholds or transparency. Its integration with enforcement bodies thus blurs the line between content moderation and state surveillance, reinforcing a broader ecosystem of digital control.
Ministry of Intelligence (MOI)
Iran’s main intelligence agency (often called Ettela’at) plays a significant role in digital surveillance. The Ministry of Intelligence conducts mass data mining and interception, especially on popular platforms like Instagram and WhatsApp (both Meta-owned). Its cyber units have developed tools to scrape user data, monitor private chats, and identify networks of activists. For example, Intelligence agents map out dissident networks by correlating phone numbers, IP addresses, and social connections gleaned from hacked social media accounts. The MOI also runs cyber-espionage operations, and in domestic crackdowns it coordinates with IRGC Intelligence Organisation to track high-profile targets.
From a legal standpoint, the Ministry of Intelligence (MOI) operates in a space almost entirely devoid of independent scrutiny, transparency, or accountability mechanisms. Unlike intelligence agencies in democratic systems, which are typically subject to parliamentary oversight, judicial review, or data protection regulations, Iran’s MOI is shielded from such checks by its exceptional legal status and its political alignment with the Supreme Leader. The MOI's expansive surveillance activities, ranging from mass data mining to targeted cyber intrusion, are mostly conducted without the need for judicial warrants, public reporting, or regulatory compliance, violating fundamental rights to privacy and due process enshrined in Article 17 of the ICCPR. The absence of statutory limits on its surveillance powers, combined with the impossibility of legal redress for victims, places the MOI outside the bounds of international norms concerning intelligence accountability. This legal vacuum enables systemic rights violations and institutionalizes impunity in the state’s digital repression apparatus.
Judiciary and Special Courts
Iran’s judiciary supports the architecture of internet repression through special computer crime courts and compliant prosecutors. Online “crimes” such as blasphemy, “insulting the Supreme Leader,” or organizing protests via social media are prosecuted under broad laws. The judiciary’s role in the internet governance system is not to provide independent oversight, but rather to legitimize censorship and surveillance with a veneer of legality. Courts routinely issue orders to block websites or hand down harsh sentences to cyber-activists under the Computer Crimes Law (2009). Meanwhile, avenues for legal challenge are deliberately limited, for instance, complaints about unlawful filtering or surveillance cannot get a fair hearing (as described above, the Administrative Justice Court cannot review cases involving top security bodies or any of the three high councils.
As discussed in detail in the previous chapter, the Computer Crimes Law (2009) contains vague and overly broad definitions of cyber offenses, granting judges wide discretion to criminalize online expression and authorize data collection without clear legal safeguards. More imporantly, the Iranian legal system lacks foundational elements needed to protect privacy rights in cyberspace: there is still no comprehensive data protection law, no clear criteria for permissible request for judicial warrants in many surveillance practices, and no independent oversight body empowered to review or challenge violations. Moreover, the judiciary’s exclusion of security-related cases from administrative review, along with full exemption of high councils such as the SCC, eliminates any meaningful path for accountability or redress. This legal architecture entrenches impunity and denies Iranian citizens the protections that international human rights law, particularly Articles 17 and 14 of the ICCPR, require in the context of surveillance and privacy.
Through this overlapping web of councils, regulators, and security organs, Iran’s government has achieved an institutional overlap that deliberately obscures accountability. By dispersing authority among parallel bodies (SCC, SCCR, SNSC, etc.), the system ensures no single entity can be pinpointed for rights violations. Internet policy is effectively insulated from democratic input: elected institutions like the Parliament or the President’s cabinet are sidelined and turned into facilitators of repressive decisions made in unelected high councils dominated by security hardliners. The above mapping shows a “multi-layered totalitarian governance” whereby strategic decisions originate at the top (Supreme Leader and SCC), flow through executive agencies (ICT Ministry, CRA, etc.), and are enforced on the ground by intelligence and police units, all with minimal transparency and no accountability. In the sections that follow, we examine major legal frameworks that entrench state power over Iran’s digital sphere and privacy right.
Codifying Control: Iran’s Main Legal Frameworks for Surveillance and Censorship
One of the defining features of Iran’s surveillance regime is its deliberate use of legal instruments to entrench authoritarian control over cyberspace. Rather than only bypassing the law, the state has constructed an elaborate system of statutes, decrees, and parallel institutions that systematically breach the right to privacy, enabling mass surveillance and suppressing digital rights. This process of legal engineering enables repression not in the shadows, but under the guise of formal legality.
A cornerstone of this architecture is the use of “parallel” legislative institutions that operate outside the democratic lawmaking process. These bodies have effectively hollowed out the role of the Majles (Parliament) in digital governance. Their decisions, including those instituting national intranet plans or filtering policies, are made without public scrutiny or parliamentary debate. The use of Article 85 of the Constitution to advance the draconian “User Protection Bill” without a full parliamentary reading illustrates how even the formal legislative process of Majles is manipulated to avoid public accountability. The result is a dual-track legal system in which de facto rules issued by unelected bodies override or bypass statutory law, fragmenting responsibility and shielding the regime from blame.
The 2009 Computer Crimes Law (CCL) is the backbone of Iran’s surveillance legality. With broadly defined offenses and vague thresholds for data collection, such as allowing authorities to access user data “whenever deemed necessary”, the law authorizes sweeping intrusions into private communications without judicial warrants. The absence of clear safeguards such as necessity, proportionality, and time limitations contravenes established international standards under instruments like the ICCPR. Moreover, the law criminalizes vague offenses like “disrupting public opinion” or “insulting sacred values,” enabling prosecutors to target activists and ordinary users alike, fostering a climate of fear and self-censorship.
The 2022 Data and National Information Management Law intensifies this coercive legal environment. Framed as a data governance reform, the law compels public and private entities to surrender data to authorities under threat of license revocation or imprisonment. Notably, it does not require independent judicial oversight, turning compliance into a legal obligation and resistance into a punishable offense. This law also mandates strict data localization, ensuring Iranian users’ data is stored within reach of security agencies. As such, it solidifies a legal regime in which state surveillance is not merely permitted but institutionalised as a normative practice.
Complementing these laws are identification mandates that legally eliminate anonymity. Systems like SHAHKAR, SIAM, and HODA, implemented via regulatory directives from the CRA and SCC, require all digital activity to be tied to national ID numbers. This transforms online presence into a fully traceable identity record. Through these instruments, the law effectively outlaws anonymous digital participation, embedding state visibility into every online interaction. In this sense, the cyberspace is turned into a panopticon prison.
To compound the reach of these surveillance laws, Iran has institutionalized the denial of judicial accountability. The Administrative Justice Court, Iran’s main venue for challenging government decisions, is expressly barred from reviewing acts of the SCC, SCCR, and the SNSC, the very bodies driving surveillance policy. There is no constitutional court or effective mechanism to invoke Article 25 of the Constitution (the right to privacy) in practice. Even when online rights are nominally protected, citizens cannot legally enforce them. This legal vacuum enables flagrant violations, such as the public broadcasting of detainees’ private data by security agencies, without remedy.
Further, Iran’s laws lack core elements of due process. Judicial warrants are not required for many forms of interception; independent oversight bodies do not exist; and affected individuals often receive no notice or recourse. The vague phrasing of laws and the lack of purpose limitation or necessity principles mean that surveillance is normalized and largely unchallengeable. International standards, such as those articulated in General Comment No. 16 of the UN Human Rights Committee, demand that privacy intrusions be lawful, necessary, proportionate, and subject to effective oversight. Iran’s legal framework consistently fails to meet these benchmarks.
The state’s justification for these measures, national security and morality, further illustrates its instrumental use of law. While international jurisprudence permits some restrictions for these aims, such restrictions must be precise and demonstrably necessary. Iran’s use of broad, abstract appeals to “moral security” or “cultural integrity” fails these tests. During the 2022–23 protests, children were surveilled and arrested for social media use, in blatant contravention of international protections such as CRC Article 16, which guarantees children's privacy rights.
In sum, Iran’s legal system does not merely enable surveillance—it constructs it. Through strategic legislation, regulatory mandates, and judicial exemptions, the state has embedded repression into law. This legal apparatus creates a facade of legitimacy for what are, in substance, violations of international human rights norms. The result is a digital environment where the law serves not as a shield for citizens, but as a sword for the state.
CCTV and Hybrid Surveillance: Where Surveillance Meets the Street
As Iran’s systemic attack on privacy rights through its surveillance architecture extends beyond cyberspace, a growing emphasis has been placed on integrating digital tools into public spaces. The convergence of physical policing and digital monitoring, what may be called hybrid surveillance, has become a defining feature of the state’s approach to public order and dissent. This section explores how technologies like CCTV and facial recognition bring surveillance from screen to street.
Over the past several years, Iranian authorities have significantly expanded the deployment of sophisticated monitoring technologies as part of a broader strategy of social control. Closed-circuit television networks, automated image-analysis software, and facial recognition capabilities are now integrated into state security practices. These systems serve multiple purposes: they facilitate enforcement of compulsory veiling regulations and enable the identification, tracking, and detention of individuals participating in demonstrations critical of the government.
The practical operation of these tools became particularly visible during the nationwide protests in 2022-23. In that context, law-enforcement and security bodies relied extensively on recorded video material to single out demonstrators and initiate arrests. In September 2023, the official website of the IIRGC Cyber Command Centre disseminated CCTV images of alleged protesters, including digitally enhanced stills generated through advanced processing techniques, and solicited public assistance in identifying those depicted. Concurrently, Hassan Karami, then commander of the Police Special Units of the Islamic Republic of Iran, publicly stated that these units were developing an “intelligent system” intended to enable future detection and identification of protest participants.
Taken together, these developments indicate a deliberate institutional investment in technologically mediated surveillance mechanisms aimed at strengthening the state’s capacity to monitor, deter, and penalize dissent.
A documented example of technologically enabled repression can be found in the prosecution of three individuals following the 2022 protests in Tehran. In a trial held on November 7, the accused, Sahand Nourmohammadzadeh, Ali Houshmandi Fotovat, and Behdad Eskandarnezhad, were charged with serious national security offenses, including moharebeh (“enmity with God”), partly on the basis of surveillance footage. Authorities introduced CCTV recordings as evidence, allegedly depicting the defendants engaging in actions such as moving highway barricades and obstructing traffic. In the case of Nourmohammadzadeh, this evidence contributed to a death sentence and reports of psychological torture, including mock executions.



Visual material obtained from internal monitoring centres and shared with human rights investigators further confirms that Iranian authorities deploy advanced surveillance technologies, including facial recognition systems, across a network of government entities. These systems are capable of identifying individuals even when partially disguised, such as those wearing masks or lacking distinctive accessories like glasses. They can also detect anomalous patterns of presence in specific locations, flagging individuals for further monitoring. The use of such technologies suggests a high degree of precision in targeting individuals during protests and raises grave concerns about proportionality, due process, and the potential for discriminatory or politically motivated enforcement.


Originally implemented in public areas to track protest activity, Iran’s CCTV and facial recognition infrastructure has steadily expanded into more intimate and controlled environments, including schools. In the wake of student-led demonstrations within educational institutions, surveillance cameras have been installed inside classrooms, extending the state’s monitoring capabilities to minors in academic settings.
These technologies have also become central to the enforcement of mandatory veiling laws. A significant number of women detained, fined, or prosecuted for hijab violations have been identified through automated surveillance networks. Following the quelling of the 2022–2023 protest wave, the Islamic Republic reactivated the so-called Morality Police, whose operations had been paused at the height of the unrest.
In April 2024, authorities launched the Noor Plan, a comprehensive surveillance campaign purportedly aimed at upholding Islamic codes of conduct in public. This initiative involves deploying AI-powered facial recognition systems and CCTV cameras across public and private venues to detect violations of hijab laws or other behaviors deemed “anti-social.” Based on data collected by these systems, including video recordings and automated identity matches, authorities may issue summonses, financial penalties, or initiate legal proceedings. While the government frames the plan as a measure to preserve public morality and social order, legal observers have raised alarm over its sweeping scope, opaque implementation, and discriminatory targeting of women and dissenters. The plan reflects an intensifying merger of religious policing and digital surveillance, posing grave risks to individual privacy and civil liberties.
According to official statements reported by Mehr News Agency, Iranian law enforcement has confirmed the nationwide deployment of intelligent surveillance technologies in public spaces to identify individuals accused of breaching "societal norms", a term often used to justify enforcement of compulsory hijab laws. These systems automatically capture and analyse images of individuals, and in many cases, send notifications directly to alleged violators, including photographic evidence gathered through surveillance devices. This mechanized method has become a central feature of Iran’s broader apparatus for regulating public behaviour. Emphasizing the reliability of these tools, General Ahmadreza Radan, Chief Commander of the Law Enforcement Forces (FARAJA), declared, “Rest assured, these cameras will not make errors.” Such claims of infallibility raise legal and ethical concerns, particularly given the absence of independent oversight or appeal mechanisms for those targeted by the technology.
In April 2023, Javan Newspaper detailed a new enforcement tactic employed by Iranian police, whereby surveillance cameras are used to identify individuals allegedly violating compulsory hijab laws. The report included an image of a sample text message sent to a supposed offender, featuring a surveillance-captured photograph as evidence of non-compliance. This method reflects the increasing reliance on automated monitoring technologies to enforce dress codes, shifting the burden of surveillance from physical policing to digital systems. It also illustrates how technology is being instrumentalized to normalize state control over personal appearance and behaviour in public, often without due process or avenues for contestation.

In June 2023, Fars News Agency released a report showcasing the use of artificial intelligence (AI) to enforce Iran’s mandatory hijab laws. The broadcast featured video footage demonstrating how AI systems are deployed to detect and monitor women in public spaces who are deemed non-compliant with state-imposed dress codes. Notably, the report portrayed instances in which plainclothes individuals, acting without presenting official identification, intervened directly, confronting women, recording them, threatening legal consequences, and using smart surveillance tools to identify them. In some cases, personal data was subsequently made public. The publication of this footage, which was vastly disputed by experts to be authentic AI technology, aimed at instilling fear and deterring dissent, marking a further escalation in the state’s technology-driven campaign to control women’s bodies and behaviour. These practices raise grave legal and ethical concerns, including the erosion of privacy rights, the absence of procedural safeguards, and the normalization of extrajudicial surveillance and intimidation in public life.
From a legal perspective, the integration of AI-enabled identification with on-the-ground enforcement significantly intensifies concerns regarding privacy, due process, and proportionality. The systematic recording, biometric identification, and potential public disclosure of personal information, particularly in the absence of transparent safeguards or judicial oversight, raise serious questions under both constitutional protections of privacy and international human rights standards. The deployment of such technologies in ordinary public spaces risks normalizing pervasive surveillance and constitutes a disproportionate interference with individual autonomy, dignity, and freedom of expression, especially when targeted at women in the context of gender-based regulatory enforcement or protesters in the context of systemic and brutal crackdown.

Beyond the expanding deployment of facial recognition technologies by police forces, Iran’s judiciary has played a key role in formalizing surveillance-based enforcement of dress codes through legislative initiatives. In April 2023, the government submitted the so-called Family Support Bill by Promoting the Culture of Chastity and Hijab (commonly referred to as the Chastity and Hijab Bill) to Parliament. The bill explicitly authorizes the use of intelligent surveillance tools, including facial recognition and CCTV, to identify and penalize women who defy mandatory veiling laws.
Article 30 of the law mandates that the Law Enforcement Command (FARAJA) develop and enhance “intelligent systems for identifying individuals who commit unlawful acts,” using both stationary and mobile camera systems. Further expanding the surveillance apparatus, Article 61 compels a broad array of public and private actors, including banks, transportation companies, retail establishments, and residential complexes, to submit their CCTV footage to police upon request. Non-compliance carries severe penalties: public employees may be suspended for up to five years, business owners face income-based fines, and others may be subjected to criminal sanctions under Iran’s penal code. Additionally, all parties must retain surveillance footage for a minimum of 20 days, institutionalizing long-term data retention without clear privacy safeguards.
Despite public opposition and prior campaign promises to revoke the measure, the bill was approved by Parliament on September 20, 2023, and ratified by the Guardian Council in September 2024, entering into force as binding law. However, the practical implementation of surveillance-based hijab enforcement significantly predated the law’s passage. Authorities had already begun using facial recognition and CCTV footage to fine, identify, and prosecute women, demonstrating how enforcement mechanisms often precede formal legal codification.
The Chastity and Hijab law builds upon over a decade of legal scaffolding aimed at normalizing surveillance in Iran. Notably, in 2010, shortly after the mass protests of 2009, the Instruction for Monitoring Video Surveillance Systems was issued by the Country’s Security Council. This regulation marked the first attempt to unify and standardize surveillance systems nationwide and laid the foundation for the fully integrated monitoring regime that now facilitates gender-based control, political repression, and widespread violations of privacy rights.
The institutionalization of Iran’s nationwide surveillance regime has involved a series of executive directives aimed at centralizing control over video monitoring infrastructure. One such directive empowers provincial and municipal governors to designate specific private companies responsible for ensuring that businesses install surveillance cameras compatible with standardized software. This move facilitates the technical integration of disparate CCTV systems into centralized processing platforms, enabling authorities to aggregate and manage footage across sectors.
A major milestone in this process came with the issuance of the Instruction for the Deployment and Supervision of Intelligent Monitoring Systems by the Country’s Security Council on June 1, 2015. This regulatory framework, consisting of 14 chapters and 37 articles, mandated the formation of local Video Surveillance Councils (VSCs) within provincial and city administrations. Headed by the governor or the deputy for political-security affairs, these VSCs are charged with overseeing the creation and operation of unified smart surveillance systems at the local level.
The directive envisions the consolidation of all traffic-related and public safety camera networks, including municipal and commercial feeds, into a single, intelligent monitoring system. This includes establishing command centres with real-time access to camera outputs across urban spaces. For instance, in July 2022, then-Police Chief Ashtari inaugurated a new surveillance control hub in Isfahan and reported a 90% increase in the force’s monitoring capabilities due to its access to both fixed and mobile camera systems. He also acknowledged that only 10 provinces had implemented such integrated centres, indicating an ongoing expansion of the national surveillance grid. This centralization model illustrates how surveillance in Iran is not only expanding in scale but becoming increasingly sophisticated in its ability to monitor civilian behaviour in both traffic and security contexts.
Operating under the authority of the VSCs, municipal governments are empowered to contract private companies, via public tenders, to develop centralized, intelligent video surveillance systems. These projects involve the unification, installation and integration of extensive CCTV infrastructure across cities. In executing these contracts, private sector entities have procured surveillance equipment, including high-resolution cameras and related technologies, from international suppliers, reportedly including vendors based in Europe and China. This arrangement highlights the transnational dimension of Iran’s surveillance apparatus, raising critical questions about foreign complicity in enabling state overreach and privacy violations.
As Iranian municipalities increasingly partner with private contractors to roll out intelligent CCTV infrastructure, this trend is not merely a modernization of urban security, it lays the groundwork for a centralized, unified, AI-compatible surveillance regime. Operating under the authority of the VSCs, municipalities are tasked with integrating surveillance systems city-wide, incorporating all traffic and security cameras into unified platforms. The compatibility requirements for camera hardware and software, mandated through procurement rules, are not arbitrary technical decisions. Rather, they are a calculated preliminary step toward mass video surveillance capable of supporting AI image processing and facial recognition technologies. These technical standards pave the way for full interoperability between local CCTV systems and national-level identification systems through platforms such as SAPTAM.
SAPTAM (also referred to as SITAM), a centralized platform designed for the unification, centralisation and integration visual monitoring of public spces and commercial establishments, has raised significant legal and human rights concerns under international privacy norms. The system requires businesses and public-facing venues to install surveillance cameras that meet SAPTAM's technical specifications and to undergo registration, inspection, and certification processes. In doing so, SAPTAM collects detailed identifying information about both legal entities and individuals, while granting police the authority to access recorded footage upon the occurrence of any criminal incident.
From a legal standpoint, SAPTAM's compliance with international human rights standards is deeply flawed. First, although the program is formalized through administrative directives, it lacks a clear basis in legislation passed by Iran's parliament. There is no transparent statutory limit on the scope of police access, nor clarity on whether the system is governed by predictable and reviewable legal standards. This absence of formal legality undermines the legitimacy of the entire framework.
Second, while the stated objective, enhancing public safety, may qualify as a legitimate aim under human rights law, the necessity and proportionality of SAPTAM remain unproven. There is no indication that less intrusive methods of policing have been considered, nor that the system’s pervasive reach is justified by any compelling evidence of efficacy. SAPTAM authorizes indiscriminate surveillance of all individuals in public spaces, including those with no connection to criminal activity, thereby exceeding the bounds of what is considered proportionate under international law.
Furthermore, the system fails to meet core principles of transparency and data subject rights. Individuals are not adequately informed that they are under surveillance, nor are they granted the right to access, correct, or delete personal data collected about them. Facial recognition and other smart analytics may be employed without disclosure or limitation, heightening the risk of function creep and discriminatory enforcement.
Finally, the lack of independent oversight is particularly troubling. Control over SAPTAM's operation rests with law enforcement and local executive authorities, with no provision for judicial or quasi-judicial review of data access or use. This internalization of surveillance powers within security institutions violates the requirement under international law for supervision by an independent authority.
In sum, the SAPTAM surveillance framework epitomizes Iran’s shift toward a fully integrated, AI-augmented surveillance state. By embedding mandatory technical standards at the municipal level, and circumventing democratic legislative processes, the state is quietly constructing a terrifying panopticon surveillance apparatus that monitors every aspect of everyday life in bother real and digital worlds.
Conclusion
The institutional and legal framework governing cyberspace in the Islamic Republic of Iran reveals a deliberate architecture of digital authoritarianism. Anchored in opaque governance structures dominated by unelected high councils and security organs, and reinforced by coercive legal instruments, this system has normalized surveillance and control as pillars of digital policy. Iran’s legislation, from the Computer Crimes Law to the Chastity and Hijab Law, not only facilitates mass data collection and interception, but also fails to provide the necessary safeguards recognized under international human rights law, including legality, necessity, proportionality, transparency, and effective remedy.
Crucially, the state's pervasive use of CCTV, AI-driven facial recognition, and identification systems like SHAHKAR and SAMAVA signal an alarming convergence of physical and digital surveillance making anonymity for citizens nonexistent. These technologies, often integrated without public oversight or democratic accountability, are not isolated tools of enforcement but essential components of a broader strategy to suppress dissent, enforce ideological conformity, and dismantle the right to privacy.
At the same time, institutional pluralism has been hollowed out by parallel rulemaking authorities whose edicts bypass the elected parliament and escape judicial scrutiny. In turn, the elected bodies are using constitutional loopholes to minimise transparency and circumvent public scrutiny and democratic due process. This dispersal of accountability, backed by a legal regime that criminalizes expression and shields surveillance from challenge, ensures that no meaningful redress is available to citizens.
Taken together, Iran’s digital governance regime represents not merely a failure to protect privacy, but an intentional and sophisticated legal design to violate it. Reversing this trajectory will require dismantling the architecture of impunity, restoring the rule of law, and aligning domestic practices with Iran’s obligations under international human rights law. Until such reforms take place, the Iranian people remain subject to an expanding surveillance state that regards digital life not as a domain of rights, but as a frontier of control.