You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

November 14, 2019

Cambodia Enacts a New E-commerce Law and a Consumer Protection Law

In support of Cambodia’s rapidly growing economy, the Cambodian government enacted the Law on Electronic Commerce (E-commerce Law) and the Law on Consumer Protection (Consumer Protection Law) on November 2, 2019. Both of these new laws change the legal landscape in important ways for businesses under their purview. 

E-commerce Law

The E-commerce Law regulates domestic and cross-border e-commerce activities in Cambodia, establishes legal certainty for electronic transactions, and enacts a number of important protections for consumers.  

The E-commerce Law broadly applies to all commercial and civil acts, documents, and transactions executed via an electronic system, except those that are related to powers of attorney, wills and successions, and real estate. The E-commerce Law grants the Cambodian government the authority to issue further regulations to limit the law’s scope; thus it will be necessary to monitor whether other types of transactions are later excluded from the scope of the law. 

The E-commerce Law has 12 chapters, 67 articles, and one annex. 

  • The first chapter contains general provisions on the aim, purpose, and scope of the law, as briefly described above, and refers to the annex, which contains a glossary of 38 key terms used throughout the law.  
  • The second and third chapters deal with the validity and process of electronic communications, including clarifying the regulatory requirements for recognizing electronic agreements and e-signatures. These chapters also discuss certain technical matters, such as when and where electronic communications are considered sent and received. 
  • The fourth chapter addresses the security of electronic records and e-signatures, and specifically prohibits identity theft. 
  • The fifth chapter is material to electronic-commerce service providers and intermediaries. This chapter covers potential liabilities for third-party content on platforms and content takedown requests. Furthermore, service providers and intermediaries, possibly including foreign entities making their platforms accessible in Cambodia, may be subject to a licensing regime and codes of conduct in Cambodia.
  • The sixth chapter contains legal provisions on consumer protection on e-commerce platforms, including matters on adequate information requirements, scams, malicious codes, and data protection. Interestingly, this chapter specifically requires both domestic and foreign e-commerce businesses, regardless of their places of business, to comply with the legal obligations regarding unsolicited emails. 
  • The seventh chapter governs electronic acts and transactions by the Cambodian government, which may facilitate governmental agencies using online application forms in the future. 
  • The eighth chapter gives legal recognition to the use of evidence in an electronic form in Cambodian legal proceedings.
  • The ninth chapter further regulates electronic fund transfers and payments. Banking and financial institutions should be aware of this chapter as it imposes certain obligations and liabilities on them concerning electronic fund transfers and payments. For instance, when a banking and financial institution has received a customer’s notification that his or her electronic payment instrument has been lost or stolen, banking and financial institutions are now liable for any transactions occurring after the notification.
  • The tenth chapter designates the Ministry of Commerce and the Ministry of Posts and Telecommunications as the competent authorities who may issue warnings and disciplinary sanction decisions on e-commerce matters.
  • The eleventh chapter outlines a number of penalties, such as fines and imprisonments, on persons violating provisions of the E-commerce Law. 
  • The last chapter notes that the E-commerce Law will not be implemented until May 2, 2020, which leaves time for government agencies to prepare any necessary implementing regulations required under the law, and for private companies to prepare for compliance. 

As businesses have almost six months to prepare for the implementation of the E-commerce Law, we recommend that they familiarize themselves with the new requirements of the law and watch out for additional implementing regulations that are likely to be released before the full implementation of the law on May 2, 2020. 

Consumer Protection Law

The Consumer Protection Law establishes rules to guarantee the rights of consumers and to ensure that businesses conduct commercial competition in Cambodia fairly. The Consumer Protection Law applies to any person who conducts any trading activities with consumers in Cambodia, regardless of whether the trading activities are for profit. The law applies to the sale of goods, services, and real rights over immovable property.

The Consumer Protection Law has 11 chapters and 51 articles.

  • The first three chapters touch on introductory and general provisions, and explain the aims and purposes of the law and key definitions. Importantly, these chapters establish the National Committee on Consumer Protection (NCCP) as Cambodia’s competent authority for consumer protection and empower consumers in each industry to form an association to protect their interests.
  • The fourth and fifth chapters regulate unfair trading activities and unfair practices. These deal, for example, with false, misleading, or deceptive advertisements, and business models equivalent to pyramid schemes.
  • The sixth chapter sets out minimum information standards that businesses must meet in connection with consumers, such as labeling requirements. These minimum information standards will be more specifically set by the relevant industry regulators. One notable element of the standards is that all information must be provided in the Khmer language.
  • The seventh to the ninth chapters establish the procedures for the NCCP to receive consumer complaints, carry out investigations, and issue decisions, and the rules for appealing the NCCP’s decisions. 
  • The tenth and eleventh chapters present a number of penalties for non-compliance with the Consumer Protection Law, including disciplinary sanctions, fines, and imprisonment. 

The Consumer Protection Law became effective upon promulgation on November 2, 2019, and prudent businesses should therefore immediately review the law to understand their compliance requirements and prepare accordingly.

For more information, please contact our Phnom Penh office on [email protected] or at +855 23 964 210.

RELATED INSIGHTS​ 

April 3, 2026
On March 16, 2026, Vietnam’s Ministry of Public Security released a draft version of a new Decree on the Prevention and Combating of Cybercrime and High-Tech Crime to replace the currently effective Decree 25/2014/ND-CP. In the draft, the ministry has proposed a comprehensive regulatory framework aimed at addressing violations occurring within the cybersecurity domain, including measures related to intellectual property. Acts of Online IP Infringement Article 9 of the draft decree notably introduces specific provisions addressing online intellectual property infringement, with detailed lists of acts considered to constitute infringement in the online environment. Copyright and related rights infringement includes: Uploading or sharing works, performances, sound recordings, video recordings, broadcasts, computer programs, software, research, documents, theses, or other intellectual creations on digital platforms without the consent of the rights holder. Unauthorized livestreaming of copyrighted television programs, sporting events, or artistic performances. Uploading, sharing, storing, transmitting, or providing links to infringing works or digital content via websites, social networks, applications, or digital platforms. Providing or using software, tools, devices, or access codes to circumvent technological protection measures or evade lawful control mechanisms implemented by rights holders. Using artificial intelligence (AI) tools to replicate the ideas or structure of another person’s work without significant new creativity or without proper attribution, thereby causing damage to the original author. Industrial property infringement includes: Manufacturing, trading, advertising, or distributing counterfeit goods bearing counterfeit trademarks, geographical indications, or industrial designs, as well as goods infringing industrial property rights through online platforms. Unauthorized registration, appropriation, or use of domain names, account names, or digital identifiers that create confusion regarding the rights holder or the origin of goods or services. Producing, using, or offering for sale products containing all or part of a patented invention via online platforms. Advertising or introducing products with technical features or characteristics identical
April 3, 2026
Thailand’s Securities and Exchange Commission (SEC) has established a comprehensive governance framework for the use of artificial intelligence and machine learning (AI/ML) in the capital markets. The framework provides guidance to capital market business operators on understanding the risks associated with AI/ML implementation and adopting appropriate practices to build public confidence in Thailand’s capital markets. While the guidelines are principle-based rather than prescriptive, they reflect the SEC’s expectations for responsible AI/ML governance and are likely to inform supervisory activities and industry standards going forward. Scope The framework applies to capital market business operators supervised by the SEC. This includes, for example, securities and derivatives firms, asset management companies, mutual fund and private fund managers, investment advisors and investment consultants (including robo-advisory service providers), derivatives intermediaries, and other licensed intermediaries and market operators in the Thai capital markets that deploy AI/ML in their operations. Core Principles of the Guidelines The framework is presented as a best-practice manual rather than prescriptive regulation, providing guidance that regulated entities may apply to their AI/ML governance and risk management as appropriate. While currently nonbinding, the guidelines signal the SEC’s expectations for the sector, particularly in relation to other binding SEC regulations such as those covering IT risk management and market conduct. The guidelines name four core principles for AI/ML deployment: Fairness: Design and develop AI/ML with consideration for fairness, equality, and social diversity to prevent discrimination against individuals or groups. Legal and ethical compliance: Ensure AI/ML use aligns with applicable laws, ethical standards, and organizational values and policies. Accountability: Establish clear responsibility—both internally and externally—for AI/ML activities and outcomes. Transparency: Provide adequate disclosure to users about AI/ML use, including explainability of decisions and traceability of activities. AI/ML Best Practices The guidelines prescribe best practices across four stages of the AI/ML lifecycle, as described below.
April 2, 2026
Thailand’s Personal Data Protection Act (PDPA) enforcement has entered a new phase, and the insurance industry is squarely in the regulatory spotlight. The Personal Data Protection Committee (PDPC) considers insurers “large-scale” processors of sensitive data—including health records, financial information, and biometric data—making the sector a focal point for enforcement action. In August 2025 alone, the PDPC issued administrative fines totaling THB 21.5 million, and fines for individual violations have ranged from THB 50,000 to THB 2 million. The PDPC has also deployed its “Eagle Eye Crawler,” an AI-driven surveillance tool that monitors websites around the clock for data leaks and noncompliant privacy notices. This article highlights the key regulatory developments directly affecting insurers and outlines practical steps toward compliance. What Has Changed: OIC and PDPC Alignment The Office of Insurance Commission (OIC) has synchronized its sector-specific rules with the PDPA through the Notification on Customer Personal Data Protection (No. 2) B.E. 2568 (2025). The combined effect of the PDPC’s general enforcement push and the OIC’s sectoral guidance creates four critical compliance areas for insurers. Consent unbundling. Consent for marketing must be strictly separated from the core insurance contract; bundling marketing consent into the policy application is no longer permissible. Agent and intermediary oversight. Insurance intermediaries are generally classified as data processors, meaning that insurers—as data controllers—must provide specific written instructions and security protocols to all agents and brokers. A 2026 enforcement trend shows controllers being held liable for the “weak security” of their vendors and downstream processors. Enhanced privacy notices. Insurers must provide a summary privacy notice alongside the full policy, plainly stating categories of data, purposes, lawful bases, disclosure recipients, cross-border transfers, retention periods, data subject rights, and easy marketing opt-out channels. DPO registration and ROPA. All organizations involved in “regular or systematic monitoring of data subjects on
March 30, 2026
In response to an emerging crisis on food safety, the government of Vietnam promulgated Decree No. 46/2026/ND-CP (Decree 46) on January 26, 2026, and Resolution No. 66.13/2026/NQ-CP (Resolution 66.13) on January 27, 2026, setting out a number of substantive changes to the procedure and strict requirements for the declaration, registration, and importation of food products. Both instruments took effect upon issuance. However, shortly after they entered into force, food businesses encountered significant implementation challenges, particularly with respect to state inspection procedures at the customs clearance stage for imported products. In response, the government issued Resolution No. 09/2026/NQ-CP (Resolution 09) on February 4, 2026, temporarily suspending Decree 46 and Resolution 66.13 until a new effective date of April 16, 2026. Continued Suspension of Implementation of Decree 46 and Resolution 66.13 After considering feedback gathered by the Ministry of Health from food businesses and other stakeholders during the suspension period, the Vietnam Government Office issued a notice on March 20, 2026, agreeing to extend the suspension until the issuance of an amended Law on Food Safety and its guiding decree. Following this notice, on March 22, 2026, the Ministry of Health prepared a draft resolution to implement the notice and replace Resolution 09. Under the draft resolution, the effectiveness of Decree 46 and Resolution No. 66.13 would continue to be suspended until the amended Law on Food Safety takes effect, except for the provisions under Resolution 66.13 allowing flexibility in documents evidencing product efficacy, which would take effect on April 16, 2026, and remain effective until the Law on Food Safety is replaced (but not later than February 28, 2027). Accordingly, for products subject to the registration declaration procedure, such as health supplements, efficacy may be substantiated by either (i) scientific evidence supporting the declared function and effects of the product