You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

November 14, 2019

Cambodia Enacts a New E-commerce Law and a Consumer Protection Law

In support of Cambodia’s rapidly growing economy, the Cambodian government enacted the Law on Electronic Commerce (E-commerce Law) and the Law on Consumer Protection (Consumer Protection Law) on November 2, 2019. Both of these new laws change the legal landscape in important ways for businesses under their purview. 

E-commerce Law

The E-commerce Law regulates domestic and cross-border e-commerce activities in Cambodia, establishes legal certainty for electronic transactions, and enacts a number of important protections for consumers.  

The E-commerce Law broadly applies to all commercial and civil acts, documents, and transactions executed via an electronic system, except those that are related to powers of attorney, wills and successions, and real estate. The E-commerce Law grants the Cambodian government the authority to issue further regulations to limit the law’s scope; thus it will be necessary to monitor whether other types of transactions are later excluded from the scope of the law. 

The E-commerce Law has 12 chapters, 67 articles, and one annex. 

  • The first chapter contains general provisions on the aim, purpose, and scope of the law, as briefly described above, and refers to the annex, which contains a glossary of 38 key terms used throughout the law.  
  • The second and third chapters deal with the validity and process of electronic communications, including clarifying the regulatory requirements for recognizing electronic agreements and e-signatures. These chapters also discuss certain technical matters, such as when and where electronic communications are considered sent and received. 
  • The fourth chapter addresses the security of electronic records and e-signatures, and specifically prohibits identity theft. 
  • The fifth chapter is material to electronic-commerce service providers and intermediaries. This chapter covers potential liabilities for third-party content on platforms and content takedown requests. Furthermore, service providers and intermediaries, possibly including foreign entities making their platforms accessible in Cambodia, may be subject to a licensing regime and codes of conduct in Cambodia.
  • The sixth chapter contains legal provisions on consumer protection on e-commerce platforms, including matters on adequate information requirements, scams, malicious codes, and data protection. Interestingly, this chapter specifically requires both domestic and foreign e-commerce businesses, regardless of their places of business, to comply with the legal obligations regarding unsolicited emails. 
  • The seventh chapter governs electronic acts and transactions by the Cambodian government, which may facilitate governmental agencies using online application forms in the future. 
  • The eighth chapter gives legal recognition to the use of evidence in an electronic form in Cambodian legal proceedings.
  • The ninth chapter further regulates electronic fund transfers and payments. Banking and financial institutions should be aware of this chapter as it imposes certain obligations and liabilities on them concerning electronic fund transfers and payments. For instance, when a banking and financial institution has received a customer’s notification that his or her electronic payment instrument has been lost or stolen, banking and financial institutions are now liable for any transactions occurring after the notification.
  • The tenth chapter designates the Ministry of Commerce and the Ministry of Posts and Telecommunications as the competent authorities who may issue warnings and disciplinary sanction decisions on e-commerce matters.
  • The eleventh chapter outlines a number of penalties, such as fines and imprisonments, on persons violating provisions of the E-commerce Law. 
  • The last chapter notes that the E-commerce Law will not be implemented until May 2, 2020, which leaves time for government agencies to prepare any necessary implementing regulations required under the law, and for private companies to prepare for compliance. 

As businesses have almost six months to prepare for the implementation of the E-commerce Law, we recommend that they familiarize themselves with the new requirements of the law and watch out for additional implementing regulations that are likely to be released before the full implementation of the law on May 2, 2020. 

Consumer Protection Law

The Consumer Protection Law establishes rules to guarantee the rights of consumers and to ensure that businesses conduct commercial competition in Cambodia fairly. The Consumer Protection Law applies to any person who conducts any trading activities with consumers in Cambodia, regardless of whether the trading activities are for profit. The law applies to the sale of goods, services, and real rights over immovable property.

The Consumer Protection Law has 11 chapters and 51 articles.

  • The first three chapters touch on introductory and general provisions, and explain the aims and purposes of the law and key definitions. Importantly, these chapters establish the National Committee on Consumer Protection (NCCP) as Cambodia’s competent authority for consumer protection and empower consumers in each industry to form an association to protect their interests.
  • The fourth and fifth chapters regulate unfair trading activities and unfair practices. These deal, for example, with false, misleading, or deceptive advertisements, and business models equivalent to pyramid schemes.
  • The sixth chapter sets out minimum information standards that businesses must meet in connection with consumers, such as labeling requirements. These minimum information standards will be more specifically set by the relevant industry regulators. One notable element of the standards is that all information must be provided in the Khmer language.
  • The seventh to the ninth chapters establish the procedures for the NCCP to receive consumer complaints, carry out investigations, and issue decisions, and the rules for appealing the NCCP’s decisions. 
  • The tenth and eleventh chapters present a number of penalties for non-compliance with the Consumer Protection Law, including disciplinary sanctions, fines, and imprisonment. 

The Consumer Protection Law became effective upon promulgation on November 2, 2019, and prudent businesses should therefore immediately review the law to understand their compliance requirements and prepare accordingly.

For more information, please contact our Phnom Penh office on [email protected] or at +855 23 964 210.

RELATED INSIGHTS​ 

December 11, 2025
On December 10, 2025, the National Assembly of Vietnam passed a new Cybersecurity Law, which will take effect on July 1, 2026. The new Cybersecurity Law was developed based on the consolidation of the 2018 Cybersecurity Law and the 2015 Law on Network Information Security. While the final approved version of the new Cybersecurity Law has not yet been published, according to official reports, the following notable requirements are confirmed to be included: The new Cybersecurity Law dedicates a specific article to prohibited acts related to cybersecurity, under which it strictly prohibits posting or disseminating information online that propagandizes against the Socialist Republic of Vietnam. The law also prohibits, among other things, (i) the appropriation, trading, seizure, or intentional disclosure of information classified as state secrets, work secrets, business secrets, personal secrets, family secrets, and private life; (ii) intentionally eavesdropping, recording, or filming online conversations without authorization; and (iii) the use of artificial intelligence (AI) or new technologies to conduct prohibited acts. The Ministry of Public Security (MPS) has the authority to require enterprises providing telecommunications, internet, and online services, as well as system administrators, to remove information violating cybersecurity laws from systems under their management. The MPS is also assigned responsibility for ensuring information security in cyberspace and data security, establishing mechanisms for IP address identity management, verifying digital account registration information, and issuing warnings and sharing information on cybersecurity threats. Information systems are classified into five levels (similar to the 2015 Law on Network Information Security) based on the degree of harm to national security and social order if an incident occurs. The MPS is the lead agency assisting the government in state management of cybersecurity. The Ministry of National Defense is responsible for managing military information systems, and the Government Cipher Committee manages cryptographic and cipher
December 4, 2025
Thailand has expanded the circumstances under which state agencies may bypass competitive bidding procedures to address urgent security challenges. On November 28, 2025, Thailand’s Ministry of Finance published the Ministerial Regulation Determining Cases of Procurement by Specific Method (No. 6) B.E. 2568 in the Royal Gazette, introducing a new pathway for procuring supplies and services needed to address cyber and military threats that may affect the stability of government agencies or the nation. For technology vendors, cybersecurity firms, and defense contractors, this regulatory change creates immediate opportunities to engage directly with government buyers facing urgent security challenges. New Fast-Track Category for Security Threats The regulation amends Thailand’s Public Procurement and Supplies Management Act B.E. 2560 (2017) to add a new category of procurement that qualifies for the “specific method”—a noncompetitive, direct selection process. Previously, agencies could use this expedited method only in limited circumstances, such as emergencies, cases with proprietary technology requirements, or national security operations. The new provision explicitly covers procurement of supplies related to preventing or resolving cyber or military threats that could impact the stability of a state agency or the country. This addition recognizes the urgent nature of modern security challenges, where competitive bidding timelines may leave agencies vulnerable during critical threat windows. State agencies dealing with active cyberattacks, preparing defensive measures against anticipated threats, or responding to military security concerns can now move directly to negotiate with qualified vendors rather than conducting lengthy public tender processes. Vendor Considerations Vendors offering cybersecurity solutions now have a regulatory avenue to work directly with government clients when stability concerns are present. These solutions include threat detection systems, anti-ransomware tools, incident response services, firewalls, and security consulting. Similarly, defense contractors providing military equipment or specialized security supplies can pursue direct engagement channels where traditional procurement methods would create
December 3, 2025
Thailand’s Civil Court has issued a regulation targeting the use of artificial intelligence (AI) in the preparation of pleadings and other documents submitted to the court. Effective November 17, 2025, the regulation aligns with September 2025 guidance from the president of the Supreme Court, and aims to safeguard accuracy, transparency, and public confidence in civil adjudication. The regulation applies to all parties submitting pleadings or any documents to the Civil Court that are prepared using AI tools or contain AI-generated content. It subjects AI used for these purposes to strict requirements on verification, disclosure, and accountability. Core Obligations The regulation imposes four principal obligations: Lawyers who use AI remain subject to duties of honesty, responsibility to the court, professional standards, and legal ethics, including the duty to assess the appropriateness of the AI tool for the work. Parties and lawyers must verify the accuracy and completeness of all facts, legal provisions, and citations in AI-generated content before submission. Parties and lawyers must disclose to the court any AI-generated content by clearly marking the beginning and end of the AI-generated portion with prescribed statements (see below). Additionally, a certification confirming the use of AI must be provided at the end of the pleading or document, stating that AI was used for certain portions and that the party has reviewed and certifies the accuracy of factual and legal content. Parties and lawyers bear the same full legal and ethical responsibility for AI-generated content as they do for personally authored documents; they cannot evade responsibility or avoid liability by citing AI-related errors. Likewise, parties must ensure that any AI-generated content is truthful, accurate, and unbiased. Prescribed Disclosure Language Each instance of AI-generated content must be preceded by the statement “[The following content was prepared using artificial intelligence]” and must end with “[End
November 25, 2025
Food safety incidents can emerge without warning, requiring businesses to act swiftly to protect consumers and comply with regulatory obligations. Across Southeast Asia, Thailand, Vietnam, and Indonesia have each developed comprehensive food recall frameworks designed to ensure rapid removal of unsafe products from the market while holding businesses accountable for compliance failures. While these three jurisdictions share common objectives—protecting public health and ensuring food safety—each has crafted distinct regulatory approaches reflecting their unique administrative structures, enforcement priorities, and legal traditions. Understanding these differences is essential for food businesses operating in the region, as recall procedures, timelines, reporting requirements, and penalties vary significantly across borders. This guide, available through the button below, examines the food recall regulations in Indonesia, Thailand, and Vietnam, providing practical guidance on legal requirements, procedural steps, and compliance obligations in each market.