You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

November 14, 2019

Cambodia Enacts a New E-commerce Law and a Consumer Protection Law

In support of Cambodia’s rapidly growing economy, the Cambodian government enacted the Law on Electronic Commerce (E-commerce Law) and the Law on Consumer Protection (Consumer Protection Law) on November 2, 2019. Both of these new laws change the legal landscape in important ways for businesses under their purview. 

E-commerce Law

The E-commerce Law regulates domestic and cross-border e-commerce activities in Cambodia, establishes legal certainty for electronic transactions, and enacts a number of important protections for consumers.  

The E-commerce Law broadly applies to all commercial and civil acts, documents, and transactions executed via an electronic system, except those that are related to powers of attorney, wills and successions, and real estate. The E-commerce Law grants the Cambodian government the authority to issue further regulations to limit the law’s scope; thus it will be necessary to monitor whether other types of transactions are later excluded from the scope of the law. 

The E-commerce Law has 12 chapters, 67 articles, and one annex. 

  • The first chapter contains general provisions on the aim, purpose, and scope of the law, as briefly described above, and refers to the annex, which contains a glossary of 38 key terms used throughout the law.  
  • The second and third chapters deal with the validity and process of electronic communications, including clarifying the regulatory requirements for recognizing electronic agreements and e-signatures. These chapters also discuss certain technical matters, such as when and where electronic communications are considered sent and received. 
  • The fourth chapter addresses the security of electronic records and e-signatures, and specifically prohibits identity theft. 
  • The fifth chapter is material to electronic-commerce service providers and intermediaries. This chapter covers potential liabilities for third-party content on platforms and content takedown requests. Furthermore, service providers and intermediaries, possibly including foreign entities making their platforms accessible in Cambodia, may be subject to a licensing regime and codes of conduct in Cambodia.
  • The sixth chapter contains legal provisions on consumer protection on e-commerce platforms, including matters on adequate information requirements, scams, malicious codes, and data protection. Interestingly, this chapter specifically requires both domestic and foreign e-commerce businesses, regardless of their places of business, to comply with the legal obligations regarding unsolicited emails. 
  • The seventh chapter governs electronic acts and transactions by the Cambodian government, which may facilitate governmental agencies using online application forms in the future. 
  • The eighth chapter gives legal recognition to the use of evidence in an electronic form in Cambodian legal proceedings.
  • The ninth chapter further regulates electronic fund transfers and payments. Banking and financial institutions should be aware of this chapter as it imposes certain obligations and liabilities on them concerning electronic fund transfers and payments. For instance, when a banking and financial institution has received a customer’s notification that his or her electronic payment instrument has been lost or stolen, banking and financial institutions are now liable for any transactions occurring after the notification.
  • The tenth chapter designates the Ministry of Commerce and the Ministry of Posts and Telecommunications as the competent authorities who may issue warnings and disciplinary sanction decisions on e-commerce matters.
  • The eleventh chapter outlines a number of penalties, such as fines and imprisonments, on persons violating provisions of the E-commerce Law. 
  • The last chapter notes that the E-commerce Law will not be implemented until May 2, 2020, which leaves time for government agencies to prepare any necessary implementing regulations required under the law, and for private companies to prepare for compliance. 

As businesses have almost six months to prepare for the implementation of the E-commerce Law, we recommend that they familiarize themselves with the new requirements of the law and watch out for additional implementing regulations that are likely to be released before the full implementation of the law on May 2, 2020. 

Consumer Protection Law

The Consumer Protection Law establishes rules to guarantee the rights of consumers and to ensure that businesses conduct commercial competition in Cambodia fairly. The Consumer Protection Law applies to any person who conducts any trading activities with consumers in Cambodia, regardless of whether the trading activities are for profit. The law applies to the sale of goods, services, and real rights over immovable property.

The Consumer Protection Law has 11 chapters and 51 articles.

  • The first three chapters touch on introductory and general provisions, and explain the aims and purposes of the law and key definitions. Importantly, these chapters establish the National Committee on Consumer Protection (NCCP) as Cambodia’s competent authority for consumer protection and empower consumers in each industry to form an association to protect their interests.
  • The fourth and fifth chapters regulate unfair trading activities and unfair practices. These deal, for example, with false, misleading, or deceptive advertisements, and business models equivalent to pyramid schemes.
  • The sixth chapter sets out minimum information standards that businesses must meet in connection with consumers, such as labeling requirements. These minimum information standards will be more specifically set by the relevant industry regulators. One notable element of the standards is that all information must be provided in the Khmer language.
  • The seventh to the ninth chapters establish the procedures for the NCCP to receive consumer complaints, carry out investigations, and issue decisions, and the rules for appealing the NCCP’s decisions. 
  • The tenth and eleventh chapters present a number of penalties for non-compliance with the Consumer Protection Law, including disciplinary sanctions, fines, and imprisonment. 

The Consumer Protection Law became effective upon promulgation on November 2, 2019, and prudent businesses should therefore immediately review the law to understand their compliance requirements and prepare accordingly.

For more information, please contact our Phnom Penh office on [email protected] or at +855 23 964 210.

RELATED INSIGHTS​ 

August 1, 2025
Thailand’s Personal Data Protection Committee (PDPC) announced to the press on August 1, 2025, that it had issued eight new administrative fines under Thailand’s Personal Data Protection Act B.E. 2562 (2019) (PDPA) in five cases of noncompliance by public and private entities. The enforcement actions reflect a growing commitment by the PDPC to penalize noncompliance across all sectors, regardless of organizational type or size. The total amount imposed to date was approximately THB 21.5 million (approx. USD 654,690), underscoring the financial risks tied to PDPA violations. The five cases—one involving a state agency and the remainder in the private sector—are summarized below. Case 1: State Agency Providing Online Services to the Public The order in this case stemmed from a cyberattack on a state agency’s web app, resulting in personal data of 200,000 data subjects being leaked to and sold on the dark web. The software developer was also found to have implemented no privacy by design, lacked an access control system, had no data breach prevention measures, and failed to conduct risk assessments or review existing security measures. Key noncompliance identified: Lack of appropriate security measures Weak password protection No risk assessment or ongoing review of security measures No data processing agreement with software developer that acted as data processor The state agency and the developer were each fined THB 153,120 (approx. USD 4,670). Case 2: Private Hospital This case involved a hospital that engaged an individual contractor to destroy patient medical record documents. However, the contractor stored the documents at their own premises, failed to follow the required destruction protocols, and ultimately used the medical records to wrap sweets, resulting in the leak of over 1,000 records during the destruction process. The contractor also failed to notify the hospital of the data breach. Although there was a
August 1, 2025
On July 30, 2025, Myanmar’s Cybersecurity Law No. 1/2025 came into effect with the State Administration Council’s issuance of Notification 113/2025. The law, which was enacted on January 1, 2025, aims to regulate various aspects of digital security and online activities. Below are some key provisions, implications, and penalties under the Cybersecurity Law. Extraterritorial penalties. The law contains an important provision that authorizes penalties against Myanmar citizens who are found guilty of violations, even if these occur outside the country’s borders. VPN definition and regulation. Virtual private networks (VPNs) are defined by this law as specific systems that function as backup networks by using technological means in order to ensure the safety of linking networks to each other. This definition sets the framework for subsequent regulations and penalties associated with VPN usage. The law does not restrict individuals or entities from using VPNs; it regulates VPN service providers. Penalties for unapproved VPN services. Establishing a VPN or providing VPN services without approval from the designated ministry (to be appointed later by the government) can result in significant penalties. For individuals, the punishment may be imprisonment for 1–6 months, a fine of MMK 1–10 million (approx. USD 476–4,760), or both, with the proceeds of the violation being confiscated. If the violator is a company or organization, the minimum fine will be MMK 10 million, and the proceeds will be confiscated. Government oversight. The ministry designated by the government is authorized to investigate and take control of cybersecurity services and digital platform services for national defense and security purposes, or upon request from a government department or organization in accordance with respective laws. Licensing requirements. The Cybersecurity Law introduces two types of licenses, valid for a period of 3–10 years, for (1) cybersecurity services and (2) digital platform providers. Digital platforms with
August 1, 2025
On July 21, 2025, Thailand’s National Cyber Security Agency (NCSA) released a draft amendment to the Cybersecurity Act B.E. 2562 (2019) for public hearing, aiming to address the rapid evolution of technology and increasing complexity of cyber threats. The proposed changes to the country’s cybersecurity framework would extend regulatory oversight to cloud service providers and data center operators hosting data for critical information infrastructure (CII) organizations regulated under the Cybersecurity Act. The NCSA will accept comments on the draft until August 5, 2025. Following the close of the public consultation period, the draft amendment will be subject to further revision during the legislative process. Key proposed amendments are discussed below. Expanded Critical Infrastructure Scope The Cybersecurity Act currently applies only to state agencies, supervising or regulating organizations, and designated CII organizations as announced by the National Cyber Security Committee (NCSC). It defines CII organizations as public or private organizations related to or providing national security, significant public services, banking and finance, information technologies, telecommunications, transportation and logistics, energy and public utilities, or public health. The draft amendment expands the scope of CII organizations to include public and private organizations related to or providing industrial work (to be further defined in subregulations) as well as service providers that store or possess data for CII organizations, such as cloud and data center service providers. CII organizations must comply with cyber threat reporting requirements and are subject to the NCSA’s interception powers. Updated Definitions and New Terminology The draft amendment more clearly distinguishes between “cyber threats” (which have yet to occur but have the potential of causing damage or impact) and “cyber incidents” (which have already occurred and have caused or are expected to cause damage or impact). The draft amendment also expands the definition of “cybersecurity” to explicitly cover both prevention
July 30, 2025
Artificial intelligence (AI) model training and data scraping are essential processes in the development of modern AI systems. AI model training involves using large datasets to teach machine learning algorithms to recognize patterns, make predictions, or generate new content. Data scraping refers to the automated extraction of information from websites or digital sources, often to assemble the vast datasets required for effective AI training. As these practices become more widespread, questions about the legality of using third-party content—especially copyrighted works—have become increasingly important. In Thailand, the legal landscape for AI developers is shaped primarily by the Copyright Act, which presents unique challenges due to the absence of a fair-use exception. This article examines the copyright-related risks and legal uncertainties facing AI developers under Thailand’s current copyright law and practices, offering strategic guidance for navigating this complex environment. Copyright Risks in AI Scraping and Training Thailand’s Copyright Act does not provide a broad fair use or fair dealing exception, unlike some other jurisdictions, such as the United States. This absence has significant consequences for AI developers: No general defense for AI training: Any use of copyrighted material for AI model training is presumed to be infringing unless a specific, narrow statutory exception applies or explicit permission is obtained from the rights holder. There is no general legal basis for using copyrighted works in AI training without authorization. Increased rights clearance burden: Developers must identify and secure licenses for every copyrighted work included in their training datasets. Given the scale and diversity of data required for effective AI models, this process can be both impractical and costly. Legal ambiguity and litigation risk: The lack of clear statutory guidance or case law leaves developers in a legal gray area. There is no established precedent clarifying whether certain uses of copyrighted material for