You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

July 26, 2021

Laos Issues E-commerce Regulations

Though online purchases of goods and services have been booming in Laos, the country’s laws and regulations have not kept pace. Providers of legal advice on these activities have therefore had to interpret laws and regulations on traditional physical retail activities instead, and apply them to online activities. However, Laos is making strides toward providing clear legal guidance for e-commerce operations by issuing legal measures to facilitate the regulation of online business activities.

For instance, on June 4, 2021, the new Decree on E-commerce No. 296/GOV (dated April 12, 2021, and published in the Lao Official Gazette on May 20) came into effect to clarify the regulatory framework for e-commerce in the country and to set requirements for electronic purchase contracts.

The decree, which applies only to operators residing or registered in Laos, regulates individuals and legal entities involved in the following activities:

  • Selling goods and services via their own electronic platform (website, program, or other instruction set);
  • Providing electronic marketplace services; and
  • Selling goods and services via electronic marketplaces.

Seller Notification Requirement

Business operators looking to sell goods or services via an electronic platform, either on their own website or application or via an electronic marketplace, must notify the relevant department of the Ministry of Industry and Commerce of their activity. (Existing operators must notify the ministry within 90 days from the decree’s effective date.) Although the chief concern of the decree is to target those whose regular activity is to sell goods and services online, the decree does not address whether those selling occasionally through an electronic marketplace still need to notify the ministry.

Documents for the notification consist primarily of the application form provided by the Ministry of Industry and Commerce, the enterprise registration certificate (i.e., proof of having registered a legal entity in Laos) or a simple ID card for individuals, a copy of the business operating license (for activities that require approval from a line ministry), and a copy of a contract with a payment service provider for payment via an electronic platform. Upon receipt of the necessary documentation, the ministry’s relevant departments or agencies will certify the notification within three working days. This certificate is valid for two years, and must be renewed thirty days before its expiry.

Electronic Marketplace Registration

Electronic marketplaces must be operated via an incorporated legal entity, which means an Enterprise Registration Certificate is a necessary prerequisite to operating an electronic marketplace in Laos. As for technical requirements, electronic marketplaces must obtain a Ministry of Technology and Communications certificate confirming their “technical conformity.” (The process and requirements for obtaining this certificate may be the subject of guidance that is yet to be issued.)

Similar to the grace period for the notification requirement mentioned above, existing electronic marketplace operators have 90 days (from June 4, 2021) to request authorization from the ministry. Upon receipt of the necessary documentation, the ministry’s relevant departments will consider and provide its authorization within five working days. This authorization is valid for three years, and must be renewed thirty days before its expiry.

Foreign Restrictions

Foreign shareholders cannot hold more than 90 percent of the shares of the legal entity operating an electronic marketplace, and the registered capital must be at least LAK 10 billion (approx. USD 1.05 million).

It is important to note that this decree does not replace existing laws and regulations that address certain types of goods or services sold, for which licensing, notification, minimum investment, and other requirements may apply. For instance, foreign participation in the provision of retail and wholesale services in Laos is limited under the Decision on Retail and Wholesale Business. Under this decision, a foreign shareholder who holds up to 50% of the shares in a retail or wholesale business must invest at least LAK 4 billion (approx. USD 423,350). Between LAK 10 billion (approx. USD 1.05 million) and less than LAK 20 billion (approx. USD 2.1 million) a foreign shareholder may hold 70% of the legal entity, while a foreign shareholder must invest at least LAK 20 billion to hold 100% of the shares of the marketplace’s legal entity conducting retail and wholesale services. Similar restrictions are likely to apply for online retail and wholesale businesses.

Transparency

The decree requires business operators of electronic platforms to disclose information on their platforms and activities, as well as on the goods and services sold. Accordingly, information on the business operator, such as its name, address, contact details, and Enterprise Registration Certificate or the relevant operating license, must be displayed on the electronic platform.

Descriptions of goods or services should note the product specifications (size, color, aspect, and so on) following the product labels as applicable, and product-related information such as origins, prices, return and warranty policies, related fees (e.g., shipment and payment methods), and terms and conditions. In addition, information on customers’ “satisfaction and opinion” concerning the goods and services must be displayed on the corresponding electronic platform. The decree also emphasizes that information on the goods or services offered must be realistic and portray products’ actual characteristics.

Product Liability

The decree also addresses liability for the goods and services sold, deeming electronic selling platforms and sellers on electronic marketplaces legally responsible for the goods and services they sell online.

The decree does not assign similar legal responsibility to entities operating electronic marketplaces on which the goods or services are sold. However, electronic marketplace operators are prohibited from authorizing or ignoring the sale of prohibited goods or services on their electronic marketplaces. Accordingly, they  must take a proactive role in the inspection of goods and services sold.

E-commerce Contracts

According to the decree, which endeavors to cover e-commerce contracts specifically (as opposed to electronic contracts more generally), there are two types of e-commerce contracts.

First, e-commerce contracts made via an “online ordering function” are defined as agreements between seller and client for the sale, purchase, or exchange of goods or services, made by electronic means via the online ordering function of an electronic platform created by the “owner of the electronic platform.” Essentially, this means e-commerce contracts that cover transactions made on electronic platforms (other than electronic marketplaces), and assumes that they use electronic means of payment.

The second type of e-commerce contract is one made “via social media,” which is a term in the decree that the regulator interprets as also covering electronic marketplace contracts for the sale, purchase, or exchange of goods or services.

The decree stipulates that the offering of either type of e-commerce contract is governed primarily by the rules provided in the electronic platform’s terms and conditions. Upon acceptance of the offer by the seller, the e-contract will be deemed formed. The offer will be nullified if the seller does not respond within 12 hours (unlike the 15 days for a traditional contract in writing), unless otherwise stipulated in the terms and conditions of the electronic platform. The client may also cancel its offer before receiving a response from the seller.

Both types of e-commerce contracts must remain accessible to clients after the transaction, (e.g. through archives and purchase histories).

For e-commerce contracts made via the online ordering function of an electronic platform (not on an electronic marketplace), the electronic platform must have a system that allows clients to review, add, amend, confirm, or cancel an offer before formally submitting it by means of the online ordering function. In case of cancellation by the client, electronic platforms must provide clients with evidence that the notification to cancel the contract was sent.

Conclusion

E-commerce activities in Laos have typically had to rely on extensive interpretation of laws that were not made to address e-commerce. The new e-commerce decree discussed in this article is an example of how the government is working to update the regulatory framework to sustain promising high-tech sectors such as e-commerce, fintech, and others. As Laos remains a relatively untapped market in these areas, the Decree on E-commerce eases both local and international investors’ concerns about launching operations by clarifying some key issues. The decree does not address sanctions for noncompliance, and questions remain regarding some of the mandatory requirements (such as the “technical requirements”) to register an electronic marketplace. Therefore, in its current state full implementation of the decree may require subsequent guidance from the authorities.

RELATED INSIGHTS​ 

June 17, 2026
Thailand’s new labeling requirements for medical devices, which include for the first time a unique device identification (UDI) requirement for software as a medical device (SaMD), take effect on June 20, 2026. The Notification of the Ministry of Public Health regarding Criteria, Methods, and Conditions on Labeling and Instructions for Use for Medical Devices 2025, which replaces a similar notification from 2020, was published in the Government Gazette on December 22, 2025. To ensure clarity, modernity, and patient safety, the regulation requires domestic manufacturers and importers to provide labels and instructions for use (IFU) that are clearly legible, complete, and free of false or misleading claims. It also permits IFU to be provided in electronic format, such as via QR codes, websites, or other digital channels—directly relevant to SaMD, where physical labels are impractical and electronic presentation is the natural medium. The notification distinguishes two categories for labeling language. Home-use medical devices (for lay users outside healthcare facilities) must have labels and IFU in Thai. Professional-use medical devices may display labels and documentation in either Thai or English. This distinction is significant for SaMD developers: software intended for clinical professionals may use English-language interfaces and IFU, while consumer-facing health applications must provide Thai-language content. Labeling and UDI Requirements Labels and IFU must include, at a minimum: Product name and intended purpose Quantity or volume Name and address of domestic manufacturer or importer Thai FDA approval number Lot, version, or serial number Manufacturing date and expiry date For SaMD, the version number requirement is particularly relevant. The regulation also mandates display of a UDI code for SaMD in risk category 2 (moderate-risk), category 3 (moderate- to high-risk), and category 4 (high-risk), according to Thailand’s medical device risk classification system (which complies with the ASEAN Medical Device Directive and the EU
June 15, 2026
The surge in AI development has led to a desperate demand for large, high-quality training data. However, real-world data can be expensive to collect, difficult to access, and often subject to strict privacy and regulatory constraints. Synthetic data, which consists of artificially generated records that replicate the statistical properties of real-world data without reproducing specific individuals’ information, provides an appealing solution by generating artificial datasets at scale without relying on identifiable personal information. It combines speed, cost efficiency, and regulatory compliance, making it a sensible alternative for organizations seeking to reduce risks while maintaining data utility. When properly anonymized, synthetic datasets may fall outside the scope of laws such as the EU’s General Data Protection Regulation (GDPR) or Thailand’s Personal Data Protection Act (PDPA), reducing compliance burdens while still supporting high-quality model training. However, relying on synthetic data without rigorous legal due diligence could be a strategic mistake. It replaces one set of known risks (scraping, direct privacy liability) with a new set of complex liabilities. The narrative that synthetic data is a “silver bullet” for privacy and IP compliance is dangerous and could be misleading. While synthetic data addresses data scarcity, it also introduces new legal uncertainties. Legal counsel should anticipate downstream risks arising from compromised data sources. Models trained on unlawfully obtained data may need to be decommissioned, even if their outputs appear lawful. What is synthetic data? Synthetic data refers to artificially generated information created using AI techniques such as deep learning and generative models. Instead of copying real records, it reproduces the statistical patterns and relationships found in the original dataset. Synthetic data generally falls into three categories: Fully synthetic data – Entirely new data points generated from learned patterns. The model studies the structure of the original data and produces records that resemble real-world
June 11, 2026
Thailand’s Electronic Transactions Development Agency (ETDA) has released a revised draft Electronic Transactions Act (ETA) for public hearing from May 12, 2026, to June 15, 2026. This is not merely an amendment to certain provisions of the current ETA, but a comprehensive redrafting of the entire act. The revised draft ETA introduces several significant changes from the current framework, with practical implications for businesses operating in Thailand. Unified Coverage of Public and Private Sectors The current law segregates government transactions into a separate chapter with distinct rules. The draft ETA eliminates this division, defining “transaction” to encompass civil and commercial juristic acts as well as administrative procedures, administrative contracts, and other acts of government agencies. Enhanced E-Signature Definition The definition of “electronic signature” is broadened to expressly include biometric data and refocused on identifying the signatory and demonstrating intent regarding the content of the electronic data. Shift in Burden of Proof When a party challenges the reliability of electronic data created using a “trusted electronic method” or a method prescribed by the ETDA, the burden of proof and the cost of proving unreliability shifts to the challenger. Introduction of New Digital Method Concepts The draft ETA introduces several new digital method concepts that are not currently recognized under the existing ETA framework. These include: Electronic timestamping (e-timestamp) Electronic registered delivery Electronic company seals Electronic stamp duty compliance Electronic identity authentication and verification Electronic transferable records (electronic bills of lading, promissory notes, and similar negotiable instruments) Recognition of Automated Systems and Electronic Contracting The draft ETA expressly recognizes the legal validity and enforceability of contracts formed through automated systems, including contracts concluded entirely between automated systems or between an automated system and a person. A party may not deny the binding effect of such contracts solely because no human review
June 5, 2026
Vietnam’s AI regulatory framework has reached an important milestone. While the Law on Artificial Intelligence No. 134/2025/QH15 (AI Law) established the foundation for AI governance, many practical compliance requirements were left to implementing regulations. On April 30, 2026, the government issued Decree No. 142/2026/ND-CP (Decree 142), which took effect on May 1, 2026, and provides the first detailed guidance on the implementation of the AI Law. Although an official list of high-risk AI systems is still pending from the prime minister, Decree 142 provides valuable insight into how Vietnam’s risk-based AI regulatory framework will operate in practice. Risk Classification Framework The AI Law adopts a risk-based approach under which AI systems are classified as high-risk, medium-risk, or low-risk. Decree 142 builds on this framework by providing detailed guidance on how these classifications are determined. High-risk AI systems are determined based on factors such as (i) their potential impact on life, health, property, human rights, public interests, or national security; (ii) the sector in which they are deployed; and (iii) the scale of affected users or integration with critical infrastructure. The latest draft list of high-risk AI systems appears to follow these same principles. Medium-risk AI systems generally include systems that may mislead, influence, or manipulate users, particularly where users may not realize they are interacting with AI or AI-generated content. The focus is therefore on transparency and authenticity risks rather than broader societal or safety concerns. Low-risk AI systems are those that do not meet the criteria for either high-risk or medium-risk classification. Importantly, Decree 142 seeks to avoid over-classification. Certain systems may fall outside the high-risk or medium-risk regimes, including internal-use systems, office-support tools, technical editing applications, certain back-end processing systems, and AI systems used in artistic, gaming, cinematic, or other creative contexts. Providers must also review and