You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

March 2, 2020

What Cambodia’s New Law on Electronic Commerce Means for Business

Informed Counsel

On November 2, 2019, Cambodia enacted the Law on Electronic Commerce (“E-commerce Law”). This development makes Cambodia the last member of the Association of Southeast Asian Nations (ASEAN)—one of the world’s fastest-growing internet markets—to adopt a domestic e-commerce law. The E-commerce Law addresses electronic communications, signatures, records, and evidence, and serves to clarify the legal environment for e-commerce in Cambodia.

In the last decade, Cambodia has experienced rapid development in the financial technology sector, and financial services and products have become more accessible to Cambodians. This financial inclusion, coupled with the availability of smart devices connected to the internet, enables local e-commerce startups and encourages foreign e-commerce businesses to enter the market. To strengthen trust and security in the online realm, Cambodia’s E-commerce Law regulates the activities of e-commerce service providers and intermediaries. The law also imposes consumer protection obligations, including data protection and cybersecurity obligations, on all e-commerce businesses. 

The E-commerce Law aims to regulate domestic and cross-border activities in Cambodia. All commercial and civil acts, documents, and transactions executed via an electronic system are subject to the E-commerce Law unless they are related to powers of attorney, wills and successions, or real estate.

The E-Commerce Law will take effect in May 2020. During the six-month gap between the law’s passage and its implementation, companies should familiarize themselves with the new obligations under the law, while government agencies are expected to issue regulations to clarify and implement the law. 

Electronic Communications   

The provisions on electronic communications that are found in a portion of Cambodia’s E-commerce Law primarily derive from two influential works of the United Nations Commission on International Trade Law (UNCITRAL); the 1996 Model Law on Electronic Commerce (MLEC) and the 2005 United Nations Convention on the Use of Electronic Communications in International Contracts (the “Electronic Communications Convention” or ECC).

Cambodia’s E-commerce Law explicitly recognizes the validity, legal effect, admissibility, and enforceability of electronic communications and reconfirms that contracts can be made electronically. Furthermore, electronic communications may satisfy requirements imposed by outdated  laws (e.g., “written,” “signed,” or “original” documents), if they fulfill certain conditions set out in the law.

The E-commerce Law generally considers an electronic communication to be sent when it leaves the originator’s information system and to be received when it becomes capable of being retrieved by the addressee. The places of business of the originator and addressee, respectively, are considered as the locations where an electronic communication is dispatched and received.   

It should be noted that Cambodia’s E-commerce Law does not include comprehensive provisions on matters related to the attribution of electronic communications and acknowledgment of receipt, as suggested by the MLEC. For example, the MLEC clarifies that if an originator states that an email is conditional on receipt of its acknowledgment, that email would not be considered as sent until the originator receives the acknowledgment. The Cambodian legislation contains no such clarification.

Electronic Signatures, Electronic Records, and Electronic Evidence

The E-commerce Law sets conditions for electronic signatures, including digital and biometric signatures, and electronic records to be deemed secure. By meeting these statutory qualifications, secure electronic records are presumed to have not been altered, and secure electronic signatures are presumed to be of the signatories having the intent to sign.   

In late 2017, prior to the enactment of the E-commerce Law, Cambodia introduced a sub-decree on digital signatures. This regulation provides legal recognition to digital signatures with a digital signature certificate issued by a licensed digital signature certification authority. However, the sub-decree has not been implemented yet as no license has been issued to any digital signature certification authority. Cambodia is likely to start implementing the regulation at the same time as the E-commerce Law. It will be important to observe how these two legal instruments correspond with each other in practice.

Cambodia’s E-commerce Law, with certain provisions similar to the Model Law on Electronic Evidence by the Commonwealth of Nations, also supports the admissibility of electronic records as evidence in legal proceedings. The mere fact that evidence is an electronic record cannot be used as grounds to render the evidence inadmissible.

The E-commerce Law also establishes rules on the validity, integrity, and authenticity of electronic evidence. The validity of electronic evidence relies on the integrity of the electronic system that stores or records the data in question. The E-commerce Law determines circumstances in which an electronic record satisfies the element of integrity unless proven otherwise. The party introducing the evidence has the burden to prove its authenticity, and to do so the E-commerce Law allows that party to present the court with an authenticity certificate issued by, for example, a competent authority or a court-appointed expert.

E-commerce Service Providers and Intermediaries, and Electronic Payment Systems

E-commerce service providers and intermediaries are now required under the E-commerce Law to obtain operating licenses from the Ministry of Commerce (MOC) and the Ministry of Post and Telecommunications (MPTC). However, the definitions of e-commerce service providers and intermediaries are crafted broadly, and it is unclear whether these licensing requirements also capture offshore e-commerce service providers and intermediaries operating without any local presence or permanent establishment in Cambodia. Since the E-commerce Law states that exceptions to this licensing regime will be clarified in the future, we hope Cambodia will issue implementing regulations that address this ambiguity before the law is implemented in May 2020.

The E-commerce Law creates a safe harbor rule for e-commerce service providers and intermediaries whereby they are not liable for unlawful third-party content on their online platforms; however, they must comply with certain mandatory content removal procedures upon becoming aware of such content. Additionally, they are obligated to comply with an e-commerce code of conduct.

The E-commerce Law also reaffirms that e-commerce service providers and intermediaries are subject to tax laws and incentives, just like brick-and-mortar businesses.     

Payment service providers must also obtain authorization or a license from the National Bank of Cambodia (NBC) before commencing operations, such as operating a payment system, providing payment services, or issuing electronic payments. However, many existing banking and financial institutions in Cambodia have already been providing these payment services and have obtained necessary authorizations under various laws (e.g., the Prakas on Payment Service Providers and the Law on Banking and Financial Institutions). For that reason, it remains uncertain whether the E-commerce Law merely reiterates the existing licensing regime for payment service providers or establishes a new, separate one.

In addition, the E-commerce Law outlines situations where payment service providers must be liable for the damage caused to customers unless the damage is caused by force majeure or the customer’s own fault.

Consumer Protection and Data Protection

Besides obligations under the newly legislated Law on Consumer Protection, which are applicable to both online and offline businesses, the E-commerce Law imposes additional requirements to which e-commerce enterprises must adhere.

The E-commerce Law requires anyone selling goods or services using electronic communications, except insurance and security companies, to disclose information that is necessary for customers to decide whether to purchase the goods or services. The information must at least include names, addresses, contacts, costs of the products and services, and terms and conditions for payments, cancellation, refunds, and so on. Furthermore, it is strictly prohibited to send unsolicited communications without providing clear and straightforward opt-out instructions irrespective of the originator’s or recipient’s locations. 

Data protection rules that apply to all sectors have also been set out for the first time in the E-commerce Law. Any business that electronically stores personal information is now obligated to establish all necessary measures to ensure that the data are reasonably protected from loss or unauthorized access, use, alteration, leaks, or disclosures. In addition, a person who enters information inaccurately to an automated system that does not allow any modification has the right to correct or delete the inaccurate information.

The E-commerce Law is much-welcomed by consumers, and is a positive step for the country’s digital environment. In addition, the harmonization that it brings with other countries should encourage cross-border transactions and paperless interactions among businesses and between businesses and governmental bodies.

RELATED INSIGHTS​ 

October 31, 2025
On September 29, 2025, Thailand’s Office of the Personal Data Protection Committee (PDPC Office) published its Regulations on the Review and Certification of Binding Corporate Rules B.E. 2568 (2025) (the Regulations). The Regulations provide clarity on the PDPC Office’s approach to reviewing and certifying binding corporate rules (BCRs) under Section 29 of the Personal Data Protection Act B.E. 2562 (2019) (PDPA), and aim to facilitate international data transfers within a group of undertakings or enterprises (a “corporate group”). In conjunction with this development, the PDPC Office also approved BCRs for two companies operating in Thailand on September 30, 2025. This milestone represents the first concrete progress since the PDPC’s Notification on Criteria for the Protection of Personal Data Sent or Transferred to a Foreign Country pursuant to Section 29 of the PDPA B.E. 2566 (2023) came into effect in March 2024. Some key features of the Regulations are set out below. Categorization of BCRs BCRs are classified into two types: (1) BCRs for Controllers (BCR-C) and (2) BCRs for Processors (BCR-P). The category must be clearly specified when submitting the BCRs to the PDPC Office. Documentation Requirement The applicant must prepare and submit the application (a standard template may be provided by the PDPC Office in the future) along with supporting documents for review and certification in the Thai language. If the supporting documents are in a foreign language, a certified Thai translation should be provided. The translation must be notarized by a notary public or qualified person. Supporting documents may include, among others, a binding instrument such as an intra-group agreement, or a list of entities subject to the BCRs. Expedited Process Requirement Organizations with existing BCR approvals under the EU or UK GDPR, or from countries announced by the PDPC under Section 28, may apply through an
October 26, 2025
AI-generated songs are now making waves in Vietnam on platforms like TikTok, with tracks such as “Say mot doi vi em” quickly gaining popularity and sparking widespread attention. This phenomenon raises a host of legal and ethical questions: Who is the author of these songs? Can they be protected by copyright? Who is responsible if there is an infringement? These questions are becoming increasingly urgent as AI music becomes more mainstream in Vietnam. Copyright Protection for AI-Generated Music in Vietnam Under current Vietnamese law, copyright protection is reserved for works that bear the mark of human creativity. The 2022 amendments to Vietnam’s Intellectual Property Law reaffirm that only works created by humans are eligible for copyright. In practice, if a human meaningfully contributes to the creative process—by providing prompts, making selections, editing, or arranging—their contribution may be protected. However, if a song is generated entirely by AI without significant human input, it is unlikely to qualify for copyright protection. When an AI-generated song does not qualify for copyright protection, the question arises as to whether the person who writes the prompts, edits, or compiles the work can still be considered the owner of an asset under the Vietnamese Civil Code. According to Article 105 of the Civil Code 2015, assets include objects, money, valuable papers, and property rights. While AI-generated music that is not protected by copyright is not considered money or valuable papers, it may be regarded as an object (in the form of a digital file or recording) or as a property right if it can be possessed, used, transferred, or exploited for value. Use of AI-Generated Works Without Copyright Protection If a song is not protected by copyright, does that mean anyone can use it freely? Not necessarily. The absence of copyright does not mean the
October 3, 2025
On September 26, 2025, the Contract Committee under Thailand’s Consumer Protection Board issued a regulation that aims to standardize contracts and enhance consumer protection within the beauty and wellness industry. The Notification on Prescribing the Beauty Service Business as a Contract-Controlled Business B.E. 2568 (2025), which takes effect on January 24, 2026, requires business operators to use a prescribed standard contract in Thai and adhere to strict mandatory provisions and prohibitions. These regulations apply to operators across all in-person and online service channels, including via digital platforms. “Beauty services business” is defined as the provision of services under an agreement allowing consumers to receive a series of treatments, either over a set number of sessions or within a set period. This includes massage, spa, other methods for cleanliness, beauty, or care of facial or body skin, and weight control and body shaping—including services offered electronically. The law excludes surgery, liposuction, and medical treatments performed by licensed practitioners. The notification establishes the following key requirements: Mandatory contract and formatting. All contracts with consumers must use the standard contract form, in Thai, with clear, readable text (minimum font size of 2 millimeters, no more than 11 characters per inch), and include all essential terms from the annexed form. Contract execution. Contracts must be made in duplicate, with one copy given to the consumer at signing. For agreements concluded through electronic channels, the process must comply with the Electronic Transactions Act and use the same required terms. Digital platforms. Business operators who provide services facilitated through a digital platform as an intermediary are ultimately responsible for ensuring the consumer receives a compliant contract. Prohibited clauses. The law prohibits clauses that limit or exclude liability for damages to life, body, health, mind, or property resulting from breach of contract or a wrongful act;
September 26, 2025
As Vietnam accelerates its digital transformation, data centers have emerged as critical infrastructure supporting the shift toward a digital government, digital economy, and digital society. For businesses targeting Vietnam’s rapidly growing data center market, a clear understanding of the evolving regulatory landscape, compliance obligations, and government incentives is key to successful market entry and operation. This article provides a strategic overview of investment opportunities and key compliance requirements in Vietnam’s dynamic data center sector. Investment Incentives to Boost Data Center Growth Since July 1, 2024, organizations and individuals across all economic sectors have been encouraged to invest in and contribute to the development of data centers. By law, there are no restrictions on shareholding ratios, capital contributions, or foreign investor participation in data center and cloud computing services under business cooperation contracts. Currently, investment in AI data centers is classified as a specially incentivized industry, qualifying for preferential treatments and incentives in terms of investment, taxation, land use, and other related areas. Large-scale data centers, together with AI and cloud computing, are currently considered as strategic technologies and products for which Vietnam offers significant fiscal, tax, and land incentives to promote investment. Additionally, these large-scale projects may receive direct financial support from local development budgets for facility construction, technical infrastructure, and equipment procurement, subject to state budget provisions and applicable laws. AI data center construction projects also enjoy preferential treatment under customs regulations. Regulatory Approvals for Providing Data Center Services The 2023 Telecom Law and its guiding documents marked a significant milestone by classifying data center services as value-added telecom services. Under the law, a data center service is defined as a telecom service that enables users to process, store, and retrieve information via a telecom network through the leasing of part or all of a data center. A