You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

March 2, 2020

What Cambodia’s New Law on Electronic Commerce Means for Business

Informed Counsel

On November 2, 2019, Cambodia enacted the Law on Electronic Commerce (“E-commerce Law”). This development makes Cambodia the last member of the Association of Southeast Asian Nations (ASEAN)—one of the world’s fastest-growing internet markets—to adopt a domestic e-commerce law. The E-commerce Law addresses electronic communications, signatures, records, and evidence, and serves to clarify the legal environment for e-commerce in Cambodia.

In the last decade, Cambodia has experienced rapid development in the financial technology sector, and financial services and products have become more accessible to Cambodians. This financial inclusion, coupled with the availability of smart devices connected to the internet, enables local e-commerce startups and encourages foreign e-commerce businesses to enter the market. To strengthen trust and security in the online realm, Cambodia’s E-commerce Law regulates the activities of e-commerce service providers and intermediaries. The law also imposes consumer protection obligations, including data protection and cybersecurity obligations, on all e-commerce businesses. 

The E-commerce Law aims to regulate domestic and cross-border activities in Cambodia. All commercial and civil acts, documents, and transactions executed via an electronic system are subject to the E-commerce Law unless they are related to powers of attorney, wills and successions, or real estate.

The E-Commerce Law will take effect in May 2020. During the six-month gap between the law’s passage and its implementation, companies should familiarize themselves with the new obligations under the law, while government agencies are expected to issue regulations to clarify and implement the law. 

Electronic Communications   

The provisions on electronic communications that are found in a portion of Cambodia’s E-commerce Law primarily derive from two influential works of the United Nations Commission on International Trade Law (UNCITRAL); the 1996 Model Law on Electronic Commerce (MLEC) and the 2005 United Nations Convention on the Use of Electronic Communications in International Contracts (the “Electronic Communications Convention” or ECC).

Cambodia’s E-commerce Law explicitly recognizes the validity, legal effect, admissibility, and enforceability of electronic communications and reconfirms that contracts can be made electronically. Furthermore, electronic communications may satisfy requirements imposed by outdated  laws (e.g., “written,” “signed,” or “original” documents), if they fulfill certain conditions set out in the law.

The E-commerce Law generally considers an electronic communication to be sent when it leaves the originator’s information system and to be received when it becomes capable of being retrieved by the addressee. The places of business of the originator and addressee, respectively, are considered as the locations where an electronic communication is dispatched and received.   

It should be noted that Cambodia’s E-commerce Law does not include comprehensive provisions on matters related to the attribution of electronic communications and acknowledgment of receipt, as suggested by the MLEC. For example, the MLEC clarifies that if an originator states that an email is conditional on receipt of its acknowledgment, that email would not be considered as sent until the originator receives the acknowledgment. The Cambodian legislation contains no such clarification.

Electronic Signatures, Electronic Records, and Electronic Evidence

The E-commerce Law sets conditions for electronic signatures, including digital and biometric signatures, and electronic records to be deemed secure. By meeting these statutory qualifications, secure electronic records are presumed to have not been altered, and secure electronic signatures are presumed to be of the signatories having the intent to sign.   

In late 2017, prior to the enactment of the E-commerce Law, Cambodia introduced a sub-decree on digital signatures. This regulation provides legal recognition to digital signatures with a digital signature certificate issued by a licensed digital signature certification authority. However, the sub-decree has not been implemented yet as no license has been issued to any digital signature certification authority. Cambodia is likely to start implementing the regulation at the same time as the E-commerce Law. It will be important to observe how these two legal instruments correspond with each other in practice.

Cambodia’s E-commerce Law, with certain provisions similar to the Model Law on Electronic Evidence by the Commonwealth of Nations, also supports the admissibility of electronic records as evidence in legal proceedings. The mere fact that evidence is an electronic record cannot be used as grounds to render the evidence inadmissible.

The E-commerce Law also establishes rules on the validity, integrity, and authenticity of electronic evidence. The validity of electronic evidence relies on the integrity of the electronic system that stores or records the data in question. The E-commerce Law determines circumstances in which an electronic record satisfies the element of integrity unless proven otherwise. The party introducing the evidence has the burden to prove its authenticity, and to do so the E-commerce Law allows that party to present the court with an authenticity certificate issued by, for example, a competent authority or a court-appointed expert.

E-commerce Service Providers and Intermediaries, and Electronic Payment Systems

E-commerce service providers and intermediaries are now required under the E-commerce Law to obtain operating licenses from the Ministry of Commerce (MOC) and the Ministry of Post and Telecommunications (MPTC). However, the definitions of e-commerce service providers and intermediaries are crafted broadly, and it is unclear whether these licensing requirements also capture offshore e-commerce service providers and intermediaries operating without any local presence or permanent establishment in Cambodia. Since the E-commerce Law states that exceptions to this licensing regime will be clarified in the future, we hope Cambodia will issue implementing regulations that address this ambiguity before the law is implemented in May 2020.

The E-commerce Law creates a safe harbor rule for e-commerce service providers and intermediaries whereby they are not liable for unlawful third-party content on their online platforms; however, they must comply with certain mandatory content removal procedures upon becoming aware of such content. Additionally, they are obligated to comply with an e-commerce code of conduct.

The E-commerce Law also reaffirms that e-commerce service providers and intermediaries are subject to tax laws and incentives, just like brick-and-mortar businesses.     

Payment service providers must also obtain authorization or a license from the National Bank of Cambodia (NBC) before commencing operations, such as operating a payment system, providing payment services, or issuing electronic payments. However, many existing banking and financial institutions in Cambodia have already been providing these payment services and have obtained necessary authorizations under various laws (e.g., the Prakas on Payment Service Providers and the Law on Banking and Financial Institutions). For that reason, it remains uncertain whether the E-commerce Law merely reiterates the existing licensing regime for payment service providers or establishes a new, separate one.

In addition, the E-commerce Law outlines situations where payment service providers must be liable for the damage caused to customers unless the damage is caused by force majeure or the customer’s own fault.

Consumer Protection and Data Protection

Besides obligations under the newly legislated Law on Consumer Protection, which are applicable to both online and offline businesses, the E-commerce Law imposes additional requirements to which e-commerce enterprises must adhere.

The E-commerce Law requires anyone selling goods or services using electronic communications, except insurance and security companies, to disclose information that is necessary for customers to decide whether to purchase the goods or services. The information must at least include names, addresses, contacts, costs of the products and services, and terms and conditions for payments, cancellation, refunds, and so on. Furthermore, it is strictly prohibited to send unsolicited communications without providing clear and straightforward opt-out instructions irrespective of the originator’s or recipient’s locations. 

Data protection rules that apply to all sectors have also been set out for the first time in the E-commerce Law. Any business that electronically stores personal information is now obligated to establish all necessary measures to ensure that the data are reasonably protected from loss or unauthorized access, use, alteration, leaks, or disclosures. In addition, a person who enters information inaccurately to an automated system that does not allow any modification has the right to correct or delete the inaccurate information.

The E-commerce Law is much-welcomed by consumers, and is a positive step for the country’s digital environment. In addition, the harmonization that it brings with other countries should encourage cross-border transactions and paperless interactions among businesses and between businesses and governmental bodies.

RELATED INSIGHTS​ 

July 24, 2025
Thai authorities have escalated efforts to block unlawful cross-border digital asset business operators. On June 19, 2025, the Ministry of Digital Economy and Society (MDES) issued a notification empowering it to ban internet access to operations or services offered by digital asset business operators who lack licenses from the Thailand Securities and Exchange Commission (SEC) under the Emergency Decree on Digital Asset Businesses B.E. 2561 (2018). This ban, issued under the 2023 Royal Decree on Measures for the Prevention and Suppression of Technology Crime, particularly aims to block Thai users’ access to services offered by unlicensed offshore digital asset providers via their own apps or websites or through public social media platforms. Compliance Requirements The notification requires internet service providers and social media platforms selected by MDES to immediately impose internet access restrictions on identified apps, websites, and IP addresses of illegal operators upon receiving MDES orders. Takedown Orders There are two tracks for competent officials at MDES to issue orders to operators: If the competent official is notified by the SEC of licensing noncompliance by a particular digital asset business operator, the competent official can issue a takedown order to the operator upon approval from the permanent secretary of MDES. If the competent official independently discovers, or receives a complaint from any third party other than the SEC, that a digital asset business operator may have violated licensing requirements, the competent official can ask the SEC to verify and confirm the relevant facts and noncompliance before seeking approval from the permanent secretary of MDES to issue the takedown order. Streamlined Enforcement Prior to this notification, the SEC could obtain takedown orders only from Thai courts under the 2007 Computer Crime Act to take down or block access to unlicensed digital asset platforms and apps. This was a relatively
July 24, 2025
Vietnam’s Ministry of Public Security recently released a draft version of the 2025 Cybersecurity Law, which is intended to replace both the existing 2018 Cybersecurity Law and the 2015 Law on Network Information Security (LNIS). This consolidation reflects a broader effort by the Vietnamese government to streamline and centralize the legal framework governing cybersecurity, data protection, and information security to be under the sole authority of the Ministry of Public Security, moving away from the previous sharing of responsibility with the former Ministry of Information and Communications (which ceased operations earlier this year and merged with the Ministry of Science and Technology). This shift aims to eliminate overlaps and improve enforcement efficiency. The draft law is built upon the foundation of principles and provisions of both the 2018 Cybersecurity Law and the 2015 LNIS, while also introducing a wide range of amendments and new regulations. By merging the two laws, the government seeks to reduce legal fragmentation and ensure consistency in definitions, obligations, and enforcement mechanisms across related domains like data protection, IT system classification, and cybercrime prevention. The newly introduced amendments include enhanced obligations for service providers, stricter controls on information transmission, classification of IT systems, designation and protection of nationally important information systems, and sector-specific violations and compliance requirements. Highlights of the draft law are discussed below. Definition and Obligations of Service Providers The draft law clearly defines and significantly broadens the scope of entities considered “service providers” under its jurisdiction. This now includes businesses and individuals offering products or services in cyberspace, including both infrastructure and content online services, such as: Internet service providers (ISPs) and providers of telecommunications, hosting, servers, domain names, VPNs, proxy services, and cloud computing; Providers of social networks, websites, and online gaming; Financial institutions, banks, foreign bank branches in Vietnam, e-wallet
July 23, 2025
On July 4, 2025, Thailand’s Electronic Transactions Development Agency (ETDA) issued two significant notifications that introduce new compliance requirements for ride-hailing platforms operating in the country. The notifications formally designate these platforms as high-impact digital services under section 18(3) of the Royal Decree on Digital Platform Service Businesses and impose a comprehensive set of additional operational obligations. These measures are designed to address regulatory gaps and enhance oversight of digital platforms providing public passenger vehicle or motorcycle ride-hailing services. First, the Notification on the Designation of Ride-Hailing Platforms under section 18(3) formally designates all ride-hailing platforms that have notified the ETDA of their operations as high-impact digital platform services under section 18(3) of the royal decree. Unlike high-risk marketplace platforms, which are named individually, any ride-hailing platform that has notified the ETDA of its operations is automatically subject to these new requirements. Next, the Notification on Additional Obligations for Ride-Hailing Platforms imposes further obligations on ride-hailing platforms, supplementing the general requirements under section 21 of the royal decree. These notifications will come into force 90 days from their publication in the Government Gazette. New Compliance Obligations The new regulatory framework introduces a range of operational, technical, and reporting requirements for ride-hailing platforms, particularly concerning the issues described below. Vehicle and Driver Compliance Operators must: Ensure that all vehicles used on the platform are registered as public vehicles in accordance with Department of Land Transport requirements Verify all drivers hold valid public driving licenses Collect service fees in compliance with applicable fare regulations under the Vehicle Law Digital Platform Features and User Verification Operators must implement robust digital platform features for both drivers and riders, including: Comprehensive identity verification and confirmation processes for drivers and riders, utilizing both face-to-face and non-face-to-face methods, including biometric and digital ID checks Real-time GPS
July 17, 2025
On July 9, 2025, Thailand issued a notification that introduces comprehensive operational requirements for digital platform service providers operating as goods marketplaces, effective December 31, 2025 (i.e., 180 days after its publication in the Government Gazette). The regulation’s official name is Notification of the Electronic Transactions Committee Re: Other Actions for Digital Platform Service Operators in the Category of Marketplace for Goods with Specific Characteristics under Section 18(2) of the Royal Decree on the Operation of Digital Platform Service Businesses that are Subject to Prior Notification B.E. 2565 (2022), B.E. 2568 (2025). Scope of Application The notification applies exclusively to goods marketplace operators formally designated by the Electronic Transactions Development Agency (ETDA), which on the same day designated 19 platforms that had previously notified the ETDA of their operations. The goods requiring enhanced oversight by these operators are limited to those regulated by the Thai Food and Drug Administration (FDA) and the Thai Industrial Standards Institute (TISI). Development from Earlier Draft An earlier draft of the notification had included a requirement for offshore platforms to establish a local entity, but this requirement was removed from the final notification. Key Obligations Despite the removal of the local entity requirement, the notification imposes a range of additional obligations on designated goods marketplace operators: Transparency. Operators must implement robust transparency measures, including clear, accessible, and understandable disclosures to users in Thai. These disclosures must cover all relevant terms and conditions, comprehensive product information, and complaint management procedures. Operators must also submit an annual compliance report to the ETDA within 60 days after the end of their accounting period, including statistics on regulated goods. Business user registration and identity verification. Before permitting the sale or advertisement of regulated goods, operators must collect and verify business user information, including contact details, identification documents, registration