You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

March 2, 2020

What Cambodia’s New Law on Electronic Commerce Means for Business

Informed Counsel

On November 2, 2019, Cambodia enacted the Law on Electronic Commerce (“E-commerce Law”). This development makes Cambodia the last member of the Association of Southeast Asian Nations (ASEAN)—one of the world’s fastest-growing internet markets—to adopt a domestic e-commerce law. The E-commerce Law addresses electronic communications, signatures, records, and evidence, and serves to clarify the legal environment for e-commerce in Cambodia.

In the last decade, Cambodia has experienced rapid development in the financial technology sector, and financial services and products have become more accessible to Cambodians. This financial inclusion, coupled with the availability of smart devices connected to the internet, enables local e-commerce startups and encourages foreign e-commerce businesses to enter the market. To strengthen trust and security in the online realm, Cambodia’s E-commerce Law regulates the activities of e-commerce service providers and intermediaries. The law also imposes consumer protection obligations, including data protection and cybersecurity obligations, on all e-commerce businesses. 

The E-commerce Law aims to regulate domestic and cross-border activities in Cambodia. All commercial and civil acts, documents, and transactions executed via an electronic system are subject to the E-commerce Law unless they are related to powers of attorney, wills and successions, or real estate.

The E-Commerce Law will take effect in May 2020. During the six-month gap between the law’s passage and its implementation, companies should familiarize themselves with the new obligations under the law, while government agencies are expected to issue regulations to clarify and implement the law. 

Electronic Communications   

The provisions on electronic communications that are found in a portion of Cambodia’s E-commerce Law primarily derive from two influential works of the United Nations Commission on International Trade Law (UNCITRAL); the 1996 Model Law on Electronic Commerce (MLEC) and the 2005 United Nations Convention on the Use of Electronic Communications in International Contracts (the “Electronic Communications Convention” or ECC).

Cambodia’s E-commerce Law explicitly recognizes the validity, legal effect, admissibility, and enforceability of electronic communications and reconfirms that contracts can be made electronically. Furthermore, electronic communications may satisfy requirements imposed by outdated  laws (e.g., “written,” “signed,” or “original” documents), if they fulfill certain conditions set out in the law.

The E-commerce Law generally considers an electronic communication to be sent when it leaves the originator’s information system and to be received when it becomes capable of being retrieved by the addressee. The places of business of the originator and addressee, respectively, are considered as the locations where an electronic communication is dispatched and received.   

It should be noted that Cambodia’s E-commerce Law does not include comprehensive provisions on matters related to the attribution of electronic communications and acknowledgment of receipt, as suggested by the MLEC. For example, the MLEC clarifies that if an originator states that an email is conditional on receipt of its acknowledgment, that email would not be considered as sent until the originator receives the acknowledgment. The Cambodian legislation contains no such clarification.

Electronic Signatures, Electronic Records, and Electronic Evidence

The E-commerce Law sets conditions for electronic signatures, including digital and biometric signatures, and electronic records to be deemed secure. By meeting these statutory qualifications, secure electronic records are presumed to have not been altered, and secure electronic signatures are presumed to be of the signatories having the intent to sign.   

In late 2017, prior to the enactment of the E-commerce Law, Cambodia introduced a sub-decree on digital signatures. This regulation provides legal recognition to digital signatures with a digital signature certificate issued by a licensed digital signature certification authority. However, the sub-decree has not been implemented yet as no license has been issued to any digital signature certification authority. Cambodia is likely to start implementing the regulation at the same time as the E-commerce Law. It will be important to observe how these two legal instruments correspond with each other in practice.

Cambodia’s E-commerce Law, with certain provisions similar to the Model Law on Electronic Evidence by the Commonwealth of Nations, also supports the admissibility of electronic records as evidence in legal proceedings. The mere fact that evidence is an electronic record cannot be used as grounds to render the evidence inadmissible.

The E-commerce Law also establishes rules on the validity, integrity, and authenticity of electronic evidence. The validity of electronic evidence relies on the integrity of the electronic system that stores or records the data in question. The E-commerce Law determines circumstances in which an electronic record satisfies the element of integrity unless proven otherwise. The party introducing the evidence has the burden to prove its authenticity, and to do so the E-commerce Law allows that party to present the court with an authenticity certificate issued by, for example, a competent authority or a court-appointed expert.

E-commerce Service Providers and Intermediaries, and Electronic Payment Systems

E-commerce service providers and intermediaries are now required under the E-commerce Law to obtain operating licenses from the Ministry of Commerce (MOC) and the Ministry of Post and Telecommunications (MPTC). However, the definitions of e-commerce service providers and intermediaries are crafted broadly, and it is unclear whether these licensing requirements also capture offshore e-commerce service providers and intermediaries operating without any local presence or permanent establishment in Cambodia. Since the E-commerce Law states that exceptions to this licensing regime will be clarified in the future, we hope Cambodia will issue implementing regulations that address this ambiguity before the law is implemented in May 2020.

The E-commerce Law creates a safe harbor rule for e-commerce service providers and intermediaries whereby they are not liable for unlawful third-party content on their online platforms; however, they must comply with certain mandatory content removal procedures upon becoming aware of such content. Additionally, they are obligated to comply with an e-commerce code of conduct.

The E-commerce Law also reaffirms that e-commerce service providers and intermediaries are subject to tax laws and incentives, just like brick-and-mortar businesses.     

Payment service providers must also obtain authorization or a license from the National Bank of Cambodia (NBC) before commencing operations, such as operating a payment system, providing payment services, or issuing electronic payments. However, many existing banking and financial institutions in Cambodia have already been providing these payment services and have obtained necessary authorizations under various laws (e.g., the Prakas on Payment Service Providers and the Law on Banking and Financial Institutions). For that reason, it remains uncertain whether the E-commerce Law merely reiterates the existing licensing regime for payment service providers or establishes a new, separate one.

In addition, the E-commerce Law outlines situations where payment service providers must be liable for the damage caused to customers unless the damage is caused by force majeure or the customer’s own fault.

Consumer Protection and Data Protection

Besides obligations under the newly legislated Law on Consumer Protection, which are applicable to both online and offline businesses, the E-commerce Law imposes additional requirements to which e-commerce enterprises must adhere.

The E-commerce Law requires anyone selling goods or services using electronic communications, except insurance and security companies, to disclose information that is necessary for customers to decide whether to purchase the goods or services. The information must at least include names, addresses, contacts, costs of the products and services, and terms and conditions for payments, cancellation, refunds, and so on. Furthermore, it is strictly prohibited to send unsolicited communications without providing clear and straightforward opt-out instructions irrespective of the originator’s or recipient’s locations. 

Data protection rules that apply to all sectors have also been set out for the first time in the E-commerce Law. Any business that electronically stores personal information is now obligated to establish all necessary measures to ensure that the data are reasonably protected from loss or unauthorized access, use, alteration, leaks, or disclosures. In addition, a person who enters information inaccurately to an automated system that does not allow any modification has the right to correct or delete the inaccurate information.

The E-commerce Law is much-welcomed by consumers, and is a positive step for the country’s digital environment. In addition, the harmonization that it brings with other countries should encourage cross-border transactions and paperless interactions among businesses and between businesses and governmental bodies.

RELATED INSIGHTS​ 

August 4, 2026
Thailand’s Personal Data Protection Act B.E. 2562 (2019) (PDPA) could soon see some important changes, as a draft bill to amend the PDPA has been introduced in the House of Representatives. The draft amendment is currently in the public consultation phase, with comments accepted from July 16 to August 15, 2026. If enacted in its current form, the amendment would make three key changes: expanding the government exemption to cover anticorruption operations, introducing a statutory definition of “government agency,” and restructuring the lawful bases for personal data processing to align with international standards. Background The PDPA has encountered several enforcement challenges since its implementation, including three core problems identified by the bill’s sponsors: (1) the current exemptions for government agencies do not cover anticorruption and misconduct-prevention operations; (2) the PDPA lacks a clear statutory definition of “government agency,” causing legal uncertainty as to which entities are covered; and (3) the existing framework for lawful bases of data processing does not align with international standards—particularly the multiple-lawful-bases system in the EU’s General Data Protection Regulation (GDPR)—making compliance inflexible for both government and private sector entities. Expanded Government Exemption The current PDPA exempts government agencies performing duties related to national security (including fiscal security), public safety, anti-money laundering, forensic science, and cybersecurity. The proposed amendment adds “prevention and suppression of corruption and misconduct” to this list of exempted functions. This would allow anticorruption bodies—most notably the National Anti-Corruption Commission (NACC), which is identified as a directly affected party—to collect, use, and disclose personal data without being subject to PDPA requirements when carrying out their duties. New Statutory Definition of “Government Agency” Notably, while the current PDPA use the term “government agency” in several provisions, the term is not comprehensively defined, creating potential uncertainty as to its scope. The draft bill therefore
August 3, 2026
On July 23, 2026, the Bank of Thailand (BOT) released for public comment its draft Notification on Digital Channel Security, which would significantly expand the scope and stringency of Thailand’s existing mobile banking security framework. If finalized in its current form, the draft notification would extend mandatory security requirements to credit card providers and credit providers, cover internet banking in addition to mobile applications, phase out SMS one-time passwords (OTPs) for transaction authentication, and introduce biometric verification requirements for high-value transactions. The public comment period is open through August 24, 2026. Background The BOT’s existing Mobile Banking Security Notification, issued in 2024, sets minimum security standards for financial institutions, specialized financial institutions (SFIs), and e-money providers, significantly reducing “money-draining app” fraud. However, fraudsters have since shifted to nonbank providers and internet banking channels, prompting the BOT to propose broader security requirements. Expanded Scope of Regulated Entities and Channels The existing Mobile Banking Security Notification covers only financial institutions, SFIs, and e-money providers offering mobile banking services. The draft expands coverage in two key areas: entities and channels. On the entity side, it adds credit card providers and credit providers that offer fund transfers to third parties at other financial service providers or that provide cash withdrawal services to individual retail customers. On the channel side, it broadens coverage to include internet banking in addition to mobile banking. Strengthened Customer Authentication The draft introduces enhanced authentication requirements in three areas: Service enrollment and device changes. Providers must implement rigorous identity verification, notify customers of enrollment results through out-of-band communication channels, and adopt risk-mitigation measures such as cooling-off periods and temporary transaction limits. Transaction-level authentication. Providers must use two-factor authentication for fund transfers, cardless ATM withdrawals, and transaction limit increases. Secure authentication factors. Key requirements include the following: “What-you-know” factors must
July 28, 2026
Data protection officers (DPOs) have become a fixture of Thailand’s privacy compliance landscape since the Personal Data Protection Act B.E. 2562 (2019) (PDPA) took full effect and the Office of the Personal Data Protection Committee (PDPC) began requiring certain organizations to appoint them. On July 7, 2026, the Office of the PDPC presented draft guidance on DPOs as part of a public consultation on a series of draft personal data protection manuals and recommendations. The draft offers the clearest indication yet of how the regulator expects the DPO role to work in practice, addressing recurring implementation issues under the PDPA—including when an organization must appoint a DPO, how the DPO should operate independently, how to manage conflicts of interest, and how data subjects and regulators should be able to contact the DPO. Because it remains in draft, organizations have an opportunity to weigh the practical implications now before the guidance is finalized. When a DPO Must Be Appointed The draft guidance clarifies the triggers for mandatory DPO appointment, including: Regular and systematic monitoring of personal data or systems on a large scale, such as tracking, analyzing, or predicting behavior, attitudes, or individual characteristics. Core activities involving large-scale processing of sensitive personal data, such as health data, biometric data, or criminal records. Certain foreign-organization representative arrangements. Public-sector coverage under relevant notifications identifying government entities that must appoint a DPO. Processing involving 100,000 or more data subjects may be considered large-scale. The guidance also contemplates voluntary DPO appointment for organizations that wish to raise their privacy governance standards, and such organizations should still comply with the standards applicable to DPOs under the law. Independence and Reporting Lines The draft guidance identifies lack of DPO independence as a core risk because an ineffective or constrained DPO may be unable to raise deficiencies
July 27, 2026
Vietnam’s new E-Commerce Law, which took effect on 1 July 2026 along with its implementing Decree No. 248/2026/ND-CP (Decree 248), marks a significant development in the country’s approach to online intellectual property (IP) enforcement, reflecting a clear shift from a reactive model of intermediary liability to one that expects platforms to play a more active role in preventing infringement. From notice-and-takedown to platform responsibility The most significant change introduced by the E-Commerce Law is the transformation of the legal role of e-commerce platforms. The existing safe harbor provisions under the IP Law and the copyright notice-and-takedown regime established by Decree 17/2023/ND-CP (Decree 17) largely required intermediaries to act only after receiving notice of infringement. Once infringing content had been removed, the platform’s legal obligation was generally considered fulfilled. The new legislation adopts a fundamentally different approach. Article 17 of the E-Commerce Law requires intermediary platforms to screen information relating to goods and services before publication in order to prevent listings involving counterfeit or IP-infringing goods, and goods of unknown origin. Rather than relying exclusively on complaints from rights holders, platforms are now expected to implement preventive measures before infringing listings become publicly available. Decree 248 further requires platforms to update keyword filters based on recommendations issued by competent authorities. These filtering mechanisms are intended to prevent prohibited listings from appearing on the platform and represent a further move away from a purely complaint-driven enforcement model. The legislation also introduces Vietnam’s first statutory stay-down obligation. Under the E-Commerce Law and Decree 248, major digital platforms must maintain automated systems capable of reviewing, warning against, and removing unlawful listings while also implementing measures to prevent repeat violations, defined under Decree 248 as conduct that has previously been identified and handled by the platform, but continues to recur. This obligation addresses one