You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

March 2, 2020

What Cambodia’s New Law on Electronic Commerce Means for Business

Informed Counsel

On November 2, 2019, Cambodia enacted the Law on Electronic Commerce (“E-commerce Law”). This development makes Cambodia the last member of the Association of Southeast Asian Nations (ASEAN)—one of the world’s fastest-growing internet markets—to adopt a domestic e-commerce law. The E-commerce Law addresses electronic communications, signatures, records, and evidence, and serves to clarify the legal environment for e-commerce in Cambodia.

In the last decade, Cambodia has experienced rapid development in the financial technology sector, and financial services and products have become more accessible to Cambodians. This financial inclusion, coupled with the availability of smart devices connected to the internet, enables local e-commerce startups and encourages foreign e-commerce businesses to enter the market. To strengthen trust and security in the online realm, Cambodia’s E-commerce Law regulates the activities of e-commerce service providers and intermediaries. The law also imposes consumer protection obligations, including data protection and cybersecurity obligations, on all e-commerce businesses. 

The E-commerce Law aims to regulate domestic and cross-border activities in Cambodia. All commercial and civil acts, documents, and transactions executed via an electronic system are subject to the E-commerce Law unless they are related to powers of attorney, wills and successions, or real estate.

The E-Commerce Law will take effect in May 2020. During the six-month gap between the law’s passage and its implementation, companies should familiarize themselves with the new obligations under the law, while government agencies are expected to issue regulations to clarify and implement the law. 

Electronic Communications   

The provisions on electronic communications that are found in a portion of Cambodia’s E-commerce Law primarily derive from two influential works of the United Nations Commission on International Trade Law (UNCITRAL); the 1996 Model Law on Electronic Commerce (MLEC) and the 2005 United Nations Convention on the Use of Electronic Communications in International Contracts (the “Electronic Communications Convention” or ECC).

Cambodia’s E-commerce Law explicitly recognizes the validity, legal effect, admissibility, and enforceability of electronic communications and reconfirms that contracts can be made electronically. Furthermore, electronic communications may satisfy requirements imposed by outdated  laws (e.g., “written,” “signed,” or “original” documents), if they fulfill certain conditions set out in the law.

The E-commerce Law generally considers an electronic communication to be sent when it leaves the originator’s information system and to be received when it becomes capable of being retrieved by the addressee. The places of business of the originator and addressee, respectively, are considered as the locations where an electronic communication is dispatched and received.   

It should be noted that Cambodia’s E-commerce Law does not include comprehensive provisions on matters related to the attribution of electronic communications and acknowledgment of receipt, as suggested by the MLEC. For example, the MLEC clarifies that if an originator states that an email is conditional on receipt of its acknowledgment, that email would not be considered as sent until the originator receives the acknowledgment. The Cambodian legislation contains no such clarification.

Electronic Signatures, Electronic Records, and Electronic Evidence

The E-commerce Law sets conditions for electronic signatures, including digital and biometric signatures, and electronic records to be deemed secure. By meeting these statutory qualifications, secure electronic records are presumed to have not been altered, and secure electronic signatures are presumed to be of the signatories having the intent to sign.   

In late 2017, prior to the enactment of the E-commerce Law, Cambodia introduced a sub-decree on digital signatures. This regulation provides legal recognition to digital signatures with a digital signature certificate issued by a licensed digital signature certification authority. However, the sub-decree has not been implemented yet as no license has been issued to any digital signature certification authority. Cambodia is likely to start implementing the regulation at the same time as the E-commerce Law. It will be important to observe how these two legal instruments correspond with each other in practice.

Cambodia’s E-commerce Law, with certain provisions similar to the Model Law on Electronic Evidence by the Commonwealth of Nations, also supports the admissibility of electronic records as evidence in legal proceedings. The mere fact that evidence is an electronic record cannot be used as grounds to render the evidence inadmissible.

The E-commerce Law also establishes rules on the validity, integrity, and authenticity of electronic evidence. The validity of electronic evidence relies on the integrity of the electronic system that stores or records the data in question. The E-commerce Law determines circumstances in which an electronic record satisfies the element of integrity unless proven otherwise. The party introducing the evidence has the burden to prove its authenticity, and to do so the E-commerce Law allows that party to present the court with an authenticity certificate issued by, for example, a competent authority or a court-appointed expert.

E-commerce Service Providers and Intermediaries, and Electronic Payment Systems

E-commerce service providers and intermediaries are now required under the E-commerce Law to obtain operating licenses from the Ministry of Commerce (MOC) and the Ministry of Post and Telecommunications (MPTC). However, the definitions of e-commerce service providers and intermediaries are crafted broadly, and it is unclear whether these licensing requirements also capture offshore e-commerce service providers and intermediaries operating without any local presence or permanent establishment in Cambodia. Since the E-commerce Law states that exceptions to this licensing regime will be clarified in the future, we hope Cambodia will issue implementing regulations that address this ambiguity before the law is implemented in May 2020.

The E-commerce Law creates a safe harbor rule for e-commerce service providers and intermediaries whereby they are not liable for unlawful third-party content on their online platforms; however, they must comply with certain mandatory content removal procedures upon becoming aware of such content. Additionally, they are obligated to comply with an e-commerce code of conduct.

The E-commerce Law also reaffirms that e-commerce service providers and intermediaries are subject to tax laws and incentives, just like brick-and-mortar businesses.     

Payment service providers must also obtain authorization or a license from the National Bank of Cambodia (NBC) before commencing operations, such as operating a payment system, providing payment services, or issuing electronic payments. However, many existing banking and financial institutions in Cambodia have already been providing these payment services and have obtained necessary authorizations under various laws (e.g., the Prakas on Payment Service Providers and the Law on Banking and Financial Institutions). For that reason, it remains uncertain whether the E-commerce Law merely reiterates the existing licensing regime for payment service providers or establishes a new, separate one.

In addition, the E-commerce Law outlines situations where payment service providers must be liable for the damage caused to customers unless the damage is caused by force majeure or the customer’s own fault.

Consumer Protection and Data Protection

Besides obligations under the newly legislated Law on Consumer Protection, which are applicable to both online and offline businesses, the E-commerce Law imposes additional requirements to which e-commerce enterprises must adhere.

The E-commerce Law requires anyone selling goods or services using electronic communications, except insurance and security companies, to disclose information that is necessary for customers to decide whether to purchase the goods or services. The information must at least include names, addresses, contacts, costs of the products and services, and terms and conditions for payments, cancellation, refunds, and so on. Furthermore, it is strictly prohibited to send unsolicited communications without providing clear and straightforward opt-out instructions irrespective of the originator’s or recipient’s locations. 

Data protection rules that apply to all sectors have also been set out for the first time in the E-commerce Law. Any business that electronically stores personal information is now obligated to establish all necessary measures to ensure that the data are reasonably protected from loss or unauthorized access, use, alteration, leaks, or disclosures. In addition, a person who enters information inaccurately to an automated system that does not allow any modification has the right to correct or delete the inaccurate information.

The E-commerce Law is much-welcomed by consumers, and is a positive step for the country’s digital environment. In addition, the harmonization that it brings with other countries should encourage cross-border transactions and paperless interactions among businesses and between businesses and governmental bodies.

RELATED INSIGHTS​ 

June 25, 2025
Generative artificial intelligence (GenAI) is no longer a distant innovation confined to science fiction and research labs; it has become an integral part of daily business operations worldwide. Employees across industries are adopting GenAI tools at a remarkable pace—including in Southeast Asia, where a tech-savvy workforce and widespread internet and mobile access have driven early adoption. The reality facing organizations today is clear: employees are integrating GenAI into their daily work, often without official approval or clear policies. This phenomenon, often called “Bring Your Own AI,” comes out of a disconnect between organizational governance and employee behavior and reveals the urgent need for proactive AI policies and oversight. For business leaders and legal teams, GenAI is both an opportunity and a challenge. On one hand, these tools can deliver real business value and boost efficiency. On the other, the unsanctioned and unmonitored use of GenAI introduces substantial legal risks, such as data privacy violations, confidentiality breaches, and intellectual property issues. The widespread adoption of GenAI tools by employees, regardless of official organizational stance or guidelines, demonstrates that prohibition is neither practical nor effective. A more strategic approach involves establishing comprehensive governance policies that encourage responsible AI use while managing the risks. Organizations that take the lead in developing GenAI governance policies are better positioned to benefit from its transformative potential. The question isn’t whether GenAI will change how we work, but how quickly organizations can put the right safeguards in place to manage this change successfully. Risks of GenAI Use The use of GenAI in business operations, whether sanctioned or not, exposes organizations to a unique set of risks. The following are particularly relevant: Data security and confidentiality: General GenAI tools in the market may transmit data to external servers, retain conversation histories, and use inputs for model training.
June 19, 2025
The Bank of Thailand (BOT) has released draft guidelines establishing principles for managing artificial intelligence (AI) risks in the financial sector. The draft guidelines provide a structured framework for the responsible adoption of AI technologies. Financial service providers will be able to use the guidelines as a reference to appropriately manage their risks in a manner that aligns with internationally recognized best practices. The BOT is accepting public comments on the draft guidelines until June 30, 2025. Scope and Application The draft guidelines apply to all financial service providers, including financial institutions and special financial institutions under the Financial Institution Business Act, as well as payment providers under the Payment Systems Act. These guidelines supplement existing BOT risk management guidelines covering IT risk management, third-party risk management, data governance, and market conduct. The guidelines define AI systems as systems that mimic human intelligence, including machine learning, deep learning, generative AI (such as large language models), and agentic AI. This definition specifically excludes rule-based automation systems like robotic process automation and condition matching. Key Risk Management Principles The guidelines lay out two main principles in managing AI risk. Governance: Financial service providers should define and establish clear roles and responsibilities for their personnel and AI system supervision structures to uphold FEAT (fairness, ethics, accountability, and transparency) principles as follows: Stakeholder roles and responsibilities. Financial service providers should define roles and responsibilities for boards and executives on AI risk oversight. Responsibilities include establishing an AI system usage policy, designating personnel responsible for AI risk management, and building awareness of AI-related risk within the organization. AI system usage policy. The AI system usage policy should be aligned with organizational objectives, regulatory requirements, and FEAT principles. These policies should be reviewed regularly to respond to technological advancements and evolving risk profiles. Risk management
June 19, 2025
Thailand’s Electronic Transactions Development Agency (ETDA) has announced plans for increased enforcement of the Royal Decree on the Operation of Digital Platform Service Businesses That Are Subject to Prior Notification B.E. 2565 (2022). The ETDA outlined a comprehensive enforcement framework and review process during an online meeting with digital platform service operators on June 11, 2025. The ETDA’s enhanced enforcement approach includes systematic reviews of notification submissions, formal correction orders, and potential criminal penalties for noncompliance. Digital platform operators should immediately assess their current notification status and prepare for increased regulatory scrutiny. Review and Amendment of Previously Submitted Notification Data The ETDA will begin reviewing operation notification forms and annual reports submitted by digital platform service operators to assess each platform’s risk level and develop tailored regulatory obligations. In this comprehensive review process, the ETDA will: Examine the accuracy and completeness of submitted notification data; Request additional information as needed by phone or email; and Issue formal orders as needed requiring operators to correct or complete missing information. Operators who fail to comply with ETDA orders may face suspension of operations, revocation of their notification receipt, and public disclosure of their noncompliant status on the ETDA’s website. The ETDA will conduct follow-up workshops in July 2025 for operators whose data remains unclear or incomplete. Enforcement Framework and Penalties The ETDA outlined a three-tiered enforcement framework with escalating consequences for different types of violations, as follows: Failure to notify before commencing operations: Operators who begin services without proper notification may face criminal penalties under the Electronic Transactions Act, including up to one year of imprisonment, fines of up to THB 100,000 (approx. USD 3,070), or both. Additional consequences include suspension of operations and potential liability for company directors. Failure to correct or comply with official orders: Noncompliance with ETDA correction
June 13, 2025
In today’s digital age, cyberattacks have become a real threat to organizations worldwide. These attacks can range from phishing and malware to ransomware and distributed denial of service (DDoS) attacks. As the frequency and sophistication of these attacks increase, so does the importance of cybersecurity compliance. In the corporate world, compliance refers to the process of ensuring that a company and its employees adhere to all relevant laws, regulations, standards, and ethical practices—but it should not stop there. Compliance should also encompass asset recovery and disciplinary measures, which can both help organizations address incidents effectively and promote good governance. Cyberattacks are malicious attempts to access or damage a computer system or network, often carried out for financial gain, for political activism, or simply to cause disruption. For instance, a successful attack might involve an attacker creating an email address that closely resembles a legitimate one, perhaps by changing only one or two characters. That email address is then inserted into an existing conversation thread, making it appear as if the user with this email address was already part of the discussion. This tactic can easily deceive a recipient into believing the email was sent from a trusted source, thereby leading them to click on malicious links, provide sensitive information, or even make payments in accordance with the attacker’s request or instructions. Phishing attacks like these are particularly dangerous and can have a serious impact on the ongoing business of a corporation because they exploit the trust and familiarity established in the original email chain. Effective Mitigation Approaches Mechanisms for addressing the aftermath of a crisis provide important recourse to affected organizations, but effective compliance mechanisms can minimize the risk of such crises ever occurring. Companies should therefore prioritize preventative measures and implementation of effective crisis management schemes. Various legal