Ensuring Information Security in Electronic Transactions in Selected Countries

In the era of digital transformation, electronic transactions are becoming increasingly prevalent and have become an important foundation for commercial activities, public services, and social governance. Therefore, many countries have enacted legal regulations to protect parties involved in electronic transactions and ensure information security. 

1. European Union 

  • eIDAS Regulation 
    • Regulation (EU) No 910/2014 (eIDAS – electronic IDentification, Authentication and Trust Services) entered into force on 1 July 2016 in EU Member States.
    • eIDAS 2.0 – officially known as the European Digital Identity Framework under Regulation (EU) 2024/1183 – is the updated version of the European Union’s framework for electronic identification, authentication, and trust services. 
    • eIDAS clearly defines the different types of electronic signatures: Standard Electronic Signature (SES), Advanced Electronic Signature (AES), and Qualified Electronic Signature (QES). 
    • An electronic signature may be denied legal validity if it does not meet the applicable technical requirements or if sector-specific legislation requires a higher level of assurance; however, it may not be denied legal effect solely because it is in electronic form. 
    • eIDAS 2.0 further develops the regulatory framework for Qualified Trust Service Providers (QTSPs), with particular emphasis on identity verification processes for individuals and legal entities when qualified certificates are issued. The objective is to ensure greater consistency and harmonization across Europe. 
    • The new qualified trust services – including electronic archiving, electronic ledgers, and the management of remote electronic signature devices – have been introduced under eIDAS 2.0. 
    • One of the most significant innovations introduced by eIDAS 2.0 is the European Digital Identity Wallet (EUDI Wallet) as a core component of Member States’ digital identity ecosystems.
  • Information Security and Trust Services 
    • eIDAS requires trust service providers to comply with technical standards, obtain certification, and assume legal responsibility. These services include electronic signature certification, electronic seals, electronic authentication, etc. 
    • Cross-border electronic identification and authentication systems: electronic signatures or recognized services from one Member State must be recognized by other Member States subject to certain conditions. 
  • Personal Data Protection 
    • The EU has the GDPR (General Data Protection Regulation), which protects privacy and personal data and applies to all personal data processed in electronic transactions. 
    • GDPR sets out clear requirements regarding consent, data access rights, the right to rectification, the “right to be forgotten,” and sanctions for violations. 

2. United States 

  • ESIGN Act and UETA 
    • Electronic Signatures in Global and National Commerce Act (ESIGN Act) of 2000: a federal law recognizing electronic signatures as having legal validity equivalent to handwritten signatures, provided that the parties agree to use electronic methods; a contract may not be denied legal effect solely because it is in electronic form. 
    • Uniform Electronic Transactions Act (UETA): a state-level law adopted by most states that supplements the legal framework for electronic transactions and electronic signatures. 
  • Information Security & Data Protection 
    • Federal or state laws on the protection of personal information and user data (e.g., data privacy laws and privacy protection laws) help ensure information security for electronic transactions. 
    • Requirements for certification, authentication, electronic record retention, and evidence that may be used in disputes. 

3. Canada 

  • PIPEDA (Personal Information Protection and Electronic Documents Act) – a federal law that protects personal information and regulates the use of electronic records/documents. 
  • Provinces and territories also have their own laws that provide similar or supplementary legal frameworks for electronic transactions/electronic signatures. The Uniform Electronic Commerce Act (UECA) has been adopted by several provinces to promote legal consistency. 

4. Australia 

  • The Electronic Transactions Act 1999 (ETA) at the federal level, together with implementing regulations, enables electronic transactions to be conducted and electronic signatures to be legally recognized. 
  • States/Territories also have their own laws following similar approaches. Regulations address the authenticity and integrity of transactions, the consent of the parties, and the use of appropriate authentication methods depending on the level of risk. 

5. Vietnam 

  • Law on Electronic Transactions 2023 (No. 20/2023/QH15) 
    • Issued on 22 June 2023 and effective from 1 July 2024, replacing the 2005 Law on Electronic Transactions. 
    • Expanded scope of application: The Law governs electronic transactions across all sectors, including areas that were previously not permitted under the former law to be conducted electronically (e.g., land use right certificates, marriage registration certificates, birth certificates, death certificates, etc.), provided that sector-specific legislation does not prohibit electronic methods. 
    • Regulations on electronic signatures (“electronic signature”) and digital signatures (“digital signature”). The new Law classifies electronic signatures according to their purposes of use, including specialized electronic signatures, public digital signatures, and official-duty electronic signatures, to ensure authenticity. 
    • Foreign electronic signatures/digital certificates are recognized if certain conditions are satisfied, such as the foreign digital certificate provider meeting standards prescribed by Vietnamese law and potentially having a representative in Vietnam. 
  • Regulations Ensuring Information Security 
    • The new Law on Electronic Transactions incorporates requirements on “ensuring information security, cybersecurity, and compliance with personal data protection laws” – organizations and individuals participating in electronic transactions must comply with these laws. 
    • Prohibited acts in electronic transactions include: using electronic transactions to harm national interests or security; obstructing or disrupting information systems; unlawfully collecting, using, disclosing, or disseminating data/data messages; forging, altering, or deleting data messages; fraud or forgery of electronic signatures and digital certificates; and unauthorized use of accounts, certificates, or digital signatures. 
  • Strengths and Limitations 
    • Advantages: The new Law has broader coverage and is more aligned with technological developments, eliminating the “gaps” left by the previous law. Recognition of foreign electronic signatures/digital certificates supports international transactions. It clearly defines prohibited acts, penalties, and legal responsibilities. 
    • Limitations/Challenges: The enforcement, inspection, and supervision of technical standards, as well as the security capabilities of certificate/digital signature service providers. Technical and security requirements are relatively high, creating difficulties for small organizations and those in remote and rural areas with limited technological infrastructure. Issues relating to personal data protection and privacy in electronic transactions, particularly when data is exchanged across borders, have also not yet been sufficiently emphasized. 

The laws governing electronic transactions in many countries, particularly developed economies, have become relatively comprehensive, covering legal frameworks, electronic signature/trust service regulations, personal data protection, enforcement of violations, international recognition, and clear technical standards. However, challenges remain regarding data security, personal data protection, and legal compliance, which need to be further strengthened and more rigorously developed. 

Reference:

Latest Blogs