Skip to content

Evidence request lists

Digital Economy Partnership Agreement (DEPA)

Evidence request list. 35 controls, 35 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

DEPA Module 1: Initial Provisions and General Definitions

DEPA-1.1
Scope

The Agreement applies to measures adopted or maintained by a Party affecting trade in the digital economy, establishing the scope of the digital trade rules among the Parties.

Artefacts an auditor will ask for
  • Domestic measures/laws implementing the obligation
  • Records of cooperation/notification activities under the article
Where this commonly fails
  • No domestic measure giving effect to the obligation
  • Treating the cooperation provision as non-binding without any implementing action
DEPA-1.2
Relation to Other Agreements

The Parties affirm their existing rights and obligations under other international agreements (e.g., the WTO Agreement) and address the relationship of DEPA to those agreements.

Artefacts an auditor will ask for
  • Domestic measures/laws implementing the obligation
  • Records of cooperation/notification activities under the article
Where this commonly fails
  • No domestic measure giving effect to the obligation
  • Treating the cooperation provision as non-binding without any implementing action
DEPA-1.3
General Definitions

Sets out the definitions applicable throughout the Agreement (including terms such as person, covered person, computing facilities, and personal information).

Artefacts an auditor will ask for
  • Consistent use of the defined terms in domestic implementing measures
Where this commonly fails
  • Inconsistent or absent transposition of key DEPA definitions

DEPA Module 2: Business and Trade Facilitation

DEPA-2.2
Paperless Trading

Each Party shall endeavour to make trade administration documents available to the public in electronic form and to accept electronic versions of trade administration documents as the legal equivalent of paper documents.

Artefacts an auditor will ask for
  • Single-window / electronic trade-document systems
  • Legal recognition of electronic trade administration documents
Where this commonly fails
  • Mandatory paper submissions with no electronic equivalent
DEPA-2.3
Domestic Electronic Transactions Framework

Each Party shall maintain a legal framework governing electronic transactions consistent with the UNCITRAL Model Law on Electronic Commerce 1996 or the UN Convention on the Use of Electronic Communications in International Contracts, and shall avoid unnecessary regulatory burden on electronic transactions.

Artefacts an auditor will ask for
  • An electronic transactions law consistent with the UNCITRAL Model Law / UN ECC
Where this commonly fails
  • No legal framework recognising electronic transactions
  • Framework inconsistent with the referenced UNCITRAL instruments
DEPA-2.4
Logistics

The Parties recognise the importance of an efficient and digitalised logistics sector and shall cooperate to facilitate trade through improvements in logistics, including the use of digital technologies.

Artefacts an auditor will ask for
  • Domestic measures/laws implementing the obligation
  • Records of cooperation/notification activities under the article
Where this commonly fails
  • No domestic measure giving effect to the obligation
  • Treating the cooperation provision as non-binding without any implementing action
DEPA-2.5
Electronic Invoicing

The Parties recognise the importance of e-invoicing and shall endeavour to ensure the interoperability of their respective e-invoicing systems and base measures on international frameworks.

Artefacts an auditor will ask for
  • E-invoicing framework aligned to international interoperability standards
Where this commonly fails
  • Closed, non-interoperable e-invoicing systems
DEPA-2.6
Express Shipments

Each Party shall adopt or maintain expedited customs procedures for express shipments while maintaining appropriate customs control and selection.

Artefacts an auditor will ask for
  • Expedited customs procedures for express shipments
Where this commonly fails
  • No expedited release process for express consignments
DEPA-2.7
Electronic Payments

The Parties recognise the importance of enabling secure, efficient and interoperable electronic payments and shall support the development of e-payment systems, adoption of international standards, and interoperability and innovation in electronic payments.

Artefacts an auditor will ask for
  • Measures supporting interoperable, standards-based electronic payments
Where this commonly fails
  • Barriers to interoperable or innovative e-payment services

DEPA Module 3: Treatment of Digital Products

DEPA-3.2
Customs Duties

No Party shall impose customs duties on electronic transmissions, including content transmitted electronically, between persons of the Parties (without prejudice to the imposition of internal taxes consistent with the Agreement).

Artefacts an auditor will ask for
  • Customs tariff treatment confirming no duties on electronic transmissions
Where this commonly fails
  • Imposing customs duties on electronic transmissions/digital content
DEPA-3.3
Non-Discriminatory Treatment of Digital Products

No Party shall accord less favourable treatment to a digital product created, produced, published, stored, transmitted, contracted for, commissioned or first made available on commercial terms in the territory of another Party than it accords to other like digital products (subject to specified exceptions, e.g. subsidies, broadcasting).

Artefacts an auditor will ask for
  • Measures ensuring non-discriminatory treatment of foreign digital products
Where this commonly fails
  • Discriminatory treatment of another Party's digital products
DEPA-3.4
ICT Products that Use Cryptography

A Party shall not require a manufacturer or supplier of an ICT product that uses cryptography, as a condition of manufacture/sale/distribution/import/use, to transfer or provide access to proprietary cryptographic information (such as private keys or algorithms) or to partner with a person in its territory (subject to defined law-enforcement and regulatory carve-outs).

Artefacts an auditor will ask for
  • Measures confirming no forced disclosure of proprietary cryptographic information as a market-access condition
Where this commonly fails
  • Mandating key escrow or cryptographic technology transfer as a condition of market access

DEPA Module 4: Data Issues

DEPA-4.2
Personal Information Protection

Each Party shall adopt or maintain a legal framework that provides for the protection of the personal information of users of electronic commerce and digital trade, taking into account international principles, guidelines and criteria (e.g., the APEC Privacy Framework and OECD Guidelines), and shall promote compatibility and interoperability between its regime and those of the other Parties.

Artefacts an auditor will ask for
  • A national personal information protection / data protection law
  • Mechanisms promoting interoperability of privacy regimes (e.g. CBPR)
Where this commonly fails
  • No legal framework for personal information protection
  • Framework not informed by recognised international privacy principles
DEPA-4.3
Cross-Border Transfer of Information by Electronic Means

Each Party shall allow the cross-border transfer of information by electronic means, including personal information, when this activity is for the conduct of the business of a covered person; a Party may adopt measures inconsistent with this provided they are not a disguised restriction on trade and do not impose restrictions greater than necessary to achieve a legitimate public policy objective.

Artefacts an auditor will ask for
  • Measures permitting cross-border data flows for business
  • Documented legitimate-public-policy justification for any restriction
Where this commonly fails
  • Blanket data-flow prohibitions
  • Restrictions exceeding what is necessary for a legitimate objective
DEPA-4.4
Location of Computing Facilities

No Party shall require a covered person to use or locate computing facilities in that Party's territory as a condition for conducting business in that territory, subject to a legitimate-public-policy-objective exception that is not a disguised restriction on trade and is not more restrictive than necessary.

Artefacts an auditor will ask for
  • Measures confirming no data-localisation requirement as a condition of doing business
  • Justification for any localisation measure
Where this commonly fails
  • Mandatory data/computing-facility localisation without a legitimate-objective basis

DEPA Module 5: Wider Trust Environment

DEPA-5.1
Cybersecurity Cooperation

The Parties recognise the evolving nature of cybersecurity threats and shall cooperate to build the capabilities of their national cybersecurity entities, share information and best practices, and promote risk-based approaches and workforce development for cybersecurity.

Artefacts an auditor will ask for
  • CSIRT/national-cyber-entity cooperation arrangements
  • Information-sharing and capability-building activities
Where this commonly fails
  • No mechanism for cross-border cybersecurity cooperation
DEPA-5.2
Online Safety and Security

The Parties recognise the importance of online safety and security and shall cooperate to promote a safe and secure online environment, including protections for users.

Artefacts an auditor will ask for
  • Domestic measures/laws implementing the obligation
  • Records of cooperation/notification activities under the article
Where this commonly fails
  • No domestic measure giving effect to the obligation
  • Treating the cooperation provision as non-binding without any implementing action

DEPA Module 6: Business and Consumer Trust

DEPA-6.2
Unsolicited Commercial Electronic Messages

Each Party shall adopt or maintain measures regarding unsolicited commercial electronic messages that require suppliers to facilitate recipients' ability to prevent ongoing reception (opt-out/consent), require consent as specified, or otherwise provide for minimisation, and shall provide recourse against non-compliant suppliers.

Artefacts an auditor will ask for
  • Anti-spam law with consent/opt-out and enforcement
  • Records of enforcement against non-compliant senders
Where this commonly fails
  • No anti-spam regime
  • No recourse mechanism for recipients
DEPA-6.3
Online Consumer Protection

Each Party shall adopt or maintain consumer protection laws to proscribe fraudulent, misleading or deceptive conduct that causes harm to consumers engaged in electronic commerce, and shall promote cooperation between national consumer protection agencies on cross-border e-commerce.

Artefacts an auditor will ask for
  • Consumer protection law covering online fraudulent/deceptive conduct
  • Cross-border consumer-agency cooperation
Where this commonly fails
  • No online consumer protection enforcement
  • No cross-border cooperation on e-commerce consumer harm
DEPA-6.4
Principles on Access to and Use of the Internet

The Parties recognise the benefits of consumers in their territories being able to access and use services and applications of their choice available on the internet (subject to reasonable network management), connect end-user devices of their choice, and access information on network management practices.

Artefacts an auditor will ask for
  • Domestic measures/laws implementing the obligation
  • Records of cooperation/notification activities under the article
Where this commonly fails
  • No domestic measure giving effect to the obligation
  • Treating the cooperation provision as non-binding without any implementing action

DEPA Module 7: Digital Identities

DEPA-7.1
Digital Identities

Recognising that interoperable digital identity regimes promote connectivity and growth in the digital economy, the Parties shall pursue mechanisms to promote compatibility and interoperability between their respective digital identity regimes, including through technical interoperability, common standards and mutual recognition.

Artefacts an auditor will ask for
  • Digital identity framework and standards
  • Arrangements pursuing mutual recognition / interoperability of digital IDs
Where this commonly fails
  • No interoperability strategy for digital identity

DEPA Module 8: Emerging Trends and Technologies

DEPA-8.1
Financial Technology Cooperation

The Parties recognise the importance of fintech to the growth of the digital economy and shall promote cooperation on fintech, including supporting the development of fintech solutions and collaboration between their fintech industries and regulators.

Artefacts an auditor will ask for
  • Domestic measures/laws implementing the obligation
  • Records of cooperation/notification activities under the article
Where this commonly fails
  • No domestic measure giving effect to the obligation
  • Treating the cooperation provision as non-binding without any implementing action
DEPA-8.2
Artificial Intelligence

The Parties recognise the economic and social importance of developing ethical and governance frameworks for the trusted, safe and responsible use of AI technologies, shall endeavour to adopt such frameworks taking into account internationally recognised principles or guidelines, and recognise the benefits of promoting their adoption.

Artefacts an auditor will ask for
  • A national AI ethics / governance framework informed by international principles
Where this commonly fails
  • No AI governance framework
  • Framework not aligned to recognised international AI principles
DEPA-8.3
Government Procurement

The Parties recognise the importance of cooperation on the use of digital technologies in government procurement and shall share information and experiences on the use of electronic means in their government procurement systems.

Artefacts an auditor will ask for
  • Domestic measures/laws implementing the obligation
  • Records of cooperation/notification activities under the article
Where this commonly fails
  • No domestic measure giving effect to the obligation
  • Treating the cooperation provision as non-binding without any implementing action
DEPA-8.4
Cooperation on Competition Policy

The Parties recognise the importance of cooperation on competition policy matters relevant to the digital economy and shall cooperate, as appropriate, on issues of mutual interest.

Artefacts an auditor will ask for
  • Domestic measures/laws implementing the obligation
  • Records of cooperation/notification activities under the article
Where this commonly fails
  • No domestic measure giving effect to the obligation
  • Treating the cooperation provision as non-binding without any implementing action

DEPA Module 9: Innovation and the Digital Economy

DEPA-9.3
Public Domain

The Parties recognise the importance of a rich and accessible public domain and the role it plays in innovation in the digital economy, and shall cooperate to identify ways to promote and expand access to the public domain.

Artefacts an auditor will ask for
  • Domestic measures/laws implementing the obligation
  • Records of cooperation/notification activities under the article
Where this commonly fails
  • No domestic measure giving effect to the obligation
  • Treating the cooperation provision as non-binding without any implementing action
DEPA-9.4
Data Innovation

The Parties recognise that data and the cross-border transfer of data drive the digital economy, and shall collaborate on data innovation, including by sharing research and industry practices and considering the use of regulatory sandboxes to facilitate trusted data-sharing and data-driven innovation.

Artefacts an auditor will ask for
  • Data-innovation collaboration activities
  • Use of regulatory sandboxes for trusted data sharing
Where this commonly fails
  • No mechanism to support data-driven innovation cooperation
DEPA-9.5
Open Government Data

Recognising that facilitating public access to and use of government information fosters economic and social development, each Party shall endeavour to make government data available in a machine-readable and open format that can be searched, retrieved, used, reused and redistributed.

Artefacts an auditor will ask for
  • Open government data published in machine-readable, open formats
Where this commonly fails
  • Government data locked in closed/proprietary formats
  • No open-data programme

DEPA Modules 10-11: SME Cooperation and Digital Inclusion

DEPA-10.1
SME Cooperation

The Parties recognise the fundamental role of SMEs in the digital economy and shall cooperate to enhance digital trade and investment opportunities for SMEs, share information (including through publicly accessible information), and maintain a dialogue on SME participation in the digital economy.

Artefacts an auditor will ask for
  • SME support programmes for digital trade
  • Publicly accessible information for SMEs on the Agreement
Where this commonly fails
  • No SME-focused digital-trade support
DEPA-11.1
Digital Inclusion

The Parties recognise the importance of digital inclusion so all people and businesses can participate in and benefit from the digital economy, and shall cooperate on inclusion matters, including for indigenous peoples, women, rural populations and low socio-economic groups.

Artefacts an auditor will ask for
  • Digital-inclusion initiatives and cooperation activities
Where this commonly fails
  • No digital-inclusion measures or cooperation

DEPA Modules 12-16: Institutional, Transparency, Dispute Settlement, Exceptions and Final Provisions

DEPA-12
Joint Committee and Contact Points

The Parties establish a Joint Committee to supervise implementation, review the Agreement, consider amendments and adopt decisions by consensus, and designate contact points to facilitate communications.

Artefacts an auditor will ask for
  • Designated DEPA contact point
  • Participation in / records of Joint Committee decisions
Where this commonly fails
  • No designated contact point
  • No engagement with the Joint Committee process
DEPA-13
Transparency

Each Party shall promptly publish or otherwise make available its laws, regulations and procedures of general application affecting matters covered by the Agreement, administer them in a consistent and impartial manner, provide review and appeal of administrative actions, and notify and provide information on request.

Artefacts an auditor will ask for
  • Publication of measures affecting the digital economy
  • Administrative review and appeal mechanisms
Where this commonly fails
  • Measures of general application not published
  • No avenue to review administrative actions
DEPA-14
Dispute Settlement

The Agreement provides a dispute settlement mechanism (good offices, conciliation, mediation and arbitration) for resolving disputes between the Parties regarding the interpretation or application of the Agreement.

Artefacts an auditor will ask for
  • Designated forum/procedures for DEPA dispute settlement
Where this commonly fails
  • No process to engage the DEPA dispute settlement mechanism
DEPA-15
Exceptions

Sets out the general exceptions, security exceptions, the Treaty of Waitangi exception (New Zealand), prudential and monetary/exchange-rate exceptions, taxation exception, and balance-of-payments safeguards that may justify otherwise-inconsistent measures.

Artefacts an auditor will ask for
  • Documented reliance on a DEPA exception where a measure derogates from an obligation
Where this commonly fails
  • Invoking an exception without meeting its conditions
DEPA-16
Final Provisions

Addresses the depositary (New Zealand), entry into force, amendments, accession by other economies, withdrawal, disclosure of information, confidentiality, the status of annexes and footnotes, and electronic signature of the Agreement.

Artefacts an auditor will ask for
  • Instruments of acceptance/accession as applicable
  • Compliance with confidentiality and disclosure provisions
Where this commonly fails
  • Non-compliance with accession or amendment procedures
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Digital Economy Partnership Agreement (DEPA) framework page.