Skip to content

Evidence request lists

Regional Comprehensive Economic Partnership (RCEP) - E-Commerce Chapter

Evidence request list. 22 controls, 22 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Chapter 12 General Provisions

RCEP-EC-12.2
Definitions

Defines key terms including covered person, computing facilities, electronic authentication, electronic signature, personal information, and trade administration documents for chapter application.

Artefacts an auditor will ask for
  • Definition mapping document
  • Domestic statute cross-reference
  • Scope determination memos
Where this commonly fails
  • Domestic definitions diverge from chapter terms
  • Covered person scope not documented
  • Sectoral application unclear
RCEP-EC-12.3
Scope

The chapter applies to measures adopted or maintained by a Party affecting electronic commerce, with carve-outs for government procurement, information held by governments, and financial services.

Artefacts an auditor will ask for
  • Scope memo
  • Carve-out register
  • Sectoral coverage matrix
  • Financial services scope opinion
Where this commonly fails
  • Procurement applications not separated
  • Government data carve-out misapplied to commercial data
  • Financial services interplay unclear
RCEP-EC-12.4
Cooperation on E-Commerce

Parties cooperate on regulatory, technical, and capacity matters to promote digital trade and address barriers affecting micro, small, and medium enterprises.

Artefacts an auditor will ask for
  • Bilateral cooperation MOUs
  • RCEP e-commerce working group minutes
  • MSME outreach reports
  • Capacity-building program rosters
  • Joint research outputs
Where this commonly fails
  • No documented participation in RCEP working groups
  • Missing MSME engagement metrics
  • Cooperation activities not tied to chapter obligations

Consumer Protection

RCEPEC-3
Consumer Protection, Paperless Trading, Customs (12.11-12)

Per RCEP: Customs Duties on Electronic Transmissions (moratorium) + Online Consumer Protection + Paperless Trading.

Artefacts an auditor will ask for
  • RCEP evidence for RCEPEC-3
Where this commonly fails
  • localization + cooperation partial

Consumer and Personal Information Protection

RCEP-EC-12.7
Online Consumer Protection

Each Party shall adopt or maintain consumer protection laws to proscribe fraudulent and deceptive commercial activities that cause harm to consumers engaged in online commerce.

Artefacts an auditor will ask for
  • Consumer protection statutes
  • Enforcement action registers
  • Online complaint portal logs
  • ICPEN or APEC cooperation records
  • Annual consumer agency reports
Where this commonly fails
  • Online-specific provisions absent
  • Cross-border redress mechanisms not operational
  • Enforcement statistics not published
RCEP-EC-12.8
Online Personal Information Protection

Each Party shall adopt or maintain a legal framework providing for the protection of personal information of users of electronic commerce, taking account of international standards and principles.

Artefacts an auditor will ask for
  • Personal data protection statute
  • Data protection authority annual report
  • Cross-border transfer guidance
  • Breach notification register
  • Privacy impact assessment templates
Where this commonly fails
  • No statutory privacy framework
  • User rights not enforceable
  • International alignment claims not substantiated
RCEP-EC-12.9
Unsolicited Commercial Electronic Messages

Each Party shall adopt or maintain measures regarding unsolicited commercial electronic messages, including requirements for consent or opt-out and recourse for non-compliant senders.

Artefacts an auditor will ask for
  • Anti-spam statute
  • Consent capture records
  • Opt-out infrastructure logs
  • Regulator enforcement actions
  • Cross-border spam complaint cooperation
Where this commonly fails
  • No central anti-spam regulator
  • Consent records not retained
  • Opt-out requests not honoured within prescribed time

Cross-Border

RCEPEC-2
Cross-Border Transfer, Computing Facilities, Localization (12.14-15)

Per RCEP: Location of Computing Facilities + Cross-Border Transfer of Information by Electronic Means including general permission + reasonable exceptions.

Artefacts an auditor will ask for
  • RCEP evidence for RCEPEC-2
Where this commonly fails
  • localization + cooperation partial

Cyber Security and Cross Border Data Flows

RCEP-EC-12.13
Cyber Security

Parties recognise the importance of building capabilities of their national entities responsible for computer security incident response and of using collaboration mechanisms to address cyber threats.

Artefacts an auditor will ask for
  • National CSIRT charter
  • Membership in FIRST or APCERT
  • Bilateral CSIRT MOUs
  • Incident response playbooks
  • Threat intelligence sharing logs
Where this commonly fails
  • CSIRT not operational 24x7
  • No formal sharing arrangements with RCEP partners
  • Exercises not conducted within prior 24 months
RCEP-EC-12.14
Location of Computing Facilities

No Party shall require a covered person to use or locate computing facilities in that Party's territory as a condition for conducting business, subject to legitimate public policy and security exceptions.

Artefacts an auditor will ask for
  • Inventory of localisation requirements by sector
  • Legitimate public policy justifications
  • Essential security interest declarations
  • Industry impact assessments
Where this commonly fails
  • Sectoral localisation rules without necessity analysis
  • Exception scope overbroad
  • No review mechanism
RCEP-EC-12.15
Cross-Border Transfer of Information by Electronic Means

No Party shall prevent a covered person from transferring information, including personal information, by electronic means across borders when this activity is for the conduct of business, subject to legitimate public policy objectives.

Artefacts an auditor will ask for
  • Cross-border data transfer policy
  • Standard contractual clause templates
  • Public policy exception register
  • Sectoral restrictions inventory
Where this commonly fails
  • De facto restrictions through sectoral guidance
  • Exception necessity not demonstrated
  • Covered person definition not aligned

Cybersecurity

RCEPEC-4
Cybersecurity, Cooperation, Dispute Resolution

Per RCEP: cybersecurity cooperation + dispute resolution mechanisms + e-commerce framework cooperation.

Artefacts an auditor will ask for
  • RCEP evidence for RCEPEC-4
Where this commonly fails
  • localization + cooperation partial

Dialogue and Dispute Settlement

RCEP-EC-12.16
Dialogue on Electronic Commerce

Parties shall convene dialogues to exchange information and experiences on electronic commerce, including emerging issues such as digital identity, online payments, and platform regulation.

Artefacts an auditor will ask for
  • Dialogue meeting minutes
  • Position papers submitted
  • Action item registers
  • Implementation reports
Where this commonly fails
  • No participation records
  • Dialogue topics not aligned with chapter scope
  • Action items not closed
RCEP-EC-12.17
Settlement of Disputes

Specified articles of the E-Commerce chapter are not subject to the dispute settlement mechanism under the agreement, with the dialogue process being the primary recourse.

Artefacts an auditor will ask for
  • Memorandum on dispute settlement carve-outs
  • Consultation request register
  • Bilateral resolution outcomes
Where this commonly fails
  • Internal teams assume full DSU coverage
  • Consultation procedures not documented
  • Alternative recourse mechanisms unclear

Domestic Regulation and Transparency

RCEP-EC-12.10
Domestic Regulatory Framework

Each Party shall adopt or maintain a legal framework governing electronic transactions consistent with the UNCITRAL Model Law on Electronic Commerce or the UN Convention on Electronic Communications.

Artefacts an auditor will ask for
  • Electronic transactions act
  • Gap analysis against UNCITRAL model law
  • Sectoral regulations referencing e-transactions
  • Court decisions on electronic contract enforceability
Where this commonly fails
  • Statute predates UN convention without alignment review
  • Sectoral exclusions not mapped
  • Functional equivalence principles missing
RCEP-EC-12.11
Customs Duties on Electronic Transmissions

Parties confirm the practice of not imposing customs duties on electronic transmissions between the Parties, reviewable in light of WTO outcomes.

Artefacts an auditor will ask for
  • Customs tariff publications
  • Treasury directives on digital imports
  • Audit trail of cross-border digital invoices
  • WTO General Council statement adherence
Where this commonly fails
  • VAT or GST applied in a manner functionally equivalent to a tariff
  • Tariff classification of digital goods unclear
  • Review obligation not actioned
RCEP-EC-12.12
Transparency

Each Party shall publish, or otherwise make publicly available, its laws, regulations, and procedures applicable to electronic commerce.

Artefacts an auditor will ask for
  • Government gazette references
  • Public consultation registers
  • Translated regulations where required
  • Enquiry point contact list
Where this commonly fails
  • Regulations not available in working language of the Party
  • Enquiry point not staffed
  • Subordinate guidance unpublished

Implementation

RCEP-EC-IMPL-01
Implementation Reporting

Parties report on implementation progress of e-commerce chapter obligations through the agreement governance structure.

Artefacts an auditor will ask for
  • Annual implementation reports
  • RCEP committee submissions
  • Status dashboards
Where this commonly fails
  • No internal implementation owner
  • Reports not aligned to chapter articles
  • Governance committee participation gaps
RCEP-EC-IMPL-02
Stakeholder Consultation

Implementation includes industry and consumer stakeholder consultation channels on e-commerce policy and reform.

Artefacts an auditor will ask for
  • Stakeholder consultation policy
  • Meeting attendee lists
  • Public submission registers
  • Response documents
Where this commonly fails
  • Consultation limited to large firms
  • MSME voices not captured
  • Submissions not addressed in policy outcomes

Personal Info

RCEPEC-1
Online Personal Information Protection (12.13)

Per RCEP E-Commerce Chapter Article 12.13: online personal information protection including legal framework + enforcement + cross-border consistency.

Artefacts an auditor will ask for
  • RCEP evidence for RCEPEC-1
Where this commonly fails
  • localization + cooperation partial

Trade Facilitation and Electronic Authentication

RCEP-EC-12.5
Paperless Trading

Each Party endeavours to make trade administration documents available in electronic form and to accept electronic versions as the legal equivalent of paper documents.

Artefacts an auditor will ask for
  • Customs single window screenshots
  • Electronic certificate of origin records
  • Trade portal URLs and traffic reports
  • Legal opinion on electronic document equivalence
  • Bilateral interoperability arrangements
Where this commonly fails
  • Trade documents still require wet signatures
  • No interoperability with partner customs systems
  • Electronic versions exist but are not legally recognised
RCEP-EC-12.6
Electronic Authentication and Electronic Signature

Parties shall not deny legal validity of a signature solely because it is in electronic form and shall permit parties to determine appropriate authentication methods, subject to performance and certification requirements.

Artefacts an auditor will ask for
  • National e-signature legislation
  • Licensed certification authority register
  • Cross-border trust list memberships
  • Reliance party agreements
  • Audit reports of accredited CAs
Where this commonly fails
  • No formal recognition of foreign e-signatures
  • Sector carve-outs not documented
  • Certification authority oversight weak
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Regional Comprehensive Economic Partnership (RCEP) - E-Commerce Chapter framework page.