Back to Frameworks

Regional Comprehensive Economic Partnership (RCEP) - E-Commerce Chapter

Asia-Pacific (15 RCEP members)
v2022 (effective)
11 domains
22 controls

The Regional Comprehensive Economic Partnership (RCEP), effective January 2022, includes a dedicated E-Commerce Chapter (Chapter 12) establishing digital trade rules among 15 Asia-Pacific countries (ASEAN-10, China, Japan, South Korea, Australia, New Zealand). RCEP covers the world's largest trading bloc by GDP (30% of global GDP). The E-Commerce Chapter addresses: electronic transactions legal framework, consumer protection online, personal data protection, cross-border data flows (with significant exceptions), paperless trading, and electronic authentication. Notable for balancing digital trade liberalisation with data sovereignty provisions.

Verified

Regional Comprehensive Economic Partnership (RCEP) - E-Commerce Chapter is a compliance framework from Asia-Pacific (15 RCEP members) with 11 domains and 22 controls that map to 127 other frameworks. The largest domains are Chapter 12 General Provisions (3 controls), Consumer and Personal Information Protection (3 controls), Cyber Security and Cross Border Data Flows (3 controls). Every control below carries what it requires and what an assessor expects to see.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (11)

Chapter 12 General Provisions

3 controls
Controls in the Chapter 12 General Provisions domain of Regional Comprehensive Economic Partnership (RCEP) - E-Commerce Chapter1 controls
CodeTitle
RCEP-EC-12.4Cooperation on E-Commerce

Consumer Protection

1 controls
Controls in the Consumer Protection domain of Regional Comprehensive Economic Partnership (RCEP) - E-Commerce Chapter1 controls
CodeTitle
RCEPEC-3Consumer Protection, Paperless Trading, Customs (12.11-12)

Consumer and Personal Information Protection

3 controls
Controls in the Consumer and Personal Information Protection domain of Regional Comprehensive Economic Partnership (RCEP) - E-Commerce Chapter3 controls
CodeTitle
RCEP-EC-12.7Online Consumer Protection
RCEP-EC-12.8Online Personal Information Protection
RCEP-EC-12.9Unsolicited Commercial Electronic Messages

Cross-Border

1 controls
Controls in the Cross-Border domain of Regional Comprehensive Economic Partnership (RCEP) - E-Commerce Chapter1 controls
CodeTitle
RCEPEC-2Cross-Border Transfer, Computing Facilities, Localization (12.14-15)

Cyber Security and Cross Border Data Flows

3 controls
Controls in the Cyber Security and Cross Border Data Flows domain of Regional Comprehensive Economic Partnership (RCEP) - E-Commerce Chapter3 controls
CodeTitle
RCEP-EC-12.13Cyber Security
RCEP-EC-12.14Location of Computing Facilities
RCEP-EC-12.15Cross-Border Transfer of Information by Electronic Means

Cybersecurity

1 controls
Controls in the Cybersecurity domain of Regional Comprehensive Economic Partnership (RCEP) - E-Commerce Chapter1 controls
CodeTitle
RCEPEC-4Cybersecurity, Cooperation, Dispute Resolution

Dialogue and Dispute Settlement

2 controls
Controls in the Dialogue and Dispute Settlement domain of Regional Comprehensive Economic Partnership (RCEP) - E-Commerce Chapter2 controls
CodeTitle
RCEP-EC-12.16Dialogue on Electronic Commerce
RCEP-EC-12.17Settlement of Disputes

Domestic Regulation and Transparency

3 controls
Controls in the Domestic Regulation and Transparency domain of Regional Comprehensive Economic Partnership (RCEP) - E-Commerce Chapter3 controls
CodeTitle
RCEP-EC-12.10Domestic Regulatory Framework
RCEP-EC-12.11Customs Duties on Electronic Transmissions
RCEP-EC-12.12Transparency

Implementation

2 controls
Controls in the Implementation domain of Regional Comprehensive Economic Partnership (RCEP) - E-Commerce Chapter2 controls
CodeTitle
RCEP-EC-IMPL-01Implementation Reporting
RCEP-EC-IMPL-02Stakeholder Consultation

Personal Info

1 controls
Controls in the Personal Info domain of Regional Comprehensive Economic Partnership (RCEP) - E-Commerce Chapter1 controls
CodeTitle
RCEPEC-1Online Personal Information Protection (12.13)

Trade Facilitation and Electronic Authentication

2 controls
Controls in the Trade Facilitation and Electronic Authentication domain of Regional Comprehensive Economic Partnership (RCEP) - E-Commerce Chapter2 controls
CodeTitle
RCEP-EC-12.5Paperless Trading
RCEP-EC-12.6Electronic Authentication and Electronic Signature

Maps to 127 other frameworks

20 total controls
USMCA Chapter 19 - Digital Trade (United States-Mexico-Canada Agreement)
4 source controls mapped|3 target controls covered
20%
US Consumer Product Safety Commission (CPSC) - Connected Product Safety
2 source controls mapped|3 target controls covered
10%
Florida Digital Bill of Rights (FDBR)
2 source controls mapped|6 target controls covered
10%
ISO/IEC 27003:2017
2 source controls mapped|2 target controls covered
10%
ISO 13485
2 source controls mapped|3 target controls covered
10%
Bahrain PDPL
2 source controls mapped|4 target controls covered
10%
Vietnam PDPD
2 source controls mapped|2 target controls covered
10%
Vietnam Law on Cybersecurity (No. 24/2018/QH14)
2 source controls mapped|3 target controls covered
10%
Texas Data Privacy Act
2 source controls mapped|1 target controls covered
10%
Taiwan PDPA
2 source controls mapped|3 target controls covered
10%
10%
South Korea ISMS-P
2 source controls mapped|5 target controls covered
10%
Switzerland New Federal Act on Data Protection (nFADP/nDSG, 2023)
2 source controls mapped|9 target controls covered
10%
Singapore Government Instruction Manual on ICT&SS Management (IM8)
2 source controls mapped|2 target controls covered
10%
Australian Privacy Principles (APPs)
2 source controls mapped|4 target controls covered
10%
Armenia Law on Protection of Personal Data (2015)
2 source controls mapped|4 target controls covered
10%
Azerbaijan Law on Personal Data (2010)
2 source controls mapped|4 target controls covered
10%
IAIS Insurance Core Principles (ICPs)
2 source controls mapped|2 target controls covered
10%
Barbados Data Protection Act 2019
2 source controls mapped|5 target controls covered
10%
GDPR
2 source controls mapped|6 target controls covered
10%
10%
ISO 26000:2010
1 source controls mapped|1 target controls covered
5%
AS9100D - Aerospace Quality Management System
1 source controls mapped|3 target controls covered
5%
SQF Code Edition 9 - Safe Quality Food
1 source controls mapped|1 target controls covered
5%
AS9100D:2016 - Quality Management Systems for Aviation, Space, and Defence
1 source controls mapped|1 target controls covered
5%
ISO 27005
1 source controls mapped|1 target controls covered
5%
Authorised Economic Operator (AEO) Programmes - Global Standards
1 source controls mapped|1 target controls covered
5%
Austria Data Protection Act (Datenschutzgesetz, DSG, amended 2018)
1 source controls mapped|5 target controls covered
5%
W3C Verifiable Credentials (VC) Data Model 2.0
1 source controls mapped|1 target controls covered
5%
Vermont Artificial Intelligence and Consumer Data Act (AICDA)
1 source controls mapped|1 target controls covered
5%
US EPA Safe Drinking Water Act (SDWA) - Cybersecurity Requirements
1 source controls mapped|1 target controls covered
5%
ISO/IEC 17025:2017 - General Requirements for Testing and Calibration
1 source controls mapped|2 target controls covered
5%
Annex 11 to EU GMP - Computerised Systems
1 source controls mapped|3 target controls covered
5%
IEC 60601-1 - Medical Electrical Equipment Safety
1 source controls mapped|2 target controls covered
5%
ISO/IEC 27031:2011
1 source controls mapped|1 target controls covered
5%
Science Based Targets Initiative (SBTi) - Net-Zero Standard
1 source controls mapped|2 target controls covered
5%
ISO 56002
1 source controls mapped|2 target controls covered
5%
ISO 37000:2021 - Governance of Organizations
1 source controls mapped|3 target controls covered
5%
ISO 19011
1 source controls mapped|3 target controls covered
5%
5%
ISO 31000:2018
1 source controls mapped|1 target controls covered
5%
NIST Cybersecurity Framework 2.0
1 source controls mapped|4 target controls covered
5%
SANS Incident Handler's Handbook and PICERL Methodology
1 source controls mapped|2 target controls covered
5%
NIST SP 800-171A Rev 3 - Assessing CUI Security Requirements
1 source controls mapped|5 target controls covered
5%
IEC 62304:2015 Medical Device Software Lifecycle Processes
1 source controls mapped|3 target controls covered
5%
ISO/IEC 25012:2008 - Data Quality Model
1 source controls mapped|2 target controls covered
5%
ISO 27018
1 source controls mapped|2 target controls covered
5%
Automotive SPICE (ASPICE) v4.0 - Process Assessment Model
1 source controls mapped|2 target controls covered
5%
DAMA-DMBOK2 - Data Management Body of Knowledge (2nd Edition)
1 source controls mapped|3 target controls covered
5%
ISO 14064 - Greenhouse Gas Accounting and Verification (Parts 1-3)
1 source controls mapped|1 target controls covered
5%
ISO/IEC 29100:2024
1 source controls mapped|4 target controls covered
5%
ISO/IEC 38500:2024 - Governance of IT
1 source controls mapped|4 target controls covered
5%
COBIT 2019
1 source controls mapped|1 target controls covered
5%
Nebraska Data Privacy Act
1 source controls mapped|2 target controls covered
5%
ISO/IEC 30111:2019
1 source controls mapped|1 target controls covered
5%
ISO 41001:2018 - Facility Management Systems
1 source controls mapped|2 target controls covered
5%
ISO/IEC 23894:2023
1 source controls mapped|4 target controls covered
5%
ISO 22320:2018
1 source controls mapped|3 target controls covered
5%
ISO/IEC 27004:2016
1 source controls mapped|2 target controls covered
5%
IEC 62351 - Power Systems Communication Security
1 source controls mapped|1 target controls covered
5%
FFIEC IT Examination Handbook
1 source controls mapped|1 target controls covered
5%
ISO 8000 - Data Quality
1 source controls mapped|2 target controls covered
5%
ISO 22739:2024 - Blockchain and Distributed Ledger Technologies Vocabulary
1 source controls mapped|3 target controls covered
5%
ISO/IEC 29147:2018
1 source controls mapped|1 target controls covered
5%
PCI SSF
1 source controls mapped|1 target controls covered
5%
AICPA Privacy Management Framework (PMF)
1 source controls mapped|5 target controls covered
5%
Kuwait National Cybersecurity Framework
1 source controls mapped|1 target controls covered
5%
ISO/IEC 27007:2020
1 source controls mapped|1 target controls covered
5%
FedRAMP High
1 source controls mapped|1 target controls covered
5%
NIST SP 800-53 Revision 5.1 HIGH
1 source controls mapped|1 target controls covered
5%
FedRAMP Moderate
1 source controls mapped|1 target controls covered
5%
NIST SP 800-53 Rev 5 MODERATE
1 source controls mapped|1 target controls covered
5%
NIST SP 800-53 Rev 5 LOW
1 source controls mapped|1 target controls covered
5%
PCI P2PE
1 source controls mapped|1 target controls covered
5%
BRCGS Global Standard for Food Safety Issue 9
1 source controls mapped|3 target controls covered
5%
US Foreign Corrupt Practices Act (FCPA)
1 source controls mapped|1 target controls covered
5%
ISO 27017
1 source controls mapped|2 target controls covered
5%
ISO 27043
1 source controls mapped|2 target controls covered
5%
ISO 20400:2017 - Sustainable Procurement
1 source controls mapped|2 target controls covered
5%
NIST SP 800-190
1 source controls mapped|2 target controls covered
5%
UK Open Banking Standard
1 source controls mapped|5 target controls covered
5%
ISO/SAE 21434
1 source controls mapped|2 target controls covered
5%
PCI PIN Security
1 source controls mapped|1 target controls covered
5%
ISO/IEC 27557:2022 - Organisational Privacy Risk Management
1 source controls mapped|2 target controls covered
5%
ASIS SPC.1-2009 - Organizational Resilience Standard
1 source controls mapped|1 target controls covered
5%
ISO 26262:2018 - Functional Safety for Road Vehicles
1 source controls mapped|1 target controls covered
5%
ISO 28001:2007 Supply Chain Security Management
1 source controls mapped|1 target controls covered
5%
PCI DSS 4.0
1 source controls mapped|1 target controls covered
5%
CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0
1 source controls mapped|4 target controls covered
5%
French Sapin II Law (Law No. 2016-1691)
1 source controls mapped|1 target controls covered
5%
OWASP SAMM
1 source controls mapped|2 target controls covered
5%
SIG (Shared Assessments)
1 source controls mapped|2 target controls covered
5%
Trinidad and Tobago Data Protection Act 2011
1 source controls mapped|5 target controls covered
5%
ISO/IEC 29115:2023 - Entity Authentication Assurance Framework
1 source controls mapped|3 target controls covered
5%
NIST SP 800-53 Rev 5
1 source controls mapped|3 target controls covered
5%
BSI IT-Grundschutz
1 source controls mapped|1 target controls covered
5%
MARS-E - Minimum Acceptable Risk Standards for Exchanges
1 source controls mapped|2 target controls covered
5%
ISO 27799
1 source controls mapped|1 target controls covered
5%
ISO/IEC 27400:2022
1 source controls mapped|3 target controls covered
5%
AML/CTF Act 2006 (Australia)
1 source controls mapped|1 target controls covered
5%
Bank Secrecy Act / Anti-Money Laundering (BSA/AML)
1 source controls mapped|1 target controls covered
5%
Illinois Biometric Information Privacy Act (BIPA)
1 source controls mapped|2 target controls covered
5%
ASD Strategies to Mitigate Cyber Security Incidents
1 source controls mapped|2 target controls covered
5%
ISO/IEC 23837 - Security Requirements for Quantum Key Distribution
1 source controls mapped|1 target controls covered
5%
FIDO2 / WebAuthn
1 source controls mapped|1 target controls covered
5%
FTC GLBA Safeguards Rule (16 CFR Part 314)
1 source controls mapped|2 target controls covered
5%
Secure by Design: A Guide for Manufacturers (CISA)
1 source controls mapped|1 target controls covered
5%
Sigstore - Software Artifact Signing and Verification
1 source controls mapped|1 target controls covered
5%
SLSA
1 source controls mapped|1 target controls covered
5%
TSA Pipeline Cybersecurity Directives
1 source controls mapped|1 target controls covered
5%
ITU-T X.805 - Security Architecture for End-to-End Communications
1 source controls mapped|2 target controls covered
5%
APPI
1 source controls mapped|3 target controls covered
5%
ISO/IEC 29134:2023
1 source controls mapped|1 target controls covered
5%
COSO Internal Control - Integrated Framework (2013)
1 source controls mapped|1 target controls covered
5%
Estonia Personal Data Protection Act (Isikuandmete kaitse seadus, 2019)
1 source controls mapped|1 target controls covered
5%
Azure Security Benchmark
1 source controls mapped|1 target controls covered
5%
UK AI Regulation Framework
1 source controls mapped|1 target controls covered
5%
TISAX - Trusted Information Security Assessment Exchange
1 source controls mapped|1 target controls covered
5%
Tanzania Personal Data Protection Act (Draft)
1 source controls mapped|4 target controls covered
5%
Student Privacy Pledge 2020
1 source controls mapped|1 target controls covered
5%
SASB Standards
1 source controls mapped|1 target controls covered
5%

What is Regional Comprehensive Economic Partnership (RCEP) - E-Commerce Chapter and who does it apply to?

Regional Comprehensive Economic Partnership (RCEP) - E-Commerce Chapter is a compliance framework from Asia-Pacific (15 RCEP members) with 11 domains and 22 controls. The Regional Comprehensive Economic Partnership (RCEP), effective January 2022, includes a dedicated E-Commerce Chapter (Chapter 12) establishing digital trade rules among 15 Asia-Pacific countries (ASEAN-10, China, Japan, South Korea, Australia, New Zealand). RCEP covers the world's largest trading bloc by GDP (30% of global GDP). The E-Commerce Chapter addresses: electronic transactions legal framework, consumer protection online, personal data protection, cross-border data flows (with significant exceptions), paperless trading, and electronic authentication. Notable for balancing digital trade liberalisation with data sovereignty provisions. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

What does Regional Comprehensive Economic Partnership (RCEP) - E-Commerce Chapter actually require?

Regional Comprehensive Economic Partnership (RCEP) - E-Commerce Chapter has 22 controls organised across 11 domains. The largest domains are Chapter 12 General Provisions (3 controls), Consumer and Personal Information Protection (3 controls), Cyber Security and Cross Border Data Flows (3 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

If I already comply with another framework, how much of Regional Comprehensive Economic Partnership (RCEP) - E-Commerce Chapter do I already cover?

Regional Comprehensive Economic Partnership (RCEP) - E-Commerce Chapter maps to 127 other compliance frameworks. The top mapping partners are USMCA Chapter 19 - Digital Trade (United States-Mexico-Canada Agreement) (20% coverage), US Consumer Product Safety Commission (CPSC) - Connected Product Safety (10% coverage), Florida Digital Bill of Rights (FDBR) (10% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I implement Regional Comprehensive Economic Partnership (RCEP) - E-Commerce Chapter?

Start your Regional Comprehensive Economic Partnership (RCEP) - E-Commerce Chapter compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Regional Comprehensive Economic Partnership (RCEP) - E-Commerce Chapter requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 22 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 686 frameworks.

Get Started Free →

Free forever — no credit card required