Iran - Electronic Commerce Law (2004)

Electronic Commerce Law

قانون تجارت الکترونیکی

Iran

RAI-IR-NA-ELECTRO-2004
Effective: February 5, 2004
In Force(In Force)
ActGovernance and OversightData Protection and PrivacyLiability and Redress
Export PDF

Iran's foundational law for digital transactions, electronic signatures, and consumer protection in the e-commerce sector.

Overview

The Electronic Commerce Law of Iran, enacted in early 2004 (corresponding to the Persian year 1382), serves as the foundational legal framework for digital transactions, electronic signatures, and data protection within the Islamic Republic of Iran. This comprehensive legislation was designed to modernize the Iranian legal system by providing legal recognition to electronic records and signatures, thereby facilitating the growth of the digital economy. The law is heavily influenced by the UNCITRAL Model Law on Electronic Commerce (1996), aiming to harmonize Iran's domestic regulations with international standards to encourage cross-border trade and technological integration. It consists of 81 articles divided into several chapters covering general provisions, electronic signatures, consumer protection, and criminal liabilities. The primary objective of this Act is to remove legal barriers to the use of electronic communications and to provide a secure environment for both businesses and consumers. By establishing the principle of functional equivalence—where electronic data messages are treated with the same legal weight as paper-based documents—the law enables the formation of contracts, the filing of legal evidence, and the provision of government services through digital channels. It addresses the unique challenges of the digital realm, such as the volatility of data and the difficulty of verifying identities, by introducing specific requirements for 'secure' electronic signatures and reliable archiving systems. This law remains the cornerstone of Iran's telecommunications and technology regulations, underpinning subsequent developments in fintech, e-government, and cybersecurity.

Definitions

The law provides a rigorous set of definitions in Article 2 to ensure clarity in the interpretation of digital concepts. A 'Data Message' (داده پیام) is defined as any information generated, sent, received, or stored by electronic, optical, or other information technology means. This broad definition ensures that the law remains technology-neutral, applying to current and future methods of digital communication. The 'Originator' refers to the person by whom, or on whose behalf, the data message has been sent or generated, while the 'Addressee' is the person intended by the originator to receive the message. This distinction is crucial for determining the timing and location of contract formation in an automated environment. Furthermore, the Act distinguishes between a standard 'Electronic Signature' and a 'Secure Electronic Signature.' An electronic signature is any symbol or process attached to or logically associated with a data message, used to identify the signatory. However, for a signature to be considered 'Secure' under Article 10, it must be unique to the signatory, created using means under their sole control, and linked to the data message in such a manner that any subsequent change in the data is detectable. Other key definitions include 'Intermediary,' 'Information System,' and 'Consumer,' each of which carries specific rights and obligations throughout the text of the legislation, particularly regarding the liability of service providers and the protection of end-users. The inclusion of 'Automated Transactions' as a defined term also allows for the legal recognition of contracts formed by pre-programmed software agents without direct human intervention at the moment of the transaction.

Governance and Institutional Framework

The governance of electronic commerce in Iran is primarily centralized under the Ministry of Industry, Mine and Trade (formerly the Ministry of Commerce). Within this ministry, the Electronic Commerce Development Center (ECDC) acts as the executive arm responsible for implementing the law's provisions. The ECDC oversees the 'e-Namad' system, a mandatory trust seal for e-commerce websites that verifies the identity and legitimacy of online businesses. This institutional framework ensures that digital platforms adhere to national standards for consumer protection and data security, providing a centralized point of oversight for the rapidly evolving digital marketplace. In addition to the Ministry of Industry, the Supreme Council of Cyberspace (SCC) and the Ministry of Information and Communications Technology (ICT) play advisory and infrastructural roles. The law also establishes a framework for 'Certification Service Providers' (CSPs), which are entities authorized to issue digital certificates for secure electronic signatures. These CSPs are regulated to ensure the integrity of the Public Key Infrastructure (PKI) in Iran. The judiciary also maintains specialized branches to handle disputes arising from this law, recognizing electronic evidence as admissible in court provided it meets the integrity requirements set forth in Chapter 2 of the Act. The ECDC is further tasked with promoting the culture of electronic commerce and facilitating the technical transition for traditional businesses into the digital sphere, ensuring that the infrastructure supports the high-security requirements of the law.

Legal Validity and Evidence

One of the most significant focus areas of the Electronic Commerce Law is the legal validity of electronic evidence. Articles 6 through 16 establish that data messages cannot be denied legal effect, validity, or enforceability solely on the grounds that they are in electronic form. This 'non-discrimination' principle is essential for the digital transformation of the judiciary and the banking sector. If a law requires information to be in writing, a data message satisfies that requirement if the information contained therein is accessible so as to be usable for subsequent reference. This has paved the way for the total digitization of many administrative processes in Iran. The law also addresses the 'Originality' requirement; a data message is considered an original if there exists a reliable assurance as to the integrity of the information from the time when it was first generated in its final form. This reliability is assessed based on the purpose for which the information was generated and in light of all relevant circumstances. Furthermore, Article 12 explicitly states that in any legal proceedings, nothing in the application of the rules of evidence shall apply so as to deny the admissibility of a data message in evidence on the sole ground that it is a data message. This provision has been instrumental in allowing Iranian courts to accept emails, digital logs, and electronic contracts as primary evidence in commercial litigation, provided their integrity can be verified through technical audits or digital signatures.

Consumer Protection

Consumer Protection is detailed extensively in Chapter 4 (Articles 33-49). The law grants consumers a 'right of withdrawal' (cooling-off period) of at least seven working days for most online purchases, during which they can return goods or cancel services without penalty. The only costs that can be imposed on the consumer during this period are the costs of returning the goods. It also mandates strict disclosure requirements for vendors, including the total price (including taxes and shipping), technical specifications, the identity of the supplier, and the physical address of the business. Furthermore, the law addresses 'Data Protection' in Article 58, prohibiting the processing of personal data (such as health, racial, or religious information) without the explicit consent of the subject, marking one of Iran's earliest legislative attempts at formalizing digital privacy rights. Vendors are also prohibited from using 'unfair terms' in electronic contracts that significantly disadvantage the consumer. If a vendor fails to provide the required pre-contractual information, the cooling-off period does not begin until that information is provided, effectively extending the consumer's right to cancel. These protections are designed to build trust in the digital marketplace, ensuring that consumers feel as secure shopping online as they do in traditional brick-and-mortar stores.

Implementation Framework

The implementation of the Electronic Commerce Law relies on the technical infrastructure provided by the National Root Certification Authority. This authority oversees the issuance of digital certificates that enable 'Secure Electronic Signatures,' which carry the same evidentiary weight as notarized signatures in the physical world. For a digital transaction to be fully compliant, businesses must ensure that their information systems are capable of maintaining the integrity of data messages from the moment they are generated until their final storage. This involves implementing robust encryption and time-stamping protocols to prevent unauthorized tampering. From a procedural standpoint, the law integrates with the Iranian Civil Code and the Civil Procedure Code. When a dispute arises, the 'integrity' of the data message is the primary factor in its admissibility. Article 15 states that the integrity of a data message is assessed by determining whether the information has remained unaltered, apart from the addition of any endorsement or any change which arises in the normal course of communication, storage, and display. The implementation framework also extends to 'Automated Transactions,' where contracts are formed by the interaction of programmed agents without human intervention at the time of the transaction, providing a legal basis for modern algorithmic trading and automated supply chains. This technical-legal hybrid approach ensures that the law remains relevant even as the underlying technology evolves from simple email exchanges to complex automated systems.

Monitoring and Evaluation

Monitoring compliance with the Electronic Commerce Law is a multi-tiered process. The Electronic Commerce Development Center (ECDC) conducts regular audits of licensed Certification Service Providers to ensure their technical operations meet the security standards defined by the executive regulations. For consumer-facing businesses, the 'e-Namad' trust seal serves as a continuous monitoring tool; businesses that violate consumer rights or fail to maintain secure systems can have their seals suspended or revoked, effectively cutting them off from the national payment gateway system. Evaluation of the law's effectiveness is periodically conducted by the Majlis Research Center (the parliamentary research arm). Since its inception, several amendments and supplementary regulations have been proposed to address emerging technologies like blockchain and artificial intelligence, which were not prevalent in 2004. The monitoring framework also involves the Central Bank of Iran (CBI) regarding electronic payment systems, ensuring that the financial aspects of e-commerce are synchronized with the legal requirements for electronic records and signatures. This inter-agency cooperation is vital for identifying gaps in the current legislation as the digital landscape evolves. The ECDC also maintains a public database of certified businesses, allowing consumers to verify the status of a vendor before engaging in a transaction, which serves as a decentralized form of market monitoring.

Penalties, Liability, and Appeals

Chapter 6 of the law (Articles 67-78) outlines a comprehensive list of crimes and penalties associated with electronic commerce. These include 'Electronic Fraud,' where the use of data messages leads to the disruption of systems or the unauthorized acquisition of property, punishable by imprisonment and fines. 'Electronic Forgery' is also strictly penalized, targeting those who alter data messages or signatures with the intent to deceive. The law specifically addresses the breach of 'Private Data Messages' (Article 71), providing criminal recourse for individuals whose digital privacy has been violated by unauthorized access or disclosure. Liability is not limited to criminal intent; the law also establishes civil liability for service providers and vendors who fail to meet their statutory obligations. For instance, if a vendor fails to provide the required disclosures or violates the seven-day return policy, they are liable for damages caused to the consumer. Appeals against regulatory decisions, such as the revocation of a digital certificate or an e-Namad seal, are handled through the Administrative Justice Court. Criminal cases are tried in specialized cybercrime courts, which utilize forensic experts to evaluate the technical evidence presented under the rules established by this Act. The penalties are designed to be deterrent, with fines often calculated based on the financial gain obtained through the illegal act or the damage caused to the victim.

Relationship to Other Instruments

The Electronic Commerce Law does not operate in isolation; it is designed to complement the existing Iranian Civil Code. Article 3 explicitly states that in the absence of specific provisions in this law, the Civil Code and other general laws apply. This ensures that the fundamental principles of contract law, such as offer and acceptance, capacity, and legality of object, remain applicable to digital transactions. Furthermore, it works in tandem with the 'Computer Crimes Law' (2009), which expanded on the criminal provisions of the 2004 Act to cover broader cybersecurity threats like hacking and data espionage. The law also intersects with the 'Law on Publication and Free Access to Information,' as it defines the standards for how government entities should store and provide access to electronic records. In the realm of financial services, it is supported by Central Bank regulations on 'Electronic Payment Systems' and 'Digital Wallets.' By providing the legal bedrock for digital signatures, the Electronic Commerce Law enables these other instruments to function in a digital environment, creating a cohesive, albeit complex, regulatory web that governs the entirety of Iran's information technology sector. It also aligns with the 'Cyber Police' (FATA) operational guidelines, providing the legal definitions necessary for law enforcement to investigate digital crimes effectively.

International Alignment

As previously noted, the Electronic Commerce Law is largely modeled after the UNCITRAL Model Law on Electronic Commerce (1996). This alignment was a strategic choice by the Iranian legislature to ensure that the country's digital legal framework would be recognizable to international partners and investors. By adopting the principles of 'Functional Equivalence' and 'Technology Neutrality,' Iran sought to facilitate its accession to the World Trade Organization (WTO) and other international trade bodies. The law's provisions on the 'Time and Place of Dispatch and Receipt' of data messages (Articles 26-30) are almost identical to international standards, which simplifies the resolution of jurisdictional issues in cross-border e-commerce. Despite this alignment, certain aspects of the law reflect local legal and religious considerations, particularly regarding the 'Rule of Laches' and specific types of contracts that may still require physical presence under Sharia-derived civil rules (such as certain marriage or property transfer documents). However, for the vast majority of commercial activities, the law provides a bridge between Iran's traditional legal system and the global digital economy. This international alignment has allowed Iranian tech companies to adopt standard global practices for user agreements, privacy policies, and digital contracting, fostering a more predictable environment for international digital cooperation and potential future integration with regional digital trade agreements.

Implementation Timeline

MilestoneDateNotes
Approval by Islamic Consultative Assembly (Majlis)2004-01-07The final version of the 81 articles was passed by the parliament.
Ratification by the Guardian Council2004-01-20Confirmed to be in compliance with the Constitution and Sharia law.
Official Gazette Publication2004-02-05The law became officially binding following its publication in the gazette.
Establishment of E-Commerce Development Center2009-08-25Created to centralize the implementation and oversight of the law.
Launch of the e-Namad Trust Seal2011-12-15Mandatory certification for B2C e-commerce platforms to ensure consumer trust.

Compliance Checklist

CheckRequired Action
Legal Recognition of RecordsEnsure all digital contracts and receipts are stored in a format that preserves their integrity and is accessible for future reference (Article 6).
Secure SignaturesUse digital certificates from an authorized Certification Service Provider (CSP) for high-value transactions to meet 'Secure Signature' status (Article 10).
Consumer DisclosureProvide clear information on identity, total price, and technical specs before the conclusion of a transaction (Article 33).
Right of WithdrawalImplement a 7-day return policy for consumers without requiring a reason or imposing penalties (Article 37).
Data PrivacyObtain explicit consent before collecting or processing personal data related to health, race, or beliefs (Article 58).
Advertising StandardsEnsure electronic advertisements are clearly identifiable and provide an easy opt-out mechanism for recipients (Article 51).

Sources and References

SourceType
Islamic Parliament of Iran - Electronic Commerce Lawgovernment
Plain English

Iran's Electronic Commerce Law, enacted in 2004, establishes the foundational legal framework for all digital transactions, electronic signatures, and consumer protection for businesses and individuals operating or engaging in e-commerce within the country.

This law applies broadly to anyone involved in digital communication and commerce in Iran, including online businesses, service providers, and consumers. It covers everything from sending an email to forming complex contracts online. Key obligations for businesses include: - Ensuring all digital contracts and records are stored securely to preserve their integrity, as electronic documents and secure digital signatures now hold the same legal weight as their paper counterparts. - Providing clear pre-contractual information to consumers, such as total price, vendor identity, and business address. - Granting consumers a mandatory seven-day "right of withdrawal" for most online purchases, allowing returns without penalty. - Obtaining explicit consent before processing sensitive personal data like health or religious information.

The law officially took effect on February 5, 2004, following its publication in the Official Gazette.

Non-compliance carries significant penalties, including imprisonment and fines for serious offenses like electronic fraud, forgery, or privacy breaches. Businesses can also face civil liability for failing consumer protection duties. The Electronic Commerce Development Center (ECDC) enforces compliance, notably through the 'e-Namad' trust seal; businesses found in violation risk losing this mandatory certification, which can effectively block their access to Iran's national payment systems.

A key practical point is that while electronic records are generally valid, certain sensitive contracts, like those for marriage or property transfer, may still require physical presence or specific traditional forms under Sharia-derived civil rules, so digital-only isn't always sufficient. Also, the mandatory 'e-Namad' trust seal for business-to-consumer (B2C) e-commerce sites is crucial for operational legitimacy.

Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.

© Regulations.AI — created on 11-Apr-2026 using Gemini 3 Flash Preview