Maldives - Digital Commerce Framework (Law No. 2/2022)
Electronic Transactions Act (Law No. 2/2022)
އިލެކްޓްރޯނިކް މުޢާމަލާތްތަކާބެހޭ ޤާނޫނު (Law No. 2/2022)
Maldives
RAI-MV-NA-LAWNO22-2022Law No. 2/2022
A law establishing the legal validity of electronic records, signatures, and trust services in the Maldives.
Summary
The Electronic Transactions Act (Law No. 2/2022) of the Maldives provides a comprehensive legal framework for digital commerce, granting legal recognition to electronic records, signatures, and trust services while aligning with international UNCITRAL standards. It establishes the Controller of Trust Services to oversee the accreditation of digital service providers and ensures that electronic communications are treated with the same legal weight as traditional paper-based documents.
Full article
Read full text ↗Overview
The Electronic Transactions Act (Law No. 2/2022) of the Maldives represents a landmark legislative milestone in the nation's journey toward a comprehensive digital economy. Ratified by President Ibrahim Mohamed Solih on April 27, 2022, the Act was designed to modernize the legal landscape by providing formal recognition to electronic records, signatures, and trust services. By establishing a robust legal framework, the Act aims to facilitate both domestic and international electronic commerce, remove historical legal barriers that favored paper-based documentation, and foster public confidence in digital interactions. The legislation is heavily influenced by international standards, specifically the United Nations Commission on International Trade Law (UNCITRAL) Model Laws, ensuring that the Maldives' digital infrastructure remains compatible with global trade practices. This Act replaces the previous regulatory frameworks and provides a more stable, statutory basis for the digital transformation of the Maldivian state, aligning with the government's Strategic Action Plan (SAP) which prioritizes the development of a digital economy and the reduction of bureaucratic hurdles through technology. The enactment of this law is seen as a prerequisite for the full implementation of the national digital identity system, e-Faas, and the modernization of the financial sector.
Definitions and Scope
The Act provides a comprehensive glossary of terms to ensure clarity in the application of digital law. A 'Data Message' is defined broadly as information generated, sent, received, or stored by electronic, magnetic, optical, or similar means, including but not limited to electronic data interchange (EDI), electronic mail, telegram, telex, or telecopy. This technology-neutral definition ensures that the law remains relevant even as new communication technologies emerge. An 'Electronic Record' refers to a data message that is created, generated, sent, communicated, received, or stored by electronic means and is capable of being retrieved in perceivable form. This definition is crucial for establishing the 'functional equivalence' principle, where an electronic record is treated with the same legal weight as a paper document. The scope of the Act is broad, covering all types of electronic communications used in commercial and non-commercial activities, including transactions between private parties and between the government and the public. However, it specifically excludes certain sensitive legal instruments such as the creation of wills, trusts, and powers of attorney, as well as contracts for the sale of immovable property, which still require traditional physical formalities to ensure security and prevent fraud in high-stakes personal and property matters.
Governance and Institutional Framework
The governance of electronic transactions in the Maldives is centralized under the Ministry responsible for technology, currently the Ministry of Homeland Security and Technology. The Ministry is tasked with the overarching policy formulation and the development of regulations necessary to implement the Act. A pivotal figure within this framework is the 'Controller of Trust Services,' an official appointed to oversee the accreditation and regulation of Trust Service Providers (TSPs). The Controller acts as the primary regulatory authority, ensuring that providers adhere to strict technical and operational standards, thereby maintaining the integrity of the digital trust ecosystem. The Controller's powers are extensive, ranging from the issuance of licenses and certificates of accreditation to the conduct of audits and investigations into the conduct of TSPs. The Controller is also responsible for maintaining a publicly accessible register of accredited trust service providers, which allows businesses and citizens to verify the legitimacy of the services they utilize. This institutional structure is designed to provide a high level of oversight, preventing fraudulent activities and ensuring that the technical infrastructure supporting electronic signatures and seals remains secure. The framework also allows for the recognition of foreign trust services, provided they meet the reliability standards established by the Controller, thus facilitating cross-border digital integration and international trade.
Legal Recognition and Functional Equivalence
One of the primary focus areas of the Act is the principle of 'Legal Recognition and Functional Equivalence.' The law explicitly states that information shall not be denied legal effect, validity, or enforceability solely on the grounds that it is in the form of a data message. This extends to the requirement for 'writing' and 'original' documents; if a law requires information to be in writing or in its original form, a data message satisfies that requirement if the information contained therein is accessible so as to be usable for subsequent reference and if there exists a reliable assurance as to the integrity of the information. This fundamental shift allows the Maldivian judiciary and administration to accept digital evidence and records as standard practice. Furthermore, the Act addresses the legal validity of electronic signatures. Where the law requires a signature of a person, that requirement is met in relation to a data message if an electronic signature is used that is as reliable as was appropriate for the purpose for which the data message was generated or communicated. The Act establishes criteria for determining reliability, including whether the signature creation data is linked to the signatory and no other person, and whether any alteration to the electronic signature made after the time of signing is detectable. This provides a clear legal pathway for the adoption of digital contracts and official government filings.
Trust Services and Accreditation
The Act introduces a sophisticated regime for 'Trust Services,' which includes electronic seals, time stamps, and website authentication. This move is intended to elevate the security and reliability of online transactions, making them as legally binding and enforceable as traditional physical counterparts. The Act distinguishes between general electronic signatures and 'Reliable Electronic Signatures,' the latter of which must meet specific criteria regarding uniqueness, sole control by the signatory, and detectability of subsequent alterations. Trust Services are defined as electronic services typically provided for a fee, consisting of the creation, verification, and validation of electronic signatures, seals, or time stamps, as well as electronic registered delivery services and certificates for website authentication. To ensure the highest level of security, the Act establishes a voluntary accreditation scheme. While parties are free to use any electronic signature technology they agree upon, those seeking the highest level of legal certainty can opt for 'Accredited Trust Services.' To become accredited, a provider must demonstrate to the Controller that they possess the financial resources, technical expertise, and secure systems necessary to operate reliably. This involves rigorous vetting of their signature-creation data management, their ability to verify the identity of subscribers, and their commitment to maintaining detailed records of issued certificates, which are essential for the long-term validity of digital transactions.
Obligations and Liability
To ensure the integrity of the digital ecosystem, the Act imposes specific obligations on both signatories and Trust Service Providers. A signatory is required to exercise reasonable care to avoid unauthorized use of their signature-creation data and to notify relevant parties without undue delay if the signature-creation data has been compromised. Failure to do so may result in the signatory being held liable for any damages resulting from the unauthorized use of the signature. On the other hand, Trust Service Providers are held to high standards of professional conduct. They must ensure the accuracy of all information contained in a certificate at the time of issuance and provide accessible means for relying parties to ascertain the identity of the TSP and the status of the certificate. The Act outlines the civil liability of TSPs; a provider can be held liable for damages caused to any person who reasonably relies on a certificate, particularly if the TSP failed to verify the accuracy of the information or failed to revoke a compromised certificate in a timely manner. This balanced liability regime ensures that all parties in a digital transaction have an incentive to maintain security and act in good faith, thereby fostering a culture of trust and accountability in the Maldivian digital marketplace.
Exclusions and Limitations
Despite its broad applicability, the Electronic Transactions Act defines its boundaries by listing specific exclusions where digital formats are not yet permitted. It does not apply to the creation or execution of wills, codicils, or other testamentary instruments; the creation or execution of trusts; or powers of attorney. Furthermore, contracts for the sale or conveyance of immovable property (real estate) and the reporting of such transactions to the relevant authorities are excluded from the scope of the Act. These exclusions exist because these specific legal areas often require higher levels of ceremonial formality, physical witnesses, or specialized government oversight to prevent fraud, coercion, and undue influence. By clearly demarcating these areas, the Act provides certainty to the legal profession and the public regarding which transactions can be fully digitized and which must still follow traditional paper-based protocols. However, the Act allows the Ministry to review these exclusions periodically and potentially narrow them as technology and security measures improve, ensuring that the law can adapt to future advancements in digital identity and secure transaction technologies.
International Alignment and Cross-Border Recognition
A core objective of the Electronic Transactions Act is to ensure that the Maldives is legally synchronized with the global digital economy. The Act is largely based on the UNCITRAL Model Law on Electronic Commerce (1996) and incorporates elements from the UNCITRAL Model Law on Electronic Signatures (2001). More importantly, it looks forward by aligning with the principles of the UNCITRAL Model Law on Electronic Transferable Records (MLETR), which facilitates the use of electronic equivalents of paper-based transferable instruments like bills of lading or promissory notes. The Act also includes provisions for the 'Recognition of Foreign Certificates and Electronic Signatures.' It adopts a non-discriminatory approach, stating that electronic signatures and certificates issued in foreign jurisdictions shall be recognized in the Maldives if they offer a substantially equivalent level of reliability. This determination is based on international standards and the specific agreement between the transacting parties. This international alignment is crucial for the Maldives' tourism and financial sectors, as it allows international investors and travelers to engage in legally binding digital transactions with Maldivian entities without the need for physical presence or complex cross-border legal hurdles, thereby enhancing the nation's competitiveness in the global market.
Implementation Timeline
| Milestone | Date | Notes |
|---|---|---|
| Parliamentary Approval | 2022-04-11 | Passed during the 29th sitting of the first session of Parliament. |
| Ratification and Gazetting | 2022-04-27 | Signed into law by the President and published in the Government Gazette. |
| Entry into Force | 2022-04-27 | The Act became effective immediately upon publication in the Gazette. |
| Regulatory Deadline | 2023-02-27 | Deadline for the Ministry to publish implementing regulations (10 months post-entry). |
| TSP Accreditation Launch | 2023-06-01 | Phased rollout of the accreditation framework for trust service providers. |
Compliance Checklist
| Check | Required Action |
|---|---|
| Legal Validity of Records | Ensure all digital records intended for legal use are stored in a format that allows for future retrieval and maintains integrity. |
| Electronic Signature Reliability | Verify that e-signatures used for high-value contracts are uniquely linked to the signer and under their sole control. |
| Trust Service Provider Status | Businesses providing digital certificates or time-stamping must apply for accreditation with the Controller of Trust Services. |
| Exclusion Verification | Review all transaction types to ensure they do not fall under excluded categories like real estate or wills. |
| Foreign Certificate Use | Verify that any foreign digital certificates used in local transactions meet the reliability standards prescribed by the Act. |
Regulatory Standards for Trust Services
| Service Type | Standard Requirement | Oversight Body |
|---|---|---|
| Electronic Signatures | Must be uniquely linked to signatory and detect subsequent changes. | Controller of Trust Services |
| Electronic Seals | Used by legal entities to ensure origin and integrity of data. | Controller of Trust Services |
| Time Stamping | Must bind data to a particular time to establish evidence of existence. | Controller of Trust Services |
| Website Authentication | Certificates must link a website to the person to whom the certificate is issued. | Controller of Trust Services |
| Registered Delivery | Must provide evidence of handling, sending, and receiving data. | Controller of Trust Services |
Related Regulations
© Regulations.AI using Gemini 3 Flash Preview · updated on 13-Jun-2026