FEATURE



Update of the Electronic Transactions Act

This article examines certain amendments introduced by the new Electronic Transactions Act that came into effect on 1 July 2010.   
_________________________________________________________________________________________________________________

Introduction

In July 1998, the Electronic Transactions Act (Cap 88) (the “ETA”) was enacted to provide a legal foundation for the rights and obligations of parties transacting electronically and to address issues arising in the context of e-commerce. At that time, Singapore was the first country in the world to implement the UNCITRAL Model Law on Electronic Commerce (the “UNCITRAL Model Law”). In the ensuing decade, we experienced an unprecedented proliferation of goods and services provided online by both private and public bodies. The legislative framework of the ETA needed to be updated in order to remain robust in an evolving marketplace.

A comprehensive review of the ETA and the Electronic Transactions (Certification Authority) Regulations (Cap 88, reg 1) (the “ETR”) was thus conducted in three stages from 2004 to 2005. The review and the ensuing public consultation was conducted jointly by the Info-communications Development Authority of Singapore (“IDA”) and the Attorney-General’s Chambers (“AGC”), in consultation with the Ministry of Information, Communications and the Arts and the Ministry of Law. The recommendations arising from the joint public consultation were consolidated and set out in a report titled “Joint IDA-AGC Review of Electronic Transactions Act Proposed Amendments 2009 (Report)” (the “Report”) issued on 30 June 2009.

On 19 May 2010, the Electronic Transactions Bill (Bill No 12/2010) (the “Bill”) was read for a second time by RAdm (NS) Lui Tuck Yew, Acting Minister for Information, Communications and the Arts. One of the main aims of the Bill is to align the law on electronic transactions with the United Nations Convention on the Use of Electronic Communications in International Contracts (the “UN Convention”) which was adopted by the General Assembly on 23 November 2005. The Bill also makes amendments to the ETA in order to facilitate the delivery of e-Government services in Singapore and to adopt a new accreditation framework for the regulation of certification authorities (“CAs”). Finally, the Bill reorganises and restructures the ETA, which will be repealed and re-enacted.

The new Electronic Transactions Act (Act 16 of 2010) (the “ETA 2010”) was gazetted and came into operation on 1 July 2010.

Main Amendments

The main amendments to the ETA fall into three categories:

1.   Alignment of the ETA with the UN Convention

The amendments in this category are necessary in order to ensure that the legislative framework for e-commerce in Singapore keeps pace with international developments. As mentioned earlier, the UNCITRAL Model Law had laid the foundation for the ETA. However, the rules set out within the UNCITRAL Model Law have since been updated and superseded by the provisions contained within the UN Convention to take into account subsequent technological developments. Incidentally, Singapore had played a key role in the development and drafting of the UN Convention.

By harmonising our rules for electronic contracting and e-commerce with the provisions of the UN Convention, it is hoped that businesses in Singapore would not be subject to different rules for domestic and cross-border transactions.

To this end, the provisions in the ETA on the requirement for signatures and the time and place of despatch and receipt of electronic records have been updated, and new sections on the provision of originals, invitations to make offers, the use of automated message systems and errors in electronic communications have been added.

Scope of new part II

Before moving on to discuss the specific amendments in this category, it may be useful to note that Part II (on electronic records and signatures) and Part IV (on electronic contracts) of the ETA have been collapsed into the new Part II dealing with electronic records, signatures and contracts. However, s 5 of the ETA 2010 makes it clear that the rules set out in Part II do not override the principle of party autonomy. Parties are free to exclude, derogate from or vary the application of the provisions in Part II to the transaction in question, including by mutually agreeing to impose additional requirements as to the form or authentication of the contract or transaction. Section 5 of the ETA 2010 also clarifies that agreement or consent to the use of electronic transactions may be inferred from the conduct of the parties, subject to any rule of law or agreement to the contrary.

Electronic signatures

Section 8 of the ETA 2010 introduces new criteria which an electronic signature must meet before it can be recognised as satisfying any rule of law requiring a signature.

The new provision requires that a method should be used to identify a person and to indicate the intention of that person, and that additionally, such method must either: (i) satisfy a “reliability test” appropriate to the circumstances of communication; or (ii) be proven in fact to fulfil the twin functions of “identification” and communication of “intention”. The second limb ensures that a party to a transaction cannot seek to invalidate the contract entered into by invoking the reliability test, where the authenticity of the electronic signature is not in question.  In other words, where the actual identity of the party appending the electronic signature and the intention of that party can be objectively ascertained, it is immaterial that the method used is not “as reliable as appropriate” in the circumstances.

As mentioned in the Report, the reliability test reminds the Courts of the need to take into account, factors other than technology (eg, any relevant agreement of the parties) in ascertaining whether an electronic signature used is sufficient to identify a signatory. The formulation of the test is also flexible enough to cater for different levels of reliability ”as appropriate for the purpose the electronic record was generated or communicated, in light of all the circumstances”. Thus, for example, the level of reliability applicable to a clickthrough agreement for the terms of use of a website may well be different from the level of reliability required in respect of a cryptographic system used in the execution of online trades.

Nevertheless, it may be interesting to consider whether the level of reliability required in particular circumstances may be so high that requirements akin to the requirements for the creation of a secure electronic signature may effectively be imposed. We would suggest that the ETA 2010 should have addressed the possible interaction between the reliability test applicable to methods for creating an electronic signature and the “commercially reasonable security procedure” to be applied to a secure electronic signature under s 18 of the ETA 2010.

Even if an electronic signature satisfies the criteria set out in s 8 of the ETA 2010, difficulties may potentially still arise if the intention of the party attaching the electronic signature to an electronic record cannot be clearly ascertained. An electronic signature could signify an intention to be bound to the terms of a contract or simply acknowledge the contents (or part of the contents) of an electronic record. Contextual evidence may, therefore, be relevant in determining the intention with which an electronic signature had been applied. For this reason, we would advise that it is important for an electronic record to be set up in a manner which evidences the signatory’s intention to be bound – much like how the language of the testimonium provision in a traditional paper contract sets the context in which a handwritten signature is applied.

Provision of originals

Section 10 of the ETA 2010 introduces a new provision legitimising the use of electronic records to satisfy any legal requirement for the provision or retention of any document, record or information in its original form (or providing for certain consequences if it is not provided or retained). In that sense, this section complements and supplements s 9 of the ETA 2010 on the retention of electronic records, which may apply where the original form of the electronic record was in fact a physical copy. Section 9 is discussed in greater detail below.

The conditions that must be met before an electronic record may be used to satisfy any legal requirement for the provision of originals are as follows:
1.   There is reliable assurance as to the integrity of the information contained within the electronic record from the time it was first created;

2.   The electronic record is capable of being displayed to the person to whom it is provided; and

3.   Any additional requirements imposed by the public agency having supervision over the relevant legal requirement have been complied with.

It is possible for public agencies to “opt out” of this default position by specifying the documents, records and/or information to which s 10 does not apply by way of an order to be published in the Gazette.

Time and place of despatch and receipt

Under s 15 of the ETA, the time of despatch is when the electronic communication enters an information system outside the control of the originator. Section 13 of the ETA 2010 moves the time of despatch of an electronic communication to the time when it leaves an information system under the control of the originator, or the party who sent it on behalf of the originator. While it may be arguable that these two points are essentially different sides of the same coin, the formulation in the ETA 2010 is probably a better fit with the notion of despatch both in the real world as well as in the context of communications on the Internet.

The ETA 2010 also introduces a new rule that applies when electronic communication does not leave an information system under the control of the originator (eg, postings on an Internet website or bulletin board or when the owner of an Intranet sends messages to other users on the network). In such a case, the time of despatch is the time when the electronic communication is received. This new rule addresses one of criticisms commonly levied against s 15 of the ETA.

The ETA 2010 further clarifies that the time of receipt is when the electronic communication is capable of being retrieved (where there is a designated electronic address) or at the time when the electronic communication is capable of being retrieved and the addressee is aware that such electronic communication has been sent (where there is no designated electronic address). By introducing the concepts of “capability of retrieval” and “awareness”, the ETA 2010 directly addresses instances where electronic communication is sent to the wrong address or where the addressee refuses to retrieve an electronic communication.

Invitations to make offers

Section 14 of the ETA 2010 introduces a new rule that electronic communications proposing to conclude contracts, and addressed to the world at large (eg, posted on the Internet), are to be treated as invitations to make offers or invitations to treat, unless there is a clear indication that the person making the proposal intended for it to be capable of immediate acceptance. Online auctions that are set up such that bids received would be accepted once a minimum or floor price is reached may, therefore,  operate within rules that deviate from this default position.

This new rule implies that online retailers are subject to the same rules as merchants displaying goods in brick-and-mortar shops or advertising to sell goods in the real world. This new rule will also help to alleviate difficulties that an online retailer may potentially face if it inadvertently posts the wrong price for a product being offered for sale. Due to the reach of the Internet and the speed by which communications over the Internet takes place, such an online retailer may find itself being flooded with orders for the product within a very short span of time, assuming that the erroneous price is much lower than the price at which the product was intended to have been sold. Thus, for example, the defendant in Chwee Kin Keong & Ors v Digilandmall.com Pte Ltd1 received 4,086 orders for a particular model of laser printers after it inadvertently posted the wrong price of S$66 (instead of the correct price of S$3,854) for the printer on its website, despite having acted promptly in removing the offending advertisement. Under this new rule, such an online retailer would not be legally bound to process the orders received, since such orders would be treated as offers subject to its acceptance.

Note, however, that this rule may not actually assist an online retailer in the shoes of the defendant in the case highlighted above, given that it had in fact processed the orders received through an automated order system and despatched confirmation notes to the plaintiffs and other purchasers who ordered the printer. In such a scenario, the new rule discussed below would apply instead.

Automated message systems

Section 15 of the ETA 2010 states that contracts formed through the use of automated message systems will not be denied validity or enforceability on the sole ground that no natural persons reviewed or intervened in the individual actions carried out by such systems or the resulting agreement. In an electronic marketplace where bids and offers are sometimes automatically generated and matched by fully automated systems, this new rule adds valuable legal certainty to such transactions.

However, for reasons alluded to above, online retailers should exercise caution in using automated message systems if they do not in fact intend to conclude binding contracts through the use of such systems. By way of illustration, if the system used by the defendant in Chwee Kin Keong & Ors v Digilandmall.com Pte Ltd had merely automatically generated e-mails acknowledging receipt of the orders, rather than e-mails confirming that the order has been accepted, it may still be in a position to argue that the previous rule, rather than this rule, applies.

Errors in electronic communications

Section 16 of the ETA 2010 introduces another new rule which may be considered a corollary of the foregoing rule. This rule allows a natural person who makes an input error in an electronic communication with an automated message system to withdraw the portion of the communication in which the input error was made, provided that the automated message system does not afford this person with an opportunity to correct the error. Further, this right only applies where the person acts promptly in raising the error to the other party, and has not used or received any material benefit or value from the other party’s goods and services.

It should be noted that this right does not extend to correcting the errors made. It is, therefore, unclear whether a person who accidentally keys in an extra “zero” in entering the amount of goods he/she wishes to buy on an online form would be entitled to abort the entire transaction. Alternatively, would such a person be required to proceed with the transaction subject to the input error being corrected, particularly since the other portions of the electronic communication remain valid? In this regard, it should be noted that the Report suggests that this entire transaction should be invalidated, since the quantity to be bought constitutes an essential term of the contract.

The ETA 2010 also does not clearly define what would constitute use or receipt of a material benefit or value from the goods or services purchased. Given that s 16 of the ETA 2010 applies in the context of electronic communications with an automated message system, it is likely that the order will be processed instantaneously, before the purchaser has an opportunity to notify the vendor of the input error. Presumably such a person would not be disentitled from relying upon this provision even if the goods or services have been received, assuming that such goods or services provided can be returned (eg, clothes which have been delivered) or destroyed (eg, software that has been downloaded).

However, as the UNCITRAL secretariat clarifies in the explanatory notes accompanying the UN Convention, this right should not apply where the return or destruction does not restore the conditions existing prior to the consummation of the transaction. For example, where the consideration purchased is in the form of information, mere access to the information constitutes a benefit that cannot be returned, even if the medium by which such information is conveyed can be returned or destroyed.  Similarly, the right would not apply where the value of the consideration changes between the time it was received and the time when it would have been returned.

Quite apart from the uncertainty highlighted above, the return of goods and/or services or the processing of a withdrawal of an order as a result of input errors will likely cause online retailers to incur additional costs and expenses, such as administrative charges. As such, while this provision has the laudable goal of affording consumers protection against mistakes made while transacting electronically, it may create some undue burden for online retailers. It may be possible for online retailers to mitigate such impact by simply setting up the automated message system in such a way that allows the consumer to review and verify that the order is correct before it is processed.

Attribution and acknowledgement of receipt

It should be briefly mentioned that s 13 (on attribution of an electronic record to its originator) and s 14 (on the ability of the originator to require receipt of the electronic record to be acknowledged) of the ETA have been deleted in the ETA 2010.

Where s 13 of the ETA is concerned, it was felt that no specific rules on attribution should be required given that evidential rules applicable to the determination of the identity of the sender of a message transmitted via physical media should likewise apply to electronic communications. The Report states that this approach “is more consonant with the principles of functional equivalence and non-discrimination of electronic communications”.

Section 14 of the ETA was deleted as it was assessed that the public (and the courts) no longer required the assurance provided by the rules in that section.

2.   E-Government

The ETA 2010 also introduces amendments to facilitate more effective delivery of e-Government services in Singapore. Section 25 of the ETA 2010 empowers a public agency to carry out various functions by electronic means. As such, a public agency may accept the filing of documents, require the provision of information, require the creation or retention of documents, require the provision or retention of originals, issue permits etc and/or require the payment of any fees in electronic form. This applies even if such electronic forms do not resemble the statutorily-prescribed physical forms for that transaction, thus giving public agencies free rein to design forms better suited to online transactions.

Correspondingly, any person who is required by any written law to carry out the relevant transactions highlighted above would satisfy such requirement if the transaction is carried out by way of an electronic record fulfilling the requirements specified by the public agency.

The other e-Government related amendment is aimed at facilitating the Government’s push towards paperless public service delivery. Section 9 of the ETA has been amended such that public agencies are required to accept the retention of documents, information or records in their electronic form. The relevant public agency may however impose additional requirements that such electronic records must comply with before the retention of that electronic record would satisfy any rule of law requiring such retention.

As opposed to s 25 which is merely permissive, s 9 of the ETA 2010 sets out the default position for public agencies. In doing so, the ETA 2010 removes the requirement in s 9(1)(d) of the ETA for the consent of the relevant public agency in relation to the retention of the electronic record to be obtained. In our experience, this has been a major limitation with s 9 of the ETA, and it has been said that this requirement renders the provision nugatory in practice, given that it would be administratively cumbersome to obtain such consent, unless blanket approval has been given.2 As with s 10 of the ETA 2010, however, public agencies can choose exclude the application of s 9 by way of an order to be published in the Gazette.

We note that the amendments discussed above tie in very nicely with the OneInBox initiative recently announced by the Singapore Government. Among other features, it is envisaged that the OneInBox service would allow individuals and businesses in Singapore to receive and retain electronic correspondences from public agencies via a single secure platform, thus obviating the need for hard copy correspondences and resulting in significant cost savings.

3.   Regulation of CAs

The last set of amendments introduced in the ETA 2010 are directed at making the regulatory framework for CAs enshrined in the ETA, which is largely premised upon the adoption of a public key infrastructure (“PKI”) solution, technologically neutral. As security technologies other than PKI are increasingly being adopted for authentication, it is important for the regulatory framework for CAs to remain agnostic to the security technology adopted, so that suitable alternatives (such as biometrics) are not denied legal recognition.

The PKI-specific provisions of the ETA have, therefore, been shifted into the Schedules of the ETA 2010. This differs slightly from the approach initially proposed in the joint public consultation conducted by IDA and AGC, which suggested that such details should be left to regulations to be promulgated under the ETA. Nevertheless, the provisions in the Schedules of the ETA 2010 can still be easily amended by way of an order published in the Gazette in the event that new authentication technologies are adopted as a “specified security procedure” under Part IV of the ETA 2010. For example, IDA is currently looking to appoint an operator to design and build a nationwide two-factor authentication platform pursuant to its National Authentication Framework initiative.

It should also be highlighted that the regulatory framework for CAs has been amended to provide for the accreditation, rather than voluntary licensing, of CAs. It is believed that an accreditation regime better reflects the voluntary nature of the framework, but in practical terms the difference may otherwise be limited. The benefits currently accorded to licensed CAs will be extended to accredited CAs.

It is also likely that certain regulatory requirements currently imposed upon CAs under the ETR will be relaxed. The Report suggests that the accreditation scheme will impose lower financial requirements and fees on CAs, provide for longer term of accreditation (in order to lower the cost incurred by CAs in conducting security audits prior to each renewal), and feature streamlined audit requirements in the form of a single Compliance Audit Checklist. These amendments appear to be aimed at lowering the barriers of entry for new entrants in order to encourage a more vibrant ecosystem for CAs. It is noted that Netrust Pte Ltd is currently the only licensed CA operating in Singapore.

Excluded Transactions

One of the issues discussed during the joint public consultation conducted by IDA and AGC was whether the list of excluded transactions set out in s 4 of the ETA should be maintained. The ETA 2010 retains most of the excluded transactions currently set out in the ETA, subject to certain minor amendments discussed below. The list of excluded transactions has however been shifted into the First Schedule of the ETA 2010, presumably to facilitate amendments to the list in the future.

Negotiable instruments and documents of title remain on the list of excluded transactions in the First Schedule of the ETA 2010 because there is as yet no recognised standard for ensuring their uniqueness in the electronic environment. However, certain specific examples of such instruments and documents (eg, bills of exchange, promissory notes, consignment notes, bills of lading) have been added for greater clarity and better alignment with the UN Convention.

Another minor amendment was made to carve out implied trusts from exclusion relating to trusts. Implied trusts would therefore be treated similarly to constructive and resulting trusts for the purposes of the ETA 2010.

It should be noted that although these classes of documents and transactions are excluded from the ETA 2010, parties are not thereby prevented from conducting these excluded matters electronically. In SM Integrated Transware Pte Ltd v Schenker Singapore (Pte) Ltd,(3) the Singapore High Court held that an e-mail correspondence could be considered to be in “writing”, and that the presence of the sender’s name in the e-mail header is sufficient to satisfy the requirement for a “signature” under s 6(d) the Civil Law Act (Cap 43). This was despite the fact that the ETA was not applicable as this case concerned a contract for the disposition of property (ie, one of the excluded transactions in s 4 of the ETA). This decision was subsequently upheld by the Singapore Court of Appeal in Joseph Mathew & anor v Singh Chiranjeev & anor,(4) with the qualifier that it should be clear that the document(s) concerned emanated from the person(s) signing them.

Liability of Network Service Providers

The final issue covered in the review of the ETA pertains to s 10 of the ETA, which exempts network service providers from civil and criminal liability in respect of third party content to which he merely provides access. This provision has been retained as s 26 of the ETA 2010 with only minor editorial amendments.

The Report states that this issue is still being considered by MICA and AGC and that a further report on this issue will be published in due course. It is hoped that the report will adequately address the perceived shortcomings of s 10 of the ETA (now s 26 of the ETA 2010), such as the lack of clarity around who would be considered a “network service provider”, and what would constitute “effective control” for the purposes of determining whether the infringing material has originated from a third party. Such clarity is all the more required given that the volume of user generated content on the Internet has grown exponentially in recent years.

Conclusion

The update to the ETA is a welcome boost to the electronic marketplace and is the result of a lengthy public consultation process, during which time the benefit of varied views of many stakeholders in this space was received. It will be important for businesses transacting online to actively review their processes in order to keep abreast of the developments described above. For the man in the street, he will no doubt look forward to the convenience of more e-Government services and perhaps a wider range of innovative authentication services to choose from.

Ken Chia
Koh See Khiang
Daryl Liu
Baker & McKenzie
E-mail:
[email protected]

Notes

1    [2004] 2 SLR 594.

2    See for example the guide issued by the Inland Revenue Authority of Singapore on “Keeping Machine-Sensible Records and Electronic Invoicing”, which sets out certain requirements that taxpayers must comply with in order to keep business records on electronic media. The Monetary Authority of Singapore has also issued various notices to regulated entities on the prevention of money laundering and countering the financing of terrorism, which touch upon record-keeping requirements. Generally speaking, such records are allowed to be kept in electronic form provided that they are admissible as evidence in a Singapore court of law.

3    [2005] 2 SLR 651.

4    [2010] 1 SLR 338.