Frequently Asked Questions
Electronic Transactions Ordinance ("ETO")
Voluntary Certification Authority Recognition Scheme under the ETO
Granting Recognition under the Voluntary Certification Authority Recognition Scheme
Digital Certificates for Electronic Transactions
Electronic Submission to Government
Electronic Transactions Ordinance ("ETO")
Q1. | What are the purposes of the ETO? |
A1. | The ETO aims to provide a clear legal framework for the conduct of secure electronic transactions by giving electronic record and electronic signature the same legal recognition as that of their paper-based counterparts. It also establishes a voluntary recognition scheme for certification authorities to enhance public confidence in the adoption of electronic transactions. |
Q2. | When was the ETO enacted? |
A2. | The ETO was enacted in January 2000 and last updated in January 2024. |
Q3. | What is the Electronic Transactions (Exclusion) Order? |
A3. | Under the ETO, the Permanent Secretary for Innovation, Technology and Industry may by Gazette specifies the ordinances that are excluded from the application of sections 5, 6, 7 and 8 of the ETO because of operational, technological, solemnity or other reasons. Please click this link to access the Electronic Transactions (Exclusion) Order . |
Voluntary Certification Authority Recognition Scheme under the ETO
Q1. | What is the Voluntary Certification Authority Recognition Scheme? |
A1. | To better protect the interest of users of certification services and enhance their confidence in electronic transactions, a Voluntary Certification Authority Recognition Scheme was established pursuant to the ETO. Under this scheme, a certification authority ("CA") may voluntarily apply to the Commissioner for Digital Policy ("CDP") for recognition and once recognized the CA shall comply with the requirements of the ETO and the Code of Practice for Recognized Certification Authorities ("Code of Practice"). Recognition will only be granted to those CAs that have reached a standard acceptable to the CDP and hence the trustworthiness of their systems and services are better ensured. |
Q2. | What is the Code of Practice for Recognized Certification Authorities? |
A2. | The Code of Practice for Recognized Certification Authorities is published by the CDP, which specifies the standards and procedures for a recognized certification authority ("CA") to carry out its functions. Recognized CAs shall comply with the Code of Practice for Recognized Certification Authorities in providing trustworthy CA services to the public. |
Q4. | Which CAs are now recognized under the ETO? |
A4. | There are now two certification authorities("CAs") recognized under the ETO. The Postmaster General is an recognized CA by virtue of the ETO. The Hongkong Post CA service commenced in January 2000. Digi-Sign Certification Services Limited became an recognized CA under the ETO in July 2001. The list of Recognized CAs is published on DPO’s web site. |
Granting Recognition under the Voluntary Certification Authority Recognition Scheme
Q1. | What are the criteria for the CDP to grant recognition to a certification authority? |
A1. | The CDP will consider various factors in granting recognition to a certification authority("CA"), including its financial status, liability cover and trustworthiness of the systems for its CA operation, with a view to better protecting users’ interest and enhancing public confidence in electronic transactions with the use of the recognized CA’s services. Please visit Recognition of Certification Authorities and Certificates for the detailed criteria. |
Q2. | What types of recognition will the CDP grant under the ETO? |
A2. | The CDP grants recognition to certification authorities("CAs") and digital certificates issued by an Recognized CA. Please visit Recognition of Certification Authorities and Certificates for details. |
Q5. | Are there guidelines for the assessment of a certification authority? |
A5. | To conduct an assessment on a certification authority("CA"), an assessor must follow the " Guidance Note on Compliance Assessment of Certification Authorities" published by the CDP. |
Q6. | How to submit application for recognition/renewal of recognition as a recognized Certification Authority and/or recognition of certificates? |
A6. | Please refer to Application for Recognition. |
Digital Certificates for Electronic Transactions
Q2. | What are the recognized digital certificates issued by certification authorities in Hong Kong? |
A2. | Recognized digital certificates are the certificates issued by certification authorities (CAs) recognized under the Electronic Transactions Ordinance (Cap. 553). The recognized digital certificates should be issued following the requirements as stipulated in the CAs' Certification Practice Statements which should be prepared in accordance with the requirements specified in the Code of Practice for Recognized Certification Authorities. Please refer to Types of Digital Certificates for details. |
Q3. | How to select and apply for a recognized digital certificate? |
A3. |
You are advised to select the type of recognized digital certificates that meet your personal / business need. Please refer to Types of Digital Certificates for more information on their purposes of use. To apply for a recognized digital certificate, each recognized certification authority has its own application procedures for its customers. For general understanding, please refer to User Journey of Using Digital Certificates. For detailed application forms and procedures, please refer to: |
Q8. | Which e-Government and e-Commerce services are accepting digital certificates? |
A8. | Currently, there are a number of e-Government services such as Government Electronic Trading Services, Road Cargo System and Voter Registration, etc. accepting digital certificates. Please also refer to Adoption of Digital Certificates in Hong Kong for more information on e-Government and e-Commerce services. |
Electronic Submission to Government
Q1. | How to submit applications / documents in electronic means to Government bureaux/departments? |
A1. | Most of the Government services have provided e-option to improve public sector efficiency and service delivery. Please visit the relevant websites of the Government bureaux / departments (B/Ds) for details on electronic submission of information to the respective B/Ds. |
Q2. | What is the required format when submitting information to Government entities in the form of electronic record? |
A2. | Under the ETO, the Permanent Secretary for Innovation, Technology and Industry may specify by Gazette the manner, format and procedure for submitting information to Government entities in the form of electronic record under various ordinances. Click this link for the latest Gazette Notice. |