🔒 Data Protection Regulatory Intelligence
Data Protection Monitor · dataprotection.gi
TW v13-gdpri-1.0.0
content: ai_generated legal review: never_reviewed (informational) publication gate: 0 failing7 sources retrieved model claude-sonnet-5 · 2026-08-05

Based mainly on secondary sources. Only 1 of the sources retrieved for this jurisdiction is official or direct reporting of official material (tier 1 or 2), against the 3 we look for. No finding on this page is shown with confidence above “Uncertain” until stronger sources are retrieved.

Taiwan

TW schema gdpri-v2 trajectory: not yet assessedregulated (omnibus)overlaps: FIM, WPM, AIC

Last updated · 10 categories · 44 claims · 17 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
44Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

Standing brief, as of 23 August 2026.

Lead Signal

Taiwan's Personal Data Protection Act Amendment, promulgated 11 November 2025, establishes the Personal Data Protection Commission as the jurisdiction's first dedicated, independent data-protection supervisory authority, responding to the Constitutional Court's 12 August 2022 ruling that mandated an independent oversight mechanism within three years. The Amendment is enacted but not yet effective; its practical force awaits an Executive Yuan commencement designation.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Comprehensive statute long in force, but the central-authority transition (NDC/sectoral regulators → PDPC) is still mid-flight with several implementing regulations only in draft/consultation.

Primary frameworkPersonal Data Protection Act 2010 (as amended 2015, 2023, 2025-2026) and its Enforcement Rules
Supervisory authorityPersonal Data Protection Commission (PDPC) Preparatory Office (transitioning from National Development Council and sector Competent Regulators)
Traffic-light rationale — AmberComprehensive statute long in force, but the central-authority transition (NDC/sectoral regulators → PDPC) is still mid-flight with several implementing regulations only in draft/consultation.

Sub-modules (5)

Regulator And AuthorityAmber

The NDC has been the interpreting authority since taking over from the Ministry of Justice, with enforcement historically carried out by industry Competent Regulators; the 2023/2025 amendments establish the PDPC as the new independent, primary supervisory authority for both government and private-sector data processing.

Claims (2):

  • The National Development Council is the lead regulator responsible for interpreting the PDPA, while enforcement falls under industry-specific Competent Regulators.
  • Amendments to the PDPA designate the Personal Data Protection Commission (PDPC) as an independent supervisory authority for both government agencies and private-sector entities, with a Preparatory Office established pending full commencement.

Act And InstrumentsGreen

Primary instruments are the PDPA and its Enforcement Rules; the PDPC has separately opened consultations on new Enforcement Rules amendments and subordinate regulations.

Claims (1):

  • The PDPC has announced draft amendments to the Enforcement Rules of the PDPA, initiating a 60-day public consultation period for stakeholder comments.

Material ScopeGreen

The PDPA is a comprehensive law covering personal data processing by both government and non-government agencies, including data transfers and breach notification, and affords data subjects access, rectification and deletion rights.

Claims (1):

  • The PDPA is a comprehensive data protection law covering the activities of government and non-government agencies, including data transfers and breach notification, with data subjects afforded access, rectification, and deletion rights.

Territorial ScopeAmber

The PDPA has extraterritorial application to government and non-government agencies operating outside Taiwan when they collect, process, or use the personal data of Taiwanese nationals, though it does not explicitly regulate goods/services or monitoring from abroad in the manner of GDPR Art 3.

Claims (1):

  • The PDPA has extraterritorial application to government and non-government agencies operating outside Taiwan that collect, process, or use the personal data of Taiwanese nationals, though it does not explicitly regulate goods/services offered or monitoring conducted from abroad.

Regulator Registration And FilingRed

No general controller registration/filing regime was identified for the PDPA; Competent Regulators may instead designate specific non-government agencies to establish security-maintenance and data-disposal plans.

Absence provenance: unavailable. Searched: Taiwan PDPA registration filing controller obligation, Taiwan PDPC registration requirement.

Category narrative97 words

Taiwan's data protection regime rests on the Personal Data Protection Act (PDPA) 2010, as amended in 2015 and further amended in 2023 and 2025-2026, plus its Enforcement Rules. Historically, the National Development Council (NDC) interpreted the PDPA while enforcement was devolved to sector-specific 'Competent Regulators'. The 2023 and 2025 amendment packages create an independent Personal Data Protection Commission (PDPC) to centralise interpretation and enforcement, but as of this run the PDPC is operating via a Preparatory Office and is issuing draft implementing regulations rather than functioning as a fully commenced independent authority — a live institutional transition.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (5)
  1. UncertainOneTrust DataGuidance — The National Development Council is the lead regulator responsible for interpreting the PDPA, while enforcement falls under industry-specific Competent Regulators.observed
  2. UncertainOneTrust DataGuidance — Amendments to the PDPA designate the Personal Data Protection Commission (PDPC) as an independent supervisory authority for both government agencies and private-sector entities, with a Preparatory Office established pending full commencement.observed
  3. UncertainOneTrust DataGuidance — The PDPC has announced draft amendments to the Enforcement Rules of the PDPA, initiating a 60-day public consultation period for stakeholder comments.observed
  4. UncertainOneTrust DataGuidance — The PDPA is a comprehensive data protection law covering the activities of government and non-government agencies, including data transfers and breach notification, with data subjects afforded access, rectification, and deletion rights.observed
  5. UncertainOneTrust DataGuidance — The PDPA has extraterritorial application to government and non-government agencies operating outside Taiwan that collect, process, or use the personal data of Taiwanese nationals, though it does not explicitly regulate goods/services offered or monitoring conducted from abroad.observed

#

Lawful bases and an enhanced-protection category list exist and were judicially tested, but definitional gaps remain versus GDPR (anonymisation, consent withdrawal, pseudonymisation is only implicit via Enforcement Rules).

Primary frameworkPDPA Articles 6, 19-20; Enforcement Rules
Supervisory authorityPersonal Data Protection Commission (PDPC) Preparatory Office / sector Competent Regulators
Traffic-light rationale — AmberLawful bases and an enhanced-protection category list exist and were judicially tested, but definitional gaps remain versus GDPR (anonymisation, consent withdrawal, pseudonymisation is only implicit via Enforcement Rules).

Sub-modules (4)

Lawful BasesAmber

The PDPA sets out lawful bases for data processing broadly similar in function to GDPR Art 6, though structured differently around government/non-government agency distinctions.

Claims (1):

  • The PDPA provides lawful bases for the collection, processing, and use of personal data, broadly paralleling the GDPR's approach to lawful bases for processing.

Special CategoriesAmber

Article 6 of the PDPA affords enhanced protection to personal data on medical records, healthcare, genetics, sex life, physical examination, and criminal records; the Constitutional Court upheld the constitutionality of the statistics/academic-research exception in Article 6(1)(4) in its 2022 judgment while flagging the absence of an independent monitoring mechanism.

Claims (2):

  • Article 6(1)(4) of the PDPA permits processing of data on medical records, healthcare, genetics, sex life, physical examination, and criminal records where necessary for statistics gathering or academic research purposes that does not lead to identification of a specific data subject.
  • Taiwan's Constitutional Court, in Judgment No. 13 of 2022, confirmed the constitutionality of Article 6(1)(4) of the PDPA but found the PDPA lacks an independent monitoring mechanism for personal data protection, directing relevant authorities to remedy this within three years.

Pseudonymisation And AnonymisationAmber

The PDPA does not directly address anonymous data or define special categories in GDPR terms; the Enforcement Rules instead refer to 'data that may not lead to the identification of a specific data subject', functionally analogous to pseudonymisation.

Claims (1):

  • The Enforcement Rules refer to 'data that may not lead to the identification of a specific data subject' as a functional analogue to pseudonymisation, but the PDPA does not directly define anonymous data as the GDPR does.
Category narrative63 words

The PDPA provides lawful bases for processing broadly analogous to GDPR Art 6, and affords enhanced protection to a defined set of sensitive categories (medical records, healthcare, genetics, sex life, physical examination, criminal records) under Article 6, upheld as constitutional by the Constitutional Court in 2022. The PDPA does not, however, explicitly define anonymisation or address consent withdrawal in the manner of GDPR.

Sources and claims (5)
  1. UncertainOneTrust DataGuidance — The PDPA provides lawful bases for the collection, processing, and use of personal data, broadly paralleling the GDPR's approach to lawful bases for processing.observed
  2. UncertainOneTrust DataGuidance — The PDPA does not address the withdrawal of consent as a discrete data-subject entitlement, unlike the GDPR.observed
  3. UncertainOneTrust DataGuidance — Article 6(1)(4) of the PDPA permits processing of data on medical records, healthcare, genetics, sex life, physical examination, and criminal records where necessary for statistics gathering or academic research purposes that does not lead to identification of a specific data subject.observed
  4. UncertainOneTrust DataGuidance — Taiwan's Constitutional Court, in Judgment No. 13 of 2022, confirmed the constitutionality of Article 6(1)(4) of the PDPA but found the PDPA lacks an independent monitoring mechanism for personal data protection, directing relevant authorities to remedy this within three years.observed
  5. UncertainOneTrust DataGuidance — The Enforcement Rules refer to 'data that may not lead to the identification of a specific data subject' as a functional analogue to pseudonymisation, but the PDPA does not directly define anonymous data as the GDPR does.observed

#

Core rights (access, rectification, erasure) are confirmed; portability and explicit restriction/objection deadlines are not clearly evidenced and are treated as gaps.

Primary frameworkPDPA (data subject rights provisions)
Supervisory authorityPersonal Data Protection Commission (PDPC) Preparatory Office / sector Competent Regulators
Traffic-light rationale — AmberCore rights (access, rectification, erasure) are confirmed; portability and explicit restriction/objection deadlines are not clearly evidenced and are treated as gaps.

Sub-modules (5)

Access RightGreen

Data subjects are provided with a right to access under the PDPA.

Claims (1):

  • Data subjects in Taiwan are provided with a right to access their personal data under the PDPA.

Rectification And ErasureGreen

Data subjects are provided rights to rectification and deletion under the PDPA.

Claims (1):

  • Data subjects in Taiwan are provided with rights to rectification and deletion of their personal data under the PDPA.

Restriction And ObjectionRed

No specific evidence of a standalone restriction-of-processing or objection right (including profiling opt-out) equivalent to GDPR Arts 18/21 was identified in available sources.

Absence provenance: unavailable. Searched: Taiwan PDPA right to object restriction of processing profiling opt-out.

Data PortabilityRed

No data portability right analogous to GDPR Art 20 was identified for the PDPA.

Absence provenance: unavailable. Searched: Taiwan PDPA data portability right.

Deadlines And Response WindowsRed

No specific statutory deadline for controller responses to data subject rights requests was located in available sources.

Absence provenance: unavailable. Searched: Taiwan PDPA response deadline data subject request.

Category narrative35 words

Data subjects under the PDPA are afforded rights to access, rectification, and deletion. Coverage of restriction/objection, portability, and statutory response deadlines is comparatively thin versus the GDPR and was not clearly evidenced in available sources.

Sources and claims (2)
  1. UncertainOneTrust DataGuidance — Data subjects in Taiwan are provided with a right to access their personal data under the PDPA.observed
  2. UncertainOneTrust DataGuidance — Data subjects in Taiwan are provided with rights to rectification and deletion of their personal data under the PDPA.observed

#

Security and breach-notification obligations are strengthening rapidly via 2025-2026 amendments and PDPC draft rules, but several instruments are still in consultation rather than in force, and ROPA/joint-controller concepts remain largely undeveloped.

Primary frameworkPDPA Articles 18, 22, 27, 48; Enforcement Rules Article 12; 2025-2026 PDPA amendments
Supervisory authorityPersonal Data Protection Commission (PDPC) Preparatory Office / sector Competent Regulators
Traffic-light rationale — AmberSecurity and breach-notification obligations are strengthening rapidly via 2025-2026 amendments and PDPC draft rules, but several instruments are still in consultation rather than in force, and ROPA/joint-controller concepts remain largely undeveloped.

Sub-modules (7)

Accountability And DpiaAmber

The PDPA and Enforcement Rules do not formally define DPIAs, but Enforcement Rules Article 12 outlines a risk-assessment mechanism functioning as a proto-DPIA.

Claims (1):

  • The PDPA and Enforcement Rules do not formally define Data Protection Impact Assessments, but Article 12 of the Enforcement Rules outlines a mechanism for establishing risk assessments as a security and maintenance measure.

Dpo RequirementsAmber

The PDPA does not use the term DPO; Article 18 instead requires assignment of dedicated personnel for security/maintenance measures. The PDPC's 2025-2026 draft regulations address duties, competency requirements, and training for Personal Data Protection Officers and related personnel, signalling a move toward a GDPR-style DPO concept.

Claims (2):

  • The PDPA and Enforcement Rules do not refer to Data Protection Officers; Article 18 of the PDPA instead requires assignment of dedicated personnel to implement security and maintenance measures preventing data from being stolen, altered, damaged, destroyed, or disclosed.
  • The PDPC announced draft regulations on the duties, competency requirements, and training of Personal Data Protection Officers and related personnel, with a 60-day consultation period.

Ropa RequirementsRed

The PDPA does not impose a general records-of-processing obligation; record-keeping is recommended only as a security/maintenance measure rather than mandated.

Claims (1):

  • Unlike the GDPR, the PDPA does not require controllers or processors to maintain records of processing activities; the PDPA instead establishes record-keeping as a recommended, non-mandatory security and maintenance measure.

Joint Controller ArrangementsRed

No joint-controller concept equivalent to GDPR was identified; the PDPA instead uses broader 'government'/'non-government agency' categories without a controller/processor joint-liability framework.

Claims (1):

  • The PDPA defines the broader concepts of 'government' and 'non-government' agencies rather than the GDPR's distinct controller/processor concepts, and does not directly address processor contractual responsibilities.

Security MeasuresAmber

Article 18 PDPA requires dedicated personnel for security/maintenance measures; Competent Regulators may designate certain non-government agencies to establish security-maintenance plans, and the PDPC has draft regulations on personal-data-file security and management in a 60-day consultation.

Claims (2):

  • Competent Regulators may designate certain non-government agencies to establish plans to maintain the security of personal data files, and may conduct on-site inspections of certain non-government agencies where deemed necessary.
  • The PDPC announced draft regulations for personal data file security and management, with a 60-day consultation period for stakeholder feedback.

Breach NotificationAmber

Taiwan's 2025 PDPA amendments introduce mandatory breach reporting; entities must notify affected individuals and report breaches to authorities within 72 hours and take immediate mitigation steps.

Claims (1):

  • Taiwan's 2025 amendments to the PDPA introduce mandatory breach reporting, requiring entities to notify affected individuals and report breaches to authorities within 72 hours and take immediate steps to mitigate harm.

Retention And DisposalAmber

Competent Regulators may designate certain non-government agencies to establish plans for how to dispose of personal data files after ceasing business operations.

Claims (1):

  • Competent Regulators may designate certain non-government agencies to establish plans for the disposal of personal data files after they cease business operations.
Category narrative82 words

Historically, the PDPA imposed lighter controller/processor obligations than the GDPR: no defined DPIA, no DPO concept (only a requirement to assign 'dedicated personnel' for security under Art 18), and no general ROPA obligation. The 2023 amendments overhauled Article 48's fine structure for security-obligation violations, and the 2025-2026 amendment package (plus PDPC draft regulations) introduces mandatory breach reporting (notification to authorities and affected individuals, framed around a 72-hour benchmark), and draft rules on PDPO duties, competency and training, and on personal-data-file security management.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (9)
  1. UncertainOneTrust DataGuidance — The PDPA and Enforcement Rules do not formally define Data Protection Impact Assessments, but Article 12 of the Enforcement Rules outlines a mechanism for establishing risk assessments as a security and maintenance measure.observed
  2. UncertainOneTrust DataGuidance — The PDPA and Enforcement Rules do not refer to Data Protection Officers; Article 18 of the PDPA instead requires assignment of dedicated personnel to implement security and maintenance measures preventing data from being stolen, altered, damaged, destroyed, or disclosed.observed
  3. UncertainOneTrust DataGuidance — The PDPC announced draft regulations on the duties, competency requirements, and training of Personal Data Protection Officers and related personnel, with a 60-day consultation period.observed
  4. UncertainOneTrust DataGuidance — Unlike the GDPR, the PDPA does not require controllers or processors to maintain records of processing activities; the PDPA instead establishes record-keeping as a recommended, non-mandatory security and maintenance measure.observed
  5. UncertainOneTrust DataGuidance — The PDPA defines the broader concepts of 'government' and 'non-government' agencies rather than the GDPR's distinct controller/processor concepts, and does not directly address processor contractual responsibilities.observed
  6. UncertainOneTrust DataGuidance — Competent Regulators may designate certain non-government agencies to establish plans to maintain the security of personal data files, and may conduct on-site inspections of certain non-government agencies where deemed necessary.observed
  7. UncertainOneTrust DataGuidance — The PDPC announced draft regulations for personal data file security and management, with a 60-day consultation period for stakeholder feedback.observed
  8. UncertainOneTrust DataGuidance — Taiwan's 2025 amendments to the PDPA introduce mandatory breach reporting, requiring entities to notify affected individuals and report breaches to authorities within 72 hours and take immediate steps to mitigate harm.observed
  9. UncertainOneTrust DataGuidance — Competent Regulators may designate certain non-government agencies to establish plans for the disposal of personal data files after they cease business operations.observed

#

A transfer-restriction mechanism exists and is being tightened, but Taiwan lacks SCC/BCR-equivalent mechanisms and has no concluded adequacy arrangement in either direction.

Primary frameworkPDPA (transfer-restriction provision); 2025-2026 PDPA amendments
Supervisory authorityPersonal Data Protection Commission (PDPC) Preparatory Office / sector Competent Regulators
Traffic-light rationale — AmberA transfer-restriction mechanism exists and is being tightened, but Taiwan lacks SCC/BCR-equivalent mechanisms and has no concluded adequacy arrangement in either direction.

Sub-modules (6)

Transfer MechanismsAmber

A competent authority may restrict or prohibit international transfers of personal data by non-government agencies where the transfer would prejudice material national interest, is restricted under treaty, or the destination lacks sound legal protection for personal data.

Claims (1):

  • A competent authority has discretion to issue an order restricting or prohibiting international transfer of personal data where the transfer would prejudice material national interest, is prohibited or restricted under a treaty or international agreement, or the destination country lacks sound legal protection for personal data.

Adequacy ReceivedRed

Taiwan's government previously indicated an intent to further amend the PDPA to meet GDPR standards and obtain an EU adequacy status decision; no concluded EU adequacy decision for Taiwan was identified in available sources.

Claims (1):

  • The Government of Taiwan has indicated a plan to further amend the PDPA to meet GDPR standards with a view to obtaining an EU adequacy status decision, though no such decision has been concluded.

Adequacy GrantedRed

No evidence was found of Taiwan formally granting adequacy-equivalent status to other jurisdictions under the PDPA's transfer-restriction framework.

Absence provenance: unavailable. Searched: Taiwan PDPA adequacy decision granted other countries.

Sccs And BcrsRed

Unlike the GDPR, the PDPA does not provide SCC or BCR mechanisms for cross-border transfers; instead it relies solely on a competent-authority restriction/prohibition power.

Claims (1):

  • The PDPA outlines instances where central authorities may restrict international data transfers but does not provide a range of enabling mechanisms such as adequacy decisions, standard contractual clauses, or binding corporate rules as found under the GDPR.

Transfer Impact AssessmentRed

No transfer impact assessment requirement analogous to post-Schrems II EU practice was identified under the PDPA.

Absence provenance: unavailable. Searched: Taiwan PDPA transfer impact assessment requirement.

Data LocalisationAmber

No general data-localisation mandate was identified; financial institutions face sector-specific outsourcing restrictions requiring prior regulatory approval or data-subject consent, which functions as a partial, sector-limited localisation control.

Claims (1):

  • Financial institutions in Taiwan are subject to strict requirements on outsourcing activities, including obtaining prior approval from their competent financial regulator or consent from data subjects, which functions as a sector-specific constraint on cross-border data flows.
Category narrative79 words

The PDPA does not provide a GDPR-style menu of transfer mechanisms (adequacy, SCCs, BCRs). Instead, a competent authority holds discretion to restrict or prohibit international transfers of personal data in defined circumstances (material national interest, treaty restriction, or inadequate protection in the destination country). Taiwan has previously signalled an intent to pursue an EU adequacy-style status but no adequacy decision (received or granted) was identified as concluded. The 2025 amendments are also reported to further restrict international data transfers.

Sources and claims (4)
  1. UncertainOneTrust DataGuidance — A competent authority has discretion to issue an order restricting or prohibiting international transfer of personal data where the transfer would prejudice material national interest, is prohibited or restricted under a treaty or international agreement, or the destination country lacks sound legal protection for personal data.observed
  2. UncertainOneTrust DataGuidance — The Government of Taiwan has indicated a plan to further amend the PDPA to meet GDPR standards with a view to obtaining an EU adequacy status decision, though no such decision has been concluded.observed
  3. UncertainOneTrust DataGuidance — The PDPA outlines instances where central authorities may restrict international data transfers but does not provide a range of enabling mechanisms such as adequacy decisions, standard contractual clauses, or binding corporate rules as found under the GDPR.observed
  4. UncertainOneTrust DataGuidance — Financial institutions in Taiwan are subject to strict requirements on outsourcing activities, including obtaining prior approval from their competent financial regulator or consent from data subjects, which functions as a sector-specific constraint on cross-border data flows.observed

#

Strong financial and health sector evidence; other sectoral sub-modules (telecoms, credit, education, insurance) carry no located overlay and default to red/absent.

Primary frameworkPDPA plus sector regulator rules (FSC, Ministry of Health and Welfare, Ministry of Transportation)
Supervisory authorityFinancial Supervisory Commission (FSC) / Ministry of Health and Welfare / other sector Competent Regulators
Traffic-light rationale — AmberStrong financial and health sector evidence; other sectoral sub-modules (telecoms, credit, education, insurance) carry no located overlay and default to red/absent.

Sub-modules (7)

Financial Sector OverlayAmber

Financial institutions face strict outsourcing requirements (prior regulatory approval or data-subject consent) and the FSC has recommended enhanced cybersecurity measures against AI-driven threats, including zero-trust architectures and continuous monitoring.

Claims (2):

  • Financial institutions in Taiwan are subject to strict requirements on their outsourcing activities, including obtaining prior approval from the competent authority of the financial institution or consent from the data subjects.
  • The Financial Supervisory Commission recommends financial institutions enhance cybersecurity measures to counter AI-driven threats, emphasizing zero-trust architectures, continuous monitoring, and senior management involvement.

Health Sector OverlayAmber

Health/genetic data receives enhanced PDPA protection, tested in constitutional litigation over National Health Insurance data reuse; the Ministry of Health and Welfare has separately proposed draft regulations on using National Health Insurance data for non-original purposes.

Claims (2):

  • The Taiwanese Supreme Administrative Court/Constitutional Court litigation confirms that National Health Insurance data may be released to third parties for research purposes under an enhanced-protection exception in PDPA Article 6(1)(4), subject to constitutional scrutiny.
  • Taiwan's Ministry of Health and Welfare announced draft regulations on the use of National Health Insurance data for non-original purposes, with a public comment period open into mid-2026.

Telecoms And EprivacyRed

No dedicated telecoms/ePrivacy overlay (cookie consent, e-communications privacy) distinct from the general PDPA was identified.

Absence provenance: unavailable. Searched: Taiwan telecoms ePrivacy law cookies communications privacy.

Employment DataAmber

Employers may collect job candidates' and employees' personal data based on the employment contract relationship, subject to PDPA notification obligations and Article 6 restrictions on sensitive categories.

Claims (1):

  • An employer may collect job candidates' and employees' personal data based on the potential or existing employment contract relationship, subject to PDPA notification obligations and Article 6 restrictions on sensitive personal data.

Credit And ScoringRed

No dedicated credit-scoring overlay was identified in available sources.

Absence provenance: unavailable. Searched: Taiwan credit scoring data protection rules.

EducationRed

No education-sector-specific data protection overlay was identified in available sources.

Absence provenance: unavailable. Searched: Taiwan education sector personal data protection rules.

InsuranceRed

No insurance-sector-specific data protection overlay was identified in available sources.

Absence provenance: unavailable. Searched: Taiwan insurance sector personal data protection rules.

Category narrative67 words

Financial and health sectors carry the clearest overlays on the general PDPA regime: financial institutions face outsourcing/approval constraints and heightened cybersecurity expectations from the Financial Supervisory Commission (FSC), while health data processing (e.g., National Health Insurance data reuse) has been the subject of direct constitutional litigation and fresh Ministry of Health and Welfare rulemaking. Telecoms/ePrivacy, credit-scoring, education, and insurance overlays were not clearly evidenced in available sources.

Sources and claims (5)
  1. UncertainOneTrust DataGuidance — Financial institutions in Taiwan are subject to strict requirements on their outsourcing activities, including obtaining prior approval from the competent authority of the financial institution or consent from the data subjects.observed
  2. UncertainOneTrust DataGuidance — The Financial Supervisory Commission recommends financial institutions enhance cybersecurity measures to counter AI-driven threats, emphasizing zero-trust architectures, continuous monitoring, and senior management involvement.observed
  3. UncertainOneTrust DataGuidance — The Taiwanese Supreme Administrative Court/Constitutional Court litigation confirms that National Health Insurance data may be released to third parties for research purposes under an enhanced-protection exception in PDPA Article 6(1)(4), subject to constitutional scrutiny.observed
  4. UncertainOneTrust DataGuidance — Taiwan's Ministry of Health and Welfare announced draft regulations on the use of National Health Insurance data for non-original purposes, with a public comment period open into mid-2026.observed
  5. UncertainOneTrust DataGuidance — An employer may collect job candidates' and employees' personal data based on the potential or existing employment contract relationship, subject to PDPA notification obligations and Article 6 restrictions on sensitive personal data.observed

#

Only a generic marketing-restriction hook was evidenced; the adtech-specific sub-modules are largely unaddressed by Taiwanese law as currently evidenced.

Primary frameworkPDPA (general marketing-restriction provisions); no dedicated ePrivacy/adtech statute identified
Supervisory authorityPersonal Data Protection Commission (PDPC) Preparatory Office / sector Competent Regulators
Traffic-light rationale — RedOnly a generic marketing-restriction hook was evidenced; the adtech-specific sub-modules are largely unaddressed by Taiwanese law as currently evidenced.

Sub-modules (6)

Cookies And TrackersRed

No dedicated cookie/tracker consent regime distinct from general PDPA notice obligations was identified.

Absence provenance: unavailable. Searched: Taiwan cookie consent law tracker regulation.

Dark PatternsRed

No dark-pattern-specific prohibition was identified in Taiwanese data protection law.

Absence provenance: unavailable. Searched: Taiwan dark patterns consent law.

Opt Out SignalsRed

No recognition of technical opt-out signals (e.g., Global Privacy Control) was identified under the PDPA.

Absence provenance: unavailable. Searched: Taiwan Global Privacy Control opt-out signal recognition.

Clean Rooms And DcrRed

No clean-room or data-collaboration-room specific rules were identified.

Absence provenance: unavailable. Searched: Taiwan data clean room regulation.

Cross Context AdvertisingRed

No cross-context-advertising ('sale'/'share') concept analogous to CPRA was identified under the PDPA.

Absence provenance: unavailable. Searched: Taiwan cross-context advertising sale share personal data.

Direct MarketingAmber

The PDPA imposes marketing restrictions, with regulators empowered to order correction and impose administrative fines for failure to comply with notification requirements, marketing restrictions, information security, or data-subject-request obligations.

Claims (1):

  • Under the PDPA, an authority may order correction by a deadline and impose an administrative fine where a non-government agency fails to comply with notification requirements, marketing restrictions, information security requirements, or obligations to respond to data-subject requests.
Category narrative38 words

The PDPA contains a marketing-related restriction (allowing regulators to act against non-compliance with marketing restrictions), but no dedicated cookie/tracker consent regime, dark-pattern prohibition, opt-out-signal recognition, clean-room framework, or cross-context-advertising rule was identified as distinct from the general PDPA.

Sources and claims (1)
  1. UncertainOneTrust DataGuidance — Under the PDPA, an authority may order correction by a deadline and impose an administrative fine where a non-government agency fails to comply with notification requirements, marketing restrictions, information security requirements, or obligations to respond to data-subject requests.observed

#

No binding ADM-transparency or biometric-specific regime yet, but the AI Basic Law and Legislative Yuan facial-recognition reports show active, rapidly evolving regulatory attention.

Primary frameworkPDPA Article 6 (genetic data); Basic Law on Artificial Intelligence (effective 2026-01-14)
Supervisory authorityPersonal Data Protection Commission (PDPC) Preparatory Office; Ministry of Digital Affairs (AI Basic Law central authority per legislative recommendation)
Traffic-light rationale — AmberNo binding ADM-transparency or biometric-specific regime yet, but the AI Basic Law and Legislative Yuan facial-recognition reports show active, rapidly evolving regulatory attention.

Sub-modules (6)

Profiling RestrictionsRed

No profiling-restriction provision analogous to GDPR Art 22 was identified under the PDPA.

Absence provenance: unavailable. Searched: Taiwan PDPA profiling restriction automated decision.

Automated Decision Making TransparencyRed

No ADM transparency/explanation right equivalent to GDPR Art 22 was identified under the PDPA itself.

Absence provenance: unavailable. Searched: Taiwan automated decision-making transparency right explanation.

Ai Risk AssessmentsAmber

Taiwan's Basic Law on Artificial Intelligence, effective January 14, 2026, establishes a regulatory framework built on seven guiding principles, mandates high-risk AI warnings, and emphasises data governance and government support for AI development.

Claims (2):

  • Taiwan's Basic Law on Artificial Intelligence, effective January 14, 2026, promotes human-centric AI development and outlines seven guiding principles for ethical compliance.
  • Taiwan's Basic Law on Artificial Intelligence establishes a regulatory framework with seven principles, mandates high-risk AI warnings, and emphasizes data governance and government support.

Biometric RegimeAmber

No dedicated binding biometric-data regime was identified; the Legislative Yuan has issued a report highlighting privacy risks of facial recognition technology and proposing legal reforms to strengthen personal data protection.

Claims (1):

  • The Legislative Yuan's report highlights privacy risks of facial recognition technology and proposes legal reforms to strengthen personal data protection in Taiwan.

Genetic DataAmber

Genetic data is listed among the enhanced-protection sensitive categories under PDPA Article 6, alongside medical, healthcare, sex-life, physical-examination, and criminal-record data.

Claims (1):

  • PDPA Article 6 lists genetic data among the categories of personal data afforded enhanced protection, alongside medical records, healthcare, sex life, physical examination, and criminal records.

State Surveillance CarveoutsRed

No explicit, standalone national-security/surveillance carve-out provision distinct from the general international-transfer restriction (which references 'material national interest') was identified.

Absence provenance: unavailable. Searched: Taiwan PDPA national security exemption surveillance carveout.

Category narrative64 words

Taiwan lacks a direct GDPR Art 22 profiling/ADM-transparency analogue under the PDPA. Momentum is instead building through a separate instrument — the AI Basic Law, effective January 14, 2026 — which promotes human-centric AI development, mandates high-risk AI warnings, and emphasises data governance, alongside legislative-branch reports flagging facial-recognition privacy risks. Genetic data receives enhanced protection as a listed sensitive category under PDPA Article 6.

Sources and claims (4)
  1. UncertainOneTrust DataGuidance — Taiwan's Basic Law on Artificial Intelligence, effective January 14, 2026, promotes human-centric AI development and outlines seven guiding principles for ethical compliance.observed
  2. UncertainOneTrust DataGuidance — Taiwan's Basic Law on Artificial Intelligence establishes a regulatory framework with seven principles, mandates high-risk AI warnings, and emphasizes data governance and government support.observed
  3. UncertainOneTrust DataGuidance — The Legislative Yuan's report highlights privacy risks of facial recognition technology and proposes legal reforms to strengthen personal data protection in Taiwan.observed
  4. UncertainOneTrust DataGuidance — PDPA Article 6 lists genetic data among the categories of personal data afforded enhanced protection, alongside medical records, healthcare, sex life, physical examination, and criminal records.observed

#

No children/vulnerable-groups-specific provisions were located; this is a confirmed, explicit statutory gap rather than a search failure.

Traffic-light rationale — RedNo children/vulnerable-groups-specific provisions were located; this is a confirmed, explicit statutory gap rather than a search failure.

Sub-modules (5)

Age VerificationRed

No age-verification requirement for data processing was identified under the PDPA.

Claims (1):

  • Unlike the GDPR, the PDPA does not address the processing of children's data nor does it provide additional age-verification or minor-specific requirements.

Minor Profiling BansRed

No minor-profiling ban was identified under the PDPA.

Absence provenance: unavailable. Searched: Taiwan minors profiling ban data protection.

Education SettingsRed

No education-setting-specific data protection rule was identified.

Absence provenance: unavailable. Searched: Taiwan education sector personal data protection rules.

Dependent AdultsRed

No dependent-adult (elderly/incapacitated) specific data protection provision was identified.

Absence provenance: unavailable. Searched: Taiwan dependent adults elderly incapacitated data protection.

Category narrative37 words

Unlike the GDPR, the PDPA does not address the processing of children's data or provide additional requirements for minors, and no parental-consent mechanism, minor-profiling ban, education-setting-specific rule, or dependent-adult protection distinct from the general regime was identified.

Sources and claims (1)
  1. UncertainOneTrust DataGuidance — Unlike the GDPR, the PDPA does not address the processing of children's data nor does it provide additional age-verification or minor-specific requirements.observed

#

Penalties and enforcement activity are real and escalating, but the central regulator (PDPC) is still transitioning to full operational status and redress mechanisms (collective/private right of action) are not clearly evidenced.

Primary frameworkPDPA Articles 47-48 (as amended 2023); PDPC/Preparatory Office rulemaking 2025-2026
Supervisory authorityPersonal Data Protection Commission (PDPC) Preparatory Office / Ministry of Digital Affairs / sector Competent Regulators
Traffic-light rationale — AmberPenalties and enforcement activity are real and escalating, but the central regulator (PDPC) is still transitioning to full operational status and redress mechanisms (collective/private right of action) are not clearly evidenced.

Sub-modules (6)

Regulator Powers And PenaltiesAmber

Regulators have corrective and investigatory powers including fines and corrective orders, with the 2023 amendments raising the general administrative-fine ceiling from TWD 200,000 to TWD 2 million and introducing a TWD 150,000-15 million per-violation fine tier for uncorrected significant security failures.

Claims (3):

  • The 2023 amendments to the PDPA grant regulators authority to impose immediate administrative fines on private-sector entities for non-compliance, removing the requirement for a rectification period prior to the imposition of fines.
  • The 2023 amendments raise the maximum administrative fine for non-compliance with PDPA security obligations from TWD 200,000 to TWD 2 million.
  • Failure to rectify identified PDPA shortcomings within a regulator-specified timeframe now carries an administrative fine ranging from TWD 150,000 to TWD 15 million per violation, with immediate fines available where failures are of a significant nature affecting a large number of data subjects.

Enforcement Activity IndexAmber

Taiwan's Ministry of Digital Development fined Shopee TWD 200,000 in 2023 for PDPA violations following a personal-data leakage incident, evidencing active enforcement under the pre-PDPC sectoral model.

Claims (1):

  • Taiwan's Ministry of Digital Development fined Shopee Pte. Ltd. TWD 200,000 for violating PDPA Articles 27(1), 48(4), and 50 following a personal-information leakage incident.

Regulator Funding And CapacityAmber

The NDC confirmed the Executive Yuan will promptly establish a preparatory office for the Personal Data Protection Commission, indicating institutional capacity-building is underway but not yet complete.

Claims (1):

  • The National Development Council confirmed that the Executive Yuan will promptly establish a preparatory office for the Personal Data Protection Commission.

Collective Redress And Class ActionsRed

No collective-redress or class-action mechanism specific to PDPA enforcement was identified in available sources.

Absence provenance: unavailable. Searched: Taiwan PDPA class action collective redress data protection.

Private Right Of ActionRed

No explicit private-right-of-action provision specific to the PDPA (beyond general civil-liability principles) was clearly evidenced in available sources.

Absence provenance: unavailable. Searched: Taiwan PDPA private right of action civil suit data subject.

Recent Developments 180DAmber

Within the last 180 days: Taiwan's AI Basic Law took effect January 14, 2026; the PDPC Preparatory Office issued draft regulations on PDPO duties/competency/training and on personal-data-file security and management (each with 60-day consultation windows); the Ministry of Transportation published a draft amendment for the transport industry with a comment period ending March 10, 2026; and the Ministry of Health and Welfare opened a comment period (into mid-2026) on draft rules for reusing National Health Insurance data.

Claims (3):

  • Taiwan's Ministry of Transportation published a draft amendment to enhance personal data protection for the transport industry, with a 14-day comment period ending March 10, 2026.
  • Taiwan's Ministry of Health and Welfare announced draft regulations on the use of National Health Insurance data for non-original purposes, with a public comment period open until June 22, 2026.
  • Taiwan's AI Basic Law, effective January 14, 2026, promotes human-centric AI development and outlines seven guiding principles for ethical compliance.
Category narrative108 words

Regulators (historically the NDC-coordinated Competent Regulators, transitioning to the PDPC) hold corrective and investigatory powers, including fines, corrective orders, and on-site inspections. The 2023 amendments materially raised penalties — the general administrative-fine ceiling rose from TWD 200,000 to TWD 2 million, with fines for uncorrected significant security failures ranging from TWD 150,000 to TWD 15 million per violation — and removed the mandatory rectification-period precondition for certain fines. Enforcement activity includes the Ministry of Digital Development's TWD 200,000 fine against Shopee for a 2023 data breach. Institutional capacity is mid-build-out via the PDPC Preparatory Office. No collective-redress/class-action or explicit private-right-of-action mechanism specific to the PDPA was clearly evidenced.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (8)
  1. UncertainOneTrust DataGuidance — The 2023 amendments to the PDPA grant regulators authority to impose immediate administrative fines on private-sector entities for non-compliance, removing the requirement for a rectification period prior to the imposition of fines.observed
  2. UncertainOneTrust DataGuidance — The 2023 amendments raise the maximum administrative fine for non-compliance with PDPA security obligations from TWD 200,000 to TWD 2 million.observed
  3. UncertainOneTrust DataGuidance — Failure to rectify identified PDPA shortcomings within a regulator-specified timeframe now carries an administrative fine ranging from TWD 150,000 to TWD 15 million per violation, with immediate fines available where failures are of a significant nature affecting a large number of data subjects.observed
  4. UncertainOneTrust DataGuidance — Taiwan's Ministry of Digital Development fined Shopee Pte. Ltd. TWD 200,000 for violating PDPA Articles 27(1), 48(4), and 50 following a personal-information leakage incident.observed
  5. UncertainOneTrust DataGuidance — The National Development Council confirmed that the Executive Yuan will promptly establish a preparatory office for the Personal Data Protection Commission.observed
  6. UncertainOneTrust DataGuidance — Taiwan's Ministry of Transportation published a draft amendment to enhance personal data protection for the transport industry, with a 14-day comment period ending March 10, 2026.observed
  7. UncertainOneTrust DataGuidance — Taiwan's Ministry of Health and Welfare announced draft regulations on the use of National Health Insurance data for non-original purposes, with a public comment period open until June 22, 2026.observed
  8. UncertainOneTrust DataGuidance — Taiwan's AI Basic Law, effective January 14, 2026, promotes human-centric AI development and outlines seven guiding principles for ethical compliance.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Publication gate

No failing checks.

schema_validpass
min_t1_per_instrument_metn/a — no subject in this jurisdiction
min_quoted_text_presentwaived — floor 0%
translation_provenance_recordedn/a — no subject in this jurisdiction
egress_verifiedpass
source_tier_integrity_okpass
jurisdiction_source_floor_metpass
tier_a_b_national_primary_pct0.0
aggregator_only_jurisdiction_count1
manual_override

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Taiwan
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewerno reviewer on record
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 44 claim(s) (44 category placement(s)), 17 source(s) in the cumulative register.

Think something on this page is wrong? Report an error.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (34 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsdeadlines and response windows
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy received
Art. 46Cross-Border & Adequacysccs and bcrs
Art. 47Cross-Border & Adequacysccs and bcrs
Art. 48Cross-Border & Adequacydata localisation
Art. 49Cross-Border & Adequacytransfer impact assessment
Art. 77Enforcement & Redressprivate right of action
Art. 78Enforcement & Redresscollective redress and class actions
Art. 79Enforcement & Redresscollective redress and class actions
Art. 82Enforcement & Redressprivate right of action
Art. 83Enforcement & Redressregulator powers and penalties
Art. 84Enforcement & Redressregulator powers and penalties

Self-audit

All 10 modules populated. Coverage relies entirely on T3 commercial/professional legal-database sources (OneTrust DataGuidance) and reporting on primary instruments (PDPA text, Constitutional Court Judgment No. 13/2022, Ministry of Digital Development enforcement order); no direct T1 retrieval of the PDPA statutory text, official PDPC/NDC gazette notices, or a verified PDPC/NDC regulator URL was performed this run. regulator_and_framework, controller_processor_duties, cross_border_and_adequacy, sectoral_watch, algorithmic_biometric_and_surveillance_governance, and enforcement_and_redress have moderate-to-good claim density; data_subject_rights, adtech_and_commercial_privacy, and children_and_vulnerable_groups are thin/red due to genuine statutory gaps rather than search failure (explicitly documented via absent_field_provenance).

Unresolved questions (5):

  • Has the Personal Data Protection Commission (PDPC) formally commenced full independent-authority operation, or does it remain a Preparatory Office as of the run date?
  • What is the PDPC's official regulator URL once fully constituted (not yet confirmed against a primary gov.tw source in this run)?
  • Is there a concluded or pending EU (or other regime) adequacy determination for Taiwan, beyond the historical aspiration to seek one?
  • Does the 2025-2026 PDPA amendment package's mandatory breach-notification obligation have a confirmed in-force effective date, or does it remain enacted-not-yet-effective pending Cabinet designation (as occurred with the 2023 PDPC-establishment provisions)?
  • Are there PDPA-specific collective-redress or private-right-of-action mechanisms distinct from general Taiwanese civil procedure?

Escalate to primary-source review: yes