Based mainly on secondary sources. Only 1 of the sources retrieved for this jurisdiction is official or direct reporting of official material (tier 1 or 2), against the 3 we look for. No finding on this page is shown with confidence above “Uncertain” until stronger sources are retrieved.
Taiwan
TWschema gdpri-v2trajectory: not yet assessedregulated (omnibus)overlaps: FIM, WPM, AIC
Last updated · 10 categories · 44
claims · 17 sources in the cumulative register
10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
44Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix(sums to 10 rendered categories; click to filter)
Jurisdiction brief
Standing brief, as of 23 August 2026.
Lead Signal
Taiwan's Personal Data Protection Act Amendment, promulgated 11 November 2025, establishes the Personal Data Protection Commission as the jurisdiction's first dedicated, independent data-protection supervisory authority, responding to the Constitutional Court's 12 August 2022 ruling that mandated an independent oversight mechanism within three years. The Amendment is enacted but not yet effective; its practical force awaits an Executive Yuan commencement designation.
Other Developments
Breach notification extends to the PDPC. Non-government agencies must now report qualifying data-breach incidents to the PDPC and retain incident documentation for PDPC inspection, alongside their existing duty to notify affected data subjects; the specific reporting threshold and timeline await PDPC subordinate regulation. A DPO mandate for non-government agencies was dropped. The first draft of the Amendment proposed extending a mandatory data-protection-officer or audit-personnel appointment requirement to non-government agencies; the final Amendment does not carry this through, and only government agencies remain subject to a DPO-appointment duty. Risk-prioritised inspection powers were also narrowed in drafting. The first draft's proposal to let the PDPC prioritise administrative inspection against higher-risk industries and agencies was not included in the final Amendment, narrowing the scope of PDPC inspection powers relative to what was originally proposed.
Cross-Monitor Connections
The PDPC's establishment and its breach-reporting powers bear on AML-adjacent data-sharing and beneficial-ownership verification data flows tracked by the financial-integrity monitor, which separately notes the Amendment's cross-monitor relevance to its beneficial-ownership and enabler-jurisdiction typology domains.
Outlook
The PDPA Amendment's practical effect remains deferred pending two events: the Executive Yuan's designation of an effective date, expected within 2026, and the PDPC's operationalisation once its Organizational Act passes. Until then, Taiwan's data-protection enforcement architecture continues to operate under the prior model, with the PDPC's investigative and administrative-inspection powers over non-government agencies not yet exercised because the body is not yet operational.
trust tier: ai_unverified
Standing brief, as of 23 August 2026.
Regulatory Status
Taiwan's data-protection framework underwent its most significant structural reform to date this cycle: the PDPA Amendment establishes the Personal Data Protection Commission, Taiwan's first dedicated independent data-protection authority, alongside new breach-reporting duties for non-government agencies. The reform responds to a 2022 Constitutional Court ruling and narrows, relative to its first draft, both the DPO-appointment mandate and the Commission's risk-prioritised inspection powers.
Outlook
Watch for the Executive Yuan's effective-date designation and the Commission's operationalisation, both expected within 2026, which will determine when the new framework takes practical effect.
10 of 10 categories
Signal
Density
Selections OR within a group, AND across groups. Press / to search.
Comprehensive statute long in force, but the central-authority transition (NDC/sectoral regulators → PDPC) is still mid-flight with several implementing regulations only in draft/consultation.
Primary frameworkPersonal Data Protection Act 2010 (as amended 2015, 2023, 2025-2026) and its Enforcement Rules
Supervisory authorityPersonal Data Protection Commission (PDPC) Preparatory Office (transitioning from National Development Council and sector Competent Regulators)
Traffic-light rationale — AmberComprehensive statute long in force, but the central-authority transition (NDC/sectoral regulators → PDPC) is still mid-flight with several implementing regulations only in draft/consultation.
Sub-modules (5)
Regulator And AuthorityAmber
The NDC has been the interpreting authority since taking over from the Ministry of Justice, with enforcement historically carried out by industry Competent Regulators; the 2023/2025 amendments establish the PDPC as the new independent, primary supervisory authority for both government and private-sector data processing.
Claims (2):
The National Development Council is the lead regulator responsible for interpreting the PDPA, while enforcement falls under industry-specific Competent Regulators.
Amendments to the PDPA designate the Personal Data Protection Commission (PDPC) as an independent supervisory authority for both government agencies and private-sector entities, with a Preparatory Office established pending full commencement.
Act And InstrumentsGreen
Primary instruments are the PDPA and its Enforcement Rules; the PDPC has separately opened consultations on new Enforcement Rules amendments and subordinate regulations.
Claims (1):
The PDPC has announced draft amendments to the Enforcement Rules of the PDPA, initiating a 60-day public consultation period for stakeholder comments.
Material ScopeGreen
The PDPA is a comprehensive law covering personal data processing by both government and non-government agencies, including data transfers and breach notification, and affords data subjects access, rectification and deletion rights.
Claims (1):
The PDPA is a comprehensive data protection law covering the activities of government and non-government agencies, including data transfers and breach notification, with data subjects afforded access, rectification, and deletion rights.
Territorial ScopeAmber
The PDPA has extraterritorial application to government and non-government agencies operating outside Taiwan when they collect, process, or use the personal data of Taiwanese nationals, though it does not explicitly regulate goods/services or monitoring from abroad in the manner of GDPR Art 3.
Claims (1):
The PDPA has extraterritorial application to government and non-government agencies operating outside Taiwan that collect, process, or use the personal data of Taiwanese nationals, though it does not explicitly regulate goods/services offered or monitoring conducted from abroad.
Regulator Registration And FilingRed
No general controller registration/filing regime was identified for the PDPA; Competent Regulators may instead designate specific non-government agencies to establish security-maintenance and data-disposal plans.
Taiwan's data protection regime rests on the Personal Data Protection Act (PDPA) 2010, as amended in 2015 and further amended in 2023 and 2025-2026, plus its Enforcement Rules. Historically, the National Development Council (NDC) interpreted the PDPA while enforcement was devolved to sector-specific 'Competent Regulators'. The 2023 and 2025 amendment packages create an independent Personal Data Protection Commission (PDPC) to centralise interpretation and enforcement, but as of this run the PDPC is operating via a Preparatory Office and is issuing draft implementing regulations rather than functioning as a fully commenced independent authority — a live institutional transition.
No new data since the standing brief. 1 periodic run re-emitted it unchanged.
Sources and claims (5)
UncertainOneTrust DataGuidance — The National Development Council is the lead regulator responsible for interpreting the PDPA, while enforcement falls under industry-specific Competent Regulators.observed
UncertainOneTrust DataGuidance — Amendments to the PDPA designate the Personal Data Protection Commission (PDPC) as an independent supervisory authority for both government agencies and private-sector entities, with a Preparatory Office established pending full commencement.observed
UncertainOneTrust DataGuidance — The PDPC has announced draft amendments to the Enforcement Rules of the PDPA, initiating a 60-day public consultation period for stakeholder comments.observed
UncertainOneTrust DataGuidance — The PDPA is a comprehensive data protection law covering the activities of government and non-government agencies, including data transfers and breach notification, with data subjects afforded access, rectification, and deletion rights.observed
UncertainOneTrust DataGuidance — The PDPA has extraterritorial application to government and non-government agencies operating outside Taiwan that collect, process, or use the personal data of Taiwanese nationals, though it does not explicitly regulate goods/services offered or monitoring conducted from abroad.observed
Lawful bases and an enhanced-protection category list exist and were judicially tested, but definitional gaps remain versus GDPR (anonymisation, consent withdrawal, pseudonymisation is only implicit via Enforcement Rules).
Traffic-light rationale — AmberLawful bases and an enhanced-protection category list exist and were judicially tested, but definitional gaps remain versus GDPR (anonymisation, consent withdrawal, pseudonymisation is only implicit via Enforcement Rules).
Sub-modules (4)
Lawful BasesAmber
The PDPA sets out lawful bases for data processing broadly similar in function to GDPR Art 6, though structured differently around government/non-government agency distinctions.
Claims (1):
The PDPA provides lawful bases for the collection, processing, and use of personal data, broadly paralleling the GDPR's approach to lawful bases for processing.
Consent ThresholdsAmber
Unlike the GDPR, the PDPA does not directly address withdrawal of consent as a standalone right.
Claims (1):
The PDPA does not address the withdrawal of consent as a discrete data-subject entitlement, unlike the GDPR.
Special CategoriesAmber
Article 6 of the PDPA affords enhanced protection to personal data on medical records, healthcare, genetics, sex life, physical examination, and criminal records; the Constitutional Court upheld the constitutionality of the statistics/academic-research exception in Article 6(1)(4) in its 2022 judgment while flagging the absence of an independent monitoring mechanism.
Claims (2):
Article 6(1)(4) of the PDPA permits processing of data on medical records, healthcare, genetics, sex life, physical examination, and criminal records where necessary for statistics gathering or academic research purposes that does not lead to identification of a specific data subject.
Taiwan's Constitutional Court, in Judgment No. 13 of 2022, confirmed the constitutionality of Article 6(1)(4) of the PDPA but found the PDPA lacks an independent monitoring mechanism for personal data protection, directing relevant authorities to remedy this within three years.
Pseudonymisation And AnonymisationAmber
The PDPA does not directly address anonymous data or define special categories in GDPR terms; the Enforcement Rules instead refer to 'data that may not lead to the identification of a specific data subject', functionally analogous to pseudonymisation.
Claims (1):
The Enforcement Rules refer to 'data that may not lead to the identification of a specific data subject' as a functional analogue to pseudonymisation, but the PDPA does not directly define anonymous data as the GDPR does.
Category narrative63 words
The PDPA provides lawful bases for processing broadly analogous to GDPR Art 6, and affords enhanced protection to a defined set of sensitive categories (medical records, healthcare, genetics, sex life, physical examination, criminal records) under Article 6, upheld as constitutional by the Constitutional Court in 2022. The PDPA does not, however, explicitly define anonymisation or address consent withdrawal in the manner of GDPR.
Sources and claims (5)
UncertainOneTrust DataGuidance — The PDPA provides lawful bases for the collection, processing, and use of personal data, broadly paralleling the GDPR's approach to lawful bases for processing.observed
UncertainOneTrust DataGuidance — The PDPA does not address the withdrawal of consent as a discrete data-subject entitlement, unlike the GDPR.observed
UncertainOneTrust DataGuidance — Article 6(1)(4) of the PDPA permits processing of data on medical records, healthcare, genetics, sex life, physical examination, and criminal records where necessary for statistics gathering or academic research purposes that does not lead to identification of a specific data subject.observed
UncertainOneTrust DataGuidance — Taiwan's Constitutional Court, in Judgment No. 13 of 2022, confirmed the constitutionality of Article 6(1)(4) of the PDPA but found the PDPA lacks an independent monitoring mechanism for personal data protection, directing relevant authorities to remedy this within three years.observed
UncertainOneTrust DataGuidance — The Enforcement Rules refer to 'data that may not lead to the identification of a specific data subject' as a functional analogue to pseudonymisation, but the PDPA does not directly define anonymous data as the GDPR does.observed
Core rights (access, rectification, erasure) are confirmed; portability and explicit restriction/objection deadlines are not clearly evidenced and are treated as gaps.
Primary frameworkPDPA (data subject rights provisions)
Traffic-light rationale — AmberCore rights (access, rectification, erasure) are confirmed; portability and explicit restriction/objection deadlines are not clearly evidenced and are treated as gaps.
Sub-modules (5)
Access RightGreen
Data subjects are provided with a right to access under the PDPA.
Claims (1):
Data subjects in Taiwan are provided with a right to access their personal data under the PDPA.
Rectification And ErasureGreen
Data subjects are provided rights to rectification and deletion under the PDPA.
Claims (1):
Data subjects in Taiwan are provided with rights to rectification and deletion of their personal data under the PDPA.
Restriction And ObjectionRed
No specific evidence of a standalone restriction-of-processing or objection right (including profiling opt-out) equivalent to GDPR Arts 18/21 was identified in available sources.
Absence provenance: unavailable. Searched: Taiwan PDPA right to object restriction of processing profiling opt-out.
Data PortabilityRed
No data portability right analogous to GDPR Art 20 was identified for the PDPA.
Absence provenance: unavailable. Searched: Taiwan PDPA data portability right.
Deadlines And Response WindowsRed
No specific statutory deadline for controller responses to data subject rights requests was located in available sources.
Data subjects under the PDPA are afforded rights to access, rectification, and deletion. Coverage of restriction/objection, portability, and statutory response deadlines is comparatively thin versus the GDPR and was not clearly evidenced in available sources.
Sources and claims (2)
UncertainOneTrust DataGuidance — Data subjects in Taiwan are provided with a right to access their personal data under the PDPA.observed
UncertainOneTrust DataGuidance — Data subjects in Taiwan are provided with rights to rectification and deletion of their personal data under the PDPA.observed
Security and breach-notification obligations are strengthening rapidly via 2025-2026 amendments and PDPC draft rules, but several instruments are still in consultation rather than in force, and ROPA/joint-controller concepts remain largely undeveloped.
Traffic-light rationale — AmberSecurity and breach-notification obligations are strengthening rapidly via 2025-2026 amendments and PDPC draft rules, but several instruments are still in consultation rather than in force, and ROPA/joint-controller concepts remain largely undeveloped.
Sub-modules (7)
Accountability And DpiaAmber
The PDPA and Enforcement Rules do not formally define DPIAs, but Enforcement Rules Article 12 outlines a risk-assessment mechanism functioning as a proto-DPIA.
Claims (1):
The PDPA and Enforcement Rules do not formally define Data Protection Impact Assessments, but Article 12 of the Enforcement Rules outlines a mechanism for establishing risk assessments as a security and maintenance measure.
Dpo RequirementsAmber
The PDPA does not use the term DPO; Article 18 instead requires assignment of dedicated personnel for security/maintenance measures. The PDPC's 2025-2026 draft regulations address duties, competency requirements, and training for Personal Data Protection Officers and related personnel, signalling a move toward a GDPR-style DPO concept.
Claims (2):
The PDPA and Enforcement Rules do not refer to Data Protection Officers; Article 18 of the PDPA instead requires assignment of dedicated personnel to implement security and maintenance measures preventing data from being stolen, altered, damaged, destroyed, or disclosed.
The PDPC announced draft regulations on the duties, competency requirements, and training of Personal Data Protection Officers and related personnel, with a 60-day consultation period.
Ropa RequirementsRed
The PDPA does not impose a general records-of-processing obligation; record-keeping is recommended only as a security/maintenance measure rather than mandated.
Claims (1):
Unlike the GDPR, the PDPA does not require controllers or processors to maintain records of processing activities; the PDPA instead establishes record-keeping as a recommended, non-mandatory security and maintenance measure.
Joint Controller ArrangementsRed
No joint-controller concept equivalent to GDPR was identified; the PDPA instead uses broader 'government'/'non-government agency' categories without a controller/processor joint-liability framework.
Claims (1):
The PDPA defines the broader concepts of 'government' and 'non-government' agencies rather than the GDPR's distinct controller/processor concepts, and does not directly address processor contractual responsibilities.
Security MeasuresAmber
Article 18 PDPA requires dedicated personnel for security/maintenance measures; Competent Regulators may designate certain non-government agencies to establish security-maintenance plans, and the PDPC has draft regulations on personal-data-file security and management in a 60-day consultation.
Claims (2):
Competent Regulators may designate certain non-government agencies to establish plans to maintain the security of personal data files, and may conduct on-site inspections of certain non-government agencies where deemed necessary.
The PDPC announced draft regulations for personal data file security and management, with a 60-day consultation period for stakeholder feedback.
Breach NotificationAmber
Taiwan's 2025 PDPA amendments introduce mandatory breach reporting; entities must notify affected individuals and report breaches to authorities within 72 hours and take immediate mitigation steps.
Claims (1):
Taiwan's 2025 amendments to the PDPA introduce mandatory breach reporting, requiring entities to notify affected individuals and report breaches to authorities within 72 hours and take immediate steps to mitigate harm.
Retention And DisposalAmber
Competent Regulators may designate certain non-government agencies to establish plans for how to dispose of personal data files after ceasing business operations.
Claims (1):
Competent Regulators may designate certain non-government agencies to establish plans for the disposal of personal data files after they cease business operations.
Category narrative82 words
Historically, the PDPA imposed lighter controller/processor obligations than the GDPR: no defined DPIA, no DPO concept (only a requirement to assign 'dedicated personnel' for security under Art 18), and no general ROPA obligation. The 2023 amendments overhauled Article 48's fine structure for security-obligation violations, and the 2025-2026 amendment package (plus PDPC draft regulations) introduces mandatory breach reporting (notification to authorities and affected individuals, framed around a 72-hour benchmark), and draft rules on PDPO duties, competency and training, and on personal-data-file security management.
No new data since the standing brief. 1 periodic run re-emitted it unchanged.
Sources and claims (9)
UncertainOneTrust DataGuidance — The PDPA and Enforcement Rules do not formally define Data Protection Impact Assessments, but Article 12 of the Enforcement Rules outlines a mechanism for establishing risk assessments as a security and maintenance measure.observed
UncertainOneTrust DataGuidance — The PDPA and Enforcement Rules do not refer to Data Protection Officers; Article 18 of the PDPA instead requires assignment of dedicated personnel to implement security and maintenance measures preventing data from being stolen, altered, damaged, destroyed, or disclosed.observed
UncertainOneTrust DataGuidance — The PDPC announced draft regulations on the duties, competency requirements, and training of Personal Data Protection Officers and related personnel, with a 60-day consultation period.observed
UncertainOneTrust DataGuidance — Unlike the GDPR, the PDPA does not require controllers or processors to maintain records of processing activities; the PDPA instead establishes record-keeping as a recommended, non-mandatory security and maintenance measure.observed
UncertainOneTrust DataGuidance — The PDPA defines the broader concepts of 'government' and 'non-government' agencies rather than the GDPR's distinct controller/processor concepts, and does not directly address processor contractual responsibilities.observed
UncertainOneTrust DataGuidance — Competent Regulators may designate certain non-government agencies to establish plans to maintain the security of personal data files, and may conduct on-site inspections of certain non-government agencies where deemed necessary.observed
UncertainOneTrust DataGuidance — The PDPC announced draft regulations for personal data file security and management, with a 60-day consultation period for stakeholder feedback.observed
UncertainOneTrust DataGuidance — Taiwan's 2025 amendments to the PDPA introduce mandatory breach reporting, requiring entities to notify affected individuals and report breaches to authorities within 72 hours and take immediate steps to mitigate harm.observed
UncertainOneTrust DataGuidance — Competent Regulators may designate certain non-government agencies to establish plans for the disposal of personal data files after they cease business operations.observed
A transfer-restriction mechanism exists and is being tightened, but Taiwan lacks SCC/BCR-equivalent mechanisms and has no concluded adequacy arrangement in either direction.
Traffic-light rationale — AmberA transfer-restriction mechanism exists and is being tightened, but Taiwan lacks SCC/BCR-equivalent mechanisms and has no concluded adequacy arrangement in either direction.
Sub-modules (6)
Transfer MechanismsAmber
A competent authority may restrict or prohibit international transfers of personal data by non-government agencies where the transfer would prejudice material national interest, is restricted under treaty, or the destination lacks sound legal protection for personal data.
Claims (1):
A competent authority has discretion to issue an order restricting or prohibiting international transfer of personal data where the transfer would prejudice material national interest, is prohibited or restricted under a treaty or international agreement, or the destination country lacks sound legal protection for personal data.
Adequacy ReceivedRed
Taiwan's government previously indicated an intent to further amend the PDPA to meet GDPR standards and obtain an EU adequacy status decision; no concluded EU adequacy decision for Taiwan was identified in available sources.
Claims (1):
The Government of Taiwan has indicated a plan to further amend the PDPA to meet GDPR standards with a view to obtaining an EU adequacy status decision, though no such decision has been concluded.
Adequacy GrantedRed
No evidence was found of Taiwan formally granting adequacy-equivalent status to other jurisdictions under the PDPA's transfer-restriction framework.
Unlike the GDPR, the PDPA does not provide SCC or BCR mechanisms for cross-border transfers; instead it relies solely on a competent-authority restriction/prohibition power.
Claims (1):
The PDPA outlines instances where central authorities may restrict international data transfers but does not provide a range of enabling mechanisms such as adequacy decisions, standard contractual clauses, or binding corporate rules as found under the GDPR.
Transfer Impact AssessmentRed
No transfer impact assessment requirement analogous to post-Schrems II EU practice was identified under the PDPA.
Absence provenance: unavailable. Searched: Taiwan PDPA transfer impact assessment requirement.
Data LocalisationAmber
No general data-localisation mandate was identified; financial institutions face sector-specific outsourcing restrictions requiring prior regulatory approval or data-subject consent, which functions as a partial, sector-limited localisation control.
Claims (1):
Financial institutions in Taiwan are subject to strict requirements on outsourcing activities, including obtaining prior approval from their competent financial regulator or consent from data subjects, which functions as a sector-specific constraint on cross-border data flows.
Category narrative79 words
The PDPA does not provide a GDPR-style menu of transfer mechanisms (adequacy, SCCs, BCRs). Instead, a competent authority holds discretion to restrict or prohibit international transfers of personal data in defined circumstances (material national interest, treaty restriction, or inadequate protection in the destination country). Taiwan has previously signalled an intent to pursue an EU adequacy-style status but no adequacy decision (received or granted) was identified as concluded. The 2025 amendments are also reported to further restrict international data transfers.
Sources and claims (4)
UncertainOneTrust DataGuidance — A competent authority has discretion to issue an order restricting or prohibiting international transfer of personal data where the transfer would prejudice material national interest, is prohibited or restricted under a treaty or international agreement, or the destination country lacks sound legal protection for personal data.observed
UncertainOneTrust DataGuidance — The Government of Taiwan has indicated a plan to further amend the PDPA to meet GDPR standards with a view to obtaining an EU adequacy status decision, though no such decision has been concluded.observed
UncertainOneTrust DataGuidance — The PDPA outlines instances where central authorities may restrict international data transfers but does not provide a range of enabling mechanisms such as adequacy decisions, standard contractual clauses, or binding corporate rules as found under the GDPR.observed
UncertainOneTrust DataGuidance — Financial institutions in Taiwan are subject to strict requirements on outsourcing activities, including obtaining prior approval from their competent financial regulator or consent from data subjects, which functions as a sector-specific constraint on cross-border data flows.observed
Strong financial and health sector evidence; other sectoral sub-modules (telecoms, credit, education, insurance) carry no located overlay and default to red/absent.
Primary frameworkPDPA plus sector regulator rules (FSC, Ministry of Health and Welfare, Ministry of Transportation)
Supervisory authorityFinancial Supervisory Commission (FSC) / Ministry of Health and Welfare / other sector Competent Regulators
Traffic-light rationale — AmberStrong financial and health sector evidence; other sectoral sub-modules (telecoms, credit, education, insurance) carry no located overlay and default to red/absent.
Sub-modules (7)
Financial Sector OverlayAmber
Financial institutions face strict outsourcing requirements (prior regulatory approval or data-subject consent) and the FSC has recommended enhanced cybersecurity measures against AI-driven threats, including zero-trust architectures and continuous monitoring.
Claims (2):
Financial institutions in Taiwan are subject to strict requirements on their outsourcing activities, including obtaining prior approval from the competent authority of the financial institution or consent from the data subjects.
The Financial Supervisory Commission recommends financial institutions enhance cybersecurity measures to counter AI-driven threats, emphasizing zero-trust architectures, continuous monitoring, and senior management involvement.
Health Sector OverlayAmber
Health/genetic data receives enhanced PDPA protection, tested in constitutional litigation over National Health Insurance data reuse; the Ministry of Health and Welfare has separately proposed draft regulations on using National Health Insurance data for non-original purposes.
Claims (2):
The Taiwanese Supreme Administrative Court/Constitutional Court litigation confirms that National Health Insurance data may be released to third parties for research purposes under an enhanced-protection exception in PDPA Article 6(1)(4), subject to constitutional scrutiny.
Taiwan's Ministry of Health and Welfare announced draft regulations on the use of National Health Insurance data for non-original purposes, with a public comment period open into mid-2026.
Telecoms And EprivacyRed
No dedicated telecoms/ePrivacy overlay (cookie consent, e-communications privacy) distinct from the general PDPA was identified.
Absence provenance: unavailable. Searched: Taiwan telecoms ePrivacy law cookies communications privacy.
Employment DataAmber
Employers may collect job candidates' and employees' personal data based on the employment contract relationship, subject to PDPA notification obligations and Article 6 restrictions on sensitive categories.
Claims (1):
An employer may collect job candidates' and employees' personal data based on the potential or existing employment contract relationship, subject to PDPA notification obligations and Article 6 restrictions on sensitive personal data.
Credit And ScoringRed
No dedicated credit-scoring overlay was identified in available sources.
Absence provenance: unavailable. Searched: Taiwan credit scoring data protection rules.
EducationRed
No education-sector-specific data protection overlay was identified in available sources.
Absence provenance: unavailable. Searched: Taiwan education sector personal data protection rules.
InsuranceRed
No insurance-sector-specific data protection overlay was identified in available sources.
Absence provenance: unavailable. Searched: Taiwan insurance sector personal data protection rules.
Category narrative67 words
Financial and health sectors carry the clearest overlays on the general PDPA regime: financial institutions face outsourcing/approval constraints and heightened cybersecurity expectations from the Financial Supervisory Commission (FSC), while health data processing (e.g., National Health Insurance data reuse) has been the subject of direct constitutional litigation and fresh Ministry of Health and Welfare rulemaking. Telecoms/ePrivacy, credit-scoring, education, and insurance overlays were not clearly evidenced in available sources.
Sources and claims (5)
UncertainOneTrust DataGuidance — Financial institutions in Taiwan are subject to strict requirements on their outsourcing activities, including obtaining prior approval from the competent authority of the financial institution or consent from the data subjects.observed
UncertainOneTrust DataGuidance — The Financial Supervisory Commission recommends financial institutions enhance cybersecurity measures to counter AI-driven threats, emphasizing zero-trust architectures, continuous monitoring, and senior management involvement.observed
UncertainOneTrust DataGuidance — The Taiwanese Supreme Administrative Court/Constitutional Court litigation confirms that National Health Insurance data may be released to third parties for research purposes under an enhanced-protection exception in PDPA Article 6(1)(4), subject to constitutional scrutiny.observed
UncertainOneTrust DataGuidance — Taiwan's Ministry of Health and Welfare announced draft regulations on the use of National Health Insurance data for non-original purposes, with a public comment period open into mid-2026.observed
UncertainOneTrust DataGuidance — An employer may collect job candidates' and employees' personal data based on the potential or existing employment contract relationship, subject to PDPA notification obligations and Article 6 restrictions on sensitive personal data.observed
Only a generic marketing-restriction hook was evidenced; the adtech-specific sub-modules are largely unaddressed by Taiwanese law as currently evidenced.
Primary frameworkPDPA (general marketing-restriction provisions); no dedicated ePrivacy/adtech statute identified
Traffic-light rationale — RedOnly a generic marketing-restriction hook was evidenced; the adtech-specific sub-modules are largely unaddressed by Taiwanese law as currently evidenced.
Sub-modules (6)
Cookies And TrackersRed
No dedicated cookie/tracker consent regime distinct from general PDPA notice obligations was identified.
Absence provenance: unavailable. Searched: Taiwan cookie consent law tracker regulation.
Dark PatternsRed
No dark-pattern-specific prohibition was identified in Taiwanese data protection law.
Absence provenance: unavailable. Searched: Taiwan dark patterns consent law.
Opt Out SignalsRed
No recognition of technical opt-out signals (e.g., Global Privacy Control) was identified under the PDPA.
Absence provenance: unavailable. Searched: Taiwan Global Privacy Control opt-out signal recognition.
Clean Rooms And DcrRed
No clean-room or data-collaboration-room specific rules were identified.
Absence provenance: unavailable. Searched: Taiwan data clean room regulation.
Cross Context AdvertisingRed
No cross-context-advertising ('sale'/'share') concept analogous to CPRA was identified under the PDPA.
Absence provenance: unavailable. Searched: Taiwan cross-context advertising sale share personal data.
Direct MarketingAmber
The PDPA imposes marketing restrictions, with regulators empowered to order correction and impose administrative fines for failure to comply with notification requirements, marketing restrictions, information security, or data-subject-request obligations.
Claims (1):
Under the PDPA, an authority may order correction by a deadline and impose an administrative fine where a non-government agency fails to comply with notification requirements, marketing restrictions, information security requirements, or obligations to respond to data-subject requests.
Category narrative38 words
The PDPA contains a marketing-related restriction (allowing regulators to act against non-compliance with marketing restrictions), but no dedicated cookie/tracker consent regime, dark-pattern prohibition, opt-out-signal recognition, clean-room framework, or cross-context-advertising rule was identified as distinct from the general PDPA.
Sources and claims (1)
UncertainOneTrust DataGuidance — Under the PDPA, an authority may order correction by a deadline and impose an administrative fine where a non-government agency fails to comply with notification requirements, marketing restrictions, information security requirements, or obligations to respond to data-subject requests.observed
No binding ADM-transparency or biometric-specific regime yet, but the AI Basic Law and Legislative Yuan facial-recognition reports show active, rapidly evolving regulatory attention.
Primary frameworkPDPA Article 6 (genetic data); Basic Law on Artificial Intelligence (effective 2026-01-14)
Supervisory authorityPersonal Data Protection Commission (PDPC) Preparatory Office; Ministry of Digital Affairs (AI Basic Law central authority per legislative recommendation)
Traffic-light rationale — AmberNo binding ADM-transparency or biometric-specific regime yet, but the AI Basic Law and Legislative Yuan facial-recognition reports show active, rapidly evolving regulatory attention.
Sub-modules (6)
Profiling RestrictionsRed
No profiling-restriction provision analogous to GDPR Art 22 was identified under the PDPA.
No ADM transparency/explanation right equivalent to GDPR Art 22 was identified under the PDPA itself.
Absence provenance: unavailable. Searched: Taiwan automated decision-making transparency right explanation.
Ai Risk AssessmentsAmber
Taiwan's Basic Law on Artificial Intelligence, effective January 14, 2026, establishes a regulatory framework built on seven guiding principles, mandates high-risk AI warnings, and emphasises data governance and government support for AI development.
Claims (2):
Taiwan's Basic Law on Artificial Intelligence, effective January 14, 2026, promotes human-centric AI development and outlines seven guiding principles for ethical compliance.
Taiwan's Basic Law on Artificial Intelligence establishes a regulatory framework with seven principles, mandates high-risk AI warnings, and emphasizes data governance and government support.
Biometric RegimeAmber
No dedicated binding biometric-data regime was identified; the Legislative Yuan has issued a report highlighting privacy risks of facial recognition technology and proposing legal reforms to strengthen personal data protection.
Claims (1):
The Legislative Yuan's report highlights privacy risks of facial recognition technology and proposes legal reforms to strengthen personal data protection in Taiwan.
Genetic DataAmber
Genetic data is listed among the enhanced-protection sensitive categories under PDPA Article 6, alongside medical, healthcare, sex-life, physical-examination, and criminal-record data.
Claims (1):
PDPA Article 6 lists genetic data among the categories of personal data afforded enhanced protection, alongside medical records, healthcare, sex life, physical examination, and criminal records.
State Surveillance CarveoutsRed
No explicit, standalone national-security/surveillance carve-out provision distinct from the general international-transfer restriction (which references 'material national interest') was identified.
Taiwan lacks a direct GDPR Art 22 profiling/ADM-transparency analogue under the PDPA. Momentum is instead building through a separate instrument — the AI Basic Law, effective January 14, 2026 — which promotes human-centric AI development, mandates high-risk AI warnings, and emphasises data governance, alongside legislative-branch reports flagging facial-recognition privacy risks. Genetic data receives enhanced protection as a listed sensitive category under PDPA Article 6.
Sources and claims (4)
UncertainOneTrust DataGuidance — Taiwan's Basic Law on Artificial Intelligence, effective January 14, 2026, promotes human-centric AI development and outlines seven guiding principles for ethical compliance.observed
UncertainOneTrust DataGuidance — Taiwan's Basic Law on Artificial Intelligence establishes a regulatory framework with seven principles, mandates high-risk AI warnings, and emphasizes data governance and government support.observed
UncertainOneTrust DataGuidance — The Legislative Yuan's report highlights privacy risks of facial recognition technology and proposes legal reforms to strengthen personal data protection in Taiwan.observed
UncertainOneTrust DataGuidance — PDPA Article 6 lists genetic data among the categories of personal data afforded enhanced protection, alongside medical records, healthcare, sex life, physical examination, and criminal records.observed
No children/vulnerable-groups-specific provisions were located; this is a confirmed, explicit statutory gap rather than a search failure.
Traffic-light rationale — RedNo children/vulnerable-groups-specific provisions were located; this is a confirmed, explicit statutory gap rather than a search failure.
Sub-modules (5)
Age VerificationRed
No age-verification requirement for data processing was identified under the PDPA.
Claims (1):
Unlike the GDPR, the PDPA does not address the processing of children's data nor does it provide additional age-verification or minor-specific requirements.
Parental ConsentRed
No parental-consent mechanism analogous to GDPR Art 8 was identified under the PDPA.
Unlike the GDPR, the PDPA does not address the processing of children's data or provide additional requirements for minors, and no parental-consent mechanism, minor-profiling ban, education-setting-specific rule, or dependent-adult protection distinct from the general regime was identified.
Sources and claims (1)
UncertainOneTrust DataGuidance — Unlike the GDPR, the PDPA does not address the processing of children's data nor does it provide additional age-verification or minor-specific requirements.observed
Penalties and enforcement activity are real and escalating, but the central regulator (PDPC) is still transitioning to full operational status and redress mechanisms (collective/private right of action) are not clearly evidenced.
Supervisory authorityPersonal Data Protection Commission (PDPC) Preparatory Office / Ministry of Digital Affairs / sector Competent Regulators
Traffic-light rationale — AmberPenalties and enforcement activity are real and escalating, but the central regulator (PDPC) is still transitioning to full operational status and redress mechanisms (collective/private right of action) are not clearly evidenced.
Sub-modules (6)
Regulator Powers And PenaltiesAmber
Regulators have corrective and investigatory powers including fines and corrective orders, with the 2023 amendments raising the general administrative-fine ceiling from TWD 200,000 to TWD 2 million and introducing a TWD 150,000-15 million per-violation fine tier for uncorrected significant security failures.
Claims (3):
The 2023 amendments to the PDPA grant regulators authority to impose immediate administrative fines on private-sector entities for non-compliance, removing the requirement for a rectification period prior to the imposition of fines.
The 2023 amendments raise the maximum administrative fine for non-compliance with PDPA security obligations from TWD 200,000 to TWD 2 million.
Failure to rectify identified PDPA shortcomings within a regulator-specified timeframe now carries an administrative fine ranging from TWD 150,000 to TWD 15 million per violation, with immediate fines available where failures are of a significant nature affecting a large number of data subjects.
Enforcement Activity IndexAmber
Taiwan's Ministry of Digital Development fined Shopee TWD 200,000 in 2023 for PDPA violations following a personal-data leakage incident, evidencing active enforcement under the pre-PDPC sectoral model.
Claims (1):
Taiwan's Ministry of Digital Development fined Shopee Pte. Ltd. TWD 200,000 for violating PDPA Articles 27(1), 48(4), and 50 following a personal-information leakage incident.
Regulator Funding And CapacityAmber
The NDC confirmed the Executive Yuan will promptly establish a preparatory office for the Personal Data Protection Commission, indicating institutional capacity-building is underway but not yet complete.
Claims (1):
The National Development Council confirmed that the Executive Yuan will promptly establish a preparatory office for the Personal Data Protection Commission.
Collective Redress And Class ActionsRed
No collective-redress or class-action mechanism specific to PDPA enforcement was identified in available sources.
Absence provenance: unavailable. Searched: Taiwan PDPA class action collective redress data protection.
Private Right Of ActionRed
No explicit private-right-of-action provision specific to the PDPA (beyond general civil-liability principles) was clearly evidenced in available sources.
Absence provenance: unavailable. Searched: Taiwan PDPA private right of action civil suit data subject.
Recent Developments 180DAmber
Within the last 180 days: Taiwan's AI Basic Law took effect January 14, 2026; the PDPC Preparatory Office issued draft regulations on PDPO duties/competency/training and on personal-data-file security and management (each with 60-day consultation windows); the Ministry of Transportation published a draft amendment for the transport industry with a comment period ending March 10, 2026; and the Ministry of Health and Welfare opened a comment period (into mid-2026) on draft rules for reusing National Health Insurance data.
Claims (3):
Taiwan's Ministry of Transportation published a draft amendment to enhance personal data protection for the transport industry, with a 14-day comment period ending March 10, 2026.
Taiwan's Ministry of Health and Welfare announced draft regulations on the use of National Health Insurance data for non-original purposes, with a public comment period open until June 22, 2026.
Taiwan's AI Basic Law, effective January 14, 2026, promotes human-centric AI development and outlines seven guiding principles for ethical compliance.
Category narrative108 words
Regulators (historically the NDC-coordinated Competent Regulators, transitioning to the PDPC) hold corrective and investigatory powers, including fines, corrective orders, and on-site inspections. The 2023 amendments materially raised penalties — the general administrative-fine ceiling rose from TWD 200,000 to TWD 2 million, with fines for uncorrected significant security failures ranging from TWD 150,000 to TWD 15 million per violation — and removed the mandatory rectification-period precondition for certain fines. Enforcement activity includes the Ministry of Digital Development's TWD 200,000 fine against Shopee for a 2023 data breach. Institutional capacity is mid-build-out via the PDPC Preparatory Office. No collective-redress/class-action or explicit private-right-of-action mechanism specific to the PDPA was clearly evidenced.
No new data since the standing brief. 1 periodic run re-emitted it unchanged.
Sources and claims (8)
UncertainOneTrust DataGuidance — The 2023 amendments to the PDPA grant regulators authority to impose immediate administrative fines on private-sector entities for non-compliance, removing the requirement for a rectification period prior to the imposition of fines.observed
UncertainOneTrust DataGuidance — The 2023 amendments raise the maximum administrative fine for non-compliance with PDPA security obligations from TWD 200,000 to TWD 2 million.observed
UncertainOneTrust DataGuidance — Failure to rectify identified PDPA shortcomings within a regulator-specified timeframe now carries an administrative fine ranging from TWD 150,000 to TWD 15 million per violation, with immediate fines available where failures are of a significant nature affecting a large number of data subjects.observed
UncertainOneTrust DataGuidance — Taiwan's Ministry of Digital Development fined Shopee Pte. Ltd. TWD 200,000 for violating PDPA Articles 27(1), 48(4), and 50 following a personal-information leakage incident.observed
UncertainOneTrust DataGuidance — The National Development Council confirmed that the Executive Yuan will promptly establish a preparatory office for the Personal Data Protection Commission.observed
UncertainOneTrust DataGuidance — Taiwan's Ministry of Transportation published a draft amendment to enhance personal data protection for the transport industry, with a 14-day comment period ending March 10, 2026.observed
UncertainOneTrust DataGuidance — Taiwan's Ministry of Health and Welfare announced draft regulations on the use of National Health Insurance data for non-original purposes, with a public comment period open until June 22, 2026.observed
UncertainOneTrust DataGuidance — Taiwan's AI Basic Law, effective January 14, 2026, promotes human-centric AI development and outlines seven guiding principles for ethical compliance.observed
No categories match.
Filters combine as OR inside a group and AND across
groups.
Publication gate
No failing checks.
schema_valid
pass
min_t1_per_instrument_met
n/a — no subject in this jurisdiction
min_quoted_text_present
waived — floor 0%
translation_provenance_recorded
n/a — no subject in this jurisdiction
egress_verified
pass
source_tier_integrity_ok
pass
jurisdiction_source_floor_met
pass
tier_a_b_national_primary_pct
0.0
aggregator_only_jurisdiction_count
1
manual_override
Editorial metadata
Provenance only. Nothing below gates publication or affects the render.
Editorial metadata for Taiwan
Field
Value
trust.lawyer_review.status
never_reviewed
trust.lawyer_review.reviewer
no reviewer on record
trust.content_source
ai_generated
Provenance and declared absence
Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.
Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.
Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.
Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.
Suppressed by doctrine: derived risk score; derived_scores = {}.
Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.
Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 44 claim(s) (44 category placement(s)), 17 source(s) in the cumulative register.
All 10 modules populated. Coverage relies entirely on T3 commercial/professional legal-database sources (OneTrust DataGuidance) and reporting on primary instruments (PDPA text, Constitutional Court Judgment No. 13/2022, Ministry of Digital Development enforcement order); no direct T1 retrieval of the PDPA statutory text, official PDPC/NDC gazette notices, or a verified PDPC/NDC regulator URL was performed this run. regulator_and_framework, controller_processor_duties, cross_border_and_adequacy, sectoral_watch, algorithmic_biometric_and_surveillance_governance, and enforcement_and_redress have moderate-to-good claim density; data_subject_rights, adtech_and_commercial_privacy, and children_and_vulnerable_groups are thin/red due to genuine statutory gaps rather than search failure (explicitly documented via absent_field_provenance).
Unresolved questions (5):
Has the Personal Data Protection Commission (PDPC) formally commenced full independent-authority operation, or does it remain a Preparatory Office as of the run date?
What is the PDPC's official regulator URL once fully constituted (not yet confirmed against a primary gov.tw source in this run)?
Is there a concluded or pending EU (or other regime) adequacy determination for Taiwan, beyond the historical aspiration to seek one?
Does the 2025-2026 PDPA amendment package's mandatory breach-notification obligation have a confirmed in-force effective date, or does it remain enacted-not-yet-effective pending Cabinet designation (as occurred with the 2023 PDPC-establishment provisions)?
Are there PDPA-specific collective-redress or private-right-of-action mechanisms distinct from general Taiwanese civil procedure?