Taiwan
Taiwan Data Privacy Laws: PDPA in Force, PDPC Still Pending
Independently fact-checked against primary sources (last audited September 10, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of September 10, 2026. · 8 primary sources cited on this page. How we verify our legal content

Taiwan Data Privacy Laws: PDPA in Force, PDPC Still Pending (2026 Guide)
Taiwan's Personal Data Protection Act (個人資料保護法, PDPA), enacted in its current form in 2010, governs the collection, processing, and use of personal data across all public and private sectors in the Republic of China (Taiwan). The text in force today is the version promulgated on May 31, 2023. One piece of that amendment is still dormant. Article 1-1, which names the PDPC as competent authority, has never commenced, because the Executive Yuan has never set its commencement date. That is why competence still sits with the sector regulators and the local governments.
A further set of amendments was promulgated on November 11, 2025, and it is not in force. Article 56 leaves the commencement date to the Executive Yuan, which has set none. The Ministry of Justice Laws and Regulations Database, current through August 28, 2026, records the act's status as "part or all of the provisions are not yet in force, last effective date: undetermined." Those dormant amendments are the ones that would add breach reporting to a regulator, move the security duty into a new Article 20-1, and create a data protection officer post in government agencies.
The Personal Data Protection Commission (個人資料保護委員會, PDPC) does not exist yet either. Only its Preparatory Office (個人資料保護委員會籌備處) has been set up. The Commission cannot be formally established until the Legislative Yuan passes a separate Organization Act, which had completed only committee first review as of the Preparatory Office's own statement of October 17, 2025.
Information last verified on 2026-09-09. This article has not yet been reviewed by a licensed lawyer admitted in the Republic of China (Taiwan).
Jurisdictional scope: This article covers data protection law in the Republic of China (Taiwan) under the Personal Data Protection Act (個人資料保護法) and the interpretations issued by the Preparatory Office of the Personal Data Protection Commission. It does not address the data protection regimes of the People's Republic of China, Hong Kong, or Macau. For recording and surveillance law in Taiwan, see Taiwan Recording Laws.
Quick Answer: How Does Taiwan's Data Privacy Law Work?
Taiwan protects personal data through the PDPA, which applies to government agencies and non-government agencies (businesses, organizations, and individuals) alike. The law requires a legal basis before personal data can be collected, processed, or used; grants data subjects rights of access, correction, and deletion; and imposes criminal, civil, and administrative penalties for violations. Enforcement today is decentralized. Each central industry regulator, and the special municipal or county and city government for businesses with no sector regulator, applies the PDPA within its own domain. The November 11, 2025 amendments would move much of that to a single independent authority, the PDPC, but they have not commenced and the Commission has not been established.
The Personal Data Protection Act: Structure and Scope
Legislative History
Taiwan's data protection framework began with the Computer-Processed Personal Data Protection Law (電腦處理個人資料保護法) of 1995, which covered only certain sectors. The Legislature replaced that statute with the current PDPA in 2010, extending coverage to all sectors and all forms of personal data processing, not just computer-processed data.
The PDPA has since been amended several times. The 2010 rewrite itself commenced on October 1, 2012 by Executive Yuan order, for every provision except Articles 6 and 54. The amendment promulgated December 30, 2015 revised the special-category-data rules and other provisions, and an Executive Yuan order brought it into force on March 15, 2016, which is when Article 6 finally commenced. A May 2023 amendment added Article 1-1, designating the yet-to-be-established PDPC as the competent authority for the entire act, and raised the Article 48 security-violation fines. Article 56 split their commencement. The revised Article 48 took effect on the date of promulgation, while Article 1-1's own date was left to the Executive Yuan, which has never set one. The Ministry of Justice history records commencement orders for the 2012 and 2016 amendments and none for Article 1-1, so that designation is enacted but dormant.
The November 11, 2025 amendments would deliver the institutional architecture: PDPC supervision, breach reporting, a renumbered security duty, and a data protection officer in public agencies. Article 56 leaves their commencement to the Executive Yuan, and no date has been set.
The PDPA applies to government agencies and to natural persons, juridical persons, and other organizations outside government (collectively "non-government agencies"). Article 51 paragraph 2 extends it beyond Taiwan's borders, to agencies outside ROC territory that collect, process, or use the personal data of ROC nationals.
Definition of Personal Data
The PDPA defines personal data broadly. Under the act, personal data is any information that can directly or indirectly identify a natural person, including:
- Names, dates of birth, and national identification card numbers
- Passport numbers and contact details
- Fingerprints, physical characteristics, and marital status
- Family information, educational records, and occupations
- Medical records, genetic data, sexual history, and health examination results
- Criminal records, financial status, and social activities
The PDPA separately recognizes a restricted category of sensitive personal data, which the act calls "special categories." These are: medical records, healthcare data, genetic data, sex life, physical examination results, and criminal records. The collection, processing, and use of special categories is generally prohibited except under specific statutory exemptions.
Territorial and Material Scope
The PDPA covers all personal data held and processed by covered entities, regardless of whether the processing is automated or manual.
The act does contain an express extraterritoriality clause. Article 51 paragraph 2 provides that the PDPA "also applies to the government and the non-government agencies outside the territory of the Republic of China (R.O.C) when they collect, process or use the personal data of R.O.C. nationals." That trigger is nationality-based, a different test from the establishment and targeting tests in GDPR Article 3. It has been in force since the 2010 rewrite and is not part of the pending amendments.
Article 51 paragraph 1 puts two things outside the act entirely: personal data collected, processed, or used by a natural person purely for personal or household activities, and audio-visual data collected in public places or at public activities that is not linked to other personal data.
Legal Bases for Collection and Processing
Government Agencies
Government agencies in Taiwan may collect, process, and use personal data when it is necessary for the performance of their statutory functions and when appropriate security measures are in place. Use must remain within the scope of the original collection purpose, unless a statutory exception permits secondary use.
Non-Government Agencies
Article 19 paragraph 1 lets a non-government agency collect or process personal data only for a specific purpose and only on one of eight bases:
- Expressly required by law.
- A contractual or quasi-contractual relationship with the data subject, and proper security measures have been adopted. Both halves are required. The security condition is part of the basis, not an optional extra.
- Data the data subject has manifestly made public, or that has been lawfully publicized.
- Statistics or academic research by an academic institution in pursuit of public interests, where the data as processed or as disclosed cannot identify a specific data subject.
- Consent of the data subject.
- Necessary for furthering public interests.
- Obtained from generally available sources, unless the data subject has an overriding interest in prohibiting the processing or use.
- The rights and interests of the data subject will not be infringed upon.
Two traps for controllers used to the GDPR. There is no "vital interests" basis for collection: protecting life, body, freedom, or property appears in Article 20 paragraph 1(3), and only as a ground for using data outside the original collection purpose. And there is no "legitimate interests" basis at all. Basis 4 is narrower than a general research exemption, because it is confined to academic institutions.
Under Article 19 paragraph 2, an agency relying on basis 7 must erase the data or stop processing or using it, on its own initiative or on request, once it knows or is told that the data subject has an overriding interest in prohibiting that use.
For sensitive personal data, the legal bases are narrower. Collection is generally prohibited unless a specific statutory exception applies, such as a legal obligation, a public interest requirement, or the written consent of the data subject.
Notice Requirements
Before or at the time of collecting personal data, the collecting entity must inform the data subject of: (1) the identity of the collecting entity; (2) the purpose of collection; (3) the categories of personal data to be collected; (4) the time period, territory, recipients, and methods of use; (5) the data subject's Article 3 rights and how to exercise them; and (6) the consequences of declining to provide the data. Recipients (對象) is the element privacy notices most often leave out.
Article 8 paragraph 2 waives the notice duty in six situations: where the law waives it; where collection is necessary for a government agency's statutory duties or a non-government agency's statutory obligation; where notice would prevent a government agency performing its statutory duties; where notice would harm public interests; where the data subject already knows the content of the notice; and where collection is for non-profit purposes with clearly no adverse effect on the data subject.
Where the data did not come from the data subject, Article 9 imposes a separate duty to disclose its source.
Data Subject Rights
The PDPA grants data subjects five core rights against both government agencies and non-government agencies:
| Right | Description |
|---|---|
| Right of inquiry and review | Data subjects may request confirmation of whether an entity holds their personal data and may review that data. |
| Right to a copy | Data subjects may request a copy of their personal data. |
| Right to supplement or correct | Data subjects may request that inaccurate personal data be corrected or supplemented. |
| Right to restrict or cease processing | Data subjects may request that collection, processing, or use of their data cease. |
| Right to deletion | Data subjects may request erasure of their personal data. |
Article 13 sets binding deadlines, and they bind government and non-government agencies alike. A request to inquire, review, or obtain a copy under Article 10 must be granted or refused within 15 days, extendable once by up to 15 more days with written notice of the reason. A request to supplement, correct, cease collection, processing or use, or erase under Article 11 must be decided within 30 days, extendable once by up to 30 more days with written notice of the reason. None of this is waiting on future PDPC regulations.
Article 10 lets an agency refuse an inquiry, review, or copy request only where national security, diplomatic or military secrets, overall economic interests, or other material national interests may be harmed; where a government agency may be prevented from performing its statutory duties; or where the vital interests of the data collector or a third party may be adversely affected.
Article 11 carries its own narrower exceptions. Where the accuracy of personal data is disputed, or where the specific purpose of collection has lapsed or the retention period has expired, the agency may keep processing or using the data if that is necessary for the performance of its official or business duties (因執行職務或業務所必須), or if the data subject has consented in writing. On the accuracy-dispute ground the written consent must also note the dispute on the record.

The PDPC: Taiwan's Planned Independent Data Protection Authority
The Constitutional Court Mandate (August 2022)
Taiwan's data protection story changed on August 12, 2022, when the Constitutional Court issued Judgment 111-Hsien-Pan-13 (Case on the National Health Insurance Research Database). The court found that existing mechanisms for personal data protection were insufficient to satisfy the constitutional right to informational self-determination under Article 22 of the Constitution of the Republic of China. Specifically, the court held that the absence of an independent supervisory authority meant that data controllers in the public sector faced no credibly independent oversight.
The Court gave a three-year grace period running from the August 12, 2022 announcement, so the deadline fell on August 12, 2025. It passed without an independent supervisory authority being established, and as of September 2026 it remains unmet.
In the words of the judgment itself: "Viewing comprehensively the Personal Data Protection Act (hereinafter 'PDPA') and other pertaining regulations, there is an insufficiency of independent supervisory instruments on data protection, which raises concerns about its constitutionality. The competent authority shall, within a grace period of three years from the announcement of this judgment, ensure relevant legal mechanisms be established to fulfill the right to protection of personal data under the Constitution." The Court added that establishing independent supervisory instruments is crucial, but that "how these instruments shall be established is up to the legislative branch."
The 2023 Legislative Response: Article 1-1
The Legislative Yuan responded on May 16, 2023, passing amendments to the PDPA that added Article 1-1. That provision designated the Personal Data Protection Commission as the competent authority for the entire PDPA, replacing the previous system under which individual sector ministries administered the act within their own domains. The National Development Council (國家發展委員會) had historically served as a coordinating body and default interpreter of the PDPA, but it held no enforcement primacy.
The Preparatory Office (December 5, 2023)
The Executive Yuan established the Preparatory Office of the Personal Data Protection Commission (個人資料保護委員會籌備處) on December 5, 2023. The Preparatory Office assumed responsibility for interpreting the PDPA from the National Development Council as of January 1, 2024. Its mandate during the preparatory phase included:
- Drafting organizational regulations for the full PDPC
- Formulating, interpreting, and coordinating amendments to the PDPA
- Developing subordinate regulations, including security management rules
- Conducting public consultations on data protection standards
The Preparatory Office was not the full PDPC. It lacked the independent enforcement authority that the Constitutional Court mandated. It served as the institutional foundation from which the full commission would emerge.
The November 11, 2025 Amendments: Promulgated, Not Commenced
The Legislative Yuan passed the amendments on third reading on October 17, 2025, and the President promulgated them on November 11, 2025. They did not establish the PDPC, and could not have. The Preparatory Office said so in its own release on the day of the third reading: the Commission's formal establishment still awaits passage of the Organization Act before it has a legal basis, and that draft had at the time completed only first review in the Legislative Yuan's Judiciary and Organic Laws and Statutes Committee. The Executive Yuan said it would set the PDPA commencement date in step with the Legislative Yuan's progress on that Act.
The dependency was written into the 2023 text. Article 1-1 paragraph 2 of the version in force provides that the powers of the central industry regulators, the local governments, and the bodies named in Articles 53 and 55 pass to the Commission from the date the Commission is established (自個人資料保護委員會成立之日起). The November 2025 amendment cut Article 1-1 back to a single sentence naming the Commission as competent authority, and moved the transition into new Article 51-1, which keeps the sector regulators in place for six years after the Commission is established.
Once the amendments commence and the Commission exists, it will hold the following principal powers:
- Issuing interpretations and binding guidance on the PDPA
- Conducting administrative inspections of non-government agencies, and coordinating inspections with sector-specific regulators and local authorities
- Retaining or copying personal data as evidence during inspections
- Imposing administrative penalties and corrective orders
- Coordinating with international data protection authorities
- Prescribing subordinate regulations, including security maintenance rules under Article 20-1
Article 56 leaves the effective date of the November 2025 amendments to the Executive Yuan, and no order has issued. The Ministry of Justice compilation, current through August 28, 2026, still records the act as not yet in force with the effective date undetermined, and the Legislative Yuan's own statute list carries no PDPC Organization Act.
The Preparatory Office pre-announced four drafts on January 22, 2026: the Personal Data File Security Maintenance and Management Regulations, the Personal Data Incident Notification, Reporting and Response Regulations, the data protection officer duties and training regulations, and an amendment to the PDPA Enforcement Rules. Further drafts followed on February 6, February 11, and March 9, 2026. None has been adopted, and the Preparatory Office has published nothing since March 9, 2026.
Who Enforces the PDPA Today
Enforcement is spread across more than two dozen sector-specific regulators and local governments. The Financial Supervisory Commission enforces the PDPA in financial services; the Ministry of Health and Welfare in healthcare; the National Communications Commission in telecommunications; and so on for every regulated industry. The special municipal and county or city governments enforce it against businesses outside any national-level sectoral regulator's jurisdiction.
That structure produces inconsistent interpretations and uneven enforcement, which is the problem the PDPC is meant to solve. It will not disappear the day the Commission opens. New Article 51-1 keeps the supervision and management matters under Article 22 paragraphs 1 and 3 to 7, Articles 23 to 26, and Articles 47 to 50, which is every administrative fine provision, with the central industry regulators and the local governments for an Executive-Yuan-announced scope of businesses, for six years from the date the Commission is established, reviewed every two years for reduction. Only businesses with no clear sector regulator move to direct PDPC supervision at once. The draft carve-out list was pre-announced on February 6, 2026.
Mandatory Data Breach Notification
Article 12 As It Stands Today
Article 12 in force imposes one duty and no more. Where an agency's violation of the act causes personal data to be stolen, leaked, altered, or otherwise infringed, the agency must notify the data subject in an appropriate manner after ascertaining the incident. There is no report to any authority, no threshold, and no fixed deadline. Failing to notify draws a rectification order first, and a fine of NT$20,000 to NT$200,000 only if the agency does not rectify in time (Article 48 paragraph 1).
What the Amendments Would Add
The November 2025 amendments rewrite Article 12. When they commence, a government or non-government agency that becomes aware that personal data it holds has been stolen, altered, damaged, lost, or leaked must:
- Notify affected data subjects; and
- Report to the PDPC where the incident falls within a notification scope to be designated by the competent authority in sub-regulations.
The amended text does not say in terms that notification is unconditioned on investigation. The point comes from a deletion. The current wording notifies the data subject 查明後, after ascertaining, and the amendment removes those characters, so notification would no longer be gated on completing an inquiry. The statute reaches that result by omission rather than by an express statement.
The amendments also require the agency to take immediate and effective response measures, to record the facts, the effects, and the measures taken, and to keep those records for the competent authority to inspect. The threshold, timeline, content, and method of reporting will come from a sub-regulation pre-announced in draft on January 22, 2026, which has not been adopted.
Penalties for Breach Notification Failures
Once the amendments commence, failing to report to the PDPC will carry an administrative fine of NT$20,000 to NT$200,000 plus a rectification order, with successive fines for each period that passes without rectification (Article 48 paragraph 2 of the amended text). Today no such duty exists, so no such fine can be imposed.
Security Obligations: Article 27 Today, Article 20-1 Later
Non-government agencies that hold personal data files already owe a security duty, and have since 2010. Article 27 paragraph 1, in force now, requires them to adopt appropriate security measures to prevent personal data being stolen, altered, damaged, lost, or leaked. A central industry regulator may also direct a non-government agency to draw up a security maintenance plan for its data files and a method for handling personal data after the business terminates.
The fines attached to that duty are not new either. Article 48 has carried NT$20,000 to NT$2,000,000 for a breach of Article 27 paragraph 1, with successive fines of NT$150,000 to NT$15,000,000 if the agency fails to rectify, since the Article 48 revision promulgated May 31, 2023, which Article 56 paragraph 2 brought into force on the day of promulgation. Where the violation is material (情節重大), the top band of NT$150,000 to NT$15,000,000 applies at first instance, together with a rectification order and successive fines. There is no cure period before that exposure attaches.
When the 2025 amendments commence, Article 27 is deleted and the same duty is re-enacted as Article 20-1, with the competent authority empowered to prescribe a common baseline security-maintenance regulation. That regulation was pre-announced in draft on January 22, 2026 and has not been adopted.
Data Protection Officers
Article 18 as in force requires a government agency holding personal data files to designate a dedicated person to handle security maintenance. That is a security role, not a data protection officer.
The 2025 amendments rewrite Article 18 to require every government agency to appoint a data protection officer (個人資料保護長), designated by the agency head from among suitable staff and given adequate personnel and resources, responsible for coordinating and supervising data protection across the agency and the agencies under it. That requirement is dormant until the amendments commence.
The DPO requirement will apply only to public-sector agencies. Non-government agencies are not required to designate a DPO under either the current or the amended PDPA, though sector-specific regulations or later PDPC guidance may address this.
Cross-Border Data Transfers
General Permissibility

Cross-border transfers of personal data are generally permitted under the PDPA. Taiwan does not require organizations to obtain an adequacy decision, implement standard contractual clauses, or use binding corporate rules as default conditions for international transfers, unlike the approach taken by the GDPR.
Government Restriction Authority (Article 21)
Article 21 empowers the competent authority to restrict a non-government agency's international transfers of personal data on four grounds, and the list reads the same in the in-force text and in the amended text:
- Major national interests are involved.
- An international treaty or agreement so stipulates.
- The receiving country lacks sound personal data protection regulations, such that the data subject's rights and interests may be harmed.
- The transfer is routed through a third country or territory to circumvent the PDPA.
The authority exercising that power today is the central industry regulator, not the PDPC.
The November 2025 amendments would move that power from the individual sector regulators to the PDPC. Until they commence and the Commission is established, transfer questions still go to the sector regulator.
Sector-Specific Restrictions
Certain industries already have sector-specific transfer restrictions in place. The Financial Supervisory Commission has rules governing transfers of financial personal data outside Taiwan. Healthcare providers must comply with Ministry of Health and Welfare rules on transfers of medical records. Organizations in regulated sectors should continue to comply with their sector-specific requirements pending PDPC consolidation guidance.
Penalties and Enforcement
Administrative Penalties
Articles 47 to 50 apply to non-government agencies only. Each of them opens 非公務機關. Government agencies owe the same substantive duties under Articles 8 to 13 and 18, but these administrative fines do not reach them. A government agency answers internally today, and once the 2025 amendments commence it answers through the new Chapter 3-1 supervision provisions in Articles 21-1 to 21-5, which carry annual reporting, audits, corrective orders, publication of the agency's name, and staff discipline rather than fines.
The table below summarizes the principal administrative penalties in force today. They are imposed by the central industry regulator (中央目的事業主管機關) or the special municipal or county and city government, not by the PDPC, which does not exist:
| Violation | Fine Range | Follow-on |
|---|---|---|
| No legal basis for collection or processing (Art. 19), use outside the collection purpose (Art. 20 para. 1), unlawful handling of special-category data (Art. 6 para. 1), or breach of a cross-border restriction order (Art. 21) | NT$50,000 to NT$500,000 | Rectification order, then a further fine for each period that passes unrectified (Art. 47) |
| Notice, data-subject-request, response-deadline, breach-notification, or marketing-opt-out failures (Arts. 8, 9, 10, 11, 12, 13 and Art. 20 paras. 2 and 3) | Rectification order first, then NT$20,000 to NT$200,000 if not rectified in time | Successive fines (Art. 48 para. 1) |
| Security-measure failure (Art. 27 para. 1) | NT$20,000 to NT$2,000,000 | Rectification order, then NT$150,000 to NT$15,000,000 for each period unrectified (Art. 48 para. 2) |
| Security-measure failure that is material (情節重大) | NT$150,000 to NT$15,000,000 at first instance | Rectification order and successive fines, with no cure period first (Art. 48 para. 3) |
| Evading, obstructing, or refusing an inspection (Art. 22 para. 4) | NT$20,000 to NT$200,000 | Art. 49 |
| Personal liability of the representative, manager, or other authorized representative | The same amount as the fine on the agency | Unless they prove they took due care to prevent the violation (Art. 50) |
Fines are not the only tool. Article 25 lets the enforcing authority prohibit further collection, processing, or use; order deletion of processed personal data files; confiscate or order the destruction of unlawfully collected data; and publish the violation together with the name of the agency and of its responsible person.
When the amendments commence, these provisions pass to the PDPC only for businesses with no clear sector regulator. For an Executive-Yuan-announced scope of businesses, Articles 47 to 50 stay with the sector regulators and local governments for six years from the Commission's establishment under new Article 51-1, reviewed every two years for reduction.
Criminal Penalties
The PDPA carries criminal sanctions for intentional violations. Article 41 provides that a person who intentionally violates the act's provisions on collection, processing, or use of personal data for the purpose of profit or with intent to harm another is subject to up to five years imprisonment and a criminal fine of up to NT$1,000,000.
Where an offender acts to profit unlawfully, both imprisonment and a fine may be imposed concurrently. The criminal provisions operate independently of administrative penalties; an organization can face both criminal prosecution of responsible individuals and administrative fines imposed on the entity.
Civil Liability
Data subjects who suffer harm from a PDPA violation may seek compensation in civil court. The PDPA provides statutory damages of NT$500 to NT$20,000 per incident per data subject, allowing recovery even where actual damages are difficult to quantify.
Aggregate compensation for a single causative event is capped at NT$200,000,000, but the cap is not absolute. Article 28 paragraph 4 provides that where the interests involved in the incident exceed NT$200,000,000, compensation runs up to the value of those interests. Where total damages exceed the cap, Article 28 paragraph 5 lifts the NT$500 per-person floor. Article 29 paragraph 2 applies both rules to non-government agencies.
A damages claim is extinguished two years after the claimant learns of the damage and of the person liable, or five years after the damage occurred, whichever comes first (Article 30).
Group litigation is available, but not through consumer protection groups. Article 32 restricts standing to an incorporated foundation with at least NT$10,000,000 in registered assets, or an incorporated charitable association with at least 100 members, where personal data protection is one of the purposes set out in its charter and it has been established for more than three years. It sues in its own name for twenty or more injured data subjects who assign it litigation authority in writing (Article 34 paragraph 1), and it must instruct an attorney as agent ad litem (Article 40). That twenty-assignor minimum is the practical gate on whether group litigation is available at all. Article 33 is the venue rule: a damages claim against a government agency goes to the district court where the agency sits, and one against a non-government agency to the district court for its principal office, principal place of business, or domicile.
Industry-Specific Requirements
Financial Services
The Financial Supervisory Commission (FSC) has issued extensive sector-specific data protection rules for banks, insurance companies, securities firms, and payment institutions. These rules often impose obligations beyond the baseline PDPA, including restrictions on data sharing, customer consent requirements at account opening, and cross-border transfer approvals. After the PDPC becomes fully operational, coordination between the FSC and the PDPC on enforcement will be a key area to monitor.
Healthcare
Medical providers, hospitals, and health insurance entities are subject to the Medical Care Act and related Ministry of Health and Welfare regulations, which impose specific safeguards for medical records and patient data. The PDPA's treatment of health examination results, medical records, and genetic data as sensitive personal data means that healthcare entities must satisfy heightened legal bases for processing.
Telecommunications
The National Communications Commission regulates telecommunications providers' handling of subscriber data, communications metadata, and location information. These requirements overlap with but are distinct from the baseline PDPA obligations.
Practical Compliance Considerations
Organizations doing business in Taiwan should prioritize the following in preparing for the PDPC's full operational launch:
-
Review legal bases for processing. Map each processing activity to one of the eight bases in Article 19 paragraph 1. A GDPR legitimate-interests assessment does not carry over, because the PDPA has no such basis; the nearest analogues are the public-interest basis and the no-infringement basis. Where you rely on the contractual basis, confirm proper security measures are in place, since that condition is part of the basis itself.
-
Establish breach detection and notification procedures. Today Article 12 requires notifying the affected data subject after ascertaining the incident, and nothing goes to a regulator. Build the process now for the amended standard, which drops the ascertainment gate and adds a report to the PDPC, response measures, and record retention, then embed the timelines once the notification-scope regulation is adopted.
-
Assess security-measures compliance under Article 27. The duty and its NT$2,000,000 fine exposure are live now, not pending. Compare current information security programs against the draft common-baseline regulation pre-announced January 22, 2026, which will carry the duty forward under Article 20-1.
-
Public agencies: plan for the DPO post. Article 18 as in force requires a designated security-maintenance person; the data protection officer post arrives with the amendments. Private organizations should monitor whether later PDPC guidance extends DPO obligations to non-government sectors.
-
Audit cross-border transfer arrangements. Article 21's four restriction grounds are already live, and your sector regulator is the body that exercises them. Once the PDPC takes that authority over, sector-specific transfer approvals may need to be revalidated.
-
Update privacy notices. Article 8 paragraph 1(4) requires the recipients of the data, not just the period, territory, and methods of use, and the Article 3 rights have to be set out with the method of exercising them. Do not name the PDPC as the supervisory authority yet; today that is the sector regulator or the local government.
Recent Developments (2022-2026)
This article is for general informational purposes only and does not constitute legal advice. Taiwan's Personal Data Protection Act is subject to continuing legislative and regulatory development; the effective date of the November 2025 amendments and their implementing regulations had not been finalized as of the date of this article. Organizations should consult a lawyer licensed to practice in the Republic of China (Taiwan) for advice specific to their circumstances. Information last verified on 2026-09-09.
Frequently Asked Questions
What is Taiwan's main data protection law?
The Personal Data Protection Act (PDPA, 個人資料保護法) is Taiwan's primary data protection statute. The version in force is the text promulgated on May 31, 2023. A further amendment promulgated on November 11, 2025 has not commenced, because Article 56 leaves the date to the Executive Yuan and no order has issued. The act governs the collection, processing, and use of personal data by both government agencies and private organizations across all sectors of the Taiwanese economy.
What is the Personal Data Protection Commission (PDPC) in Taiwan?
The Personal Data Protection Commission (個人資料保護委員會, PDPC) is the independent data protection authority Taiwan is in the process of creating. It does not exist yet. Only its Preparatory Office, set up on December 5, 2023, is operating, and pdpc.gov.tw still identifies itself as 個人資料保護委員會籌備處. The Commission cannot be formally established until the Legislative Yuan passes a separate Organization Act, which had completed only committee first review as of October 17, 2025. Until then the PDPA is enforced by the central industry regulators and the special municipal and county or city governments.
Has Taiwan's Personal Data Protection Commission been established?
No. The Constitutional Court issued Judgment 111-Hsien-Pan-13 on August 12, 2022, giving three years to put an independent data protection mechanism in place. The Legislative Yuan added Article 1-1 to the PDPA in May 2023, naming the future Commission as competent authority. The Preparatory Office launched on December 5, 2023 and took over the Article 53 and 55 responsibilities from the National Development Council on January 1, 2024. The three-year deadline lapsed on August 12, 2025 with no Commission in existence. The amendments promulgated November 11, 2025 give the Commission its powers but do not create it; that needs the separate Organization Act, and the amendments themselves need an Executive Yuan commencement order that has not issued.
Does Taiwan require mandatory data breach notification?
To the data subject, yes. To a regulator, not yet. Article 12 as in force requires only that the agency notify the affected data subject, in an appropriate manner, after ascertaining the incident. There is no report to any authority and no fixed deadline. Failing to notify draws a rectification order, then NT$20,000 to NT$200,000 if the agency does not rectify in time. The November 2025 amendments would add a report to the PDPC for incidents within a scope still to be designated, along with response measures and record retention, but they have not commenced.
What are the penalties for violating Taiwan's PDPA?
Administrative fines in force today, all of which reach non-government agencies only: NT$50,000 to NT$500,000 under Article 47 for collecting or processing with no legal basis under Article 19, using data outside the collection purpose, mishandling special-category data, or breaching a cross-border restriction order; NT$20,000 to NT$2,000,000 under Article 48 for a security-measure failure, rising to NT$150,000 to NT$15,000,000 if it is not rectified, and NT$150,000 to NT$15,000,000 at first instance where the violation is material; NT$20,000 to NT$200,000 for obstructing an inspection; and under Article 50 the same amount again, personally, against the representative or manager unless they prove due care. Article 25 also allows a processing ban, deletion orders, confiscation, and publication of the violation. Criminal sanctions under Article 41 reach five years imprisonment and NT$1,000,000. Civil damages run NT$500 to NT$20,000 per incident per data subject, with an aggregate cap of NT$200,000,000 for one event that rises to the value of the interests involved where those exceed NT$200,000,000.
Are cross-border data transfers allowed from Taiwan?
Cross-border transfers are generally permitted. Taiwan does not require adequacy decisions or standard contractual clauses as prerequisites. Article 21 lets the competent authority restrict a transfer on four grounds: major national interests are involved; an international treaty or agreement so stipulates; the receiving country lacks sound data protection regulations such that data subjects' rights may be harmed; or the transfer is routed through a third country to circumvent the PDPA. That authority is the central industry regulator today. The November 2025 amendments would move it to the PDPC once they commence.
Who needs to appoint a Data Protection Officer in Taiwan?
Nobody yet. Article 18 as in force requires a government agency holding personal data files to designate a dedicated person for security maintenance, which is not the same role. The November 2025 amendments rewrite Article 18 to require every government agency to appoint a data protection officer (個人資料保護長), but they have not commenced. No DPO requirement applies to non-government agencies under either version, though later PDPC guidance may address this.
How does Taiwan's PDPA compare to the GDPR?
Both require a legal basis for processing, recognize sensitive data categories, grant rights of access, correction, and deletion, and require security measures. The differences matter. The PDPA's eight bases in Article 19 include neither legitimate interests nor vital interests, and its research basis is confined to academic institutions. Extraterritorial reach turns on the nationality of the data subject under Article 51 paragraph 2, not on establishment or targeting. No adequacy decision or standard contractual clauses are needed for transfers. No organization in Taiwan is required to appoint a data protection officer today. There is still no duty to report a breach to a regulator. And remedies use statutory per-incident damages rather than turnover-based fines.
What sectors have additional data protection requirements beyond the baseline PDPA?
Financial services (regulated by the Financial Supervisory Commission), healthcare (regulated by the Ministry of Health and Welfare under the Medical Care Act), and telecommunications (regulated by the National Communications Commission) all have sector-specific data protection rules that exceed the baseline PDPA obligations. Organizations in these sectors must comply with both the PDPA and their sector-specific requirements.
When do the November 2025 PDPA amendments take effect?
No date has been set. Article 56 leaves commencement to the Executive Yuan, and as of September 2026 no order has issued; the Ministry of Justice database records the act as not yet in force with the effective date undetermined. The Executive Yuan has said it will set the date in step with the Legislative Yuan's progress on the separate PDPC Organization Act, which has not passed. Watch the Preparatory Office for the commencement order and for the sub-regulations pre-announced in draft on January 22, 2026, including the security maintenance rules for Article 20-1 and the breach notification and reporting rules for Article 12.
Updates
The President of the Republic of China promulgated amendments to the Personal Data Protection Act, passed on third reading on October 17, 2025. The amendments would give the Personal Data Protection Commission its supervisory powers, add breach reporting under a revised Article 12, move the security duty from Article 27 into a new Article 20-1, require government agencies to appoint a data protection officer under Article 18, and transfer Article 21 cross-border transfer restriction powers to the Commission. They did not establish the Commission, which needs a separate Organization Act, and Article 56 leaves their commencement date to the Executive Yuan, which has set none.
The Legislative Yuan passed amendments adding Article 1-1 to the PDPA, formally designating the forthcoming Personal Data Protection Commission as the competent authority for the entire act. This was the direct legislative response to the August 2022 Constitutional Court judgment.
The PDPC Preparatory Office pre-announced its first package of draft sub-regulations under the amended PDPA: the draft Personal Data File Security Maintenance and Management Regulations, the draft Personal Data Incident Notification, Reporting and Response Regulations, the draft data protection officer duties and training regulations, and a draft amendment to the PDPA Enforcement Rules. Further drafts followed. On February 6, 2026 came the draft list of non-government agencies that stay under sector regulators and local governments under Article 51-1, plus the draft policy-promotion-meeting rules; on February 11, 2026 the draft inspection rules for non-government agencies; and on March 9, 2026 the draft audit rules for government agencies. None has been adopted, and the Executive Yuan has still not set an effective date for the November 2025 amendments.
The Preparatory Office of the PDPC assumed responsibility for interpreting the Personal Data Protection Act from the National Development Council, becoming the de facto PDPA policy authority ahead of the full commission's establishment.
The Executive Yuan established the Preparatory Office of the Personal Data Protection Commission (個人資料保護委員會籌備處), launching Taiwan's transition to an independent data protection authority. The Preparatory Office was tasked with drafting organizational regulations, formulating sub-regulations, and preparing for the full PDPC.
The Constitutional Court of the Republic of China issued Judgment 111-Hsien-Pan-13 in the National Health Insurance Research Database case. The court held that there was an insufficiency of independent supervisory instruments for data protection and gave a three-year grace period from the announcement to establish the relevant legal mechanisms, leaving their design to the legislature. That deadline, August 12, 2025, passed with no independent authority established.
Corrected the article's scope note and section heading to say the Personal Data Protection Commission has not been established and that its Preparatory Office issues the interpretations that exist today; noted that Article 1-1 of the 2023 amendment has itself never commenced; attributed the transition clause to the 2023 text rather than the November 2025 text, which moved it into Article 51-1; replaced an inaccurate list of grounds for refusing a data subject request with the actual Article 11 exceptions; stated that the Articles 47 to 50 administrative fines bind non-government agencies only; corrected the group-litigation citation to Article 34 and added its requirement of written assignment by twenty or more data subjects; and re-dated the 2026 sub-regulation changelog entry to the January 22, 2026 package it opens with.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Reviewed and approved by an editor
Sources and References
- Personal Data Protection Act (PDPA) full text — law.moj.gov.tw(law.moj.gov.tw).gov
- Preparatory Office of the Personal Data Protection Commission — official site(pdpc.gov.tw).gov
- Constitutional Court Judgment 111-Hsien-Pan-13 (2022) — Judicial Yuan(cons.judicial.gov.tw).gov
- Jones Day — Taiwan Passes Major Amendments to the PDPA (December 2025)(jonesday.com)
- K&L Gates — New Developments in the Taiwan PDPA (January 2026)(klgates.com)
- Personal Data Protection Act, promulgated text of 11 November 2025 with the MOJ status line recording that it is not yet in force, effective date undetermined(law.moj.gov.tw).gov
- Stellex Law Firm — President Promulgates PDPA Amendments (2025)(stellexlaw.com)
- Personal Data Protection Act, the 31 May 2023 text that is actually in force, MOJ historical versions(law.moj.gov.tw).gov
- Preparatory Office of the PDPC, release of 17 October 2025 on the Legislative Yuan third reading, stating the Commission cannot be established until the Organization Act passes(pdpc.gov.tw).gov
- ICLG — Data Protection Laws and Regulations 2025-2026 Taiwan(iclg.com)
- Chambers & Partners — Data Protection & Privacy 2026 Taiwan(practiceguides.chambers.com)
- DLA Piper — Taiwan Data Protection Laws of the World(dlapiperdataprotection.com)
- Taiwan News — PDPC Preparatory Office Launch December 2023(taiwannews.com.tw)
- Enforcement Rules of the PDPA — law.moj.gov.tw(law.moj.gov.tw).gov
- Preparatory Office of the PDPC - Duties and Mandate(pdpc.gov.tw).gov