EnglishZH-TW
Taiwan flag

Taiwan

Taiwan Data Privacy Laws: PDPA in Force, PDPC Still Pending

Independently fact-checked against primary sources (last audited September 10, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of September 10, 2026. · 8 primary sources cited on this page. How we verify our legal content

Taiwan Data Privacy Laws: PDPA in Force, PDPC Still Pending

Frequently Asked Questions

What is Taiwan's main data protection law?

The Personal Data Protection Act (PDPA, 個人資料保護法) is Taiwan's primary data protection statute. The version in force is the text promulgated on May 31, 2023. A further amendment promulgated on November 11, 2025 has not commenced, because Article 56 leaves the date to the Executive Yuan and no order has issued. The act governs the collection, processing, and use of personal data by both government agencies and private organizations across all sectors of the Taiwanese economy.

What is the Personal Data Protection Commission (PDPC) in Taiwan?

The Personal Data Protection Commission (個人資料保護委員會, PDPC) is the independent data protection authority Taiwan is in the process of creating. It does not exist yet. Only its Preparatory Office, set up on December 5, 2023, is operating, and pdpc.gov.tw still identifies itself as 個人資料保護委員會籌備處. The Commission cannot be formally established until the Legislative Yuan passes a separate Organization Act, which had completed only committee first review as of October 17, 2025. Until then the PDPA is enforced by the central industry regulators and the special municipal and county or city governments.

Has Taiwan's Personal Data Protection Commission been established?

No. The Constitutional Court issued Judgment 111-Hsien-Pan-13 on August 12, 2022, giving three years to put an independent data protection mechanism in place. The Legislative Yuan added Article 1-1 to the PDPA in May 2023, naming the future Commission as competent authority. The Preparatory Office launched on December 5, 2023 and took over the Article 53 and 55 responsibilities from the National Development Council on January 1, 2024. The three-year deadline lapsed on August 12, 2025 with no Commission in existence. The amendments promulgated November 11, 2025 give the Commission its powers but do not create it; that needs the separate Organization Act, and the amendments themselves need an Executive Yuan commencement order that has not issued.

Does Taiwan require mandatory data breach notification?

To the data subject, yes. To a regulator, not yet. Article 12 as in force requires only that the agency notify the affected data subject, in an appropriate manner, after ascertaining the incident. There is no report to any authority and no fixed deadline. Failing to notify draws a rectification order, then NT$20,000 to NT$200,000 if the agency does not rectify in time. The November 2025 amendments would add a report to the PDPC for incidents within a scope still to be designated, along with response measures and record retention, but they have not commenced.

What are the penalties for violating Taiwan's PDPA?

Administrative fines in force today, all of which reach non-government agencies only: NT$50,000 to NT$500,000 under Article 47 for collecting or processing with no legal basis under Article 19, using data outside the collection purpose, mishandling special-category data, or breaching a cross-border restriction order; NT$20,000 to NT$2,000,000 under Article 48 for a security-measure failure, rising to NT$150,000 to NT$15,000,000 if it is not rectified, and NT$150,000 to NT$15,000,000 at first instance where the violation is material; NT$20,000 to NT$200,000 for obstructing an inspection; and under Article 50 the same amount again, personally, against the representative or manager unless they prove due care. Article 25 also allows a processing ban, deletion orders, confiscation, and publication of the violation. Criminal sanctions under Article 41 reach five years imprisonment and NT$1,000,000. Civil damages run NT$500 to NT$20,000 per incident per data subject, with an aggregate cap of NT$200,000,000 for one event that rises to the value of the interests involved where those exceed NT$200,000,000.

Are cross-border data transfers allowed from Taiwan?

Cross-border transfers are generally permitted. Taiwan does not require adequacy decisions or standard contractual clauses as prerequisites. Article 21 lets the competent authority restrict a transfer on four grounds: major national interests are involved; an international treaty or agreement so stipulates; the receiving country lacks sound data protection regulations such that data subjects' rights may be harmed; or the transfer is routed through a third country to circumvent the PDPA. That authority is the central industry regulator today. The November 2025 amendments would move it to the PDPC once they commence.

Who needs to appoint a Data Protection Officer in Taiwan?

Nobody yet. Article 18 as in force requires a government agency holding personal data files to designate a dedicated person for security maintenance, which is not the same role. The November 2025 amendments rewrite Article 18 to require every government agency to appoint a data protection officer (個人資料保護長), but they have not commenced. No DPO requirement applies to non-government agencies under either version, though later PDPC guidance may address this.

How does Taiwan's PDPA compare to the GDPR?

Both require a legal basis for processing, recognize sensitive data categories, grant rights of access, correction, and deletion, and require security measures. The differences matter. The PDPA's eight bases in Article 19 include neither legitimate interests nor vital interests, and its research basis is confined to academic institutions. Extraterritorial reach turns on the nationality of the data subject under Article 51 paragraph 2, not on establishment or targeting. No adequacy decision or standard contractual clauses are needed for transfers. No organization in Taiwan is required to appoint a data protection officer today. There is still no duty to report a breach to a regulator. And remedies use statutory per-incident damages rather than turnover-based fines.

What sectors have additional data protection requirements beyond the baseline PDPA?

Financial services (regulated by the Financial Supervisory Commission), healthcare (regulated by the Ministry of Health and Welfare under the Medical Care Act), and telecommunications (regulated by the National Communications Commission) all have sector-specific data protection rules that exceed the baseline PDPA obligations. Organizations in these sectors must comply with both the PDPA and their sector-specific requirements.

When do the November 2025 PDPA amendments take effect?

No date has been set. Article 56 leaves commencement to the Executive Yuan, and as of September 2026 no order has issued; the Ministry of Justice database records the act as not yet in force with the effective date undetermined. The Executive Yuan has said it will set the date in step with the Legislative Yuan's progress on the separate PDPC Organization Act, which has not passed. Watch the Preparatory Office for the commencement order and for the sub-regulations pre-announced in draft on January 22, 2026, including the security maintenance rules for Article 20-1 and the breach notification and reporting rules for Article 12.

Updates

The President of the Republic of China promulgated amendments to the Personal Data Protection Act, passed on third reading on October 17, 2025. The amendments would give the Personal Data Protection Commission its supervisory powers, add breach reporting under a revised Article 12, move the security duty from Article 27 into a new Article 20-1, require government agencies to appoint a data protection officer under Article 18, and transfer Article 21 cross-border transfer restriction powers to the Commission. They did not establish the Commission, which needs a separate Organization Act, and Article 56 leaves their commencement date to the Executive Yuan, which has set none.

The Legislative Yuan passed amendments adding Article 1-1 to the PDPA, formally designating the forthcoming Personal Data Protection Commission as the competent authority for the entire act. This was the direct legislative response to the August 2022 Constitutional Court judgment.

The PDPC Preparatory Office pre-announced its first package of draft sub-regulations under the amended PDPA: the draft Personal Data File Security Maintenance and Management Regulations, the draft Personal Data Incident Notification, Reporting and Response Regulations, the draft data protection officer duties and training regulations, and a draft amendment to the PDPA Enforcement Rules. Further drafts followed. On February 6, 2026 came the draft list of non-government agencies that stay under sector regulators and local governments under Article 51-1, plus the draft policy-promotion-meeting rules; on February 11, 2026 the draft inspection rules for non-government agencies; and on March 9, 2026 the draft audit rules for government agencies. None has been adopted, and the Executive Yuan has still not set an effective date for the November 2025 amendments.

The Preparatory Office of the PDPC assumed responsibility for interpreting the Personal Data Protection Act from the National Development Council, becoming the de facto PDPA policy authority ahead of the full commission's establishment.

The Executive Yuan established the Preparatory Office of the Personal Data Protection Commission (個人資料保護委員會籌備處), launching Taiwan's transition to an independent data protection authority. The Preparatory Office was tasked with drafting organizational regulations, formulating sub-regulations, and preparing for the full PDPC.

The Constitutional Court of the Republic of China issued Judgment 111-Hsien-Pan-13 in the National Health Insurance Research Database case. The court held that there was an insufficiency of independent supervisory instruments for data protection and gave a three-year grace period from the announcement to establish the relevant legal mechanisms, leaving their design to the legislature. That deadline, August 12, 2025, passed with no independent authority established.

Corrected the article's scope note and section heading to say the Personal Data Protection Commission has not been established and that its Preparatory Office issues the interpretations that exist today; noted that Article 1-1 of the 2023 amendment has itself never commenced; attributed the transition clause to the 2023 text rather than the November 2025 text, which moved it into Article 51-1; replaced an inaccurate list of grounds for refusing a data subject request with the actual Article 11 exceptions; stated that the Articles 47 to 50 administrative fines bind non-government agencies only; corrected the group-litigation citation to Article 34 and added its requirement of written assignment by twenty or more data subjects; and re-dated the 2026 sub-regulation changelog entry to the January 22, 2026 package it opens with.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Reviewed and approved by an editor

Sources and References

  1. Personal Data Protection Act (PDPA) full text — law.moj.gov.tw(law.moj.gov.tw).gov
  2. Preparatory Office of the Personal Data Protection Commission — official site(pdpc.gov.tw).gov
  3. Constitutional Court Judgment 111-Hsien-Pan-13 (2022) — Judicial Yuan(cons.judicial.gov.tw).gov
  4. Jones Day — Taiwan Passes Major Amendments to the PDPA (December 2025)(jonesday.com)
  5. K&L Gates — New Developments in the Taiwan PDPA (January 2026)(klgates.com)
  6. Personal Data Protection Act, promulgated text of 11 November 2025 with the MOJ status line recording that it is not yet in force, effective date undetermined(law.moj.gov.tw).gov
  7. Stellex Law Firm — President Promulgates PDPA Amendments (2025)(stellexlaw.com)
  8. Personal Data Protection Act, the 31 May 2023 text that is actually in force, MOJ historical versions(law.moj.gov.tw).gov
  9. Preparatory Office of the PDPC, release of 17 October 2025 on the Legislative Yuan third reading, stating the Commission cannot be established until the Organization Act passes(pdpc.gov.tw).gov
  10. ICLG — Data Protection Laws and Regulations 2025-2026 Taiwan(iclg.com)
  11. Chambers & Partners — Data Protection & Privacy 2026 Taiwan(practiceguides.chambers.com)
  12. DLA Piper — Taiwan Data Protection Laws of the World(dlapiperdataprotection.com)
  13. Taiwan News — PDPC Preparatory Office Launch December 2023(taiwannews.com.tw)
  14. Enforcement Rules of the PDPA — law.moj.gov.tw(law.moj.gov.tw).gov
  15. Preparatory Office of the PDPC - Duties and Mandate(pdpc.gov.tw).gov
Share: