Taiwan
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked today.
The answer
Taiwan lets personal data leave the country freely unless the ministry that regulates your industry has issued an order stopping it. There is no single privacy regulator: each industry ministry polices its own sector, and each has written its own security and breach-reporting rules. A big reform that would create one national regulator was passed in November 2025 but has never been switched on.
Eight questions about Taiwan
The questions a team asks when they are deciding where to store their users' data. Every country on this site answers the same eight, in the same order.
Do Taiwan's rules apply to my company?
Yes. Taiwan's privacy law reaches a foreign company with no office and no staff in Taiwan. The law says plainly that it also applies to organisations outside Taiwan that collect, process or use the personal data of Taiwanese people. There is no revenue or headcount threshold to fall below, and the law does not require you to appoint a local representative.
Personal Data Protection Act (個人資料保護法), Article 51, paragraph 2, in the version currently in force: 公務機關及非公務機關,在中華民國領域外對中華民國人民個人資料蒐集、處理或利用者,亦適用本法. The official English rendering is: 'The PDPA also applies to the government and the non-government agencies outside the territory of the Republic of China (R.O.C) when they collect, process or use the personal data of R.O.C. nationals.' Criminal liability also travels: Article 43 applies the Act's two criminal offences to Taiwanese nationals who commit them outside Taiwan against other Taiwanese nationals. Practical reach is a separate question from legal reach — enforcement is carried out by whichever ministry supervises your industry, and a company with no Taiwanese entity is harder for them to reach.
Sources
- Official sourceLaws & Regulations Database of the Republic of China (Taiwan), Ministry of JusticePersonal Data Protection Act, Articles 43 and 51 — text currently in force (version of 31 May 2023)
law.moj.gov.tw
“公務機關及非公務機關,在中華民國領域外對中華民國人民個人資料蒐集、處理或利用者,亦適用本法。”
Link checked 18 August 2026
- Official sourceMinistry of JusticePersonal Data Protection Act — official English translation
law.moj.gov.tw
Link checked 18 August 2026
Can I store my users' data outside Taiwan?
In general, yes. Taiwan's privacy law does not ask you to sign anything or get anyone's permission before sending personal data abroad. Instead it gives each industry ministry the power to order that data in its sector may not go to a particular country. But four sectors have real walls, and in two of them the wall is absolute.
The general rule is Article 21 of the Personal Data Protection Act, in force since 2012: the central authority for your industry may restrict an international transfer where major national interests are involved, where a treaty says so, where the destination country lacks proper data protection law so that people could be harmed, or where the transfer routes through a third country to dodge the Act. Note what this is not: it is not a general ban, not a permission regime, and not a paperwork requirement. Sector overrides, each with its own rating: HEALTH (data must stay in the country) — where a hospital or clinic uses cloud services for electronic medical records, the storage location must be inside Taiwan unless the Ministry of Health and Welfare approves an exception. NATIONAL HEALTH INSURANCE DATA (data must stay in the country) — under the National Health Insurance Data Management Act, which commenced on 10 August 2026, only government bodies, public juridical persons, and medical institutions, academic research institutions and universities established inside Taiwan may apply for secondary use, and the data must be worked on in a secure environment at a place the authority designates. A foreign university or company simply cannot get it. BANKING AND CONSUMER FINANCE (a copy must stay in the country) — customer data for materially significant consumer-finance information systems should in principle be stored in Taiwan; if it is stored offshore, important customer data must be backed up and kept in Taiwan unless the Financial Supervisory Commission approves otherwise, and the offshore country's data protection law must not be weaker than Taiwan's. TELECOMS (data can leave with the right paperwork) — the National Communications Commission's binding rules require communications enterprises to check, before every international transfer, whether the Commission has restricted it, and to comply. INSURANCE, SECURITIES, EDUCATION, GAMING, MAPPING AND DEFENCE — no localisation rule found on a government source, checked 18 August 2026, confidence medium.
Sources
- Official sourceMinistry of JusticePersonal Data Protection Act, Article 21 — restriction of international transmission, text currently in force
law.moj.gov.tw
“非公務機關為國際傳輸個人資料,而有下列情形之一者,中央目的事業主管機關得限制之:一、涉及國家重大利益。二、國際條約或協定有特別規定。三、接受國對於個人資料之保護未有完善之法規,致有損當事人權益之虞。四、以迂迴方法向第三國(地區)傳輸個人資料規避本法。”
Link checked 18 August 2026
- Official sourceMinistry of Health and WelfareRegulations Governing the Production and Management of Electronic Medical Records by Medical Institutions, Article 8
law.moj.gov.tw
“前項雲端服務之資料儲存地點,應設置於我國境內。但因特殊情形,經中央主管機關核准者,不在此限。”
Link checked 18 August 2026
- Official sourceMinistry of Health and WelfareNational Health Insurance Data Management Act, Articles 8, 9 and 13
law.moj.gov.tw
“前條申請者,以政府機關(構)、行政法人,或於中華民國境內設立之醫療機構、學術研究機構、大學,及受政府機關委託之大學、法人、機構為限。”
Link checked 18 August 2026
- Official sourceFinancial Supervisory CommissionRegulations Governing Internal Operating Systems and Procedures for the Outsourcing of Financial Institution Operation, Articles 17 to 20
law.moj.gov.tw
“涉及重大性消費金融業務資訊系統之客戶資料儲存地以位於我國境內為原則。如位於境外,除經主管機關核准者外,客戶重要資料應在我國留存備份。”
Link checked 18 August 2026
What do I need in place before data leaves Taiwan?
Under the general law, nothing. No standard contract, no government approval, no adequacy finding, no consent form. The model is a blocklist run sector by sector: you may send data anywhere unless the ministry that supervises your industry has issued an order stopping it. Your real job is to find out which ministry supervises you and check whether it has issued one.
This is unusual and worth stating precisely. Taiwan has no equivalent of European standard contractual clauses, no binding corporate rules regime and no national list of approved destinations. Article 21 of the Personal Data Protection Act is a power to restrict, not a duty to obtain anything. Is the list populated? We can confirm the mechanism is live but could not open the text of any individual restriction order on a government website. Two regulators' own binding regulations tell the firms they supervise to check for such restrictions before transferring, which only makes sense if orders exist: the Financial Supervisory Commission requires firms to '進行個人資料國際傳輸前,檢視是否受本會限制並遵循之' and the National Communications Commission requires them to '進行個人資料國際傳輸前,檢視是否受本會相關法令限制並遵循之'. Treat the list as populated in telecoms and finance and verify with the regulator directly. Breaching such an order is not merely a fine — it is a criminal offence carrying up to five years in prison, and an administrative fine of NT$50,000 to NT$500,000 (roughly $1,600 to $16,000) with repeat fines until you fix it. When the November 2025 amendment finally commences, this power transfers from the industry ministries to the new national commission.
Sources
- Official sourceMinistry of JusticePersonal Data Protection Act, Articles 21, 41 and 47 — transfer restriction power, criminal offence and administrative fine
law.moj.gov.tw
“意圖為自己或第三人不法之利益或損害他人之利益,而違反……中央目的事業主管機關依第二十一條限制國際傳輸之命令或處分,足生損害於他人者,處五年以下有期徒刑,得併科新臺幣一百萬元以下罰金。”
Link checked 18 August 2026
- Official sourceNational Communications CommissionNCC Regulations for Non-government Agencies Designated to Maintain the Security of Personal Data Files, Article 5
law.moj.gov.tw
“進行個人資料國際傳輸前,檢視是否受本會相關法令限制並遵循之。”
Link checked 18 August 2026
- Official sourceFinancial Supervisory CommissionFSC Regulations for Non-government Agencies Designated to Maintain the Security of Personal Data Files, Article 5
law.moj.gov.tw
“進行個人資料國際傳輸前,檢視是否受本會限制並遵循之。”
Link checked 18 August 2026
Who enforces the rules in Taiwan, and what can they do?
There is no national privacy regulator in Taiwan today. A Personal Data Protection Commission is named in the law as the authority in charge, but that provision has never been switched on, the law creating the Commission is still only a bill, and what exists is a preparatory office that writes draft rules and cannot fine anyone. Enforcement is done instead by whichever ministry regulates your industry, plus city and county governments, and those bodies are genuinely active.
Three separate facts, each verified on a government site. First, Article 1-1 of the Personal Data Protection Act says the competent authority is the Personal Data Protection Commission. That article was added on 31 May 2023 with its commencement left to the Executive Yuan, and the official law database records the Act's status as 本法規部分或全部條文尚未生效,最後生效日期:未定 — some or all provisions are not yet effective, latest effective date undetermined. Second, the preparatory office's own press release of 17 October 2025 states that formal establishment of the Commission still requires the organic act to pass, that the draft had only cleared preliminary committee review, and that the Executive Yuan will designate the commencement date of the amended Act separately. Third, the only instruments in the national law database bearing the Commission's name are the preparatory office's provisional organisation rules of 23 September 2023. The preparatory office took over two narrow rule-making functions from the National Development Council on 1 January 2024 — publishing the table of specific purposes and data categories, and the Act's enforcement rules — and nothing more. Meanwhile the Financial Supervisory Commission, the National Communications Commission, the Ministry of Health and Welfare and the Ministry of Digital Affairs all supervise, inspect and fine within their sectors under Articles 22 to 25 and 47 to 50. The National Communications Commission has a standing scoring framework for setting fines on communications enterprises that breach the Act, referred to inside its own binding regulation — evidence that fining is routine rather than theoretical. The rating is therefore active in the sectors, dormant nationally.
Sources
- Official sourceMinistry of JusticePersonal Data Protection Act — legislative history and effectiveness status
law.moj.gov.tw
“生效狀態:※本法規部分或全部條文尚未生效,最後生效日期:未定”
Link checked 18 August 2026
- Official sourcePreparatory Office of the Personal Data Protection CommissionPress release, 17 October 2025 — Legislative Yuan passes the Personal Data Protection Act amendment
pdpc.gov.tw
“惟個資會之正式成立,仍須俟組織法立法通過後始有法源依據;目前組織法草案業經立法院「司法及法制委員會」初審完竣,尚待進一步完成立法程序。未來行政院將配合組織法在立法院之審議進度,並審酌相關行政準備作業時間後,另行指定個資法新法之施行日期。”
Link checked 18 August 2026
- Official sourcePreparatory Office of the Personal Data Protection CommissionPreparatory Office of the Personal Data Protection Commission — announcements, latest item dated 9 March 2026
pdpc.gov.tw
Link checked 18 August 2026
- Official sourceNational Communications CommissionNCC personal data security regulation, Article 4 — refers to the Commission's own scoring framework for setting fines under the Personal Data Protection Act
law.moj.gov.tw
Link checked 18 August 2026
How long do I have to keep the data?
Both directions apply, and the floors are set by other laws, not the privacy law. Accounting vouchers must be kept at least five years and account books and financial statements at least ten years. Medical records must be kept at least seven years, and for children until seven years after they turn eighteen; records from human trials must be kept forever. Going the other way, you must delete personal data once the purpose you collected it for has gone or the period you set has run out.
The ceiling is Article 11, paragraph 3 of the Personal Data Protection Act: when the specific purpose of collection no longer exists or the relevant time period expires, you must erase the data or stop processing and using it, either on your own initiative or when the person asks. The same paragraph resolves the conflict with the floors: the duty does not apply where keeping the data is necessary for performing an official or business duty, or where the person has agreed in writing. In practice a statutory keeping duty beats the deletion duty. People also have a standalone right to demand erasure under Article 3, and a right to demand you stop collecting, processing or using their data. One hard deletion mandate is now live: under Article 25 of the National Health Insurance Data Management Act, health insurance data obtained for secondary use before the Act commenced on 10 August 2026 must be destroyed, except where a government body holds it to perform statutory duties, and failing to destroy it attracts a fine of NT$2 million to NT$10 million (roughly $64,000 to $320,000).
Sources
- Official sourceMinistry of Economic AffairsBusiness Entity Accounting Act, Article 38 — five years for vouchers, ten years for books and financial statements
law.moj.gov.tw
“各項會計憑證,除應永久保存或有關未結會計事項者外,應於年度決算程序辦理終了後,至少保存五年。各項會計帳簿及財務報表,應於年度決算程序辦理終了後,至少保存十年。”
Link checked 18 August 2026
- Official sourceMinistry of Health and WelfareMedical Care Act, Article 70 — medical record retention
law.moj.gov.tw
“醫療機構之病歷,應指定適當場所及人員保管,並至少保存七年。但未成年者之病歷,至少應保存至其成年後七年;人體試驗之病歷,應永久保存。”
Link checked 18 August 2026
- Official sourceMinistry of JusticePersonal Data Protection Act, Articles 3 and 11 — erasure and stop-processing duties, text currently in force
law.moj.gov.tw
Link checked 18 August 2026
What happens if there is a breach?
Count at least three clocks, and the fastest is one hour. Telecoms companies and larger internet providers must tell the communications regulator within one hour of learning about a major personal data incident, then file a full report within seventy-two hours. Government bodies and designated critical infrastructure operators also have one hour, under the separate cyber security law. Financial firms get seventy-two hours. And under the privacy law itself you must tell the affected people once you have established the facts, with no fixed deadline attached.
Clock one — National Communications Commission regulation, Article 4: a major personal data incident must be reported to the Commission within one hour of becoming aware, with a follow-up report on the prescribed form within seventy-two hours; if the Commission or another agency told you about the incident first, the form is due within forty-eight hours. This covers telecommunications enterprises, providers of internet access with three thousand or more subscribers, and other communications enterprises the Commission names. Clock two — Regulations on the Notification and Response of Cyber Security Incidents, amended 5 January 2026, Articles 6 and 11: government agencies and designated non-government agencies must report to the platform the authority specifies within one hour of becoming aware. Damage control or recovery must be completed within seventy-two hours for level one and two incidents. Clock three — Financial Supervisory Commission regulation, Article 6: a major personal data incident must be reported to the Commission within seventy-two hours on the prescribed form. Clock four — Personal Data Protection Act, Article 12 as currently in force: you must notify the affected people in an appropriate way after ascertaining the facts. There is no hour count, and there is no duty to tell a regulator at all under the statute itself. That changes when the November 2025 amendment commences: a unified reporting duty to the new national commission is added, with the deadline to be set in a regulation that has not been made.
Sources
- Official sourceNational Communications CommissionNCC Regulations for Non-government Agencies Designated to Maintain the Security of Personal Data Files, Article 4 — one-hour reporting
law.moj.gov.tw
“非公務機關遇有重大個人資料事故者,應於知悉後一小時內通報本會,並於七十二小時內依附表格式,續行通報本會。但非公務機關接獲本會或有關機關通報發生事故時,應於四十八小時內,依附表格式通報本會。”
Link checked 18 August 2026
- Official sourceMinistry of Digital AffairsRegulations on the Notification and Response of Cyber Security Incidents and Drills, Articles 6, 8 and 11 (amended 5 January 2026)
law.moj.gov.tw
“公務機關知悉資通安全事件後,應於一小時內至主管機關指定之系統平臺通報。”
Link checked 18 August 2026
- Official sourceFinancial Supervisory CommissionFSC Regulations for Non-government Agencies Designated to Maintain the Security of Personal Data Files, Article 6 — seventy-two hour reporting
law.moj.gov.tw
“非公務機關遇有重大個人資料事故者,應依附件格式於七十二小時內通報本會。”
Link checked 18 August 2026
What trips people up in Taiwan?
Five things that will cost someone their weekend. First, the official English text of the privacy law on the government's own website includes provisions that are not law yet, including the one naming the national regulator. Second, breaking a cross-border transfer order is a crime, not a fine — up to five years in prison. Third, there is no single regulator to ask; your duties depend on which ministry supervises you. Fourth, a bank asked for Taiwanese customer data by a foreign financial regulator must get Taiwan's regulator's permission first. Fifth, if you are sued, you have to prove you were not at fault.
(1) The Ministry of Justice law database publishes the amended text, and the English translation shows Article 1-1 naming the Personal Data Protection Commission as competent authority. The database's own status line records that some or all provisions have not taken effect and the effective date is undetermined. A naive read of the English page will get the regulator, the breach-reporting duty, the data protection officer duty and the fine levels wrong. (2) Article 41 of the Act as in force: acting with intent to gain an unlawful benefit or harm another's interest, and breaching an industry authority's order restricting international transmission, so as to cause harm, is punishable by up to five years' imprisonment plus a fine up to NT$1 million (about $32,000). Under Article 45 that offence is prosecuted without needing a complaint from the victim, and Article 44 increases the sentence by up to half for public officials. (3) Compliance is fragmented: each central industry authority issues its own personal data file security maintenance regulation under Article 27, and each sets its own security plan requirements and its own breach clock — one hour in telecoms, seventy-two hours in finance. (4) Regulations Governing Internal Operating Systems and Procedures for the Outsourcing of Financial Institution Operation, Article 17, subparagraph 5: where the financial regulator of the country hosting your outsourced provider asks for Taiwanese customer information, the financial institution must first notify Taiwan's Financial Supervisory Commission and obtain its consent before handing anything over. (5) Article 29: a non-government agency is liable for damage unless it can prove the harm was not caused by its intent or negligence. Courts may award NT$500 to NT$20,000 per person per incident without proof of actual loss, and total awards for one incident are capped at NT$200 million, roughly $6.4 million. Registered foundations and public-interest associations can bring group claims.
Sources
- Official sourceMinistry of JusticePersonal Data Protection Act — status line showing provisions not yet effective
law.moj.gov.tw
“一百十四年十一月十一日修正第 1-1、12、18、21、22~26、41、47~49、52、53、55 條條文……施行日期,由行政院定之。”
Link checked 18 August 2026
- Official sourceMinistry of JusticePersonal Data Protection Act, Articles 27, 29, 41, 44 and 45 — text currently in force
law.moj.gov.tw
“非公務機關違反本法規定,致個人資料遭不法蒐集、處理、利用或其他侵害當事人權利者,負損害賠償責任。但能證明其無故意或過失者,不在此限。”
Link checked 18 August 2026
- Official sourceFinancial Supervisory CommissionRegulations Governing Internal Operating Systems and Procedures for the Outsourcing of Financial Institution Operation, Article 17
law.moj.gov.tw
“受委託機構所在地金融主管機關請求提供我國客戶資訊時,金融機構應先將事由通知我國主管機關並取得同意後始得提供。”
Link checked 18 August 2026
What is changing soon in Taiwan?
One thing has already landed and one is waiting on a switch. The National Health Insurance Data Management Act came into force on 10 August 2026, and it gives people a short window to opt their health records out of research use before silence counts as agreement. Separately, the big privacy reform passed in November 2025 is sitting on the shelf: the Cabinet can bring it into force whenever it likes, by a single order, with no consultation.
Landing now. The National Health Insurance Data Management Act was promulgated on 19 December 2025 and the Cabinet set it to start on 10 August 2026 by an order dated 6 August 2026. Article 16 requires the authority to stop accepting new secondary-use applications for thirty days from commencement, and provides that a person who does not ask for their data to be stopped within that window is treated as having agreed — so the window closes around 9 September 2026. Opting out later is still allowed but only works going forward. Health insurance data already released for secondary use before 10 August 2026 must be destroyed, unless a government body holds it for statutory duties. Dormant switches, in order of importance. One: the Executive Yuan can set the commencement date of the November 2025 privacy amendment at any time by order. That single order would create a national regulator with power to receive breach reports, set a common baseline security regulation, restrict international transfers, and audit and inspect both government and private bodies. Two: the organic act creating the Personal Data Protection Commission is still only a bill. It had cleared preliminary committee review by October 2025, and the regulator's own website has published nothing since 9 March 2026. Three: any central industry authority can restrict cross-border transfers by order under Article 21 at any time, with no consultation and no appeal to a national regulator. Four: when the Commission is finally established, a six-year transition begins during which existing industry regulators keep supervising the businesses they already supervise, with the list cut back every two years. Also on the shelf: six draft regulations pre-announced between January and March 2026, covering the enforcement rules, the data protection officer competency rules, audit rules for government bodies, inspection rules for private bodies, and the list of businesses that stay with their industry regulator.
Sources
- Official sourceMinistry of Health and WelfareNational Health Insurance Data Management Act — Executive Yuan order of 6 August 2026 setting commencement on 10 August 2026
law.moj.gov.tw
“中華民國一百十五年八月六日行政院院臺衛字第 1151018599 號令發布定自一百十五年八月十日施行”
Link checked 18 August 2026
- Official sourceNational Health Insurance AdministrationApplying to stop use of your health insurance data beyond the original purpose (opt-out mechanism)
nhi.gov.tw
Link checked 18 August 2026
- Official sourcePreparatory Office of the Personal Data Protection CommissionPress release, 17 October 2025 — commencement of the amended Act to be designated separately by the Executive Yuan
pdpc.gov.tw
Link checked 18 August 2026
The rules, layer by layer
Rules stack in layers. Knowing which layer a rule sits in tells you whether your industry, your state, or a contract can override it.
Layer 1
National rules
Added by this country on top of any bloc rules.
3 rules here
Layer 2
Industry rules
Made by an industry regulator. These usually beat the general position.
6 rules here
Read the stack from the top down. Anything lower normally wins: an industry rule beats the national position, and the national position sits on top of the bloc rules.
National rules3 rules
個人資料保護法 (Personal Data Protection Act)
Act of parliament · Promulgated 11 August 1995 as the Computer-Processed Personal Data Protection Act; renamed and rewritten 26 May 2010; current operative text as amended 31 May 2023
Taiwan's general privacy law. It applies to organisations outside Taiwan that handle Taiwanese people's data, requires no paperwork to send data abroad, and leaves supervision to whichever ministry regulates your industry. Its most striking feature is criminal liability: several breaches carry prison sentences, not just fines. Beware that the published text includes provisions that have never commenced.
Enforced by Personal Data Protection Commission (Preparatory Office) — not yet operational
Transfer model: Blocklist · Accepted routes: Nothing required
What it makes you do
- Tell people what you doMust state the collector's name, purpose, categories, and the period, territory, recipients and methods of use.
- Get consent
- Let people see their data — within 360 hoursDecide within 15 days, extendable by 15 more.
- Let people correct their data — within 720 hoursDecide within 30 days, extendable by 30 more.
- Let people delete their data
- Let people objectMarketing must stop on request, and the first marketing contact must offer a free way to refuse.
- Secure the dataArticle 27: adopt appropriate security measures. Your industry authority may order you to write a formal security plan and a plan for handling data after you stop trading.
- Tell affected peopleNotify affected individuals in an appropriate way after ascertaining the facts. No fixed deadline in the statute.
- Delete data after a period
- Written vendor contractA party engaged to process data is treated as the engaging organisation, which must supervise it properly.
What it costs if you get it wrong
- Criminal liability: 5 years' imprisonment plus a fine up to NT$1,000,000 — about $32 thousandUnlawful collection, processing or use of sensitive or ordinary personal data, or breach of an international transfer restriction order, with intent to gain or harm
- Fixed maximum fine: NT$15,000,000 — about $480 thousandSerious failure of security measures or failure to adopt a required security plan, repeat fines until fixed
- Fixed maximum fine: NT$500,000 — about $16 thousandBreach of an international transfer restriction order, or unlawful collection or use, repeat fines until fixed
- Fixed maximum fine: NT$200,000 — about $6 thousandFailure to give notice, answer access requests, correct data or notify a breach
- Order to stopRegulator may ban collection, processing or use, order deletion of files, confiscate or destroy data, and publish the violation and the responsible person's name
- Claims by individuals: NT$500 to NT$20,000 per person per incident, capped at NT$200,000,000 per incident — about $6 millionDamage claim; the organisation must prove it was not at fault
Sources
- Official sourceLaws & Regulations Database of the Republic of China (Taiwan), Ministry of JusticePersonal Data Protection Act — full text of the version currently in force
law.moj.gov.tw
Link checked 18 August 2026
- Official sourceMinistry of JusticePersonal Data Protection Act — legislative history and commencement record
law.moj.gov.tw
Link checked 18 August 2026
個人資料保護法部分條文修正 (Amendment to certain articles of the Personal Data Protection Act)
Act of parliament · Passed by the Legislative Yuan 17 October 2025; promulgated by Presidential Order 華總一經字第11400114521號 on 11 November 2025; commencement date to be set by the Executive Yuan
A large reform package, passed and signed, that would give Taiwan a real national privacy regulator with breach reporting, audit and inspection powers. It has no legal effect until the Cabinet issues an order setting the start date, and as of 18 August 2026 no such order has been issued. Do not plan around this text as if it binds you today.
Enforced by Personal Data Protection Commission (Preparatory Office) — not yet operational
Transfer model: Blocklist · Accepted routes: Nothing required
What it makes you do
- Report breaches to the regulatorNew duty to report incidents to the national commission. Content, method and deadline to be set in a regulation that has not been made. Not yet in force.
- Appoint a data protection officerGovernment agencies must appoint a personal data protection officer. Not yet in force.
- Secure the dataNew Article 20-1 lets the commission issue a single common baseline security regulation for private bodies. Not yet in force.
- Independent auditAnnual implementation reports and audits for government agencies, plus commission audits and on-site inspections. Not yet in force.
- Put a transfer safeguard in placeThe power to restrict international transfers moves from industry ministries to the national commission. Not yet in force.
What it costs if you get it wrong
- Fixed maximum fine: NT$15,000,000 — about $480 thousandSerious breach of security duties, once commenced
- Fixed maximum fine: NT$200,000 — about $6 thousandFailure to report an incident, once commenced
Sources
- Official sourceMinistry of JusticePersonal Data Protection Act — amendment history showing commencement left to the Executive Yuan and effectiveness undetermined
law.moj.gov.tw
“生效狀態:※本法規部分或全部條文尚未生效,最後生效日期:未定”
Link checked 18 August 2026
- Official sourcePreparatory Office of the Personal Data Protection CommissionPress release, 17 October 2025 — what the amendment does and why it cannot start yet
pdpc.gov.tw
Link checked 18 August 2026
個人資料保護委員會組織法草案 (Draft Organic Act of the Personal Data Protection Commission)
Draft law · Approved by the Executive Yuan at its 3945th meeting on 27 March 2025 and sent to the Legislative Yuan; preliminary review completed by the Judiciary and Organic Laws Committee as at 17 October 2025
The law that would actually create Taiwan's national privacy regulator is still a bill. Without it the Commission has no legal basis to exist, which is why the Commission named in the privacy law has never been set up and why the 2025 privacy amendment has not been switched on. This is a proposal, not binding law.
Enforced by Personal Data Protection Commission (Preparatory Office) — not yet operational
Sources
- Official sourcePreparatory Office of the Personal Data Protection CommissionPress release, 27 March 2025 — Executive Yuan approves the draft Organic Act of the Personal Data Protection Commission
pdpc.gov.tw
Link checked 18 August 2026
- Official sourcePreparatory Office of the Personal Data Protection CommissionPress release, 17 October 2025 — organic act still awaiting further legislative steps
pdpc.gov.tw
“目前組織法草案業經立法院「司法及法制委員會」初審完竣,尚待進一步完成立法程序。”
Link checked 18 August 2026
Industry rules6 rules
醫療機構電子病歷製作及管理辦法 (Regulations Governing the Production and Management of Electronic Medical Records by Medical Institutions)
Directly binding regulation · Article 8, made under Article 69 of the Medical Care Act; amended 18 July 2022 · Health and social care
Where a hospital or clinic uses cloud services for electronic medical records, the data must be stored inside Taiwan. The only way out is a case-by-case approval from the health ministry for special circumstances. The cloud provider must also be certified against a security standard the ministry recognises.
Enforced by Ministry of Health and Welfare
Transfer model: Approval each time · Accepted routes: Government sign-off needed
What it makes you do
- Keep the data in the countryThe storage location for cloud services used for electronic medical records must be inside Taiwan, unless the Ministry of Health and Welfare approves an exception in special circumstances.
- Hold a security certificateThe cloud provider must hold certification against an information security standard recognised by the Ministry.
- Written vendor contractThe contract must cover supervision, audit access for the authority, immediate notice of security failures, a ban on sub-contracting without the hospital's consent, and a mechanism to move the data back.
Sources
- Official sourceMinistry of Health and WelfareRegulations Governing the Production and Management of Electronic Medical Records by Medical Institutions, Article 8
law.moj.gov.tw
“前項雲端服務之資料儲存地點,應設置於我國境內。但因特殊情形,經中央主管機關核准者,不在此限。”
Link checked 18 August 2026
全民健康保險資料管理條例 (National Health Insurance Data Management Act)
Act of parliament · Promulgated by Presidential Order 華總一義字第11400129981號 on 19 December 2025; brought into force by Executive Yuan Order 院臺衛字第1151018599號 of 6 August 2026 · Health and social care
Taiwan's answer to a 2022 Constitutional Court ruling that the health insurance database had no proper legal basis and no opt-out. It creates one: research use is limited to Taiwanese institutions, must happen inside a designated secure environment, cannot be commercial, and every insured person can block their own records. It started on 10 August 2026 and the first opt-out window is short.
Enforced by National Health Insurance Administration
Transfer model: Not allowed
What it makes you do
- Keep the data in the countryOnly government bodies, public juridical persons, and medical institutions, academic research institutions and universities established inside Taiwan may apply. Foreign institutions are excluded outright.
- Register or notifyEvery secondary use needs an approved plan, reviewed by a panel on which outside experts, civil society and lay members must be at least half.
- Let people object — from 10 August 2026People may ask for their health insurance data to be blocked from secondary use. The block is registered within 30 days and works only going forward.
- Delete data after a periodHealth insurance data obtained for secondary use before 10 August 2026 must be destroyed, except where a government body holds it to perform statutory duties.
- Secure the dataAnalysis must be carried out in the manner, at the time and at the place the authority designates, inside a secure environment, with items banned from being taken out.
What it costs if you get it wrong
- Fixed maximum fine: NT$10,000,000 — about $320 thousandSecondary use of health insurance data without approval, plus a one-year ban on applying and destruction of the data
- Fixed maximum fine: NT$2,500,000 — about $80 thousandDeparting from the approved plan, taking banned items out of the secure environment, or producing identifiable results
- Criminal liability: 1 to 7 years' imprisonment plus a fine up to NT$10,000,000, rising to 3 to 10 years and NT$50,000,000 where national security is targeted — about $2 millionAttacking or intruding into the health insurance database or its core information systems
Sources
- Official sourceMinistry of Health and WelfareNational Health Insurance Data Management Act — full text
law.moj.gov.tw
“本條例施行起三十日內,主管機關或保險人應停止受理依第十一條第一項申請特定目的外利用健保資料。當事人未於前項期間內請求停止利用,視為同意其健保資料為特定目的外利用。”
Link checked 18 August 2026
- Official sourceMinistry of Health and WelfareNational Health Insurance Data Management Act — commencement order of 6 August 2026
law.moj.gov.tw
Link checked 18 August 2026
- Official sourceConstitutional Court of TaiwanTCC Judgment 111-Hsien-Pan-13 (111年憲判字第13號), 12 August 2022 — the Health Insurance Database Case
cons.judicial.gov.tw
“相關機關應自本判決宣示之日起3年內制定或修正相關法律,明定請求停止及例外不許停止之主體、事由、程序、效果等事項。逾期未制定或修正相關法律者,當事人得請求停止上開目的外利用。”
Link checked 18 August 2026
金融機構作業委託他人處理內部作業制度及程序辦法 (Regulations Governing Internal Operating Systems and Procedures for the Outsourcing of Financial Institution Operation)
Directly binding regulation · Articles 17 to 20, made under Article 45-1(3) of the Banking Act and Article 21(4) of the Credit Cooperatives Act; amended 13 April 2026 · Banking
Taiwan's banks and credit card issuers can process customer data offshore, but not freely. Anything material in consumer finance needs the financial regulator's advance approval, the data should in principle stay in Taiwan, and if it goes abroad a Taiwanese backup of important customer data is compulsory unless the regulator says otherwise.
Enforced by Financial Supervisory Commission
Transfer model: Approval each time · Accepted routes: Government sign-off needed, Security review needed
What it makes you do
- Keep the data in the countryCustomer data for materially significant consumer-finance information systems should in principle be stored in Taiwan. If stored offshore, important customer data must be backed up and retained in Taiwan unless the regulator approves otherwise.
- Register or notifyOffshoring a materially significant consumer-finance information system needs prior written approval from the Financial Supervisory Commission, with a board resolution, a legality analysis and a full outsourcing plan.
- Do not hand data to foreign authorities on demandIf the financial regulator where your outsourced provider sits asks for Taiwanese customer information, you must notify Taiwan's regulator and get its consent first.
- Put a transfer safeguard in placeThe destination country's data protection law must not be weaker than Taiwan's requirements.
- Independent auditAt least one general and one special audit each year, with a cross-border outsourcing audit report to the board within four months of year end.
- Secure the dataCustomer data sent to or stored with a cloud provider must be encrypted or tokenised, with a proper key management scheme, and the provider must not be able to access it.
What it costs if you get it wrong
- Order to stopThe regulator may require the institution to terminate the outsourcing contract, fix problems within a deadline, or suspend the arrangement
Sources
- Official sourceFinancial Supervisory CommissionRegulations Governing Internal Operating Systems and Procedures for the Outsourcing of Financial Institution Operation, Articles 17 to 20 (amended 13 April 2026)
law.moj.gov.tw
“金融機構辦理作業委外,涉及重大性消費金融業務資訊系統委託至境外處理,應檢具下列書件向主管機關申請核准。”
Link checked 18 August 2026
國家通訊傳播委員會指定非公務機關個人資料檔案安全維護辦法 (NCC Regulations for Non-government Agencies Designated to Maintain the Security of Personal Data Files)
Directly binding regulation · Made under Article 27(3) of the Personal Data Protection Act; amended 1 July 2022 · Telecoms
Taiwan's telecoms rulebook carries the country's fastest privacy clock: one hour to tell the communications regulator about a major personal data incident. It also applies to internet access providers with three thousand or more subscribers, and it requires operators to check for cross-border transfer restrictions before sending data abroad.
Enforced by National Communications Commission
Transfer model: Blocklist · Accepted routes: Nothing required
What it makes you do
- Report breaches to the regulator — within 1 hourOne hour from becoming aware, then a full report on the prescribed form within 72 hours. If the regulator told you first, the form is due within 48 hours.
- Put a transfer safeguard in placeBefore any international transfer of personal data, check whether the Commission's rules restrict it and comply.
- Secure the dataA written security maintenance plan and a plan for handling data after the business ends, signed by the person in charge.
- Independent audit — applies at: 5,000 or more subscribers whose data is handledThe plan must include a domestic or international personal data security audit scheme and an implementation plan.
What it costs if you get it wrong
- Fixed maximum fine: NT$15,000,000 — about $480 thousandSerious failure to maintain personal data security, under Article 48 of the Personal Data Protection Act
Sources
- Official sourceNational Communications CommissionNCC Regulations for Non-government Agencies Designated to Maintain the Security of Personal Data Files, Articles 2 to 5
law.moj.gov.tw
“非公務機關遇有重大個人資料事故者,應於知悉後一小時內通報本會,並於七十二小時內依附表格式,續行通報本會。”
Link checked 18 August 2026
金融監督管理委員會指定非公務機關個人資料檔案安全維護辦法 (FSC Regulations for Non-government Agencies Designated to Maintain the Security of Personal Data Files)
Directly binding regulation · Made under Article 27(3) of the Personal Data Protection Act; amended 14 December 2021 · Finance
The financial regulator's own privacy rulebook, covering banks, financial holding companies, insurers, securities firms and others it supervises. It sets a seventy-two hour breach report to the regulator and requires firms to check for cross-border transfer restrictions before sending personal data abroad.
Enforced by Financial Supervisory Commission
Transfer model: Blocklist · Accepted routes: Nothing required
What it makes you do
- Report breaches to the regulator — within 72 hoursMajor personal data incidents must be reported to the Financial Supervisory Commission on the prescribed form within 72 hours.
- Put a transfer safeguard in placeBefore any international transfer of personal data, check whether the Commission has restricted it and comply.
- Assess high-risk projectsMap where personal data sits in your business processes, assess the risks, and design controls to match.
- Independent auditCorrective and preventive measures after an incident must be reviewed by an independent, accredited expert.
What it costs if you get it wrong
- Fixed maximum fine: NT$15,000,000 — about $480 thousandSerious failure to maintain personal data security, under Article 48 of the Personal Data Protection Act
Sources
- Official sourceFinancial Supervisory CommissionFSC Regulations for Non-government Agencies Designated to Maintain the Security of Personal Data Files, Articles 2, 5 and 6
law.moj.gov.tw
“非公務機關遇有重大個人資料事故者,應依附件格式於七十二小時內通報本會。”
Link checked 18 August 2026
資通安全事件通報應變及演練辦法 (Regulations on the Notification and Response of Cyber Security Incidents and Drills)
Directly binding regulation · Made under Articles 10(4), 17(4) and 24 of the Cyber Security Management Act; amended 5 January 2026 · Government
Taiwan's cyber incident regime, run by the digital ministry. Government bodies and designated critical infrastructure operators get one hour to report an incident, one of the shortest deadlines anywhere. This clock runs alongside, not instead of, the privacy breach clocks.
Enforced by Ministry of Digital Affairs
What it makes you do
- Report cyber incidents — within 1 hourGovernment agencies report to the platform the authority designates within one hour of becoming aware. Designated non-government agencies, which include critical infrastructure operators, report to their industry regulator within one hour.
- Secure the data — within 72 hoursDamage control or recovery must be completed within 72 hours for level one and two incidents, and faster for major incidents.
- Independent auditSocial engineering drills every six months and a notification and response exercise every year.
Sources
- Official sourceMinistry of Digital AffairsRegulations on the Notification and Response of Cyber Security Incidents and Drills, Articles 6, 8, 10 and 11
law.moj.gov.tw
“特定非公務機關知悉資通安全事件後,應於一小時內依中央目的事業主管機關指定之方式,進行資通安全事件之通報。”
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.
Whether any specific order restricting international transfer of personal data has been issued under Article 21, and to which countries
The mechanism is confirmed from the statute, and two regulators' own binding rules order firms to check for such restrictions before transferring, which strongly implies orders exist. But the National Communications Commission's site returned an access error to our fetcher and its separate legal database was unreachable, so we could not open the text of any individual order. The transfer blocklist is therefore recorded as populated-unknown rather than empty. This is the single biggest gap in this record.
Whether the Executive Yuan has set a commencement date for the November 2025 privacy amendment at any point between 8 and 18 August 2026
The national law database records the status as 'not yet effective, date undetermined', but its content is compiled only to 7 August 2026 and refreshes weekly. We cannot prove a negative for the eleven days since.
Whether the Organic Act of the Personal Data Protection Commission passed the Legislative Yuan at any point after March 2026
The regulator's own site has published nothing since 9 March 2026, and its news list is rendered by JavaScript so we could only read the items exposed on the homepage. We did not separately check the Legislative Yuan's bill tracker.
Localisation or storage rules in insurance, securities, education, online gaming, mapping and geospatial data, and defence
No rule found, checked 18 August 2026, confidence medium. The financial outsourcing rules we cite are made under the Banking Act and formally bind banks, credit cooperatives, bills finance companies and credit card institutions; parallel instruments almost certainly exist for insurers and securities firms but we did not locate them. Our attempt to read the National Land Surveying and Mapping Act returned no usable text. Absence of a finding here is a gap, not a clearance.
Enforcement volume — how many fines the sector regulators actually issue each year under the privacy law
Both fsc.gov.tw and ncc.gov.tw blocked automated fetching, so we could not open penalty registers or statistics. The 'active' enforcement rating rests on the regulators' own binding regulations, including the NCC's standing fine-scoring framework, rather than on counted decisions. Treat the rating as well-founded but not quantified.
Whether the National Health Insurance Data Management Act's thirty-day opt-out window ends on 8 or 9 September 2026
The Act says thirty days from commencement, which was 10 August 2026, but does not state whether the day of commencement counts. Plan to the earlier date.
Whether the replacement rules for electronic payment institutions impose an in-country information system requirement
The Regulations Governing the Standards for Information System and Security Control of Electronic Payment Institutions were abolished on 25 April 2023 and we could not locate the successor instrument in the national law database using the search terms available.
30-day cadence. Two things can change this record overnight with a single order and no consultation: the Executive Yuan setting the commencement date of the November 2025 privacy amendment, which would create a national regulator and move the cross-border transfer power to it, and any industry ministry issuing a transfer restriction order under Article 21. A third date is fixed and imminent: the health insurance opt-out window closes in early September 2026.
Freshness and refresh
Freshness
Checked today — on 18 August 2026.
Re-checked every 30 days. Next check due 17 September 2026.
Compare with
- Taiwan versus Argentina
- Taiwan versus Armenia
- Taiwan versus Australia
- Taiwan versus Austria
- Taiwan versus Azerbaijan
- Taiwan versus Brazil
- Taiwan versus Bulgaria
- Taiwan versus Cambodia
- Taiwan versus Canada
- Taiwan versus China
- Taiwan versus Croatia
- Taiwan versus Cyprus
- Taiwan versus Estonia
- Taiwan versus France
- Taiwan versus Georgia
- Taiwan versus Germany
- Taiwan versus Greece
- Taiwan versus Hong Kong SAR
- Taiwan versus Hungary
- Taiwan versus Iceland
- Taiwan versus India
- Taiwan versus Indonesia
- Taiwan versus Ireland
- Taiwan versus Israel
- Taiwan versus Italy
- Taiwan versus Japan
- Taiwan versus Latvia
- Taiwan versus Lithuania
- Taiwan versus Luxembourg
- Taiwan versus Malta
- Taiwan versus Mexico
- Taiwan versus Mongolia
- Taiwan versus Nepal
- Taiwan versus Netherlands
- Taiwan versus Poland
- Taiwan versus Russia
- Taiwan versus Saudi Arabia
- Taiwan versus Serbia
- Taiwan versus Singapore
- Taiwan versus Slovakia
- Taiwan versus Slovenia
- Taiwan versus South Korea
- Taiwan versus Spain
- Taiwan versus Sri Lanka
- Taiwan versus Sweden
- Taiwan versus Switzerland
- Taiwan versus Thailand
- Taiwan versus Turkey
- Taiwan versus Ukraine
- Taiwan versus United Arab Emirates
- Taiwan versus United Kingdom
- Taiwan versus United States
- Taiwan versus Uzbekistan