Skip to the content
Global Data RulesData governance rules, country by country

Taiwan

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.

If you collect data about people in Taiwan — customers, users, employees — these are the rules you have to follow. Here is the short version.

The short version

Depends on your industryWork: HighEnforcement: Active

You can send Taiwanese personal data abroad freely. The only thing that stops you is an order from the ministry that regulates your industry. Taiwan has no single privacy regulator. Each industry ministry polices its own industry. Each has written its own security and breach-reporting rules. A big reform would create one national regulator. Parliament passed it in November 2025, but it has never been switched on.

Data governance in Taiwan

The eight things that decide how you handle data about people in Taiwan. Same eight on every country page, so you can compare.

Who has to follow these rules

Yes. Taiwan's privacy law applies even if you have no office and no staff in Taiwan. It says plainly that it also covers organisations outside Taiwan that collect, use or store the personal data of Taiwanese people. There is no revenue or staff cut-off that keeps you out. You do not have to appoint a local representative.

Where the data is allowed to live

In general, yes. Taiwan's privacy law does not ask you to sign anything before sending personal data abroad. You do not need anyone's permission either. Instead, each industry ministry can order that data in its industry may not go to a particular country. Four industries have real limits. In two of them, the ban is absolute.

What to do: Check your own industry against the restricted list before you pick a hosting region.

Sending data out of the country

Under the general law, nothing. No standard contract. No government approval. No official decision that a country is safe enough. No consent form. You can send data anywhere unless the ministry that supervises your industry has issued an order stopping it. Your real job is to find out which ministry supervises you. Then check whether it has issued such an order.

Ways to send data out:
Nothing required · Government sign-off needed

What to do: Budget months, not weeks: government sign-off has to be in hand before the data moves.

The regulator, and whether it actually acts

There is no national privacy regulator in Taiwan today. The law names a Personal Data Protection Commission as the authority in charge. That part of the law has never been switched on. The law that would create the Commission is still only a bill. What exists is a preparatory office. It writes draft rules and cannot fine anyone. Enforcement is done by whichever ministry regulates your industry, plus city and county governments. Those bodies are active.

How long you must keep it — and when to delete it

There are both minimum and maximum keep times. The minimums come from other laws, not the privacy law. Accounting vouchers must be kept at least five years. Account books and financial statements must be kept at least ten years. Medical records must be kept at least seven years. For children, medical records must be kept until seven years after they turn eighteen. Records from human trials must be kept forever. Going the other way, you must delete personal data once the purpose you collected it for has gone. The same applies once the period you set has run out.

What you have to do here:
Keep data for a minimum period · Delete data after a period · Let people delete their data

What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.

If something goes wrong

You have at least three deadlines, and the fastest is one hour. Telecoms companies and larger internet providers must tell the communications regulator within one hour of learning about a major personal data incident. They then file a full report within seventy-two hours. Government bodies and designated critical infrastructure operators also have one hour, under the separate cyber security law. Financial firms get seventy-two hours. Under the privacy law itself, you must tell the people affected once you have established the facts. No fixed deadline is attached to that one.

What you have to do here:
Report breaches to the regulator · Tell affected people · Report cyber incidents

What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.

What catches people out

Five things catch people out. First, the official English text of the privacy law on the government's own website includes parts that are not law yet. That includes the part naming the national regulator. Second, breaking a cross-border transfer order is a crime, not just a fine. It carries up to five years in prison. Third, there is no single regulator to ask. Your duties depend on which ministry supervises you. Fourth, if a foreign financial regulator asks a bank for Taiwanese customer data, the bank must get Taiwan's regulator's permission first. Fifth, if someone sues you, you have to prove you were not at fault.

What you have to do here:
Do not hand data to foreign authorities on demand
What it costs if you get it wrong:
Criminal liability · Claims by individuals

What's changing next

One law has already started, and one is waiting to be switched on. The National Health Insurance Data Management Act came into force on 10 August 2026. It gives people a short window to stop their health records being used for research. If they say nothing, that counts as agreement. Separately, the big privacy reform passed in November 2025 is not in force. The Cabinet can start it whenever it likes, with a single order and no consultation.

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries6 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Health and social care

Health and social care data must stay in the country

Official name: 醫療機構電子病歷製作及管理辦法 (Regulations Governing the Production and Management of Electronic Medical Records by Medical Institutions) · Article 8, made under Article 69 of the Medical Care Act; amended 18 July 2022 · Directly binding regulation

In forceNo — it stays put

Where a hospital or clinic uses cloud services for electronic medical records, the data must be stored inside Taiwan. The only way out is a case-by-case approval from the health ministry for special circumstances. The cloud provider must also be certified against a security standard the ministry recognises.

In force since 18 July 2022

Enforced by Ministry of Health and Welfare

How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed

Health and social care

Health and social care data must stay in the country (Health and social care)

Official name: 全民健康保險資料管理條例 (National Health Insurance Data Management Act) · Promulgated by Presidential Order 華總一義字第11400129981號 on 19 December 2025; brought into force by Executive Yuan Order 院臺衛字第1151018599號 of 6 August 2026 · Act of parliament

In forceNo — it stays put

This law answers a 2022 Constitutional Court ruling. The court said the health insurance database had no proper legal basis and no opt-out. This law creates one. Research use is limited to Taiwanese institutions. It must happen inside a designated secure environment. It cannot be commercial. Every insured person can block their own records. The law started on 10 August 2026, and the first opt-out window is short.

In force since 10 August 2026

Enforced by National Health Insurance Administration

How this country controls where data goes: Not allowed

Banking

Banking data needs a copy kept in the country

Official name: 金融機構作業委託他人處理內部作業制度及程序辦法 (Regulations Governing Internal Operating Systems and Procedures for the Outsourcing of Financial Institution Operation) · Articles 17 to 20, made under Article 45-1(3) of the Banking Act and Article 21(4) of the Credit Cooperatives Act; amended 13 April 2026 · Directly binding regulation

In forceA copy must stay

Taiwan's banks and credit card issuers can handle customer data abroad, but not freely. Anything material in consumer finance needs the financial regulator's approval in advance. The data should normally stay in Taiwan. If it goes abroad, you must keep a Taiwanese backup of important customer data. The regulator can say otherwise.

In force since 13 April 2026

Enforced by Financial Supervisory Commission

How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed, Security review needed

Applies to every company3 rules

These bind you whatever business you are in, once the country's rules reach you.

Breach reporting rules

Official name: 個人資料保護法 (Personal Data Protection Act) · Promulgated 11 August 1995 as the Computer-Processed Personal Data Protection Act; renamed and rewritten 26 May 2010; current operative text as amended 31 May 2023 · Act of parliament

Partly in forceYes — store it anywhere

This is Taiwan's general privacy law. It applies to organisations outside Taiwan that handle Taiwanese people's data. It requires no paperwork to send data abroad. Supervision is left to whichever ministry regulates your industry. Its most striking feature is criminal liability. Several breaches carry prison sentences, not just fines. Note that the published text includes parts that have never started.

In force since 1 October 2012

Enforced by Personal Data Protection Commission (Preparatory Office) — not yet operational

How this country controls where data goes: Any country except banned ones · Accepted routes: Nothing required

Breach reporting rules (Passed by the Legislative Yuan 17 October 2025; promulgated by Presidential Order 華總一經字第11400114521號 on 11 November 2025; commencement date to be set by the Executive Yuan)

Official name: 個人資料保護法部分條文修正 (Amendment to certain articles of the Personal Data Protection Act) · Passed by the Legislative Yuan 17 October 2025; promulgated by Presidential Order 華總一經字第11400114521號 on 11 November 2025; commencement date to be set by the Executive Yuan · Act of parliament

Passed, not yet fully in forceYes — store it anywhere

A large reform package, passed and signed. It would give Taiwan a real national privacy regulator, with breach reporting, audit and inspection powers. It has no legal effect until the Cabinet issues an order setting the start date. As of 18 August 2026 no such order has been issued. Do not plan around this text as if it binds you today.

Enforced by Personal Data Protection Commission (Preparatory Office) — not yet operational

How this country controls where data goes: Any country except banned ones · Accepted routes: Nothing required

General data protection law

Official name: 個人資料保護委員會組織法草案 (Draft Organic Act of the Personal Data Protection Commission) · Approved by the Executive Yuan at its 3945th meeting on 27 March 2025 and sent to the Legislative Yuan; preliminary review completed by the Judiciary and Organic Laws Committee as at 17 October 2025 · Draft law

ProposedNot yet established

The law that would actually create Taiwan's national privacy regulator is still a bill. Without it, the Commission has no legal basis to exist. That is why the Commission named in the privacy law has never been set up. It is also why the 2025 privacy amendment has not been switched on. This is a proposal, not binding law.

Enforced by Personal Data Protection Commission (Preparatory Office) — not yet operational

Not fully verified — see “What we're not sure about” below.

Who you would hear from

  • 個人資料保護委員會籌備處

    Named in the privacy law as the national competent authority; in practice only drafts rules

    The part of the law naming it as competent authority was added on 31 May 2023 but has never started. The organic act needed to create it is still a bill. What exists is a preparatory office, set up under temporary organisation rules of 23 September 2023. On 1 January 2024 it took over two narrow rule-making jobs from the National Development Council. It cannot fine, order or inspect. Its most recent published announcement is dated 9 March 2026.

  • 金融監督管理委員會

    Banking, payments, insurance, securities; personal data supervision of the firms it licenses

    It issues binding outsourcing and personal data security rules. It approves the handling of data abroad case by case. It takes incident reports within 72 hours.

  • 國家通訊傳播委員會

    Telecommunications, broadcasting and internet access; personal data supervision of communications enterprises

    It runs a one-hour breach reporting system. It keeps a standing scoring system for setting fines on communications enterprises that breach the privacy law. Its own binding rules refer to that scoring system.

  • 衛生福利部

    Health and social care; electronic medical records; health insurance data policy

  • 衛生福利部中央健康保險署

    National health insurance records, secondary-use approvals and the opt-out register

    Operates the opt-out service through which insured people can block secondary use of their health insurance data.

  • 數位發展部

    Cyber security law, incident reporting for government bodies and critical infrastructure

  • 憲法法庭

    Constitutional review; ruled in 2022 that Taiwan's lack of an independent data protection supervisor is constitutionally deficient

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.

  • Whether any specific order restricting international transfer of personal data has been issued under Article 21, and to which countries

    We could not confirm whether any orders restricting transfers abroad have been issued. The power itself is confirmed in the statute. Two regulators' own binding rules tell firms to check for such restrictions before transferring, which strongly suggests orders exist. But the National Communications Commission's site returned an access error to us, and its separate legal database was unreachable. So we could not read the text of any individual order. Ask your industry regulator directly before you send data abroad. This is the single biggest gap in this record.

  • Whether the Executive Yuan has set a commencement date for the November 2025 privacy amendment at any point between 8 and 18 August 2026

    We could not confirm the position after 7 August 2026. The national law database records the status as 'not yet effective, date undetermined'. But its content is compiled only up to 7 August 2026, and it refreshes weekly. Check the database for anything issued since.

  • Whether the Organic Act of the Personal Data Protection Commission passed the Legislative Yuan at any point after March 2026

    We could not confirm how far the bill has got. The regulator's own site has published nothing since 9 March 2026. We did not check the Legislative Yuan's bill tracker. Check it if the timing matters to you.

  • Localisation or storage rules in insurance, securities, education, online gaming, mapping and geospatial data, and defence

    We found no rule for these industries, checked 18 August 2026, confidence medium. The financial outsourcing rules we cite are made under the Banking Act. They formally bind banks, credit cooperatives, bills finance companies and credit card institutions. Similar rules almost certainly exist for insurers and securities firms, but we did not find them. We also could not read the National Land Surveying and Mapping Act. If you work in these industries, check before you rely on this.

  • Enforcement volume — how many fines the sector regulators actually issue each year under the privacy law

    We could not confirm how much enforcement actually happens. Both fsc.gov.tw and ncc.gov.tw blocked automated reading, so we could not open penalty registers or statistics. Our 'active' rating rests on the regulators' own binding rules, including the communications regulator's standing fine-scoring system. It is not based on counted decisions. Treat the rating as well-founded but not measured.

  • Whether the National Health Insurance Data Management Act's thirty-day opt-out window ends on 8 or 9 September 2026

    We could not confirm the exact end of the opt-out window. The Act says thirty days from the start date, which was 10 August 2026. It does not say whether the start day counts. Plan for the earlier date.

  • Whether the replacement rules for electronic payment institutions impose an in-country information system requirement

    We could not confirm what replaced the old electronic payment security rules. The Regulations Governing the Standards for Information System and Security Control of Electronic Payment Institutions were abolished on 25 April 2023. We could not find the replacement in the national law database with the search terms available. If you run an electronic payment business, ask the Financial Supervisory Commission.

Freshness and refresh

Freshness

Checked about 2 months ago, on 18 August 2026.

Re-checked every 30 days. Next check due 17 September 2026.

Read the exact prompt used to research this page

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.