Taiwan
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.
If you collect data about people in Taiwan — customers, users, employees — these are the rules you have to follow. Here is the short version.
The short version
You can send Taiwanese personal data abroad freely. The only thing that stops you is an order from the ministry that regulates your industry. Taiwan has no single privacy regulator. Each industry ministry polices its own industry. Each has written its own security and breach-reporting rules. A big reform would create one national regulator. Parliament passed it in November 2025, but it has never been switched on.
Data governance in Taiwan
The eight things that decide how you handle data about people in Taiwan. Same eight on every country page, so you can compare.
Who has to follow these rules
Yes. Taiwan's privacy law applies even if you have no office and no staff in Taiwan. It says plainly that it also covers organisations outside Taiwan that collect, use or store the personal data of Taiwanese people. There is no revenue or staff cut-off that keeps you out. You do not have to appoint a local representative.
The reach comes from the Personal Data Protection Act (個人資料保護法), Article 51, paragraph 2, in the version now in force: 公務機關及非公務機關,在中華民國領域外對中華民國人民個人資料蒐集、處理或利用者,亦適用本法. The official English version says the Act also applies to government and non-government agencies outside the territory of the Republic of China (R.O.C). It covers them when they collect, use or store the personal data of R.O.C. nationals. Criminal liability travels too. Article 43 applies the Act's two criminal offences to Taiwanese nationals who commit them outside Taiwan against other Taiwanese nationals. What the law says and what a regulator can do to you are different questions. Enforcement is carried out by whichever ministry supervises your industry. A company with no Taiwanese entity is harder for them to reach.
Sources
- Official sourceLaws & Regulations Database of the Republic of China (Taiwan), Ministry of JusticePersonal Data Protection Act, Articles 43 and 51 — text currently in force (version of 31 May 2023)
law.moj.gov.tw
“公務機關及非公務機關,在中華民國領域外對中華民國人民個人資料蒐集、處理或利用者,亦適用本法。”
Link checked 18 August 2026
- Official sourceMinistry of JusticePersonal Data Protection Act — official English translation
law.moj.gov.tw
Link checked 18 August 2026
Where the data is allowed to live
In general, yes. Taiwan's privacy law does not ask you to sign anything before sending personal data abroad. You do not need anyone's permission either. Instead, each industry ministry can order that data in its industry may not go to a particular country. Four industries have real limits. In two of them, the ban is absolute.
The general rule is Article 21 of the Personal Data Protection Act, in force since 2012. The central authority for your industry may block a transfer abroad in four cases. Where major national interests are involved. Where a treaty says so. Where the destination country lacks proper data protection law, so people could be harmed. Or where the transfer routes through a third country to dodge the Act. This is not a general ban. It is not a permission system, and it is not a paperwork exercise. Industry by industry. HEALTH (data must stay in the country). Where a hospital or clinic uses cloud services for electronic medical records, the storage location must be inside Taiwan. The Ministry of Health and Welfare can approve an exception. NATIONAL HEALTH INSURANCE DATA (data must stay in the country). The National Health Insurance Data Management Act started on 10 August 2026. Only bodies set up inside Taiwan may apply to reuse this data. Those are government bodies, public juridical persons, medical institutions, academic research institutions and universities. The data must be worked on in a secure environment, at a place the authority designates. A foreign university or company cannot get it at all. BANKING AND CONSUMER FINANCE (a copy must stay in the country). Customer data for materially significant consumer-finance information systems should normally be stored in Taiwan. If it is stored abroad, important customer data must be backed up and kept in Taiwan. The Financial Supervisory Commission can approve otherwise. The other country's data protection law must not be weaker than Taiwan's. TELECOMS (data can leave only if conditions are met). The National Communications Commission's binding rules apply to communications enterprises. Before every transfer abroad, you must check whether the Commission has restricted it, and follow that. INSURANCE, SECURITIES, EDUCATION, GAMING, MAPPING AND DEFENCE. We found no rule on a government source about data having to stay in Taiwan. Checked 18 August 2026, confidence medium.
Sources
- Official sourceMinistry of JusticePersonal Data Protection Act, Article 21 — restriction of international transmission, text currently in force
law.moj.gov.tw
“非公務機關為國際傳輸個人資料,而有下列情形之一者,中央目的事業主管機關得限制之:一、涉及國家重大利益。二、國際條約或協定有特別規定。三、接受國對於個人資料之保護未有完善之法規,致有損當事人權益之虞。四、以迂迴方法向第三國(地區)傳輸個人資料規避本法。”
Link checked 18 August 2026
- Official sourceMinistry of Health and WelfareRegulations Governing the Production and Management of Electronic Medical Records by Medical Institutions, Article 8
law.moj.gov.tw
“前項雲端服務之資料儲存地點,應設置於我國境內。但因特殊情形,經中央主管機關核准者,不在此限。”
Link checked 18 August 2026
- Official sourceMinistry of Health and WelfareNational Health Insurance Data Management Act, Articles 8, 9 and 13
law.moj.gov.tw
“前條申請者,以政府機關(構)、行政法人,或於中華民國境內設立之醫療機構、學術研究機構、大學,及受政府機關委託之大學、法人、機構為限。”
Link checked 18 August 2026
- Official sourceFinancial Supervisory CommissionRegulations Governing Internal Operating Systems and Procedures for the Outsourcing of Financial Institution Operation, Articles 17 to 20
law.moj.gov.tw
“涉及重大性消費金融業務資訊系統之客戶資料儲存地以位於我國境內為原則。如位於境外,除經主管機關核准者外,客戶重要資料應在我國留存備份。”
Link checked 18 August 2026
What to do: Check your own industry against the restricted list before you pick a hosting region.
Sending data out of the country
Under the general law, nothing. No standard contract. No government approval. No official decision that a country is safe enough. No consent form. You can send data anywhere unless the ministry that supervises your industry has issued an order stopping it. Your real job is to find out which ministry supervises you. Then check whether it has issued such an order.
- Ways to send data out:
- Nothing required · Government sign-off needed
This setup is unusual, so here it is precisely. Taiwan has no equivalent of European standard contractual clauses. It has no company-wide binding rules system, and no national list of approved destinations. Article 21 of the Personal Data Protection Act is a power to restrict. It is not a duty to obtain anything. Have any restriction orders been issued? We can confirm the power is live. We could not open the text of any individual order on a government website. Two regulators tell the firms they supervise to check for such restrictions before transferring. That only makes sense if orders exist. The Financial Supervisory Commission requires firms to '進行個人資料國際傳輸前,檢視是否受本會限制並遵循之'. The National Communications Commission requires them to '進行個人資料國際傳輸前,檢視是否受本會相關法令限制並遵循之'. Assume restrictions exist in telecoms and finance, and check with the regulator directly. Breaking such an order is a crime, not just a fine. It carries up to five years in prison. There is also a fine of NT$50,000 to NT$500,000 (roughly $1,600 to $16,000), repeated until you fix the problem. When the November 2025 amendment starts, this power moves from the industry ministries to the new national commission.
Sources
- Official sourceMinistry of JusticePersonal Data Protection Act, Articles 21, 41 and 47 — transfer restriction power, criminal offence and administrative fine
law.moj.gov.tw
“意圖為自己或第三人不法之利益或損害他人之利益,而違反……中央目的事業主管機關依第二十一條限制國際傳輸之命令或處分,足生損害於他人者,處五年以下有期徒刑,得併科新臺幣一百萬元以下罰金。”
Link checked 18 August 2026
- Official sourceNational Communications CommissionNCC Regulations for Non-government Agencies Designated to Maintain the Security of Personal Data Files, Article 5
law.moj.gov.tw
“進行個人資料國際傳輸前,檢視是否受本會相關法令限制並遵循之。”
Link checked 18 August 2026
- Official sourceFinancial Supervisory CommissionFSC Regulations for Non-government Agencies Designated to Maintain the Security of Personal Data Files, Article 5
law.moj.gov.tw
“進行個人資料國際傳輸前,檢視是否受本會限制並遵循之。”
Link checked 18 August 2026
What to do: Budget months, not weeks: government sign-off has to be in hand before the data moves.
The regulator, and whether it actually acts
There is no national privacy regulator in Taiwan today. The law names a Personal Data Protection Commission as the authority in charge. That part of the law has never been switched on. The law that would create the Commission is still only a bill. What exists is a preparatory office. It writes draft rules and cannot fine anyone. Enforcement is done by whichever ministry regulates your industry, plus city and county governments. Those bodies are active.
Three separate facts, each verified on a government site. First, Article 1-1 of the Personal Data Protection Act says the competent authority is the Personal Data Protection Commission. That article was added on 31 May 2023, and the Executive Yuan was left to set its start date. The official law database records the Act's status as 本法規部分或全部條文尚未生效,最後生效日期:未定. That means some or all of it is not yet in effect, with no date set. Second, the preparatory office published a press release on 17 October 2025. It said the Commission can only be set up formally once the organic act passes. The draft had cleared preliminary committee review only. It also said the Executive Yuan will set the start date of the amended Act separately. Third, the only rules in the national law database carrying the Commission's name are the preparatory office's temporary organisation rules of 23 September 2023. On 1 January 2024 the preparatory office took over two narrow rule-making jobs from the National Development Council. Those are publishing the table of specific purposes and data categories, and the Act's enforcement rules. Nothing more. Four bodies do the real work. They are the Financial Supervisory Commission, the National Communications Commission, the Ministry of Health and Welfare and the Ministry of Digital Affairs. Each supervises, inspects and fines within its own industry. They do this under Articles 22 to 25 and 47 to 50. The National Communications Commission has a standing scoring system for setting fines on communications enterprises that breach the Act. Its own binding rules refer to it. That shows fining is routine, not theoretical. So enforcement is active in the industries and dormant nationally.
Sources
- Official sourceMinistry of JusticePersonal Data Protection Act — legislative history and effectiveness status
law.moj.gov.tw
“生效狀態:※本法規部分或全部條文尚未生效,最後生效日期:未定”
Link checked 18 August 2026
- Official sourcePreparatory Office of the Personal Data Protection CommissionPress release, 17 October 2025 — Legislative Yuan passes the Personal Data Protection Act amendment
pdpc.gov.tw
“惟個資會之正式成立,仍須俟組織法立法通過後始有法源依據;目前組織法草案業經立法院「司法及法制委員會」初審完竣,尚待進一步完成立法程序。未來行政院將配合組織法在立法院之審議進度,並審酌相關行政準備作業時間後,另行指定個資法新法之施行日期。”
Link checked 18 August 2026
- Official sourcePreparatory Office of the Personal Data Protection CommissionPreparatory Office of the Personal Data Protection Commission — announcements, latest item dated 9 March 2026
pdpc.gov.tw
Link checked 18 August 2026
- Official sourceNational Communications CommissionNCC personal data security regulation, Article 4 — refers to the Commission's own scoring framework for setting fines under the Personal Data Protection Act
law.moj.gov.tw
Link checked 18 August 2026
How long you must keep it — and when to delete it
There are both minimum and maximum keep times. The minimums come from other laws, not the privacy law. Accounting vouchers must be kept at least five years. Account books and financial statements must be kept at least ten years. Medical records must be kept at least seven years. For children, medical records must be kept until seven years after they turn eighteen. Records from human trials must be kept forever. Going the other way, you must delete personal data once the purpose you collected it for has gone. The same applies once the period you set has run out.
- What you have to do here:
- Keep data for a minimum period · Delete data after a period · Let people delete their data
The maximum is Article 11, paragraph 3 of the Personal Data Protection Act. When the specific purpose of collection no longer exists, or the relevant time period expires, you must erase the data. You can stop using and storing it instead. You must do this on your own initiative, or when the person asks. The same paragraph settles the clash with the minimum keep times. The duty does not apply where keeping the data is necessary to perform an official or business duty. It also does not apply where the person has agreed in writing. So a keeping duty set by law beats the deletion duty. People also have a separate right to demand erasure under Article 3. They can also demand that you stop collecting, using or storing their data. One firm deletion rule is now live. Article 25 of the National Health Insurance Data Management Act covers health insurance data obtained for secondary use before the Act started on 10 August 2026. That data must be destroyed. The exception is a government body holding it to perform duties set by law. If you fail to destroy it, the fine is NT$2 million to NT$10 million (roughly $64,000 to $320,000).
Sources
- Official sourceMinistry of Economic AffairsBusiness Entity Accounting Act, Article 38 — five years for vouchers, ten years for books and financial statements
law.moj.gov.tw
“各項會計憑證,除應永久保存或有關未結會計事項者外,應於年度決算程序辦理終了後,至少保存五年。各項會計帳簿及財務報表,應於年度決算程序辦理終了後,至少保存十年。”
Link checked 18 August 2026
- Official sourceMinistry of Health and WelfareMedical Care Act, Article 70 — medical record retention
law.moj.gov.tw
“醫療機構之病歷,應指定適當場所及人員保管,並至少保存七年。但未成年者之病歷,至少應保存至其成年後七年;人體試驗之病歷,應永久保存。”
Link checked 18 August 2026
- Official sourceMinistry of JusticePersonal Data Protection Act, Articles 3 and 11 — erasure and stop-processing duties, text currently in force
law.moj.gov.tw
Link checked 18 August 2026
What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.
If something goes wrong
You have at least three deadlines, and the fastest is one hour. Telecoms companies and larger internet providers must tell the communications regulator within one hour of learning about a major personal data incident. They then file a full report within seventy-two hours. Government bodies and designated critical infrastructure operators also have one hour, under the separate cyber security law. Financial firms get seventy-two hours. Under the privacy law itself, you must tell the people affected once you have established the facts. No fixed deadline is attached to that one.
- What you have to do here:
- Report breaches to the regulator · Tell affected people · Report cyber incidents
DEADLINE 1: National Communications Commission rules, Article 4. You must report a major personal data incident to the Commission within one hour of becoming aware of it. A follow-up report on the prescribed form is due within seventy-two hours. If the Commission or another agency told you about the incident first, the form is due within forty-eight hours. This covers telecommunications enterprises, providers of internet access with three thousand or more subscribers, and other communications enterprises the Commission names. DEADLINE 2: Regulations on the Notification and Response of Cyber Security Incidents, amended 5 January 2026, Articles 6 and 11. Government agencies and designated non-government agencies must report to the platform the authority specifies. The deadline is one hour from becoming aware. Damage control or recovery must be completed within seventy-two hours for level one and two incidents. DEADLINE 3: Financial Supervisory Commission rules, Article 6. You must report a major personal data incident to the Commission within seventy-two hours, on the prescribed form. DEADLINE 4: Personal Data Protection Act, Article 12, as currently in force. You must tell the people affected in a suitable way after you have established the facts. There is no hour count. The Act itself does not make you tell a regulator at all. That changes when the November 2025 amendment starts. It adds a single reporting duty to the new national commission. The deadline will be set in a regulation that has not been made yet.
Sources
- Official sourceNational Communications CommissionNCC Regulations for Non-government Agencies Designated to Maintain the Security of Personal Data Files, Article 4 — one-hour reporting
law.moj.gov.tw
“非公務機關遇有重大個人資料事故者,應於知悉後一小時內通報本會,並於七十二小時內依附表格式,續行通報本會。但非公務機關接獲本會或有關機關通報發生事故時,應於四十八小時內,依附表格式通報本會。”
Link checked 18 August 2026
- Official sourceMinistry of Digital AffairsRegulations on the Notification and Response of Cyber Security Incidents and Drills, Articles 6, 8 and 11 (amended 5 January 2026)
law.moj.gov.tw
“公務機關知悉資通安全事件後,應於一小時內至主管機關指定之系統平臺通報。”
Link checked 18 August 2026
- Official sourceFinancial Supervisory CommissionFSC Regulations for Non-government Agencies Designated to Maintain the Security of Personal Data Files, Article 6 — seventy-two hour reporting
law.moj.gov.tw
“非公務機關遇有重大個人資料事故者,應依附件格式於七十二小時內通報本會。”
Link checked 18 August 2026
What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.
What catches people out
Five things catch people out. First, the official English text of the privacy law on the government's own website includes parts that are not law yet. That includes the part naming the national regulator. Second, breaking a cross-border transfer order is a crime, not just a fine. It carries up to five years in prison. Third, there is no single regulator to ask. Your duties depend on which ministry supervises you. Fourth, if a foreign financial regulator asks a bank for Taiwanese customer data, the bank must get Taiwan's regulator's permission first. Fifth, if someone sues you, you have to prove you were not at fault.
- What you have to do here:
- Do not hand data to foreign authorities on demand
- What it costs if you get it wrong:
- Criminal liability · Claims by individuals
(1) The Ministry of Justice law database publishes the amended text. The English translation shows Article 1-1 naming the Personal Data Protection Commission as competent authority. The database's own status line says some or all of the Act has not taken effect, with no date set. Read the English page at face value and you will get four things wrong. The regulator, the breach-reporting duty, the data protection officer duty and the fine levels. (2) Article 41 of the Act as in force. It makes one thing a crime: breaching an industry authority's order restricting transmission abroad. Two conditions apply. You must act with intent to gain an unlawful benefit or harm another's interest. And you must cause harm. The punishment is up to five years' imprisonment, plus a fine of up to NT$1 million (about $32,000). Under Article 45 that offence is prosecuted without a complaint from the victim. Article 44 increases the sentence by up to half for public officials. (3) Compliance is split up. Each central industry authority issues its own personal data file security maintenance rules under Article 27. Each sets its own security plan requirements and its own breach deadline. It is one hour in telecoms and seventy-two hours in finance. (4) Regulations Governing Internal Operating Systems and Procedures for the Outsourcing of Financial Institution Operation, Article 17, subparagraph 5. Your outsourced provider may sit in another country. If that country's financial regulator asks for Taiwanese customer information, you must first tell Taiwan's Financial Supervisory Commission. You must get its consent before handing anything over. (5) Article 29. A private organisation is liable for damage unless it can prove the harm was not caused by its intent or negligence. Courts may award NT$500 to NT$20,000 per person per incident, with no proof of actual loss. Total awards for one incident are capped at NT$200 million, roughly $6.4 million. Registered foundations and public-interest associations can bring group claims.
Sources
- Official sourceMinistry of JusticePersonal Data Protection Act — status line showing provisions not yet effective
law.moj.gov.tw
“一百十四年十一月十一日修正第 1-1、12、18、21、22~26、41、47~49、52、53、55 條條文……施行日期,由行政院定之。”
Link checked 18 August 2026
- Official sourceMinistry of JusticePersonal Data Protection Act, Articles 27, 29, 41, 44 and 45 — text currently in force
law.moj.gov.tw
“非公務機關違反本法規定,致個人資料遭不法蒐集、處理、利用或其他侵害當事人權利者,負損害賠償責任。但能證明其無故意或過失者,不在此限。”
Link checked 18 August 2026
- Official sourceFinancial Supervisory CommissionRegulations Governing Internal Operating Systems and Procedures for the Outsourcing of Financial Institution Operation, Article 17
law.moj.gov.tw
“受委託機構所在地金融主管機關請求提供我國客戶資訊時,金融機構應先將事由通知我國主管機關並取得同意後始得提供。”
Link checked 18 August 2026
What's changing next
One law has already started, and one is waiting to be switched on. The National Health Insurance Data Management Act came into force on 10 August 2026. It gives people a short window to stop their health records being used for research. If they say nothing, that counts as agreement. Separately, the big privacy reform passed in November 2025 is not in force. The Cabinet can start it whenever it likes, with a single order and no consultation.
STARTING NOW. The National Health Insurance Data Management Act was promulgated on 19 December 2025. The Cabinet set it to start on 10 August 2026, by an order dated 6 August 2026. Article 16 makes the authority stop accepting new secondary-use applications for thirty days from the start date. A person who does not ask for their data to be stopped within that window is treated as having agreed. So the window closes around 9 September 2026. You can still opt out later, but it only works going forward. Health insurance data already released for secondary use before 10 August 2026 must be destroyed. The exception is a government body holding it for duties set by law. WAITING TO BE SWITCHED ON, in order of importance. One: the Executive Yuan can set the start date of the November 2025 privacy amendment at any time, by order. That single order would create a national regulator. It could receive breach reports, set one common baseline security rule, restrict transfers abroad, and audit and inspect both government and private bodies. Two: the organic act creating the Personal Data Protection Commission is still only a bill. It had cleared preliminary committee review by October 2025. The regulator's own website has published nothing since 9 March 2026. Three: any central industry authority can restrict cross-border transfers by order under Article 21, at any time. There is no consultation and no appeal to a national regulator. Four: when the Commission is finally established, a six-year transition begins. During it, existing industry regulators keep supervising the businesses they already supervise. The list is cut back every two years. Also waiting: six draft regulations were announced between January and March 2026. They cover five things. The enforcement rules. The data protection officer competency rules. Audit rules for government bodies. Inspection rules for private bodies. And the list of businesses that stay with their industry regulator.
Sources
- Official sourceMinistry of Health and WelfareNational Health Insurance Data Management Act — Executive Yuan order of 6 August 2026 setting commencement on 10 August 2026
law.moj.gov.tw
“中華民國一百十五年八月六日行政院院臺衛字第 1151018599 號令發布定自一百十五年八月十日施行”
Link checked 18 August 2026
- Official sourceNational Health Insurance AdministrationApplying to stop use of your health insurance data beyond the original purpose (opt-out mechanism)
nhi.gov.tw
Link checked 18 August 2026
- Official sourcePreparatory Office of the Personal Data Protection CommissionPress release, 17 October 2025 — commencement of the amended Act to be designated separately by the Executive Yuan
pdpc.gov.tw
Link checked 18 August 2026
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries6 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Health and social care data must stay in the country
Official name: 醫療機構電子病歷製作及管理辦法 (Regulations Governing the Production and Management of Electronic Medical Records by Medical Institutions) · Article 8, made under Article 69 of the Medical Care Act; amended 18 July 2022 · Directly binding regulation
Where a hospital or clinic uses cloud services for electronic medical records, the data must be stored inside Taiwan. The only way out is a case-by-case approval from the health ministry for special circumstances. The cloud provider must also be certified against a security standard the ministry recognises.
Enforced by Ministry of Health and Welfare
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed
What you have to do
- Keep the data in the countryCloud services used for electronic medical records must store the data inside Taiwan. The Ministry of Health and Welfare can approve an exception in special circumstances.
- Hold a security certificateThe cloud provider must hold certification against an information security standard recognised by the Ministry.
- Written vendor contractThe contract must cover five things. Supervision. Audit access for the authority. Immediate notice of security failures. A ban on sub-contracting without the hospital's consent. And a way to move the data back.
Sources
- Official sourceMinistry of Health and WelfareRegulations Governing the Production and Management of Electronic Medical Records by Medical Institutions, Article 8
law.moj.gov.tw
“前項雲端服務之資料儲存地點,應設置於我國境內。但因特殊情形,經中央主管機關核准者,不在此限。”
Link checked 18 August 2026
Health and social care data must stay in the country (Health and social care)
Official name: 全民健康保險資料管理條例 (National Health Insurance Data Management Act) · Promulgated by Presidential Order 華總一義字第11400129981號 on 19 December 2025; brought into force by Executive Yuan Order 院臺衛字第1151018599號 of 6 August 2026 · Act of parliament
This law answers a 2022 Constitutional Court ruling. The court said the health insurance database had no proper legal basis and no opt-out. This law creates one. Research use is limited to Taiwanese institutions. It must happen inside a designated secure environment. It cannot be commercial. Every insured person can block their own records. The law started on 10 August 2026, and the first opt-out window is short.
Enforced by National Health Insurance Administration
How this country controls where data goes: Not allowed
What you have to do
- Keep the data in the countryOnly government bodies, public juridical persons, and medical institutions, academic research institutions and universities established inside Taiwan may apply. Foreign institutions are excluded outright.
- Register or notifyEvery secondary use needs an approved plan. A panel reviews it. Outside experts, civil society and lay members must make up at least half of that panel.
- Let people object — from 10 August 2026People may ask for their health insurance data to be blocked from secondary use. The block is registered within 30 days and works only going forward.
- Delete data after a periodHealth insurance data obtained for secondary use before 10 August 2026 must be destroyed, except where a government body holds it to perform statutory duties.
- Secure the dataAnalysis must follow the manner, time and place the authority designates. It must happen inside a secure environment. Certain items may not be taken out.
What it costs if you get it wrong
- Fixed maximum fine: NT$10,000,000 — about $320 thousandSecondary use of health insurance data without approval, plus a one-year ban on applying and destruction of the data
- Fixed maximum fine: NT$2,500,000 — about $80 thousandDeparting from the approved plan, taking banned items out of the secure environment, or producing identifiable results
- Criminal liability: 1 to 7 years' imprisonment plus a fine up to NT$10,000,000, rising to 3 to 10 years and NT$50,000,000 where national security is targeted — about $2 millionAttacking or intruding into the health insurance database or its core information systems
Sources
- Official sourceMinistry of Health and WelfareNational Health Insurance Data Management Act — full text
law.moj.gov.tw
“本條例施行起三十日內,主管機關或保險人應停止受理依第十一條第一項申請特定目的外利用健保資料。當事人未於前項期間內請求停止利用,視為同意其健保資料為特定目的外利用。”
Link checked 18 August 2026
- Official sourceMinistry of Health and WelfareNational Health Insurance Data Management Act — commencement order of 6 August 2026
law.moj.gov.tw
Link checked 18 August 2026
- Official sourceConstitutional Court of TaiwanTCC Judgment 111-Hsien-Pan-13 (111年憲判字第13號), 12 August 2022 — the Health Insurance Database Case
cons.judicial.gov.tw
“相關機關應自本判決宣示之日起3年內制定或修正相關法律,明定請求停止及例外不許停止之主體、事由、程序、效果等事項。逾期未制定或修正相關法律者,當事人得請求停止上開目的外利用。”
Link checked 18 August 2026
Banking data needs a copy kept in the country
Official name: 金融機構作業委託他人處理內部作業制度及程序辦法 (Regulations Governing Internal Operating Systems and Procedures for the Outsourcing of Financial Institution Operation) · Articles 17 to 20, made under Article 45-1(3) of the Banking Act and Article 21(4) of the Credit Cooperatives Act; amended 13 April 2026 · Directly binding regulation
Taiwan's banks and credit card issuers can handle customer data abroad, but not freely. Anything material in consumer finance needs the financial regulator's approval in advance. The data should normally stay in Taiwan. If it goes abroad, you must keep a Taiwanese backup of important customer data. The regulator can say otherwise.
Enforced by Financial Supervisory Commission
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed, Security review needed
What you have to do
- Keep the data in the countryCustomer data for materially significant consumer-finance information systems should in principle be stored in Taiwan. If stored offshore, important customer data must be backed up and retained in Taiwan unless the regulator approves otherwise.
- Register or notifyMoving a materially significant consumer-finance information system abroad needs written approval from the Financial Supervisory Commission first. You also need a board resolution, a legality analysis and a full outsourcing plan.
- Do not hand data to foreign authorities on demandIf the financial regulator where your outsourced provider sits asks for Taiwanese customer information, you must notify Taiwan's regulator and get its consent first.
- Put a transfer safeguard in placeThe destination country's data protection law must not be weaker than Taiwan's requirements.
- Independent auditAt least one general and one special audit each year, with a cross-border outsourcing audit report to the board within four months of year end.
- Secure the dataCustomer data sent to or stored with a cloud provider must be encrypted or tokenised. You need a proper key management scheme. The provider must not be able to read the data.
What it costs if you get it wrong
- Order to stopThe regulator may require the institution to terminate the outsourcing contract, fix problems within a deadline, or suspend the arrangement
Sources
- Official sourceFinancial Supervisory CommissionRegulations Governing Internal Operating Systems and Procedures for the Outsourcing of Financial Institution Operation, Articles 17 to 20 (amended 13 April 2026)
law.moj.gov.tw
“金融機構辦理作業委外,涉及重大性消費金融業務資訊系統委託至境外處理,應檢具下列書件向主管機關申請核准。”
Link checked 18 August 2026
Breach reporting rules (Telecoms)
Official name: 國家通訊傳播委員會指定非公務機關個人資料檔案安全維護辦法 (NCC Regulations for Non-government Agencies Designated to Maintain the Security of Personal Data Files) · Made under Article 27(3) of the Personal Data Protection Act; amended 1 July 2022 · Directly binding regulation
Taiwan's telecoms rulebook carries the country's shortest privacy deadline. You have one hour to tell the communications regulator about a major personal data incident. It also applies to internet access providers with three thousand or more subscribers. It makes operators check for restrictions on transfers abroad before sending data.
Enforced by National Communications Commission
How this country controls where data goes: Any country except banned ones · Accepted routes: Nothing required
What you have to do
- Report breaches to the regulator — within 1 hourOne hour from becoming aware, then a full report on the prescribed form within 72 hours. If the regulator told you first, the form is due within 48 hours.
- Put a transfer safeguard in placeBefore any international transfer of personal data, check whether the Commission's rules restrict it and comply.
- Secure the dataA written security maintenance plan and a plan for handling data after the business ends, signed by the person in charge.
- Independent audit — applies at: 5,000 or more subscribers whose data is handledThe plan must include a domestic or international personal data security audit scheme and an implementation plan.
What it costs if you get it wrong
- Fixed maximum fine: NT$15,000,000 — about $480 thousandSerious failure to maintain personal data security, under Article 48 of the Personal Data Protection Act
Sources
- Official sourceNational Communications CommissionNCC Regulations for Non-government Agencies Designated to Maintain the Security of Personal Data Files, Articles 2 to 5
law.moj.gov.tw
“非公務機關遇有重大個人資料事故者,應於知悉後一小時內通報本會,並於七十二小時內依附表格式,續行通報本會。”
Link checked 18 August 2026
Banking rules
Official name: 金融監督管理委員會指定非公務機關個人資料檔案安全維護辦法 (FSC Regulations for Non-government Agencies Designated to Maintain the Security of Personal Data Files) · Made under Article 27(3) of the Personal Data Protection Act; amended 14 December 2021 · Directly binding regulation
This is the financial regulator's own privacy rulebook. It covers banks, financial holding companies, insurers, securities firms and others it supervises. It sets a seventy-two hour deadline for reporting a breach to the regulator. It also makes firms check for restrictions before sending personal data abroad.
Enforced by Financial Supervisory Commission
How this country controls where data goes: Any country except banned ones · Accepted routes: Nothing required
What you have to do
- Report breaches to the regulator — within 72 hoursMajor personal data incidents must be reported to the Financial Supervisory Commission on the prescribed form within 72 hours.
- Put a transfer safeguard in placeBefore any international transfer of personal data, check whether the Commission has restricted it and comply.
- Assess high-risk projectsMap where personal data sits in your business processes, assess the risks, and design controls to match.
- Independent auditCorrective and preventive measures after an incident must be reviewed by an independent, accredited expert.
What it costs if you get it wrong
- Fixed maximum fine: NT$15,000,000 — about $480 thousandSerious failure to maintain personal data security, under Article 48 of the Personal Data Protection Act
Sources
- Official sourceFinancial Supervisory CommissionFSC Regulations for Non-government Agencies Designated to Maintain the Security of Personal Data Files, Articles 2, 5 and 6
law.moj.gov.tw
“非公務機關遇有重大個人資料事故者,應依附件格式於七十二小時內通報本會。”
Link checked 18 August 2026
Cyber security rules
Official name: 資通安全事件通報應變及演練辦法 (Regulations on the Notification and Response of Cyber Security Incidents and Drills) · Made under Articles 10(4), 17(4) and 24 of the Cyber Security Management Act; amended 5 January 2026 · Directly binding regulation
These are Taiwan's cyber incident rules, run by the digital ministry. Government bodies and designated critical infrastructure operators get one hour to report an incident. That is one of the shortest deadlines anywhere. This deadline runs alongside the privacy breach deadlines, not instead of them.
Enforced by Ministry of Digital Affairs
What you have to do
- Report cyber incidents — within 1 hourGovernment agencies report to the platform the authority designates within one hour of becoming aware. Designated non-government agencies, which include critical infrastructure operators, report to their industry regulator within one hour.
- Secure the data — within 72 hoursDamage control or recovery must be completed within 72 hours for level one and two incidents, and faster for major incidents.
- Independent auditSocial engineering drills every six months and a notification and response exercise every year.
Sources
- Official sourceMinistry of Digital AffairsRegulations on the Notification and Response of Cyber Security Incidents and Drills, Articles 6, 8, 10 and 11
law.moj.gov.tw
“特定非公務機關知悉資通安全事件後,應於一小時內依中央目的事業主管機關指定之方式,進行資通安全事件之通報。”
Link checked 18 August 2026
Applies to every company3 rules
These bind you whatever business you are in, once the country's rules reach you.
Breach reporting rules
Official name: 個人資料保護法 (Personal Data Protection Act) · Promulgated 11 August 1995 as the Computer-Processed Personal Data Protection Act; renamed and rewritten 26 May 2010; current operative text as amended 31 May 2023 · Act of parliament
This is Taiwan's general privacy law. It applies to organisations outside Taiwan that handle Taiwanese people's data. It requires no paperwork to send data abroad. Supervision is left to whichever ministry regulates your industry. Its most striking feature is criminal liability. Several breaches carry prison sentences, not just fines. Note that the published text includes parts that have never started.
Enforced by Personal Data Protection Commission (Preparatory Office) — not yet operational
How this country controls where data goes: Any country except banned ones · Accepted routes: Nothing required
What you have to do
- Tell people what you doYou must give the collector's name and the purpose. You must also give the categories of data, and the period, place, recipients and ways it will be used.
- Get consent
- Let people see their data — within 360 hoursDecide within 15 days, extendable by 15 more.
- Let people correct their data — within 720 hoursDecide within 30 days, extendable by 30 more.
- Let people delete their data
- Let people objectMarketing must stop on request, and the first marketing contact must offer a free way to refuse.
- Secure the dataArticle 27: adopt appropriate security measures. Your industry authority may order you to write a formal security plan and a plan for handling data after you stop trading.
- Tell affected peopleTell the people affected in a suitable way, once you have established the facts. The Act sets no fixed deadline.
- Delete data after a period
- Written vendor contractA company you hire to handle data is treated as you. You must supervise it properly.
What it costs if you get it wrong
- Criminal liability: 5 years' imprisonment plus a fine up to NT$1,000,000 — about $32 thousandUnlawful collection, processing or use of sensitive or ordinary personal data, or breach of an international transfer restriction order, with intent to gain or harm
- Fixed maximum fine: NT$15,000,000 — about $480 thousandSerious failure of security measures or failure to adopt a required security plan, repeat fines until fixed
- Fixed maximum fine: NT$500,000 — about $16 thousandBreach of an international transfer restriction order, or unlawful collection or use, repeat fines until fixed
- Fixed maximum fine: NT$200,000 — about $6 thousandFailure to give notice, answer access requests, correct data or notify a breach
- Order to stopRegulator may ban collection, processing or use, order deletion of files, confiscate or destroy data, and publish the violation and the responsible person's name
- Claims by individuals: NT$500 to NT$20,000 per person per incident, capped at NT$200,000,000 per incident — about $6 millionDamage claim; the organisation must prove it was not at fault
Sources
- Official sourceLaws & Regulations Database of the Republic of China (Taiwan), Ministry of JusticePersonal Data Protection Act — full text of the version currently in force
law.moj.gov.tw
Link checked 18 August 2026
- Official sourceMinistry of JusticePersonal Data Protection Act — legislative history and commencement record
law.moj.gov.tw
Link checked 18 August 2026
Breach reporting rules (Passed by the Legislative Yuan 17 October 2025; promulgated by Presidential Order 華總一經字第11400114521號 on 11 November 2025; commencement date to be set by the Executive Yuan)
Official name: 個人資料保護法部分條文修正 (Amendment to certain articles of the Personal Data Protection Act) · Passed by the Legislative Yuan 17 October 2025; promulgated by Presidential Order 華總一經字第11400114521號 on 11 November 2025; commencement date to be set by the Executive Yuan · Act of parliament
A large reform package, passed and signed. It would give Taiwan a real national privacy regulator, with breach reporting, audit and inspection powers. It has no legal effect until the Cabinet issues an order setting the start date. As of 18 August 2026 no such order has been issued. Do not plan around this text as if it binds you today.
Enforced by Personal Data Protection Commission (Preparatory Office) — not yet operational
How this country controls where data goes: Any country except banned ones · Accepted routes: Nothing required
What you have to do
- Report breaches to the regulatorNew duty to report incidents to the national commission. Content, method and deadline to be set in a regulation that has not been made. Not yet in force.
- Appoint a data protection officerGovernment agencies must appoint a personal data protection officer. Not yet in force.
- Secure the dataNew Article 20-1 lets the commission issue a single common baseline security regulation for private bodies. Not yet in force.
- Independent auditAnnual implementation reports and audits for government agencies, plus commission audits and on-site inspections. Not yet in force.
- Put a transfer safeguard in placeThe power to restrict international transfers moves from industry ministries to the national commission. Not yet in force.
What it costs if you get it wrong
- Fixed maximum fine: NT$15,000,000 — about $480 thousandSerious breach of security duties, once commenced
- Fixed maximum fine: NT$200,000 — about $6 thousandFailure to report an incident, once commenced
Sources
- Official sourceMinistry of JusticePersonal Data Protection Act — amendment history showing commencement left to the Executive Yuan and effectiveness undetermined
law.moj.gov.tw
“生效狀態:※本法規部分或全部條文尚未生效,最後生效日期:未定”
Link checked 18 August 2026
- Official sourcePreparatory Office of the Personal Data Protection CommissionPress release, 17 October 2025 — what the amendment does and why it cannot start yet
pdpc.gov.tw
Link checked 18 August 2026
General data protection law
Official name: 個人資料保護委員會組織法草案 (Draft Organic Act of the Personal Data Protection Commission) · Approved by the Executive Yuan at its 3945th meeting on 27 March 2025 and sent to the Legislative Yuan; preliminary review completed by the Judiciary and Organic Laws Committee as at 17 October 2025 · Draft law
The law that would actually create Taiwan's national privacy regulator is still a bill. Without it, the Commission has no legal basis to exist. That is why the Commission named in the privacy law has never been set up. It is also why the 2025 privacy amendment has not been switched on. This is a proposal, not binding law.
Enforced by Personal Data Protection Commission (Preparatory Office) — not yet operational
Sources
- Official sourcePreparatory Office of the Personal Data Protection CommissionPress release, 27 March 2025 — Executive Yuan approves the draft Organic Act of the Personal Data Protection Commission
pdpc.gov.tw
Link checked 18 August 2026
- Official sourcePreparatory Office of the Personal Data Protection CommissionPress release, 17 October 2025 — organic act still awaiting further legislative steps
pdpc.gov.tw
“目前組織法草案業經立法院「司法及法制委員會」初審完竣,尚待進一步完成立法程序。”
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.
Whether any specific order restricting international transfer of personal data has been issued under Article 21, and to which countries
We could not confirm whether any orders restricting transfers abroad have been issued. The power itself is confirmed in the statute. Two regulators' own binding rules tell firms to check for such restrictions before transferring, which strongly suggests orders exist. But the National Communications Commission's site returned an access error to us, and its separate legal database was unreachable. So we could not read the text of any individual order. Ask your industry regulator directly before you send data abroad. This is the single biggest gap in this record.
Whether the Executive Yuan has set a commencement date for the November 2025 privacy amendment at any point between 8 and 18 August 2026
We could not confirm the position after 7 August 2026. The national law database records the status as 'not yet effective, date undetermined'. But its content is compiled only up to 7 August 2026, and it refreshes weekly. Check the database for anything issued since.
Whether the Organic Act of the Personal Data Protection Commission passed the Legislative Yuan at any point after March 2026
We could not confirm how far the bill has got. The regulator's own site has published nothing since 9 March 2026. We did not check the Legislative Yuan's bill tracker. Check it if the timing matters to you.
Localisation or storage rules in insurance, securities, education, online gaming, mapping and geospatial data, and defence
We found no rule for these industries, checked 18 August 2026, confidence medium. The financial outsourcing rules we cite are made under the Banking Act. They formally bind banks, credit cooperatives, bills finance companies and credit card institutions. Similar rules almost certainly exist for insurers and securities firms, but we did not find them. We also could not read the National Land Surveying and Mapping Act. If you work in these industries, check before you rely on this.
Enforcement volume — how many fines the sector regulators actually issue each year under the privacy law
We could not confirm how much enforcement actually happens. Both fsc.gov.tw and ncc.gov.tw blocked automated reading, so we could not open penalty registers or statistics. Our 'active' rating rests on the regulators' own binding rules, including the communications regulator's standing fine-scoring system. It is not based on counted decisions. Treat the rating as well-founded but not measured.
Whether the National Health Insurance Data Management Act's thirty-day opt-out window ends on 8 or 9 September 2026
We could not confirm the exact end of the opt-out window. The Act says thirty days from the start date, which was 10 August 2026. It does not say whether the start day counts. Plan for the earlier date.
Whether the replacement rules for electronic payment institutions impose an in-country information system requirement
We could not confirm what replaced the old electronic payment security rules. The Regulations Governing the Standards for Information System and Security Control of Electronic Payment Institutions were abolished on 25 April 2023. We could not find the replacement in the national law database with the search terms available. If you run an electronic payment business, ask the Financial Supervisory Commission.
Freshness and refresh
Freshness
Checked about 2 months ago, on 18 August 2026.
Re-checked every 30 days. Next check due 17 September 2026.