Skip to the content
Global Data RulesData governance rules, country by country

Taiwan

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked today.

The answer

Depends on your industryWork: HighEnforcement: Active

Taiwan lets personal data leave the country freely unless the ministry that regulates your industry has issued an order stopping it. There is no single privacy regulator: each industry ministry polices its own sector, and each has written its own security and breach-reporting rules. A big reform that would create one national regulator was passed in November 2025 but has never been switched on.

Eight questions about Taiwan

The questions a team asks when they are deciding where to store their users' data. Every country on this site answers the same eight, in the same order.

Do Taiwan's rules apply to my company?

Yes. Taiwan's privacy law reaches a foreign company with no office and no staff in Taiwan. The law says plainly that it also applies to organisations outside Taiwan that collect, process or use the personal data of Taiwanese people. There is no revenue or headcount threshold to fall below, and the law does not require you to appoint a local representative.

High confidenceNational rulesAll industries

Can I store my users' data outside Taiwan?

In general, yes. Taiwan's privacy law does not ask you to sign anything or get anyone's permission before sending personal data abroad. Instead it gives each industry ministry the power to order that data in its sector may not go to a particular country. But four sectors have real walls, and in two of them the wall is absolute.

High confidenceDepends on your industryBlocklistHealth and social careBankingTelecoms

What do I need in place before data leaves Taiwan?

Under the general law, nothing. No standard contract, no government approval, no adequacy finding, no consent form. The model is a blocklist run sector by sector: you may send data anywhere unless the ministry that supervises your industry has issued an order stopping it. Your real job is to find out which ministry supervises you and check whether it has issued one.

High confidenceBlocklistNothing requiredGovernment sign-off needed

Who enforces the rules in Taiwan, and what can they do?

There is no national privacy regulator in Taiwan today. A Personal Data Protection Commission is named in the law as the authority in charge, but that provision has never been switched on, the law creating the Commission is still only a bill, and what exists is a preparatory office that writes draft rules and cannot fine anyone. Enforcement is done instead by whichever ministry regulates your industry, plus city and county governments, and those bodies are genuinely active.

High confidenceActivePartly in forceProposed

How long do I have to keep the data?

Both directions apply, and the floors are set by other laws, not the privacy law. Accounting vouchers must be kept at least five years and account books and financial statements at least ten years. Medical records must be kept at least seven years, and for children until seven years after they turn eighteen; records from human trials must be kept forever. Going the other way, you must delete personal data once the purpose you collected it for has gone or the period you set has run out.

High confidenceKeep data for a minimum periodDelete data after a periodLet people delete their data

What happens if there is a breach?

Count at least three clocks, and the fastest is one hour. Telecoms companies and larger internet providers must tell the communications regulator within one hour of learning about a major personal data incident, then file a full report within seventy-two hours. Government bodies and designated critical infrastructure operators also have one hour, under the separate cyber security law. Financial firms get seventy-two hours. And under the privacy law itself you must tell the affected people once you have established the facts, with no fixed deadline attached.

High confidenceReport breaches to the regulatorTell affected peopleReport cyber incidents

What trips people up in Taiwan?

Five things that will cost someone their weekend. First, the official English text of the privacy law on the government's own website includes provisions that are not law yet, including the one naming the national regulator. Second, breaking a cross-border transfer order is a crime, not a fine — up to five years in prison. Third, there is no single regulator to ask; your duties depend on which ministry supervises you. Fourth, a bank asked for Taiwanese customer data by a foreign financial regulator must get Taiwan's regulator's permission first. Fifth, if you are sued, you have to prove you were not at fault.

High confidenceCriminal liabilityClaims by individualsDo not hand data to foreign authorities on demandPartly in force

What is changing soon in Taiwan?

One thing has already landed and one is waiting on a switch. The National Health Insurance Data Management Act came into force on 10 August 2026, and it gives people a short window to opt their health records out of research use before silence counts as agreement. Separately, the big privacy reform passed in November 2025 is sitting on the shelf: the Cabinet can bring it into force whenever it likes, by a single order, with no consultation.

High confidencePassed, not yet fully in forceProposedIn force

The rules, layer by layer

Rules stack in layers. Knowing which layer a rule sits in tells you whether your industry, your state, or a contract can override it.

  1. Layer 1

    National rules

    Added by this country on top of any bloc rules.

    3 rules here

  2. Layer 2

    Industry rules

    Made by an industry regulator. These usually beat the general position.

    6 rules here

Read the stack from the top down. Anything lower normally wins: an industry rule beats the national position, and the national position sits on top of the bloc rules.

National rules3 rules

個人資料保護法 (Personal Data Protection Act)

Act of parliament · Promulgated 11 August 1995 as the Computer-Processed Personal Data Protection Act; renamed and rewritten 26 May 2010; current operative text as amended 31 May 2023

Partly in forceYes — store it anywhere

Taiwan's general privacy law. It applies to organisations outside Taiwan that handle Taiwanese people's data, requires no paperwork to send data abroad, and leaves supervision to whichever ministry regulates your industry. Its most striking feature is criminal liability: several breaches carry prison sentences, not just fines. Beware that the published text includes provisions that have never commenced.

In force since 1 October 2012

Enforced by Personal Data Protection Commission (Preparatory Office) — not yet operational

Transfer model: Blocklist · Accepted routes: Nothing required

High confidence

個人資料保護法部分條文修正 (Amendment to certain articles of the Personal Data Protection Act)

Act of parliament · Passed by the Legislative Yuan 17 October 2025; promulgated by Presidential Order 華總一經字第11400114521號 on 11 November 2025; commencement date to be set by the Executive Yuan

Passed, not yet fully in forceYes — store it anywhere

A large reform package, passed and signed, that would give Taiwan a real national privacy regulator with breach reporting, audit and inspection powers. It has no legal effect until the Cabinet issues an order setting the start date, and as of 18 August 2026 no such order has been issued. Do not plan around this text as if it binds you today.

Enforced by Personal Data Protection Commission (Preparatory Office) — not yet operational

Transfer model: Blocklist · Accepted routes: Nothing required

High confidence

個人資料保護委員會組織法草案 (Draft Organic Act of the Personal Data Protection Commission)

Draft law · Approved by the Executive Yuan at its 3945th meeting on 27 March 2025 and sent to the Legislative Yuan; preliminary review completed by the Judiciary and Organic Laws Committee as at 17 October 2025

ProposedNot yet established

The law that would actually create Taiwan's national privacy regulator is still a bill. Without it the Commission has no legal basis to exist, which is why the Commission named in the privacy law has never been set up and why the 2025 privacy amendment has not been switched on. This is a proposal, not binding law.

Enforced by Personal Data Protection Commission (Preparatory Office) — not yet operational

Medium confidence

Industry rules6 rules

醫療機構電子病歷製作及管理辦法 (Regulations Governing the Production and Management of Electronic Medical Records by Medical Institutions)

Directly binding regulation · Article 8, made under Article 69 of the Medical Care Act; amended 18 July 2022 · Health and social care

In forceNo — it stays put

Where a hospital or clinic uses cloud services for electronic medical records, the data must be stored inside Taiwan. The only way out is a case-by-case approval from the health ministry for special circumstances. The cloud provider must also be certified against a security standard the ministry recognises.

In force since 18 July 2022

Enforced by Ministry of Health and Welfare

Transfer model: Approval each time · Accepted routes: Government sign-off needed

High confidence

全民健康保險資料管理條例 (National Health Insurance Data Management Act)

Act of parliament · Promulgated by Presidential Order 華總一義字第11400129981號 on 19 December 2025; brought into force by Executive Yuan Order 院臺衛字第1151018599號 of 6 August 2026 · Health and social care

In forceNo — it stays put

Taiwan's answer to a 2022 Constitutional Court ruling that the health insurance database had no proper legal basis and no opt-out. It creates one: research use is limited to Taiwanese institutions, must happen inside a designated secure environment, cannot be commercial, and every insured person can block their own records. It started on 10 August 2026 and the first opt-out window is short.

In force since 10 August 2026

Enforced by National Health Insurance Administration

Transfer model: Not allowed

High confidence

金融機構作業委託他人處理內部作業制度及程序辦法 (Regulations Governing Internal Operating Systems and Procedures for the Outsourcing of Financial Institution Operation)

Directly binding regulation · Articles 17 to 20, made under Article 45-1(3) of the Banking Act and Article 21(4) of the Credit Cooperatives Act; amended 13 April 2026 · Banking

In forceA copy must stay

Taiwan's banks and credit card issuers can process customer data offshore, but not freely. Anything material in consumer finance needs the financial regulator's advance approval, the data should in principle stay in Taiwan, and if it goes abroad a Taiwanese backup of important customer data is compulsory unless the regulator says otherwise.

In force since 13 April 2026

Enforced by Financial Supervisory Commission

Transfer model: Approval each time · Accepted routes: Government sign-off needed, Security review needed

High confidence

Who you would hear from

  • 個人資料保護委員會籌備處

    Named in the privacy law as the national competent authority; in practice only drafts rules

    The Commission itself does not exist. The provision naming it as competent authority was added on 31 May 2023 but has never commenced, and the organic act needed to create it is still a bill. What exists is a preparatory office, set up under provisional organisation rules of 23 September 2023, which took over two narrow rule-making functions from the National Development Council on 1 January 2024. It cannot fine, order or inspect. Its most recent published announcement is dated 9 March 2026.

  • 金融監督管理委員會

    Banking, payments, insurance, securities; personal data supervision of the firms it licenses

    Issues binding outsourcing and personal data security regulations, approves offshore processing case by case, and takes incident reports within 72 hours.

  • 國家通訊傳播委員會

    Telecommunications, broadcasting and internet access; personal data supervision of communications enterprises

    Runs a one-hour breach reporting regime and maintains a standing scoring framework for setting fines on communications enterprises that breach the privacy law, referenced inside its own binding regulation.

  • 衛生福利部

    Health and social care; electronic medical records; health insurance data policy

  • 衛生福利部中央健康保險署

    National health insurance records, secondary-use approvals and the opt-out register

    Operates the opt-out service through which insured people can block secondary use of their health insurance data.

  • 數位發展部

    Cyber security law, incident reporting for government bodies and critical infrastructure

  • 憲法法庭

    Constitutional review; ruled in 2022 that Taiwan's lack of an independent data protection supervisor is constitutionally deficient

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.

  • Whether any specific order restricting international transfer of personal data has been issued under Article 21, and to which countries

    The mechanism is confirmed from the statute, and two regulators' own binding rules order firms to check for such restrictions before transferring, which strongly implies orders exist. But the National Communications Commission's site returned an access error to our fetcher and its separate legal database was unreachable, so we could not open the text of any individual order. The transfer blocklist is therefore recorded as populated-unknown rather than empty. This is the single biggest gap in this record.

  • Whether the Executive Yuan has set a commencement date for the November 2025 privacy amendment at any point between 8 and 18 August 2026

    The national law database records the status as 'not yet effective, date undetermined', but its content is compiled only to 7 August 2026 and refreshes weekly. We cannot prove a negative for the eleven days since.

  • Whether the Organic Act of the Personal Data Protection Commission passed the Legislative Yuan at any point after March 2026

    The regulator's own site has published nothing since 9 March 2026, and its news list is rendered by JavaScript so we could only read the items exposed on the homepage. We did not separately check the Legislative Yuan's bill tracker.

  • Localisation or storage rules in insurance, securities, education, online gaming, mapping and geospatial data, and defence

    No rule found, checked 18 August 2026, confidence medium. The financial outsourcing rules we cite are made under the Banking Act and formally bind banks, credit cooperatives, bills finance companies and credit card institutions; parallel instruments almost certainly exist for insurers and securities firms but we did not locate them. Our attempt to read the National Land Surveying and Mapping Act returned no usable text. Absence of a finding here is a gap, not a clearance.

  • Enforcement volume — how many fines the sector regulators actually issue each year under the privacy law

    Both fsc.gov.tw and ncc.gov.tw blocked automated fetching, so we could not open penalty registers or statistics. The 'active' enforcement rating rests on the regulators' own binding regulations, including the NCC's standing fine-scoring framework, rather than on counted decisions. Treat the rating as well-founded but not quantified.

  • Whether the National Health Insurance Data Management Act's thirty-day opt-out window ends on 8 or 9 September 2026

    The Act says thirty days from commencement, which was 10 August 2026, but does not state whether the day of commencement counts. Plan to the earlier date.

  • Whether the replacement rules for electronic payment institutions impose an in-country information system requirement

    The Regulations Governing the Standards for Information System and Security Control of Electronic Payment Institutions were abolished on 25 April 2023 and we could not locate the successor instrument in the national law database using the search terms available.

30-day cadence. Two things can change this record overnight with a single order and no consultation: the Executive Yuan setting the commencement date of the November 2025 privacy amendment, which would create a national regulator and move the cross-border transfer power to it, and any industry ministry issuing a transfer restriction order under Article 21. A third date is fixed and imminent: the health insurance opt-out window closes in early September 2026.

Freshness and refresh

Freshness

Checked today — on 18 August 2026.

Re-checked every 30 days. Next check due 17 September 2026.

Read the exact prompt used to research this page

Compare with

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.