Taiwan

Comprehensive

Personal Data Protection Act (PDPA) 2012 (amended 2023)

Authority: National Development Council / Sector regulators | Enforcement: Active | Enacted: October 2012

Overview

Taiwan's PDPA applies to both public and private sectors. The 2023 amendment established a dedicated data protection authority under the National Development Council. Taiwan has sector-specific enforcement with active compliance expectations.

14-Topic Coverage

Data Protection Authority

Partially Addressed

No single dedicated authority. National Development Council and sector regulators share oversight. Reform to establish dedicated authority.

Data Subject Rights

Fully Addressed

Rights to access, correction, deletion, cessation of collection/processing/use, and supplementation.

Cross-Border Transfer

Fully Addressed

Central authority may restrict transfers to specific countries. International cooperation requirements.

Breach Notification

Fully Addressed

Must notify data subjects after discovery of breach.

DPO Requirements

Partially Addressed

Must designate person for data protection. Larger organisations expected to have formal roles.

Children's Data

Partially Addressed

General provisions apply. No specific age-based threshold.

Penalties & Enforcement

Fully Addressed

Administrative fines up to TWD 50 million. Criminal penalties for certain violations.

Sector-Specific Rules

Fully Addressed

FSC financial data rules, health data regulations, NCC telecom requirements.

AI & Automated Decisions

Partially Addressed

General data protection provisions apply. AI governance framework developing.

Data Localisation

Partially Addressed

Some sector-specific localisation for financial and health data.

Significant Data Fiduciary

Not Addressed

No equivalent concept.

Government Data

Fully Addressed

PDPA applies to government agencies with specific provisions.