WorldPrivacyAtlas
Laws by country

Jurisdiction Guides / Asia-Pacific

Taiwan Privacy & Data Protection Laws

Every regime below can apply to a business handling Taiwan residents' data, depending on whether you have an established presence there, actively offer goods or services to residents, or monitor their behavior. This is a general reference, not a determination for your specific business — run the full questionnaire to see which of these actually apply to you.

Comprehensive Privacy Law · 1

October 1, 2012 (2010 revision); the amendments promulgated November 11, 2025 commence on a date to be set by the Executive Yuan, which had not been set as of September 2026
Personal Data Protection Act
Taiwan PDPA
Verify details

Taiwan's PDPA applies to public and private entities collecting, processing or using personal data, with Article 51(2) extending it to the personal data of Taiwan nationals collected, processed or used outside Taiwan by a Taiwanese natural or legal person — a nationality-and-actor anchor rather than a targeting test, so a purely foreign business with no Taiwanese entity is generally outside its reach and the trigger below reflects established presence only. The 2023 amendment removed the previous ceiling on administrative fines and mandated creation of an independent supervisory authority; the Personal Data Protection Commission has been standing up through a preparatory office, and enforcement has until now been distributed across sector regulators. A larger amendment followed on November 11, 2025, rewriting a long list of articles (including Arts. 1-1, 12, 18 and 21-26) and adding new ones to constitute the Commission as the competent authority, centralise supervision, and carry a transition of regulatory authority over a period of years. It is not yet operative: the national law database records its commencement as 'to be determined by the Executive Yuan', and no such date had been set as of September 2026. Plan for two regimes, and confirm the Commission's current operational status before relying on either.

Personal Data Protection Act (promulgated 1995 as the Computer-Processed Personal Data Protection Act; substantially revised 2010, amended 2015, 2023 and 2025), Art. 51(2); Art. 56 (commencement)Read regulation →

Cross-Border Data Transfer · 1

October 1, 2012 (Art. 21); the 2025 amendments commence on a date to be set by the Executive Yuan, which had not been set as of September 2026
Personal Data Protection Act — restrictions on international transmission of personal data
Taiwan PDPA Art. 21
Verify details

Taiwan does not impose a general prohibition on exporting personal data. Art. 21 instead gives the competent authority a discretionary POWER to restrict international transmission in defined circumstances, and that power has historically been exercised sector by sector, by the ministry regulating the industry concerned, rather than through a standing adequacy regime. The practical consequence is the reverse of most regimes here: the default is permission, and the compliance question is whether a restriction has been issued for your sector and destination — which means checking the relevant industry regulator, not a central list. The November 2025 amendments move that power to the new Personal Data Protection Commission, centralising it — but they are not yet operative: the national law database records their commencement as still to be determined by the Executive Yuan, checked September 2026. Marked 'check': the specific statutory grounds on which a restriction may be imposed were not verified against the primary text, and the sector-by-sector inventory of restrictions actually in force could not be assembled from a single source.

Personal Data Protection Act, Art. 21; amendments promulgated November 11, 2025 (commencement date to be set by the Executive Yuan)Read regulation →

Data Security & Breach Notification · 1

October 1, 2012 (Art. 12); the 2025 amendments commence on a date to be set by the Executive Yuan, which had not been set as of September 2026
Personal Data Protection Act — notification following a personal data breach
Taiwan PDPA Art. 12
Verify details

Read the date line carefully, because Taiwan is mid-transition. The provision in force, Art. 12, requires notifying the DATA SUBJECT after ascertaining the facts where personal data has been stolen, disclosed, altered, or otherwise infringed — there is no general duty to notify a regulator, and no fixed hour count. Amendments promulgated November 11, 2025 change that materially: they establish the Personal Data Protection Commission as a dedicated central supervisory authority and add a duty to notify it, reported at 72 hours from discovery of a qualifying breach. Their commencement, however, is expressly left to the Executive Yuan, and the national law database still records it as undetermined — checked September 2026, so the old regime is what binds today. Marked 'check' on the 72-hour figure rather than on the commencement: that number comes from secondary analyses of the amended text and was not read off the statute, so confirm it before building to it, and do not assume the data-subject duty disappears when the regulator duty arrives.

Personal Data Protection Act, Art. 12; amendments promulgated November 11, 2025 (commencement date to be set by the Executive Yuan)Read regulation →

Other Asia-Pacific jurisdictions