Data Security & Breach Notification
Personal Data Protection Act — notification following a personal data breach
Taiwan · October 1, 2012 (Art. 12); the 2025 amendments commence on a date to be set by the Executive Yuan, which had not been set as of September 2026
Verify detailsRead the date line carefully, because Taiwan is mid-transition. The provision in force, Art. 12, requires notifying the DATA SUBJECT after ascertaining the facts where personal data has been stolen, disclosed, altered, or otherwise infringed — there is no general duty to notify a regulator, and no fixed hour count. Amendments promulgated November 11, 2025 change that materially: they establish the Personal Data Protection Commission as a dedicated central supervisory authority and add a duty to notify it, reported at 72 hours from discovery of a qualifying breach. Their commencement, however, is expressly left to the Executive Yuan, and the national law database still records it as undetermined — checked September 2026, so the old regime is what binds today. Marked 'check' on the 72-hour figure rather than on the commencement: that number comes from secondary analyses of the amended text and was not read off the statute, so confirm it before building to it, and do not assume the data-subject duty disappears when the regulator duty arrives.
This is a general reference, not legal advice or a determination that this law applies to your specific business. Run the full questionnaire to check against your actual presence, activities, and data types.