WorldPrivacyAtlas
Laws by country

Data Security & Breach Notification

Personal Data Protection Act — notification following a personal data breach

Taiwan PDPA Art. 12

Taiwan · October 1, 2012 (Art. 12); the 2025 amendments commence on a date to be set by the Executive Yuan, which had not been set as of September 2026

Verify details

Read the date line carefully, because Taiwan is mid-transition. The provision in force, Art. 12, requires notifying the DATA SUBJECT after ascertaining the facts where personal data has been stolen, disclosed, altered, or otherwise infringed — there is no general duty to notify a regulator, and no fixed hour count. Amendments promulgated November 11, 2025 change that materially: they establish the Personal Data Protection Commission as a dedicated central supervisory authority and add a duty to notify it, reported at 72 hours from discovery of a qualifying breach. Their commencement, however, is expressly left to the Executive Yuan, and the national law database still records it as undetermined — checked September 2026, so the old regime is what binds today. Marked 'check' on the 72-hour figure rather than on the commencement: that number comes from secondary analyses of the amended text and was not read off the statute, so confirm it before building to it, and do not assume the data-subject duty disappears when the regulator duty arrives.

Personal Data Protection Act, Art. 12; amendments promulgated November 11, 2025 (commencement date to be set by the Executive Yuan)Read regulation →

This is a general reference, not legal advice or a determination that this law applies to your specific business. Run the full questionnaire to check against your actual presence, activities, and data types.