Data protection compliance in Taiwan cannot be achieved with a privacy policy alone. Before collecting data, you must specify the purpose and confirm the statutory grounds for collection, processing and use. Data later used for marketing or AI training, transferred to a cloud provider or sent overseas is not automatically covered simply because consent was obtained once. Cookies, IP addresses and other indirectly identifiable data must be assessed by how they are actually linked. This section covers notice duties, data-subject rights, vendor oversight, sensitive data, cross-border transfers, breach reporting and enforcement trends. It helps you map each data flow and determine where notice, consent, restrictions or records are required. SUNRISE Media plans and produces this column for Startup Island TAIWAN. Expert review | Legal: Zhong Yin Law Firm · Finance and tax: urCFO This column is based on the laws of Taiwan as of August 2026. Subsequent amendments are not reflected. Individual cases still require assessment by a lawyer or an accountant.
Startup Island TAIWAN connects startups with recruitment channels, talent development programs, and ecosystem partners. Resources include university networks, startup job platforms, community events, and government-supported initiatives designed to help companies attract and retain talent in Taiwan.
Yes. Under Taiwan's Personal Data Protection Act (PDPA), “personal data” includes data that identifies a person indirectly: a single record does not reveal who someone is, but the person becomes identifiable once the record is matched, combined, or linked with other data. Taiwan's competent authority readily treats cookies, dynamic IP addresses, and device IDs as this type of data. Even after pseudonymization or hashing, if the data can still be traced back to a specific person, the company must complete the same notification and consent obligations.
Why It MattersArticle 2, Subparagraph 1 of the PDPA (the provision that defines personal data) and Article 3 of its Enforcement Rules base the test on whether a person can be re-identified, not on whether a name appears. A foreign company that applies GDPR instincts in Taiwan tends to misjudge the following questions: 1.What counts as personal data? Data that can identify a specific person after being matched, combined, or linked with other information (a membership database, telecom records) is personal data. 2.Who must be able to identify the person? The law does not require that anyone could identify the person. It is enough that the company holding the data, or a specific third party, can restore the link with technical means. 3.Does pseudonymization or hashing take data out of the PDPA? No, not while re-identification remains objectively possible. Foreign companies often assume pseudonymized data falls outside the PDPA; in Taiwan practice, if an ID still maps to one person's behavioral trail and that trail leads back to a natural person, the authority leans toward treating it as personal data. For example, running the same algorithm on both datasets is enough to match the same person. 4.Dynamic IP addresses: The competent authority has held that dynamic IP addresses are personal data, because the data holder (or its partners) can reasonably obtain matching data and identify the person (citing the CJEU judgment in Case C-582/14, Breyer).
What To Do1.Inventory data by asking “who does this lead back to,” not “does it contain a name.” List every data item your website collects and ask, item by item: once matched against a membership database, advertiser data, or telecom records, can it identify a specific person? If yes, manage it as personal data. 2.Test what de-identification actually achieves. Apply one standard to pseudonymization, hashing, and encryption: is re-identification still objectively possible? If running the same algorithm on both datasets matches the same person, the data remains under the PDPA. 3.Notify before you collect. State every collected item in the privacy policy, including browsing records and device identifiers, and place a prominent cookie banner on the homepage stating the purposes and categories of collection. If data comes from a parent company or a local partner, the company must also tell users where the data came from (see Q4). 4.Let users refuse collection. Give users a control in the cookie banner or privacy settings; once they click it, the company stops collecting their browsing records (this is the opt-out). Collect only the items the service needs. The legal basis is Article 5 of the PDPA: collection and use must not exceed the scope of the specific purpose (the principle of proportionality) and must be conducted in good faith. Case A foreign company embedded tracking code across multiple Taiwanese websites, collected users' browsing behavior, generated “interest tags,” and assigned each browser a unique ID. The company argued that it never collected names or phone numbers, so the PDPA did not apply. It therefore gave no notification for indirect collection, and its privacy policy never stated that browsing records were among the items collected. The problem was the unique ID. The number means nothing by itself, but it continuously tracks one person's behavior, and it can be matched and combined with member data held by advertisers until it identifies a specific person. The competent authority therefore treated it as indirectly identifying personal data. The remediation was concrete: the company redesigned its notification flow, placed a prominent cookie banner on its homepage stating the purposes and categories of collection, and added an opt-out, bringing its data collection back within Article 5's requirements of proportionality and good faith.
No, not as it stands. Foreign companies tend to hold one of two extreme misconceptions about Taiwan's Personal Data Protection Act (PDPA). Some assume Taiwan runs on the same rules as the EU, publish the headquarters' GDPR-based privacy policy on their Taiwan site as is, and end up omitting the specific notification items the PDPA separately requires. Others assume Taiwan regulates lightly and never draw up the personal data security maintenance plan their competent authority requires. What Taiwan actually does: most day-to-day collection stands on performance of a contract, so a company does not need the user's consent for every piece of data. The requirements on security maintenance and on criminal liability, though, run stricter than most foreign companies expect. Taiwan's PDPA differs from the GDPR and the APPI in at least three respects. First, a foreign company in Taiwan does not answer to a single independent regulator; it answers to the central government authority in charge of its industry. Second, for special categories of personal data such as medical records and genetic data, Taiwan requires written consent, and the company has to keep a verifiable signature record. Third, beyond administrative fines, an individual who acts with unlawful intent may face criminal liability of up to five years imprisonment.
Why It MattersReading the PDPA alone is not enough. Taiwan still regulates in a distributed way, so a company has to look up the administrative order that matches the category of business it runs in Taiwan (retail, telecommunications or finance, for example), or it will be penalized for failing to draw up the security maintenance plan its particular industry requires. The differences go beyond those three. Together with how specific the notification has to be, and whether the data has been organized into a database, there are five areas in all: 1.Who regulates a foreign company? Both the GDPR and the APPI have an independent supervisory authority: the data protection authorities (DPAs) of the EU member states, and Japan's Personal Information Protection Commission (PPC). Taiwan still regulates in a distributed way, with each industry's central government authority in charge (the Ministry of Economic Affairs, the Financial Supervisory Commission and the Ministry of Health and Welfare, for example) issuing its own security maintenance regulations. 2.How specific the notification has to be?Article 8 of the PDPA, the provision on notifying users at the point of collection, requires a company to expressly notify six statutory items when it collects the data, among them the specific purpose and the time period, area, recipients and manner of use. A foreign company that applies its global privacy policy as is may fall short of full notification because it never spells out the recipients of the data or the specific purpose. 3.How consent works for special categories? The GDPR asks for explicit consent for sensitive personal data such as health data. Article 6 of the PDPA asks for written consent. Practice has relaxed this to electronic signatures, but a bare checkbox with no adequate electronic signature record still carries a compliance risk where medical, genetic or criminal record data is involved. 4.What follows a violation?The GDPR ceiling is EUR 20 million or 4% of worldwide turnover. Taiwan's administrative fine runs from NT$20,000 to NT$2 million, rising to between NT$150,000 and NT$15 million where the circumstances are serious, and it can be imposed again for each continuing violation. Read the two ceilings with their currencies attached: in real money they sit far apart, and Taiwan's is the lower one. Article 41 of the PDPA additionally retains criminal liability: an individual who acts with the intent to impair the interest of others or to gain unlawful benefits for himself or herself (not limited to financial benefits), and who violates the PDPA, may face imprisonment of up to five years. This puts considerable legal pressure on the foreign company's responsible person in Taiwan, such as a branch manager. 5.Whether the data sits in a database? Japanese companies often assume that data which never went into a database (paper records, or scattered data that was never filed) falls outside the rules. Taiwan's PDPA takes the broad definition: any data from which a person can be identified directly or indirectly is protected, whether or not it has been organized into a database. Taiwan is also easier than the GDPR in two respects. First, most day-to-day collection stands on performance of a contract, so a company does not have to design a consent flow for every piece of data. Second, the 2015 amendment narrowed criminal liability to acts carried out with the intent to gain unlawful benefits for oneself or a third person, or to impair the interest of others, which sharply reduced the risk that a foreign company's responsible person commits a criminal offense through an administrative oversight.
What To DoBuild your Taiwan compliance program in this order: 1.Identify which central government authority in charge of the industry your business falls under. Work from the category of business your company runs in Taiwan (retail, telecommunications or finance, for example), find the authority in charge, and look up the security maintenance regulations it has issued. Reading the PDPA itself is not enough; the concrete security requirements sit in that administrative order. The good news is that you do this once, and you will not have to repeat it as long as your registered business scope stays the same. 2.Draw up the security maintenance plan, appoint dedicated personnel and keep records of regular audits, following that authority's regulations. Taiwan's authorities, among them the Ministry of Digital Affairs and the Ministry of Economic Affairs, have broad power to open an inspection on their own initiative once a data breach makes the news. A foreign company that has not appointed dedicated personnel or carried out regular audits under its industry's regulations can be penalized for inadequate security measures even where no breach has occurred. 3.Check whether performance of a contract works before you reach for consent. Under Articles 19 and 20 of the PDPA, a contract or a quasi-contract relationship (negotiations before signing, for example) is itself a lawful ground for collection and use, and no separate consent is needed. Where the data is necessary to perform the contract (e-commerce delivery or after-sales service, for example), rely on Article 19, Subparagraph 2 rather than forcing users to tick a consent box. Leaning too heavily on consent only adds to the company's burden of proof. (For the full order of analysis, see Q3.) 4.Rewrite the global privacy policy into a Taiwan version. Work through the six statutory notification items in Article 8, Paragraph 1 of the PDPA and spell out the recipients of the data and the specific purpose. Translating the English policy into Chinese does not make it meet Taiwan's notification requirements. This is a one-off documentation exercise, and it stays settled once done. (For the four items foreign companies most often miss, see Q4.) 5.If your company handles special categories of personal data, prepare a separate written consent. For the six categories, which are medical records, healthcare data, genetic data, data concerning a person's sex life, records of physical examination and criminal records, consent cannot sit inside the general terms of service. It needs its own signature or checkbox field, and a verifiable record. If your company does not handle these six categories, you can skip this step. 6.Make sure the responsible person in Taiwan understands what triggers criminal liability. Article 41 of the PDPA applies to the individual who commits the act, not to the company. It is triggered where that individual acts with the intent to impair the interest of others or to gain unlawful benefits for himself or herself, and violates the PDPA. Who decides and who actually handles personal data inside your Taiwan organization has a direct bearing on who counts as that individual. The GDPR has no equivalent provision, and headquarters compliance training usually does not cover it. 7.If you are a Japanese company, do not judge by whether the data has been filed into a database. Taiwan draws no line between structured and unstructured storage. Paper lists and scattered contact details are protected under the PDPA just the same, as long as a person can be identified from them. Case A foreign company runs mobile phone retail in Taiwan and also handles telecom subscriptions on behalf of carriers. After a personal data breach, the first question the company had to answer internally was this: which authority do we report to? Under the current distributed regulation, the answer turns on which line of business is involved. For the part involving controlled telecommunications equipment, the authority is the National Communications Commission (NCC); for ordinary retail of communications equipment, it is the Ministry of Economic Affairs. Two lines of business in one company, two authorities in charge. A company that has not worked out in advance which authority oversees each of its lines of business will spend the hours after an incident working out where to report, and that delay itself draws a penalty.
No, you do not need consent for every item. Foreign companies' legal teams tend to hold one of two opposite misconceptions about Taiwan's Personal Data Protection Act (PDPA). Some insist on obtaining explicit consent before storing any user data, which stalls marketing and business operations. Others assume that consent settles everything, and bundle data unrelated to the service into the consent terms. What Taiwan actually requires is this: collecting personal data calls for a specific purpose plus one of the grounds listed in the statute, and consent is only one of those grounds. Apart from consent, the three grounds most useful to foreign companies, and the ones to check first, are a contract or quasi-contract relationship with the user, an express provision of law, and no infringement of the user's rights and interests.
Why It MattersUnder Article 19 of the PDPA (the grounds on which a non-government agency may collect and process personal data), a company that wants to collect an item of personal data must have a specific purpose and must meet one of the circumstances the article lists. Obtaining consent (Article 7) is one of those circumstances; meet any of the others and the company may collect the data lawfully, without seeking separate consent. Legal teams at foreign companies often read this article as consent or nothing, design every collection point around a consent checkbox, and stall marketing and business operations. In practice, the three grounds below are the ones foreign companies rely on most: 1. A contract or quasi-contract relationship with the user (Article 19, Paragraph 1, Subparagraph 2). This covers e-commerce delivery, providing a SaaS service, fulfilling membership obligations, and interviewing job applicants, which counts as a quasi-contract. The condition is that the data must be necessary to perform the contract: an address is necessary to deliver. 2. An express provision of law (Article 19, Paragraph 1, Subparagraph 1). This covers keeping transaction records under tax law and keeping employee records under the Labor Standards Act. The condition is that it reaches only the items and the retention period that the law expressly requires. 3. No infringement of the user's rights and interests (Article 19, Paragraph 1, Subparagraph 8). This covers internal administration, and minor uses that are not sensitive and do not affect the user's rights and interests. This subparagraph is a catch-all and looks like the widest of the three, yet practice reads it very narrowly; once marketing, tracking, or sharing data with a third party is involved, it will usually not hold. Where these three grounds apply, a company does not have to build a consent checkbox flow around every item of data.
What To DoWork through the following order, then decide whether you need consent: 1. Start by asking whether the data is necessary to perform the contract. E-commerce delivery, providing a SaaS service, fulfilling membership obligations, and interviewing job applicants, which counts as a quasi-contract, all fall under Article 19, Paragraph 1, Subparagraph 2 of the PDPA. The test is necessity: an address is necessary to deliver, and data unrelated to performing the contract cannot ride along. 2. Check the collection against the proper and reasonable connection standard. That standard asks whether the collection is logically necessary to the purpose of the contract. Where filling station operators insisted on writing the license plate number on the credit card slip, the competent authority held that this bore no relation to performing the fuel purchase contract and was not necessary, and that no separate consent had been obtained, so the practice was unlawful. 3. Define the scope of the service clearly in your terms of service. A foreign company should set out what the service covers in its terms of service (ToS), so that the act of collecting data connects directly to performing the contract. 4. Map Taiwan's local statutes, and keep statutory retention separate from consent. A foreign company's branch in Taiwan should map the local statutes that apply to it, the Money Laundering Control Act and the Tax Collection Act among them, and keep this category of collection separate from consent, so that a user withdrawing consent does not put the company in breach of other statutes. 5. Before you market, separate use within the purpose from use beyond it. Where the marketing has a proper and reasonable connection to the product under the original contract, such as offering ink to someone who bought a printer, it is use within the specific purpose under Article 20 of the PDPA and no separate consent is needed. Where the product is entirely unrelated, such as offering insurance to someone who bought a printer, it is use beyond the specific purpose, and you must obtain a separate, standalone consent. 6. Do not bundle non-essential collection into consent. Tying the collection of non-essential data to switching the service on, and forcing users to consent, may be held to breach the principle of proportionality or the principle of good faith, and may even fall foul of the obviously unfair provisions of the Consumer Protection Act. Which ground a particular collection falls under depends on how your terms of service are written, and on how directly that item of data connects to the purpose of the contract. Case: The head of a staffing agency also held a second, ordinary company. The online job bank charged the two types of account differently and gave them different levels of access to resumes: the ordinary company paid less and held different permissions from an agency. He signed up with the job bank in the name of that ordinary company, downloaded applicants' resumes through the ordinary company's account, and used them for matching work in his own staffing agency. The court held that although the resumes had been obtained through a lawful channel, he had used the data for a purpose outside what had been agreed, and had done so intending to obtain unlawful benefit, which amounted to an offense under Article 41 of the PDPA.
No. Where users filled in the list themselves, the company must provide notice covering all six items under Article 8. Where someone else passed the list on, the company must provide the first five of those items and also state where the data came from. Foreign companies operating in Taiwan commonly assume that because the list came from a partner or from headquarters, because that party obtained consent at the time, and because the company already has a privacy policy on its own website, the Taiwan entity does not need to take any further action. The duty to inform under Taiwan's Personal Data Protection Act (PDPA) rests with the company that actually uses the data. Whether or not the upstream partner or the overseas headquarters obtained user consent, the company using the list in Taiwan must still provide its own notice.
Why It MattersTaiwan's PDPA distinguishes between two types of collection and governs them under different articles. Where users provide their data to a company directly, Article 8 applies. Where the data does not come from the users but is obtained from a partner, an overseas headquarters, or another third party, Article 9 applies. The law refers to this as indirect collection. For direct collection from users, Article 8, Paragraph 1 requires a company to expressly inform the data subject of six items at the time of collection: (1) the name of the company, (2) the purpose of collection, (3) the categories of personal data collected, (4) the time period, area, recipients and manner of use, (5) the data subject's rights under Article 3 and the methods for exercising them, and (6) the effect on the data subject of electing not to provide the data. These six items can sit in a single notice document, such as the privacy policy on the company website, and preparing it is a one-time exercise. The notice is complete only when the data subject can actually see that document at the point of collection. Where the data does not come from the users directly, Article 9 requires the company using it to inform the data subject of the first five items listed above, plus one further item: the source of the personal data. This is the item foreign companies most often omit when they apply a global privacy policy unchanged. As to timing, the notice must in principle be given before use. The statutory wording is "before the processing or use." Article 9, Paragraph 3 allows the notice to be given together with the first use of the data in relation to the data subject, and this is the provision that matters most in practice.
What To DoIf your company receives a list passed on by someone else, work through the following steps. 1. First, establish which role you are in. If you are only processing the data as a party commissioned by your overseas headquarters, the law treats the use as headquarters' own, and no separate duty to inform users of the source arises. But once you take the list from headquarters for your Taiwan company's own operations, this is indirect collection, and at the first use you must tell users that the source of the data is the parent company. 2. You do not have to delay a launch to give notice. For indirectly collected data, the notice may be provided at the time of first use. In the first marketing email you send or the first call you make, you can give notice of the source and the matters listed in Article 8, Paragraph 1, Items 1 through 5. The required notice may take more than one sentence. There is no need to send a notice letter first and a marketing message afterward. 3. Do not assume that because the party sharing the data, such as the parent company, already obtained consent, you have no duty to inform. In practice you will usually need to show that users actually knew that you, meaning the Taiwan subsidiary, would receive the data. The kind of evidence that works is a contract the user signed with the third party whose terms state that the data will go to the company now using it and list every item to be notified. A vague line in a third party's privacy policy saying the data "may be shared with partners" may fall short of actual knowledge in the eyes of a Taiwanese court. 4. Finally, fill the gaps in your global privacy policy. Check it item by item against Articles 8 and 9. Four areas are where foreign companies most often fall short. (1) What users actually do when they want to access, correct or delete their own data. "Contact us" is not enough. The policy must give the channel, such as a specific web address, a form, or a dedicated line. (2) For data collected directly from users, what happens if users elect not to provide the data. The policy must set out the consequences, such as being unable to register, unable to receive a delivery, or unable to claim a discount. (3) Which recipients receive the users' data and which areas it is used in. "Global affiliates" is too vague. The policy must list them, such as the location of the parent company and the third-party vendor providing cloud services. (4) Where the user data the company holds was obtained from. Where the list did not come from the users themselves, the policy must state the source of the data. Case: A company obtained a marketing list made up of data on friends and relatives supplied by its own other users. The company took the view that the data had been volunteered by its users and was lawfully sourced, and used it for marketing immediately. Even where data is supplied by a third person, the company is the collector, and under Article 9 of the PDPA it must still inform the data subject of the source of the personal data and the other statutory items before the processing or use. The company could not show that the data subject had actual knowledge of its collection, and it had not given notice. The only opportunity for complete compliance was to give notice together with the first use. Once the first use had been completed without notice, the violation had already occurred. Before the data subject requested deletion, the company could still try to give late notice or obtain consent to reduce the legal risk; once the data subject exercised the right to deletion, however, the company had to delete that person's personal data.
The notice cannot wait. The rest can follow the stages of your operation. Taiwan's Personal Data Protection Act (PDPA) turns on the act of collection, not on whether a company has been incorporated. The privacy notice has to be ready before you collect the first piece of personal data from a person in Taiwan. The duty begins the moment that data is collected, not on the day company registration is completed. A common assumption is that while the Taiwan entity is not yet incorporated and not yet operating, the privacy policy can wait until launch, and that only a handful of email addresses are being collected in the meantime. But even a pre-launch sign-up form amounts to collection once it takes in the name or contact details of a person in Taiwan, and the duty to inform under Article 8 arises with it.
Why It MattersThe PDPA applies on the basis of acts of collecting, processing or using personal data, and does not depend on whether the Taiwan entity has been incorporated. Even a pre-launch sign-up form on a website, for example one that lets visitors leave their details to receive a launch notice, already amounts to collection once it involves the name or contact details of a person in Taiwan. The first risk of collecting personal data before the Taiwan entity is incorporated is that the identity of the collector is unclear. The privacy notice has to state the name of the company collecting the data, and while that company is not yet registered the field is often left vague. The notice is then incomplete, which in turn affects the lawfulness of the collection. Before incorporation is completed, the notice may name the company's preparatory office. If no entity has yet been established in Taiwan and the overseas parent is collecting the data first for market research or advance service reservations, the notice should name the overseas parent. If the data will later be transferred to the Taiwan subsidiary after it is established, the notice must include the Taiwan subsidiary among the recipients. The second risk is purpose drift. Where a list is collected for the stated purpose of a product launch and is later used to market financial products or sold on, using it without obtaining fresh consent amounts to use beyond the stated purpose: use for a purpose that was not disclosed at the outset. The two risks have something in common. Both arise while the Taiwan entity is not yet set up and the team's attention is still on the market and the product.
What To DoData protection compliance when entering the Taiwan market can be arranged in four stages, with minimum requirements at each stage. 1. The assessment stage. What you are doing is market research, pre-launch promotion, and gathering prospective customer contacts. Two things have to be done at this stage: the website needs a privacy policy that meets Article 8, and the collection form must display the required notice while the company retains a record of each user's consent. 2. The setup stage. What you are doing is choosing an office, hiring your first employees, and finding local third-party vendors. At this stage, provide applicants and employees with the applicable personal data notice and obtain their acknowledgment, and put in place a commissioning agreement with the local vendors that provides for proper supervision. 3. The start of operations. What you are doing is launching the product, handling transactions, and running marketing campaigns. Two things need attention. First, if your industry is one for which the law requires it, put in place a personal data file security maintenance plan, a security management document that the competent authority requires specified businesses to draw up. The required scope of the plan depends on the industry, and which central government authority in charge of the industry regulates your business will directly determine what goes into it. Second, marketing has to stay within the specific purpose stated at the outset, and users must have a way to refuse further marketing. 4. The scale-up stage. What you are doing is the international transmission of personal data, in other words moving it across borders, and integrating group resources. Two points deserve particular attention: review the lawfulness of the international transmission and check whether the competent authority has imposed any restriction on transmission of this kind, and conduct a personal data impact assessment to confirm that there is a basis for using the data for any purpose not disclosed at the outset. Of these four stages, foreign companies most often overlook the importance of the first. The list used for the first wave of marketing is usually shared within the group, bought from a third party, or supplied by a partner, so the duty under Article 9 to tell users where indirectly collected data came from often arises before company registration is even complete. (For what users have to be told about a list passed on by someone else, see Q4.) 5. The last thing is to keep the records from the four stages above. This matters for companies that intend to raise funds or be acquired in Taiwan, because at the due diligence stage the counterparty's Taiwan counsel will go through four items one by one: (1) whether the notices under Articles 8 and 9 were given, and whether there are system logs showing that users checked the consent box, (2) whether a security maintenance plan was drawn up as the competent authority requires, (3) whether there is a record of periodic checks on third parties commissioned to process personal data, such as cloud service providers and marketing agencies, and (4) whether personal data has been sent back to the parent company and whether that complies with Article 21. Case: (The following scenario is fictional and is used to illustrate how the legal analysis is structured.) A foreign company had not finished setting up its Taiwan entity when it published a pre-launch sign-up form on its website, taking in the names and email addresses of visitors in Taiwan who wanted a launch notice. The notice on the form identified the collector only by the group's English-language name, and which entity would operate in Taiwan had not yet been decided. After the entity was set up, the company put the list to a different use: marketing a financial product that the pre-launch page had never mentioned. What the users had agreed to was a launch notice, not a pitch for a financial product. That list was the company's earliest core customer list. The notice was incomplete at the outset and the later use went beyond what had been disclosed, so the collection itself was defective and every subsequent use was unlawful. Ultimately, that specific customer list, which was unlawfully collected and used through the pre-launch form, may have to be removed from the company's customer relationship management system (CRM, the system where a company keeps its customer lists and its records of dealings with them) and destroyed, and may no longer be retained or used. Other data in the system that was lawfully collected is not affected.