Personal Data Protection Act (個人資料保護法)
Personal Data Protection Act (個人資料保護法) Laws and Regulations Database of the Republic of China (Taiwan), pcode I0050021, as amended effective 2025-10-17
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force 11 months, effective 17 October 2025.
A comprehensive regime rule binding public and private bodies.
As of 22 September 2026.
What it requires
- Collect, process, or use the personal data of an individual in Taiwan only for a specific purpose and on one of the Act's stated lawful bases, and confine use to the purpose stated at collection unless a further basis under Article 16 or 20 applies.
- Notify an affected individual when personal data held has been stolen, altered, damaged, lost, or leaked, and report the incident to the Personal Data Protection Commission where the circumstances fall within the reporting scope the Commission has specified.
- Before transferring personal data outside Taiwan, check whether the Personal Data Protection Commission has restricted that transfer under Article 21.
If you get it wrong
Criminal exposureYes
Private right of actionYes
Criminal exposure note
Intentionally violating Article 6 paragraph 1, Article 15, Article 16, Article 19, Article 20 paragraph 1, or a cross-border transfer restriction under Article 21, for unlawful gain or to harm another, and thereby causing harm, carries imprisonment up to five years and a fine up to NT$1,000,000 (Article 41).
Penalty structure
Administrative fines are tiered by violation: NT$50,000-500,000 for core Article 6/19/20/21 violations (Article 47); NT$20,000-200,000 for lesser notice, correction, or breach-notification procedure violations (Article 48, first tier); and NT$20,000-2,000,000, rising to NT$150,000-15,000,000 for a material violation, for security and maintenance plan failures (Article 48, later tiers). The fixed_cap recorded here is the highest of those bands.
- Rule
- Fixed only
- As of
- 22 September 2026
- Currency
- TWD
- Fixed cap
- 15,000,000
Statutory damages
Article 28's damages formula, extended to non-government agencies by Article 29, sets a floor of NT$500 per data subject per incident where the actual damage cannot be readily proven; the corresponding aggregate per-incident cap is not confirmed here.
- As of
- 22 September 2026
- Currency
- TWD
- Per person minimum
- 500
Who enforces it
Enforcement body
Personal Data Protection Commission (PDPC)
What it reaches
Obligation class
Consent, Data subject rights, Breach notice, Transfer, Security, Reporting
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
The PDPA requires government and non-government agencies alike to collect and process personal data only for a specific purpose and on one of the bases the Act states (Articles 15, 16, 19, 20), notify the data subject when personal data held has been stolen, altered, damaged, lost, or leaked and, in specified circumstances, report the incident to the competent authority (Article 12), and implement security and maintenance measures to prevent theft, alteration, damage, loss, or leakage of personal data files (Article 20-1).
Since an amendment effective October 17, 2025, the Act's competent authority is the Personal Data Protection Commission, an independent agency, which supervises government agencies through periodic and ad hoc audits (Articles 21-1 through 21-5) and may inspect a non-government agency it deems likely to violate the Act (Article 22).
A non-government agency is civilly liable for injury caused by an unlawful collection, processing, or use of personal data (Article 29), with a statutory minimum of NT$500 per data subject per incident where actual damages cannot be readily shown, and 20 or more affected data subjects may delegate a lawsuit to an incorporated foundation or charity (Article 34).
When LexLint raises it
crawls_webtrains_modelsgenerates_contentdeploys_chatbotautomated_outreachhigh_risk_decisionsprocesses_voiceprocesses_biometrics
Read the law
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.