Law / Taiwan

Taiwan

4 of 5 named instruments researched to a stage, across one of the six areas of law we track: 4 in force. As of 19 September 2026.

  1. AI law none researched
  2. Privacy law none researched
  3. Scraping law none researched
  4. Cybersecurity law 4
  5. Age gating law none researched
  6. News aggregation law none researched

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Cybersecurity law4 instruments, 4 in force

Research summary (838 words)

Taiwan's primary cyber-resilience statute, the Cyber Security Management Act (資通安全管理法, Cyber Security Management Act, pcode A0030297), was replaced in full on Sept. 24, 2025 and took effect Dec. 1, 2025 under the Ministry of Digital Affairs (MODA) as competent authority.

Chapter III binds a 'Specific Non-Government Agency,' a term the Act defines to mean 'a critical infrastructure provider, a government-owned enterprise, a designated foundation, or any enterprise, organization, or institution under control of the government' (Art. 3(6)), with a critical infrastructure provider's own class turning on the Executive Yuan's periodic designation of a physical or virtual asset, system or network whose disruption would significantly affect national security, the public interest, daily life or economic activity (Art. 3(7)-(8)).

Every such agency must formulate, implement and report on a cyber security maintenance plan matched to a government-assigned responsibility level, appoint a dedicated Chief Information Security Officer, and submit to periodic audits (Arts. 7-8, 20-23, 30), and must separately maintain a notification and response mechanism and report a cyber security incident to the sector's own central competent authority as soon as it becomes aware of one (Arts. 24, 29).

Because a designated critical infrastructure provider is precisely the cross-sector essential-infrastructure-operator shape this corpus's activity vocabulary expresses through its general essential-service-operator role rather than through any single sector flag, both duties are flagged here; the Act's other named classes, a government-owned enterprise, a nationwide foundation, or a government-controlled enterprise, are named in each instrument's own description of who is bound rather than flagged, because government ownership as such is not an activity or role this corpus's vocabulary currently expresses.

Articles 11 and 27 separately bar a government agency, or a specific non-government agency the central competent authority so restricts, from downloading, installing or using a product the competent authority has determined poses a risk of harm to national cyber security; this is a procurement and use restriction running to the operator itself rather than a design, support-period or vulnerability-handling duty running to a product's manufacturer, so it is named here rather than treated as a product-security-requirements instrument.

Article 33 confirms that where a cyber security incident under this Act involves a personal data breach, the matter is additionally governed by the Personal Data Protection Act (個人資料保護法, pcode I0050021); that Act's own Article 20-1 duty, that 'Non-government agencies possessing personal data files shall implement security and maintenance measures to prevent the theft, alteration, damage, loss, or leakage of personal data,' is this jurisdiction's privacy-topic finding rather than restated here, and has not yet been researched under that topic as of this writing.

A second, sector-specific duty sits in the Telecommunications Management Act (電信管理法, pcode K0060111, enacted 2019, most provisions effective July 1, 2020): Article 15 requires a telecommunications enterprise that has established a public network using allocated telecommunications resources, or another enterprise the competent authority separately announces, to draw up and implement an info-communications security maintenance plan, and Article 42 separately lets the competent authority designate all or part of that network as critical telecommunications infrastructure, whose establisher must then draw up and implement a critical telecommunications infrastructure protection plan the competent authority evaluates and may audit.

Both duties transferred from the National Communications Commission to the Ministry of Digital Affairs on Aug. 27, 2022, and both carry their own escalating fine on non-compliance (Arts. 76, 79).

A third, financial-sector duty sits in a Financial Supervisory Commission (FSC) regulation issued under the Banking Act and four sibling statutes, the Implementation Rules of Internal Audit and Internal Control System of Financial Holding Companies and Banking Industries (金融控股公司及銀行業內部控制及稽核制度實施辦法, pcode G0380218), whose current full-text version was promulgated May 6, 2026: Article 24 requires a financial holding company or a bank, credit cooperative, bills finance company or trust enterprise to establish a dedicated information security unit under a Chief Information Security Officer ranked deputy general manager or above, and Article 25 sets that unit's minimum functions, including cyber security protection and incident-response mechanisms.

This regulation sets no fine of its own; a violation is enforced through the administrative-sanction provisions of the parent statutes it is issued under, not independently traced to a specific article.

Taiwan has no enacted law setting security requirements a software product or connected device must meet before or after it is placed on the market; the product-restriction provisions named above run to a designated operator's own use of a product, not to the product's manufacturer, so a product-security-requirements duty is a researched absence.

Taiwan also has no general reasonable-security or information-security-programme statute reaching a business simply because it holds data with no sector or designation gate; the nearest analogue, the Personal Data Protection Act's Article 20-1 security-safeguards duty, is a comprehensive-regime provision that belongs to the privacy topic under this profile's own seam rule, so a general security-baseline duty is likewise a researched absence.

The Cyber Security Management Act's own enforcement rules (資通安全管理法施行細則, pcode A0030303) are confirmed to exist by name, but their substantive content was not independently reviewed, and that gap is recorded as an open question on the affected instruments below.

Sector security regimes

Bank and Financial Holding Company Internal Control Rules, Dedicated Information Security Unit

Arts. 24-25 of the Implementation Rules of Internal Audit and Internal Control System of Financial Holding Companies and Banking Industries… (金融控股公司及銀行業內部控制及稽核制度實施辦法), full-text revision promulgated May 6, 2026 (Financial Supervisory Commission Order Jin-Guan-Yin-Guo-Zi No. 11502710961), effective on promulgation for the articles cited hereOfficial English translation

In force 5 months, effective 6 May 2026. Binds private bodies.

What this law does

Article 24 of the Financial Supervisory Commission's internal-control regulation for financial holding companies and the banking business requires each to 'establish a dedicated information security unit subordinate to the general manager, which shall not concurrently handle information technology operations or other operations that present a conflict of interest with its duties,' headed by 'a person ranked vice general manager or above, or a person with equivalent responsibilities' serving as Chief Information Security Officer.

That officer 'shall report the overall implementation of information security from the preceding year to the board of directors each year'. Article 25 requires the dedicated unit to take charge of 'the planning, management, and execution of the information security system to manage information security risks' and to build 'mechanisms related to cyber security protection, assessment and response to cyber security intelligence, and reporting of and response to cyber security incidents.'

What it requires

Cyber Security Management Act, Specific Non-Government Agency Cyber Security Management

Arts. 3(6)-(8) 7-8, 20-23 and 30 of the Cyber Security Management Act (資通安全管理法), full-text amendment promulgated Sept. 24, 2025 (Presidential Order Hua-Zong-Yi-Yi-Zi No. 11400095391), effective Dec. 1, 2025Official English translation

In force 10 months, effective 1 December 2025. Binds private bodies.

What this law does

Chapter III of the Cyber Security Management Act binds a 'Specific Non-Government Agency,' defined to mean 'a critical infrastructure provider, a government-owned enterprise, a designated foundation, or any enterprise, organization, or institution under control of the government' (Art. 3(6)).

A critical infrastructure provider's own class is defined by reference to 'physical or virtual assets, systems, or networks, the functions of which, once they cease to operate or their performance is reduced, may have a significant impact on national security, social and public interests, people's lives, or economic activities' (Art. 3(7)), a class the Executive Yuan periodically designates.

A critical infrastructure provider 'shall comply with the requirements of their assigned cyber security responsibility levels, appoint dedicated cyber security personnel, and ... formulate, revise, and implement cyber security maintenance plans' (Art. 20, Paragraph 2). Every other specific non-government agency carries the identical duty under Article 21, Paragraph 1.

Every specific non-government agency must also 'appoint a Chief Information Security Officer ... responsible for promoting and overseeing the specific non-government agency's cyber security-related affairs' (Art. 23). A failure to formulate, implement or report on the maintenance plan draws, under Article 30, 'a fine of not less than NT$100,000 and not more than NT$5,000,000 ... for each violation.'

What it requires

Telecommunications Management Act, Cyber Security and Critical Infrastructure Protection Plans

Arts. 15 42, 76 and 79 of the Telecommunications Management Act (電信管理法), enacted June 26, 2019, effective July 1, 2020 for the provisions cited hereOfficial English translation

In force since 1 July 2020. Binds private bodies.

What this law does

Article 15 of the Telecommunications Management Act requires that 'Telecommunications enterprises who have established a PSTN using telecommunications resources or other telecommunications enterprises announced by the competent authority shall draw up an info-communications security maintenance plan and implement it accordingly'.

Separately, Article 42 lets the competent authority 'designate the PSTN, in whole or in part, as the critical telecommunications infrastructure,' whose establisher 'shall ... draw up a critical telecommunications infrastructure protection plan' subject to the competent authority's evaluation. Failing the general maintenance-plan duty draws a fine under Article 79 for 'Violating Paragraph 1 of Article 15, where no info-communications security management plan has been drawn up or implemented,'.

Failing the critical-infrastructure protection-plan duty draws a separate, higher fine under Article 76 for a party who 'fails to submit critical telecommunications infrastructure protection plan to the competent authority for approval within the prescribed deadline or fails to implement the approved plan.'

What it requires

Vulnerability and incident reporting

Cyber Security Management Act, Cyber Security Incident Reporting

Arts. 24 and 29 of the Cyber Security Management Act (資通安全管理法) full-text amendment promulgated Sept. 24, 2025 (Presidential Order Hua-Zong-Yi-Yi-Zi No. 11400095391), effective Dec. 1, 2025Official English translation

In force 10 months, effective 1 December 2025. Binds private bodies.

What this law does

Article 24 requires every specific non-government agency to 'establish notification and response mechanisms for cyber security incidents,' and, 'When specific non-government agencies become aware of a cyber security incident, they shall notify the central competent authority in charge of the relevant sector of the incident'.

Failing that notification duty draws, under Article 29, 'a fine of not less than NT$300,000 and not more than NT$10,000,000,' escalating for continued non-correction past the ordered deadline.

What it requires

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.