Skip to content
Is there an AI for this?

Jurisdiction

Taiwan

Source
Editorial review of primary sources — not yet re-anchored
Verified
Evidence not verified
Confidence
Low

Structured issue-spotting to support your own review — not legal advice. Verify against the cited primary sources and your counsel.

01Framework

Taiwan regulates personal data under the Personal Data Protection Act. A substantial amendment was promulgated on 11 November 2025 but has no commencement order, so the version in force remains the earlier text and the sector regulator, not a central data protection authority, still exercises the cross-border power. The Personal Data Protection Commission has not been established; only its Preparatory Office operates. The Artificial Intelligence Basic Act, in force since 14 January 2026, is a framework statute directed at government, with the National Science and Technology Council as competent authority and a two-year law-adaptation programme.

Region
North Asia
ISO code
TW
Privacy framework
Personal Data Protection Act (個人資料保護法). Applies to public and non-public agencies, with separate collection and use rules for each. Notice at collection, purpose limitation, and a set of statutory bases are the core; special categories including medical records, genetic data, sexual life, health examination and criminal records are subject to a narrower regime. Article 21 lets the competent authority restrict international transfer in defined circumstances — under the text in force, that is the central sector regulator, and restrictions are issued sector by sector rather than as a general adequacy list.
AI-specific rules
The Artificial Intelligence Basic Act took effect on the date of its promulgation, 14 January 2026. It sets principles, directs the Executive Yuan to establish a National AI Strategic Committee, names the National Science and Technology Council as central competent authority, and requires the enactment, amendment or repeal of related laws within two years. It carries no penalties for private deployers, so the operative constraints on a company remain the PDPA and sector rules. Below it sit administrative instruments: the Executive Yuan’s reference guidelines on generative AI in government, which prohibit using generative AI to draft classified documents, and the Ministry of Digital Affairs risk classification framework issued under the Act in July 2026.
Last reviewed
20 Aug 2026
Status
published

Cross-border transfer

Article 21 of the PDPA does not create a general permission regime. It lets the competent authority restrict international transfer where national interests are involved, where a treaty applies, where the receiving jurisdiction lacks adequate protection, or where the transfer is a way of evading the Act. Under the text in force that authority is the central sector regulator, which issues restrictions sector by sector. The live example on the review date is the Food and Drug Administration’s order restricting western-medicine wholesale and retail businesses from transferring personal data to mainland China, Hong Kong and Macau, published 30 September 2025 and effective 1 October 2026. So the practical question is not "is transfer allowed" but "has my sector regulator issued an order, and does it name the destination I am proposing".

Primary sources

  1. Legislation個人資料保護法 — 全國法規資料庫 (current page, carries the not-yet-effective warning)
  2. LegislationPersonal Data Protection Act — Laws and Regulations Database (English translation)
  3. Legislation人工智慧基本法 — 全國法規資料庫
  4. LegislationArtificial Intelligence Basic Act — Laws and Regulations Database (English)
  5. Regulator page個人資料保護委員會籌備處 — 機關沿革
  6. Legislation個人資料保護委員會籌備處暫行組織規程 — 全國法規資料庫
  7. Regulator guidance行政院及所屬機關(構)使用生成式 AI 參考指引
  8. Regulator guidance數位發展部 — 訂定「人工智慧風險分類框架」
  9. Regulator guidance衛生福利部食品藥物管理署 — 限制西藥批發、零售業將當事人個人資料國際傳輸至大陸地區、香港及澳門

02Regulations and guidance

6 instruments
InstrumentStatus
AI Basic ActA framework act of twenty articles. Names the National Science and Technology Council as central competent authority, directs the Executive Yuan to establish a National AI Strategic Committee convened by the Premier, and requires related laws to be enacted, amended or repealed within two years of the effective date. It imposes no penalties on private deployers.In force
MODA AI Risk FrameworkRisk classification framework issued by the Ministry of Digital Affairs under the Artificial Intelligence Basic Act, effective on the date of issue. It gives Taiwanese deployments a local vocabulary for describing AI risk that sits alongside, rather than replaces, the sectoral rules.In force
PDPC Preparatory Office RulesThe Executive Yuan established a Preparatory Office to set up the future Personal Data Protection Commission. Its listed tasks include drafting the Commission’s organic legislation, and Article 5 provides that the Office is abolished when the Commission is established — which is why the Commission does not yet exist as a regulator.In force
PDPATaiwan’s data protection statute, with separate regimes for public and non-public agencies and a narrower regime for special categories. The version on the Ministry of Justice database carries a warning that some or all provisions have not yet taken effect and that the last effective date is undetermined, so the amended text is not the law in force.Partly in force
EY Generative AI GuidelinesNon-binding reference guidelines for the Executive Yuan and its agencies. Classified documents must be drafted personally by the responsible officer and generative AI must not be used for them; officials must not put confidential official information or personal data into a prompt; and public enterprises, public schools and government-funded foundations may apply the guidelines by reference.In force
TFDA Transfer RestrictionAn order made under PDPA Article 21 subparagraph 3, restricting western-medicine wholesale and retail businesses from transferring data subjects’ personal data to mainland China, Hong Kong and Macau. Included as the working example of how Taiwanese cross-border restrictions actually arrive: from a sector regulator, for one sector, naming specific destinations.Adopted, not yet applicable

03Common enterprise issues

4
  • Cross-border transfers

    Check your sector regulator, not a general rule

    Restrictions under Article 21 are issued per sector and per destination. A telecoms operator, a pharmacy wholesaler and a staffing agency can each face a different answer for the same destination, and the orders are published on the sector regulator’s site rather than in one register.

  • Personal data

    The amended PDPA is not the law yet

    Advisers and vendor materials increasingly describe the November 2025 amendment as if it were in force. It has no commencement order. Design to the text in force, and plan for the amendment as a known future change rather than a present obligation.

  • High-risk AI

    The AI Basic Act does not regulate your deployment directly

    It is a framework act aimed at government, with a two-year programme to adapt sectoral law. The obligations that will eventually bite on companies are the ones that programme produces, not the Act itself.

  • Confidentiality

    Government-facing work inherits the generative AI guidelines

    The Executive Yuan guidelines prohibit using generative AI to prepare classified documents and restrict what officials may put into a prompt. Suppliers working with agencies are commonly asked to mirror them.


04Vendor restrictions

1

Restrictions we have written down and the page each one must be checked against. A restriction becomes a verified claim only once the sync job has fetched that page and found the phrase it declares; until then it is an editorial note with a link, and says so.

  • Microsoftclaim pending review

    No Taiwan region appeared in the Azure Foundry Models availability matrix when it was fetched on 2026-08-20. A Taiwan deployment normally runs in another Asia-Pacific region, which makes region choice a data-location decision rather than a performance one.

    Page to verify against


05Stacks with notes for this jurisdiction

0

No published stack carries a compliance note for this jurisdiction yet.


06Evidence

0 records · 0 of 6 instruments

Every instrument above that we have fetched and anchored carries a footnote. The rest link to their primary source but have not been fetched and hashed yet, and are marked ASSESSMENT rather than FACT.

No sources were recorded for this answer. Nothing on this page should be treated as verified.

Improve this page

Sign in to contribute

From the field

0 deployments · 0 questions

Nobody has reported deploying this here yet, and no question has been opened against this page. Both appear once a reviewer accepts them.