Law / Taiwan

Taiwan

All 11 named instruments researched to a stage, across all six areas of law we track: 11 in force. As of 22 September 2026.

When they take effect5 of 11 carry a date, 6 do not.
2020: 1 instrument (1 in force) ’20 2021: 0 instruments 2022: 0 instruments 2023: 0 instruments 2024: 0 instruments 2025: 3 instruments (3 in force) 2026: 1 instrument (1 in force) ’26 today

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

  1. AI law 1
  2. Privacy law 1
  3. Scraping law 3
  4. Cybersecurity law 4
  5. Age gating law 1
  6. News aggregation law 1

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

AI law1 instrument, 1 in force

Research summary (171 words)

Taiwan's Artificial Intelligence Basic Act establishes a national framework for the government's promotion and oversight of artificial intelligence, naming the National Science and Technology Council as the central AI competent authority and the special municipality, county, or city governments as the local competent authority, and creating an Executive Yuan-convened National AI Strategic Committee.

Article 4 sets seven governing principles, including privacy protection and data governance, cybersecurity and safety, transparency and explainability, and fairness and non-discrimination, for the government to apply while developing an AI risk taxonomy and risk-based management regulations under Article 16.

The Act does not itself impose a directly enforceable disclosure, labeling, or risk-classification duty on a developer or deployer; Article 18 gives the government two years from the Act's effective date to bring existing laws into conformity with it or to enact the implementing rules its principles call for, so a specific compliance duty for a given AI activity currently rests with whatever sector regulation the government adopts under that mandate rather than with this Act's own text.

AI governance

Artificial Intelligence Basic Act (人工智慧基本法)

Artificial Intelligence Basic Act (人工智慧基本法), Laws and Regulations Database of the Republic of China (Taiwan), pcode H0160093, Arts. 1-20Laws and Regulations Database of the Republic of China (Taiwan), Ministry of Justice, official English translation

In force. Binds public and private bodies.

What this law does

This 20-article framework act sets the government's guiding principles for AI development and application (Article 4: sustainable development and well-being, human autonomy, privacy protection and data governance, cybersecurity and safety, transparency and explainability, fairness and non-discrimination, and accountability), designates the National Science and Technology Council as the central AI competent authority with local governments at the municipal or county level (Article 2), and directs the Ministry of Digital Affairs to build a risk taxonomy and assessment framework that sector regulators use to write risk-based management regulations (Article 16).

For high-risk AI application, Article 17 directs the government to clarify liability attribution and establish relief, compensation, or insurance mechanisms, rather than creating those mechanisms itself.

Article 18 gives the government two years from this Act's effective date to bring existing law into conformity with it or enact rules it requires, so a disclosure, crawler or training-data, agent-transaction, or automated-decision duty for a specific AI activity is not yet a duty this Act itself imposes.

What it requires

Privacy law1 instrument, 1 in force

Research summary (173 words)

Taiwan's Personal Data Protection Act (PDPA) is a single omnibus statute covering both government and non-government agencies' collection, processing, and use of personal data, enforced since an October 2025 amendment by an independent Personal Data Protection Commission (PDPC) rather than by sector regulators.

The Act requires one of several stated lawful bases before collecting, processing, or using personal data, imposes heightened bases for a narrower category of sensitive data (medical, healthcare, genetic, sex-life, physical-examination, and criminal-record data) that does not extend to biometric identifiers as such, and gives a non-government agency an additional lawful basis to process data obtained from publicly available sources without exempting that data from the Act's other duties.

A breach must be notified to the data subject and, where the circumstances fall within a specified reporting scope, to the competent authority; cross-border transfer by a non-government agency may be restricted by the competent authority only in four stated circumstances; and both administrative fines and, for the Act's core violations, criminal penalties and a private civil remedy back the regime.

Comprehensive regime

Personal Data Protection Act (個人資料保護法)

Personal Data Protection Act (個人資料保護法) Laws and Regulations Database of the Republic of China (Taiwan), pcode I0050021, as amended effective 2025-10-17Laws and Regulations Database of the Republic of China (Taiwan), Ministry of Justice, official English translation

In force 11 months, effective 17 October 2025. Binds public and private bodies.

What this law does

The PDPA requires government and non-government agencies alike to collect and process personal data only for a specific purpose and on one of the bases the Act states (Articles 15, 16, 19, 20), notify the data subject when personal data held has been stolen, altered, damaged, lost, or leaked and, in specified circumstances, report the incident to the competent authority (Article 12), and implement security and maintenance measures to prevent theft, alteration, damage, loss, or leakage of personal data files (Article 20-1).

Since an amendment effective October 17, 2025, the Act's competent authority is the Personal Data Protection Commission, an independent agency, which supervises government agencies through periodic and ad hoc audits (Articles 21-1 through 21-5) and may inspect a non-government agency it deems likely to violate the Act (Article 22).

A non-government agency is civilly liable for injury caused by an unlawful collection, processing, or use of personal data (Article 29), with a statutory minimum of NT$500 per data subject per incident where actual damages cannot be readily shown, and 20 or more affected data subjects may delegate a lawsuit to an incorporated foundation or charity (Article 34).

What it requires

Scraping law3 instruments, 3 in force

Research summary (160 words)

Taiwan has no scraping-specific statute; open-web crawling of a public, unauthenticated page is reached, if at all, by general law written for other purposes. The Criminal Code's computer-security chapter criminalizes defeating a password, protective measure, or system loophole to access a computer, but does not on its own text reach access that defeats none of those barriers.

The Copyright Act's general fair-use standard, not a dedicated text-and-data-mining exception, governs whether collecting or training on copyrighted text is exploitable, and the Fair Trade Act's residual unfair-competition clause is the closest Taiwan comes to a misappropriation doctrine for systematic reuse of another's content or compiled data.

No sui generis database right, no dedicated statute addressing robots.txt's legal weight or AI-training-specific crawling, and no reported case law on browsewrap or clickwrap Terms of Service enforceability specifically for scraping were located in the primary sources checked; each remains an open question under Taiwan's general contract and unfair-competition law rather than a settled, scraping-specific rule.

Computer misuse

Criminal Code, Offenses Against Computer Security

Criminal Code of the Republic of China (中華民國刑法), Arts. 358-363Laws and Regulations Database of the Republic of China (Taiwan), Ministry of Justice, official English translation

In force. Binds public and private bodies.

What this law does

Chapter 36 criminalizes gaining access to another's computer or related equipment by entering another's password, cracking its protective measures, or exploiting a system loophole without cause (Article 358); obtaining, deleting, or altering another's computer data without cause and causing injury (Article 359); interfering with another's computer or related equipment through a computer program or other electromagnetic method without cause and causing injury (Article 360); and making a program specifically to commit one of those offenses (Article 362).

Offending against a public office's computer increases the punishment by up to one half (Article 361), and prosecution of the Article 358 through 360 offenses proceeds only upon the victim's complaint (Article 363). Accessing a page that requires defeating no password, protective measure, or system loophole is not within the text of any offense in this chapter.

What it requires

Unfair competition

Fair Trade Act, general clause against deceptive or unfair competitive conduct

Fair Trade Act (公平交易法), Arts. 6, 25, 42Laws and Regulations Database of the Republic of China (Taiwan), Ministry of Justice, official English translation

In force. Binds private bodies.

What this law does

Article 25 is a residual general clause: beyond the Fair Trade Act's other named prohibitions, no enterprise may engage in deceptive conduct, or conduct that is obviously unfair and capable of affecting trading order. The Fair Trade Commission, the Act's named competent authority, may order an enterprise violating Article 25 to cease, rectify, or take corrective action, and may separately impose an administrative penalty of NT$50,000 to NT$25,000,000 (Article 42).

Taiwan has not enacted a dedicated hot-news or database-misappropriation statute; a claim that a competitor's systematic reuse of another's factual reporting or compiled data is unfair has to be brought, if at all, under this general clause rather than under a named misappropriation tort.

What it requires

Cybersecurity law4 instruments, 4 in force

Research summary (838 words)

Taiwan's primary cyber-resilience statute, the Cyber Security Management Act (資通安全管理法, Cyber Security Management Act, pcode A0030297), was replaced in full on Sept. 24, 2025 and took effect Dec. 1, 2025 under the Ministry of Digital Affairs (MODA) as competent authority.

Chapter III binds a 'Specific Non-Government Agency,' a term the Act defines to mean 'a critical infrastructure provider, a government-owned enterprise, a designated foundation, or any enterprise, organization, or institution under control of the government' (Art. 3(6)), with a critical infrastructure provider's own class turning on the Executive Yuan's periodic designation of a physical or virtual asset, system or network whose disruption would significantly affect national security, the public interest, daily life or economic activity (Art. 3(7)-(8)).

Every such agency must formulate, implement and report on a cyber security maintenance plan matched to a government-assigned responsibility level, appoint a dedicated Chief Information Security Officer, and submit to periodic audits (Arts. 7-8, 20-23, 30), and must separately maintain a notification and response mechanism and report a cyber security incident to the sector's own central competent authority as soon as it becomes aware of one (Arts. 24, 29).

Because a designated critical infrastructure provider is precisely the cross-sector essential-infrastructure-operator shape this corpus's activity vocabulary expresses through its general essential-service-operator role rather than through any single sector flag, both duties are flagged here; the Act's other named classes, a government-owned enterprise, a nationwide foundation, or a government-controlled enterprise, are named in each instrument's own description of who is bound rather than flagged, because government ownership as such is not an activity or role this corpus's vocabulary currently expresses.

Articles 11 and 27 separately bar a government agency, or a specific non-government agency the central competent authority so restricts, from downloading, installing or using a product the competent authority has determined poses a risk of harm to national cyber security; this is a procurement and use restriction running to the operator itself rather than a design, support-period or vulnerability-handling duty running to a product's manufacturer, so it is named here rather than treated as a product-security-requirements instrument.

Article 33 confirms that where a cyber security incident under this Act involves a personal data breach, the matter is additionally governed by the Personal Data Protection Act (個人資料保護法, pcode I0050021); that Act's own Article 20-1 duty, that 'Non-government agencies possessing personal data files shall implement security and maintenance measures to prevent the theft, alteration, damage, loss, or leakage of personal data,' is this jurisdiction's privacy-topic finding rather than restated here, and has not yet been researched under that topic as of this writing.

A second, sector-specific duty sits in the Telecommunications Management Act (電信管理法, pcode K0060111, enacted 2019, most provisions effective July 1, 2020): Article 15 requires a telecommunications enterprise that has established a public network using allocated telecommunications resources, or another enterprise the competent authority separately announces, to draw up and implement an info-communications security maintenance plan, and Article 42 separately lets the competent authority designate all or part of that network as critical telecommunications infrastructure, whose establisher must then draw up and implement a critical telecommunications infrastructure protection plan the competent authority evaluates and may audit.

Both duties transferred from the National Communications Commission to the Ministry of Digital Affairs on Aug. 27, 2022, and both carry their own escalating fine on non-compliance (Arts. 76, 79).

A third, financial-sector duty sits in a Financial Supervisory Commission (FSC) regulation issued under the Banking Act and four sibling statutes, the Implementation Rules of Internal Audit and Internal Control System of Financial Holding Companies and Banking Industries (金融控股公司及銀行業內部控制及稽核制度實施辦法, pcode G0380218), whose current full-text version was promulgated May 6, 2026: Article 24 requires a financial holding company or a bank, credit cooperative, bills finance company or trust enterprise to establish a dedicated information security unit under a Chief Information Security Officer ranked deputy general manager or above, and Article 25 sets that unit's minimum functions, including cyber security protection and incident-response mechanisms.

This regulation sets no fine of its own; a violation is enforced through the administrative-sanction provisions of the parent statutes it is issued under, not independently traced to a specific article.

Taiwan has no enacted law setting security requirements a software product or connected device must meet before or after it is placed on the market; the product-restriction provisions named above run to a designated operator's own use of a product, not to the product's manufacturer, so a product-security-requirements duty is a researched absence.

Taiwan also has no general reasonable-security or information-security-programme statute reaching a business simply because it holds data with no sector or designation gate; the nearest analogue, the Personal Data Protection Act's Article 20-1 security-safeguards duty, is a comprehensive-regime provision that belongs to the privacy topic under this profile's own seam rule, so a general security-baseline duty is likewise a researched absence.

The Cyber Security Management Act's own enforcement rules (資通安全管理法施行細則, pcode A0030303) are confirmed to exist by name, but their substantive content was not independently reviewed, and that gap is recorded as an open question on the affected instruments below.

Sector security regimes

Bank and Financial Holding Company Internal Control Rules, Dedicated Information Security Unit

Arts. 24-25 of the Implementation Rules of Internal Audit and Internal Control System of Financial Holding Companies and Banking Industries… (金融控股公司及銀行業內部控制及稽核制度實施辦法), full-text revision promulgated May 6, 2026 (Financial Supervisory Commission Order Jin-Guan-Yin-Guo-Zi No. 11502710961), effective on promulgation for the articles cited hereOfficial English translation

In force 5 months, effective 6 May 2026. Binds private bodies.

What this law does

Article 24 of the Financial Supervisory Commission's internal-control regulation for financial holding companies and the banking business requires each to 'establish a dedicated information security unit subordinate to the general manager, which shall not concurrently handle information technology operations or other operations that present a conflict of interest with its duties,' headed by 'a person ranked vice general manager or above, or a person with equivalent responsibilities' serving as Chief Information Security Officer.

That officer 'shall report the overall implementation of information security from the preceding year to the board of directors each year'. Article 25 requires the dedicated unit to take charge of 'the planning, management, and execution of the information security system to manage information security risks' and to build 'mechanisms related to cyber security protection, assessment and response to cyber security intelligence, and reporting of and response to cyber security incidents.'

What it requires

Cyber Security Management Act, Specific Non-Government Agency Cyber Security Management

Arts. 3(6)-(8) 7-8, 20-23 and 30 of the Cyber Security Management Act (資通安全管理法), full-text amendment promulgated Sept. 24, 2025 (Presidential Order Hua-Zong-Yi-Yi-Zi No. 11400095391), effective Dec. 1, 2025Official English translation

In force 10 months, effective 1 December 2025. Binds private bodies.

What this law does

Chapter III of the Cyber Security Management Act binds a 'Specific Non-Government Agency,' defined to mean 'a critical infrastructure provider, a government-owned enterprise, a designated foundation, or any enterprise, organization, or institution under control of the government' (Art. 3(6)).

A critical infrastructure provider's own class is defined by reference to 'physical or virtual assets, systems, or networks, the functions of which, once they cease to operate or their performance is reduced, may have a significant impact on national security, social and public interests, people's lives, or economic activities' (Art. 3(7)), a class the Executive Yuan periodically designates.

A critical infrastructure provider 'shall comply with the requirements of their assigned cyber security responsibility levels, appoint dedicated cyber security personnel, and ... formulate, revise, and implement cyber security maintenance plans' (Art. 20, Paragraph 2). Every other specific non-government agency carries the identical duty under Article 21, Paragraph 1.

Every specific non-government agency must also 'appoint a Chief Information Security Officer ... responsible for promoting and overseeing the specific non-government agency's cyber security-related affairs' (Art. 23). A failure to formulate, implement or report on the maintenance plan draws, under Article 30, 'a fine of not less than NT$100,000 and not more than NT$5,000,000 ... for each violation.'

What it requires

Telecommunications Management Act, Cyber Security and Critical Infrastructure Protection Plans

Arts. 15 42, 76 and 79 of the Telecommunications Management Act (電信管理法), enacted June 26, 2019, effective July 1, 2020 for the provisions cited hereOfficial English translation

In force since 1 July 2020. Binds private bodies.

What this law does

Article 15 of the Telecommunications Management Act requires that 'Telecommunications enterprises who have established a PSTN using telecommunications resources or other telecommunications enterprises announced by the competent authority shall draw up an info-communications security maintenance plan and implement it accordingly'.

Separately, Article 42 lets the competent authority 'designate the PSTN, in whole or in part, as the critical telecommunications infrastructure,' whose establisher 'shall ... draw up a critical telecommunications infrastructure protection plan' subject to the competent authority's evaluation. Failing the general maintenance-plan duty draws a fine under Article 79 for 'Violating Paragraph 1 of Article 15, where no info-communications security management plan has been drawn up or implemented,'.

Failing the critical-infrastructure protection-plan duty draws a separate, higher fine under Article 76 for a party who 'fails to submit critical telecommunications infrastructure protection plan to the competent authority for approval within the prescribed deadline or fails to implement the approved plan.'

What it requires

Vulnerability and incident reporting

Cyber Security Management Act, Cyber Security Incident Reporting

Arts. 24 and 29 of the Cyber Security Management Act (資通安全管理法) full-text amendment promulgated Sept. 24, 2025 (Presidential Order Hua-Zong-Yi-Yi-Zi No. 11400095391), effective Dec. 1, 2025Official English translation

In force 10 months, effective 1 December 2025. Binds private bodies.

What this law does

Article 24 requires every specific non-government agency to 'establish notification and response mechanisms for cyber security incidents,' and, 'When specific non-government agencies become aware of a cyber security incident, they shall notify the central competent authority in charge of the relevant sector of the incident'.

Failing that notification duty draws, under Article 29, 'a fine of not less than NT$300,000 and not more than NT$10,000,000,' escalating for continued non-correction past the ordered deadline.

What it requires

Age gating law1 instrument, 1 in force

Research summary (78 words)

Taiwan has not enacted a dedicated age-verification statute for adult content, a social-media minor-access law, an app-store age-verification requirement, or a named age-appropriate design code.

The closest primary-source instrument located is the Child and Juvenile Welfare and Rights Protection Act, which requires an internet platform provider to adopt protection measures against content harmful to a child's or juvenile's physical and mental health and to restrict or remove such content once notified, without itself prescribing a specific age-verification method.

Age-appropriate design code

Child and Juvenile Welfare and Rights Protection Act, internet content protection duties

Child and Juvenile Welfare and Rights Protection Act (兒童及少年福利與權益保障法), Arts. 2, 46, 46-1, 94Laws and Regulations Database of the Republic of China (Taiwan), Ministry of Justice, official English translation

In force. Binds private bodies.

What this law does

The communications and broadcasting competent authority must entrust private organizations with establishing content-protection agencies for children's and juveniles' internet use, and an internet platform provider, defined broadly as any provider of internet platform services including storage space, websites, or web-linking services, must establish self-regulatory norms and adopt clear, feasible protection measures against content harmful to a child's or juvenile's physical and mental health (Article 46).

Where the competent authority for the relevant business notifies a platform provider that its content is harmful or that its protection measures are inadequate, the provider must restrict a child's or juvenile's access or browsing, or remove the content beforehand; a provider that fails to do so is fined NT$60,000 to NT$300,000 and ordered to improve within a set period (Article 94).

Article 46-1 separately prohibits anyone from disseminating or transmitting content harmful to a child's or juvenile's physical and mental health on the internet without taking clear, feasible protection measures or cooperating with a platform's protection mechanisms, in a way that makes the content accessible to a child or juvenile. "Children and juveniles" means persons under eighteen (Article 2).

The Act does not itself prescribe a specific age-verification method, leaving the content-classification system, filtering software, and self-regulatory norms to be developed under the competent authority's protection mechanisms.

Note and primary source

News aggregation law1 instrument, 1 in force

Research summary (141 words)

Taiwan has not enacted a press-publisher neighbouring right, a compelled platform-to-publisher bargaining regime, or a machine-readable text-and-data-mining opt-out mechanism.

What Taiwan's Copyright Act does provide is narrower and more specific: a bare factual news report carries no copyright at all, a person reporting a current event may exploit, within the scope necessary, a work seen or heard in the course of that event, and a newspaper, magazine, or internet transmission may republish commentary on a current event that has already appeared in a newspaper, magazine, or online, unless the original publisher has indicated that republication is not authorized.

Beyond those exceptions and the Act's general fair-use standard, a claim that systematic reuse of another's reporting is unfair would have to proceed, if at all, under the Fair Trade Act's general unfair-competition clause rather than under a dedicated hot-news or misappropriation doctrine.

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.