Personal Data Protection Act
Taiwan’s Personal Data Protection Act (PDPA) governs the collection, processing and use of personal and sensitive health-related information (e.g. medical records, treatment, genetic information). The 2025 amendment of the Act introduces significant changes to Taiwan’s data protection framework, strengthening regulatory oversight, organisational accountability, data security, and protections for individuals’ personal data. The new provisions have been promulgated but are not yet in force, with the effective date to be determined by Taiwan’s Executive Yuan.
Our Experts Are Here To Help You!
Ensure your clinical data complies with Taiwan’s Personal Data Protection Act
Key Requirements:
- Lawful basis and notice: personal data processing requires a lawful ground (Articles 15/16 and 19/20) and prior notice to data subjects at the point of collection (Articles 8 and 9), covering the purpose, categories, recipients, retention and the individual’s rights.
- Sensitive data protections: medical records, healthcare data, genetic data, health examination results, sex life and criminal records are special categories under Article 6, whose processing is prohibited unless specific exceptions apply, in practice one of them being the data subject’s separate written informed consent.
- Data subject rights: Article 3 grants five rights that cannot be waived in advance, namely inquiry of access and review, obtaining a copy, correction or supplementation, ceasing collection, processing or use, and deletion.
- Breach notification: data subjects must be notified once the facts of an incident are ascertained (Article 12), and the 2025 amendment adds a mandatory duty to report qualifying breaches to the competent Supervisory Authority (PDPC), with the detailed scope, content, method and time limits for notification and reporting to be prescribed by the PDPC.
- Cross-border transfers: the competent authority (moving to the PDPC) may restrict international transfers where major national interests, treaty obligations, inadequate protection in the destination country that may prejudice data subjects’ rights, or circumvention of the PDPA are involved (Article 21).
- Security measures: organisations must implement appropriate technical and organisational safeguards (previously covered by Article 27 and replaced by the new Article 20-1 under the 2025 PDPA amendment); failure to rectify a violation can attract cumulative administrative fines of up to NTD 15 million (approximately US$465,000).
- Clinical research: studies involving human subjects require ethics committee (IRB) approval and informed consent under the Human Subjects Research Act, applied alongside PDPA obligations, with further sector rules under the Medical Care Act and the Human Biobank Management Act.
How MyData-TRUST Can Support You:
- Build a tailored compliance roadmap for your Taiwan operations
- Provide ongoing data protection guidance, operational support and advice to ensure compliance with local privacy requirements
- Deliver training and awareness programmes for clinical and research teams
- Support you to identify, assess and mitigate data protection risks associated with processing activities, projects, systems and new initiatives
- Review contracts, informed consent forms and clinical trial documentation
Why Compliance Matters for Life Sciences:
- Builds trust in clinical trials and research projects
- Implements safeguards for sensitive health and genetic data
- Mitigates reputational and regulatory risks
Why Choose MyData-TRUST?
- Legal expertise dedicated to data protection compliance
- Proven experience integrating privacy into Life Sciences projects
- Practical support for research and patient data use
- Guidance for cross-border clinical trial data transfers
Frequently asked questions
Does Taiwan’s PDPA require a local representative or a Data Protection Officer?
There is currently no general obligation for private (non-government) organisations to appoint a Data Protection Officer or a local representative under the PDPA. The 2025 amendment introduces a Data Protection Officer requirement for government agencies only (Article 18). Foreign sponsors without a Taiwan establishment should nonetheless confirm their position, as the PDPC may issue further guidance. In the meantime, appointing a Data Protection Officer (or equivalent accountable privacy lead) is highly recommended to ensure clear internal ownership of privacy governance, timely handling of data subject requests and incident escalation, and consistent oversight of third parties and study sites.
Is data breach notification mandatory in Taiwan?
Yes. Article 12 requires notifying affected data subjects once the facts of an incident have been ascertained. The 2025 amendment introduces an additional mandatory duty to report qualifying breaches to the competent Supervisory Authority, the Personal Data Protection Commission (PDPC); however, the exact thresholds and reporting timeline are to be set by the PDPC in future implementing regulations. Note that the 2025 amendments have been promulgated but the amended provisions are not yet in force.
Can health data be transferred outside Taiwan for a clinical trial?
Cross-border transfers are generally permitted, but the competent authority (the PDPC once operational) may restrict them in specified circumstances under Article 21, including where the destination country lacks adequate protection. For sensitive personal data such as health and genetic information, the transfer must also comply with the specific requirements of Article 6 and have an applicable statutory basis. Data subjects must be informed in advance about the transfer of their personal data abroad. Other specific safeguards may apply depending on the context of the transfer.
Need more information about MyData-TRUST? Get in touch with our experts.
MyData-TRUST offers global coverage

