• About
  • Privacy Poilicy
  • Disclaimer
  • Contact
CoinInsight
  • Home
  • Bitcoin
  • Ethereum
  • Regulation
  • Market
  • Blockchain
  • Ripple
  • Future of Crypto
  • Crypto Mining
No Result
View All Result
  • Home
  • Bitcoin
  • Ethereum
  • Regulation
  • Market
  • Blockchain
  • Ripple
  • Future of Crypto
  • Crypto Mining
No Result
View All Result
CoinInsight
No Result
View All Result
Home Regulation

Taiwan: Modification to Private Knowledge Safety Act

Coininsight by Coininsight
November 21, 2025
in Regulation
0
Taiwan: Modification to Private Knowledge Safety Act
189
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter


Briefly

On 17 October 2025, the Legislative Yuan handed the modification (“Modification”) to the Private Knowledge Safety Act (PDPA). After promulgation by the President, the efficient date of the Modification shall be determined by Government Yuan and anticipate to be in pressure in 2026.


The primary drive for the Modification is to adjust to the Constitutional Courtroom’s ruling issued on 12 August 2022 (111年度憲判字第13號健保資料庫案判決), which mandates the institution of an unbiased supervisory mechanism for private information safety inside three years.

The PDPA has been amended in Might 2023 so as to add Article 1-1 (not efficient but), which offers that the competent authority of the PDPA would be the Private Knowledge Safety Fee (PDPC), the primary devoted authority for private information safety. The Preparatory Workplace of the PDPC was established on 5 December 2023. The PDPC shall be formally established after the Organizational Act of the PDPC (which was proposed together with the Modification) is handed by the Legislative Yuan.

The Modification additionally contains the next key modifications.

Authorities businesses are actually required to nominate DPO (Article 18)

Though the primary draft of the Modification proposed that the PDPC could designate sure non-government businesses to nominate DPO and private information safety audit personnel, the Modification doesn’t embrace this requirement so solely authorities businesses are required to take action.

Knowledge breach notification/report (Article 12)

  • Beneath the present PDPA, if there’s a information breach, the non-government company solely must notify the information topic. Beneath the Modification, the non-government company may additionally must report back to the PDPC. The brink, timeline and different necessities on report shall be additional decided by the PDPC in rules.
  • The Modification requires the non-government company to maintain the documentation of the info incident for inspection by the PDPC. The file retention interval shall be decided by the PDPC in rules.
  • Violation of the brand new necessities above shall be topic to an administrative superb starting from NTD 20,000 (USD 625) to NTD 200,000 (USD 6,250), which can be imposed consecutively if the non‑authorities company fails to rectify inside the specified time frame. (new Paragraph 2, Article 48).
  • The PDPC could delegate the acceptance and onward notification of the report back to different businesses, administrative organizations, or public curiosity teams to deal with the matter (Para 1, Article 52).

Administration inspection

  • The primary draft of the Modification proposed that the PDPC could select the industries and non-government businesses with larger threat of private information infringement to prioritize administrative inspection in opposition to them (Article 27). The Modification doesn’t embrace this concept.
  • That mentioned, even when there isn’t any indication of violation, below the Modification the PDPC should still conduct proactive administrative inspection for reviewing the non-government businesses’ compliance with the PDPA. The PDPC will promulgate rules for issues relating to proactive inspection (new para 2, Article 22).
  • The non-government businesses can not refuse the inspection except there are “justifiable causes” (Para 4, Article 22).

6-year transition interval (Article 51-1)

  • The PDPC will request the Government Yuan to announce which of the non-government businesses (doubtless those who have already got particular competent authorities) will stay to be regulated by the present central competent authorities or native governments as much as six years after the PDPC is established.
  • Each two years, the PDPC will talk about with the competent authorities in command of the trade involved and report back to and request the Government Yuan to scale back the scope of the non-government industries that stay to be supervised by the competent authorities.
  • Nevertheless, as soon as the Modification is in impact, the ability below Article 21 of the PDPA to limit cross‑border information switch shall be transferred from the competent authorities in command of the trade involved to the PDPC.

The PDPC will promulgate Laws for Safety and Upkeep of Private Data Information (Article 20-1 and 51-1)

Beneath the Modification, the PDPC will promulgate baseline Laws for Safety and Upkeep of Private Data Information for non-government businesses. (Article 20-1) In the course of the transition interval, the related Laws for Safety and Upkeep of Private Data Information promulgated by the competent authorities shall be primarily based on the PDPC’s baseline model however could be stricter (Paragraphs 3 to 4, Article 51-1).

Administrative enchantment (Article 53-1)

Because the PDPC is an unbiased authority, the enchantment in opposition to the rulings of the PDPC shall be filed with the Administrative Courtroom straight.

Nevertheless, through the transition interval, the enchantment in opposition to the rulings of the central competent authorities or native governments shall be filed with the PDPC.

The Modification follows the choice of Constitutional Courtroom’s ruling to ascertain an unbiased supervisory mechanism for private information safety. Given the brand new regulatory necessities, corporations are suggested to evaluate if they’ve any hole between the Modification and their present information safety apply, particularly the info breach response plan. If sure, corporations shall instantly modify the present insurance policies and operations for compliance with these necessities. If in case you have any questions, please be at liberty to contact us.

Related articles

United Kingdom: FCA Launches Assessment on Future AI Strategy

United Kingdom: FCA Launches Assessment on Future AI Strategy

March 3, 2026
‘AI All over the place’ Mandates Fail With out Credible Use Instances and Human Checkpoints

‘AI All over the place’ Mandates Fail With out Credible Use Instances and Human Checkpoints

March 2, 2026


Briefly

On 17 October 2025, the Legislative Yuan handed the modification (“Modification”) to the Private Knowledge Safety Act (PDPA). After promulgation by the President, the efficient date of the Modification shall be determined by Government Yuan and anticipate to be in pressure in 2026.


The primary drive for the Modification is to adjust to the Constitutional Courtroom’s ruling issued on 12 August 2022 (111年度憲判字第13號健保資料庫案判決), which mandates the institution of an unbiased supervisory mechanism for private information safety inside three years.

The PDPA has been amended in Might 2023 so as to add Article 1-1 (not efficient but), which offers that the competent authority of the PDPA would be the Private Knowledge Safety Fee (PDPC), the primary devoted authority for private information safety. The Preparatory Workplace of the PDPC was established on 5 December 2023. The PDPC shall be formally established after the Organizational Act of the PDPC (which was proposed together with the Modification) is handed by the Legislative Yuan.

The Modification additionally contains the next key modifications.

Authorities businesses are actually required to nominate DPO (Article 18)

Though the primary draft of the Modification proposed that the PDPC could designate sure non-government businesses to nominate DPO and private information safety audit personnel, the Modification doesn’t embrace this requirement so solely authorities businesses are required to take action.

Knowledge breach notification/report (Article 12)

  • Beneath the present PDPA, if there’s a information breach, the non-government company solely must notify the information topic. Beneath the Modification, the non-government company may additionally must report back to the PDPC. The brink, timeline and different necessities on report shall be additional decided by the PDPC in rules.
  • The Modification requires the non-government company to maintain the documentation of the info incident for inspection by the PDPC. The file retention interval shall be decided by the PDPC in rules.
  • Violation of the brand new necessities above shall be topic to an administrative superb starting from NTD 20,000 (USD 625) to NTD 200,000 (USD 6,250), which can be imposed consecutively if the non‑authorities company fails to rectify inside the specified time frame. (new Paragraph 2, Article 48).
  • The PDPC could delegate the acceptance and onward notification of the report back to different businesses, administrative organizations, or public curiosity teams to deal with the matter (Para 1, Article 52).

Administration inspection

  • The primary draft of the Modification proposed that the PDPC could select the industries and non-government businesses with larger threat of private information infringement to prioritize administrative inspection in opposition to them (Article 27). The Modification doesn’t embrace this concept.
  • That mentioned, even when there isn’t any indication of violation, below the Modification the PDPC should still conduct proactive administrative inspection for reviewing the non-government businesses’ compliance with the PDPA. The PDPC will promulgate rules for issues relating to proactive inspection (new para 2, Article 22).
  • The non-government businesses can not refuse the inspection except there are “justifiable causes” (Para 4, Article 22).

6-year transition interval (Article 51-1)

  • The PDPC will request the Government Yuan to announce which of the non-government businesses (doubtless those who have already got particular competent authorities) will stay to be regulated by the present central competent authorities or native governments as much as six years after the PDPC is established.
  • Each two years, the PDPC will talk about with the competent authorities in command of the trade involved and report back to and request the Government Yuan to scale back the scope of the non-government industries that stay to be supervised by the competent authorities.
  • Nevertheless, as soon as the Modification is in impact, the ability below Article 21 of the PDPA to limit cross‑border information switch shall be transferred from the competent authorities in command of the trade involved to the PDPC.

The PDPC will promulgate Laws for Safety and Upkeep of Private Data Information (Article 20-1 and 51-1)

Beneath the Modification, the PDPC will promulgate baseline Laws for Safety and Upkeep of Private Data Information for non-government businesses. (Article 20-1) In the course of the transition interval, the related Laws for Safety and Upkeep of Private Data Information promulgated by the competent authorities shall be primarily based on the PDPC’s baseline model however could be stricter (Paragraphs 3 to 4, Article 51-1).

Administrative enchantment (Article 53-1)

Because the PDPC is an unbiased authority, the enchantment in opposition to the rulings of the PDPC shall be filed with the Administrative Courtroom straight.

Nevertheless, through the transition interval, the enchantment in opposition to the rulings of the central competent authorities or native governments shall be filed with the PDPC.

The Modification follows the choice of Constitutional Courtroom’s ruling to ascertain an unbiased supervisory mechanism for private information safety. Given the brand new regulatory necessities, corporations are suggested to evaluate if they’ve any hole between the Modification and their present information safety apply, particularly the info breach response plan. If sure, corporations shall instantly modify the present insurance policies and operations for compliance with these necessities. If in case you have any questions, please be at liberty to contact us.

Tags: ActAmendmentDataPersonalprotectionTaiwan
Share76Tweet47

Related Posts

United Kingdom: FCA Launches Assessment on Future AI Strategy

United Kingdom: FCA Launches Assessment on Future AI Strategy

by Coininsight
March 3, 2026
0

Briefly On 27 January 2026 the Monetary Conduct Authority (FCA) launched the Mills Assessment to look at the long-term affect of AI...

‘AI All over the place’ Mandates Fail With out Credible Use Instances and Human Checkpoints

‘AI All over the place’ Mandates Fail With out Credible Use Instances and Human Checkpoints

by Coininsight
March 2, 2026
0

Broad top-down mandates to make use of AI fail as a result of they’re too obscure to behave on, whereas...

LRN、次世代型Catalyst Phishingを発表: セキュリティ&コンプライアンスチームの人為的なリスクを軽減する フィッシングシュミレーションプラットフォーム

LRN、次世代型Catalyst Phishingを発表: セキュリティ&コンプライアンスチームの人為的なリスクを軽減する フィッシングシュミレーションプラットフォーム

by Coininsight
March 2, 2026
0

最新のフィッシングシミュレーションと行動ベーストレーニングの実施で、人為的なサイバーリスクの軽減と強固なセキュリティ文化の構築を支援 ニューヨーク — YYYY年MM月DD日— 倫理・コンプライアンス(E&C)ソリューションのグローバルリーダーであるLRN Companyは、本日、Catalyst Phishingのリリースを発表しました。Catalyst Phishingは、最新のフィッシングシミュレーションとトレーニングソリューションを提供し、高度化するソーシャルエンジニアリングの脅威に対する従業員の対応テスト、追跡、強化します。 Brandon Corridor Groupアワードなどいくつもの受賞歴があるCatalystプラットフォームで運用きるCatalyst Phishingは、行動変容を目的とし、従来の意識向上トレーニングを超える成果をセキュリティチームとコンプライアンスチームに提供します。プラットフォームでは、最新のサイバー攻撃の傾向を反映して随時更新されるテンプレート集を使用して、現実的なフィッシングシミュレーションを実施します。従業員がフィッシングシミュレーションをクリックすると、その行動を察知したCatalyst Phishingにより、マイクロラーニングがタイムリーに割り当てられ、人為的なサイバーリスクの軽減を支援します。 「依然としてフィッシングは、組織の最大のサイバーセキュリティリスクのひとつです。攻撃は巧妙化し、AIによるターゲットを絞ったマルチチャンネルキャンペーンが行われています。」と、LRN CompanyのChief Product and Expertise Officer(最高製品技術責任者)であるParijat Jauhariは述べています。「Catalyst...

DOJ Takes Unprecedented Motion to Implement CFIUS Divestment Order in U.S. District Court docket

DOJ Takes Unprecedented Motion to Implement CFIUS Divestment Order in U.S. District Court docket

by Coininsight
March 1, 2026
0

by Stephenie Gosnell Handler and Chris Mullen From left to proper: Stephenie Gosnell Handler and Chris Mullen (images courtesy of...

UK hits Russia with largest sanctions package deal but on battle anniversary

UK hits Russia with largest sanctions package deal but on battle anniversary

by Coininsight
February 28, 2026
0

On the anniversary of Russia’s full-scale invasion of Ukraine, the UK has launched its largest-ever sanctions package deal, focusing on...

Load More
  • Trending
  • Comments
  • Latest
MetaMask Launches An NFT Reward Program – Right here’s Extra Data..

MetaMask Launches An NFT Reward Program – Right here’s Extra Data..

July 24, 2025
Finest Bitaxe Gamma 601 Overclock Settings & Tuning Information

Finest Bitaxe Gamma 601 Overclock Settings & Tuning Information

November 26, 2025
Naval Ravikant’s Web Price (2025)

Naval Ravikant’s Web Price (2025)

September 21, 2025
Haedal token airdrop information

Haedal token airdrop information

April 24, 2025
Kuwait bans Bitcoin mining over power issues and authorized violations

Kuwait bans Bitcoin mining over power issues and authorized violations

2
The Ethereum Basis’s Imaginative and prescient | Ethereum Basis Weblog

The Ethereum Basis’s Imaginative and prescient | Ethereum Basis Weblog

2
Unchained Launches Multi-Million Greenback Bitcoin Legacy Mission

Unchained Launches Multi-Million Greenback Bitcoin Legacy Mission

1
Earnings Preview: Microsoft anticipated to report larger Q3 income, revenue

Earnings Preview: Microsoft anticipated to report larger Q3 income, revenue

1
OpenAI Abandons SWE-bench Verified After Discovering 59% of Failed Exams Had been Flawed

OpenAI Abandons SWE-bench Verified After Discovering 59% of Failed Exams Had been Flawed

March 3, 2026
The three largest stinkers in my SIPP plunged once more this week – what on earth ought to I do?

Why worth shares are outperforming progress shares in 2026

March 3, 2026
Nasdaq Needs Buyers to Make Sure or No Bets on Its Index amid Occasion-Buying and selling Increase

Nasdaq Needs Buyers to Make Sure or No Bets on Its Index amid Occasion-Buying and selling Increase

March 3, 2026
Shiba Inu Eyes Potential Rebound as Ethereum Tokenization Expands

Shiba Inu Eyes Potential Rebound as Ethereum Tokenization Expands

March 3, 2026

CoinInight

Welcome to CoinInsight.co.uk – your trusted source for all things cryptocurrency! We are passionate about educating and informing our audience on the rapidly evolving world of digital assets, blockchain technology, and the future of finance.

Categories

  • Bitcoin
  • Blockchain
  • Crypto Mining
  • Ethereum
  • Future of Crypto
  • Market
  • Regulation
  • Ripple

Recent News

OpenAI Abandons SWE-bench Verified After Discovering 59% of Failed Exams Had been Flawed

OpenAI Abandons SWE-bench Verified After Discovering 59% of Failed Exams Had been Flawed

March 3, 2026
The three largest stinkers in my SIPP plunged once more this week – what on earth ought to I do?

Why worth shares are outperforming progress shares in 2026

March 3, 2026
  • About
  • Privacy Poilicy
  • Disclaimer
  • Contact

© 2025- https://coininsight.co.uk/ - All Rights Reserved

No Result
View All Result
  • Home
  • Bitcoin
  • Ethereum
  • Regulation
  • Market
  • Blockchain
  • Ripple
  • Future of Crypto
  • Crypto Mining

© 2025- https://coininsight.co.uk/ - All Rights Reserved

Social Media Auto Publish Powered By : XYZScripts.com
Verified by MonsterInsights