Taiwan's PDPA Amendment: 72-Hour Reporting
8 min read
Taiwan promulgated the amended Personal Data Protection Act, usually shortened to PDPA, on 11 November 2025, and the supporting regulations have been going out for public comment since. For any company holding member records, orders or form submissions, two changes matter most: an incident has to be reported within a deadline, and the regulator can fine you without first giving you a period to put things right. This sets out what is settled, what is still draft, and what you can prepare without waiting for either. Two things to be plain about. This is Taiwan's law and Taiwan's reform, and at the time of writing the supporting regulations are still at the public comment stage rather than in force. If you sit under the GDPR or another regime the ideas will look familiar and the thresholds will not match. And this is a general summary rather than legal advice: the announcements of the competent authority and the rules in force are what govern.
1. What the amendment changed
Oversight of personal data used to sit with the sector regulator for each industry, so the same conduct could be held to different standards depending on your line of business. The core of this amendment is to pull that together and add real enforcement tools. Five things changed.
| Item | What it becomes |
|---|---|
| The regulator | A Personal Data Protection Commission is established as the single competent authority. Existing industries keep a transition period of up to six years after the commission is set up, during which the original central sector regulator or the local government still has jurisdiction |
| Incident reporting | Written into the law. Where a personal data incident occurs and meets a defined scope, it must be reported to the competent authority, with prompt and effective response measures taken and records kept |
| Notifying the people affected | Tightened. "The incident is still under investigation" and "we did not breach the Act" are no longer grounds for delaying the notice |
| Penalties | For failures such as not reporting an incident or having no security maintenance plan, the authority may impose a penalty directly rather than first ordering correction within a set period |
| Administrative remedy | A challenge to a penalty decision now goes straight to administrative litigation |
Of those last two rows, being fined without a chance to correct first is what hits smaller companies hardest. The old pattern was that you supplied whatever was missing once you were told, that was the end of it, and the fine sat behind as a threat. Under the new rules, not having done the thing is punishable in itself, with no wait for you to remedy it. That moves compliance from "after being caught" to "routinely".
Six years of transition sounds generous, but it exists so the regulators can hand over, not as a grace period for you. The reporting duty and the security maintenance requirement are a separate question from who enforces them.
2. What the three supporting regulations cover
The Act itself only sets direction. What decides how far you have to go is these three regulations.
The first is the amendment to the enforcement rules. It changes how "no longer able to identify a specific person" is assessed, judging by the technical methods available at the time whether the data can still directly identify a specific individual. In plain terms, your claim that a dataset is de-identified and therefore out of scope gets measured against what technology can currently do. Masking a few columns being enough today does not mean it is enough next year.
The second is the regulation on security maintenance and management of personal data files. It requires every non-government entity to follow a common set of security measures, with additional requirements for larger ones. This is the one that touches daily work most, and section four takes it apart.
The third is the regulation on personal data incident notification, reporting and response. It answers the four questions that arise after an incident: which situations must be reported, within how long, who has to be told, and how long the records must be kept. Read this one first, because it is the only one with a clock running.
3. Reporting: which incidents, and how fast
This is the part worth knowing in advance, because the clock starts from becoming aware, not from having established the facts. Wait until the internal picture is clear and the time is usually gone.
The draft draws a line so that not every small problem reaches the regulator. Meet any one of the following and the incident falls inside the reporting scope.
Any one of these triggers reporting
- The incident involves special-category data. Medical records, healthcare data, genetic data, sex life, health examination results and criminal records, regardless of how many entries are involved.
- One hundred or more people affected. This counts the individuals affected by this incident, not the total size of your database.
- Ten thousand or more personal data records held. This one looks at the scale you normally hold, independent of how big the incident is.
Seventy-two hours sounds generous and is not. Incidents tend to surface at a weekend or over a holiday, and inside that window you have to judge the scope, confirm how many records are involved, decide who to notify and find somebody with the authority to sign it off. So what needs preparing is not the reporting form. It is the process for who gets called when something looks wrong and who makes the call. The form can always be filled in on the day. The process cannot be invented on the day.
The investigation and the response measures also have to be recorded for later inspection. That is the easiest thing to drop at the time, because everybody is busy stopping the bleeding. Put one person in charge of writing down times and actions, and the things that cannot be reconstructed afterwards do not go missing.
4. The security maintenance plan: who needs one, and what goes in it
The draft splits the requirement into two levels. Every non-government entity follows the common security measures, which is the floor. Larger organisations, meaning those that are not small or medium enterprises and hold ten thousand or more personal data records, also have to implement enhanced measures.
The common measures are basic work: periodically taking stock of which personal data you hold, managing personnel security, running training. That level is what most small companies have to reach, so there is no need to frighten yourself. The enhanced measures are the substantial project, covering a written security maintenance plan, a designated responsible person, and an annual risk assessment and audit. Work out which level you are in before deciding how much to spend.
If you do have to write that plan, the content amounts to answering seven questions: which personal data you hold, where it lives, who can access it, how it is protected, what happens after an incident, how long it is kept, and how it gets deleted when the period is up. Answer those seven fully and the document is complete.
Looked at another way, the value of the document is not how it reads. It is that it forces you to take an honest inventory of what you store and who can reach it. Most companies turn up data on the first pass that should have been deleted long ago: a sign-up list from an event three years back, an account still active for somebody who left, a customer list an outsourced supplier took a copy of at the time. Nobody thinks about any of it day to day, and all of it counts towards your numbers when something goes wrong.
5. Five things you can do now
The effective date is not set and all three regulations are still drafts. The five below are useful whatever the final wording says, and once they are done, compliance is mostly a matter of writing them up as a document.
Five things that do not depend on the rules being finalised
- Inventory the personal data you hold. Member records, orders, booking records, form submissions, support conversations and sign-up lists all count. Include the copies scattered across colleagues' spreadsheets and mailboxes, which is usually where the gap is.
- Count the records. That number decides which level of requirement you fall into, and whether an incident has to be reported. Most people's estimate from memory is far off the real figure, and almost always low.
- Tidy up access rights. Who can view, who can export, whether accounts for leavers are disabled, whether an outsourced supplier still has access. This takes the longest and turns up problems most directly.
- Confirm the site itself has no obvious holes. Forms that collect personal data running over an encrypted connection, passwords stored irreversibly, two-factor authentication on the admin area, and the system and plugins kept updated. However complete the documents are, a site with a hole in it still ends badly.
- Write down the incident process. Who gets called first, who judges the scope, who decides on reporting, what you say publicly. One page is enough, but it has to exist before the incident.
None of the five needs the wording finalised and none of them is wasted. Even if the final thresholds differ from the current drafts, you still end up holding a clear list of your data, a clean permissions table, and a page telling you who to call.
6. The timetable is still moving, so do not work from old summaries
The amended Act has been promulgated, but the date it takes effect is for the Executive Yuan to set separately. The three supporting regulations are still at the public comment stage and their content may change. That means some of the summaries findable online were written against earlier versions: the numbers look confident and are already out of date.
To check the current position, read the announcements from the Personal Data Protection Commission, which is the only authoritative source. The statute itself is published in full on Taiwan's national law database. The thresholds and deadlines in this piece also come from the drafts and may be adjusted before they are finalised. Confirm what the text actually says at the time before committing budget or people.
One more boundary. Judgements about penalties, reporting duties and scope of application belong with a lawyer or an accountant. The technical preparation can start now; the legal determination is not something to guess at, and not something to settle on the strength of a blog post. This is a general summary, not legal advice. It also describes Taiwan's rules only, so if you hold data under another country's regime, that regime is the one you answer to.
The direction of the amendment is clear: from dealing with it after the event to being prepared before it and speaking up within a deadline after it. For a small company the most useful preparation is not studying the text. It is taking stock of what data you hold, who can reach it, and who to call when something happens. Do those three and no final wording leaves you starting from zero. As a reminder, this is a general summary of Taiwan's rules rather than legal advice, and the announcements from the Personal Data Protection Commission and the law in force are what govern.
Common questions
- We only hold a few hundred customer records. Do we still have to report?
- Under the draft thresholds, the reporting duty turns on whether the incident involves special-category data, whether one hundred or more people are affected, or whether you hold ten thousand or more personal data records. A company with a few hundred records can still fall inside the scope if a single leak affects more than a hundred people. The thresholds can be adjusted before they are finalised, so the announced text is what applies.
- Is there a security maintenance plan template we can just copy?
- You can find the structure online, but the content cannot be copied. The plan has to state which personal data you actually hold, where it lives, who can access it, how it is protected and how incidents are handled. Only you can fill those in, and most companies discover on the first attempt that permissions have never been tidied. Do the inventory first: the document is a product of the inventory, not the other way round.
- When does the new regime take effect?
- The amended Act has been promulgated, but the effective date is for the Executive Yuan to set separately, and the supporting regulations are still at the public comment stage. Because the timetable is still moving, check the Personal Data Protection Commission announcements directly for the current position rather than relying on online summaries, which may have been written against earlier versions.