TAIWAN Law and Practice Contributed by: Ken-Ying Tseng, Winona Chen and Roger Kai, Lee and Li Attorneys-at-Law
Lee and Li Attorneys-at-Law 8F, No 555 Sec 4 Zhongxiao E Rd Taipei 11072 Taiwan
Tel: +886 2 2763 8000 Fax: +886 2 2766 5566 Email: attorneys@leeandli.com Web: www.leeandli.com
1. General Overview of Laws and Regulators 1.1 Cybersecurity Regulation Strategy Taiwan’s Cybersecurity Regulatory System and the Legislative Purpose Taiwan faces national-level organised cyber threats due to its special political and economic status. As such, cybersecurity is a key policy focus. In May 2021, the Executive Yuan listed cybersecurity as one of the six core strategic industries meriting special promo - tion. Accordingly, the primary objective of the Cyber Security Management Act (CSMA) is to “proactively carry out national cyber security policies and accel - erate the construction of an environment for national cyber security” to guarantee national security and protect the public interest (Article 1 of the CSMA). In this context, cybersecurity is recognised as a nation - al security priority in Taiwan, and the government is empowered to allocate resources, co-ordinate private sector capabilities and foster the development of pro - fessional expertise to achieve these goals. Recent Amendment of the CSMA and the Relevant Regulations On 1 December 2025, the Executive Yuan announced the enforcement of amendments to the CSMA. This marks the first revision of the CSMA since its origi - nal enactment in 2019, reflecting a response to the growing severity of cyber threats and a commitment to strengthening the industry’s overall cybersecu - rity posture. Notably, the amendment transfers the authority overseeing the CSMA from the Executive
Yuan to the Ministry of Digital Affairs (MODA). It also introduces key provisions, including a clear prohibition on government agencies from downloading, install - ing or using products that may compromise national cybersecurity. Additionally, the amendment broadens MODA’s audit authority over government agencies, mandates that agencies engaging in outsourcing enter into written contracts and requires their co-operation in cybersecurity drills. Enactment of the Regulations Governing the Review of Products Endangering National Cybersecurity As noted in the foregoing, to protect government operations from potential cybersecurity threats, the CSMA expressly prohibits the use of products that could compromise national cybersecurity. Further - more, pursuant to the authority granted by the amend - ed CSMA, MODA has issued regulations establishing a standardised process for government and specific non-government agencies to report information and communication technology (ICT) products suspected of posing risks to national cybersecurity. 1.2 Cybersecurity Laws CSMA The CSMA governs the management of information and communications security by government agen - cies and certain non-government agencies (ie, criti - cal infrastructure providers, public utilities and gov - ernment-sponsored foundations). The Enforcement Rules of the CSMA further define and set forth the rules, guidelines and key terms of the CSMA.
392 CHAMBERS.COM
Powered by FlippingBook