TAIWAN Law and Practice Contributed by: Ken-Ying Tseng, Winona Chen and Roger Kai, Lee and Li Attorneys-at-Law
5. Security Certification for ICT Products, Services and Processes 5.1 Key Cybersecurity Certification Legislation For government agencies and specific non-gov - ernment agencies that are subject to the CSMA, the Regulations on Classification of Cyber Security Responsibility Levels classify their responsibilities into five levels (A–E) and prescribe the security require - ments for each level in terms of management, techni - cal measures, and awareness and training. For government agencies and “specific non-govern - ment agencies”, each of the competent authorities for those agencies has issued guidelines in which ISO27001 is referred to and recommended. However, there is no reference to specific cybersecurity obliga - tions that shall be imposed on government agencies or specific non-government agencies. The specific cybersecurity obligations vary among industries. For instance, operators in the telecom - munications industry are required to obtain ISO/ IEC 27001 and ISO/IEC 27011 certifications, while financial institutions are required to meet the secu - rity standards stipulated by the relevant competent authorities. According to Article 11 of the CSMA, the information security responsibility levels are classified into Level A, Level B and Level C agencies, which should respec - tively allocate at least four, two and one dedicated information security personnel. Each personnel must hold at least one professional information security cer - tification. The Administration for Cyber Security has continuously updated a list of recognised information security certification on their website. 6. Cybersecurity in Other Regulations 6.1 Cybersecurity and Data Protection Data Breach Notification According to the Personal Data Protection Act (PDPA), if personal data is involved in a data breach incident, either a public agency or a non-public agency shall inform the affected data subjects of the incident as
soon as it investigates the same. In the notice to the data subjects, the relevant facts concerning the inci - dent, such as what data was stolen, when the inci - dent happened, the potential suspects with regard to the breach and the remedial actions that have been taken, shall be described. The PDPA does not set forth any threshold for the notification to the affected data subjects. Technical and Organisational Measures (Including Data Breach Report) The Taiwanese government has implemented a decentralised approach to supervise compliance with the PDPA. Under this approach, central government authorities in various industries, as well as local gov - ernments, are granted supervisory power to enforce specific provisions outlined in the PDPA, such as stipulating rules with regard to technical and organi - sational matters for the industry sectors under their purview, as well as requiring data controllers to report data security incidents to them via a designated form (normally within 72 hours). Under the designated form, the report should normally include the following information: • basic details of the reporting entities (such as the entity’s name, the notifier’s name and contact information); • the time the incident occurred; • the type of incident (including the volume of per - sonal data affected); • the cause of the incident, damage status and potential consequences; • the response measures planned or implemented; and • the anticipated timeframe and method for notifying affected data subjects. Currently, the threshold for reporting a data breach varies across different industry sectors. Depending on the rules imposed by the competent authorities, some sectors do not have any threshold, while others may base reporting requirements on the incident’s severity or the number of affected data subjects.
403 CHAMBERS.COM
Powered by FlippingBook