TAIWAN Law and Practice Contributed by: Ken-Ying Tseng, Winona Chen and Roger Kai, Lee and Li Attorneys-at-Law
Amendments to the PDPA and the Establishment of the PDPC On 11 November 2025, the PDPA underwent anoth - er round of amendments, with the effective date to be set by the Executive Yuan. The amended PDPA mainly addresses the responsibilities of the soon-to- be-established Personal Data Protection Commission (PDPC) and its succession of power from other gov - ernment authorities, becoming the only competent authority under the PDPA. According to the amended PDPA, the PDPC, after its establishment, will intro - duce a new rule regarding technical and organisational matters, including certain cybersecurity requirements relevant to personal data protection, which generally applies to all entities subject to the PDPA. 6.2 Cybersecurity and AI On 14 January 2026, the Artificial Intelligence Basic Act (the “AI Basic Act”) was formally promulgated and took effect. While the AI Basic Act is primarily principle-based and does not impose specific manda - tory requirements, it establishes a foundational legal framework empowering government authorities to develop further regulations. For instance, under the AI Basic Act, government authorities should enhance data governance by minimising unnecessary collec - tion, processing or use of personal data, while inte - grating data protection principles into the design of AI systems. Moreover, throughout the research, devel - opment and deployment of AI, appropriate cyber - security measures must be implemented to guard against security threats and attacks, thereby ensuring the integrity and safety of AI systems. Furthermore, MODA is tasked with adopting international standards to create an AI risk classification framework and sup - porting competent authorities of various industries in establishing risk-based management rules. In addition to the AI Basic Act, certain sectors have guidelines for implementing AI technology. Key guide - lines are as follows. The FSC and relevant financial industry associations have issued guidelines governing the use of AI in the financial sector. Notably, the Operational Guidelines for Financial Institutions Using Artificial Intelligence Technology (the “FSC AI Guidelines”), published by the Banking Association, require financial institutions
to uphold the principle of fair treatment throughout all stages of AI algorithm development and deploy - ment in financial services. Furthermore, during the AI model training phase, institutions must safeguard the integrity and security of AI models and algorithms by implementing robust measures such as data quality control, model validation and ongoing monitoring. The FSC AI Guidelines align with existing cybersecurity and data protection requirements, while also introduc - ing specific obligations tailored to the responsible use of AI technology in the financial industry. The Executive Yuan has promulgated the Guidelines for the Application of Artificial Intelligence in National Critical Infrastructure (the “CI AI Guidelines”), which are designed specifically for the competent authorities overseeing industry sectors and the critical infrastruc - ture providers under their supervision. The CI AI Guidelines establish recommended risk categories for the deployment of AI technologies and require the adoption of appropriate mitigation meas - ures. In cases where no effective measures exist, the use of AI may be prohibited. Additionally, the CI AI Guidelines enhance the obligations set forth by the CSMA and the relevant regulations regarding the implementation of AI. For instance, regulated entities should incorporate safety design principles during the design phase of the product development life cycle. For incident reporting, the CI AI Guidelines adhere to the Regulations on the Notification and Response of Cyber Security Incident, mandating that incidents be reported within one hour of discovery. Similar to the FSC AI Guidelines, the CI AI Guidelines align with existing cybersecurity and data protection require - ments. 6.3 Cybersecurity in the Healthcare Sector The MOHW, under the authorisation of the CSMA, has issued the Regulations for Information Security Man - agement of Specific Non-Government Agencies under the MOHW (the “MOHW Regulations”). The MOHW Regulations set forth clear and detailed requirements that designated non-government agencies must fol - low when developing and executing their cybersecu - rity maintenance plans.
404 CHAMBERS.COM
Powered by FlippingBook