TAIWAN Trends and Developments Contributed by: Eddie Hsiung, Tsung-Yuan Shen and Nita Ye, Lee and Li, Attorneys-at-Law
Personal data protection In addition to the management of medical devices, the protection of personal data has emerged as a key concern in the deployment of AI within the healthcare field. As AI technologies rely on vast amounts of sensi - tive patient information to enhance diagnostic accu - racy and treatment personalisation, important issues regarding the protection of personal data have arisen. The Personal Data Protection Act The Personal Data Protection Act (PDPA), last amend - ed in May 2023, serves as the core legislation for per - sonal data protection in Taiwan. Under the PDPA, “per - sonal data” encompasses any information capable of directly or indirectly identifying an individual, such as name, date of birth, national identification card num - ber, passport number, physical characteristics, finger - prints, marital status, family information, educational background, occupation, medical records, healthcare data, genetic data, sexual history, records of physi - cal examination, criminal record, contact information, financial conditions, and social activities. The PDPA outlines the responsibilities of data control - lers and processors in the collection, processing, and use of personal data, ensuring that such activities are conducted in accordance with the regulations, such as acquiring the consent of the data subject prior to the use and collection of personal data. The PDPA also prescribes requirements for personal data secu - rity, mandates timely notification in the event of data breaches, and provides mechanisms for individuals to exercise their rights regarding their personal data. Additionally, the scope of personal data is further delineated to include a distinct category of “sensi - tive personal data”, which encompasses information such as medical records, healthcare details, genetic data, sexual history, physical examination results, and criminal record. Due to the nature of such data, the PDPA imposes more stringent regulatory require - ments, mandating that such sensitive personal data may be collected, processed, and used only under specific conditions, such as where the collection, pro - cessing, and/or use is/are expressly required by law, or after provision of the data subjects’ written consent.
In the context of the healthcare sector, the personal data processed by AI largely encompass medical records and healthcare-related information, which are classified as sensitive personal data under the PDPA and are subject to more stringent regulatory requirements. Moreover, the deployment of AI within healthcare frequently entails cross-border transfer of personal data, thereby introducing additional compli - ance requirements in data protection laws. Conse - quently, the collection, processing, and use of per - sonal data in AI-driven healthcare applications will be subject to multiple layers of legal considerations and require more diligence in implementing data compli - ance mechanisms to mitigate risks and protect per - sonal data. Initiatives regarding personal health data Since its inception in 1995, Taiwan’s NHI system has been managed by the NHIA, which oversees a large volume of personal data. From 2000 to 2016, the NHIA entrusted data management to the National Health Research Institute, which created the National Health Insurance Research Database for external research. In 2012, amid rising concerns about personal data privacy, seven individuals objected to the NHIA’s dis - closure of their personal data to third parties, result - ing in petitions and administrative lawsuits that were ultimately unsuccessful. In 2017, the plaintiffs pursued a constitutional interpretation to determine the legality of such personal data release. In August 2022, Taiwan’s Constitutional Court ruled in the Judgment of Constitutional Court (111) Sian-Pan- Zi No 13 , mandating that laws must be revised within three years to strengthen protection of personal data under the PDPA. Key requirements included estab - lishing an independent oversight mechanism, defining clear regulations for NHI data usage, and permitting individuals to opt out of personal data usage. To comply, the PDPA was amended in May 2023, des - ignating the Personal Data Protection Commission (PDPC) as the authority overseeing the relevant data protection regulations. A Preparatory Office for the PDPC was accordingly established in December 2023 for the purpose of formulating organisational laws and regulations of the PDPC and revising and interpreting the PDPA. In light of the time constraint imposed by
119 CHAMBERS.COM
Powered by FlippingBook