Legal Notice: The information below has been compiled based on laws, government guidance, and publicly available information as of August 2026. It is intended for general informational purposes as a Blog article and does not constitute legal advice for any specific incident. Privacy and cybersecurity laws in Taiwan, the United States, the European Union, and Japan may be amended over time. Individual U.S. states, specific industries, and certain EU member states may also have additional requirements. Actual cases should be assessed based on the location of the data subjects, the company’s place of business, the applicable industry, the nature of the data processing activities, and the laws in effect at the time of the incident.
Personal data breaches are no longer simply a matter of “hackers stealing data.”
A misdirected email, a misconfigured cloud folder, an employee account that was never deactivated after the employee left the company, a publicly exposed API, a customer service recording stored in a shared folder, or even an employee accidentally sending a file containing personal data to the wrong recipient can all result in a personal data breach.
For ordinary individuals, the real problem is often not simply the fact that “someone has seen the data,” but the chain of risks that may arise after a breach:
- Targeted scams
- Account takeover
- Credit card fraud
- Identity theft
- Damage to privacy and reputation
- Financial losses
- Long-term harassment
For businesses, the situation is even more complicated. After a personal data breach occurs, the company may need to do more than simply patch the vulnerability. The incident may also involve:
- Incident response
- Digital forensics
- Personal data protection laws
- Reporting to regulatory authorities
- Notification of affected individuals
- Civil damages and compensation
- Administrative penalties
- Criminal liability
- GDPR
- U.S. state data breach notification laws
- Japan’s APPI
- Industry-specific regulations, including those applicable to financial institutions, healthcare organizations, and publicly listed companies
Therefore, the truly important question is not whether a personal data breach will happen, but rather:
If it really happens, do I know what I should do?
Five Things to Remember After a Personal Data Breach
If you have just received a notification saying, “Your personal data may have been compromised,” you do not necessarily need to read the entire article first.
Start by remembering these five things:
- First, confirm exactly what information was exposed.
- If your password may have been exposed, change it immediately and do not continue reusing the same password.
- If financial information was exposed, immediately contact your bank or credit card company through an official channel.
- Do not assume someone is a legitimate customer service representative simply because they know your name, address, order details, or purchase amount.
- Keep the breach notification, transaction records, text messages, emails, customer service records, and other relevant evidence.
After that, depending on the type of data involved and the circumstances of the incident, determine whether you need to report the matter to the police, file a complaint, seek compensation, or take other legal action.
I. What Is “Personal Data”? It Is More Than Just an ID Number
Under Taiwan’s Personal Data Protection Act, personal data is not limited to identification numbers.
Any information that can directly or indirectly identify a specific natural person may constitute personal data. Examples include a person’s name, date of birth, national identification number, passport number, contact information, financial circumstances, education, occupation, medical records, medical information, genetic information, health examination records, criminal records, social activities, and other similar information.
In other words:
Personal data does not necessarily have to identify someone on its own. If different pieces of information can be combined to directly or indirectly identify a specific individual, that information may also be protected under personal data protection laws.
For example:
- Name
- Phone number
- Email address
- Home address
- Order information
- Membership number
- Purchase records
- IP address
- Device information
Whether such information constitutes personal data still depends on the specific circumstances and whether it can directly or indirectly identify a particular individual.
Common types of personal data can be broadly divided into the following categories:
- Basic identification information: Name, date of birth, national identification number, passport number, and photographs.
- Contact information: Mobile phone number, address, email address, and LINE ID.
- Account and online information: Account credentials, passwords, login records, IP addresses, and device information.
- Transaction information: Orders, purchased items, payment methods, and partial credit card numbers.
- Financial information: Bank account numbers, income, loans, and credit status.
- Employment or education information: Company, job title, school, résumé, and employee number.
- More sensitive information: Medical records, medical information, genetic information, health examination records, criminal records, and similar information.
In Taiwan, the Personal Data Protection Act imposes stricter requirements on information such as medical records, medical information, genetic information, sex life, health examinations, and criminal records.
⚠️ More complete data does not necessarily mean that harm has already occurred, but it will generally increase the risks of targeted scams, identity theft, and other forms of misuse.
A breach involving only your name and email address is very different from a breach involving your name, national identification number, address, mobile phone number, bank account information, and purchase records all at once.
The latter may make it easier for criminals to impersonate a bank, e-commerce company, hospital, or government agency. They may even quote your actual order and purchase information to make their story more convincing and lower your guard.
II. What Problems Might I Face After a Personal Data Breach?
A personal data breach does not mean that “your money will definitely be stolen the next second.”
More commonly, attackers first use leaked information to establish trust and then persuade victims to take actions that put them at risk.
1. 📱 Targeted Scams and Phishing Messages
One of the most common risks after a data breach is not an immediate account takeover, but receiving a scam call from someone who “knows a lot of details” about you.
For example, the person contacting you may know:
- Your name
- Phone number
- Order information
- Purchased products
- Hotel reservation information
- Bank name
- Purchase amount
They may then claim that:
- “Your order was charged twice.”
- “There was an error with your membership upgrade.”
- “Your refund failed.”
- “Your credit card needs to be re-verified.”
Using these or similar excuses, they may ask you to operate your online banking account, use an ATM, or click on a fake website and enter your credit card or account information.
Therefore:
“They know my personal information” does not mean “they are an official representative.”
If you receive a suspicious phone call, text message, or email, find the official website or official customer service number of the relevant company or bank yourself. Do not use the contact information provided by the person who contacted you.
2. 🔑 Account Takeover
If the leaked information includes an account username and password, and you use the same password on other websites, attackers may carry out what is known as a “credential stuffing attack.”
A credential stuffing attack involves using previously leaked usernames and passwords to attempt to log into other websites or services.
For example:
Email: [email protected]
Password: 12345678
If the same password is also used for:
- Gmail
- Shopping websites
- Cloud storage
- Company systems
then a breach at one platform could potentially affect your other accounts as well.
You can think of password reuse like this:
Using the same key to open your home, office, and safe.
Once that key is stolen, the other places may also be at risk.
3. 💳 Credit Card Fraud or Financial Losses
If your credit card number, expiration date, security code, online banking credentials, or other authentication information is compromised, the following may occur:
- Unauthorized credit card transactions
- Unauthorized linking of your card to a mobile payment service
- Attempts to log into your bank account
- Unauthorized use of your account
However, it is important to note:
A financial data breach does not necessarily mean that fraudulent transactions or account losses will occur.
The actual level of risk depends on what information the attacker obtained, the authentication mechanisms used by the bank or payment platform, and whether the data is actually misused for illegal purposes.
Even if only your name, phone number, and order information were exposed, you should not take the situation lightly.
This is because scammers may first use real information to establish trust and then persuade the victim to provide additional information, such as:
- OTP verification codes
- Credit card security codes
- Online banking passwords
- Identity verification information
4. 🪪 Identity Theft
After a copy of your national ID card, passport, National Health Insurance card, information related to your Citizen Digital Certificate, or other identifying information is exposed, criminals may attempt to use it to apply for:
- Accounts
- Mobile phone numbers or services
- Digital or virtual services
- Financial services
- Other services that require identity verification
Whether identity theft or impersonation can actually succeed still depends on the identity verification procedures used by each institution.
Therefore, the more precise statement is not:
“If your ID card information is exposed, it will definitely be misused.”
Rather:
The more complete the information, the higher the potential risk of identity theft or impersonation will generally be.
5. 🧠 Psychological Stress and Reputational Harm
If the information exposed includes:
- Medical records
- Health information
- Private contact information
- Work performance evaluations
- Family information
- Other sensitive information
it may result in:
- Anxiety
- Harassment
- Reputational damage
- Impact on personal relationships
- Impact on employment
- Invasion of privacy
Personal data protection laws do not only deal with situations in which someone “loses money to a scam.”
Where the applicable legal requirements are met, non-economic harm may also form part of a claim for damages or compensation.
III. 8 Steps to Take Immediately After Discovering a Personal Data Breach
If you receive a notification from a company or government agency stating:
“Your personal data may have been affected.”
Do not simply delete the email and move on.
It is recommended that you follow these eight steps.
1. First, Determine “What Was Exposed”
Do not stop at simply saying:
“My personal data was exposed.”
Instead, try to confirm as much of the following as possible:
- Which organization experienced the incident?
- When did the data breach occur?
- When was the breach discovered?
- What types of data were involved?
- Did the breach include passwords?
- Were the passwords securely hashed?
- Did the breach include national ID numbers, passport information, or copies of identification documents?
- Did it include credit card information, bank account details, or transaction records?
- Did it include medical or other sensitive information?
- Has the data already been made publicly available?
- Could the data potentially be downloaded, sold, or misused?
If a company notifies you that a breach has occurred, you can ask the company to explain:
- The categories of data affected
- When the incident occurred
- The remedial measures that have already been taken
- What protective actions you should take
- The appropriate contact person or department for further inquiries
2. Change Your Passwords Immediately — and Do Not Change It on Just One Website
If the exposed information may include passwords, prioritize the following accounts:
- Email accounts
- Online banking and financial accounts
- Major accounts such as Apple, Google, and Microsoft
- Social media platforms
- Messaging apps
- Shopping, hotel booking, and food delivery platforms
- Work accounts
- Cloud storage
If the same password has been used on multiple websites:
Every account that uses the same password should have its password changed.
Your new passwords should avoid using:
- Your name
- Your date of birth
- Your mobile phone number
- Your national identification number
- Simple sequential numbers or characters
- Your company name
Ideally, use a password manager to create a different, strong password for each website or service.
3. Enable Multi-Factor Authentication (MFA)
Multi-factor authentication (MFA) means that, in addition to a password, you are required to provide one or more additional forms of verification, such as:
- Authenticator apps
- Device verification
- Security keys
- Biometric authentication
Even if your password is exposed, an additional layer of authentication may still prevent an unauthorized person from logging into your account.
If a platform offers multiple options, such as:
- SMS verification
- Authenticator apps
- Passkeys
- Security keys
choose a stronger authentication method based on what the platform supports, and make sure to store your backup codes securely.
4. If Financial Information Is Exposed, Contact Your Bank Immediately
If the breach involves:
- Credit cards
- Bank accounts
- Online banking passwords
- Financial authentication information
- Mobile payment services
contact your bank directly using the official phone number listed on the bank’s website, your passbook, or the back of your credit card.
Do not use a phone number provided through a suspicious text message or an unfamiliar incoming call.
You can ask your bank to assist with:
- Temporarily suspending or replacing your credit card.
- Disabling unnecessary overseas or online transactions.
- Lowering your transfer and card spending limits.
- Checking for recent suspicious transactions.
- Resetting your online banking password.
- Resetting device bindings or linked devices.
- Enabling notifications for every transaction.
If unauthorized transactions or unexplained transfers have already occurred, immediately file a dispute with your bank and keep records of:
- Case numbers
- Dates and times of communications
- Transaction records
- Relevant documents
5. Do Not Trust Someone Simply Because They Know Your Information
After a personal data breach, one of the biggest advantages scammers have is:
They may actually know your real information.
Therefore, the fact that someone can tell you your:
- Name
- Address
- Order number
- Purchase amount
- Membership information
does not mean that the person is actually a customer service representative, bank employee, or government official.
Remember these principles:
- Do not provide SMS verification codes.
- Do not operate an ATM based on instructions given over the phone.
- Do not enable screen sharing.
- Do not allow strangers to remotely control your device.
- Do not click links in unfamiliar text messages or emails.
- Do not provide your online banking password.
- Do not provide your credit card security code.
- Hang up the phone and independently look up the official phone number before contacting the organization again.
If you have questions, you can call the 165 Anti-Fraud Consultation Hotline. If you have already fallen victim to fraud or the situation is urgent, contact the police and report the incident as soon as possible.
6. Preserve All Evidence
Keep the following:
- The breach notification sent by the company.
- The complete contents of the email.
- Screenshots of text messages and conversations on messaging apps.
- Suspicious URLs and sender information.
- Bank transaction records.
- Police report documents, including the official report copies provided when reporting the incident.
- The dates and times of calls with the company’s customer service team, along with case numbers.
- Receipts and records of expenses incurred while dealing with the incident.
- Notifications of unusual or unauthorized account logins.
Evidence is not only useful for reporting an incident to the police.
If the matter later involves:
- Complaints or appeals
- Consumer disputes
- Civil claims for compensation
- Insurance claims
- Regulatory investigations
these records may all be important and valuable.
7. Formally Submit a Written Inquiry to the Organization Responsible for the Breach
Under Taiwan’s Personal Data Protection Act, individuals have certain rights regarding their own personal data, including the right to inquire about, access, and obtain copies of their personal data, as well as to supplement or correct it. Under applicable conditions, individuals may also request that the collection, processing, or use of their personal data be suspended, or that the data be deleted.
You may submit your inquiry by email or in writing:
I recently learned that your company experienced a personal data security incident. Please explain whether I was affected, what categories of personal data were involved, when the incident occurred and when it was discovered, the possible cause of the incident, the remedial measures that have been taken so far, and what protective measures I should take. Please also provide the appropriate contact person or department for this matter and explain how I will be notified of the results of any subsequent investigation.
One advantage of handling the matter in writing is that, if a dispute arises later, you will have a record showing:
- When you made the inquiry
- What you asked
- How the organization responded
- Whether the organization handled the matter proactively
8. Continue Monitoring — Do Not Watch for Only Three Days
Personal data is not like a credit card.
A credit card can be canceled and replaced, but:
Information such as your name, date of birth, national identification number, and address may remain valid for a long time and may even be copied or reused.
Therefore, you should not monitor the situation for only a few days after a breach.
How long you should continue monitoring depends on the sensitivity of the exposed data and the level of risk involved.
It is recommended that you regularly check:
- Email login activity
- Account login records
- Credit card statements and bank transactions
- New mobile payment service linkages
- Notifications regarding mobile phone numbers or unfamiliar services
- Credit or loan-related notifications
- Whether your social media accounts show unfamiliar posts or messages (abnormal activity)
IV. If I Am a Company That Has Experienced a Personal Data Breach, What Should I Do?
A cyberattack against a company does not necessarily mean that the company has violated the law.
However, the reverse is also true:
Saying “we are also a victim” does not automatically mean that the company has no legal liability whatsoever.
Regulatory authorities and courts may further examine whether the company:
- Took appropriate security measures in advance
- Had reasonable access controls in place
- Conducted an inventory of its data
- Maintained appropriate logs
- Applied necessary security patches
- Properly managed outsourced service providers
- Took immediate action to contain the incident after discovering it
- Conducted an appropriate investigation
- Provided notifications as required by law
- Took appropriate remedial measures
Therefore, when a company handles a personal data breach, it cannot simply focus on “kicking the hackers out.”
1. 🚨 Immediately Activate Incident Response Procedures
The first priority should be to contain the scope of the incident, for example by:
- Isolating infected devices
- Disabling compromised accounts
- Revoking exposed keys
- Applying security patches
- Preventing further downloads of the affected data
- Disabling abnormal APIs
- Restricting access from suspicious sources
However:
⚠️ Do not rush to format computers, delete logs, or reinstall systems.
Doing so may destroy evidence that is needed for a subsequent investigation.
Cybersecurity, digital forensics, or professional incident response personnel should be involved to preserve:
- System logs
- Login records
- Network traffic
- EDR / SIEM records
- Access trails
- API logs
- Cloud audit logs
- Relevant devices
2. 🔎 Determine the Scope of the Incident
The company should determine:
- When the incident occurred
- When the incident was discovered
- The point of entry used by the attacker
- The cause of the attack
- The affected systems
- The categories of personal data involved
- The number of records involved
- Whether sensitive data was involved
- Whether passwords were involved
- Whether financial information was involved
- Whether the data was made publicly available
- Whether the data was downloaded
- Which customers were affected
- Which employees were affected
- Whether business partners were involved
- Whether outsourced service providers were involved
- Whether cloud service providers were involved
In particular, it is important to distinguish between:
“The system was compromised”
and:
“Personal data was confirmed to have been obtained without authorization.”
The two situations are not necessarily identical when it comes to legal analysis and incident assessment.
3. 📣 Notify the Affected Individuals
Article 12 of Taiwan’s current Personal Data Protection Act provides that when personal data held by a government agency or non-government agency is stolen, leaked, altered, or otherwise infringed upon, the organization must investigate the matter and notify the affected individuals in an appropriate manner.
Whether there is also an obligation to notify a regulatory authority, which authority must be notified, and the applicable deadline must be determined further based on the industry involved, the competent authority for the relevant business, and other applicable laws and regulations.
A notification should not simply say:
“Please remain vigilant.”
Instead, it should explain, to the extent reasonably possible:
- What happened
- When it happened
- When it was discovered
- What data may have been affected
- What actions the company has already taken
- What protective measures the affected individuals should take
- Customer service and complaint channels
- How to obtain further information
4. 🏛️ Confirm Industry-Specific Reporting Obligations
Companies cannot look only at the Personal Data Protection Act.
Different industries may also be subject to their own security and incident reporting requirements, such as:
- Financial services
- Telecommunications
- Healthcare
- Insurance
- Securities
- E-commerce
- Transportation
- Government agencies
- Entities subject to Taiwan’s Cyber Security Management Act
Therefore, companies should assess:
Personal Data Protection Act + Requirements of the Competent Authority for the Relevant Industry + Other Applicable Laws and Regulations
rather than looking at only one law.
Special Note: Taiwan’s “72-Hour” Requirement Should Not Be Applied as a Blanket Rule
The amendments to Taiwan’s Personal Data Protection Act promulgated on November 11, 2025 introduced and adjusted requirements relating to personal data security incident reporting, response, and record-keeping, and also modified certain administrative responsibilities. However, the official status of these amended provisions currently indicates that their effective date is “to be determined.”
Therefore, as of August 2026:
The “72-hour” requirement and other provisions contained in amendments that have not yet taken effect should not be treated as a uniformly applicable, currently effective personal data breach notification deadline for all companies in Taiwan.
The applicable reporting deadline should instead be determined based on the laws and regulations in force at the time of the incident, industry-specific requirements, and the requirements of the relevant competent authority.
5. 🧾 Preserve Complete Records of the Incident
The company should preserve:
- The incident timeline
- The time the incident was discovered
- The time at which the company became legally aware of the incident
- The risk assessment
- The affected data
- The number of affected individuals
- Legal assessments and determinations
- The personnel responsible for making decisions
- The time of any reports or notifications to regulatory authorities
- The contents of notifications
- Security patches and remediation measures
- Corrective and remedial measures
- Reasons for any delays
These records are not only useful for regulatory investigations, but can also help the company demonstrate whether it took reasonable measures to handle and respond to the incident.
V. What Legal Liabilities May Arise After a Personal Data Breach?
A personal data breach may involve:
- Administrative liability
- Civil liability
- Criminal liability
These three types of liability may exist simultaneously.
For example:
A company may face administrative penalties while also being subject to a civil claim for damages brought by affected individuals. If there is also an intentional unlawful act that satisfies the elements of a criminal offense, criminal liability may arise as well.
1. Administrative Liability: Regulatory Authorities May Impose Penalties and Require Corrective Action
An important distinction must be made between:
Provisions currently in force
and
Amendments promulgated in November 2025 that have not yet taken effect.
Under the currently effective framework of Taiwan’s Personal Data Protection Act, non-government agencies have a duty to maintain the security of personal data files. Article 27 currently requires appropriate security measures to be taken to prevent personal data from being stolen, disclosed, altered, or otherwise infringed upon.
Under the current Article 48, violations of the security maintenance obligations under Paragraph 1 of Article 27, among other provisions, may result in:
- A fine of NT$20,000 to NT$2 million
- An order to make corrections within a specified period
- If the violation is not corrected within the specified period, a fine of NT$150,000 to NT$15 million may be imposed for each subsequent violation
- More substantial penalties may apply in cases involving serious circumstances
These provisions arise from the currently effective security maintenance obligations and Article 48 as amended in 2023.
Therefore:
⚠️ It is not the case that “if a company is hacked, it will automatically be fined NT$15 million.”
Whether a violation has actually occurred, and the amount of any penalty, will still depend on factors such as:
- Whether the company violated its security maintenance obligations
- Whether appropriate technical measures were implemented
- Whether appropriate organizational measures were implemented
- Whether access controls were reasonable
- Whether the company conducted an inventory of its data
- Whether audit records were maintained
- Whether security vulnerabilities were patched
- Whether outsourced services and vendors were properly managed
- Whether the company responded proactively after the incident
- The findings of the regulatory authority’s investigation
In addition, Article 48 as amended in November 2025 further redesigned certain penalties relating to security maintenance and breach notification. However, these amendments have not yet taken effect.
2. Civil Liability: Affected Individuals May Seek Compensation for Damages
Under Taiwan’s Personal Data Protection Act:
- If a government agency violates the Personal Data Protection Act and infringes upon an individual’s rights, it may be liable for damages.
- If a non-government agency violates the Personal Data Protection Act and infringes upon an individual’s rights, it may likewise be liable for damages. However, a non-government agency may not be liable if it can prove that it was not acting intentionally or negligently.
Potential damages may include:
- Actual financial losses
- Necessary expenses incurred in dealing with the incident
- Infringement of privacy rights
- Damage to reputation
- Other non-economic damages
How Much Compensation Can You Receive for a Personal Data Breach?
This is one of the questions people are most concerned about.
Article 28 of Taiwan’s Personal Data Protection Act provides that if an affected individual has difficulty proving, or is unable to prove, the actual amount of damages, the individual may ask the court to determine the amount based on the circumstances of the infringement, at:
NT$500 to NT$20,000 per person per incident
as the basis for calculation.
When the same underlying facts result in the infringement of the rights of multiple individuals, the aggregate maximum amount is generally:
NT$200 million
However, the law provides for exceptions.
Most importantly:
⚠️ Receiving a personal data breach notification does not automatically entitle you to NT$20,000 in compensation.
Whether compensation can actually be claimed will generally depend on factors including:
- Whether the defendant violated the Personal Data Protection Act.
- Whether the individual’s personal data was actually infringed upon.
- Whether the company acted intentionally or negligently.
- Whether there is a causal relationship between the data breach and the damages.
- Whether the affected individual actually suffered financial or non-economic damages.
- How the court determines the circumstances and severity of the infringement.
3. Criminal Liability: Intentional Unlawful Use of Personal Data May Result in Imprisonment
A common misconception should also be avoided here:
“A personal data breach” does not automatically mean that “a criminal offense under the Personal Data Protection Act has been committed.”
A personal data breach caused solely by negligence does not automatically constitute the criminal offense set out in Article 41 of the Personal Data Protection Act.
Under the currently effective Article 41, criminal liability applies to conduct involving specific intent that violates relevant provisions of the Personal Data Protection Act and is sufficient to cause harm to another person. Such conduct may be punishable by imprisonment for up to five years, together with a fine of up to NT$1 million.
For example:
An employee intentionally steals the company’s customer list for financial gain and sells it to a group of scammers.
Compared with:
A company accidentally exposes personal data because of a configuration error.
The two situations may be evaluated very differently in terms of criminal liability.
Therefore:
When a company is attacked by hackers, the first questions should be whether its security maintenance obligations were satisfied and whether the incident was handled appropriately. Criminal liability, however, requires further examination of the individual’s subjective intent and the other statutory elements of the offense.
It should also be noted that Article 41 was amended in November 2025. The wording has been revised, but the official status currently indicates that the amendment has not yet taken effect.
VI. How Should Cross-Border Personal Data Breaches Be Handled? Regulations in the EU, the United States, and Japan
If a company operates in Taiwan but its customers, employees, or users are located in:
- the European Union
- the United States
- Japan
the personal data breach may not be governed solely by Taiwanese law.
This is particularly important for:
- Cross-border e-commerce
- SaaS
- Apps
- Cloud services
- Hotel booking platforms
- Airlines
- Financial services
- Global membership platforms
These businesses need to pay particular attention to cross-border data issues.
When assessing a cross-border incident, the question is not simply:
“Where is the company incorporated?”
Other factors may also include:
- Where the data subjects are located
- Whether the company offers goods or services to individuals in that jurisdiction
- The company’s data processing activities
- The relevant industry
- Local data protection laws
- Cross-border data transfer requirements
1. European Union: The GDPR Emphasizes Risk Assessment and 72-Hour Notification
The GDPR refers to a personal data breach as a:
Personal Data Breach
The scope is not limited to situations where “hackers steal the data.”
It may also include:
- Unauthorized access
- Unauthorized disclosure
- Loss of data
- Destruction of data
- Alteration of data
- Data becoming unavailable due to ransomware
- Accidentally sending personal data to the wrong email recipient
- Incorrect cloud access permissions
Key Steps for Handling Personal Data Breaches Under the GDPR
1. First Determine Whether the Incident Poses a Risk to the Rights and Freedoms of Natural Persons
If the incident:
is unlikely to result in a risk to the rights and freedoms of natural persons
the organization may, in principle, not be required to notify the supervisory authority.
However, the organization should still keep records of:
- What happened
- The impact
- The reasons for the assessment
- The remedial measures taken
and other relevant information.
This is an important part of the GDPR’s principle of accountability.
2. When Notification Is Required, Notify the Supervisory Authority in Principle Within 72 Hours
The core requirement of Article 33 of the GDPR is:
If a personal data breach is likely to result in a risk to the rights and freedoms of natural persons, the supervisory authority should, in principle, be notified within 72 hours after the controller becomes aware of the breach.
What is important is that:
The 72-hour period does not mechanically begin the moment someone first notices that “something seems wrong with the computer.”
The key issue is when the data controller can reasonably be considered to have become aware that:
an incident constituting a personal data breach has occurred.
Therefore, the company should clearly record the following during its incident response process:
- The time the abnormal activity was first detected
- The time the intrusion was confirmed
- The time it was confirmed that personal data had been affected
- The time the company legally became aware of the incident
If all information cannot be obtained within 72 hours, the company may submit an initial notification first and provide additional information later.
The European Data Protection Board (EDPB) also emphasizes that companies should conduct a risk assessment based on factors including the type of data, its sensitivity, the volume of data involved, potential harm, the individuals affected, and other relevant circumstances.
3. In Cases of High Risk, the Data Subjects May Also Need to Be Notified
If the personal data breach is likely to result in a:
high risk
to the rights and freedoms of natural persons, the affected individuals will generally also need to be notified without undue delay, in addition to notifying the supervisory authority.
The notification should explain as clearly as possible:
- What happened
- What types of data were involved
- What risks may arise
- What measures the affected individuals can take
- What remedial measures the company has taken
- Contact information for the appropriate point of contact
4. Data Processors Also Have a Notification Responsibility
If the incident occurs at:
- A cloud service provider
- An outsourced customer service provider
- A system maintenance and operations provider
- A SaaS provider
- Another data processor
The data processor should notify the data controller without undue delay.
Therefore, companies will often specify in their outsourcing agreements:
An internal incident notification deadline that is shorter than the statutory deadline.
For example, a company may require a vendor to notify it within several hours after discovering a suspected incident, rather than waiting until the statutory deadline is approaching.
The GDPR’s 72-Hour Rule Does Not Mean “Complete the Entire Investigation Within 72 Hours”
This point is very important.
Companies should not interpret the GDPR as requiring them to:
“Complete the entire digital forensic investigation within 72 hours.”
Instead, the key point is:
A company should not completely refrain from taking notification action simply because its investigation has not yet been completed.
The company may submit the information currently available and provide additional information later.
What Is the Maximum Fine Under the GDPR?
Administrative fines under the GDPR vary depending on the provision that has been violated.
For certain serious violations, the statutory maximum can reach:
€20 million, or 4% of the company’s total worldwide annual turnover from the preceding financial year, whichever is higher.
However, this is:
The maximum statutory limit.
It does not mean:
“A personal data breach automatically results in a €20 million fine.”
The actual penalty will still take into account factors including:
- The nature of the incident
- The duration of the violation
- Whether the conduct was intentional or negligent
- The types of data involved
- The number of individuals affected
- The extent of the harm
- The company’s level of cooperation
- The remedial measures taken
2. United States: There Is No Single Universal Rule — Both State and Industry-Specific Laws Must Be Checked
The U.S. personal data breach regulatory framework is very different from the GDPR.
Its most distinctive feature is:
There is no single federal law that covers all general businesses, all types of data, and all personal data breach incidents.
In practice, a company may need to review multiple sources of requirements at the same time, including:
- State laws
- Federal laws
- Industry-specific regulations
- Contractual obligations
- Payment card rules
- Requirements imposed by regulatory authorities
All 50 U.S. states, the District of Columbia, and certain U.S. territories have laws relating to data breach notifications. However, the requirements are not completely consistent across jurisdictions, including differences in the definition of personal information, the definition of a breach, who must be notified, notification deadlines, and exceptions for encrypted data.
Therefore:
A company cannot look only at the state where its headquarters is located.
If affected individuals are located in:
- California
- New York
- Texas
- Florida
the relevant laws of each state may need to be reviewed separately.
How Should a U.S. Company Respond After Discovering a Data Breach?
A company can establish an incident response process based on the following steps:
- Immediately establish an incident response team.
- Include cybersecurity, digital forensics, legal, operations, human resources, public relations, and senior management personnel.
- Isolate the affected systems.
- Prevent further unauthorized data exfiltration.
- Preserve digital evidence.
- Identify the point of entry of the attack.
- Identify the types of data involved.
- Determine the number of affected individuals.
- Determine the states in which the affected individuals reside.
- Analyze notification obligations on a state-by-state basis.
- Analyze federal requirements based on the applicable industry.
- Notify affected individuals.
- Patch and remediate vulnerabilities.
- Monitor for subsequent risks of identity theft or fraud.
U.S. Healthcare Industry: HIPAA
If a company is subject to HIPAA and experiences a breach involving unsecured Protected Health Information (PHI), it may be required to notify:
- Affected individuals
- HHS
- The media, in certain circumstances
If the breach involves 500 or more individuals, notification to HHS should generally be made without unreasonable delay and no later than 60 calendar days after the discovery of the breach.
If fewer than 500 individuals are affected, the HHS reporting requirements are different and notification can generally be submitted on an annual basis.
Therefore:
The U.S. “60-day” period is not a universal deadline that applies to all companies.
U.S. Public Companies: The SEC’s Four-Business-Day Disclosure Requirement
U.S. public companies must also pay attention to the SEC’s cybersecurity incident disclosure rules.
If a company determines that a cybersecurity incident is material, it is generally required to disclose the incident within:
Four business days after determining that the incident is material
through Form 8-K, Item 1.05.
This is an area where mistakes are particularly easy to make:
The SEC’s four-business-day period does not begin when the company first discovers the hacker or cyberattack.
Instead, it is tied to:
The point at which the company determines that the incident is material
and that timing is critical.
Therefore, a U.S. public company may simultaneously face:
State data breach notification laws + industry-specific laws + SEC disclosure obligations
rather than dealing with only one of these requirements.
3. Japan: The APPI Requires Mandatory Reporting and Individual Notification for Certain Serious Incidents
Japan’s primary legislation is:
Act on the Protection of Personal Information
It is commonly referred to in English as:
Act on the Protection of Personal Information (APPI)
The primary regulatory authority is:
Personal Information Protection Commission (PPC)
What Types of Personal Data Breaches May Require Notification?
One of the key features of Japan’s APPI framework is that certain types of incidents that may seriously harm the rights and interests of individuals are subject to mandatory reporting and notification requirements.
These primarily include:
- Incidents involving “Special Care-Required Personal Information,” such as medical records, health information, or criminal records.
- Incidents that may cause financial harm due to the improper use of the data, such as credit card information or accounts and passwords that enable payments.
- Incidents that may have occurred for an improper purpose, such as external intrusion, malicious removal of data by an employee, ransomware, or data theft.
- Personal data incidents involving more than 1,000 data subjects.
The Japanese PPC’s current official guidance also clearly distinguishes between the deadlines for preliminary reports and final reports.
How Should Japan’s 3–5 Day, 30-Day, and 60-Day Periods Be Understood?
When an incident meets the reporting requirements, the PPC’s current official guidance states that:
Preliminary Report
In principle:
Within 3–5 days from the date the incident is discovered
a preliminary report should be submitted.
Final Report
Under ordinary circumstances:
Within 30 days from the date the incident is discovered
the final report should be completed.
If the incident involves:
A possibility that the incident occurred for an improper purpose
the deadline for the final report may be extended to:
Within 60 days from the date the incident is discovered.
However, it is important to note:
⚠️ The 60-day period is a deadline for the final report in certain circumstances; it is not a grace period allowing a company to “wait until the 60th day before taking action.”
After discovering an incident, the company should still immediately:
- Contain the incident
- Investigate the incident
- Assess the situation
- Preserve evidence
- Determine whether a reporting obligation exists
- Notify affected individuals
Japan Also Requires Notification to Affected Individuals
For incidents that meet the applicable requirements, companies are generally required to notify the affected individuals as soon as reasonably possible.
The notification may include:
- An overview of the incident
- What types of personal data were involved
- The cause of the incident
- Potential risks
- Measures that have already been taken
- Contact information for the appropriate point of contact
If directly notifying the affected individuals is genuinely difficult, other methods that protect the rights and interests of the affected individuals may be used in accordance with the applicable requirements.
One important feature of Japan’s framework is:
The assessment is not limited to situations where it has already been confirmed that the data was downloaded.
Incidents involving the leakage, loss, or destruction of personal data, as well as incidents where there is a possibility of improper use, should all be assessed in accordance with the APPI.
The Japanese PPC’s official guidance also includes scenarios such as ransomware within the scope of incidents involving the leakage or other compromise of personal data.
VII. What Are the Differences Between Taiwan, the EU, the United States, and Japan?
| Comparison Item | Taiwan | EU GDPR | United States | Japan APPI |
|---|---|---|---|---|
| Regulatory Structure | Personal Data Protection Act + competent authorities for specific industries and industry-specific regulations | GDPR + Member State and industry-specific requirements | State laws + federal laws + industry-specific regulations | APPI + specific industry and related regulations |
| Core Assessment | Based on the laws and industry regulations in effect at the time of the incident | Based on the risk to the rights and freedoms of individuals | Based on state laws, the types of data involved, the location of affected residents, and industry-specific requirements | Based on whether the incident falls within specified serious categories |
| Regulatory Notification | Depends on the applicable laws and industry-specific requirements | Generally within 72 hours when the applicable conditions are met | Requirements vary by state and industry | Generally a preliminary report within approximately 3–5 days when the applicable conditions are met |
| Notification to Affected Individuals | Subject to the Personal Data Protection Act and related requirements | Generally required when there is a high risk | Depends on state laws and industry-specific requirements | Prompt notification when the applicable conditions are met |
| Key Characteristic | Industry-specific requirements are fragmented, and the effective date of amendments must be carefully considered | 72 hours + risk-based assessment + accountability | Highly fragmented, requiring state-by-state analysis | Specific serious incident categories + preliminary/final reporting |
| Common Mistake | Treating amendments that have not yet taken effect as current law | Waiting until the entire forensic investigation is completed before making a notification | Looking only at the state where the company’s headquarters is located | Treating the 60-day period as a grace period for handling the incident |
Sources: [eur-lex.europa.eu], [edpb.europa.eu], [ncsl.org], [hhs.gov], [sec.gov], [ppc.go.jp], [ppc.go.jp]
The Four Most Important Differences
First, the deadlines are different.
The GDPR has a relatively clear 72-hour notification rule for reporting to the supervisory authority; Japan requires a prompt preliminary report followed by additional information; in the United States, the applicable requirements must be determined based on the relevant state and industry; and in Taiwan, companies should currently assess their obligations based on the Personal Data Protection Act, industry-specific regulations, and requirements imposed by the competent authorities that were in effect when the incident occurred. The GDPR’s 72-hour rule should not simply be treated as a statutory deadline applicable to all companies in Taiwan.
Second, the notification thresholds are different.
The EU focuses on the risk to individuals’ rights and freedoms; Japan identifies specific categories such as Special Care-Required Personal Information, potential financial harm, incidents involving an improper purpose, and incidents affecting more than 1,000 individuals; in the United States, the definitions of personal information, unauthorized acquisition, and risk of harm vary from state to state.
Third, the regulatory authority structure is different.
In the EU, GDPR is enforced by data protection supervisory authorities in the respective Member States; in Japan, the PPC serves as the central authority; in the United States, an incident may involve state attorneys general, the FTC, HHS, the SEC, or other industry-specific regulators at the same time. A cross-border incident may therefore require separate notifications to multiple regulatory authorities, rather than sending one notification and assuming that all obligations have been satisfied.
Fourth, recordkeeping obligations are equally important.
Regardless of whether an external notification is ultimately required, companies should maintain records of the time the incident was discovered, the time it was legally determined to be known, the risk assessment, the affected data, the legal analysis, the decision-makers, the remedial measures, and the reasons for any delay. In particular, under the GDPR, the decision not to notify should itself be supported by documented and auditable reasons.
VIII. Have There Really Been Personal Data Breach Cases in Taiwan?
The answer is: Yes—and they have occurred in more than just technology companies.
At present, Taiwan does not have a single “personal data breach rate” that can be directly applied across all industries.
This is because notification systems are distributed among different competent authorities for specific industries, definitions of incidents vary, and some companies may not discover a breach until they encounter fraud, find their data being sold on the dark web, or become the subject of a regulatory investigation. Therefore, rather than citing a potentially misleading single percentage, it is more useful to understand the risks through actual enforcement actions and publicly disclosed cases.
Case 1: Customer Data Breach at Shanghai Commercial & Savings Bank
In 2023, Taiwan’s Financial Supervisory Commission (FSC) imposed a NT$10 million fine on Shanghai Commercial & Savings Bank over deficiencies related to a customer data breach, pursuant to the Banking Act. The FSC identified issues including inadequate controls over personal computer administrator privileges and portable devices, failure to retain logs of personal data usage in accordance with internal requirements, and incomplete testing and verification of the implementation of information security monitoring software. This case serves as a reminder that the problem is not necessarily limited to having a “weak firewall.” Access control, portable devices such as USB drives, and proper recordkeeping are equally important. See the FSC’s publicly available enforcement decision: “Case Concerning Deficiencies Related to the Shanghai Commercial & Savings Bank Customer Data Breach.”
Case 2: Leakage of First Financial Life Insurance’s Telemarketing Call Recordings
In 2025, First Financial Life Insurance was fined a total of NT$600,000 and ordered to make corrections within a specified period after using non-de-identified telemarketing call recordings for employee training. The recordings were stored in a shared public folder, were not fully included in the company’s personal data inventory, and did not have complete access and deletion logs. This case demonstrates that personal data does not exist only in databases. Customer service recordings, paper documents, shared folders, and training materials may also contain personal data. See: “Enforcement Case Concerning First Financial Life Insurance’s Telemarketing and Personal Data Protection Practices.”
Case 3: China Airlines, CarPlus Auto Rental, iRent, and Other Incidents
When explaining amendments to Taiwan’s Personal Data Protection Act in 2023, Taiwan’s National Development Council (NDC) cited personal data breach incidents involving China Airlines, CarPlus Auto Rental, and iRent, among others. The relevant transportation authorities required the companies to make corrections within specified periods and imposed penalties. These cases demonstrate that industries such as airlines, car rental, e-commerce, hospitality, financial services, and insurance can all become targets of cyberattacks or unauthorized access when they hold large amounts of consumer data.
IX. The 5 Most Common Misconceptions
Misconception 1: “Only a Leaked National ID Number Is Serious”
A combination of a name, phone number, email address, and order information may already be enough to conduct highly convincing and targeted scams.
Misconception 2: “Changing the Password Solves the Problem”
If an identity card number, address, transaction information, or medical information has already been exposed, changing a password only addresses the account security risk. It cannot eliminate other risks such as identity theft, impersonation, or violations of privacy.
Misconception 3: “The Company Was Hacked, So It Has No Responsibility at All”
Whether a company is a victim of a cyberattack and whether the company fulfilled its duty to protect personal data are two separate questions. If a company failed to implement basic security measures, access controls, or audit trails, it may still face administrative and civil liability.
Misconception 4: “If No Money Was Stolen, There Is No Basis for Compensation”
Personal data protection laws recognize non-economic damages. However, an affected individual still needs to explain how their rights were infringed, and the court will determine the matter based on the specific circumstances. Receiving a data breach notification does not automatically mean that compensation will be awarded.
Misconception 5: “Deleting the Data Means There Will Be No Evidence Left”
Randomly deleting files, reinstalling systems, or clearing logs after an incident may make an investigation more difficult. It may also prevent a company from demonstrating what security and incident-response measures it actually implemented. The proper approach is to first isolate the affected systems and preserve evidence, and then have qualified professionals conduct analysis and recovery.
X. Personal Data Breach Self-Help Checklist
👤 For Individuals
- ☐ Identify the types of data that were exposed
- ☐ Check whether passwords were included
- ☐ Change all passwords that have been reused across different services
- ☐ Enable multi-factor authentication
- ☐ Check email login activity and records
- ☐ Check social media accounts
- ☐ Contact your bank if financial information was exposed
- ☐ Check credit card and bank transactions
- ☐ Check mobile payment accounts and activity
- ☐ Keep the data breach notification
- ☐ Keep relevant text messages and emails
- ☐ Keep records of communications with customer service
- ☐ Do not click suspicious links
- ☐ Do not provide OTPs
- ☐ Do not provide credit card security codes
- ☐ Contact 165 if you suspect fraud
- ☐ Report the incident to the police as soon as possible if you have already suffered financial loss
- ☐ Continue monitoring your accounts and financial activity
🏢 For Businesses
- ☐ Activate the personal data and cybersecurity incident response team
- ☐ Establish an incident command center
- ☐ Isolate affected systems
- ☐ Prevent further damage from spreading
- ☐ Preserve system logs
- ☐ Preserve digital evidence
- ☐ Identify the point of entry of the attack
- ☐ Establish the incident timeline
- ☐ Identify the affected data
- ☐ Determine the number of affected data records
- ☐ Determine the number of affected individuals
- ☐ Determine whether sensitive data is involved
- ☐ Determine whether financial information is involved
- ☐ Determine whether the data was downloaded or publicly exposed
- ☐ Determine whether Taiwan’s Personal Data Protection Act applies
- ☐ Confirm the requirements of the competent authority for the relevant industry
- ☐ Identify which countries are involved in any cross-border data transfers
- ☐ Determine whether the GDPR applies
- ☐ Determine whether the APPI applies
- ☐ Check applicable U.S. state laws
- ☐ Determine whether industry-specific regulations such as HIPAA or SEC requirements apply
- ☐ Record the time at which the incident was legally determined to be known
- ☐ Create a list of applicable notification deadlines
- ☐ Confirm notification obligations of outsourced service providers
- ☐ Determine whether affected individuals should be notified
- ☐ Provide customer support and remediation channels
- ☐ Patch and remediate vulnerabilities
- ☐ Reset access permissions
- ☐ Revoke credentials and tokens
- ☐ Review the security practices of outsourced service providers
- ☐ Complete the incident report
- ☐ Conduct post-incident improvements
- ☐ Conduct incident response exercises
XI. How Can Businesses Prevent Personal Data Breaches?
Truly mature cybersecurity is not about waiting until a data breach occurs before taking action.
Businesses should establish a comprehensive data protection framework before an incident occurs.
1. Conduct a Thorough Data Inventory
At a minimum, a business should know:
What personal data do we have?
And:
Where is this data stored?
For example:
- Database
- NAS
- File Server
- Cloud Storage
- CRM
- ERP
- SaaS
- Customer Service Systems
- Backups
- Paper Documents
2. Establish Data Classification
Classify data according to its level of sensitivity, for example:
- Public
- Internal
- Confidential
- Personal Data
- Sensitive Personal Data
Then establish different requirements for each classification, including:
- Access Permissions
- Encryption Requirements
- Retention Periods
- Backup Methods
- Deletion Methods
3. Implement the Principle of Least Privilege
Employees should not think:
“For convenience, I should be able to access everything.”
Instead, organizations should adopt:
Need to Know
and:
Least Privilege
principles.
4. Immediately Disable Accounts When Employees Leave
Many data breaches do not necessarily come from sophisticated hackers.
They may also occur because:
A former employee’s account can still be used to log in.
Therefore, organizations should establish a process such as:
HR Offboarding Process → IT Notification → Account Deactivation → Token Revocation → VPN Revocation → Cloud Access Revocation
as a standard procedure.
5. Encrypt Important Data
At a minimum, organizations should consider:
- Encryption in Transit
- Encryption at Rest
- Encrypted Backups
- Key Management
Especially for:
- National Identification Numbers
- Financial Data
- Medical Data
- Passwords
- Sensitive Personal Data
6. Establish Logging and Monitoring
Organizations should ensure that critical systems can answer:
- Who logged in?
- Who viewed the data?
- Who downloaded it?
- Who modified it?
- When did it happen?
- From which IP address?
Without logs, when an incident occurs, organizations are often left with only:
“Guesswork.”
XII. Conclusion: After a Personal Data Breach, Speed and Documentation Are Equally Important
It is difficult to completely “undo” a personal data breach, but proper handling can significantly reduce the damage.
For individuals, the most important steps are to change passwords as soon as possible, enable multi-factor authentication, contact financial institutions, watch out for targeted scams, and preserve evidence.
For businesses, it is not enough to address technical vulnerabilities. They must also conduct incident investigations, make legal assessments, notify regulatory authorities, notify affected individuals, and implement follow-up improvements.
If an incident involves customers or employees in different countries, a business should not handle the matter solely according to the laws of the jurisdiction where the company is registered.
The same incident may trigger the EU GDPR’s 72-hour notification requirement, Japan’s APPI requirements for reporting certain serious incidents, U.S. state notification requirements, as well as industry-specific regulations applicable to financial institutions, healthcare organizations, or publicly listed companies.
For cross-border incidents, the most important step is not to choose one legal framework over another. Instead, first identify where the affected individuals are located, what types of data are involved, and which notification deadline is the shortest. Legal, cybersecurity, operations, and public relations teams should then work together to manage the content of notifications and avoid missed notifications, delayed reporting, or inconsistent statements across jurisdictions.
Personal data protection is not the responsibility of the IT department alone.
Customer service recordings, paper resumes, shared folders, marketing lists, outsourced systems, and access rights belonging to former employees can all become points of vulnerability.
A truly mature approach is to complete data inventories, access-level classifications, incident notification procedures, and regular drills before an incident occurs, rather than waiting until customers start receiving scam calls before investigating what went wrong.
Finally, remember this practical principle:
Once personal data has been exposed, control the risk first, determine the scope next, preserve evidence at the same time, and only then focus on accountability.
A truly mature organization is not defined by:
“How quickly it responds after an incident occurs.”
Instead, it is defined by whether:
Before an incident occurs, it already knows where its data is, who can access it, how access is monitored, how notifications should be made, and who is responsible for making decisions when an incident occurs.
Personal data protection is, at its core, also information security.
If you are dealing with an actual incident, you can contact the 165 Anti-Fraud Information Center to verify suspected scams. For information on personal data protection laws and government procedures, refer to the Personal Data Protection Commission Preparatory Office’s “Personal Information Breach Response Process” and the current text of the Personal Data Protection Act.
XIII. References
Laws and Government Resources
- Full Text of the Personal Data Protection Act
- Personal Information Breach Response Process
- Personal Data Breach Dispute Resolution Process
- Article 28 of the Personal Data Protection Act: Liability for Damages of Government Agencies
- Article 29 of the Personal Data Protection Act: Liability for Damages of Non-Government Agencies
- Article 41 of the Personal Data Protection Act: Criminal Liability
- Article 48 of the Personal Data Protection Act: Administrative Penalties
- Q&A on Amendments to the Personal Data Protection Act
- 165 Anti-Fraud Information Center
- National Development Council: Amendments to the Personal Data Protection Act and Penalties for Corporate Personal Data Breaches
- Related Report on the Draft Supporting Regulations for 72-Hour Personal Data Breach Notification
Taiwan Personal Data Breach and Penalty Cases
- China Airlines Customer Personal Data Breach Case: Ministry of Transportation Planned Penalties
- CarPlus Personal Data Breach: Highway Bureau Imposed a NT$100,000 Fine
- iRent Personal Data Breach: Highway Bureau Imposed a NT$200,000 Fine
- ShangHai Commercial & Savings Bank Customer Data Breach Penalty Case
- First Financial Life Insurance Personal Data Protection Penalty Case
Judicial Practice
EU GDPR and Personal Data Breach Guidelines
- EU General Data Protection Regulation (GDPR), Regulation (EU) 2016/679
- European Data Protection Board: Guidelines 9/2022 on Personal Data Breach Notification under GDPR
- European Data Protection Board: Guidelines 01/2021 on Examples regarding Personal Data Breach Notification
U.S. Personal Data Breach and Industry Regulations
- Federal Trade Commission: Data Breach Response, A Guide for Business
- National Conference of State Legislatures: Security Breach Notification Laws
- U.S. Department of Health and Human Services: HIPAA Breach Notification Rule
- U.S. Department of Health and Human Services: Submitting Notice of a Breach to the Secretary
- U.S. Securities and Exchange Commission: Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure
Japan APPI and Personal Data Breach Guidelines
- Personal Information Protection Commission, Japan: Act on the Protection of Personal Information
- Personal Information Protection Commission, Japan: Response to Personal Data Breaches and Related Resources
- Personal Information Protection Commission, Japan: Mandatory Reporting of Personal Data Breaches and Notification to Affected Individuals
- Personal Information Protection Commission, Japan: Personal Data Breach Incident Reporting System




