← All legal documents · Privacy Policy · Children's Privacy Notice

Balance — Taiwan Country Annex

Effective date: 28 June 2026 Last updated: 28 June 2026

Owner: , Director, BabaYaga Program, TOO — Privacy Officer and Designated Child Safety Officer for every Taiwanese resident covered by this Annex; the Data Protection Officer ("DPO") under the Personal Data Protection Act (Chinese: 個人資料保護法, the "PDPA Taiwan") read with the Organic Act of the Personal Data Protection Commission (Chinese: 個人資料保護委員會組織法) passed by the Legislative Yuan (Chinese: 立法院) on 19 December 2024 and promulgated by Presidential Decree on 1 January 2025 (the "PDPC Taiwan Organic Act") + the Enforcement Rules of the Personal Data Protection Act (Chinese: 個人資料保護法施行細則) (the "PDPA Taiwan Enforcement Rules") + the Personal Data Protection Commission of the Republic of China (Chinese: 個人資料保護委員會, the "PDPC Taiwan") subordinate-rules series in operational transition during 2025-2026 (the PDPA Taiwan does not at the Effective date contain a strict statutory mandatory-DPO requirement equivalent to GDPR Article 37 / PDPA Singapore Section 11(3) / PDPA Thailand Section 41 / PDPA Malaysia Section 12A / PIPL Article 52, but Balance designates inline as best practice consistent with PDPC Taiwan transitional guidance + the Article 6 sensitive-data + children's-data heightened-protection framework + the international DPO standard); with business contact published as the publicly-accessible privacy contact under PDPA Taiwan Article 8 + Article 9 + Article 13 transparency obligations; the designated contact point for the Personal Data Protection Commission (the "PDPC Taiwan"), the Ministry of Digital Affairs (Chinese: 數位發展部, the "MODA"), the Ministry of Justice (Chinese: 法務部, the "MOJ"), the National Police Agency (Chinese: 內政部警政署, the "NPA"), the Ministry of Justice Investigation Bureau (Chinese: 法務部調查局, the "MJIB"), the Ministry of Health and Welfare — Children and Families Agency (Chinese: 衛生福利部社會及家庭署, the "CFA, MOHW"), the National Communications Commission (Chinese: 國家通訊傳播委員會, the "NCC"), the Financial Supervisory Commission (Chinese: 金融監督管理委員會, the "FSC") — to the extent any FSC-sector regulation engages, the Ministry of Economic Affairs (Chinese: 經濟部, the "MOEA"), the Consumer Protection Committee of the Executive Yuan (Chinese: 行政院消費者保護委員會, the "CPC") + the Department of Consumer Protection of the Executive Yuan, the Taiwan Computer Emergency Response Team / Coordination Center (Chinese: 臺灣電腦網路危機處理暨協調中心, the "TWCERT/CC"), and the Institute of Watch Internet Network (Chinese: 網路內容防護機構, the "iWIN") under their respective intake protocols. Reviewed: at least once a year, by 9 June. Re-opened immediately on (a) any amendment to the Personal Data Protection Act (Chinese: 個人資料保護法, "PDPA Taiwan") — the principal substantive provisions of which trace their lineage to the Computer-Processed Personal Data Protection Act of 1995 (Chinese: 電腦處理個人資料保護法) (the "1995 Act") subsequently substantively renamed and modernised by the Personal Data Protection Act Amendment of 26 May 2010 (Chinese: 個人資料保護法修正) (the "2010 Amendment") (the renaming and modernisation in force in stages from 1 October 2012 with the Article 6 sensitive-personal-data provision finally in force from 15 March 2016 by Executive Yuan Order (Chinese: 行政院令) — the "2012 Commencement / 2016 Article 6 Commencement"); further substantively amended by the PDPA Taiwan Amendment of 30 December 2015 (the "2015 Amendment") refining the Article 6 sensitive-data regime + the cross-border transfer regime under Article 21 + the Article 41 criminal-liability quanta; further substantively amended by the PDPA Taiwan Amendment of 16 May 2023 in force 31 May 2023 (the "2023 Amendment") introducing Article 1-1 requirement for the establishment of the independent supervisory authority + heightened administrative fines + supplementing the Article 12 data-subject-notification obligation operationalisation — and any further amendment thereto including any future PDPA Taiwan Amendment (the § 18 versioning protocol covers their enactment); (b) any amendment to the Six Personal Data Protection Principles at PDPA Taiwan Article 5 (personal data shall be collected, used, processed lawfully and properly without exceeding the necessary scope of the specific purpose and with respect for the rights and interests of the data subject in a manner of good faith and reasonableness) + Article 6 sensitive personal data (medical records / health-examination results / genetic data / sex life / criminal record + biometric data prescribed by central competent authority — Balance does NOT process Article 6 sensitive personal data of Taiwanese residents) + Article 7 consent + Article 8 transparency notice when data are collected from data subject + Article 9 transparency notice when data are collected from a source other than the data subject + Article 10 right of access + Article 11 right of correction / right of supplementation / right of deletion / right of cessation of collection / use / disclosure / right of refusal to provide further data + Article 12 data-subject-notification obligation on breach ("in a timely manner" / Chinese: 適當方式) + Article 13 response window + Article 14 prescribed fee + Article 15-19 non-government-agency collection / use / disclosure rules + Article 20 use beyond original purpose + Article 21 cross-border transfer restrictions + Article 22-25 central-competent-authority supervisory powers; (c) any Regulation (規則), Order (命令), Directive (指令), Notice (公告), or Determination (認定) issued by the PDPC Taiwan under the PDPC Taiwan Organic Act Article 4 + Article 5 + the PDPA Taiwan Article 22 — including the body of historical pre-PDPC-Taiwan-era subordinate instruments which the PDPC Taiwan is in operational transition during 2025-2026 to issue / re-issue / consolidate / replace, including the Personal Data Protection Act Enforcement Rules (Chinese: 個人資料保護法施行細則) (most recently amended 1 March 2016 + 1 July 2023), the Regulations Governing the Security Maintenance and Management of Personal Data Files for Specific Non-government Agencies Designated by the National Communications Commission, the Regulations Governing the Security Maintenance and Management of Personal Data Files for Specific Non-government Agencies Designated by the Financial Supervisory Commission, the Regulations Governing the Security Maintenance and Management of Personal Data Files for Specific Non-government Agencies Designated by the Ministry of Economic Affairs, the Restriction on Cross-Border Transfers of Personal Data by NCC-Supervised Non-Government Agencies to Mainland China (NCC Order Tong-Tong-Wei-Zi No. 10141050780 of 17 September 2012) (NOT applicable to Balance — Balance is not an NCC-supervised non-government agency), the Restriction on Cross-Border Transfers of Personal Data by FSC-Supervised Non-Government Agencies to Mainland China (NOT applicable to Balance — Balance is not FSC-supervised), and any further PDPC Taiwan subordinate legislation; (d) any decision of the District Court (Chinese: 地方法院), the High Court (Chinese: 高等法院), the Supreme Court (Chinese: 最高法院), the Administrative Court (Chinese: 行政法院) — including the High Administrative Courts (Chinese: 高等行政法院) and the Supreme Administrative Court (Chinese: 最高行政法院) — or the Constitutional Court (Chinese: 憲法法庭, since the 4 January 2022 reform replacing the Council of Grand Justices) bearing on the PDPA Taiwan, on the Constitution of the Republic of China (1947) Article 12 (secrecy of correspondence) read with the Judicial Yuan Interpretation No. 603 (J.Y. Interpretation No. 603, 28 September 2005, recognising the right to informational self-determination / 資訊自主權 / right to informational privacy as a constitutional right anchored in Constitution Articles 22 + 23), Judicial Yuan Interpretation No. 631 (intercept), Judicial Yuan Interpretation No. 689 (paparazzi privacy), and on the established privacy doctrines applied by Taiwanese courts; (e) any amendment to the Children and Youth Welfare and Protection Act (Chinese: 兒童及少年福利與權益保障法) (the principal Taiwanese child-welfare statute, originally Children's Welfare Act 1973 + Youth Welfare Act 1989 + Children and Youth Welfare Act 2003 + renamed and substantively re-enacted as Children and Youth Welfare and Protection Act on 30 November 2011 + multiply amended through to most recent 2023 amendment) including the Children and Youth Welfare and Protection Act Amendment in force from 11 January 2023; (f) any amendment to the Criminal Code (Chinese: 中華民國刑法, the "Criminal Code") — in particular Article 221 (rape), Article 222 (aggravated rape), Article 225 (sexual intercourse / indecent act with persons unable to resist), Article 227 (sexual intercourse / indecent act with persons under 14 — statutory rape — aggravated; with persons 14 to under 16 — lesser penalty), Article 227-1 (reduction in special-circumstance cases involving persons under 18), Article 228 (sexual coercion by trust / authority / supervision), Article 230 (incest), Article 231 (procurement for sexual intercourse / indecent act), Article 231-1 (aggravated procurement for sexual purposes with persons under 18), Article 233 (procurement of person under 18 for sexual purposes), Article 234 (intentional public indecent acts), Article 235 (manufacture / distribution / sale / public exhibition of obscene articles / writing / pictures / sound recording / video — modulated by Constitutional Court Judgment 113-Hsien-Pan-3 of 26 January 2024 declaring the Article 235 obscenity-test elements unconstitutional to the extent they capture artistic / scientific / educational / non-harmful materials, with a 2-year sunset for legislative revision — § 18 versioning trigger covers the legislative successor instrument), and Articles 358-363 Chapter 36 Offences Against Computer Use (Article 358 unauthorised intrusion into computer system; Article 359 unauthorised acquisition / deletion / alteration of electromagnetic records of others; Article 360 unauthorised interference with computer of others; Article 362 manufacture of malicious computer programme; Article 363 prosecution-on-complaint); (g) any amendment to the Child and Youth Sexual Exploitation Prevention Act (Chinese: 兒童及少年性剝削防制條例, the "CYSEPA"), originally Child and Youth Sexual Transactions Prevention Act 1995 renamed and substantively amended by the 2017 Amendment in force 1 January 2018 + further amended 27 May 2023 to expand online-grooming and CSAM offences — in particular Article 31 (using child or youth in sexual transactions / sexual exploitation), Article 32 (mediating sexual transactions with child or youth — heightened penalty for force / coercion / threat / fraud / drug), Article 33 (advertising sexual transactions with child or youth on broadcast / television / electronic information / internet / printed press), Article 34 (production / publication of advertisement of sexual transactions with child or youth in any medium — broader than Article 33), Article 36 (production / direction / aid in the production / facilitation of sexual exploitation visual or audio materials of child or youth — CSAM production offence), Article 37 (sale / transfer / lease / transmission of CSAM with intent), Article 38 (possession of CSAM without reasonable cause — possession offence introduced by 2017 amendment), Article 39 (advertising / soliciting CSAM dissemination), Article 40 (online-grooming offence — using internet or electronic communications to solicit child or youth to engage in sexual transactions / sexual activity / production of CSAM — introduced by 2017 amendment + strengthened by 2023 amendment), Article 50 mandatory reporting by enumerated personnel including telecoms and internet operators of CSAE-suspect content + Article 51 mandatory cooperation; (h) any amendment to the Communication Security and Surveillance Act (Chinese: 通訊保障及監察法, the "CSSA") in force from 14 July 1999, substantively amended by the Communication Security and Surveillance Act Amendment of 23 January 2014 introducing the application of telecommunications data warrant regime + the 2018 amendment refining the retention-and-destruction-of-data-from-intercepts protocols + the 2020 amendment on real-time interception of equipment-based communications — Articles 5-7 judicial-warrant intercept regime + Article 11 emergency intercept + Article 13 retention + Article 18-1 voluntary cooperation by operators + Article 32-1 cross-border cooperation request; (i) any amendment to the Cyber Security Management Act (Chinese: 資通安全管理法) in force 1 January 2019 — Critical Information Infrastructure (CII) regime administered by MODA; Balance NOT designated as CII at the Effective date — § 18 versioning protocol covers any designation; (j) any amendment to the Consumer Protection Act (Chinese: 消費者保護法, the "CPA Taiwan") originally enacted 11 January 1994 + multiply amended most recently 1 February 2023 — in particular Article 11-1 prudent-content review of standard contracts + cooling-off-of-standard-contracts review + Article 19 mail-order / distance-selling 7-day right of rescission (Chinese: 七日鑑賞期 — qī rì jiànshǎngqī) for distance-selling contracts measured from receipt of goods or commencement of services + Article 19-2 refund obligations + Article 51 punitive damages up to ten times the actual damages for malicious acts + Article 53 consumer-protection injunctive remedy + the Application Conditions of Article 19 Paragraph 1 Reasonable Exception (Chinese: 通訊交易解除權合理例外情事適用準則) of 1 January 2016 setting out the seven categories of distance-selling transaction excluded from the 7-day right of rescission — including digital content / online services where the consumer has expressly consented to immediate performance and acknowledged the loss of the right of rescission; (k) any amendment to the Multi-level Marketing Supervision Act + the Electronic Signatures Act (Chinese: 電子簽章法) + the Civil Code (Chinese: 民法) — in particular Article 12 (age of majority — 18 years since the Civil Code Amendment of 22 December 2020 in force from 1 January 2023 lowering the age of majority from 20 to 18), Article 13 (juveniles 7 to under 18 of limited legal capacity), Article 75 juristic acts by persons without legal capacity are void, Article 77-79 (juristic acts by persons of limited legal capacity require the legal representative's consent; an act done without that consent is voidable + Article 79 ratification by the legal representative + Article 84 specific carve-outs for trade-and-profession acts of limited-capacity persons working with legal-representative consent), Articles 184-188 tort liability, Article 195 compensation for non-pecuniary damage for personality-right infringement including life / body / health / liberty / credit / privacy / chastity / other personality interests, and Articles 1084-1090 parental rights and responsibilities; (l) any amendment to the Computer-Processed Personal Data Protection Act of 1995 (Chinese: 電腦處理個人資料保護法) (now superseded by the renamed-and-modernised PDPA Taiwan via the 2010 Amendment); (m) any amendment to a sub-processor's Taiwanese data-handling posture under our sub-processor register; (n) the bringing into force of any post-Effective-date Taiwanese regulation governing automated processing or related techniques (covered by the deliberate-silence carve-out in § 2 of this Annex); (o) Taiwan's accession to (or domestic implementation of) the Council of Europe Convention 108 / Convention 108+ (Taiwan is not a party — Taiwan is not a member of the Council of Europe and the unique-status complications affect treaty accessibility for Taiwan) or the Convention on Cybercrime (Budapest Convention — Taiwan is not a party for the same unique-status reasons) — § 18 versioning protocol covers any domestic-implementation initiative; (p) any amendment to the Money Laundering Control Act (Chinese: 洗錢防制法) insofar as it engages production orders against non-government agencies; (q) any Order or Directive issued under PDPA Taiwan Article 21 restricting cross-border transfers of personal data by non-government agencies in defined sectors, or any Restriction on Cross-Border Transfers by a central competent authority (MODA / NCC / FSC / MOEA / others) under PDPA Taiwan Article 21; (r) any amendment to the Mutual Legal Assistance in Criminal Matters Act (Chinese: 國際刑事司法互助法) in force 6 June 2018 — and any change to the body of bilateral mutual-legal-assistance arrangements that Taiwan maintains via its diplomatic surrogates including the Agreement on Mutual Legal Assistance in Criminal Matters between the American Institute in Taiwan and the Taipei Economic and Cultural Representative Office in the United States signed 26 March 2002 in force 28 March 2002 (the "Taiwan-US MLAA"). Classification: Public legal annex. This document is published at Privacy Policy alongside the global Privacy Policy (H1) and at Children's Privacy Notice alongside the Children's Privacy Notice (H2), and is incorporated by reference into both. It is one of the country annexes that travel with the global documents under the "global policy + per-country annex" architecture documented in our internal compliance plan § 6.3.

This Annex discharges the country-annex obligations referenced in:

This Annex is the canonical Taiwanese-resident extension of the global Privacy Policy and Children's Privacy Notice. Where this Annex grants a Taiwanese resident a right that the global Policy does not, this Annex governs. Where the global Policy grants a Taiwanese resident a right that this Annex does not, the global Policy governs. The two are read together.

This Annex is drafted in English. The official language of the Republic of China (Taiwan) is Mandarin Chinese written in Traditional Chinese characters (Chinese: 繁體中文 / 正體中文); Taiwanese Hokkien, Hakka, and the official languages of the 16 indigenous peoples recognised under the Indigenous Peoples Basic Law (Chinese: 原住民族基本法) of 5 February 2005 read with the Development of National Languages Act (Chinese: 國家語言發展法) of 9 January 2019 are national languages with statutory protection. Traditional Chinese translation of this Annex is queued for the Phase-2 locale rollout per our internal compliance tracker. No translation is statutorily required at the Effective date for the English-language privacy notice to a Taiwanese resident (the PDPA Taiwan does not mandate Mandarin Chinese / Traditional Chinese notification; the PDPC Taiwan transitional interpretive practice + the legacy MOJ interpretive practice accepts notices in English provided the notice is intelligible to the data subject — and PDPC Taiwan transitional guidance prefers Traditional Chinese notification for materially-affected Taiwanese-resident data subjects, which Balance will deliver via the Phase-2 locale rollout).


1. Scope and applicability

This Annex applies to every Balance user (parent or kid) whose country of residence is Taiwan — the territory under the effective jurisdiction of the Republic of China comprising the islands of Taiwan / Formosa (organised as 6 special municipalities (直轄市) — New Taipei / Taipei / Taoyuan / Taichung / Tainan / Kaohsiung — 3 provincial cities () — Keelung / Hsinchu / Chiayi — 13 counties () — Hsinchu / Miaoli / Changhua / Nantou / Yunlin / Chiayi / Pingtung / Yilan / Hualien / Taitung / Penghu / Kinmen / Lienchiang/Matsu), plus the offshore islands under ROC effective control (Penghu Archipelago / Kinmen / Matsu Islands / Pratas Islands / Itu Aba / Taiping Island). There is no provincial / county-level data-protection sub-layer that derogates from the PDPA Taiwan in respect of Balance's commercial processing (the PDPA Taiwan applies uniformly across the territory under ROC effective jurisdiction).

We determine country of residence at install/sign-up time by (a) the country the parent self-declares in the in-app onboarding flow, (b) the IP-geolocation read at sign-up (which we discard immediately after the residence decision — our internal data-flow map § 2.1 stores no IP after the authentication request closes), and (c) the Play Store account locale that Google Play passes to us at install (which for Taiwan defaults to zh-TW — Traditional Chinese, Taiwan). The residence determination is reviewable at any time by the parent at Settings → Account → Region.

Where any of the three signals identifies Taiwan as the country of residence, this Annex applies, even if the other signals are non-Taiwanese. The most-protective-for-the-data-subject reading is the controlling reading per our internal compliance plan § 6.3.

The PDPA Taiwan has explicit territorial reach defined at Article 51 paragraph 2 of the PDPA Taiwan: the PDPA Taiwan applies to a non-government agency outside the territory of the Republic of China that collects, processes, or uses the personal data of a data subject in the Republic of China. Balance squarely targets Taiwanese residents through Google Play Taiwan, through publication of this Annex at balance.babayagaprogram.com, and through delivery of the parental-control service to Taiwanese-resident parents and kids; the PDPA Taiwan applies in respect of all personal data Balance processes in connection with Taiwanese-resident users via Article 51 paragraph 2 (extraterritorial reach to non-government agency outside the ROC processing the personal data of a data subject in the ROC).


2. Statutory framework — what applies

The Taiwanese personal-data-protection regime is dominated by the Personal Data Protection Act (Chinese: 個人資料保護法, "PDPA Taiwan"), traced to the Computer-Processed Personal Data Protection Act of 11 August 1995 (the "1995 Act") substantively renamed and modernised by the PDPA Taiwan Amendment of 26 May 2010 (the "2010 Amendment") in force in stages from 1 October 2012 by Executive Yuan Order of 21 September 2012 with the Article 6 sensitive-personal-data provision in force from 15 March 2016 by Executive Yuan Order; substantively refined by the 2015 Amendment of 30 December 2015 (Article 6 sensitive-data regime + Article 21 cross-border transfer regime + Article 41 criminal-liability quanta); and most recently amended by the 2023 Amendment of 16 May 2023 in force from 31 May 2023 introducing Article 1-1 requirement for the independent supervisory authority + heightened administrative-fine quanta + supplementing Article 12. The PDPA Taiwan is supplemented by the Personal Data Protection Act Enforcement Rules (Chinese: 個人資料保護法施行細則) most recently amended 1 July 2023 (the "PDPA Taiwan Enforcement Rules"), and by the body of central-competent-authority subordinate instruments which the PDPC Taiwan is in operational transition during 2025-2026 to issue / re-issue / consolidate / replace. Adjacent layers: the Constitution of the Republic of China (1947) Article 12 + the Judicial Yuan Interpretation No. 603 (28 September 2005, recognising the right to informational self-determination); the Children and Youth Welfare and Protection Act (Chinese: 兒童及少年福利與權益保障法); the Criminal Code including Chapter 16 Offences Against Sexual Autonomy + Chapter 36 Offences Against Computer Use; the Child and Youth Sexual Exploitation Prevention Act (Chinese: 兒童及少年性剝削防制條例); the Communication Security and Surveillance Act (CSSA); the Cyber Security Management Act; the Consumer Protection Act (CPA Taiwan); the Civil Code (Chinese: 民法); the Electronic Signatures Act; the Money Laundering Control Act; the Mutual Legal Assistance in Criminal Matters Act read with the Taiwan-US MLAA of 2002.

Instrument Short cite What it does Balance's posture
Constitution of the Republic of China ROC Constitution — promulgated 1 January 1947 + in force 25 December 1947, with subsequent Additional Articles of the Constitution (most recently amended 2005). Article 8 habeas-corpus protection + Article 12 secrecy of correspondence — the express constitutional anchor of communicational privacy; Article 22 catch-all other freedoms and rights of the people not detrimental to social order or public welfare — the textual foundation for the constitutional right to informational self-determination / informational privacy read with Judicial Yuan Interpretation No. 603 of 28 September 2005 (Chinese: 司法院釋字第603號解釋, the principal constitutional-court ruling on informational privacy); Article 23 limitation clause (rights may be restricted by law where necessary to prevent infringement of others' rights / to avoid imminent danger / to maintain social order / to advance public welfare); Article 80 independence of the judiciary; Article 156 state duty to protect maternity and children. The Constitutional Court (Chinese: 憲法法庭) since the 4 January 2022 reform replacing the Council of Grand Justices hears constitutional questions including individual constitutional complaints under the Constitutional Court Procedure Act of 4 January 2022 (Chinese: 憲法訴訟法). The constitutional anchor. The right to informational privacy in Taiwan is constitutional (Articles 22 + 23 + 12 + Judicial Yuan Interpretation No. 603) AND statutory (PDPA Taiwan + adjacent regimes). Applies as the constitutional layer. Treatment in §§ 3, 6, 13 below.
Personal Data Protection Act PDPA Taiwan — traced to the Computer-Processed Personal Data Protection Act of 11 August 1995 (the "1995 Act") substantively renamed and modernised by the PDPA Taiwan Amendment of 26 May 2010 in force in stages from 1 October 2012 by Executive Yuan Order of 21 September 2012 with Article 6 sensitive-personal-data provision in force from 15 March 2016; substantively refined by the 2015 Amendment of 30 December 2015; most recently amended by the 2023 Amendment of 16 May 2023 in force 31 May 2023. Chapter 1 General Provisions (Articles 1-14 — purpose + definitions + lawful-bases framework); Article 1 purpose (to govern the collection / processing / use of personal data to prevent infringement of the personality right + to facilitate the proper use of personal data); Article 1-1 (introduced by 2023 Amendment) the requirement to establish an independent supervisory authority; Article 2 definitions (personal data / collection / processing / use / non-government agency); Article 5 the foundational principle: personal data shall be collected / used / processed lawfully and properly without exceeding the necessary scope of the specific purpose and with respect for the rights and interests of the data subject in a manner of good faith and reasonableness; Article 6 sensitive personal data heightened regime — categories: medical records / health-examination results / genetic data / sex life / criminal record + biometric data prescribed by central competent authority + such other personal data that the central competent authority designates (the principal categories codified at the time of the 2015 Amendment and operative since the 15 March 2016 commencement) — strict lawful-bases regime for collection / processing / use of Article 6 sensitive personal data (Balance does NOT process Article 6 sensitive personal data of Taiwanese residents); Article 7 consent — written consent + electronic-equivalent consent under the Electronic Signatures Act; Article 8 transparency notice when data collected from data subject — purposes + categories + intended scope of use + recipients + rights + consequences of non-provision; Article 9 transparency notice when data collected from a source other than the data subject — purposes + categories + intended scope of use + recipients + rights + sources + consequences (with specified carve-outs); Article 10 right of access including right to obtain a copy of the personal data being processed + the PDPA Taiwan Enforcement Rules Article 26 + Article 13 of the PDPA Taiwan 15-working-day response window for data-access requests + extendable by 15 working days on notice; Article 11 right of correction / right of supplementation / right of deletion / right of cessation of collection or processing or use / right of refusal to provide further data + obligation to cease processing on a finding of unlawful collection / processing / use; Article 12 data-subject-notification on breach — when personal data has been stolen / disclosed / altered or otherwise infringed in violation of the PDPA Taiwan, the data controller (the term used in PDPA Taiwan is non-government agency — Chinese: 非公務機關) shall notify the data subject in a timely manner (Chinese: 以適當方式); Article 13 response window — 15 working days extendable by 15 working days; Article 14 prescribed fee for the data-access request (the PDPA Taiwan Enforcement Rules limit the fee to actual cost; Balance does not charge in practice). Chapter 2 Collection / Processing / Use by Government Agencies (Articles 15-18 — n/a to Balance). Chapter 3 Collection / Processing / Use by Non-Government Agencies (Articles 19-27): Article 19 lawful-bases catalogue for non-sensitive personal data — (1) specifically prescribed by law; (2) performance of contract or quasi-contract; (3) data already disclosed by the data subject themselves or other lawful disclosure; (4) academic research carried out by an academic-research institution / based on public interest / proportional; (5) with the written consent of the data subject under Article 7; (6) advancement of public interest; (7) personal data obtained from sources generally accessible to the public, except where the data subject's significant interest in protecting that data should prevail; (8) other; Article 20 use beyond original purpose — limited to the carve-outs of (1) statutory requirement; (2) public interest; (3) vital interest of the data subject; (4) explicit written consent; (5) personal data obtained from generally accessible sources; (6) academic research; (7) public-interest mission of public authority; Article 21 cross-border transfer restriction — the central competent authority for the industry of the non-government agency may RESTRICT the cross-border transfer of personal data in defined circumstances: (1) involves major national interest; (2) any international treaty or agreement so provides; (3) the receiving country lacks adequate regulations governing personal data protection and the data subject's rights and interests are likely to be infringed; (4) cross-border transfer is conducted via a third country to circumvent the PDPA Taiwan — the principal sectoral restrictions in force at the Effective date target Mainland China for NCC-supervised telecoms operators (NCC Order Tong-Tong-Wei-Zi No. 10141050780 of 17 September 2012) and FSC-supervised financial institutions (not applicable to Balance); Article 22-25 central-competent-authority supervisory powers (investigation + remediation + administrative-action orders); Article 27 data-security obligation — non-government agencies shall implement appropriate security measures to prevent personal data from being stolen / altered / damaged / destroyed / disclosed; the central competent authority may further prescribe data-protection plans + designated personnel (the operational anchor of the sectoral Regulations Governing the Security Maintenance and Management of Personal Data Files for Specific Non-government Agencies issued by NCC / FSC / MOEA in their respective sectors — none of which engage Balance directly as a non-NCC / non-FSC / non-MOEA-supervised entity, but the substantive standards are adopted by Balance as best practice). Chapter 4 Damages and Civil Remedies (Articles 28-31 — civil liability for damages caused by infringement; punitive elements; Article 28 government-agency civil liability; Article 29 non-government-agency civil liability — strict liability with diligent-good-faith carve-out; Article 28(3) statutory damages from NT$500 to NT$20,000 per data subject per infringement + Article 28(4) class-action mechanism + Article 31 statute of limitations). Chapter 5 Penalties (Articles 41-50): Article 41 criminal-liability quantum — unlawful collection / processing / use of personal data with intent to obtain unlawful profit for self or others or with intent to harm the rights and interests of others — imprisonment up to 5 years + criminal fine up to NT$1 million; Article 42 offences for altering / destroying / making impossible the use of personal data files; Articles 47-48 administrative fines (the 2023 Amendment raised administrative fines for serious violations to NT$15 million per violation for repeat / aggravated cases); Article 50 legal-person liability + officer-in-default liability. Chapter 6 Supplementary Provisions (Articles 51-56): Article 51 paragraph 1 carve-out for purely personal / household activities; Article 51 paragraph 2 extraterritorial reach — the PDPA Taiwan applies to a non-government agency outside the territory of the Republic of China that collects / processes / uses the personal data of a data subject in the Republic of China; Article 52 central-competent-authority designation framework; Article 53 PDPA Taiwan Enforcement Rules authorisation. The principal statute. Applies in full to Balance as a non-government agency established outside Taiwan that targets services to Taiwanese residents (Article 51 paragraph 2 extraterritorial reach). Treatment in §§ 3, 4, 6, 7, 8, 11, 13 below.
Personal Data Protection Act Enforcement Rules PDPA Taiwan Enforcement Rules — first issued by the Ministry of Justice on 26 September 2012 + multiply amended (most recently 1 July 2023). Operationalises the PDPA Taiwan including definitions of personal data + lawful bases + the Article 10 access procedure + the Article 11 correction / deletion procedure + the Article 27 data-security operational guidance + cross-border transfer factors. Article 12 general categories of personal data; Article 17 Article 8 transparency-notice content; Article 22 + Article 26 Article 10 access response specifications; Article 35 Article 12 data-subject-notification operationalisation (notification must contain the facts of the breach + the response measures taken); Article 17 non-government agency's data-security plan content; Article 18 designated personnel obligations. Applies in full. The operational implementation of the PDPA Taiwan. Treatment in §§ 6, 11 below.
Organic Act of the Personal Data Protection Commission PDPC Taiwan Organic Act — passed by the Legislative Yuan on 19 December 2024 and promulgated by Presidential Decree on 1 January 2025. The Organic Act establishes the Personal Data Protection Commission (Chinese: 個人資料保護委員會, the "PDPC Taiwan") as the independent supervisory authority for the PDPA Taiwan, satisfying the Article 1-1 requirement introduced by the 2023 Amendment. Article 2 functions of the PDPC Taiwan include (1) the formulation of personal-data-protection policy; (2) supervision and enforcement of the PDPA Taiwan; (3) administrative-action proceedings; (4) public education; (5) international cooperation; (6) coordination with central competent authorities. Article 3 independence (the PDPC Taiwan exercises its functions independently). Articles 4-6 composition (the PDPC Taiwan comprises Commissioners nominated by the Premier with approval of the Legislative Yuan; Chairperson + Vice-Chairperson + members). Articles 7-10 office + budget. Articles 11-13 transitional provisions (operational transition during 2025-2026 from the legacy fragmented sectoral-supervisor model — under which the MOJ was the cross-cutting interpretive authority + the NCC / FSC / MOEA / other central competent authorities supervised within their sectors — to the unified PDPC Taiwan model). The independent supervisory authority. Applies. Operational transition during 2025-2026. Treatment in § 3 below.
Children and Youth Welfare and Protection Act CYWPA — Chinese: 兒童及少年福利與權益保障法. Originally Children's Welfare Act 1973 + Youth Welfare Act 1989 + Children and Youth Welfare Act 2003 + renamed and substantively re-enacted as Children and Youth Welfare and Protection Act on 30 November 2011 + multiply amended through to most recent 11 January 2023 amendment. Article 2 definitionschild (Chinese: 兒童 / ér-tóng) means a person under 12 years of age; youth (Chinese: 少年 / shào-nián) means a person 12 to under 18 years of age; children and youth (Chinese: 兒童及少年) is the umbrella term; Article 4 state duty to safeguard the interests of children and youth + best interest of the child as the primary consideration; Article 7 government coordination; Article 19 general welfare provisions; Article 43 prohibited acts directed at children and youth including consumption of inappropriate substances + viewing of inappropriate content; Article 46 the Institute of Watch Internet Network (iWIN) statutory anchor — the Ministry of Health and Welfare shall coordinate with relevant agencies to establish a network-content protection institution + iWIN is the operative implementation; Article 47 internet-content classification system; Article 49 prohibited acts against children and youth including (1) abandonment; (2) abuse; (3) failure to provide adequate care + supervision; (4) sale / transfer / pledge / mortgage of child or youth; (5) production / sale / dissemination of CSAM; (6) using child or youth to engage in begging / illegal / immoral / dangerous acts; (7) employment in inappropriate places; (15) using child or youth as photograph subject or video subject for sexual purpose; (16) disclosing identifying information of child or youth in a manner detrimental to the child or youth; Article 53 mandatory reporting by enumerated personnel (medical / educational / childcare / police / judicial / social-work / community-care personnel) of suspected child abuse / neglect / exploitation + good-faith-reporting immunity; Article 54 government cooperation duties; Article 69 anonymity protection — broadcast / television / electronic / print media shall not disclose any information that may reveal the identity of a child or youth involved in (1) victim of crime; (2) defendant or suspect; (3) administrative cases involving the child or youth; Article 97 penalties (administrative fines + business-licence suspension for severe violations of Article 49). The principal Taiwanese child-welfare statute. Applies. Treatment in § 5 + § 14 below.
Criminal Code Criminal Code — Chinese: 中華民國刑法. The principal general criminal statute, originally enacted 1 January 1935 + multiply amended. Substantive sections relevant to Balance's child-safety + lawful-access posture: Chapter 16 Offences Against Sexual AutonomyArticle 221 rape (imprisonment 3-10 years; heightened if aggravated under Article 222); Article 222 aggravated rape (imprisonment 7+ years to life — including the aggravator of the victim being a person under 14); Article 224 indecent act by force / threat / coercion / drug / hypnosis / against will (imprisonment 6 months-5 years); Article 224-1 aggravated indecent act (imprisonment 3-10 years); Article 225 sexual intercourse / indecent act with persons unable to resist; Article 227 sexual intercourse / indecent act with persons under 14 — statutory rape — paragraph 1 sexual intercourse with person under 14 (imprisonment 3-10 years) + paragraph 2 indecent act on person under 14 (imprisonment 6 months-5 years) + paragraph 3 sexual intercourse with person 14 to under 16 (imprisonment up to 7 years) + paragraph 4 indecent act on person 14 to under 16 (imprisonment up to 3 years); Article 227-1 reduced or exempt penalty for offences under Article 227 where actor is under 18 — special provision for adolescent-on-adolescent cases; Article 228 sexual coercion by trust / authority / supervision (imprisonment up to 6 months-5 years for sexual intercourse; up to 3 years for indecent act); Article 230 incest (imprisonment up to 5 years); Article 231 procurement for sexual intercourse / indecent act (imprisonment up to 5 years + fine); Article 231-1 aggravated procurement for sexual purposes with persons under 18 (imprisonment 7+ years to life — heightened against use of force / coercion / threat / fraud / drug); Article 233 procurement of person under 18 for sexual purposes; Article 234 intentional public indecent acts; Article 235 manufacture / distribution / sale / public exhibition of obscene articles / writing / pictures / sound recording / video — MODULATED BY Constitutional Court Judgment 113-Hsien-Pan-3 of 26 January 2024 declaring the Article 235 obscenity-test elements unconstitutional to the extent they capture artistic / scientific / educational / non-harmful materials, with a 2-year sunset for legislative revision — § 18 versioning trigger; Chapter 36 Offences Against Computer UseArticle 358 unauthorised intrusion into computer system (imprisonment up to 3 years + fine NT$100K); Article 359 unauthorised acquisition / deletion / alteration of electromagnetic records of others (imprisonment up to 5 years + fine NT$600K); Article 360 unauthorised interference with computer of others (imprisonment up to 3 years + fine); Article 362 manufacture of malicious computer programme + harm caused (imprisonment up to 5 years + fine); Article 363 prosecution-on-complaint requirement for certain Chapter-36 offences. Applies. Treatment in § 14 below.
Child and Youth Sexual Exploitation Prevention Act CYSEPA — Chinese: 兒童及少年性剝削防制條例. Originally Child and Youth Sexual Transactions Prevention Act 1995 + renamed and substantively amended by the 2017 Amendment in force 1 January 2018 + further substantively amended by the 2023 Amendment of 27 May 2023 to expand online-grooming and CSAM offences. The principal Taiwanese CSAE statute. Article 1 purpose (preventing sexual exploitation of children and youth); Article 2 definitions including sexual exploitation (Chinese: 性剝削) — engaging child or youth in sexual transactions / sexual activities for filming / photographing / public exhibition; victim child or youth protective regime; Article 31 using child or youth in sexual transactions — basic offence — imprisonment 1-7 years (heightened if victim under 14 — imprisonment 7+ years to life); Article 32 mediating sexual transactions with child or youth — heightened penalty for force / coercion / threat / fraud / drug; Article 33 advertising sexual transactions with child or youth on broadcast / television / electronic information / internet / printed press — imprisonment up to 5 years + fine; Article 34 production / publication / dissemination of advertisement of sexual transactions with child or youth in any medium — imprisonment up to 5 years + fine; Article 36 the principal CSAM-production offence — production / direction / aid in the production / facilitation of sexual exploitation visual or audio materials of child or youth — imprisonment 1-7 years (heightened if victim under 14 — imprisonment 3-10 years; heightened if force / coercion / threat / fraud / drug — imprisonment 7+ years to life); Article 37 the CSAM-distribution offence — sale / transfer / lease / transmission / public exhibition of CSAM with intent — imprisonment up to 2-5 years + fine; Article 38 the CSAM-possession offence introduced by 2017 amendment — possession of CSAM without reasonable cause — imprisonment up to 1 year + fine + mandatory destruction; Article 39 the CSAM-advertising offence — advertising / soliciting CSAM dissemination — imprisonment up to 3 years + fine; Article 40 the ONLINE-GROOMING offence introduced by the 2017 amendment + strengthened by the 2023 amendment — using internet / electronic communications / equivalent technology to solicit child or youth to engage in sexual transactions / sexual activity / production of CSAM — imprisonment up to 3 years + fine NT$100,000-1,000,000; Article 50 mandatory reporting by enumerated personnel of suspected CSAE — including educational personnel + childcare personnel + medical personnel + police + judicial personnel + social-work personnel + telecoms and internet operators with respect to CSAE-suspect content; Article 51 mandatory cooperation. The principal Taiwanese CSAE statute. Applies. Treatment in § 14 below.
Communication Security and Surveillance Act CSSA — Chinese: 通訊保障及監察法. Enacted 14 July 1999 + substantively amended by the 2014 Amendment (introducing the application of telecommunications data warrant regime + the new-form intercept-of-electronic-equipment-based-communications protocols) + the 2018 Amendment (refining retention-and-destruction-of-data-from-intercepts) + the 2020 Amendment (real-time interception of equipment-based communications); the principal Taiwanese interception / communications-security statute. Article 5 judicial-warrant intercept regime — interception of communication content requires a court-issued warrant on probable cause of an enumerated qualifying offence + the necessity test + the proportionality test; Article 7 emergency intercept by prosecution with retrospective judicial review; Article 11 scope and form of warrant; Article 13 retention of intercept records; Article 18-1 voluntary cooperation by operators where lawful basis is engaged; Article 32-1 international-cooperation framework for cross-border intercept requests; Articles 24-27 of the Application of Telecommunications Data Regime (the 2014-Amendment-introduced warrant regime for non-content communications-data — separate from the Article 5 content-intercept regime). The principal Taiwanese intercept / communications-data statute. Applies. Treatment in § 13 below.
Cyber Security Management Act Cyber Security Management Act — Chinese: 資通安全管理法. In force 1 January 2019. The principal Taiwanese cybersecurity statute. Establishes the Department of Cyber Security + (post-2022) MODA cyber-security division as the cross-government cybersecurity coordinator + the Critical Information Infrastructure (CII) regime applicable to designated CII operators (government agencies + critical-private-sector CII designees). Cybersecurity-incident notification obligations on CII operators (initial notification within 1 hour for the most serious incidents). Balance is NOT designated as Critical Information Infrastructure under the Act; § 18 versioning protocol covers any designation. Voluntary cooperation with TWCERT/CC (the national CERT) is honoured as a best-effort security overlay. Applies as a context-setting fact (Balance not designated as CII). Treatment in § 13 below.
Consumer Protection Act CPA Taiwan — Chinese: 消費者保護法. Enacted 11 January 1994 + multiply amended (most recently 1 February 2023). Chapter 1 definitions (Article 2 — consumer / business operator / consumer relationship); Chapter 2 Health and Safety Articles 7-10 product safety; Chapter 3 Health Information Notice and Standardised Contracts Articles 11-17 — Article 11-1 prudent-content review of standard contracts + cooling-off-of-standard-contracts review (the Consumer Protection Committee may prescribe model standard-contract content for specific sectors + business operators using standard-form contracts must afford the consumer a reasonable period to review the contract before execution); Chapter 4 Special Trading Practices Articles 18-19-2 — Article 18 mail-order / distance-selling and door-to-door selling disclosure requirements + Article 19 mail-order / distance-selling 7-DAY RIGHT OF RESCISSION (Chinese: 七日鑑賞期) — measured from receipt of goods / commencement of services + Article 19-2 refund obligations — within 15 days of rescission notice; the principal distance-selling consumer protection in Taiwan. The Application Conditions of Article 19 Paragraph 1 Reasonable Exception (Chinese: 通訊交易解除權合理例外情事適用準則) of 1 January 2016 sets out the seven categories of distance-selling transaction excluded from the 7-day right of rescission: (1) goods that may deteriorate / spoil within the rescission period; (2) goods customised to the consumer's specifications; (3) goods that have been mixed with other goods after delivery; (4) sealed audio / video / software products that have been unsealed; (5) services that have been performed before the rescission period expires with the consumer's express consent (operative for digital online services where the consumer has expressly consented to immediate performance and acknowledged the loss of the right of rescission — the operative carve-out for typical online-subscription supply); (6) newspapers / periodicals; (7) online digital content that has commenced provision after the consumer's express consent. Chapter 5 Consumer Protection Administration Articles 39-49 — Consumer Protection Committee of the Executive Yuan + Department of Consumer Protection of the Executive Yuan + Consumer Protection Officers; Chapter 6 Consumer Disputes Articles 43-46 — consumer-dispute mediation regime + Consumer Dispute Mediation Committee; Chapter 7 Consumer Protection Litigation Articles 47-55 — class-action regime + Article 51 punitive damages up to 10 times the actual damages for malicious acts + Article 53 injunctive remedy by consumer-protection group. Enforced by the Consumer Protection Committee of the Executive Yuan + the Department of Consumer Protection of the Executive Yuan + local-government Consumer Protection Officers + the local Consumer Dispute Mediation Committees + the District Courts under the Article 47-55 litigation regime. The principal Taiwanese consumer-protection statute. Applies in full. Treatment in § 16 below.
Civil Code Civil Code — Chinese: 民法. The principal Taiwanese civil statute, originally enacted in stages 1929-1931 + multiply amended. Article 12 age of majority — 18 years since the Civil Code Amendment of 22 December 2020 in force from 1 January 2023 lowering the age of majority from 20 to 18 (the corresponding amendments to the Civil Code Articles 13 / 980 / 1077 / 1086 / 1118 + multiple ancillary statutes that referenced age of 20 have been harmonised in the 1 January 2023 commencement package); Article 13 persons under 7 of no legal capacity; persons 7 to under 18 of limited legal capacity (under the 1 January 2023 amendments); Article 75 juristic acts by persons without legal capacity are void; Article 76 juristic acts of persons without legal capacity to be performed by the legal representative; Article 77 juristic acts of persons with limited legal capacity require the consent of the legal representative; Article 78 unilateral juristic acts of persons with limited legal capacity without legal-representative consent are void; Article 79 bilateral juristic acts of persons with limited legal capacity without legal-representative consent are voidable until ratified by the legal representative; Article 80 legal-representative response deadline upon counterparty inquiry; Article 81 voidable / valid distinctions; Article 82 counterparty's right of revocation in respect of voidable juristic acts of limited-capacity persons; Article 83 misrepresentation of legal capacity; Article 84 specific carve-out for trade-and-profession acts of limited-capacity persons working with legal-representative consent; Article 85 specific carve-out for limited-capacity persons engaged in commerce with legal-representative consent; Article 86 statutory carve-outs; Articles 184-188 tort liability — Article 184 general tort + Article 184(2) breach of statutory duty + Article 185 joint tortfeasors + Article 188 employer liability; Article 195 compensation for non-pecuniary damage for personality-right infringement — life / body / health / liberty / credit / privacy / chastity / other personality interests; Articles 1084-1090 parental rights and responsibilities (jointly exercised by both parents under Article 1089; substituted decision-maker scheme on disagreement). Applies. Treatment in § 16 below.
Money Laundering Control Act Money Laundering Control Act — Chinese: 洗錢防制法. The principal Taiwanese anti-money-laundering statute. Engages production orders against non-government agencies. Enforced by the Investigation Bureau of the Ministry of Justice (Anti-Money Laundering Division). Applies. Treatment in § 13 below.
Mutual Legal Assistance in Criminal Matters Act + Taiwan-US MLAA Mutual Legal Assistance in Criminal Matters Act — Chinese: 國際刑事司法互助法. In force 6 June 2018. The principal Taiwanese foreign-state-cooperation statute in criminal matters — given Taiwan's unique international-law status the operative framework is via Taiwan's diplomatic surrogates and bilateral arrangements. The Agreement on Mutual Legal Assistance in Criminal Matters between the American Institute in Taiwan and the Taipei Economic and Cultural Representative Office in the United States (the "Taiwan-US MLAA") signed 26 March 2002 in force 28 March 2002 is the principal bilateral mutual-legal-assistance arrangement covering the US; bilateral arrangements exist with multiple other partners. Applies. Treatment in § 13 below.
EU adequacy None. Taiwan does not hold an EU adequacy decision under GDPR Article 45 at the Effective date. Taiwan applied for adequacy assessment in 2018 + the European Commission has not issued an adequacy decision. EU/EEA → Taiwan transfers are governed by EU SCCs + Transfer Impact Assessment. Cross-reference in EU / EEA annex § 8. The absence of EU adequacy does not affect Balance's posture because Balance has no Taiwanese data residency (the backend is in the US — see § 9 below).
Convention 108 / Convention 108+ Not applicable. Taiwan is not a party to the Council of Europe Convention 108 or Convention 108+. Taiwan is not a member of the Council of Europe and the unique-status complications affect treaty accessibility for Taiwan. Applies as a context-setting fact. Treatment in § 8 below.
APEC Cross-Border Privacy Rules (CBPR) Taiwan (under the name Chinese Taipei as used in APEC) has been an APEC participating economy since 1991. Taiwan formally joined the operational APEC CBPR system + the APEC PRP (Privacy Recognition for Processors) on 4 December 2018 as a participating economy with an Accountability Agent designation; the operational Accountability Agent designation for Taiwan is the Institute for Information Industry (Chinese: 財團法人資訊工業策進會, the "III") under MOEA / MODA coordination. Applies as a context-setting fact + as an additional contractual-protection overlay route via III as Accountability Agent for Taiwan-to-third-country APEC-region transfers; the principal operational mechanism for Balance is the PDPA Taiwan Article 21 + the PDPC Taiwan transitional cross-border framework.
Budapest Convention on Cybercrime Not applicable at the Effective date. Taiwan is not a party to the Convention on Cybercrime (Budapest Convention) for the same unique-status reasons. Applies as a context-setting fact. Cross-border lawful-access for Taiwan is via the Mutual Legal Assistance in Criminal Matters Act + the Taiwan-US MLAA + bilateral arrangements via Taiwan's diplomatic surrogates.

(Any prospective Taiwanese regulation governing automated processing, algorithmic decisions, or related techniques — including any post-Effective-date PDPC Taiwan Regulation / Order / Notice in that area, the Taiwan AI Basic Act draft (Chinese: 人工智慧基本法草案) submitted by the Executive Yuan to the Legislative Yuan in May 2024 + still under legislative review at the Effective date, the Reference Guidelines on Generative AI Use by Executive Yuan and its Subordinate Agencies (issued by MODA in September 2023, voluntary guidance for government agencies only), the MODA Reference Guidance on the Safe Use of Generative AI in the Public Sector, any future Taiwanese primary legislation on artificial intelligence before the Legislative Yuan, and any successor instrument — is intentionally omitted from this Annex on the principle that this Annex makes no affirmative or negative statement about whether Balance does or does not process personal data using techniques within the scope of any such Taiwanese regulation. Balance's substantive product posture is described elsewhere in the policy bundle and is the controlling reference; this Annex's silence on the topic is deliberate and is not to be read as an implicit statement either way.)


3. Supervisory authorities

3.1 PDPC Taiwan — Personal Data Protection Commission

The principal supervisory authority is the Personal Data Protection Commission (Chinese: 個人資料保護委員會, the "PDPC Taiwan"), the independent supervisory authority established under the Organic Act of the Personal Data Protection Commission passed by the Legislative Yuan on 19 December 2024 and promulgated by Presidential Decree on 1 January 2025, satisfying the Article 1-1 requirement introduced by the PDPA Taiwan 2023 Amendment. The PDPC Taiwan is in operational transition during 2025-2026 from the legacy fragmented sectoral-supervisor model — under which the Ministry of Justice (Chinese: 法務部, the "MOJ") was the cross-cutting interpretive authority via the Department of Legal Affairs and the central competent authorities (NCC / FSC / MOEA + others) supervised within their respective sectors — to the unified PDPC Taiwan model. Until the PDPC Taiwan is fully operational, the legacy fragmented model continues to apply concurrently. The PDPC Taiwan's decisions are appealable to the High Administrative Courts under the Administrative Procedure Act (Chinese: 行政程序法) + the Administrative Litigation Act (Chinese: 行政訴訟法) and onwards to the Supreme Administrative Court.

Field Value
Name Personal Data Protection Commission (Chinese: 個人資料保護委員會, PDPC Taiwan)
Status Independent supervisory authority under the Organic Act of the Personal Data Protection Commission (promulgated 1 January 2025); in operational transition during 2025-2026
Headquarters At the Effective date — published at PDPC Taiwan operational website (transition under way)
Website At the Effective date — PDPC Taiwan operational website is being brought online; legacy interpretive authority via MOJ Department of Legal Affairs at https://www.moj.gov.tw/
Complaint channel At the Effective date — PDPC Taiwan complaint portal is being brought online; complaints may continue to be filed via the relevant central competent authority + via MOJ Department of Legal Affairs until the PDPC Taiwan portal becomes operational; § 18 versioning protocol covers full PDPC Taiwan operationalisation
Phone Published at PDPC Taiwan operational website
Data-Subject-Notification channel Balance follows PDPA Taiwan Article 12 in a timely manner (Chinese: 以適當方式) data-subject notification + the PDPA Taiwan Enforcement Rules Article 35 minimum-content schedule; PDPC Taiwan notification operational rules are tracked under § 18

The PDPC Taiwan is the first-line forum for any PDPA-Taiwan-grounded complaint from any Taiwanese resident on full operationalisation. Pending full operationalisation, a Taiwanese resident may pursue complaints via (i) the relevant central competent authority (NCC / FSC / MOEA + sectoral supervisors) for any sectoral-supervised non-government agency (n/a directly to Balance — Balance is not in an NCC / FSC / MOEA-supervised sector); (ii) the Ministry of Justice Department of Legal Affairs for cross-cutting PDPA Taiwan interpretive matters; (iii) the Consumer Protection Officers at the local-government level for consumer-protection-affecting privacy complaints; (iv) the District Court for the PDPA Taiwan Article 28-31 civil-liability action. We accept all data subject access / privacy enquiries at (named individual: , in his capacity as the designated DPO consistent with PDPC Taiwan transitional guidance) and respond within the PDPA Taiwan timelines (see § 6 below).

A Taiwanese resident may also pursue private remedies via (i) the PDPA Taiwan Chapter 4 civil liability under Articles 28-31 (including the statutory-damages range of NT$500 to NT$20,000 per data subject per infringement at Article 28(3) and the class-action mechanism at Article 28(4)); (ii) the Civil Code Article 195 personality-right compensation for invasion of privacy (one of the enumerated personality interests in Article 195(1)); (iii) the Civil Code Articles 184-188 general tort liability; (iv) the Constitutional Court Constitutional Court Procedure Act of 4 January 2022 individual constitutional complaint route in connection with state action invoking the Constitution Article 22 + Article 23 + Article 12 + Judicial Yuan Interpretation No. 603 informational-privacy doctrine.

3.2 Legacy central competent authorities (transitional)

Until the PDPC Taiwan is fully operational, the legacy central competent authorities continue to exercise sectoral supervision concurrently:

Body Sectoral subject matter URL
Ministry of Justice (MOJ) — Department of Legal Affairs法務部法律事務司 Cross-cutting PDPA Taiwan interpretive authority + body of interpretive Letter Replies under PDPA Article 53 https://www.moj.gov.tw/ — +886 2 2191 0189
National Communications Commission (NCC)國家通訊傳播委員會 PDPA Article 27 sectoral data-security regulations for telecoms / broadcasting / communications + Article 21 cross-border restriction order for telecoms operators (Tong-Tong-Wei-Zi No. 10141050780 of 17 September 2012 — n/a to Balance) https://www.ncc.gov.tw/
Financial Supervisory Commission (FSC)金融監督管理委員會 PDPA Article 27 sectoral data-security regulations for financial-services non-government agencies + Article 21 cross-border restriction order for financial-services operators (n/a to Balance) https://www.fsc.gov.tw/
Ministry of Economic Affairs (MOEA)經濟部 PDPA Article 27 sectoral data-security regulations for non-government agencies in the commerce / industry sector https://www.moea.gov.tw/
Ministry of Digital Affairs (MODA)數位發展部 Cyber Security Management Act + digital-platform-services regulatory coordination + cross-government digital-governance functions transferred to MODA on its establishment 27 August 2022 https://moda.gov.tw/

3.3 Other regulatory bodies

Body Subject matter URL
Ministry of Health and Welfare (MOHW) — Children and Families Agency (CFA, MOHW)衛生福利部社會及家庭署 Children and Youth Welfare and Protection Act lead agency + iWIN coordination https://www.sfaa.gov.tw/
Ministry of Health and Welfare (MOHW) — Protective Services Section Children + women + family-violence protective services https://www.mohw.gov.tw/ — Hotline 113 Women & Children Protection Hotline (24/7)
Institute of Watch Internet Network (iWIN)網路內容防護機構 Statutory CYWPA Article 46 internet-content-protection institution + INHOPE-member CSAM hotline https://www.iwin.org.tw/
National Police Agency (NPA), Ministry of the Interior內政部警政署 Criminal investigation; emergency 110 https://www.npa.gov.tw/ — Emergency 110
Criminal Investigation Bureau, NPA內政部警政署刑事警察局 National criminal investigation including cybercrime + CSAE https://www.cib.gov.tw/
Ministry of Justice Investigation Bureau (MJIB)法務部調查局 National security + cybercrime + financial crime + counterintelligence + AMLA enforcement https://www.mjib.gov.tw/
Ministry of Justice (MOJ)法務部 Cross-cutting PDPA interpretive authority + Public Prosecutor coordination + Mutual Legal Assistance Central Authority https://www.moj.gov.tw/
Taiwan High Prosecutors Office + District Prosecutors Offices臺灣高等檢察署 / 地方檢察署 Public prosecution; Criminal Code + CYSEPA + PDPA criminal-liability prosecutions https://www.tph.moj.gov.tw/
Consumer Protection Committee, Executive Yuan行政院消費者保護委員會 Consumer Protection Act policy coordination + standard-contract review + cross-government coordination https://www.cpc.ey.gov.tw/
Department of Consumer Protection, Executive Yuan行政院消費者保護處 Consumer Protection Act administrative implementation https://www.cpc.ey.gov.tw/
Local-government Consumer Protection Officers地方政府消費者保護官 First-line consumer-protection enforcement under the Consumer Protection Act via local government website (each special municipality / provincial city / county) — Consumer Service Hotline 1950
Taiwan Computer Emergency Response Team / Coordination Center (TWCERT/CC)臺灣電腦網路危機處理暨協調中心 National CERT under TWNIC coordination https://www.twcert.org.tw/
National Center for Cyber Security Technology (NCCST)國家資通安全研究院 National cybersecurity research + CII coordination support under MODA via MODA
Constitutional Court憲法法庭 Constitutional review under the Constitutional Court Procedure Act 2022 https://cons.judicial.gov.tw/
Control Yuan / National Human Rights Commission監察院 / 國家人權委員會 Independent human-rights oversight https://www.cy.gov.tw/
iWIN Hotline — Institute of Watch Internet Network INHOPE-member CSAM hotline + child-online-safety report intake https://www.iwin.org.tw/ — Hotline +886 2 2577 5118
ECPAT Taiwan — End Child Prostitution and Trafficking in Taiwan台灣展翅協會 CSAE prevention NGO https://www.ecpat.org.tw/
Garden of Hope Foundation勵馨社會福利事業基金會 Children + youth + women anti-violence and anti-sexual-exploitation NGO https://www.goh.org.tw/ — Hotline +886 2 8911 8595
World Vision Taiwan台灣世界展望會 Children's-protection NGO https://www.worldvision.org.tw/
Pearl S. Buck Foundation Taiwan財團法人賽珍珠基金會 Children-of-multi-ethnic-families welfare NGO https://www.psbf.org.tw/
Taiwan Fund for Children and Families (TFCF)家扶基金會 Children's-welfare NGO https://www.ccf.org.tw/
Lifeline Taipei台北市生命線協會 Emotional-support 24-hour hotline https://www.lifeline.org.tw/ — Hotline 1995
Teacher Chang Foundation張老師基金會 Youth and family counselling hotline https://www.1980.org.tw/ — Hotline 1980
MOHW 1957 Welfare Service Hotline 24/7 social-welfare consultation hotline dial 1957 (toll-free within Taiwan)
MOHW 113 Women & Children Protection Hotline 24/7 women + children + family-violence protection hotline dial 113 (toll-free within Taiwan)
NPA 110 Emergency Police emergency dial 110 (toll-free within Taiwan)
Consumer Service Hotline 1950 Consumer-protection-officer hotline dial 1950 (toll-free within Taiwan)

3.4 The DPO

PDPA Taiwan does not at the Effective date contain a strict statutory mandatory-DPO requirement equivalent to GDPR Article 37 / PDPA Singapore Section 11(3) / PDPA Thailand Section 41 / PDPA Malaysia Section 12A / PIPL Article 52. However, PDPA Taiwan Article 27 paragraph 2 authorises the central competent authority to require designated personnel and a data-protection plan for security maintenance + the body of sectoral Regulations Governing the Security Maintenance and Management of Personal Data Files for Specific Non-government Agencies issued by NCC / FSC / MOEA require designated personnel for non-government agencies in their respective sectors. The PDPC Taiwan transitional guidance is expected to consolidate the designated-personnel requirement across sectors during 2025-2026 (§ 18 versioning trigger). Balance designates inline as best practice consistent with the PDPC Taiwan transitional guidance + the Article 6 sensitive-data + children's-data heightened-protection framework + the international DPO standard.

The Balance designated personnel / DPO is:

The DPO's business contact is published in this Annex, in the global Privacy Policy (Privacy Policy § 1), and at balance.babayagaprogram.com — satisfying the PDPA Taiwan Article 8 + Article 9 + Article 13 transparency obligations and the PDPC Taiwan transitional guidance. The DPO is the contact point for the PDPC Taiwan / legacy central competent authorities on any regulatory matter and for data subjects on rights-exercise matters. The DPO need not be a Taiwanese citizen or resident but must be readily accessible during Taiwanese business hours per the PDPC Taiwan transitional guidance.


4. Lawful bases — PDPA Taiwan Article 19 (lawful bases) + Article 7 (consent) + Article 6 (sensitive-data carve-out)

The PDPA Taiwan is a purpose-and-consent regime modulated by the Article 19 lawful-bases catalogue for non-sensitive personal data (performance of contract / law / public interest / written consent / generally accessible sources / academic research) + the Article 6 sensitive-data heightened regime. Balance processes personal data of Taiwanese residents on the following PDPA Taiwan mapping:

Processing purpose PDPA Taiwan basis Cross-reference
Run the parental-control service the parent signed up for (account creation, family configuration, kid profile, limits, schedules, tasks, earned-time ledger, end-to-end-encrypted proof media) Article 19(2) performance-of-contract necessity + Article 7 written consent of the parent (electronic-equivalent consent under the Electronic Signatures Act) + Article 5 principle of good faith + proportionality + Article 8 transparency notice at collection + Article 27 data-security obligation H1 § 4; H7 PA-01 through PA-08; § 7 of this Annex
Process the kid's personal data Article 19(2) performance-of-contract + Article 7 written consent of the parent on behalf of the kid under Civil Code Articles 75-79 minor-incapacity doctrine + Article 12 age of majority 18 + Articles 1084-1090 parental rights + Article 5 + Article 8 + the Children and Youth Welfare and Protection Act protective framework § 7 of this Annex; our Data Protection Impact Assessment § 6
Deliver operational alerts Article 19(2) + Article 8 transparency (primary purpose) H1 § 4; H7 PA-09; M3
Detect, prevent, and respond to security incidents, abuse, fraud, and unauthorised access Article 27 data-security obligation + Article 19(1) prescribed by law (Criminal Code Chapter 36) + Article 19(8) other-lawful-purpose carve-out H7 PA-15; § 13 below
Comply with legal, regulatory, and supervisory obligations Article 19(1) prescribed by law + Article 20 use-beyond-original-purpose carve-out (1) statutory requirement § 13 below; M1; § 14 below
Process Verifiable Parental Consent for the kid's data Article 7 + Article 8 + Article 19(2) — collection of the parent's personal data for the primary purpose of obtaining VPC § 7 of this Annex; A-US § 5
Process the parent's billing / subscription data Article 19(2) performance-of-contract necessity; CPA Taiwan + Application Conditions of Article 19 Paragraph 1 Reasonable Exception + Civil Code consumer-protection overlay in § 16 below H4; § 16 below

Balance does not process Article 6 sensitive personal data (medical records / health-examination results / genetic data / sex life / criminal record + biometric data prescribed by central competent authority + such other personal data that the central competent authority designates) in respect of any Taiwanese resident.

Balance does not collect any Taiwanese national or government-issued identification number — neither the ROC National Identification Number (Chinese: 國民身分證統一編號, 10 alphanumeric characters) issued under the Household Registration Act (Chinese: 戶籍法) nor the ROC Passport Number issued under the Passport Act (Chinese: 護照條例) nor the driver's licence number issued under the Road Traffic Management and Penalty Act. The MOJ + the legacy NCC interpretive practice on collection of the ROC National Identification Number imposes strict purpose-limitation; Balance's posture aligns: none collected.


5. Children's rights overlay

Taiwan does not have a children-specific data-protection statute equivalent to COPPA (US), GDPR Art 8, or Quebec Private Sector Act s 8.1, at the Effective date. The children's regime is built up from (i) the PDPA Taiwan + the PDPC Taiwan transitional guidance on children's data processing (forthcoming subordinate legislation — § 18 versioning protocol covers issuance); (ii) the Constitution Article 22 read with Judicial Yuan Interpretation No. 603 informational-privacy doctrine + Article 156 state duty to protect children; (iii) the Children and Youth Welfare and Protection Act (CYWPA); (iv) the Criminal Code Chapter 16 sexual-offences chapter at Articles 221-235 + the Child and Youth Sexual Exploitation Prevention Act (CYSEPA); (v) the Civil Code Article 12 age of majority 18 (post-1 January 2023 amendment) + Articles 75-79 minor-incapacity doctrine + Articles 1084-1090 parental rights; (vi) the UN Convention on the Rights of the Child (Taiwan is not a UN member and has not formally acceded — the UN-status complications affect treaty accession for Taiwan; however, Taiwan has domestically implemented the substantive principles of the CRC via the Implementation Act of the Convention on the Rights of the Child (Chinese: 兒童權利公約施行法) of 4 June 2014 in force 20 November 2014 — the CRC's substantive provisions are domestically applicable in Taiwan via this statutory implementation regardless of formal accession).

5.1 Definitions

For the purposes of this Annex:

Balance applies the most-protective reading and obtains Verifiable Parental Consent for every Taiwanese kid regardless of age, using the VPC mechanism in United States annex § 5 (email-verified parent account creation + payment-method capture at subscription time + parent's affirmative in-app action of creating the kid profile and pairing the kid's device). The VPC screen for Taiwanese residents itemises the categories of personal data being processed, the purposes for which it is being processed, the third parties to whom it may be disclosed (sub-processors), and the data subject's rights under the PDPA Taiwan + the Constitution Article 22 + Judicial Yuan Interpretation No. 603 informational-privacy doctrine + the established Taiwanese privacy doctrine.

Balance does not provide a kid-self-serve consent path inside the app. The parent always consents on behalf of the kid; the kid app's UI is designed for the kid to see their own limits, schedules, tasks, and earned-time ledger, and to request changes through the in-app "request change" affordance, which is forwarded to the parent device for the parent's decision. This is the most-protective reading of the PDPA Taiwan + the CYWPA + the Civil Code Articles 75-79 minor-incapacity doctrine + the Article 12 age of majority 18 + the Implementation Act of the CRC.

5.4 No advertising directed at children

Balance does not display advertising to any user (parent or kid), does not allow any third party to display advertising in Balance, and does not build a behavioural-advertising data file of any user. This is consistent with: (i) the PDPA Taiwan Article 5 principle of good faith and proportionality + Article 11 right of cessation of collection / processing / use; (ii) the Children and Youth Welfare and Protection Act Article 43 prohibition on exposing children and youth to inappropriate content + the CYWPA Article 47 internet-content classification regime; (iii) the Fair Trade Act fair-competition principles. Cross-references: the Play Console Data Safety form § 2 (Contains ads: No); the Play Console Child Safety Standards declaration § 3 ATTESTATION-D.

5.5 Cooperation routes

The principal Taiwanese child-protection bodies are: (i) the Ministry of Health and Welfare — Children and Families Agency (CFA, MOHW) — the principal child-welfare lead agency under the CYWPA; (ii) the MOHW Protective Services Section + Hotline 113 Women & Children Protection Hotline 24/7; (iii) the MOHW 1957 Welfare Service Hotline 24/7; (iv) the National Police Agency (NPA) + NPA Criminal Investigation Bureau + MJIB; (v) the iWIN — Institute of Watch Internet Network — the CYWPA Article 46 statutory internet-content-protection institution + INHOPE-member CSAM hotline; (vi) the ECPAT Taiwan — CSAE prevention NGO; (vii) the Garden of Hope Foundation — children + youth + women anti-violence and anti-sexual-exploitation NGO; (viii) the Taiwan Fund for Children and Families (TFCF) — children's-welfare NGO; (ix) the World Vision Taiwan and Pearl S. Buck Foundation Taiwan — children's-protection NGOs; (x) the Lifeline Taipei 1995 + Teacher Chang Foundation 1980 — youth and family counselling hotlines. Balance cooperates with each on incidents involving Taiwanese kids — see § 14 below.


6. PDPA Taiwan rights catalogue

6.1 The rights catalogue

A Taiwanese resident has the following rights under the PDPA Taiwan + the PDPA Taiwan Enforcement Rules as in force at the Effective date.

6.2 Timeline

Where the access carve-outs at PDPA Taiwan Article 10 paragraphs 2 + 3 apply (national security / national interest / important interest of a third party / where compliance would prejudice the controller's performance of statutory duty), Balance may decline to provide access and explain the reasons.

6.3 Identity verification

Where there is reasonable doubt about the identity of the natural person making the request, Balance may request additional information necessary to confirm the identity. The identity-verification protocol uses the parent's existing authentication credential.

6.4 Fees

Under PDPA Taiwan Article 14 + the PDPA Taiwan Enforcement Rules, a controller may charge a reasonable fee for processing a data access request — limited to actual cost. Balance does not charge for access in practice.

6.5 Language

A request may be submitted in Traditional Chinese / Mandarin Chinese or English. The PDPC Taiwan + the legacy central competent authorities accept complaints in Traditional Chinese (preferred for procedural materials) and English.


7. Children's data — PDPA Taiwan + CYWPA + Civil Code

Balance processes personal data of Taiwanese kids under the following layered framework:

For Balance:

A parent may revoke consent at any time at Settings → Family → [kid name] → "Delete this kid" (or by email to ). Revocation triggers the cascade documented in Data Retention & Deletion Policy § 7. Revocation does not affect the lawfulness of processing carried out before the revocation.


8. International data transfers from Taiwan — PDPA Taiwan Article 21 + the central-competent-authority restriction regime + APEC CBPR overlay

The controller (BabaYaga Program, TOO) is established in Kazakhstan. The backend (Emergent Labs Inc.) is hosted in the United States. Proof-media storage (Google Cloud Storage) is in the United States. Push (Firebase Cloud Messaging), sign-in (Google Sign-In), and billing (Google Play Billing) are operated by Google LLC and dispatched from the United States. Transactional email (Resend) is dispatched from the United States. Accordingly, every Taiwanese resident's personal data leaves Taiwan at the point of being uploaded to the Balance backend.

8.1 The Taiwan-to-US transfer mechanism — PDPA Taiwan Article 21 + APEC CBPR overlay

PDPA Taiwan Article 21 sets out the cross-border transfer restriction mechanism: the central competent authority for the industry of the non-government agency may RESTRICT the cross-border transfer of personal data where (1) the transfer involves major national interest; (2) any international treaty or agreement so provides; (3) the receiving country lacks adequate regulations governing personal data protection and the data subject's rights and interests are likely to be infringed; (4) the cross-border transfer is conducted via a third country to circumvent the PDPA Taiwan. At the Effective date, the principal sectoral restrictions in force target Mainland China for NCC-supervised telecoms operators (NCC Order Tong-Tong-Wei-Zi No. 10141050780 of 17 September 2012 — n/a to Balance) and FSC-supervised financial institutions (n/a to Balance — Balance is not in any sector with an active Article 21 restriction order at the Effective date).

In the absence of a sectoral restriction, PDPA Taiwan does not require prior PDPC / sectoral-authority approval for outbound cross-border transfers by non-government agencies in sectors without active Article 21 restrictions. The transfer is permissible subject to (i) the consent of the data subject under Article 7; (ii) the lawful basis under Article 19; (iii) the Article 27 data-security obligation extending to cross-border processing; (iv) the PDPC Taiwan transitional guidance on cross-border accountability (forthcoming — § 18 versioning protocol).

Balance relies on the following stack to satisfy the PDPA Taiwan cross-border transfer framework:

8.2 The Taiwan-to-KZ axis (controller administrative access)

The controller's personnel in Kazakhstan have administrative access to the US-hosted backend for operational purposes. Because Kazakhstan is a third country, the Taiwan-KZ axis is covered by the PDPA Taiwan Article 27 data-security obligation extending to cross-border + Article 19(2) performance-of-contract + Article 7 parent's written consent — written processor agreements signed between Emergent Labs (as processor) and BabaYaga Program, TOO (as controller) in inverse, with EU-SCC substance + ASEAN Model Contractual Clauses substance preserved. The transfer-impact analysis for the KZ leg is in our international-transfer pack § 7.

8.3 PDPA Taiwan RoPA + designated-personnel framework

The PDPA Taiwan does not require formal database registration with the PDPC Taiwan or with the legacy central competent authorities (in contrast with the pre-2010 Computer-Processed Personal Data Protection Act registration regime which was abolished by the 2010 Amendment). Non-government agencies in sectors with active Regulations Governing the Security Maintenance and Management of Personal Data Files for Specific Non-government Agencies (NCC / FSC / MOEA) must implement a data-security plan + designate personnel + maintain internal records. Balance is not in an NCC / FSC / MOEA-supervised sector at the Effective date + therefore the sectoral Regulations do not directly engage; Balance nonetheless adopts the substantive standards as best practice and maintains the internal RoPA at our Records of Processing Activities (Article 30).

8.4 APEC CBPR overlay

Taiwan (as Chinese Taipei in APEC) joined the operational APEC CBPR system + the APEC PRP (Privacy Recognition for Processors) on 4 December 2018 as a participating economy with the Institute for Information Industry (III) as the designated Accountability Agent under MOEA / MODA coordination. The APEC CBPR system provides a complementary accountability framework for cross-border data transfers within the APEC region (which includes Singapore, the Philippines, the United States, Canada, Japan, the Republic of Korea, Mexico, Australia, and other APEC economies at the Effective date). Balance's principal operational mechanism remains the PDPA Taiwan Article 19(2) + Article 7 + Article 27 stack; the APEC CBPR + PRP framework is an additional accountability overlay route.

8.5 ASEAN Model Contractual Clauses for Cross Border Data Flows (January 2021) — substantive overlay

Taiwan is not an ASEAN Member State, but the ASEAN Model Contractual Clauses for Cross Border Data Flows (January 2021) provide a recommended-form contractual-clauses template usable across the Asia-Pacific. Balance's sub-processor agreements incorporate the substance of the ASEAN Model Contractual Clauses as a substantive overlay (see our international-transfer pack § 6).


9. Data residency for Taiwanese residents

Question Answer
Where is the backend hosted? United States. Emergent Labs Inc. (Delaware) on US infrastructure.
Where is the MongoDB database located? United States.
Where is the proof-media storage located? United States — Google Cloud Storage us multi-region.
Where are push notifications dispatched from? United States — Firebase Cloud Messaging.
Is any Taiwanese resident's personal data held in Taiwan? No. Every Taiwanese resident's personal data is held in the United States. The PDPA Taiwan Article 19(2) performance-of-contract + Article 7 parent's consent + Article 27 data-security + APEC CBPR + PRP overlay stack in § 8 above is the legal basis for the transfer.
Where is the controller? Kazakhstan (BabaYaga Program, TOO). The controller has administrative access to the US-hosted backend via written processor agreements.
Is there a Taiwanese establishment? No. Balance has no permanent establishment in Taiwan. The PDPA Taiwan Article 51 paragraph 2 extraterritorial reach is the basis for Balance's PDPA Taiwan compliance.
Where is the supervisory authority? Taiwan — PDPC Taiwan (on full operationalisation) + legacy central competent authorities + the regulatory bodies in § 3.3 above.

The decision to centralise on a US-only backend is documented in our internal compliance plan § 6. Taiwan does not impose a comprehensive data-localisation mandate on parental-control services at the Effective date, with the exception of certain sector-specific regimes (e.g., the Banking Act directives on outsourcing by Taiwanese banks — not applicable to Balance; the Securities and Exchange Act directives — not applicable to Balance; certain Telecommunications Act directives on telecoms data localisation — not applicable to Balance; the NCC Order Tong-Tong-Wei-Zi No. 10141050780 of 17 September 2012 restricting cross-border transfers by NCC-supervised telecoms operators to Mainland China — not applicable to Balance).


10. Sub-processors touching Taiwanese-resident data

Sub-processor Role Location of processing Taiwanese transfer paperwork
Emergent Labs Inc. (Delaware, USA) — using MongoDB Atlas (MongoDB, Inc., US) for the production database; relationship governed by Emergent ToS (22 Dec 2025) + Privacy Policy (28 May 2026) as the GDPR Art 28(3) "other legal act" (no standalone DPA available outside Enterprise per Emergent final position 2026-06-10; full handling in our internal vendor-handling plan); MongoDB Atlas Customer DPA + EU SCCs Module 2 + UK IDTA Addendum at https://www.mongodb.com/legal/dpa cover the storage layer Hosts the FastAPI backend + MongoDB cluster United States PDPA Taiwan Article 19(2) + Article 7 written consent + Article 27 data-security written processor agreement per our international-transfer pack § 6; E2EE supplementary measure for proof media; ASEAN Model Contractual Clauses substance + APEC CBPR-aligned accountability.
Google LLC — Google Cloud Storage (USA) Stores end-to-end-encrypted proof-media ciphertext United States (us multi-region) PDPA Taiwan Article 27 written processor agreement (Google Cloud Data Processing Addendum) + Article 7 consent + Article 19(2) performance-of-contract; ciphertext-only handling.
Google LLC via Google Cloud (USA) Periodic (daily) backups of our operational database United States (us multi-region) PDPA Taiwan Article 27 written processor agreement (Google Cloud Data Processing Addendum) + Article 7 consent + Article 19(2) performance-of-contract; the backup archive holds the operational data we hold about the resident (account, family, kid profile, usage totals, tasks, earned-time ledger, device identifiers, push tokens), other than the items that never reach our backend in readable form (the kid's proof media and the media-encryption keys); retained on a 30-day rolling window, then automatically deleted.
Google LLC — Firebase Cloud Messaging Delivers push notifications to Taiwanese kid + parent devices United States PDPA Taiwan Article 27 + Article 7 + Article 19(2) as above; push body deliberately free of sensitive content (cross-reference: the just-in-time permission disclosures).
Google LLC — Google Sign-In Authenticates parent Google identity (when used) United States PDPA Taiwan Article 27 + Article 7 + Article 19(2) as above.
Google LLC — Google Play Billing Processes subscription purchases United States PDPA Taiwan Article 27 + Article 7 + Article 19(2) + Google Play Developer Distribution Agreement.
Resend, Inc. (San Francisco, CA, USA) Delivers transactional email to Taiwanese parent users United States PDPA Taiwan Article 27 + Article 7 + Article 19(2).

Every sub-processor is bound by a written data-processing agreement that forbids processing of any data we transmit for any purpose other than performing the service we engaged them for, and that incorporates the security and confidentiality controls in our Records of Processing Activities (Article 30) § 7 + PDPA Taiwan Article 27 + the substantive standards of the legacy sectoral Regulations Governing the Security Maintenance and Management of Personal Data Files for Specific Non-government Agencies (adopted as best practice). The full sub-processor list, with each row's processor-agreement status, is at our sub-processor register.


11. Breach notification — PDPA Taiwan Article 12 + Enforcement Rules Article 35

PDPA Taiwan Article 12 + the PDPA Taiwan Enforcement Rules Article 35 is the principal breach-notification regime. The Taiwanese regime requires data-subject notification in a timely manner (Chinese: 以適當方式) when personal data has been stolen / disclosed / altered or otherwise infringed in violation of the PDPA Taiwan:

Audience Trigger Deadline Channel
PDPC Taiwan + central competent authority A personal data breach involving stolen / disclosed / altered / unlawfully accessed personal data. The PDPA Taiwan does NOT statutorily impose a specific PDPC notification deadline at the Effective date; the PDPC Taiwan transitional guidance is expected to operationalise a notification timeline (the legacy sectoral Regulations Governing the Security Maintenance and Management of Personal Data Files prescribed sectoral notification windows — typically 72 hours — for sectoral-supervised non-government agencies). Balance internal anchor: without undue delay, where feasible within 72 hours from awareness of the personal data breach (matched to GDPR Article 33 benchmark exceeding the PDPA Taiwan statutory floor); PDPC Taiwan operational rules tracked under § 18. PDPC Taiwan online portal (on full operationalisation) + relevant central competent authority pending
Affected individuals (PDPA Taiwan Article 12) A personal data breach where personal data has been stolen / disclosed / altered or otherwise infringed in violation of the PDPA Taiwan. In a timely manner (Chinese: 以適當方式) under PDPA Taiwan Article 12; Balance internal anchor: 24-hour-from-confirmation initial parent notification + comprehensive follow-up within 72 hours. Carve-outs where data has been rendered unintelligible (e.g., E2EE ciphertext case) — affected-individual notification may be limited or staged where notification would prejudice ongoing investigation. Direct email to the affected parent on file; in-app banner where the parent is logged in; out-of-app contact via the public-website incident page if email is no longer deliverable. The notification is in English, with a Traditional Chinese version queued for the Phase-2 locale rollout.
CSAE-specific An incident with a CSAE component. Per § 14 below + the internal runbook (M1). iWIN + NPA Criminal Investigation Bureau + MJIB + MOHW CFA + MOHW Hotline 113.

The internal breach-decision SLA is at our breach-notification runbook § 5.4 + § 9: preliminary classification within one business day, formal assessment under PDPA Taiwan Article 12 + Enforcement Rules Article 35 completed within 48 hours of discovery for risk-to-rights-and-freedoms escalation, data-subject notification within the 72-hour Balance internal anchor.

11.1 Minimum content of the Article 12 data-subject notification (Enforcement Rules Article 35)

The Article 12 data-subject notification states: - the facts of the personal data breach including how it occurred + the chronology of events; - the categories and approximate number of personal data records possibly affected; - the response measures taken to address the breach + mitigation steps; - the name and contact details of the DPO / designated personnel (, named individual: ) — the contact from whom the affected data subjects may obtain additional information.

The English-language template lives in our breach-notification runbook § 8.1. A Traditional Chinese version is queued for Phase 2 locale rollout.

11.2 Non-compliance — PDPA Taiwan Chapter 5 penalties

11.3 Concurrent Cyber Security Management Act / TWCERT/CC notification

For incidents involving cybersecurity attacks on the controller's systems, the Cyber Security Management Act notification regime applies only to designated CII operators. Balance is NOT designated as Critical Information Infrastructure under the Act. Voluntary cooperation with TWCERT/CC (the national CERT) is honoured as a best-effort security overlay.


12. Cookies, spam, and electronic direct marketing

Taiwan does not have a dedicated ePrivacy / cookies statute. The substantive position on cookies and electronic direct marketing is derived from: (i) PDPA Taiwan Article 7 + Article 8 + Article 19 + Article 20 for any cookie that processes personal data; (ii) the PDPC Taiwan transitional guidance and the legacy MOJ + sectoral interpretive practice; (iii) the Consumer Protection Act + Fair Trade Act (Chinese: 公平交易法) prohibitions on misleading advertising; (iv) the Children and Youth Welfare and Protection Act Article 43 prohibition on exposing children and youth to inappropriate content; (v) PDPA Taiwan Article 11 right of cessation of collection / processing / use for marketing purposes.

12.1 In-app — strictly-necessary storage only

The Balance app (parent and kid) does not deploy any cookie-equivalent storage that is not strictly necessary for the service. The strictly-necessary storage Balance uses (authentication tokens in Android SecureStore; the device-pairing key wrap; the kid app's earned-time cache) is operationally necessary and is covered by the parent's sign-up consent.

The public legal-documents site (balance.babayagaprogram.com) uses only strictly-necessary cookies; no analytics cookies; no advertising cookies; no third-party trackers; no fingerprinting; no embedded social plugins.

12.3 Electronic direct marketing — not sent

Balance does not send marketing communications to Taiwanese residents. The only email Balance sends to Taiwanese parent users is transactional — account creation, password reset, subscription receipts, security alerts, and parent-action notifications. Transactional messages are outside any commercial-electronic-message definition. If Balance ever introduces a marketing channel, we will comply with: (i) PDPA Taiwan Article 7 prior written consent + Article 8 transparency; (ii) PDPA Taiwan Article 11 right of cessation of marketing processing; (iii) the Consumer Protection Act Chapter 4 fair-trading rules + Fair Trade Act Article 21 prohibition on misleading advertising; (iv) CYWPA Article 43 prohibition on exposing children and youth to inappropriate content.

12.4 No telemarketing

Balance does not place telemarketing voice calls, SMS, or messaging-app outreach to Taiwanese residents.


13. Lawful-access requests and the encryption posture

Taiwanese authorities may serve a lawful-access request on Balance via:

The Balance architectural posture interacts with these mechanisms as follows:

The full encryption posture is in our encryption-posture record.


14. CSAE reporting routes — Taiwan

A Taiwanese resident (parent, kid, or third party) who wishes to report a CSAE concern about Balance, about a third party encountered outside Balance, or about a Balance user, may use any of the following routes:

The full CSAE Country Routing Table is in Child Safety Standards § 8.6.


15. Complaint routes (summary)

A Taiwanese resident who is dissatisfied with Balance's handling of a privacy enquiry or a child-safety concern may complain to any of the following authorities:

Authority Subject matter Address / URL
Personal Data Protection Commission (PDPC Taiwan) PDPA Taiwan — on full operationalisation Published at PDPC Taiwan operational website (transition under way); § 18 versioning
Ministry of Justice (MOJ) — Department of Legal Affairs Cross-cutting PDPA Taiwan interpretive authority (transitional) https://www.moj.gov.tw/ — +886 2 2191 0189
National Communications Commission (NCC) PDPA Taiwan Article 27 sectoral data-security for telecoms / broadcasting / communications + Article 21 cross-border restriction (n/a to Balance) https://www.ncc.gov.tw/
Financial Supervisory Commission (FSC) PDPA Taiwan Article 27 sectoral data-security for financial services (n/a to Balance) https://www.fsc.gov.tw/
Ministry of Economic Affairs (MOEA) PDPA Taiwan Article 27 sectoral data-security for commerce / industry https://www.moea.gov.tw/
Ministry of Digital Affairs (MODA) Cyber Security Management Act + digital-platform-services regulatory coordination https://moda.gov.tw/
Consumer Protection Committee, Executive Yuan Consumer Protection Act policy coordination + standard-contract review https://www.cpc.ey.gov.tw/
Department of Consumer Protection, Executive Yuan Consumer Protection Act administrative implementation https://www.cpc.ey.gov.tw/
Local-government Consumer Protection Officers First-line consumer-protection enforcement (Consumer Service Hotline 1950) via local government — Hotline 1950
Ministry of Health and Welfare (MOHW) — Children and Families Agency CYWPA child-welfare lead agency; Hotline 113 + Hotline 1957 https://www.sfaa.gov.tw/ — Hotline 113 / 1957
National Police Agency (NPA) — Criminal Investigation Bureau CSAE + cybercrime https://www.cib.gov.tw/; Emergency 110
Ministry of Justice Investigation Bureau (MJIB) National-level cybercrime + AMLA + CSAE https://www.mjib.gov.tw/
iWIN — Institute of Watch Internet Network INHOPE CSAM hotline + CYWPA Article 46 internet-content-protection institution https://www.iwin.org.tw/ — Hotline +886 2 2577 5118
TWCERT/CC National CERT + cyber-incident handling https://www.twcert.org.tw/
Control Yuan / National Human Rights Commission Independent human-rights oversight https://www.cy.gov.tw/
District Court / High Court / Supreme Court PDPA Taiwan Chapter 4 civil action (NT$500-20,000 statutory damages + class action); CYSEPA + Criminal Code + CYWPA prosecutions via Judicial Yuan https://www.judicial.gov.tw/
High Administrative Courts / Supreme Administrative Court Administrative review under the Administrative Litigation Act via Judicial Yuan
Constitutional Court Constitutional review under the Constitutional Court Procedure Act 2022 https://cons.judicial.gov.tw/

A Taiwanese resident may always first raise the matter with us at (data access; named individual: , in his capacity as the designated DPO / designated personnel consistent with PDPC Taiwan transitional guidance + the PDPA Taiwan Article 27 paragraph 2 designated-personnel framework). We will respond within the PDPA Taiwan timelines. The PDPC Taiwan (and the legacy MOJ + central competent authorities) accept direct complaints where the data subject demonstrates that internal-remedy exhaustion is impracticable or where the complaint involves a serious matter warranting immediate regulatory action.


16. Consumer rights — the CPA Taiwan + Application Conditions of Article 19 Paragraph 1 Reasonable Exception + Civil Code overlay

The Consumer Protection Act (Chinese: 消費者保護法, the "CPA Taiwan"), the Application Conditions of Article 19 Paragraph 1 Reasonable Exception (Chinese: 通訊交易解除權合理例外情事適用準則) of 1 January 2016 (the "Reasonable Exception Conditions"), and the Civil Code apply to Balance's subscription flow as a consumer transaction (the parent is a consumer within the CPA Taiwan Article 2 definition). Treatment is implemented in Subscription Terms § 20.

16.1 CPA Taiwan Chapter 3 — standardised contracts + Article 11-1 prudent-content review

CPA Taiwan Article 11 requires standard-form contracts to be plain, intelligible, and equitable. CPA Taiwan Article 11-1 prescribes prudent-content review of standard contracts + cooling-off-of-standard-contracts review (the Consumer Protection Committee may prescribe model standard-contract content for specific sectors + business operators using standard-form contracts must afford the consumer a reasonable period to review the contract before execution). CPA Taiwan Article 12 prohibits terms in standard contracts that conflict with the principle of good faith + are obviously unfair to the consumer. The Balance Terms of Service (Terms of Service) and the in-app subscription flow are drafted to comply with Articles 11 + 11-1 + 12.

16.2 CPA Taiwan Chapter 4 — special trading practices — distance-selling

CPA Taiwan Article 18 requires the distance-selling business operator to disclose in the manner of the transaction: (i) the business operator's name + business address + means of contact; (ii) the nature of the goods or services + price; (iii) the manner + time + place of delivery / performance; (iv) the consumer's right of rescission and the manner of exercise; (v) any other matters prescribed by the central competent authority. CPA Taiwan Article 19 the 7-DAY RIGHT OF RESCISSION (Chinese: 七日鑑賞期 — qī rì jiànshǎngqī) — a consumer who enters into a distance-selling contract may rescind the contract by issuing the rescission notice within 7 days from receipt of goods or commencement of services without giving any reason. CPA Taiwan Article 19-2 sets out refund obligations within 15 days from rescission.

16.3 Application Conditions of Article 19 Paragraph 1 Reasonable Exception — digital content carve-out

The Application Conditions of Article 19 Paragraph 1 Reasonable Exception (Chinese: 通訊交易解除權合理例外情事適用準則) of 1 January 2016 sets out the seven categories of distance-selling transaction excluded from the 7-day right of rescission: - (1) goods that may deteriorate / spoil within the rescission period; - (2) goods customised to the consumer's specifications; - (3) goods that have been mixed with other goods after delivery and become inseparable; - (4) sealed audio / video / software products that have been unsealed by the consumer; - (5) services that have been performed before the rescission period expires with the consumer's express consent; - (6) newspapers / periodicals; - (7) online digital content that has commenced provision after the consumer's express consent and acknowledgement of loss of the right of rescission.

The Balance subscription supply is digital content / online services that commence immediately after the consumer's affirmative subscription action. Where the Balance subscription flow includes the consumer's express consent to immediate performance and acknowledgement of the loss of the right of rescission (per Reasonable Exception category 5 or 7), the 7-day right of rescission under CPA Taiwan Article 19 may be excluded. Notwithstanding the availability of the Reasonable Exception, Balance honours a voluntary 14-day no-questions Google Play Billing refund — exceeding the 7-day statutory floor and standing independently of the Reasonable Exception availability. The 14-day refund window is documented at Subscription Terms § 20.

16.4 CPA Taiwan Chapter 6 — consumer-dispute mediation

CPA Taiwan Articles 43-46 establishes the consumer-dispute mediation regime + Consumer Dispute Mediation Committee at the local-government level (each special municipality / provincial city / county). A Taiwanese consumer may first lodge a consumer complaint with the local-government Consumer Service Centre + Consumer Protection Officer (Hotline 1950), with referral to the Consumer Dispute Mediation Committee where direct resolution fails.

16.5 CPA Taiwan Chapter 7 — consumer-protection litigation + Article 51 punitive damages

CPA Taiwan Articles 47-55 establishes the consumer-protection class-action regime — a consumer-protection group accredited by the Consumer Protection Committee may file a class action on behalf of similarly-situated consumers; certified by the District Court. CPA Taiwan Article 51 authorises punitive damages up to ten times the actual damages for malicious acts of the business operator; up to five times for grossly negligent acts. CPA Taiwan Article 53 authorises consumer-protection-group injunctive remedies.

16.6 Civil Code — capacity-of-minors framework + Article 12 age of majority

Under Civil Code Articles 13 + 77-79, a minor (under 18 since the 1 January 2023 amendment lowering age of majority from 20 to 18) of limited legal capacity (7 to under 18) requires the consent of the legal representative for juristic acts; an act done without that consent is voidable under Articles 78-79 (until ratified by the legal representative). The subscription contract is between Balance and the parent (who is 18+ — the Civil Code age of majority). The kid is a beneficiary of the service supplied to the parent. Balance does not contract directly with kids.

16.7 Civil Code Article 195 personality-right framework

Civil Code Article 195 authorises compensation for non-pecuniary damage for personality-right infringement — life / body / health / liberty / credit / privacy / chastity / other personality interests. The Article 195 personality-right framework is the principal Taiwanese civil-law tort remedy for invasion of privacy + provides a substantive overlay to the PDPA Taiwan Article 28 statutory-damages regime.

16.8 Forum and choice of law

The Balance Terms of Service preserve the consumer's domicile forum (see Terms of Service § 19); choice-of-law clauses or jurisdiction clauses that would deprive the Taiwanese consumer of mandatory CPA Taiwan + PDPA Taiwan protection are subject to CPA Taiwan Article 12 (standard-contract unfair-terms screen) + the Act Governing the Choice of Law in Civil Matters Involving Foreign Elements (Chinese: 涉外民事法律適用法) Article 8 public-policy reservation + the public policy doctrine recognised by Taiwanese courts.


17. Cross-references


18. Versioning and review

This Annex follows the same strict versioning protocol as the rest of the Phase-1 bundle:


End of Taiwan Country Annex.

← Back to Privacy Policy · Children's Privacy Notice