Multiple Regulations
Taiwan currently lacks a unified framework specifically regulating the digital market or digital services.
While the Executive Yuan of Taiwan launched the “Digital Nation and Innovative Economic Development Plan (DIGI+)” to promote digital economic development, Taiwan currently has yet to promulgate a single law governing the digital market or digital services. Regulations related to the digital economy may cross multiple laws covering multiple aspects. For example:
Challenges of Adjusting Existing Regulations for Digital Goods and Services
With the development of the digital economy, legal challenges have begun to emerge. Notable examples include:
Overview
Taiwan has not yet introduced a unified tax act specifically addressing digital goods and services sold through online platforms. However, the current income tax and business tax framework applicable to traditional goods and services extends to digital transactions, with the Ministry of Finance (MOF) identifying taxable targets in the digital domain as follows:
Taxation on cross-border transactions is more complex; thus, we discuss it below.
Taxation of Cross-Border Transactions
(a) Income tax: For cross-border transactions, determining the portion of income generated within Taiwan is critical for tax purposes. The MOF specifies income tax calculations based on the formula below:
Income (domestic source income) × Net Profit Ratio × Domestic Profit Contribution × Withholding Rate
(b) Business tax: To determine the scope of business that should be subject to Taiwan’s business tax, the MOF classifies cross-border sales of digital goods and services into six categories based on factors such as:
Virtual Currency Transactions
The MOF announced plans to introduce tax regulations for virtual currency transactions by 2025, signalling an increased focus on this emerging sector.
Regulatory Compliance
Regulatory compliance is a major challenge for businesses.
Tax Implications for Digital Advertising Revenues
Income × Net Profit Ratio × Domestic Profit Contribution × Withholding Rate
Ensuring Compliance With Tax Regulations
Consumer Protection Act Governs Digital Goods and Services
The Consumer Protection Act is the primary law governing consumer protection in digital transactions. In addition, the E-Commerce Consumer Protection Guidelines, issued by the Executive Yuan’s Consumer Protection Committee, provide administrative guidance and outline best practices to help businesses comply with the legal requirements. Moreover, consumer information in transactions should also be protected under the PDPA.
Dispute Resolution
Under the Consumer Protection Act, when consumer disputes (including those involving digital products and services) arise, consumers may:
Advisable Practices for Establishing Dispute Resolution Mechanisms
Businesses providing digital products or services may refer to the E-Commerce Consumer Protection Guidelines as a Best Practice for establishing dispute resolution mechanisms.
To ensure fair and transparent dispute resolution, the E-Commerce Consumer Protection Guidelines specify that:
The guidelines also recommend that businesses establish a consumer service centre or provide a dedicated consumer complaint hotline to handle consumer disputes and prioritise resolution through the Consumer Dispute Mediation Committee or by reaching a settlement between the parties.
Ensuring Compliance With Consumer Protection Standards
To align with relevant consumer protection standards, businesses are advised to implement and ensure the following:
The Impact on Taiwan’s Legal Landscape
Blockchain and cryptocurrency technology enable large-scale, timely and cross-border transfers of funds, thus promoting financial inclusion. However, they have also become instruments for illicit conducts or crimes.
To address these issues, the Taiwan government continues to strengthen regulations on anti-money laundering and fraud prevention, while progressively bringing Virtual Asset Service Providers (VASPs) under regulatory oversight and promoting industry self-regulation.
Legal Challenges and Opportunities of Blockchain and Cryptocurrency
Challenges
Opportunities
Regulation in Taiwan Governing VASPs
Taiwan adopts a progressive regulatory approach for VASPs. The Financial Supervisory Commission (FSC) first developed guidance principles and supported the establishment of self-regulatory codes to balance financial innovation and consumer protection, before introducing more stringent regulations.
With the above regulatory approach, 2024 was a particularly impactful year for the crypto industry in Taiwan. Key regulations in 2024 are as follows.
Implementation of the VASP registration regime
The Anti-Money Laundering Registration Regulations for VASP (“VASP Registration Regulation”) became effective on 30 November 2024. VASPs that have not completed AML registration as of 30 November 2024 are prohibited from providing virtual asset services. Non-compliance may result in penalties, including imprisonment of up to two years for individuals and/or fines up to TWD50 million for entities.
VASPs that completed AML declarations before 30 November 2024 must still apply for and complete their AML registration by 30 September 2025. VASPs that fail to do so will be prohibited from conducting virtual asset operations.
Differentiated legal compliance obligations for VASPs
Under the VASP Registration Regulation, VASPs are classified into five categories: Virtual Asset Exchangers, Virtual Asset Trading Platforms, Virtual Asset Transferors, Virtual Asset Custodians and Virtual Asset Underwriters. While the VASP Registration Regulation requires general compliance for all VASPs, differentiated legal obligations are provided based on the nature of their services. The key points include:
VASPs’ anti-fraud obligations
Under the Fraud Crime Hazard Prevention Act announced in July 2024, VASPs are obligated to co-operate with law enforcement agencies in establishing a reporting system and freezing suspected funds or virtual assets for anti-fraud purposes. Violations of these obligations may result in a fine ranging from TWD200,000 to TWD2 million; in serious cases, the fine will be from TWD1 million to TWD10 million.
VASPs are obligated to join the VASP Association and comply with self-regulatory codes
The Taiwan VASP Association was officially established in June 2024. According to the VASP Registration Regulation, VASPs must join the VASP Association before operating virtual asset businesses, and adhere to the self-regulatory codes set forth by the VASP Association. The VASP Association has released seven self-regulatory codes, covering virtual asset listing/delisting reviews, customer protection and anti-money laundering.
The FSC has announced plans to submit a draft of a dedicated virtual asset law to the Executive Yuan by June 2025. Relevant businesses should closely monitor the latest regulatory developments.
Regulations on Cloud Computing and Edge Computing
Currently, Taiwan does not have a single piece of legislation specifically addressing cloud computing or edge computing. However, government agencies in certain industries have established rules for the use of cloud services. For example:
Banking industry
The Regulations Governing Internal Operating Systems and Procedures for the Outsourcing of Financial Institution Operation require banks using outsourced cloud services to:
Further, the Guidelines for Financial Institutions Utilising Emerging Technologies, issued by the Bankers Association, further specifies security controls for banks using cloud services, including:
Healthcare industry
The Regulations Governing the Production and Management of Electronic Medical Records by Medical Institutions require that medical institutions using cloud services or outsourcing their electronic medical record information system to service providers must establish the following control measures:
Issues Related to Personal Data Protection
The collection, processing or use of personal data via cloud computing must serve a specific purpose and have legitimate causes in accordance with the PDPA. In addition, the entities utilising cloud service providers for activities directly or indirectly involving the collection, processing and/or use of others’ personal data must notify individuals who provide their personal data of such collection, processing and/or use.
Cloud service providers entrusted to collect, process or use others’ personal data are required to comply with the same legal obligations as the entities that engage them (Article 4 of the PDPA). Moreover, the entrusting entities must supervise the cloud service providers and be responsible for any violation made by the cloud service providers (Article 8 of the Enforcement Rules of the PDPA). Such supervision measures include:
Regulations on AI
Currently, Taiwan does not have a single act specifically addressing AI. It was not until 15 July 2024 that the National Science and Technology Council drafted the Artificial Intelligence Fundamental Act and sought public consultation. This draft is still pending approval by the Executive Yuan. Despite the lack of an overarching AI law, several sector-specific guidelines have been issued. For example:
Legislation on Deepfake Technologies
Deepfake technology has been linked to criminal activities, particularly the creation of falsified sexual images, posing significant threats to personal privacy and dignity. To address these issues, Taiwan amended the Criminal Code on 7 January 2023, introducing a key provision, Article 319-4, to criminalise the creation of false sexual images using computer synthesis or other technological methods. Violators may be sentenced to up to five years of imprisonment. If the offence is committed with the intention to profit from such offence, the maximum sentence may increase to seven years of imprisonment.
Regulations on the Application of AI in Transportation
Taiwan has implemented laws governing the use of AI in transportation:
Unmanned Vehicles Technology Innovative Experimentation Act (2018)
This allows companies that wish to launch unmanned vehicles on the market to apply for approval from the competent authority to conduct innovative experiments beforehand. “Unmanned vehicle” refers to a driverless transport vehicle that may be an automobile, aircraft, ship or any combination of these items, which is operated through remote control or autonomous operation and is equipped with the sensing, positioning, monitoring, and decision-making and control technology. Currently, self-driving vehicles are not permitted for use outside designated experimental areas.
Civil Aviation Act (amended on 25 April 2018)
The amendments to this act introduced a specific chapter governing the use of drones, defined as an unmanned aerial vehicle, the flight control of which is operated by way of signal link through remote control device or by autopilot without human pilot on board, and any other kind of aircraft as announced by the Civil Aviation Administration. Any drone flight conducted in open spaces must comply with the Civil Aviation Act and its associated regulations.
Principles Revealed in the Draft of the Artificial Intelligence Fundamental Act
The draft Artificial Intelligence Fundamental Act outlines principles to guide AI development and application. While the draft only provides some high-level principles, it emphasises the promotion of the following key principles:
Outline of Internet of Things Related Regulations
Taiwan currently does not have a unified law specifically addressing the Internet of Things (IoT). Instead, multiple laws and regulatory requirements managed by various authorities are involved, including the National Communications Commission (NCC) and the Ministry of Digital Affairs (MODA).
Public telecommunications networks
If communication among IoT devices requires the establishment of a telecommunications network to provide public communication, operators must comply with the following requirements:
Prior to launch
After launch
Dedicated telecommunications networks
If communications among IoT devices are only operated through the radio frequency in a telecommunications network established for private use (“Dedicated Telecommunications Network”), the radio frequency is required to be approved by the MODA while the establishment of the Dedicated Telecommunications Network should obtain prior approval from the NCC under the Regulations Governing the Establishment and Use of Dedicated Telecommunications Networks.
Controlled radio-frequency devices
For IoT devices classified as controlled telecommunications radio-frequency devices, their manufacturers or importers must follow the requirements under the TM Act and the Administrative Regulations on Manufacturing, Import and Report of the Controlled Telecommunications Radio-Frequency Devices, and obtain prior approval before launching such devices.
Personal data protection requirements
If the collection, processing, or use of personal data are involved in the operation of IoT devices, operators should ensure compliance with the PDPA.
Self-Regulatory Rules for Financial Institutions Using IoT Devices
Financial institutions are required to follow relevant self-regulatory rules established by financial institutions associations. Please see ‘Financial Industry’ in 4.3 Data Sharing.
Deployment of IoT devices or technologies involves navigating a complex regulatory environment, as it often falls under the purview of multiple government authorities, each with its own regulations. Businesses must therefore identify the relevant authorities and ensure compliance with the regulations applicable to their respective industries.
Taiwan does not have a single regulation specifically governing IoT data sharing. Instead, specific industries are subject to IoT-related regulations or guidelines that govern sharing practices. For example:
Financial Industry
The following guidelines regulate IoT data sharing and security for financial institutions:
These rules require banks and insurance companies to ensure that IoT devices used have identity authentication mechanisms, use wireless networks with encryption protocols, and monitor access control and network connections of IoT devices.
Healthcare Industry
Under the CSM Act, the Ministry of Health and Welfare (MOHW) issued the Cybersecurity Standards for Information and Communication Systems in the Healthcare Sector. Hospitals designated as providers of critical healthcare infrastructure must (i) manage wireless networks and access control when using medical IoT devices and (ii) prohibit data exchanges between wireless network-connected devices and the hospital’s core network.
If IoT data sharing involves the transfer of personal data, it is subject to the PDPA. The collection, processing, and use of personal data must have a specific purpose and legitimate causes. If the transfer of IoT data includes sensitive personal data, such as medical records, healthcare information, genetic data, sex life, physical examination or criminal records, the PDPA imposes stricter regulations on its processing and use.
Audiovisual media services in Taiwan, including traditional radio and television (“broadcasting businesses”), are primarily governed by the Radio and Television Act, the Satellite Broadcasting Act, and the Cable Radio and Television Act (collectively, “the Broadcasting Acts”), with the NCC acting as their competent authority. As these acts were enacted prior to the emergence of video-sharing platforms and streaming platforms, such as Netflix, YouTube and Spotify, these modern services are currently outside their regulatory scope. Although the NCC proposed the Draft Digital Services Act in 2020 and the Draft Act Governing Internet Audiovisual Services in 2022 to address this regulatory gap, neither has been enacted to date.
Licensing Requirements
Broadcasting businesses are required to apply for licences from the NCC prior to offering broadcasting service in Taiwan.
Renewal applications must be submitted before the licence expires to avoid disruptions in service.
Fees for Licensing and Renewal
(a) terrestrial-based broadcasting:
(b) cable broadcasting:
(c) satellite-based broadcasting:
Restrictions on Foreign Investment
Foreign investments in broadcasting businesses is highly regulated:
Scope of Regulation Under the TM Act and Related Regulations
The TM Act and its related regulations form the primary regulatory framework for telecommunications services. The competent authority is, in principle, the NCC, although the MODA oversees specific tasks (such as the application and allocation of telecommunications resources).
Under the TM Act, “telecommunications services” refers to “services that provide public communication using public telecommunications networks”, specifically including mobile broadband services, international submarine cable circuit leasing services, domestic land cable circuit leasing services, satellite fixed communications services, etc.
The TM Act also regulates:
Registration of Telecommunications Enterprises and Approval Mechanism for Public Telecommunications Network Establishment
Registration as a telecommunications enterprise is not mandatory for all providers of telecommunications services. Under the TM Act, registration is mandatory only if they:
All providers must apply to the NCC for approval to establish public telecommunications networks before offering telecommunications services and apply to the MODA if the services provided require the use of telecommunications resources such as radio frequencies. Please see ‘Public telecommunications networks’ in 4.1 Machine-to-Machine Communications, Communications Secrecy and Data Protection for details.
Cybersecurity Requirements for Telecommunications Services
The TM Act requires telecommunications enterprises that establish public telecommunications networks using telecommunications resources, as well as other telecommunications enterprises announced by the competent authority, to stipulate and implement a cybersecurity maintenance plan, including but not limited to the scope of cybersecurity management, tiered handling methods and joint defence response measures for cybersecurity incidents.
Applicants for public telecommunications networks establishment must include in their network establishment plan a comprehensive layout and architecture diagram of cybersecurity detection and protection measures. The plan must also detail the brand, model, quantity, capacity, functionality, manufacturer’s company name and country of origin for relevant facilities, as well as the operational management and physical security planning of the network.
The MODA may designate all or part of a public telecommunications network as critical telecommunications infrastructure. For such designated critical telecommunications infrastructure, the operator must, within the specified timeframe, stipulate a Critical Telecommunications Infrastructure Protection Plan and implement it upon evaluation. The MODA has promulgated the Regulations for Administration on Designation and Protection of Critical Telecommunications Infrastructure to regulate this process.
Taiwan does not currently have a standalone piece of legislation specifically addressing net neutrality. However, relevant provisions in the TM Act are designed to protect consumer rights or promote fair market competition. Specific examples include:
(a) Prohibition on unjustifiable service refusal: Telecommunications enterprises may not, without legitimate reason, refuse requests for telecommunications services or the transmission of communications.
(b) Number portability and equal access services: To protect user rights and promote market competition, telecommunications enterprises providing services using user numbers must offer number portability services or equal access services.
(c) Interconnection obligations: Telecommunications enterprises, under the principles of technical feasibility and fairness, may not, without legitimate reason, refuse interconnection negotiations when requested by other telecommunications enterprises.
(d) Regulation of significant market power entities (“SMP Entities”): The NCC enforces asymmetric regulation on telecommunications enterprises identified as SMP Entities in specific telecommunications service markets, which may include requiring such SMP Entities to ensure that:
Please refer to 3 Artificial Intelligence and 4 Internet of Things for details of the legislative status of emerging technologies such as IoT and AI and their impact on the telecommunications industry.
After the Executive Yuan designated the 4.8-4.9 GHz band for private 5G network use, “assisting enterprise clients in building private 5G networks” has become a key business initiative actively pursued by major telecommunications enterprises. In response, the MODA has promulgated the Regulations Governing the Establishment and Use of Mobile Broadband Dedicated Telecommunications Networks as guidelines for enterprises.
(a) Cybersecurity and risk management: The competent authorities are expected to place greater emphasis on regulatory requirements to manage risks associated with the use of emerging technologies in various telecommunications scenarios. For instance, operators may be required to propose more targeted cybersecurity protection measures in their network establishment plans.
(b) Compliance considerations: As outlined above, although there is currently no specific legislation addressing the integration of emerging technologies by telecommunications enterprises, operators should still comply with the existing regulatory framework when adopting such technologies. Particular attention should be given to areas such as personal data protection, cybersecurity and intellectual property rights protection.
Legal Compliance Points for Technology Agreements
In practice, the types of technology agreements are diverse, including but not limited to technology licensing, technology transfer, commissioned development and technology co-operation. While Taiwan has not enacted laws specifically regulating technology agreements, there are many legal compliance points to be aware of during the negotiation or performance stages. The key points are as follows:
(a) Personal data protection: Compliance with the PDPA is crucial when collecting, processing or using personal data.
(b) Fair trade compliance: Agreements must comply with the Fair Trade Act to avoid anti-competitive practices or engaging in unfair competition, such as “discriminatory treatment of the licensee”, “exclusive grand-back licensing”, “package licensing” or “restricting the licensee’s implementation of technology”. The Fair Trade Commission has issued the “Principles for the Handling of Technology Licensing Agreements” for businesses to follow.
(c) Export control: Agreements involving the exportation of “Strategic High-Tech Commodities”, such as dual-use military and commercial products or goods on the technology export control list, or involving “goods that require an international import certificate or other related guarantees issued by Taiwan in accordance with the exporting country’s regulations”, require approval from the International Trade Administration of the Ministry of Economic Affairs.
(d) Investment or co-operation in China, Hong Kong or Macau: Agreements involving “investing or technology co-operation in Mainland China” or “investing or technology co-operation in Hong Kong or Macau” require approval from the Ministry of Economic Affairs under relevant regulations.
Sector-Specific Considerations
The competent authorities for specific industries have promulgated “Personal Data File Security Maintenance Plans or Methods for Handling Personal Data After Business Termination” for their respective industries and are empowered to restrict the international transmission of personal data by businesses under their jurisdiction. Current restrictions include:
Many associations have established self-regulatory codes for the use of emerging technologies, such as the “Operational Guidelines for Financial Institutions Using Emerging Technologies”, “Principles for the Use of Emerging Technologies in the Insurance Industry” and the “Self-Regulatory Guidelines for Emerging Technology Cybersecurity in the Taiwan Securities Association”. Therefore, if the technology agreement involves the use of emerging technologies, businesses need to comply with the corresponding regulations according to their industry.
Key Points for Telecommunications Service Agreements
Under the TM Act, major telecommunications businesses recognised by the NCC, such as Chunghwa Telecom, must establish standard service contract terms that specify the rights and obligations with users, and submit them for approval before implementation. The contract terms should include but not limited to the following items:
In addition, if a significant dispute arises regarding a telecommunications service agreement between telecommunications businesses, they may apply to the NCC for conciliation to resolve the dispute.
Considerations for Network Interconnection Agreements
According to the TM Act, “interconnection” refers to a “network connection between telecommunications enterprises so as to enable their respective subscribers to communicate with subscribers of the other telecommunications enterprises or receive services provided by the other telecommunications enterprises”. As mentioned in (c) in 6.2 Net Neutrality Regulations, telecommunications enterprises may not refuse to negotiate interconnection requests from other telecommunications enterprises.
As mentioned in 6.2 Net Neutrality Regulations, the NCC has adopted special regulatory measures for SMP Entities in specific telecommunications service markets. If an interconnection agreement cannot be reached, each party may apply to the NCC for a ruling.
Regulations on Electronic Signatures
The Electronic Signatures Act (ESA) is the primary legislation governing electronic records, electronic signatures, digital signatures and relevant certification authorities.
(a) Legal equivalency: According to the ESA, electronic records and electronic signatures that meet the requirements of the ESA are deemed functionally equivalent to physical documents and signatures.
(b) Digital signatures: A digital signature:
(c) Counterparty consent
Regulations on Digital Identity
Taiwan does not currently have specific legislation governing digital identity. However, the government provides guidance on digital identity for certain industries. For instance, in the financial sector, the FSC issued the Guidelines for Conducting Digital Identity Authentication by Financial Services Enterprises to establish common and consistent application principles for digital identity authentication in the financial industry.
Legal Framework Governing Software and Online Gaming Industry
In Taiwan, the legal framework governing the software and online gaming industry primarily focuses on consumer dispute resolution and the protection of children and adolescents. Key regulations include:
(a) Game Software Rating Management Regulations;
(b) Mandatory and Prohibitory Provisions of Standard Form Contracts for Online Game Services (“Online Game Services Provisions”); and
(c) Mandatory and Prohibitory Provisions of Standard Form Contracts for Online Game Points (Cards) (“Online Game Points Provisions”).
To address consumer disputes, the Online Game Services Provisions stipulate that advertisements, promotional content, fee rate charts and game rules are considered integral parts of the contract between the gaming business and users. Users are also granted the right to withdraw from the contract within seven days after commencing the game, without providing a justifiable reason, and users may request a refund for unused prepaid game points without incurring any fees.
For protection of children and adolescents, the Game Software Rating Management Regulations require gaming businesses to assign ratings to their games based on content and include clear warnings and labels regarding game themes and risks.
The gaming industry in Taiwan also faces various intellectual property protection issue. Please refer to 9.3 Intellectual Property for details.
Legal Requirements for Games Providing In-Game Purchases, Loot Boxes and Gambling Elements
(a) Games providing in-game purchases: The Online Game Services Provisions require gaming businesses to clearly display payment methods and product or service information on their official website homepages, game login pages or purchase pages. Any fee adjustments must be announced at least 30 days prior to implementation. Additionally, prepaid game points purchased by users must not be subject to an expiration date.
(b) Games providing value-added services or products: When users purchase prepaid game points for value-added services or products, the Online Game Points Provisions require gaming businesses to provide performance guarantees to ensure the redeemability of the prepaid game points.
(c) Games providing loot boxes and gambling-like elements: For games offering loot boxes or similar elements, the Online Game Services Provisions require gaming businesses to disclose the event details, rewards and probabilities of winning. Additionally, a warning such as “This is a chance-based item; purchasing does not guarantee specific rewards” must be included. If the game involves gambling-like activities via telecommunications, electronic communications, the internet or similar methods, it may be deemed illegal and subject to criminal liability.
Legal Requirements for Age Ratings and Content Restrictions
The Game Software Rating Management Regulations also require gaming businesses to prominently display ratings labels, content descriptions and warnings on the product packaging, user’s guide, downloaded page, homepage or link to the game.
(a) Ratings labels: Games are categorised into five ratings based on their content, including elements such as sexual themes, violence, terror or drugs: Restricted (“R”, for users aged 18 and above), Parental Guidance 15 (“PG 15”, for users aged 15 and above), Parental Guidance 12 (“PG 12”, for users aged 12 and above), Protected (“P”, for users aged six and above) and General Public (“G”, suitable for all ages). Gaming businesses must complete the rating process before a game is launched and register the rating and related content with the MODA database.
(b) Content descriptions: If the game content involves certain scenarios, such as scenarios involving sex, violence, terror, tobacco and alcohol, drugs, improper use of language or anti-social behaviour, the content descriptions regarding the scenarios must be clearly indicated.
(c) Warnings: Gaming businesses must prominently display warning messages in Chinese, including but not limited to:
The gaming industry in Taiwan is regulated jointly by central and local government authorities. At the central level, the Administration for Digital Industries under the MODA serves as the primary regulator, while local governments are responsible for enforcing relevant regulations. If standard form contracts used by gaming businesses violate mandatory or prohibited provisions outlined in applicable regulations, regulatory bodies may require corrections within a specified timeframe under the Consumer Protection Act. Failure to comply within the deadline may result in fines, and persistent non-compliance could lead to repeated penalties.
In recent years, Taiwan has experienced a surge in fraud cases, with game point scams being a significant concern. To address this issue, the MODA has implemented anti-fraud measures for game points. These measures involve collaboration among game point card providers, game businesses, convenience stores and customer service providers to establish fraud prevention mechanisms and intercept fraudulent financial flows.
Copyright Protection for Game Businesses
Under Taiwan’s Copyright Act, works are classified into various categories, including but not limited to:
Taiwan courts have ruled that games often comprise multiple types of works, such as:
For these elements to receive copyright protection, they must reflect original human creativity, express the author’s individuality and not fall under exclusions provided by law.
However, game rules and user interfaces commonly used by users are not protected under the Copyright Act.
In cases of copyright infringement, copyright holders may:
The common IP challenge faced by game developers in Taiwan is allegations of plagiarism between games. Courts typically evaluate two key factors to determine copyright infringement:
If these criteria are satisfied and the use does not fall under fair use, the court may find that the defendant infringed upon the copyright of the original game.
Trade Mark Protection for Gaming Businesses
To prevent consumer confusion, gaming businesses may register trade marks for their game brands, titles, characters, backgrounds, items and designs pursuant to the Trade Mark Act. In addition, the Taiwan Intellectual Property Office has recommended that gaming businesses apply for trade mark registration for virtual goods and services.
In cases of potential trade mark infringement, the proprietor of a registered trade mark may take legal action to prevent such violations. For imported or exported goods suspected of infringing trade mark rights, the proprietor may file an application with customs to detain the goods. If infringement is confirmed, the trade mark owner has the right to demand the cessation of the infringement and seek compensation for damages incurred.
Intellectual Property Issues Surrounding UGC
User-generated content (UGC) may qualify for protection under the Copyright Act depending on its nature. However, UGC may also result in copyright or trade mark infringement if it involves unauthorised use of third-party intellectual property. Currently, Taiwan does not have specific legislation or judicial precedents addressing disputes arising from UGC in the gaming industry.
There is currently no specific law regulating social media in Taiwan; however, several regulations apply to social media operations in various contexts. Below is an overview of the key laws and challenges:
Anti-Fraud Measures
The Fraud Crime Hazard Prevention Act (FCHPA) requires specific online advertising platform operators to adopt necessary measures to prevent fraud. Key provisions include:
Online advertising platform operators that fail to comply will be jointly liable with the advertising commissioner or funder for damages incurred by individuals misled by the fraudulent advertisements.
Personal Data Protection
Social media operators must comply with the PDPA when collecting, processing and utilising user data. If the social media operator conducts business involving data processing, it must also comply with “Regulations Regarding the Security Maintenance and Administration of Personal Data Files in Digital Economy Industry”. The key requirements are:
If businesses wish to collect customers’ personal data and use the contact information such as phone numbers or emails to provide product information and promote sales for marketing, they must provide a method for individuals to decline marketing during the initial marketing contact. Once an individual expresses refusal to receive further marketing, the business must immediately cease using their personal data for such purposes.
Copyright Protection
Modern users enjoy sharing various types of content, such as text, images and videos, on social media. If such content is copyright-protected, the uploader or sharer may infringe on others’ copyrights, and the social media operator providing the service could also face legal risks for being deemed to be facilitating or participating in the infringement.
To balance the protection of copyright owners and the development of the internet industry, the Copyright Act provides safe harbour provisions. If specific requirements are met, online service providers offering social media services are exempt from liability for users’ copyright infringements. Common requirements for exemption, for example, are that online service providers must:
In addition to the common requirements above, different types of online service providers must comply with other specific requirements for exemption.
The MODA is the competent authority for social media platforms conducting online advertising business. The MODA has the authority to designate specific platforms to be subject to the FCHPA, formulate obligations for fraud prevention, impose fines for non-compliance, and mandate corrective measures within a specified timeframe.
Recent enforcement actions by the MODA include, on 16 September 2024, designating Google, Line, Meta and TikTok as entities subject to the FCHPA. On 28 November 2024, the MODA announced that the above entities must, starting from 30 November 2024, restrict browsing, stop broadcasting or adopt other necessary actions regarding advertisements identified as fraudulent or clearly related to fraud within 24 hours of receiving a notification from competent authorities.
9F, 218 Tun Hwa S. Rd.
Sec. 2
Taipei 106033
Taiwan
R.O.C.
+886 2 2378 5780
+886 2 2378 5781
lawtec@leetsai.com www.leetsai.comIntroduction
The progress of technology and changes in people’s lifestyles have led to the rapid growth of emerging technologies such as AI, cloud computing, IoT and blockchain, increasing the extent to which people depend on and are influenced by technology. While these advancements offer expanded opportunities in investment, consumption and entertainment, they also present challenges such as fraud and money laundering. In response, Taiwan has implemented regulatory measures to foster innovation while addressing risks.
I. Regulation of Virtual Assets
A. Taiwan’s virtual asset regulatory history and development
Taiwan has adopted a gradual approach to regulating virtual asset service providers (VASPs). In addition to government departments, self-regulatory organisations play a critical role in cultivating a culture of compliance within the industry. Key developments are summarised below:
(1) Phase 1: anti-money laundering (AML) regulation
Since 2021, the Financial Supervisory Commission (FSC) has enforced the “Regulations Governing Anti-Money Laundering and Countering the Financing of Terrorism for Enterprises Handling Virtual Currency Platform or Transaction” (“VASP AML Regulations”). These regulations mandate that VASPs complete AML declarations before providing virtual asset services and comply with regulations such as customer identification and transaction monitoring. As of 17 January 2025, 23 VASPs in Taiwan have completed their AML declarations.
(2) Phase 2: promoting VASP to establish an association and developing self-regulatory codes
In 2023, the FSC issued the “Guidelines for the Administration of Virtual Asset Service Provider” (“VASP Guidelines”), which required VASPs to establish an association. With the support of the FSC, the Taiwan VASP Association was established in June 2024 (“Association”). From November 2024 to January 2025, the Association issued seven self-regulatory codes covering issues such as virtual asset listing and delisting review, customer protection, anti-money laundering, fraud prevention, cybersecurity management, and asset segregation and safekeeping.
(3) Phase 3: establishment of VASP registration regime
In accordance with Article 6 of the Money Laundering Control Act and the “Anti-Money Laundering Registration Regulations for Virtual Asset Service Providers” (“VASP Registration Regulations”), effective from 30 November 2024, VASPs must complete AML registration with the FSC before they can legally provide virtual asset services in Taiwan. Failure to comply will result in criminal liability, with penalties including up to two years of imprisonment and a fine of up to TWD5 million for individuals, and fines of up to TWD50 million for entities. It is important to note that while the registration regime is structured under the anti-money laundering framework, its substantive content also covers crucial issues such as protection of clients’ assets and maintenance of market discipline. For detailed regulatory content, please refer to the section “I.B. Current Regulations for VASPs”.
(4) Phase 4: development of a VASP-specific law
Starting with anti-money laundering measures, Taiwan has gradually implemented a step-by-step regulatory approach for VASPs, accompanied by the establishment of self-regulatory organisations and communication with the industry. The Taiwan government further strengthened its control over VASPs by creating the registration system. In line with these efforts, the FSC plans to submit a draft VASP-specific law to the Executive Yuan in June 2025, which will further regulate VASP-related issues.
B. Current regulations for VASPs
VASPs must comply with the following main regulations, including the VASP Registration Regulations, the VASP AML Regulations, the Fraud Crime Hazard Prevention Act (FCHPA) and self-regulatory codes. The key points are outlined as follows:
(1) VASP Registration Regulations
The VASP Registration Regulations categorise VASPs into five types: Virtual Asset Exchangers, Virtual Asset Trading Platforms, Virtual Asset Transferors, Virtual Asset Custodians and Virtual Asset Underwriters. In addition to general requirements for all VASPs, the VASP Registration Regulations also impose different legal obligations based on the type of service provided by different VASPs.
Specifically, all VASPs are required to:
Additionally, VASPs are required to comply with specific regulations depending on the services they provide. For example, Virtual Asset Trading Platforms must comply with the following key requirements:
(2) AML regulations and enforcement
To combat money laundering and terrorist financing (AML/CFT), VASPs must comply with several key regulations, including but not limited to:
To ensure VASPs comply with the aforementioned regulations, the FSC has intensified its enforcement of AML measures. In addition to designating “AML issues” as a key focus in VASP financial inspections, the FSC imposed fines of millions of TWD on four major Taiwanese VASPs for AML deficiencies in 2024.
(3) FCHPA
As blockchain technology facilitates rapid fund transfers and provides a certain level of anonymity, it poses a risk of being exploited by fraud groups for the transfer of proceeds of crime. Therefore, the FCHPA and its associated regulations require VASPs to comply with fraud prevention obligations similar to those of financial institutions. For further details, please refer to the section on “II.B. Key Anti-Fraud Obligations Across Industries”.
(4) Self-regulatory codes
Compared with the above requirements, the self-regulatory codes announced by the Association are more technical and detailed, addressing issues such as the listing and delisting review of virtual assets, customer protection and AML/CFT. Since the VASP registration regime requires VASPs to join the Association and comply with its self-regulatory codes, failure of compliance may result in the FSC either rejecting the VASP’s registration application or revoking the registration of an already registered VASP. Consequently, these codes hold a certain degree of mandatory force for VASPs.
C. Regulations for financial institutions conducting businesses related to virtual assets
The FSC previously took a conservative approach regarding financial institutions’ involvement in virtual asset-related businesses. For example, in a 2014 press release, it stated that “banks and other financial institutions are prohibited from accepting or exchanging Bitcoin, and from offering Bitcoin-related services via their ATMs”. However, there has been a recent shift in policy, with the FSC now exploring the possibility of allowing financial institutions to engage in limited virtual asset businesses.
(1) Custody businesses
On 28 November 2024, the FSC announced that financial institutions could apply for a business trial for virtual asset custody businesses between January and April 2025. Financial institutions must submit relevant documents such as their plans regarding custody models, customer service, compliance measures and security for application. The trial period is expected to last approximately six months, with a review period of about two months.
(2) ETF sub-delegation businesses
On 30 September 2024, the FSC announced that professional investors would be allowed to invest in foreign virtual asset exchange-traded funds (ETFs) through sub-delegation. Securities firms executing such trades must confirm that the client qualifies as a professional investor, and assess the client’s investment knowledge and experience related to virtual assets prior to their first purchase to ensure the suitability of investing in virtual asset ETFs.
Securities firms have responded positively to this policy. The first firm to act on it launched more than 70 US virtual asset ETFs on 24 December 2024, offering professional investors the opportunity to invest through sub-delegation.
II. Fraud Crime Prevention Measures
A. Legislative background and regulatory framework
In response to the evolving nature of fraud crimes, the Executive Yuan established the “Anti-Fraud Command Centre”, with participation from five government agencies: the Ministry of the Interior, the National Communications Commission (NCC), the FSC, the Ministry of Justice and the Ministry of Digital Affairs (MODA), to co-ordinate and supervise inter-ministerial fraud prevention strategies and actions. From a legal perspective, Taiwan announced amendments to four related laws on 31 July 2024: the FCHPA, the Money Laundering Control Act, the Communication Security and Surveillance Act, and the Code of Criminal Procedure. Key points are summarised as follows:
(1) FCHPA
As the core regulation for fraud prevention, the FCHPA addresses the insufficiency of civil and criminal laws in deterring fraudulent activities and protecting victims. The FCHPA includes the following key measures:
(2) Money Laundering Control Act
Key amendments to this act require VASPs and third-party payment providers to complete necessary registration or filing. Non-compliance may result in criminal liability. These measures aim to improve government oversight, foster a culture of compliance and prevent such entities from being exploited as tools for transferring proceeds of the crime.
(3) Communication Security and Surveillance Act
Recent amendments broaden the authority of law enforcement agencies to conduct surveillance and access online records, enhancing the efficiency of criminal investigations.
(4) Code of Criminal Procedure
A new chapter on “Special Compulsory Measures” regulates the use of technological methods, such as GPS or other tracking tools, to locate suspects. These amendments aim to balance the rights of suspects with the goals of criminal investigations.
B. Key Anti-Fraud Obligations Across Industries
(1) Financial institutions and VASPs
The FSC is the governing authority, and financial institutions and VASPs are subject to anti-fraud obligations under the FCHPA. Key requirements include:
(2) Telecommunications businesses
The NCC is the governing authority, and telecommunications businesses (eg, Chunghwa Telecom) must comply with the following key anti-fraud obligations:
(3) Digital economy industries
The MODA is the governing authority, and digital economy industries subject to fraud prevention obligations under the FCHPA include online advertising platforms operators, third-party payment service providers, e-commerce companies and online gaming operators. Key obligations are as follows:
III. Other Measures to Address Fraud and Money Laundering Issues
Due to the vast and complex nature of fraud and money laundering issues in the digital era, addressing these challenges solely through government legislation is increasingly impractical. Therefore, in addition to legislative efforts to address the issues mentioned above, Taiwan also places significant emphasis on leveraging technological tools to improve the efficiency of fraud and money laundering prevention. At the same time, many private organisations and individuals are actively involved in promoting fraud detection capabilities or strengthening cross-border co-operation in fraud prevention resources.
A. Examples of utilising technological tools to address fraud and money laundering issues
B. Contributions of private organisations and individuals in fraud prevention
Conclusion
Taiwan has always placed great emphasis on the development of technology, fintech and digital economy-related industries. Recently, it has focused on establishing comprehensive VASP regulatory measures and promoting policies related to fraud prevention and anti-money laundering. Given the rapid pace of regulatory changes, businesses must stay alert to regulatory trends to ensure compliance and lawful operation in Taiwan.
9F, 218 Tun Hwa S. Rd.
Sec. 2
Taipei 106033
Taiwan
R.O.C.
+886 2 2378 5780
+886 2 2378 5781
lawtec@leetsai.com www.leetsai.com