A Preferred Model for Taiwan’s agency level AI risk categorization and management: A Cross-Jurisdictional Perspective

A Preferred Model for Taiwan’s agency level AI risk categorization and management: A Cross-Jurisdictional Perspective

2025/09/15

Taiwan’s draft Artificial Intelligence Basic Law includes a provision allowing each government agency to establish its own risk-based AI management rules tailored to sector-specific regulatory needs[1]. To strike an effective balance between innovation and oversight, selecting an appropriate reference model is essential. After comparing major jurisdictions, this research argues that the United States Office of Management and Budget (OMB) Memorandum M-25-21—Accelerating Federal Use of AI through Innovation, Governance, and Public Trust[2]—offers the most balanced and practical approach for Taiwan’s agencies to refer to at this initial stage of developing AI regulation and promoting AI adoption.

This article will first present an overview of the U.S. M-25-21 framework and its key features. It will then explain why the U.S. model is more suitable for Taiwan than those of other jurisdictions. Finally, it will conclude with recommendations for the government.

I. Overview of the U.S. M-25-21 Framework

Issued in April 2025 under Executive Order 14179, M-25-21 directs federal agencies to accelerate the adoption of artificial intelligence while maintaining a set of minimum safeguards. The memorandum identifies three priorities—innovation, governance, and public trust—and structures AI oversight around these principles.

It requires every executive branch agency to designate a Chief AI Officer (CAIO), a senior official empowered to promote AI innovation, maintain a current inventory of AI use cases, and ensure that processes such as determining “high-impact” uses are in place. Rather than imposing a centralized management system, M-25-21 allows each agency to make context-sensitive determinations and to accept or waive risk management requirements. This approach recognizes that agencies vary widely in mission and capacity and are best positioned to understand the potential risks and benefits of AI within their own domains.

The memorandum defines high-impact AI as systems whose outputs serve as a principal basis for decisions or actions with legal, material, binding, or significant rights and safety consequences. It offers a non-exhaustive list of presumed high-impact categories, including safety-critical functions of critical infrastructure, traffic management, patient diagnosis, blocking protected speech, and law enforcement applications. If an agency official determines that a specific AI use within these categories does not meet the high-impact definition, they must submit written documentation to notify the CAIO. By tying the definition to the effect of an AI system’s output rather than to a fixed sectoral list, M-25-21 provides a flexible method for identifying high-risk AI applications while preserving room for innovation.

II. Key Features of the U.S. M-25-21 Framework

A. Minimum Risk Management Practices

To ensure protection without creating excessive barriers, M-25-21 specifies a set of minimum risk management practices that each agency must apply when using high-impact AI. Agencies are required to conduct pre-deployment testing under realistic conditions to confirm that AI systems perform as intended and to prepare appropriate risk mitigation plans. Even when agencies lack access to source code or training data, they are expected to use alternative testing methods—such as querying the AI service and observing its outputs—to assess performance and potential risks.

Before deploying a high-impact AI system, agencies must complete an AI impact assessment. This assessment must explain the system’s intended purpose and expected benefits, analyze the quality and appropriateness of the data used, and evaluate potential impacts on privacy, civil rights, and civil liberties. It should also include a cost analysis, planned reassessment schedules and procedures, and comments highlighting potential concerns or gaps from an independent reviewer who was not involved in the system’s development. Importantly, the assessment must carry the signature of an accountable official who formally accepts the risk of deploying the AI system.

Once deployed, agencies are expected to monitor AI systems continuously for performance drift, security vulnerabilities, or unforeseen adverse effects, and to implement appropriate mitigations and maintain documentation. Human oversight is equally essential: operators must receive specific training to interpret AI outputs, intervene when necessary, and use fail-safes or override mechanisms to minimize the risk of significant harm in high-impact situations.

To protect the public, M-25-21 insists that individuals affected by AI-enabled decisions have access to timely human review and opportunities to appeal adverse outcomes. Appeals should not impose unnecessary burdens on individuals or the administration. Furthermore, agencies are expected to seek feedback from end users and the public to inform AI-related decision-making. These combined practices—testing, assessment, independent review, monitoring, human oversight, remedies, and feedback—form a balanced foundation for responsible AI use. The memorandum also requires agencies to safely discontinue any high-impact use cases that fail to comply with the minimum practices.

B. Waiver System: Purpose and Conditions

A distinctive feature of M-25-21 is its formal system for waivers from the minimum risk management practices. The waiver mechanism exists to reconcile two priorities: ensuring safety and rights protections on the one hand, and enabling innovation and rapid response on the other. Waivers may be considered when following a particular requirement would actually increase risks to safety or rights overall, or when compliance would create an unacceptable impediment to critical agency operations. For example, during a natural disaster or public health emergency, strict adherence to every procedural requirement might delay the deployment of an AI application that could save lives. In such situations, the CAIO may authorize a waiver to permit rapid deployment while still tracking and reassessing the use.

Waivers for pilot programs are equally important for encouraging experimentation and innovation. They allow agencies to conduct small-scale, time-limited AI projects without implementing all minimum risk management practices, provided certain conditions are met: the pilot must be certified by the CAIO, centrally tracked, offer opt-in and opt-out options for individual participation, and apply minimum risk management practices where practicable.

The memorandum imposes safeguards on this flexibility. Every waiver must be documented with a written determination explaining the reasoning, centrally tracked, and reassessed annually or whenever significant changes to the AI application’s conditions or context occur. CAIOs retain the power to revoke waivers at any time, and agencies must report any granted or revoked waiver to OMB annually and within 30 days of significant modifications. This approach maintains accountability while preventing rigid rules from becoming obstacles to effective governance.

C. Disclosure Requirements for High-Impact Use and Waivers

M-25-21 strongly emphasizes transparency as a pillar of public trust. Each agency must maintain an inventory of all AI use cases, submit it to OMB, and post a public version on the agency’s website. This inventory should be updated annually and, ideally, throughout the year to reflect the agency’s current use of AI. Transparency ensures that the public, civil society, and oversight bodies can understand where AI is influencing important government decisions without exposing sensitive or classified details.

Similarly, agencies must publicly release summaries of each waiver or determination, including the justification, or explicitly indicate when no determinations or waivers are active. By making these summaries visible, the system builds confidence that waivers are granted for legitimate reasons. At the same time, OMB retains the authority to request detailed records concerning exception determinations within presumed high-impact categories. This combination of public disclosure and federal oversight helps maintain trust while safeguarding privacy, national security, and proprietary information.

III. Why M-25-21 Stands Out for Taiwan’s AI Governance among Global Approaches

Taiwan’s draft AI Basic Law envisions a decentralized system in which each agency determines its own risk classification and management practices[3]. The U.S. framework aligns closely with this philosophy. By empowering agencies to identify high-risk AI use cases tailored to their specific contexts, M-25-21 helps ensure that AI governance remains grounded in operational realities. At the same time, adopting M-25-21’s baseline practices, waiver safeguards, and disclosure requirements would provide consistency and public accountability across agencies. The combination of minimum risk management practices and transparent waiver use would encourage innovation while reassuring the public that any exceptions are justified, continuously monitored, and effectively controlled. Furthermore, embracing an approach that reflects emerging international consensus—particularly the emphasis on transparency in both U.S. and EU regimes—would position Taiwan to harmonize with global AI governance trends and strengthen its credibility in international markets.

In contrast, the European Union’s AI Act predefines high-risk categories and mandates strict conformity assessments, CE Marking, and post-market monitoring[4]—an approach that is comprehensive but resource-intensive and may not suit all agencies equally. Australia’s ongoing discussions had been trending toward a similarly comprehensive model, but there has recently been backlash against this approach. Korea’s AI Basic Act[5] references high-risk AI only in broad terms and leaves most operational details undefined. M-25-21 strikes a middle ground, offering minimum yet concrete safeguards while preserving the flexibility agencies need to tailor governance to their specific domains.

IV. Recommendations and Conclusion

Based on this analysis, this research recommends that each agency designate a senior AI leader similar to a CAIO, maintain a public inventory of high-impact AI use cases, and publish summaries of waivers or determinations while safeguarding sensitive information. Agencies should also be encouraged to share AI resources and lessons learned to reduce duplication and strengthen governance maturity across government. Over time, these risk management practices can be refined in response to operational experience and evolving international standards. By adopting these principles, Taiwan can empower its agencies to innovate responsibly, protect citizens’ rights, and build public trust—ensuring that AI deployment across government remains both effective and aligned with global best practices.

 

[1]〈政院通過「人工智慧基本法」草案 建構AI發展與應用良善環境 打造臺灣成為AI人工智慧島〉,行政院,https://www.ey.gov.tw/Page/9277F759E41CCD91/5d673d1e-f418-47dc-ab35-a06600f77f07(最後瀏覽日期︰2025/09/15)。

[2] United States Office of Management and Budget (OMB), M-25-21 Accelerating Federal Use of AI through Innovation, Governance, and Public Trust, https://www.whitehouse.gov/wp-content/uploads/2025/02/M-25-21-Accelerating-Federal-Use-of-AI-through-Innovation-Governance-and-Public-Trust.pdf (last visited Sept 15, 2025).

[3] 蘇文彬,〈行政院通過AI基本法草案,將不設立AI專責機關〉,iThome,https://www.ithome.com.tw/news/170874(最後瀏覽日期︰2025/09/15)。

[4] Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence and amending Regulations (EC) No 300/2008, (EU) No 167/2013, (EU) No 168/2013, (EU) 2018/858, (EU) 2018/1139 and (EU) 2019/2144 and Directives 2014/90/EU, (EU) 2016/797 and (EU) 2020/1828 (Artificial Intelligence Act), https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32024R1689 (last visited Sept 15, 2025).

※A Preferred Model for Taiwan’s agency level AI risk categorization and management: A Cross-Jurisdictional Perspective,STLI, https://stli.iii.org.tw/en/article-detail.aspx?no=105&tp=2&i=168&d=9402 (Date:2026/09/09)
Quote this paper
You may be interested
The use of automated facial recognition technology and supervision mechanism in UK

The use of automated facial recognition technology and supervision mechanism in UK I. Introduction   Automatic facial recognition (AFR) technology has developed rapidly in recent years, and it can identify target people in a short time. The UK Home Office announced the "Biometrics Strategy" on June 28, 2018, saying that AFR technology will be introduced in the law enforcement, and the Home Office will also actively cooperate with other agencies to establish a new oversight and advisory board in order to maintain public trust. AFR technology can improve law enforcement work, but its use will increase the risk of intruding into individual liberty and privacy.   This article focuses on the application of AFR technology proposed by the UK Home Office. The first part of this article describes the use of AFR technology by the police. The second part focuses on the supervision mechanism proposed by the Home Office in the Biometrics Strategy. However, because the use of AFR technology is still controversial, this article will sort out the key issues of follow-up development through the opinions of the public and private sectors. The overview of the discussion of AFR technology used by police agencies would be helpful for further policy formulation. II. Overview of the strategy of AFR technology used by the UK police   According to the Home Office’s Biometrics Strategy, the AFR technology will be used in law enforcement, passports and immigration and national security to protect the public and make these public services more efficient[1]. Since 2017 the UK police have worked with tech companies in testing the AFR technology, at public events like Notting Hill Carnival or big football matches[2].   In practice, AFR technology is deployed with mobile or fixed camera systems. When a face image is captured through the camera, it is passed to the recognition software for identification in real time. Then, the AFR system will process if there is a ‘match’ and the alarm would solicit an operator’s attention to verify the match and execute the appropriate action[3]. For example, South Wales Police have used AFR system to compare images of people in crowds attending events with pre-determined watch lists of suspected mobile phone thieves[4]. In the future, the police may also compare potential suspects against images from closed-circuit television cameras (CCTV) or mobile phone footage for evidential and investigatory purposes[5].   The AFR system may use as tools of crime prevention, more than as a form of crime detection[6]. However, the uses of AFR technology are seen as dangerous and intrusive by the UK public[7]. For one thing, it could cause serious harm to democracy and human rights if the police agency misuses AFR technology. For another, it could have a chilling effect on civil society and people may keep self-censoring lawful behavior under constant surveillance[8]. III. The supervision mechanism of AFR technology   To maintaining public trust, there must be a supervision mechanism to oversight the use of AFR technology in law enforcement. The UK Home Office indicates that the use of AFR technology is governed by a number of codes of practice including Police and Criminal Evidence Act 1984, Surveillance Camera Code of Practice and the Information Commissioner’s Office (ICO)’s Code of Practice for surveillance cameras[9]. (I) Police and Criminal Evidence Act 1984   The Police and Criminal Evidence Act (PACE) 1984 lays down police powers to obtain and use biometric data, such as collecting DNA and fingerprints from people arrested for a recordable offence. The PACE allows law enforcement agencies proceeding identification to find out people related to crime for criminal and national security purposes. Therefore, for the investigation, detection and prevention tasks related to crime and terrorist activities, the police can collect the facial image of the suspect, which can also be interpreted as the scope of authorization of the  PACE. (II) Surveillance Camera Code of Practice   The use of CCTV in public places has interfered with the rights of the people, so the Protection of Freedoms Act 2012 requires the establishment of an independent Surveillance Camera Commissioner (SCC) for supervision. The Surveillance Camera Code of Practice  proposed by the SCC sets out 12 principles for guiding the operation and use of surveillance camera systems. The 12 guiding principles are as follows[10]: A. Use of a surveillance camera system must always be for a specified purpose which is in pursuit of a legitimate aim and necessary to meet an identified pressing need. B. The use of a surveillance camera system must take into account its effect on individuals and their privacy, with regular reviews to ensure its use remains justified. C. There must be as much transparency in the use of a surveillance camera system as possible, including a published contact point for access to information and complaints. D. There must be clear responsibility and accountability for all surveillance camera system activities including images and information collected, held and used. E. Clear rules, policies and procedures must be in place before a surveillance camera system is used, and these must be communicated to all who need to comply with them. F. No more images and information should be stored than that which is strictly required for the stated purpose of a surveillance camera system, and such images and information should be deleted once their purposes have been discharged. G. Access to retained images and information should be restricted and there must be clearly defined rules on who can gain access and for what purpose such access is granted; the disclosure of images and information should only take place when it is necessary for such a purpose or for law enforcement purposes. H. Surveillance camera system operators should consider any approved operational, technical and competency standards relevant to a system and its purpose and work to meet and maintain those standards. I. Surveillance camera system images and information should be subject to appropriate security measures to safeguard against unauthorised access and use. J. There should be effective review and audit mechanisms to ensure legal requirements, policies and standards are complied with in practice, and regular reports should be published. K. When the use of a surveillance camera system is in pursuit of a legitimate aim, and there is a pressing need for its use, it should then be used in the most effective way to support public safety and law enforcement with the aim of processing images and information of evidential value. L. Any information used to support a surveillance camera system which compares against a reference database for matching purposes should be accurate and kept up to date. (III) ICO’s Code of Practice for surveillance cameras   It must need to pay attention to the personal data and privacy protection during the use of surveillance camera systems and AFR technology. The ICO issued its Code of Practice for surveillance cameras under the Data Protection Act 1998 to explain the legal requirements operators of surveillance cameras. The key points of ICO’s Code of Practice for surveillance cameras are summarized as follows[11]: A. The use time of the surveillance camera systems should be carefully evaluated and adjusted. It is recommended to regularly evaluate whether it is necessary and proportionate to continue using it. B. A police force should ensure an effective administration of surveillance camera systems deciding who has responsibility for the control of personal information, what is to be recorded, how the information should be used and to whom it may be disclosed. C. Recorded material should be stored in a safe way to ensure that personal information can be used effectively for its intended purpose. In addition, the information may be considered to be encrypted if necessary. D. Disclosure of information from surveillance systems must be controlled and consistent with the purposes for which the system was established. E. Individuals whose information is recoded have a right to be provided with that information or view that information. The ICO recommends that information must be provided promptly and within no longer than 40 calendar days of receiving a request. F. The minimum and maximum retention periods of recoded material is not prescribed in the Data Protection Act 1998, but it should not be kept for longer than is necessary and should be the shortest period necessary to serve the purposes for which the system was established. (IV) A new oversight and advisory board   In addition to the aforementioned regulations and guidance, the UK Home Office mentioned that it will work closely with related authorities, including ICO, SCC, Biometrics Commissioner (BC), and Forensic Science Regulator (FSR) to establish a new oversight and advisory board to coordinate consideration of law enforcement’s use of facial images and facial recognition systems[12].   To sum up, it is estimated that the use of AFR technology by law enforcement has been abided by existing regulations and guidance. Firstly, surveillance camera systems must be used on the purposes for which the system was established. Secondly, clear responsibility and accountability mechanisms should be ensured. Thirdly, individuals whose information is recoded have the right to request access to relevant information. In the future, the new oversight and advisory board will be asked to consider issues relating to law enforcement’s use of AFR technology with greater transparency. IV. Follow-up key issues for the use of AFR technology   Regarding to the UK Home Office’s Biometrics Strategy, members of independent agencies such as ICO, BC, SCC, as well as civil society, believe that there are still many deficiencies, the relevant discussions are summarized as follows: (I) The necessity of using AFR technology   Elizabeth Denham, ICO Commissioner, called for looking at the use of AFR technology carefully, because AFR is an intrusive technology and can increase the risk of intruding into our privacy. Therefore, for the use of AFR technology to be legal, the UK police must have clear evidence to demonstrate that the use of AFR technology in public space is effective in resolving the problem that it aims to address[13].   The Home Office has pledged to undertake Data Protection Impact Assessments (DPIAs) before introducing AFR technology, including the purpose and legal basis, the framework applies to the organization using the biometrics, the necessity and proportionality and so on. (II)The limitations of using facial image data   The UK police can collect, process and use personal data based on the need for crime prevention, investigation and prosecution. In order to secure the use of biometric information, the BC was established under the Protection of Freedoms Act 2012. The mission of the BC is to regulate the use of biometric information, provide protection from disproportionate enforcement action, and limit the application of surveillance and counter-terrorism powers.   However, the BC’s powers do not presently extend to other forms of biometric information other than DNA or fingerprints[14]. The BC has expressed concern that while the use of biometric data may well be in the public interest for law enforcement purposes and to support other government functions, the public benefit must be balanced against loss of privacy. Hence, legislation should be carried to decide that crucial question, instead of depending on the BC’s case feedback[15].   Because biometric data is especially sensitive and most intrusive of individual privacy, it seems that a governance framework should be required and will make decisions of the use of facial images by the police. (III) Database management and transparency   For the application of AFR technology, the scope of biometric database is a dispute issue in the UK. It is worth mentioning that the British people feel distrust of the criminal database held by the police. When someone is arrested and detained by the police, the police will take photos of the suspect’s face. However, unlike fingerprints and DNA, even if the person is not sued, their facial images are not automatically deleted from the police biometric database[16].   South Wales Police have used AFR technology to compare facial images of people in crowds attending major public events with pre-determined watch lists of suspected mobile phone thieves in the AFR field test. Although the watch lists are created for time-limited and specific purposes, the inclusion of suspects who could possibly be innocent people still causes public panic.   Elizabeth Denham warned that there should be a transparency system about retaining facial images of those arrested but not charged for certain offences[17]. Therefore, in the future the UK Home Office may need to establish a transparent system of AFR biometric database and related supervision mechanism. (IV) Accuracy and identification errors   In addition to worrying about infringing personal privacy, the low accuracy of AFR technology is another reason many people oppose the use of AFR technology by police agencies. Silkie Carlo, director of Big Brother Watch, said the police must immediately stop using the AFR technology and avoid mistaking thousands of innocent citizens as criminals; Paul Wiles, Biometrics Commissioner, also called for legislation to manage AFR technology because of its accuracy is too low and the use of AFR technology should be tested and passed external peer review[18].   In the Home Office’s Biometric Strategy, the scientific quality standards for AFR technology will be established jointly with the FSR, an independent agency under the Home Office. In other words, the Home Office plans to extend the existing forensics science regime to regulate AFR technology.   Therefore, the FSR has worked with the SCC to develop standards relevant to digital forensics. The UK government has not yet seen specific standards for regulating the accuracy of AFR technology at the present stage. V. Conclusion   From the discussion of the public and private sectors in the UK, we can summarize some rules for the use of AFR technology. Firstly, before the application of AFR technology, it is necessary to complete the pre-assessment to ensure the benefits to the whole society. Secondly, there is the possibility of identifying errors in AFR technology. Therefore, in order to maintain the confidence and trust of the people, the relevant scientific standards should be set up first to test the system accuracy. Thirdly, the AFR system should be regarded as an assisting tool for police enforcement in the initial stage. In other words, the information analyzed by the AFR system should still be judged by law enforcement officials, and the police officers should take the responsibilities.   In order to balance the protection of public interest and basic human rights, the use of biometric data in the AFR technology should be regulated by a special law other than the regulations of surveillance camera and data protection. The scope of the identification database is also a key point, and it may need legislators’ approval to collect and store the facial image data of innocent people. Last but not least, the use of the AFR system should be transparent and the victims of human rights violations can seek appeal. [1] UK Home Office, Biometrics Strategy, Jun. 28, 2018, https://www.gov.uk/government/publications/home-office-biometrics-strategy (last visited Aug. 09, 2018), at 7. [2] Big Brother Watch, FACE OFF CAMPAIGN: STOP THE MET POLICE USING AUTHORITARIAN FACIAL RECOGNITION CAMERAS, https://bigbrotherwatch.org.uk/all-campaigns/face-off-campaign/ (last visited Aug. 16, 2018). [3] Lucas Introna & David Wood, Picturing algorithmic surveillance: the politics of facial recognition systems, Surveillance & Society, 2(2/3), 177-198 (2004). [4] Supra note 1, at 12. [5] Id, at 25. [6] Michael Bromby, Computerised Facial Recognition Systems: The Surrounding Legal Problems (Sep. 2006)(LL.M Dissertation Faculty of Law University of Edinburgh), http://citeseerx.ist.psu.edu/viewdoc/download?doi=10.1.1.197.7339&rep=rep1&type=pdf , at 3. [7] Owen Bowcott, Police face legal action over use of facial recognition cameras, The Guardian, Jun. 14, 2018, https://www.theguardian.com/technology/2018/jun/14/police-face-legal-action-over-use-of-facial-recognition-cameras (last visited Aug. 09, 2018). [8] Martha Spurrier, Facial recognition is not just useless. In police hands, it is dangerous, The Guardian, May 16, 2018, https://www.theguardian.com/commentisfree/2018/may/16/facial-recognition-useless-police-dangerous-met-inaccurate (last visited Aug. 17, 2018). [9] Supra note 1, at 12. [10] Surveillance Camera Commissioner, Surveillance camera code of practice, Oct. 28, 2014, https://www.gov.uk/government/publications/surveillance-camera-code-of-practice (last visited Aug. 17, 2018). [11] UK Information Commissioner’s Office, In the picture: A data protection code of practice for surveillance cameras and personal information, Jun. 09, 2017, https://ico.org.uk/for-organisations/guide-to-data-protection/encryption/scenarios/cctv/ (last visited Aug. 10, 2018). [12] Supra note 1, at 13. [13] Elizabeth Denham, Blog: facial recognition technology and law enforcement, Information Commissioner's Office, May 14, 2018, https://ico.org.uk/about-the-ico/news-and-events/blog-facial-recognition-technology-and-law-enforcement/ (last visited Aug. 14, 2018). [14] Monique Mann & Marcus Smith, Automated Facial Recognition Technology: Recent Developments and Approaches to Oversight, Automated Facial Recognition Technology, 10(1), 140 (2017). [15] Biometrics Commissioner, Biometrics Commissioner’s response to the Home Office Biometrics Strategy, Jun. 28, 2018, https://www.gov.uk/government/news/biometrics-commissioners-response-to-the-home-office-biometrics-strategy (last visited Aug. 15, 2018). [16] Supra note 2. [17] Supra note 13. [18] Jon Sharman, Metropolitan Police's facial recognition technology 98% inaccurate, figures show, INDEPENDENT, May 13, 2018, https://www.independent.co.uk/news/uk/home-news/met-police-facial-recognition-success-south-wales-trial-home-office-false-positive-a8345036.html (last visited Aug. 09, 2018).

Finland’s Technology Innovation System

I. Introduction   When, Finland, this country comes to our minds, it is quite easy for us to associate with the prestigious cell-phone company “NOKIA”, and its unbeatable high technology communication industry. However, following the change of entire cell-phone industry, the rise of smart phone not only has an influence upon people’s communication and interaction, but also makes Finland, once monopolized the whole cell-phone industry, feel the threat and challenge coming from other new competitors in the smart phone industry. However, even though Finland’s cell-phone industry has encountered frustrations in recent years in global markets, the Finland government still poured many funds into the area of technology and innovation, and brought up the birth of “Angry Birds”, one of the most popular smart phone games in the world. The Finland government still keeps the tradition to encourage R&D, and wishes Finland’s industries could re-gain new energy and power on technology innovation, and indirectly reach another new competitive level.   According to the Statistics Finland, 46% Finland’s enterprises took innovative actions upon product manufacturing and the process of R&D during 2008-2010; also, the promotion of those actions not merely existed in enterprises, but directly continued to the aspect of marketing and manufacturing. No matter on product manufacturing, the process of R&D, the pattern of organization or product marketing, we can observe that enterprises or organizations make contributions upon innovative activities in different levels or procedures. In the assignment of Finland’s R&D budgets in 2012, which amounted to 200 million Euros, universities were assigned by 58 million Euros and occupied 29% R&D budgets. The Finland Tekes was assigned by 55 million Euros, and roughly occupied 27.5% R&D budgets. The Academy of Finland (AOF) was assigned by 32 million Euros, and occupied 16% R&D budges. The government’s sectors were assigned by 3 million Euros, and occupied 15.2% R&D budgets. Other technology R&D expenses were 2.1 million Euros, and roughly occupied 10.5% R&D. The affiliated teaching hospitals in universities were assigned by 0.36 million Euros, and occupied 1.8% R&D budgets. In this way, observing the information above, concerning the promotion of technology, the Finland government not only puts more focus upon R&D innovation, but also pays much attention on education quality of universities, and subsidizes various R&D activities. As to the Finland government’s assignment of budges, it can be referred to the chart below.   As a result of the fact that Finland promotes industries’ innovative activities, it not only made Finland win the first position in “Growth Competitiveness Index” published by the World Economic Forum (WEF) during 2000-2006, but also located the fourth position in 142 national economy in “The Global Competitiveness Report” published by WEF, preceded only by Swiss, Singapore and Sweden, even though facing unstable global economic situations and the European debt crisis. Hence, observing the reasons why Finland’s industries have so strong innovative power, it seems to be related to the Finland’s national technology administrative system, and is worthy to be researched. II. The Recent Situation of Finland’s Technology Administrative System A. Preface   Finland’s administrative system is semi-presidentialism, and its executive power is shared by the president and the Prime Minister; as to its legislative power, is shared by the Congress and the president. The president is the Finland’s leader, and he/she is elected by the Electoral College, and the Prime Minister is elected by the Congress members, and then appointed by the president. To sum up, comparing to the power owned by the Prime Minister and the president in the Finland’s administrative system, the Prime Minister has more power upon executive power. So, actually, Finland can be said that it is a semi-predisnetialism country, but trends to a cabinet system.   Finland technology administrative system can be divided into four parts, and the main agency in each part, based upon its authority, coordinates and cooperates with making, subsidizing, executing of Finland’s technology policies. The first part is the policy-making, and it is composed of the Congress, the Cabinet and the Research and Innovation Council; the second part is policy management and supervision, and it is leaded by the Ministry of Education and Culture, the Ministry of Employment and the Economy, and other Ministries; the third part is science program management and subsidy, and it is composed of the Academy of Finland (AOF), the National Technology Agency (Tekes), and the Finnish National Fund Research and Development (SITRA); the fourth part is policy-executing, and it is composed of universities, polytechnics, public-owned research institutions, private enterprises, and private research institutions. Concerning the framework of Finland’s technology administrative, it can be referred to below. B. The Agency of Finland’s Technology Policy Making and Management (A) The Agency of Finland’s Technology Policy Making   Finland’s technology policies are mainly made by the cabinet, and it means that the cabinet has responsibilities for the master plan, coordinated operation and fund-assignment of national technology policies. The cabinet has two councils, and those are the Economic Council and the Research and Innovation Council, and both of them are chaired by the Prime Minister. The Research and Innovation Council is reshuffled by the Science and Technology Policy Council (STPC) in 1978, and it changed name to the Research and Innovation Council in Jan. 2009. The major duties of the Research and Innovation Council include the assessment of country’s development, deals with the affairs regarding science, technology, innovative policy, human resource, and provides the government with aforementioned schedules and plans, deals with fund-assignment concerning public research development and innovative research, coordinates with all government’s activities upon the area of science, technology, and innovative policy, and executes the government’s other missions.   The Research and Innovation Council is an integration unit for Finland’s national technology policies, and it originally is a consulting agency between the cabinet and Ministries. However, in the actual operation, its scope of authority has already covered coordination function, and turns to direct to make all kinds of policies related to national science technology development. In addition, the consulting suggestions related to national scientific development policies made by the Research and Innovation Council for the cabinet and the heads of Ministries, the conclusion has to be made as a “Key Policy Report” in every three year. The Report has included “Science, Technology, Innovation” in 2006, “Review 2008” in 2008, and the newest “Research and Innovation Policy Guidelines for 2011-2015” in 2010.   Regarding the formation and duration of the Research and Innovation Council, its duration follows the government term. As for its formation, the Prime Minister is a chairman of the Research and Innovation Council, and the membership consists of the Minister of Education and Science, the Minister of Economy, the Minister of Finance and a maximum of six other ministers appointed by the Government. In addition to the Ministerial members, the Council shall comprise ten other members appointed by the Government for the parliamentary term. The Members must comprehensively represent expertise in research and innovation. The structure of Council includes the Council Secretariat, the Administrative Assistant, the Science and Education Subcommittee, and the Technology and Innovation Subcommittee. The Council has the Science and Education Subcommittee and the Technology and Innovation Subcommittee with preparatory tasks. There are chaired by the Ministry of Education and Science and by the Minister of Economy, respectively. The Council’s Secretariat consists of one full-time Secretary General and two full-time Chief Planning Officers. The clerical tasks are taken care of at the Ministry of Education and Culture. (B) The Agency of Finland’s Technology Policy Management   The Ministries mainly take the responsibility for Finland’s technology policy management, which includes the Ministry of Education and Culture, the Ministry of Employment and Economy, the Ministry of Social Affairs and Health, the Ministry of Agriculture and Forestry, the Ministry of Defense, the Ministry of Transport and Communication, the Ministry of Environment, the Ministry of Financial, and the Ministry of Justice. In the aforementioned Ministries, the Ministry of Education and Culture and the Ministry of Employment and Economy are mainly responsible for Finland national scientific technology development, and take charge of national scientific policy and national technical policy, respectively. The goal of national scientific policy is to promote fundamental scientific research and to build up related scientific infrastructures; at the same time, the authority of the Ministry of Education and Culture covers education and training, research infrastructures, fundamental research, applied research, technology development, and commercialization. The main direction of Finland’s national scientific policy is to make sure that scientific technology and innovative activities can be motivated aggressively in universities, and its objects are, first, to raise research funds and maintain research development in a specific ratio; second, to make sure that no matter on R&D institutions or R&D training, it will reach fundamental level upon funding or environment; third, to provide a research network for Finland, European Union and global research; fourth, to support the research related to industries or services based upon knowledge-innovation; fifth, to strengthen the cooperation between research initiators and users, and spread R&D results to find out the values of commercialization, and then create a new technology industry; sixth, to analyze the performance of national R&D system.   As for the Ministry of Employment and Economy, its major duties not only include labor, energy, regional development, marketing and consumer policy, but also takes responsibilities for Finland’s industry and technical policies, and provides industries and enterprises with a well development environment upon technology R&D. The business scope of the Ministry of Employment and Economy puts more focus on actual application of R&D results, it covers applied research of scientific technology, technology development, commercialization, and so on. The direction of Finland’s national technology policy is to strengthen the ability and creativity of industries’ technology development, and its objects are, first, to develop the new horizons of knowledge with national innovation system, and to provide knowledge-oriented products and services; second, to promote the efficiency of the government R&D funds; third, to provide cross-country R&D research networks, and support the priorities of technology policy by strengthening bilateral or multilateral cooperation; fourth, to raise and to broaden the efficiency of research discovery; fifth, to promote the regional development by technology; sixth, to evaluate the performance of technology policy; seventh, to increase the influence of R&D on technological change, innovation and society; eighth, to make sure that technology fundamental structure, national quality policy and technology safety system will be up to international standards. (C) The Agency of Finland’s Technology Policy Management and Subsidy   As to the agency of Finland’s technology policy management and subsidy, it is composed of the Academy of Finland (AOF), the National Technology Agency (Tekes), and the Finnish National Fund Research and Development (SITRA). The fund of AOF comes from the Ministry of Education and Culture; the fund of Tekes comes from the Ministry of Employment and Economy, and the fund of SITRA comes from independent public fund supervised by the Finland’s Congress. (D) The Agency of Finland’s Technology Plan Execution   As to the agency of Finland’s technology plan execution, it mainly belongs to the universities under Ministries, polytechnics, national technology research institutions, and other related research institutions. Under the Ministry of Education and Culture, the technology plans are executed by 16 universities, 25 polytechnics, and the Research Institute for the Language of Finland; under the Ministry of Employment and Economy, the technology plans are executed by the Technical Research Centre of Finland (VTT), the Geological Survey of Finnish, the National Consumer Research Centre; under the Ministry of Social Affairs and Health, the technology plans are executed by the National Institute for Health and Welfare, the Finnish Institute of Occupational Health, and University Central Hospitals; under the Ministry of Agriculture and Forestry, the technology plans are executed by the Finnish Forest Research Institute (Metla), the Finnish Geodetic Institute, and the Finnish Game and Fisheries Research Institute (RKTL); under the Ministry of Defense, the technology plans are executed by the Finnish Defense Forces’ Technical Research Centre (Pvtt); under the Ministry of Transport and Communications, the technology plans are executed by the Finnish Meteorological Institute; under the Ministry of Environment, the technology plans are executed by the Finnish Environment Institute (SYKE); under the Ministry of Financial, the technology plans are executed by the Government Institute for Economic Research (VATT). At last, under the Ministry of Justice, the technology plans are executed by the National Research Institute of Legal Policy.

Strengthening Taiwan’s Pharmaceutical Resilience: Legal Reflections from the European Union’s Critical Medicines Act

Strengthening Taiwan’s Pharmaceutical Resilience: Legal Reflections from the European Union’s Critical Medicines Act 2025/11/15 Introduction: From Vulnerability to Vision For Taiwan, an island state positioned at the crossroads of geopolitical tension and globalized medical trade, the question of pharmaceutical resilience is no longer a technical concern but a constitutional one. A nation’s ability to secure the continuous availability of essential medicines defines not only its public health capacity but the very credibility of its governance. In this light, the European Union’s (hereunder, the “EU”) proposed Critical Medicines Act (hereunder, “EU CMA”) offers Taiwan an illuminating case of how law can move beyond crisis management toward systemic foresight[1]. Resilience in the pharmaceutical sector is not merely about supply stability; it embodies a triple constitutional function—protecting life and health as fundamental rights, safeguarding national security through stable access to critical goods, and reinforcing trust in regulatory governance. Law thus becomes the medium through which uncertainty is rendered governable. The global pandemic revealed that the absence of legal foresight can paralyze even the most advanced health systems, exposing the structural fragility behind administrative efficiency. While Taiwan’s current pharmaceutical regulatory framework remains largely event-driven, reactive, and post-facto, the EU CMA exemplifies an industry-oriented, anticipatory, and pre-emptive model. The contrast underscores a jurisprudential lesson: resilience cannot be legislated through emergency decrees alone; it must be architected through a continuous, legally structured process that anticipates vulnerabilities before they materialize. This article identifies three foundational principles embedded in the EU CMA—visibility, diversification, and agility—and explores how these principles could guide Taiwan in constructing a forward-looking pharmaceutical resilience regime. The goal is not imitation, but inspiration—extracting from the EU experience a conceptual framework for a resilient Taiwanese pharmaceutical order. The EU CMA as a Law of Foresight The EU CMA represents a paradigm shift in pharmaceutical governance. Instead of fragmented national reactions to shortages, the Act establishes a Union-wide framework “to strengthen the availability and security of supply of critical medicinal products” through coordinated information systems, joint vulnerability assessments, and strategic industrial actions[2]. Its architecture reflects a policy-cycle logic: identification of critical medicines (Union list), assessment of vulnerabilities (harmonized monitoring), and action to strengthen capacity (strategic projects, coordinated procurement). Each stage is legally codified and procedurally transparent. The EU CMA thus transforms resilience from a policy aspiration into a governance architecture mandated by law. This approach reveals a fundamental evolution in regulatory philosophy: from law as reaction to law as anticipation. The EU does not merely respond to pharmaceutical disruptions; it legislates the ability to foresee them. This transformation elevates resilience from a managerial tool to a juridical principle that guides administrative behavior and industrial coordination. In this sense, the EU CMA operates as a constitutional statute of preparedness—one that embeds strategic vigilance within the ordinary operations of the market. Moreover, the Act’s systemic design demonstrates a rare synthesis of industrial, health, and competition policies under a unified legal grammar. By integrating economic instruments (such as incentives for local production) with public health imperatives (such as the availability of essential drugs), the EU CMA transforms siloed policy domains into a coherent resilience regime. It institutionalizes coordination not as an afterthought but as a binding legal discipline. Crucially, the EU’s approach embodies what might be called the legality of anticipation: law as an instrument that compels foresight. Resilience here is treated as a public good, transcending national borders but rooted in legal coordination. For Taiwan—whose pharmaceutical imports are geographically concentrated and whose market size limits domestic leverage—the lesson is profound: foresight must be institutional, not intuitive. Visibility: Law as an Instrument of Anticipation At the heart of the EU CMA lies the principle of visibility—the legalization of information as a tool of preparedness. The Act mandates the creation of a Union list of critical medicines[3] and a continuous monitoring system for supply vulnerabilities, coordinated through the Critical Medicines Coordination Group[4]. By institutionalizing information flows, the EU transforms data into a public good and transparency into an act of resilience. Visibility performs a dual function. On one hand, it is technocratic, enabling states to detect early signals of supply risk. On the other, it is constitutional, embedding accountability within knowledge. Uncertainty, when unregulated, leads to discretion; when structured, it becomes a risk, which law can govern. The EU CMA thus converts chaos into cognition—an epistemic transformation at the heart of modern administrative law. For Taiwan, this implies a shift from episodic crisis reporting toward permanent, cross-sectoral data governance. Information duties should not be seen as bureaucratic burdens but as civic infrastructures that permit collective foresight. Visibility, therefore, is not simply about surveillance but about legally enabling knowledge—the first step toward prevention rather than post-hoc management. Diversification: Embedding Resilience into Market Rationality The second principle, diversification, redefines efficiency itself. The EU CMA promotes manufacturing capacity within Europe under the doctrine of “open strategic autonomy”[5]. It supports Strategic Projects that enhance production, encourages cooperation with like-minded countries, and authorizes procurement methods that reward resilience factors alongside price—what EU law calls “MEAT” (Most Economically Advantageous Tender)[6]. This reframes the very idea of market rationality: security and competition are not opposites but complements. Law functions here as a corrective to market myopia, ensuring that the invisible hand does not ignore visible fragility. By quantifying resilience as a measurable value, the EU transforms precaution into an economic variable. For Taiwan—whose procurement and reimbursement systems have historically emphasized price containment—this perspective opens conceptual space. Resilience should not be perceived as inefficiency, but as intertemporal justice: a society’s investment in its future continuity. A diversified system—of suppliers, regions, and regulatory instruments—creates not redundancy but adaptability. In this sense, diversification is law’s expression of prudence in an interconnected economy. Agility: From Administrative Response to Legal Readiness The third principle, agility, captures the law’s capacity to act swiftly yet lawfully. The EU CMA institutionalizes flexibility through accelerated procedures for strategic projects, coordinated procurement frameworks, and crisis response mechanisms[7]. These powers are accompanied by procedural safeguards and sunset clauses, ensuring proportionality and reversibility. Agility thus represents legality in motion: action without arbitrariness. It reconciles speed with scrutiny by embedding emergency measures within predefined legal channels. The lesson for Taiwan is both institutional and philosophical—true readiness is not improvisation, but preparation that preserves legitimacy. In Taiwan’s current system, regulatory energy peaks during emergencies and dissipates thereafter. A mature resilience framework would instead cultivate continuous readiness—administrative structures that learn, anticipate, and adapt. Agility, understood legally, means codifying responsiveness as a standing competence of governance. It is the hinge connecting foresight and execution, legality and flexibility. Taiwan’s Legal Trajectory: From Event-Driven to Industry-Oriented Regulation Comparatively, Taiwan’s Pharmaceutical Affairs Act—even with its proposed amendments—remains largely event-driven and post-crisis in design[8]. Regulatory intervention often follows episodes of shortage or disruption. While recently introduced draft revisions strengthening supply chain obligations[9], these proposed revisions still operate primarily within a reactive paradigm. By contrast, the EU CMA envisions an industry-oriented, anticipatory, and system-based model. It embeds resilience into the legal DNA of pharmaceutical policy—linking regulation, industrial strategy, and public health. For Taiwan, this means evolving from regulatory firefighting to regulatory design: from curing failures to cultivating foresight. To achieve this, Taiwan’s legal development must transcend compliance formalism and embrace a culture of legal learning—where rules are not static commands but adaptive instruments of governance. The transition from event-driven to foresight-driven lawmaking will not only strengthen national health security but also elevate Taiwan’s position in the network of like-minded economies pursuing resilient supply systems. Conclusion: Toward a Resilient Legal Modernity The EU Critical Medicines Act demonstrates that law can be an architecture of anticipation. Its three pillars—visibility, diversification, and agility—form a grammar of resilience that integrates market mechanisms, administrative capacity, and democratic legitimacy. For Taiwan, the value of this model lies not in replication but in reflection. Visibility teaches that knowledge must be institutionalized. Diversification reminds us that resilience can coexist with efficiency. Agility shows that speed and legality are not mutually exclusive. Together, they suggest a new philosophy of governance: one that replaces reaction with design, and uncertainty with structured foresight. Yet the deeper lesson of the EU CMA is that resilience is not simply a functional attribute of a regulatory system—it is a constitutional virtue of modern states. To build resilience is to affirm the social contract anew: to promise citizens not that crises will never occur, but that when they do, institutions will stand ready, transparent, and just. This transforms law from a mirror of disorder into an instrument of collective composure. For Taiwan, embracing resilience as a constitutional principle means reimagining the relationship between law, science, and sovereignty. In a world where disruption is perpetual—whether by pandemics, trade shocks, or technological change—resilience becomes the language through which legality and modernity converge. It marks the transition from governing by reaction to governing by imagination. While the EU CMA relies on the Union’s vast market power to incentivize and coordinate pharmaceutical resilience, Taiwan faces a distinct structural challenge: its market size, though dynamic, cannot generate comparable leverage on a global scale. This asymmetry compels Taiwan to craft a dual strategy—anchoring its domestic resilience through legal foresight, while simultaneously aligning with international frameworks that promote secure and diversified supply chains. How Taiwan can reconcile these two imperatives—maintaining openness and integration with global partners, yet safeguarding autonomous resilience at home—will define the next frontier of its pharmaceutical governance. It is within this strategic and normative intersection that the Institute for Information Industry’s Science and Technology Law Institute (STLI) will continue its research efforts, exploring legal architectures capable of linking Taiwan’s national resilience with the broader ecosystem of global health security. Ultimately, resilience is not merely a regulatory principle but a moral commitment to time—a covenant between generations that law will foresee, prepare, and preserve. As Taiwan refines its pharmaceutical governance, the lesson from the EU CMA is both institutional and existential: to govern resilience is to govern the future itself, and to govern the future is to affirm the dignity of foresight as the highest form of rule of law. [1] EUROPEAN COMMISSION, Proposal for a Regulation of the European Parliament and of the Council laying down a framework for strengthening the availability and security of supply of critical medicinal products as well as for improving the availability of, and access to, medicinal products of common interest (Critical Medicines Act), COM(2025) 102 final (Mar. 11, 2025), https://health.ec.europa.eu/document/download/2abe4fc8-059e-47d9-a20a-d9e3bfc5dc2c_en?filename=mp_com2025_102_act_en.pdf (last visited Nov. 2, 2025). [2] id. at Page 17. [3] id. at Page 27. [4] id. at Page 35. [5] CRITICAL MEDICINES ALLIANCE, STRATEGIC REPORT OF THE CRITICAL MEDICINES ALLIANCE (Feb. 28, 2025), https://health.ec.europa.eu/document/download/3da9dfc0-c5e0-4583-a0f1-1652c7c18c3c_en?filename=hera_cma_strat-report_en.pdf (last visited Nov. 2, 2025). [6] EUROPEAN COMMISSION, Proposal for a Regulation of the European Parliament and of the Council laying down a framework for strengthening the availability and security of supply of critical medicinal products as well as for improving the availability of, and access to, medicinal products of common interest (Critical Medicines Act), COM(2025) 102 final (Mar. 11, 2025), https://health.ec.europa.eu/document/download/2abe4fc8-059e-47d9-a20a-d9e3bfc5dc2c_en?filename=mp_com2025_102_act_en.pdf (last visited Nov. 2, 2025). [7] id. at Page 7. [8] Pharmaceutical Affairs Act (Taiwan), Ministry of Justice, https://law.moj.gov.tw/ENG/LawClass/LawAll.aspx?pcode=L0030001 (last visited Nov. 2, 2025). [9] 〈衛生福利部公告「藥事法」部分條文修正草案〉,法源法律網,https://www.lawbank.com.tw/news/NewsContent.aspx?NID=206187.00(最後瀏覽日:2025/11/03)。

The Institutionalization of the Taiwan Personal Data Protection Committee - Triumph of Digital Constitutionalism: A Legal Positivism Analysis

The Institutionalization of the Taiwan Personal Data Protection Committee - Triumph of Digital Constitutionalism: A Legal Positivism Analysis 2023/07/13 The Legislative Yuan recently passed an amendment to the Taiwan Personal Data Protection Act, which resulted in the institutionalization of the Taiwan Personal Data Protection Commission (hereunder the “PDPC”)[1]. This article aims to analyze the significance of this institutionalization from three different perspectives: legal positivism, digital constitutionalism, and Millian liberalism. By examining these frameworks, we can better understand the constitutional essence of sovereignty, the power dynamics among individuals, businesses, and governments, and the paradox of freedom that the PDPC addresses through governance and trust. I.Three Layers of Significance 1.Legal Positivism The institutionalization of the PDPC fully demonstrates the constitutional essence of sovereignty in the hands of citizens. Legal positivism emphasizes the importance of recognizing and obeying (the sovereign, of which it is obeyed by all but does not itself obey to anyone else, as Austin claims) laws that are enacted by legitimate authorities[2]. In this context, the institutionalization of the PDPC signifies the recognition of citizens' rights to control their personal data and the acknowledgment of the sovereign in protecting their privacy. It underscores the idea that the power to govern personal data rests with the individuals themselves, reinforcing the principles of legal positivism regarding sovereign Moreover, legal positivism recognizes the authority of the state in creating and enforcing laws. The institutionalization of the PDPC as a specialized commission with the power to regulate and enforce personal data protection laws represents the state's recognition of the need to address the challenges posed by the digital age. By investing the PDPC with the authority to oversee the proper handling and use of personal data, the state acknowledges its responsibility to protect the rights and interests of its citizens. 2.Digital Constitutionalism The institutionalization of the PDPC also rebalances the power structure among individuals, businesses, and governments in the digital realm[3]. Digital constitutionalism refers to the principles and norms that govern the relationship between individuals and the digital sphere, ensuring the protection of rights and liberties[4]. With the rise of technology and the increasing collection and use of personal data, individuals often find themselves at a disadvantage compared to powerful entities such as corporations and governments[5]. However, the PDPC acts as a regulatory body that safeguards individuals' interests, rectifying the power imbalances and promoting digital constitutionalism. By establishing clear rules and regulations regarding the collection, use, and transfer of personal data, the PDPC may set a framework that ensures the protection of individuals' privacy and data rights. It may enforce accountability among businesses and governments, holding them responsible for their data practices and creating a level playing field where individuals have a say in how their personal data is handled. 3.Millian Liberalism The need for the institutionalization of the PDPC embodies the paradox of freedom, as raised in John Stuart Mill’s “On Liberty”[6], where Mill recognizes that absolute freedom can lead to the infringement of others' rights and well-being. In this context, the institutionalization of the PDPC acknowledges the necessity of governance to mitigate the risks associated with personal data protection. In the digital age, the vast amount of personal data collected and processed by various entities raises concerns about privacy, security, and potential misuse. The institutionalization of the PDPC represents a commitment to address these concerns through responsible governance. By setting up rules, regulations, and enforcement mechanisms, the PDPC ensures that individuals' freedoms are preserved without compromising the rights and privacy of others. It strikes a delicate balance between individual autonomy and the broader social interest, shedding light on the paradox of freedom. II.Legal Positivism: Function and Authority of the PDPC 1.John Austin's Concept of Legal Positivism: Sovereignty, Punishment, Order To understand the function and authority of the PDPC, we turn to John Austin's concept of legal positivism. Austin posited that laws are commands issued by a sovereign authority and backed by sanctions[7]. Sovereignty entails the power to make and enforce laws within a given jurisdiction. In the case of the PDPC, its institutionalization by the Legislative Yuan reflects the recognition of its authority to create and enforce regulations concerning personal data protection. The PDPC, as an independent and specialized committee, possesses the necessary jurisdiction and competence to ensure compliance with the law, administer punishments for violations, and maintain order in the realm of personal data protection. 2.Dire Need for the Institutionalization of the PDPC There has been a dire need for the establishment of the PDPC following the Constitutional Court's decision in August 2022, holding that the government needed to establish a specific agency in charge of personal data-related issues[8]. This need reflects John Austin's concept of legal positivism, as it highlights the demand for a legitimate and authoritative body to regulate and oversee personal data protection. The PDPC's institutionalization serves as a response to the growing concerns surrounding data privacy, security breaches, and the increasing reliance on digital platforms. It signifies the de facto recognition of the need for a dedicated institution to safeguard the individual’s personal data rights, reinforcing the principles of legal positivism. Furthermore, the institutionalization of the PDPC demonstrates the responsiveness of the legislative branch to the evolving challenges posed by the digital age. The amendment to the Taiwan Personal Data Protection Act and the subsequent institutionalization of the PDPC are the outcomes of a democratic process, reflecting the will of the people and their desire for enhanced data protection measures. It signifies a commitment to uphold the rule of law and ensure the protection of citizens' rights in the face of emerging technologies and their impact on privacy. 3.Authority to Define Cross-Border Transfer of Personal Data Upon the establishment of the PDPC, it's authority to define what constitutes a cross-border transfer of personal data under Article 21 of the Personal Data Protection Act will then align with John Austin's theory on order. According to Austin, laws bring about order by regulating behavior and ensuring predictability in society. By granting the PDPC the power to determine cross-border data transfers, the legal framework brings clarity and consistency to the process. This promotes order by establishing clear guidelines and standards, reducing uncertainty, and enhancing the protection of personal data in the context of international data transfers. The PDPC's authority in this regard reflects the recognition of the need to regulate and monitor the cross-border transfer of personal data to protect individuals' privacy and prevent unauthorized use or abuse of their information. It ensures that the transfer of personal data across borders adheres to legal and ethical standards, contributing to the institutionalization of a comprehensive framework for cross-border data transfer. III.Conclusion In conclusion, the institutionalization of the Taiwan Personal Data Protection Committee represents the convergence of legal positivism, digital constitutionalism, and Millian liberalism. It signifies the recognition of citizens' sovereignty over their personal data, rebalances power dynamics in the digital realm, and addresses the paradox of freedom through responsible governance. By analyzing the PDPC's function and authority in the context of legal positivism, we understand its role as a regulatory body to maintain order and uphold the principles of legal positivism. The institutionalization of the PDPC serves as a milestone in Taiwan's commitment to protect individuals' personal data and safeguard the digital rights. In essence, the institutionalization of the Taiwan Personal Data Protection Committee represents a triumph of digital constitutionalism, where individuals' rights and interests are safeguarded, and power imbalances are rectified. It also embodies the recognition of the paradox of freedom and the need for responsible governance in the digital age in Taiwan. Reference: [1] Lin Ching-yin & Evelyn Yang, Bill to establish data protection agency clears legislative floor, CNA English News, FOCUS TAIWAN, May 16, 2023, https://focustaiwan.tw/society/202305160014 (last visited, July 13, 2023). [2] Legal positivism, Stanford Encyclopedia of Philosophy, https://plato.stanford.edu/entries/legal-positivism/?utm_source=fbia (last visited July 13, 2023). [3] Edoardo Celeste, Digital constitutionalism: how fundamental rights are turning digital, (2023): 13-36, https://doras.dcu.ie/28151/1/2023_Celeste_DIGITAL%20CONSTITUTIONALISM_%20HOW%20FUNDAMENTAL%20RIGHTS%20ARE%20TURNING%20DIGITAL.pdf (last visited July 3, 2023). [4] GIOVANNI DE GREGORIO, DIGITAL CONSTITUTIONALISM IN EUROPE: REFRAMING RIGHTS AND POWERS IN THE ALGORITHMIC SOCIETY 218 (2022). [5] Celeste Edoardo, Digital constitutionalism: how fundamental rights are turning digital (2023), https://doras.dcu.ie/28151/1/2023_Celeste_DIGITAL%20CONSTITUTIONALISM_%20HOW%20FUNDAMENTAL%20RIGHTS%20ARE%20TURNING%20DIGITAL.pdf (last visited July 13, 2023). [6]JOHN STUART MILL,On Liberty (1859), https://openlibrary-repo.ecampusontario.ca/jspui/bitstream/123456789/1310/1/On-Liberty-1645644599.pdf (last visited July 13, 2023). [7] Legal positivism, Stanford Encyclopedia of Philosophy, https://plato.stanford.edu/entries/legal-positivism/?utm_source=fbia (last visited July 13, 2023). [8] Lin Ching-yin & Evelyn Yang, Bill to establish data protection agency clears legislative floor, CNA English News, FOCUS TAIWAN, May 16, 2023, https://focustaiwan.tw/society/202305160014 (last visited, July 13, 2023).

TOP