▸case-01 We are designing the checkout and registration flow for a Taipei-based online store on Cyberbiz. To maximize conversion, the product team wants a single mandatory checkbox at signup stating 'I agree to the Terms of Service and Privacy Policy, and consent to receiving promotional SMS and email newsletters.' Evaluate this proposal under Taiwan Personal Data Protection Act (PDPA) rules and specify how marketing consent must be presented. | pass→pass | 50,561 | 50,871 | +1% | 1 | 1 | 0% | 2,876 | 3,160 | +10% | 0 | 0 | — |
▸case-02 A Taiwanese e-commerce brand is drafting its online registration privacy notice to satisfy Article 8 of Taiwan's Personal Data Protection Act (PDPA). List the statutory items that must be explicitly communicated to the individual before or at the time of collecting their personal data. | pass→pass | 17,672 | 11,633 | -34% | 1 | 1 | 0% | 2,581 | 2,283 | -12% | 0 | 0 | — |
▸case-03 An online retailer targeting shoppers in Taiwan plans to deploy a cookie banner that pre-checks 'Analytics' and 'Marketing' cookies, placing the burden on visitors to untick them in settings. Assess whether pre-checked non-essential cookie categories comply with Taiwan privacy standards and detail the required user interaction mechanism. | pass→pass | 16,287 | 46,966 | +188% | 1 | 1 | 0% | 2,458 | 2,955 | +20% | 0 | 0 | — |
▸case-04 A customer of a Taiwan e-commerce store submits a Data Subject Access Request (DSAR) demanding immediate total deletion of all their personal data, including historical invoice and transaction records from 6 months ago. The store owner wants to erase everything immediately to avoid privacy disputes. Explain how the store should handle transaction data retention under the Taiwan Personal Data Protection Act in conjunction with the Commercial Accounting Act. | pass→pass | 46,656 | 48,730 | +4% | 1 | 1 | 0% | 2,423 | 3,292 | +36% | 0 | 0 | — |
▸case-05 A customer submits a request to inspect and receive a copy of their personal profile and order history under Article 3 of Taiwan's Personal Data Protection Act. What is the maximum statutory timeframe allowed for the merchant to make a decision and respond to this request? | pass→pass | 26,407 | 9,947 | -62% | 1 | 1 | 0% | 1,006 | 1,638 | +63% | 0 | 0 | — |
▸case-06 A Taiwan e-commerce platform migrates its production database containing Taiwanese customer PII (names, phone numbers, addresses) to an AWS US-East (N. Virginia) region. The engineering team argues that since AWS is a global cloud provider, no specific regulatory compliance assessment or user notification is needed. Evaluate this claim under Article 21 of Taiwan's Personal Data Protection Act. | pass→pass | 23,026 | 23,587 | +2% | 1 | 1 | 0% | 3,039 | 4,169 | +37% | 0 | 0 | — |
▸case-07 To enable seamless 1-click reordering, a Taiwanese fashion e-commerce site plans to save full credit card numbers, expiration dates, and 3-digit CVV/CVC security codes directly in its PostgreSQL database. Assess the legality and security compliance of storing raw CVV codes under payment card standards and Taiwan PDPA. | pass→pass | 26,144 | 20,299 | -22% | 1 | 1 | 0% | 3,480 | 3,719 | +7% | 0 | 0 | — |
▸case-08 A Taiwanese online shop embeds Facebook Pixel, Google Tag Manager, and TikTok Pixel across its store. During checkout, these scripts extract customer phone numbers and email addresses directly from form fields. What technical controls must be implemented to prevent unauthorized PII exposure to third-party scripts? | fail→pass | 20,269 | 19,017 | -6% | 1 | 1 | 0% | 3,065 | 3,594 | +17% | 0 | 0 | — |
▸case-09 A Taiwan e-commerce company allows customer service agents and software engineers to query full customer database records without audit logging. During an internal audit, the security lead suggests access logs are optional for internal staff. Explain the requirement for access logging under Taiwan PDPA security measures. | pass→pass | 15,001 | 17,581 | +17% | 1 | 1 | 0% | 2,473 | 3,014 | +22% | 0 | 0 | — |
▸case-10 A Taiwanese e-commerce company suffers an SQL injection breach compromising 50,000 customer order records. The management team wants to delay notifying regulators and affected customers until an internal investigation concludes 30 days later. Evaluate this delay against Taiwan's data breach notification requirements. | pass→pass | 17,908 | 17,860 | -0% | 1 | 1 | 0% | 2,429 | 3,313 | +36% | 0 | 0 | — |
▸case-11 When collecting customer shipping addresses to hand over to local delivery providers (like Black Cat / Kerry TJ) in Taiwan, how must the e-commerce store categorize the legal purpose under the Ministry of Justice Specific Purpose Codes (特定目的)? | pass→pass | 15,429 | 16,021 | +4% | 1 | 1 | 0% | 2,476 | 2,928 | +18% | 0 | 0 | — |
▸case-12 An online store in Taiwan sends promotional SMS messages to customers who made a purchase last month. The SMS message contains no instructions or link for opting out. When a customer calls to complain, the support team tells them opting out is not supported. How does this violate Taiwan PDPA Article 20? | pass→pass | 10,734 | 15,424 | +44% | 1 | 1 | 0% | 1,835 | 2,368 | +29% | 0 | 0 | — |
▸case-13 A Taiwan e-commerce database contains order records that are 8 years old. The tax audit period (7 years) and commercial accounting retention requirement (5 years) have both expired, and there are no active legal disputes. What action must the e-commerce operator take regarding these records under Article 11 of Taiwan's Personal Data Protection Act? | pass→pass | 8,437 | 10,552 | +25% | 1 | 1 | 0% | 1,398 | 2,062 | +47% | 0 | 0 | — |
▸case-14 A Taiwan group-buying platform receives customer delivery details indirectly from corporate partners who run promotional campaigns. Under Article 9 of Taiwan's Personal Data Protection Act, what notification obligations apply before processing this indirectly collected PII? | pass→pass | 10,849 | 14,441 | +33% | 1 | 1 | 0% | 1,875 | 2,818 | +50% | 0 | 0 | — |
▸case-15 When designing a GDPR and Taiwan PDPA compliant cookie management modal for an e-commerce platform, how should cookie categories be structured to ensure valid consent? | pass→pass | 19,215 | 19,108 | -1% | 1 | 1 | 0% | 3,117 | 3,377 | +8% | 0 | 0 | — |
▸case-16 A user emails a Taiwan online store requesting a complete digital copy of all their personal data records. What identity verification procedure and cost assessment rules apply under Taiwan PDPA Article 3 and Article 14? | pass→pass | 15,120 | 19,406 | +28% | 1 | 1 | 0% | 2,395 | 3,427 | +43% | 0 | 0 | — |
▸case-17 An e-commerce backend system stores both customer order histories and internal employee HR records (national ID, emergency contact, salary). Describe the operational separation and access control restrictions required under security maintenance regulations of Taiwan PDPA. | pass→pass | 16,912 | 22,907 | +35% | 1 | 1 | 0% | 2,707 | 3,858 | +43% | 0 | 0 | — |
▸case-18 A Taiwan e-commerce company chooses Google Cloud Platform (GCP) Singapore region to host its primary customer database. What explicit disclosure must be included in the user-facing agreement to meet Taiwan legal requirements for cross-border data processing? | pass→pass | 13,704 | 14,140 | +3% | 1 | 1 | 0% | 2,211 | 2,540 | +15% | 0 | 0 | — |
▸case-19 A customer who actively uses a Taiwan online shopping app requests that the platform stop using their purchase history for personalized product recommendation algorithms, while keeping their account active for purchases. Can the store refuse this request under Taiwan PDPA? | pass→pass | 14,022 | 11,753 | -16% | 1 | 1 | 0% | 2,284 | 2,093 | -8% | 0 | 0 | — |
▸case-20 A Taiwan e-commerce merchant contracts a third-party SaaS vendor for AI customer service chatbots and passes customer conversation histories and contact details to the vendor. What oversight obligations must the merchant fulfill under Article 8 of Taiwan PDPA Enforcement Rules (施行細則 §8)? | pass→pass | 12,823 | 19,962 | +56% | 1 | 1 | 0% | 2,121 | 2,947 | +39% | 0 | 0 | — |
▸case-21 A Berlin-based fashion brand operating strictly within Germany asks its legal team to prepare a Record of Processing Activities (ROPA) under Article 30 of the EU General Data Protection Regulation (GDPR). Provide the mandatory structural requirements for an EU GDPR Article 30 controller record. | fail→fail | 15,712 | 23,253 | +48% | 1 | 1 | 0% | 2,638 | 2,478 | -6% | 0 | 0 | — |
▸case-22 A Taiwanese e-commerce team is setting up automated tagging and broadcast messaging triggers inside the LINE Official Account Manager backend for a promotional coupon campaign. Explain how to configure user tags and rich menus in the LINE OA platform. | pass→pass | 20,810 | 23,985 | +15% | 1 | 1 | 0% | 3,201 | 4,343 | +36% | 0 | 0 | — |
▸case-23 A customer purchases a pair of shoes from a Taiwanese online retailer, receives the item, and requests an unconditional refund on day 5 under Article 19 of Taiwan's Consumer Protection Act (消費者保護法). The merchant claims that because the customer signed the terms of service agreeing to 'all sales are final', no return is allowed. Evaluate the merchant's claim under Taiwan Consumer Protection Act. | pass→pass | 13,836 | 14,270 | +3% | 1 | 1 | 0% | 2,336 | 2,599 | +11% | 0 | 0 | — |