E-Commerce PDPA Compliance
STATUS: SKELETON — body pending.
When to use this skill
- Designing member signup consent for a TW store
- Building cookie-consent banner for TW traffic
- Responding to DSAR (resident data subject access request)
- Designing data-retention policy for order / payment data
- Cross-border transfer (TW → AWS US / GCP APAC)
Do NOT use when
- Generic PDPA / GDPR concepts →
law-gdpr-pdpa - Marketing consent for LINE OA →
tw-ecom-operations-line-oa
Core concepts
TODO: 個資法 §5 specific-purpose principle, 第八條 告知義務, 蒐集 vs 處理 vs 利用 split.
Decision tree
TODO: data flow → consent form design.
Implementation guidance
TODO: consent form template, DSAR SOP, retention schedule, cross-border transfer assessment.
Gotchas
TODO: 5-6 pitfalls (opt-in vs opt-out confusion, third-party embed leakage, employee access logging, data-breach 72hr notification).
IRON LAW
TODO.
Output Format
TODO.
Related
law-gdpr-pdpatw-ecom-operations-line-oa
Last verified: 2026-04