National Chengchi University
Uedu Main Site
Explore Uedu
Student Console
Register as Member/Login
Research Informed Consent Center
Survey Center
Teacher Console
Course Setup
Support & Messages
Uptime Data

UeduGPTs

--

Jupyters

6

Local AI

--

Uedu Code

--

CISOSE26 Local AI Uedu Code UG26
政治大學 AQI 56 26°C PM2.5 11
AI Reply Desktop Notifications

Show a desktop notification when the AI TA finishes replying

Chat Message Notifications

Notify me when classmates post messages in the forum

Sound notification

Play an alert sound whenever there is a new notification

Cross-Jurisdiction · Cross-Jurisdiction Compliance Matrix

跨法域合規對照表

This document presents, in a single-page matrix, the Uedu platform's governance approach for six major jurisdictions, including Taiwan PDPA, EU GDPR + Swiss nFADP, Singapore PDPA, Japan APPI, Korea PIPA and UK GDPR. For detailed explanations by jurisdiction, please see the corresponding Jurisdiction Notes.

Document Versionv1.0
Effective Date2026-04-10
Last Updated2026-09-14
Published Online2026-05-12
Legal Review StatusSelf-authored; partner-side review invited
LanguageTraditional Chinese (legal baseline version)
Self-authored disclosure. This comparison table is a self-disclosure of Uedu’s governance position, not reviewed by external lawyers; its purpose is to provide partner institutions with a starting point for their own legal assessment. The citations of individual legal provisions, summaries of requirements, and descriptions of corresponding practices in this document are intended to disclose Uedu’s governance position, not a legal opinion, and do not constitute an assertion of legal compliance. This platform uses the wording “designed in alignment with” rather than the categorical legal claim “compliant with”.

1. Scope and priority order

Priority levelJurisdictionResources provided by this Data Governance Framework
P0Taiwan Personal Data Protection Act (PDPA)This comparison table + Taiwan PDPA Notes
P0EU GDPR + Swiss nFADPThis comparison table + EU GDPR & Swiss nFADP Notes
P0Singapore PDPAThis comparison table + Singapore PDPA Notes
P1Japan APPIOnly the key difference fields listed in this comparison table
P1Korea PIPASame as above
P1UK GDPRSame as above

When the research partner is in a P1 jurisdiction and enters the formal collaboration stage, this centre will upgrade that jurisdiction to P0 and establish corresponding Jurisdiction Notes.

2. Comparison table

The table presents “core requirements of the relevant jurisdiction” and “Uedu's corresponding practices” side by side. Specific implementation details of “Uedu's corresponding practices” are set out in Data Governance Framework, Privacy and Data Retention Policy, and List of Sub-processors.

Topic Taiwan PDPA EU GDPR + Swiss nFADP Singapore PDPA Korea PIPA UK GDPR
Lawful Basis §19 Collection / §20 Use: contract / consent of the data subject / express legal provision / academic research, etc. GDPR Art. 6: six bases; Swiss nFADP has a comparable structure, but the definition of personal data is slightly broader than under GDPR Consent Obligation as a principle; enumerated exemptions Consent must be obtained from the individual; the purpose of personal data use must be specified and notified Consent must be given separately; purpose, items and retention period must be disclosed Substantially equivalent to EU GDPR Art. 6
Service use is governed by the terms of service agreed to at registration; research use is obtained through separate IRB consent forms Same on the left; for special category personal data (physiological sensing), dual consent under Art. 6(1)(a) + Art. 9(2)(a) Same as above; users in Singapore consent directly on the registration page Consistent with Taiwan practice; new research data are obtained with individual consent Same as above Aligned with EU practice
Notice and transparency §8 Duty to inform: collector, purpose, categories, period of use, recipients, means of use, rights of the data subject Art. 13-14: detailed mandatory notices; including controller identity, retention period, rights, and cross-border mechanisms Notification Obligation: inform the purpose of collection Clarify the purpose of use and notify or announce Disclosure items are more detailed than GDPR Same as EU GDPR
The consent form and registration page provide notice; the Privacy Policy is published publicly in this governance centre Same on the left; this governance centre publicly discloses the controller's identity (individual, not institution), Privacy Contact, and cross-border transfer mechanism Same as above; the Privacy Policy provides an English version (to be published once the EN translation is finalised) Same as above Same as above Same as above
Special category personal data §6 Special categories of personal data (medical, genetic, sexual life, health examination, criminal records); in principle prohibited, but may be processed where an exception applies Art. 9: race, politics, religion, trade unions, genes, biological characteristics, health, sex life, sexual orientation; principle of prohibition There is no GDPR-style special category concept, but special conditions are set for specific data. "Personally identifiable information": medical information, criminal records, race, religion, etc.; in principle, explicit consent is required "Sensitive personal data": thoughts, beliefs, trade union membership, health, sexual life, etc.; in principle prohibited Same as EU GDPR Art. 9
Physiological sensing (HRV, sleep) and gender identity surveys fall into this category; individual explicit consent is obtained through an IRB consent form Same on the left; GDPR Art. 9(2)(a) 'explicit consent' is the lawful basis; research use also invokes Art. 9(2)(j) + Art. 89 Health and physiological data are obtained with individual consent; higher protection standard for 'sensitive personal data' Collection of "personally identifiable information" is carried out with individual consent Same as above Same as above
Retention period §11 On expiry of the retention period, it shall be deleted proactively or upon request Art. 5(1)(e) storage limitation principle; Art. 17 right to erasure Retention Limitation Obligation: must not be retained once the purpose has been achieved No fixed retention period is specified; follows the principle of fulfilling the purpose Destroy within 5 days after the retention period expires or the purpose has been achieved Same as EU GDPR
Uedu adopts a three-tier retention strategy (applicable to all jurisdictions):
  1. Directly identifying personal data: self-service account deletion currently only deactivates the account and does not automatically erase data; full deletion is handled case by case upon email request (GDPR Art. 5(1)(e), Art. 17)
  2. Personal data in backup: automatically deleted on a 30-day rotation
  3. Platform-side teaching records: retained permanently; research export data does not include names, email addresses, or student ID numbers (GDPR Art. 89)
  4. Researcher export: limited to within 5 years from the date the data were generated
See details Privacy and data retention policy §2。
Cross-border transfer mechanism §21 The central competent authority for the relevant industry may restrict cross-border transfers; currently there is no ban on educational data Art. 44-49: adequacy decisions/SCCs/BCRs/derogations; the Swiss nFADP has an independent adequacy list Transfer Limitation: must ensure the receiving location has an equivalent level of protection (through contract or data subject consent) Consent must be obtained from the individual or meet the equivalent protection standards recognised by the PPC Prior individual consent must be obtained or a specific exemption must apply Same as EU GDPR; the UK's adequacy list is maintained by the ICO
For LLM inference in European collaborations, Uedu may route via the Switzerland North / West Europe region of Microsoft Azure OpenAI Service (in accordance with Microsoft's EU Data Boundary commitment). Transfers to the United States (OpenAI) have Zero Data Retention enabled. Email is handled via the Mailgun EU region. See sub-processor list.

The specific documented procedures in this section (such as signing SCCs and the Swiss FDPIC adequacy list's assessment of Taiwan) are left for the partner institutions' DPO or counsel in the relevant jurisdiction to review and complete together when the collaboration begins.
Data subject rights §3: enquiry / request access / request a copy / request supplementation or correction / request cessation of collection, processing or use / request deletion Art. 15-22: access, rectification, erasure, restriction, portability, objection, objection to automated decision-making Access & Correction Obligations; no explicit data portability right Disclosure, correction, and suspension of use requests A full and comprehensive list of data subject rights, including claims for damages Same as EU GDPR
Uedu provides the following equally to all data subjects: (1) a self-service account deletion interface (which currently only deactivates the account; full deletion is by email request); (2) the option to email [email protected] to exercise other rights, with a response within 30 days. The right to data portability (GDPR Art. 20) currently has no self-service interface and is handled upon written request. See Privacy and data retention policy §7 for details.
Protection of minors Under 7: legal representative acts on behalf of the child; 7–20: requires permission from the legal representative Art. 8: for direct provision of information society services to those under 16 (Member States may lower this to 13), parental consent is required Under the PDPA, processing for those under 13 requires parental consent No specific age is specified; follows the Civil Code and PPC guidance Processing for children under 14 requires consent from a legal representative Processing for children under 13 requires parental consent
Uedu is primarily used in tertiary institutions; most users are already over 18. Where there are minor users in senior high school collaborations (the first being Taipei Municipal Nangang High School), the legal representative's consent (parental consent form) plus the individual's independent consent are obtained; no profiling or automated decision-making is carried out for minor users. See Privacy and Data Retention Policy §9.
Breach notification deadline §12: notify the data subject by appropriate means; no explicit 72-hour requirement GDPR Art. 33: notify the supervisory authority within 72 hours; Swiss nFADP: notify the FDPIC "as soon as possible" PDPC Mandatory Data Breach Notification: notify the PDPC within 3 days (where 500+ people are involved or there is serious harm) Report to PPC promptly; reporting by the person involved is also the principle Report to PIPC + the individual concerned within 72 hours Same as EU GDPR: notify the ICO within 72 hours
Uedu applies the strictest time limit in each jurisdiction: where a personal data breach occurs, it is reported to the competent authorities in all affected jurisdictions within 72 hours, and data subjects are notified in accordance with the requirements of each jurisdiction depending on the severity of the incident. The breach reporting contact is [email protected] (subject line marked [URGENT BREACH NOTIFICATION]).
Supervisory authority Personal Data Protection Commission (PDPC, from 2025; currently implemented by the Personal Data Protection Office of the National Development Council) EU: each Member State's DPA (for example, the Irish DPC and Germany's BfDI); Switzerland: FDPIC Personal Data Protection Commission(PDPC, Singapore) Personal Information Protection Commission (PPC, Japan) 개인정보보호위원회(PIPC, Korea) Information Commissioner's Office(ICO, UK)
Uedu handles correspondence from competent authorities via [email protected]; for incidents involving multiple jurisdictions, the Privacy Contact coordinates centrally and maintains independent reporting channels for each contact point. Uedu has no DPO within the meaning of GDPR Art. 37 (disclosed in Data Governance Framework §7).

3. Legal nature and limitations

  • This comparison table is a high-level disclosure of governance positions and does not constitute legal advice. For specific applicability conditions, liability determinations and litigation risks in each jurisdiction, please consult a qualified legal adviser for each case.
  • The article numbers cited in this comparison table are those of the version used when Uedu's governance position was formulated; jurisdictions may amend their laws after this comparison table is updated, and users should verify the current legal text themselves.
  • The disclosure in the 'Uedu Corresponding Approach' field is a unilateral statement by the Uedu platform; it does not constitute any commitment to regulators in any jurisdiction, nor does it replace the formal notification, registration or licensing procedures required by each jurisdiction.
  • When the data processing involved in the research collaboration goes beyond the situations covered by this comparison table (such as biological samples, clinical medical data, intensive monitoring of minors, etc.), this comparison table does not apply and the case must be reassessed individually.

4. Update mechanism

  • This comparison table is updated when: (i) any jurisdiction makes a material legal amendment; (ii) Uedu's governance position changes; (iii) a new P0 jurisdiction is added.
  • Updated to the versioning system under the Data Governance Framework §6
  • Major changes to existing partners will be notified by email 30 days in advance
  • The lifting of draft status (after obtaining endorsement from external legal counsel) will be marked by a version jump and announced on the centre's homepage

5. Contact point

Privacy Contact[email protected]
Objections to, or suggested corrections for, the content of this comparison table[email protected] (please include [COMPLIANCE MATRIX FEEDBACK] in the subject line)

This comparison table is an index document for Jurisdiction Notes; for detailed explanations of P0 jurisdictions, please refer to the corresponding individual pages.