Data protection, sector regulators and licences
What data protection laws ask of companies in Europe, India, the Gulf and Singapore, what breaking them can cost, and why licences shape whole industries.
Firm processes and online tests change from year to year and differ by office. Use this to prepare, and confirm the exact current steps on the firm's own careers page.
Key takeaways
- Personal data is any information that identifies a person, such as a name, phone number, location or purchase history.
- Market entry: "Do we need a licence, and how long does it take?" is often the first question in banking, telecom, health or aviation.
- India, Digital Personal Data Protection Act 2023: the Rules were notified on 14 November 2025 with an eighteen-month phase-in, so most duties on companies apply from about May 2027.
- Saudi Arabia, Personal Data Protection Law: in force since 14 September 2023, with a one-year transition that ended on 14 September 2024 (law firm summary).
Key idea
Personal data is any information that identifies a person, such as a name, phone number, location or purchase history. Data protection laws say a company may collect it only for a clear purpose, on a lawful basis such as consent, keep only what it needs, protect it, let people see and correct it, and report breaches. Breaking these rules can cost a share of turnover.
The main laws (checked on 1 October 2026)
- European Union, GDPR (General Data Protection Regulation): for the most serious breaches, fines up to EUR 20 million or 4 percent of worldwide annual turnover, whichever is higher; a lower cap of EUR 10 million or 2 percent applies to other breaches (European Commission; European Data Protection Board). In May 2023 Ireland's Data Protection Commission fined Meta EUR 1.2 billion for transferring EU users' data to the US without adequate protection (DPC).
- India, Digital Personal Data Protection Act 2023: the Rules were notified on 14 November 2025 with an eighteen-month phase-in, so most duties on companies apply from about May 2027. Penalties reach INR 250 crore for failing to keep data secure and INR 200 crore for not reporting a breach or breaking the rules on children's data (PIB). In early 2026 the government consulted on shortening some deadlines (reported), so check the current dates.
- Saudi Arabia, Personal Data Protection Law: in force since 14 September 2023, with a one-year transition that ended on 14 September 2024 (law firm summary). Fines reach SAR 5 million per violation and can be doubled for a repeat (SDAIA, Article 36).
- United Arab Emirates: a federal law, Federal Decree-Law No. 45 of 2021, plus separate laws in financial free zones such as the DIFC Data Protection Law No. 5 of 2020 (UAE Government portal).
- Singapore, Personal Data Protection Act: fines can reach 10 percent of annual turnover in Singapore or SGD 1 million, whichever is higher; the turnover-based cap applies to larger firms (Singapore Ministry of Digital Development and Information).
Worked case
Is a loyalty data project worth the data risk?
The prompt
A fictional German retailer with worldwide turnover of EUR 3 billion wants to use loyalty card data to send personal offers. It expects EUR 6 million a year of extra profit. Building proper consent, security and data deletion would cost EUR 2 million once and EUR 0.5 million a year (illustrative). Should it go ahead, and what does the GDPR cap mean for the decision?
The structure
- Project value against compliance cost, then the size of the downside
- Net yearly profit after compliance running cost
- Payback on the one-off compliance build
- Key: Maximum GDPR fine against yearly project profit
Working it through
1. Net yearly profit
EUR 6 million minus EUR 0.5 million.
Net yearly profit (EUR million):6 - 0.5 = 5.52. Payback in months
EUR 2 million one-off divided by EUR 5.5 million a year, times 12.
Payback (months):2 ÷ 5.5 × 12 = 4.363. Maximum GDPR fine
For the most serious breaches: 4 percent of EUR 3,000 million is above EUR 20 million, so 4 percent applies.
Maximum fine (EUR million):3,000 × 0.04 = 1204. Fine in years of project profit
EUR 120 million divided by EUR 5.5 million.
Years of project profit:120 ÷ 5.5 = 21.82
The recommendation
Go ahead, but only with compliance built in from the start. The project pays back the EUR 2 million build in under five months and then earns about EUR 5.5 million a year. Cutting corners to save that EUR 2 million would be a bad trade: the maximum fine of EUR 120 million equals more than 21 years of the project's profit, before counting lost customer trust.
Risks: Fewer customers may give consent than planned, which lowers the EUR 6 million; A data breach brings costs beyond fines: notifying customers, fixing systems, lost sales.
Next steps: Test what share of customers opt in with a clear, honest offer; Agree with the data protection officer what data is kept and for how long.
An online retailer has annual turnover in Singapore of SGD 150 million. What is its maximum penalty under Singapore's data protection law, in SGD million?
Sector regulators and licences
Many industries cannot operate without a licence (official permission) from a sector regulator. Banks need a banking licence from the central bank and must hold enough capital. Telecom operators need spectrum licences, usually bought at auction. Airlines need traffic rights between countries and take-off and landing slots at busy airports. Utilities such as power grids and water networks often have their prices or returns set by a regulator. Medicines need approval from health regulators before sale. Insurers, payment firms and broadcasters need licences too.
Licences matter in cases because they are barriers to entry: they limit who can compete. In December 2020 the Monetary Authority of Singapore chose 4 winners from 14 eligible applications for new digital bank licences: two full banks (a Grab and Singtel group, and Sea) and two wholesale banks serving businesses (MAS). A market entry case in a licensed industry must ask: do we need a licence, how long does it take, how many are issued, and could we partner with or buy a firm that already holds one?
Market entry: "Do we need a licence, and how long does it take?" is often the first question in banking, telecom, health or aviation. Digital growth cases: personalisation, AI and data sharing need consent and security; count their cost and the fine cap. Pricing cases in regulated utilities: the regulator may set the price, so profit comes from cost and investment, not from price moves.
See the regulated-return business model patternUnder the GDPR, for the most serious breaches, a company with worldwide turnover of EUR 100 million faces a maximum fine of:
Why is a banking licence a barrier to entry?
Sources for this lesson (10)
- European Commission: data protection enforcement and sanctions, GDPR fines up to EUR 20 million or 4 percent of worldwide annual turnover (official)
- European Data Protection Board: Guidelines 04/2022 on the calculation of administrative fines under the GDPR, the two fine tiers and "whichever is higher" (official)
- Data Protection Commission (Ireland): conclusion of inquiry into Meta Ireland, EUR 1.2 billion fine for data transfers to the US (May 2023, official)
- Press Information Bureau, Government of India: DPDP Rules, 2025 notified on 14 November 2025, eighteen-month phased compliance and penalties (official)
- Takshashila Institution: MeitY considers reducing DPDP Act compliance timelines (January 2026, reported)
- Saudi Data and AI Authority (SDAIA): Personal Data Protection Law, English translation, Article 36 fines (official)
- Morgan Lewis: Saudi Arabia Personal Data Protection Law, transition period ends 14 September 2024 (September 2024, law firm summary)
- UAE Government portal: data protection laws, Federal Decree-Law No. 45 of 2021 and DIFC Law No. 5 of 2020 (official)
- Singapore Ministry of Digital Development and Information: closing note on the Personal Data Protection (Amendment) Bill, penalty cap of 10 percent of Singapore turnover or SGD 1 million, whichever is higher (official)
- Monetary Authority of Singapore: successful applicants of licences to operate new digital banks (4 December 2020, official)
My notes on this lesson
0 of 5,000 characters. Saves automatically.
Try the 3 remaining checks and drills above to complete this lesson (0 of 3 done).
Spotted something wrong or out of date? Report a mistake. We check every report and correct the page.