So What Club
Start free
People, rules and responsibility: organisation, regulation and sustainability
Lesson 6 of 8 Math checked Facts checked against sources on 1 October 2026 12 min

Data protection, sector regulators and licences

What data protection laws ask of companies in Europe, India, the Gulf and Singapore, what breaking them can cost, and why licences shape whole industries.

Firm processes and online tests change from year to year and differ by office. Use this to prepare, and confirm the exact current steps on the firm's own careers page.

Key takeaways

  • Personal data is any information that identifies a person, such as a name, phone number, location or purchase history.
  • Market entry: "Do we need a licence, and how long does it take?" is often the first question in banking, telecom, health or aviation.
  • India, Digital Personal Data Protection Act 2023: the Rules were notified on 14 November 2025 with an eighteen-month phase-in, so most duties on companies apply from about May 2027.
  • Saudi Arabia, Personal Data Protection Law: in force since 14 September 2023, with a one-year transition that ended on 14 September 2024 (law firm summary).

Key idea

Personal data is any information that identifies a person, such as a name, phone number, location or purchase history. Data protection laws say a company may collect it only for a clear purpose, on a lawful basis such as consent, keep only what it needs, protect it, let people see and correct it, and report breaches. Breaking these rules can cost a share of turnover.

The main laws (checked on 1 October 2026)

  • European Union, GDPR (General Data Protection Regulation): for the most serious breaches, fines up to EUR 20 million or 4 percent of worldwide annual turnover, whichever is higher; a lower cap of EUR 10 million or 2 percent applies to other breaches (European Commission; European Data Protection Board). In May 2023 Ireland's Data Protection Commission fined Meta EUR 1.2 billion for transferring EU users' data to the US without adequate protection (DPC).
  • India, Digital Personal Data Protection Act 2023: the Rules were notified on 14 November 2025 with an eighteen-month phase-in, so most duties on companies apply from about May 2027. Penalties reach INR 250 crore for failing to keep data secure and INR 200 crore for not reporting a breach or breaking the rules on children's data (PIB). In early 2026 the government consulted on shortening some deadlines (reported), so check the current dates.
  • Saudi Arabia, Personal Data Protection Law: in force since 14 September 2023, with a one-year transition that ended on 14 September 2024 (law firm summary). Fines reach SAR 5 million per violation and can be doubled for a repeat (SDAIA, Article 36).
  • United Arab Emirates: a federal law, Federal Decree-Law No. 45 of 2021, plus separate laws in financial free zones such as the DIFC Data Protection Law No. 5 of 2020 (UAE Government portal).
  • Singapore, Personal Data Protection Act: fines can reach 10 percent of annual turnover in Singapore or SGD 1 million, whichever is higher; the turnover-based cap applies to larger firms (Singapore Ministry of Digital Development and Information).

Worked case

Is a loyalty data project worth the data risk?

The prompt

A fictional German retailer with worldwide turnover of EUR 3 billion wants to use loyalty card data to send personal offers. It expects EUR 6 million a year of extra profit. Building proper consent, security and data deletion would cost EUR 2 million once and EUR 0.5 million a year (illustrative). Should it go ahead, and what does the GDPR cap mean for the decision?

Open this case to practice it with a partner

The structure

  • Project value against compliance cost, then the size of the downside
    • Net yearly profit after compliance running cost
    • Payback on the one-off compliance build
    • Key: Maximum GDPR fine against yearly project profit

Working it through

  1. 1. Net yearly profit

    EUR 6 million minus EUR 0.5 million.

    Net yearly profit (EUR million):6 - 0.5 = 5.5
  2. 2. Payback in months

    EUR 2 million one-off divided by EUR 5.5 million a year, times 12.

    Payback (months):2 ÷ 5.5 × 12 = 4.36
  3. 3. Maximum GDPR fine

    For the most serious breaches: 4 percent of EUR 3,000 million is above EUR 20 million, so 4 percent applies.

    Maximum fine (EUR million):3,000 × 0.04 = 120
  4. 4. Fine in years of project profit

    EUR 120 million divided by EUR 5.5 million.

    Years of project profit:120 ÷ 5.5 = 21.82

The recommendation

Go ahead, but only with compliance built in from the start. The project pays back the EUR 2 million build in under five months and then earns about EUR 5.5 million a year. Cutting corners to save that EUR 2 million would be a bad trade: the maximum fine of EUR 120 million equals more than 21 years of the project's profit, before counting lost customer trust.

Risks: Fewer customers may give consent than planned, which lowers the EUR 6 million; A data breach brings costs beyond fines: notifying customers, fixing systems, lost sales.

Next steps: Test what share of customers opt in with a clear, honest offer; Agree with the data protection officer what data is kept and for how long.

Timed math drill

An online retailer has annual turnover in Singapore of SGD 150 million. What is its maximum penalty under Singapore's data protection law, in SGD million?

Sector regulators and licences

Many industries cannot operate without a licence (official permission) from a sector regulator. Banks need a banking licence from the central bank and must hold enough capital. Telecom operators need spectrum licences, usually bought at auction. Airlines need traffic rights between countries and take-off and landing slots at busy airports. Utilities such as power grids and water networks often have their prices or returns set by a regulator. Medicines need approval from health regulators before sale. Insurers, payment firms and broadcasters need licences too.

Licences matter in cases because they are barriers to entry: they limit who can compete. In December 2020 the Monetary Authority of Singapore chose 4 winners from 14 eligible applications for new digital bank licences: two full banks (a Grab and Singtel group, and Sea) and two wholesale banks serving businesses (MAS). A market entry case in a licensed industry must ask: do we need a licence, how long does it take, how many are issued, and could we partner with or buy a firm that already holds one?

Where this shows up in a case

Market entry: "Do we need a licence, and how long does it take?" is often the first question in banking, telecom, health or aviation. Digital growth cases: personalisation, AI and data sharing need consent and security; count their cost and the fine cap. Pricing cases in regulated utilities: the regulator may set the price, so profit comes from cost and investment, not from price moves.

See the regulated-return business model pattern
Check your understanding

Under the GDPR, for the most serious breaches, a company with worldwide turnover of EUR 100 million faces a maximum fine of:

Check your understanding

Why is a banking licence a barrier to entry?

Sources for this lesson (10)
My notes on this lesson

0 of 5,000 characters. Saves automatically.

Try the 3 remaining checks and drills above to complete this lesson (0 of 3 done).

Spotted something wrong or out of date? Report a mistake. We check every report and correct the page.