Introduction
Every acquisition is a data acquisition. When two organisations consolidate operations, they merge customer databases, employee records, vendor files, and years of accumulated processing history. Buyers routinely run detailed financial and technology diligence on a target, but privacy diligence is often treated as a checkbox exercise, if it happens at all.
That gap is now a direct financial and regulatory exposure. A recent SRS Acquiom and Mergermarket survey of 150 senior U.S. investment banking executives found that cybersecurity has overtaken ESG as a diligence priority, with 97% of respondents citing it as an area of intensifying scrutiny, and 45% naming technology and data review the single most expensive and difficult part of the diligence process.
Under India's DPDP Act 2023, the stakes are structural, on closing, the acquirer becomes the Data Fiduciary for every personal data processing activity the target ever ran.
WHAT IS PRIVACY DUE DILIGENCE IN M&A
Privacy due diligence is the systematic assessment of how a target organisation collects, stores, shares, and disposes of personal data and whether that processing has a documented legal basis. It sits alongside financial and technology diligence. Privacy diligence asks who can access this data, why, and under what legal authority a question neither of the other workstreams is built to answer.
Teams often confirm that a target's core database is encrypted and call the data secure, without checking who holds the credentials, what gets exported, or where those exports end up. Even encryption protects data at rest; it says nothing about the spreadsheet a finance analyst emails to a dozen colleagues every month.
WHY IT'S A PRIVACY CONCERN
Undiscovered privacy liabilities transfer to the buyer, often invisibly, and surface only after closing when remediation is more expensive and regulatory exposure has already accrued.
Gibson Dunn's review of technology M&A diligence found that 96% of CIOs surveyed said technology due diligence uncovered issues or opportunities with a material impact on deal terms evidence that the data layer, not just infrastructure, regularly changes deal economics.
Furthermore, market surveys of dealmakers cited by Intralinks found that nearly three-quarters would walk away from an acquisition if an undisclosed data breach came to light. Globally, India ranked fifth by reported data breach volume as of the last available quarterly count, underscoring that the risk is not theoretical.
Under the DPDP Act, the consequences are also specific and priced. Section 8(5) exposes a Data Fiduciary to penalties of up to ₹250 crore for failing to implement reasonable security safeguards, and Section 8(6) carries penalties of up to ₹200 crore for failing to notify a breach. Both obligations transfer with the business. However, the DPDP Act does not replace all existing obligations. The Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 still apply to non-personal sensitive data and cybersecurity baseline standards. For financial sector deals, the Reserve Bank of India’s outsourcing guidelines and digital lending norms impose additional data localization and audit requirements.
WHERE THE EXPOSURE ACTUALLY LIVES
Fragmented systems are where most privacy risk sits. A pattern repeated across Indian enterprises is outdated CRMs, archived mail servers, unlogged backup systems, and departmental spreadsheets that haven’t been mapped to a single governance framework.
-
Encrypted systems, unencrypted workflows
Consider a scenario during a healthcare merger where patient records stored in the hospital’s electronic health record (EHR) system were properly encrypted and access-controlled. However, data mapping revealed that medical summaries, appointment schedules, insurance details, and patient identification numbers were routinely exported to unencrypted PDF and spreadsheet files for administrative reporting. These files were shared through email, stored on departmental network folders, and accessible to employees for several years. In this case, the administrative reporting and file-sharing workflow, not the secured EHR database itself, is the source of risk exposure.
-
Undisclosed or under-reported breaches
Say a target is delayed in disclosing a breach affecting ‘X’ customer records, discovered 45 days after it occurred, with notifications issued 60 days after discovery and no Data Protection Board filing on record. That breach, and the compliance failure around it, becomes the acquirer's problem the moment the deal closes.
-
Real-world precedent extends well beyond India
In India, the 2022 acquisition of a mid-sized NBFC by a top private bank revealed post-close that the target had suffered a ransomware incident affecting 1.8 million customer records. The breach had not been reported to CERT-In (mandatory under 2022 directives) and led to a penalty of approximately ₹6 crore under the IT Act, not including remediation costs. This case, cited in the DSCI-PwC India Data Breach Report 2023, demonstrates that undisclosed incidents are not hypothetical and that India’s regulatory engine is already active, even before DPDP Act enforcement fully ramps up.
Verizon's acquisition of Yahoo and Marriott's acquisition of Starwood are both widely cited examples where undisclosed pre-acquisition breaches surfaced after closing and materially affected valuation, litigation exposure, and regulatory penalties for the acquirer. Verizon discounted its acquisition of Yahoo by $350 million after pre-acquisition breaches were disclosed.
HOW TO RUN PRIVACY DUE DILIGENCE
-
Information gathering
Request an inventory of data systems, third-party processors, breach history for the past three to five years, and documented consent or legal basis for processing. Pair document requests with interviews of IT administrators, HR, finance, and customer-facing teams.
-
Data mapping and system verification
Query sample records and review access logs to see who exports data and how often. Walk through shared drives and departmental folders; personal data collects there outside any controlled system. Check backup and archive systems specifically, since deleted data frequently persists there in recoverable form. Map cross-border transfers against DPDP Act Section 16, which restricts transfers outside India unless the recipient jurisdiction offers adequate protection or the data principal has given explicit consent.
-
Breach history verification
Cross-reference the target's disclosed incidents against regulatory filings, news coverage, and former-employee accounts. A gap between what was disclosed and what actually happened is itself a compliance failure, independent of the breach.
-
Undisclosed breach liability
A breach the target never properly reported becomes a live compliance failure the day the deal closes. Under the DPDP Act, the obligation to notify both the Data Protection Board and affected data principals arises immediately upon knowledge of the breach any delay inherited by the acquirer is already a violation.
-
Consent gaps
Data collected under vague or undocumented consent can't lawfully be used for new purposes including the marketing and cross-sell activity that often justifies the acquisition in the first place.
-
Vendor exposure
Processors without a formal DPA may retain, reuse, or mishandle data in ways the acquirer has no contractual visibility into, let alone control over.
-
Cross-border transfer risk
Data flowing to overseas group entities or vendors without a documented legal basis under Section 16 is an active violation the moment it's inherited, not a historical one.
ACTION ITEMS CHECKLIST
- Issue written notice assuming Data Fiduciary responsibility, naming a system owner for each data repository
- Freeze marketing, secondary use, and third-party sharing of data lacking documented consent or a DPA
- Restrict and log access to sensitive systems
CONCLUSION
Privacy due diligence in M&A is a direct input into valuation, deal risk, and post-closing liability. Under the DPDP Act, 2023 and the DPDP Rules, 2025, the acquirer inherits every processing activity, every consent gap, and every unreported breach the moment the deal closes. A structured diligence framework, paired with a disciplined post-closing remediation plan, is a fiduciary obligation that transfers with the business the moment the deal closes. Without it, the acquirer carries every consent gap, every unreported breach, and every processing violation into its own books.
We at Data Secure (Data Privacy Automation Solution) DATA SECURE - Data Privacy Automation Solution can help you to understand Privacy and Trust while lawfully processing the personal data and provide Privacy Training and Awareness sessions in order to increase the privacy quotient of the organisation.
We can design and implement RoPA, DPIA and PIA assessments for meeting compliance and mitigating risks as per the requirement of legal and regulatory frameworks on privacy regulations across the globe especially conforming to GDPR, UK DPA 2018, CCPA, India Digital Personal Data Protection Act 2023. For more details, kindly visit DPO India – Your outsourced DPO Partner in 2025 (dpo-india.com).
For any demo/presentation of solutions on Data Privacy and Privacy Management as per EU GDPR, CCPA, CPRA or India DPDP Act 2023 and Secure Email transmission, kindly write to us at info@datasecure.ind.in or dpo@dpo-india.com.
For downloading the various Global Privacy Laws kindly visit the Resources page of DPO India - Your Outsourced DPO Partner in 2025
We serve as a comprehensive resource on the Digital Personal Data Protection Act, 2023 (Digital Personal Data Protection Act 2023 & Draft DPDP Rules 2025), India's landmark legislation on digital personal data protection. It provides access to the full text of the Act, the Draft DPDP Rules 2025, and detailed breakdowns of each chapter, covering topics such as data fiduciary obligations, rights of data principals, and the establishment of the Data Protection Board of India. For more details, kindly visit DPDP Act 2023 – Digital Personal Data Protection Act 2023 & Draft DPDP Rules 2025
We provide in-depth solutions and content on AI Risk Assessment and compliance, privacy regulations, and emerging industry trends. Our goal is to establish a credible platform that keeps businesses and professionals informed while also paving the way for future services in AI and privacy assessments. To Know More, Kindly Visit – Your Trusted Partner in AI Risk Assessment and Privacy Compliance | AI-Nexus