Privacy Due Diligence In Acquisitions
Privacy due diligence has a habit of stopping on the day the deal closes. The data room shuts, an integration team takes over, and questions that mattered during the transaction quietly go unasked. Regulators stopped finding that pattern acceptable a decade ago.
A buyer inherits three things. It inherits the data. It inherits the promises somebody made when collecting that data. And it inherits whatever was already going wrong inside the target’s systems. Privacy due diligence prices all three before signature, then keeps checking afterwards.
What privacy due diligence has to find before the deal
Four questions carry most of the weight.
What personal data does the target hold, and where does it sit? On what basis was it collected, and what were people told at the time? Which contracts govern its onward flow, including processors, sub-processors and cross-border transfers? What incidents, complaints and regulatory correspondence remain open?
None of that is answerable without an inventory. A target that cannot produce a record of its processing activities has already told you something about its programme maturity.
What the Marriott penalty says about due diligence
Marriott acquired Starwood in September 2016. An attacker had installed a web shell on a Starwood system on 29 July 2014. Nobody discovered the intrusion until 8 September 2018.
The ICO’s penalty notice of 30 October 2020 records around 339 million guest records involved. Roughly 30.1 million related to the European Economic Area and 7 million to the UK. The fine came to £18.4 million.
Between the ICO’s opening position and its final one, the public account shifted, and the difference is instructive. Its 2019 statement of intent announced an intended fine of £99,200,396. It said Marriott had failed to undertake sufficient privacy due diligence when it bought Starwood.
A year later the penalty notice is narrower. The Commissioner made no finding of infringement for the period between the acquisition and the GDPR taking effect on 25 May 2018. She also left open whether due diligence during a takeover had been possible at all. Her conclusion was that the arrival of the GDPR mattered a great deal for a business of that size, and that Marriott should have reassessed the security of the systems it had acquired.
Due diligence that does not stop at completion
That is the transferable lesson, and it outlives the transaction. Knowing what you hold and securing it does not pause while integration runs.
Put a due diligence date in the integration plan, by which acquired systems meet your own control standard, and treat it as a commitment. Where a target’s estate is too large to assess at once, sequence it by risk and write the sequence down. A documented plan is what separates a considered decision from a gap.
What you may do with data you have bought
Owning an asset does not rewrite the terms on which somebody collected the data. That principle turns up in enforcement on both sides of the Atlantic.
RadioShack’s customer data came up for sale in bankruptcy in 2015. The FTC wrote to the court on 18 May 2015 asking for conditions on any sale. It wanted the information sold only as part of a larger set of assets. It wanted the buyer to be in substantially the same line of business. And it wanted the buyer to honour the privacy policies in force at the point of collection. The buyer should also “provide consumers with notice and obtain their affirmative consent before using data in a way that is materially different from the promises RadioShack made”.
Read that as a checklist for the integration plan. A marketing list acquired with a business carries the consent people actually gave.
Where this sits in the programme life cycle
The CIPM Body of Knowledge, the IAPP document listing what the exam can test, puts this in two places on purpose. Assessing data covers privacy due diligence and contractual obligations before the deal. Sustaining programme performance covers risk mitigation and stakeholder communication after it.
Splitting the subject that way hints at how examiners use it. A question set before completion asks what you need to find out. The same scenario set after completion asks what you now have to fix, and in what order.
Assessment types earn their place here. A threshold analysis decides whether a fuller assessment has to follow. An impact assessment covers the processing you are taking on. A transfer impact assessment covers the flows that came with it. Candidates who sequence those calmly tend to find governance model questions easier too.
Preparing for the questions
Deal scenarios reward a habit rather than a memorised list. Ask who the controller is now. Then work out what the people whose data it is were told. Finally, identify what changed on completion. Most plausible-looking CIPM options fail one of those three.
For a timed run at scenario questions, the CIPM trial exam is the cheapest way to find out how you pace them.
Where the reasoning rather than the material is the problem, the CIPM Exam Question Masterclass takes a question apart and shows why the distractor was written.
