All of it. The 4 million customer records collected under a privacy policy that did not align with the acquirer's. The employee records managed under HR practices that did not meet the acquirer's standards. The vendor relationships with data processing agreements that had not been reviewed in three years. The legacy systems storing data in formats and locations that the acquirer's data governance program had never assessed. The due diligence covered the financials. The data liability was disclosed in a paragraph.
What Acquisition Due Diligence Misses
Acquisition due diligence has a well-developed playbook for financial, legal, and operational assessment. Privacy and data governance due diligence is a newer discipline that has not achieved equivalent maturity in most deal processes. The result is acquisitions that are financially sound and data governance disasters: organizations that inherit personal data collected without adequate consent, under privacy notices that misrepresent the actual processing, stored in systems whose security does not meet the acquirer's standards, and governed by vendor agreements whose terms have not been reviewed since they were signed.
The paragraph in the due diligence disclosure that addresses privacy says 'the company maintains a privacy policy and has not received any material regulatory actions.' This is true and meaningless. It confirms that a privacy policy exists and that regulators have not yet acted. It does not assess whether the privacy policy reflects actual data practices, whether the data collection consent is valid under the regulatory framework that applies post-acquisition, whether the vendor agreements for data processing are adequate, or what the remediation cost would be to bring the acquired company's data governance to the acquirer's standard.
The gap between 'maintains a privacy policy' and 'has adequate data governance' is where acquisition data liability lives. Most due diligence confirms the first without assessing the second.
The Liability Categories
Consent That Does Not Survive the Acquisition
Personal data collected by the acquired company was collected under the acquired company's privacy notice, for the acquired company's stated purposes, with the data subjects' understanding that their data was held by the acquired company. Post-acquisition processing of that data by the acquiring organization is, in most privacy regulatory frameworks, a new processing activity by a new controller. Whether the original consent covers the new processing depends on whether the original privacy notice contemplated change of control and whether the purposes for which the acquirer will use the data are materially different from the purposes disclosed to data subjects.
Organizations that acquire companies and immediately merge their customer data into the acquirer's systems without assessing the consent coverage for the merged processing have created a potential mass processing-without-adequate-basis event. The scale of the exposure is the scale of the acquired data population.
Vendor Agreements That Bind the Acquirer
The acquired company's vendor agreements transfer to the acquirer as part of the acquisition. Data processing agreements that were adequate for the acquired company's processing may not be adequate for the acquirer's processing or for the regulatory framework that applies to the combined entity. Vendor agreements that contain data handling restrictions, jurisdiction limitations, or audit right provisions that conflict with the acquirer's requirements create operational constraints that may not be visible until the acquirer attempts to use the acquired data in ways the vendor agreements do not permit.
Legacy Systems With Unknown Data Holdings
Acquired companies frequently have legacy systems that were built without formal data governance, are poorly documented, and hold data that the acquired company's own team cannot fully characterize. The acquirer inherits these systems with their unknown data holdings. The data that was never inventoried may include sensitive personal data, special category data, or data collected under terms that created specific handling obligations. The discovery of that data — through a data mapping exercise, a security assessment, or a data subject request — may reveal liabilities that were not visible at acquisition.
The Remediation Timeline Reality
Data governance remediation for an acquired company is measured in months to years, not weeks. Reviewing and renegotiating vendor agreements across a large vendor portfolio takes time. Migrating data from legacy systems to governed infrastructure takes time. Notifying data subjects of the change in controller and providing opt-out opportunities where required takes time. Building the data mapping and consent management infrastructure for the acquired data population takes time.
Organizations that close acquisitions without a data governance remediation plan and timeline have inherited liability without a plan for addressing it. The liability continues to accrue during the period between acquisition and remediation. Regulators who investigate the combined entity post-acquisition may find data governance failures in the acquired business that the acquirer is now responsible for, whether or not the acquirer knew about them at acquisition.
Building Data Governance Due Diligence
Data governance due diligence that produces an accurate liability assessment covers the acquired company's privacy notices against their actual data practices — assessing whether the notice reflects what the company actually does with data. It covers the legal basis for processing of the acquired company's significant data categories — assessing whether the basis is valid and whether it will survive the change of control. It covers the vendor data processing agreements — assessing whether they are adequate for the processing they govern and compatible with the acquirer's requirements. And it covers the security posture of systems holding personal data — assessing whether the security meets the acquirer's standards and what the remediation cost is where it does not.
This assessment produces a data governance liability estimate that belongs in the deal valuation alongside the financial liabilities. Organizations that have made data governance due diligence a standard part of their acquisition process have avoided surprises that other acquirers have discovered after the deal closed.
Assess the data liability before the deal closes. The remediation is more expensive after.
Inherited data is inherited liability. Price it into the deal. Plan for the remediation before the acquisition closes.
Enterprise practitioner perspective. Not legal advice. Part of the Deep Trust Governance Series by Verisq. Get the free weekly Breach Digest.
