Mergers & acquisitions
What is privacy and security due diligence in an acquisition?
Reviewed by the Privacy Horizon team · Last reviewed
Quick answer
Privacy and security due diligence is the structured review a buyer performs on an acquisition target to understand what personal data it holds, how lawfully and safely it handles that data, and what privacy and cyber risks come with the deal. It covers data inventories, consent and compliance posture, security controls, past breaches, and vendor and AI exposure — so liabilities are priced, disclosed, or remediated before closing.
On this page
- What does privacy and security due diligence cover?
- Why does privacy and security matter in an M&A deal?
- What documents and evidence should you request from the target?
- When in the deal should due diligence happen, and what are the common red flags?
- What does privacy and security due diligence cost, and how is it structured?
- Frequently asked questions
What does privacy and security due diligence cover?
Privacy and security due diligence is the part of an acquisition where the buyer investigates the target's data practices and cyber posture so that hidden liabilities surface before money changes hands. Unlike financial or legal due diligence, it focuses on the personal information the target collects, the legal basis for holding it, the controls protecting it, and the obligations that transfer to the buyer at closing.
The goal is not only to confirm the target is compliant today. It is to quantify risk: a single past breach, an unlawful data-sharing arrangement, or a product trained on data the company never had the right to use can materially change what the business is worth and what the buyer inherits.
- Data inventory and flows — what personal and sensitive data is collected, where it lives, and who it is shared with
- Legal and regulatory posture — applicable laws (PIPEDA, Quebec's Law 25, PHIPA, GDPR, US state laws), consent practices, and privacy notices
- Security controls — access management, encryption, logging, vulnerability and patch management, and whether a recent assessment exists
- Incident history — past breaches, regulator interactions, complaints, and outstanding remediation
- Vendor and sub-processor risk — third parties that touch personal data and the contracts governing them
- AI and product exposure — models, training data, and automated decisions that may carry their own compliance obligations
Why does privacy and security matter in an M&A deal?
Privacy and security matter in M&A because data risk does not disappear at closing — it transfers to the buyer along with the assets. When you acquire a company, you generally acquire its data, its data-handling history, and its unresolved liabilities, including breaches that occurred before the deal but are discovered after.
Regulators and courts have held acquirers accountable for the privacy and security failings of companies they bought, even where the buyer was unaware at the time. That is why diligence findings flow directly into deal economics: they can justify a lower purchase price, trigger specific indemnities or escrow holdbacks, become conditions the seller must remediate before closing, or — in serious cases — end the deal.
For buyers in healthcare, public-sector supply chains, and high-growth technology, the stakes are higher still, because the target's customers and the regulators that oversee them expect demonstrable privacy and security maturity from anyone who inherits their data.
What documents and evidence should you request from the target?
Request the documents that let you verify, rather than assume, how the target handles data. The strongest diligence is evidence-based: written policies are useful, but proof that those policies operate in practice is what reduces a buyer's exposure.
- Data maps or records of processing showing what personal and sensitive data is held and where it flows
- Privacy policies, consent records, and data-subject request logs
- Recent assessments — Privacy Impact Assessments, Threat & Risk Assessments, penetration test reports, and any SOC 2 or ISO 27001 reports
- Security policies plus evidence they are followed: access reviews, encryption standards, logging, and patch records
- Breach and incident history, regulator correspondence, and complaint records
- Vendor and sub-processor lists with the data-processing agreements that govern them
- For AI-enabled products, documentation of training-data sources, model use, and automated decision-making
When in the deal should due diligence happen, and what are the common red flags?
Privacy and security due diligence should begin early — once a letter of intent or term sheet is in place and a data room opens — and continue until closing, because late findings leave little time to renegotiate or remediate. Starting early also lets the buyer scope remediation and reflect it in the purchase agreement instead of absorbing surprises afterward.
Certain findings recur often enough to act as warning signs. None is automatically fatal, but each warrants deeper investigation and may affect price, terms, or timing.
- No data inventory — the target cannot say what personal data it holds or where it lives
- Missing or stale assessments — no PIA, TRA, penetration test, or audit in recent memory
- Undisclosed or poorly handled past breaches, or unresolved regulator complaints
- Weak vendor governance — sub-processors with no data-processing agreements in place
- Consent and notice gaps, especially for sensitive, health, or cross-border data
- AI products built on training data the company may not have had the right to use
What does privacy and security due diligence cost, and how is it structured?
The cost of privacy and security due diligence varies widely and is driven by scope rather than a fixed fee, so an accurate quote depends on the specifics of the target. For that reason Privacy Horizon does not publish a flat M&A diligence price; we scope each engagement to the deal and provide a quote after an initial consultation.
Engagements are typically structured around the work involved rather than the headline value of the deal, and shaped by the cost drivers below. Because a buyer is weighing diligence cost against the liabilities it might inherit, the right structure is the one that matches the deal's risk. Booking a consultation is the fastest way to scope the work and receive a tailored quote rather than a generic estimate.
- Target complexity — the volume and sensitivity of data, number of systems, and how many jurisdictions are in play
- Depth required — a focused review versus a full assessment that adds a TRA or penetration testing of the target's environment
- Sector obligations — healthcare (PHIPA), public sector, and regulated buyers usually require deeper, evidence-based review
- Timeline pressure — compressed deal timelines and parallel workstreams increase effort
- Post-close work — remediation planning and integration support beyond the diligence report itself
Frequently asked questions
No. A SOC 2 report is meaningful third-party evidence about a defined set of systems over a defined period, but it does not cover privacy-law compliance, undisclosed breaches, or systems outside its scope. Read the scope, the trust-services criteria covered, and any exceptions in the auditor's opinion carefully, and pair it with your own assessment rather than treating it as a clean bill of health.
In most deals the buyer inherits the target's data and its data-handling liabilities, including breaches that happened before closing but are discovered later. Diligence findings are what let a buyer push those risks back to the seller through price reductions, indemnities, escrow holdbacks, or pre-closing conditions.
It depends on the target's size, the sensitivity of its data, and how organized its records are. A focused review of a small SaaS company is faster than a multi-jurisdiction healthcare target. Starting once the data room opens gives enough runway to investigate red flags and reflect them in the deal.
The buyer typically commissions diligence to protect itself, but sellers increasingly run their own privacy and security review beforehand — sometimes called sell-side or vendor diligence — to fix gaps early, support their valuation, and avoid surprises during the buyer's review.
A serious finding rarely ends a deal on its own. More often it reshapes the terms: the buyer may lower the price, require the seller to remediate before closing, add specific indemnities, hold funds in escrow, or carve the risky asset out of the transaction.
Keep exploring
All Mergers & acquisitionsWhat is SOC 2, and does my business need it?
SOC 2 is an independent report on how a service organization protects customer data. Learn what it covers, who requires it, and whether your business needs one.
ReadCompliance & regulationsWhat is a cybersecurity risk assessment, and how often should we do one?
A cybersecurity risk assessment identifies threats to your data and systems and how to manage them. Do one at least annually and after any significant change.
ReadPrivacy breach & incident responseWhat should I do after a data breach?
The steps to take after a data breach: contain it, investigate scope, meet your legal notification obligations (PIPEDA, GDPR, HIPAA), remediate, and document everything.
ReadPrivacy & security assessmentsPIA vs TRA: which assessment do you need (or do you need both)?
PIA vs TRA: a PIA assesses privacy risk to individuals; a TRA assesses security threats to systems. Learn which assessment you need, or whether you need both.
ReadMergers & acquisitionsIs a SOC 2 report enough to prove an acquisition target is secure?
Is a SOC 2 report enough to prove an acquisition target is secure? No — here is what a SOC 2 covers, what it misses, and how to fill the gaps in M&A.
ReadPrivacy & security assessmentsWhat's involved in a Privacy Impact Assessment: inputs, timeline, and cost?
What's involved in a Privacy Impact Assessment — the inputs, timeline, and cost drivers of a PIA, and how to scope one for your project or product.
Read