Skip to main content

New: AI Privacy Impact Assessments for teams shipping AI features. Learn more

← Back to all insights

Mergers & Acquisitions

Privacy and Cyber Due Diligence Before You Acquire a Company

Privacy HorizonJune 22, 20268 min read
A handshake in a boardroom representing an acquisition

When you buy the company, you buy its data problems too

Acquisitions move fast once a deal gets serious. The financials check out, the product roadmap is exciting, the team looks strong, and everyone wants to sign before the momentum fades. In that rush, privacy and cybersecurity are often treated as a single checkbox: someone asks for a SOC 2 report, it arrives, and the box gets ticked.

That is how acquirers end up owning a problem they never priced in. When you buy a company, you do not just buy its revenue and its people. You buy every record it ever collected, every system it never patched, and every regulatory obligation it quietly fell short of. If the target had an undisclosed breach, an unlawful data-sharing arrangement, or a database of personal information it has no legal basis to hold, those liabilities tend to follow the business to you.

Good privacy and cyber due diligence is not about killing deals. It is about pricing risk honestly, protecting yourself with the right contract terms, and walking into integration with your eyes open. This guide covers what that work involves, the red flags that should change your offer, and how to scope it so it fits the deal timeline instead of derailing it.

What privacy and cyber due diligence actually examines

This is broader than a security review. It asks two connected questions: is the target's data lawful to hold and use, and is it adequately protected? A target can pass one and fail the other. Spotless security controls do not help if the company collected the data unlawfully, and airtight consent does not matter if the database is sitting unencrypted on an exposed server.

  • Data inventory and mapping: what personal and sensitive information the target holds, where it lives, who it is shared with, and which jurisdictions it touches.
  • Legal basis and consent: whether the company can lawfully collect, use, and disclose that data under PIPEDA, provincial health laws such as Ontario's PHIPA, Quebec's Law 25, the GDPR, or others, depending on where its customers and records are.
  • Security posture: technical and organizational controls, access management, encryption, vulnerability and patch management, and how the target handles vendors and subprocessors.
  • Incident history: past breaches, near-misses, regulator correspondence, and whether required notifications were actually made.
  • Contracts and commitments: privacy promises made to customers, data processing agreements, and obligations that may restrict how you can integrate or use the acquired data.
  • Governance: whether anyone actually owns privacy and security, or whether it has been nobody's job for years.

Why a SOC 2 report is a starting point, not a finish line

The most common mistake we see acquirers make is treating a SOC 2 report as proof that the target is secure. It is useful evidence, but it answers a narrower question than most buyers assume.

A SOC 2 report tells you that an independent auditor examined a defined set of controls, within a scope the company itself chose, against the relevant Trust Services Criteria. It does not tell you that every system is covered, that the controls still hold today, or that the target is meeting its privacy obligations under Canadian or other law. Reading a SOC 2 report well means reading past the cover page.

  • Check the scope. A report that covers one product but excludes the systems holding the most sensitive data is far less reassuring than it looks.
  • Check the type. A Type 1 report confirms only that controls were suitably designed at a point in time. A Type 2 confirms they operated effectively over a period (commonly three to twelve months), which is what you actually want.
  • Read the exceptions. The auditor's noted exceptions and management's responses often reveal more than the opinion letter.
  • Check the dates. A report covering a period that ended a year ago says little about the company you are buying today.
  • Mind the gap. SOC 2 centres on security and the other Trust Services Criteria; privacy is an optional criterion that is frequently left out of scope, so a typical report will not confirm that data was collected lawfully.
  • In short, a clean SOC 2 narrows your uncertainty. It does not eliminate it, and it should never be the only artifact you rely on.

The red flags that should change your offer

Some findings are routine and easily remediated after closing. Others should directly affect price, deal structure, or whether you proceed at all. The difference usually comes down to whether the issue is a fixable gap or a transferred liability.

  • An undisclosed or under-reported breach, especially one where required notifications to regulators or affected individuals were never made.
  • Personal or health information held with no clear legal basis or with expired consent, which can mean you are inheriting data you have no right to use.
  • Sensitive data flowing to vendors or jurisdictions without proper agreements, or to subprocessors the company cannot even fully list.
  • No owner for privacy and security, no incident response plan, and no record of risk assessments, which together signal that controls are improvised rather than managed.
  • Customer or enterprise contracts containing privacy commitments the target has not actually been meeting.
  • Heavy reliance on a single audit artifact with no supporting evidence, no internal policies, and no remediation tracking behind it.
  • Retention practices that keep everything forever, multiplying both regulatory exposure and breach impact.

How to scope the work to the size of the deal

Due diligence should be proportionate. A small SaaS acquisition does not need the same depth as buying a regional health network, and applying full rigour to a minor deal just burns time you do not have. The trick is matching effort to the sensitivity of the data and the size of the exposure.

A workable approach is to triage first, then go deep only where the triage raises concerns:

  • Triage: a short questionnaire and document request covering data types, jurisdictions, breach history, existing audits, and who owns privacy and security. This alone surfaces most of the serious red flags.
  • Targeted deep dive: where triage flags risk, examine the relevant systems, contracts, and incident records in detail rather than auditing everything.
  • Independent verification: validate the most material claims yourself instead of taking the seller's word, particularly around breach history and data legality.
  • Quantify and document: translate findings into concrete dollar exposure and clear remediation steps the deal team can act on.
  • The goal is not a 200-page report nobody reads. It is a clear-eyed view of what you are buying, mapped to the decisions the deal team actually has to make.

Turning findings into deal protection and a 100-day plan

Diligence only pays off if the findings shape the transaction and the integration that follows. The output should feed two things: the contract and the post-close plan.

On the contract side, material findings become specific representations, warranties, and indemnities. If the target asserts there have been no breaches, get that in writing with teeth behind it. Where a known issue exists, consider a holdback or escrow tied to remediation, so the seller keeps skin in the game until it is fixed.

  • Map each finding to a remediation action with an owner and a deadline, so nothing gets lost the moment the deal closes.
  • Prioritize anything that creates ongoing legal exposure, such as unlawfully held data or missing breach notifications, ahead of cosmetic gaps.
  • Plan the integration carefully. Merging two environments can expand the attack surface and combine datasets in ways that trigger new privacy obligations.
  • Decide who owns privacy and security in the combined organization from day one, rather than assuming it will sort itself out.

The bottom line for acquirers

Privacy and cyber due diligence is one of the highest-leverage uses of time in any acquisition involving meaningful amounts of personal or sensitive data. It costs a fraction of a typical deal and routinely uncovers risks worth far more than the work to find them.

Treat security artifacts like a SOC 2 report as evidence to interrogate, not a verdict to accept. Scope the work to the data and the deal size. And translate what you learn into contract terms and a concrete remediation plan rather than a report that sits in a folder. The acquirers who do this well treat the closing date as the start of a 100-day plan, not the end of the privacy conversation.

If you are evaluating a target and want an independent, plain-language read on its privacy and security posture before you sign, Privacy Horizon runs acquisition diligence across healthcare, public sector, and technology deals in 43-plus jurisdictions. The aim is simple: make sure the company you think you are buying is the company you actually get.

  • What is privacy and security due diligence in an acquisition
  • Is a SOC 2 report enough to prove an acquisition target is secure

What's Protecting Your Business from the Next Threat?

Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.