Mergers & Acquisitions
The Privacy and Security Problems That Quietly Erode Deal Value

Value rarely dies in a single explosion
When a deal falls apart over privacy or security, people imagine a dramatic moment: a breach disclosure, a regulator's letter, a headline. In practice, that is the rare case. Most of the value lost in an acquisition does not vanish all at once. It erodes quietly, line by line, as diligence surfaces small problems that each chip a little off the price, lengthen the timeline, or load the deal with reps, warranties, and holdbacks.
The pattern is familiar to anyone who has sat on either side of a transaction. The target looks healthy: the product works, the customers are real, the revenue is growing. Then the data room opens, and a series of unglamorous findings start to accumulate: a data map that does not exist, a SOC 2 report that covers the wrong things, contracts that promised security commitments nobody operationalised. None of these is fatal on its own. Together, they tell a buyer that the business carries more risk and more remediation cost than the model assumed, and the offer adjusts accordingly.
This post is about those quiet problems. Whether you are buying, selling, or advising, knowing where deal value leaks helps you find it before the other side does.
Why these problems stay hidden until diligence
Privacy and security debt is easy to carry and hard to see from the outside. A company can grow for years while postponing the unglamorous work of documenting how data flows, who can access it, and what was promised to customers. Nothing breaks, so nothing forces the issue.
Diligence is the first time someone has both the motive and the access to look closely. A buyer is not just evaluating whether the product works; they are evaluating whether the obligations attached to the data are knowable, manageable, and transferable. That is a different and more demanding test than day-to-day operations ever applies.
- Operations rewards shipping; diligence rewards evidence. A control that works but cannot be demonstrated is treated, correctly, as a risk.
- Founders often conflate a clean security record with a defensible one. No incidents to date is not proof of a managed programme.
- The cost of fixing a gap is lowest before anyone is watching and highest under a signed letter of intent with a closing clock running.
The data map nobody can produce
The single most common quiet killer is the absence of a credible data inventory. Ask a target to show what personal and sensitive data it holds, where it lives, which third parties touch it, and on what basis it was collected, and the answer is frequently a long pause followed by a best guess.
For a buyer, this is more than an inconvenience. If the target cannot describe its own data, it cannot have assessed its own privacy obligations, which means the buyer is inheriting an unquantified liability. In Canadian deals this is sharpened by overlapping regimes: PIPEDA federally, Quebec's Law 25 with its tighter consent and cross-border transfer rules, and sector legislation such as Ontario's PHIPA for personal health information. A target selling into healthcare or government that has never completed a privacy impact assessment is effectively asking the buyer to take its risk posture on faith.
The fix is unglamorous and powerful: a current data inventory and data flow map, a record of what was collected and why, and privacy impact assessments where the data is sensitive. Sellers who walk into diligence with this material reframe the conversation from suspicion to confidence.
The SOC 2 report that does not say what people think it says
A SOC 2 report is reassuring to wave around and easy to misread. Buyers and sellers alike often treat the existence of a report as the end of the security conversation. It is closer to the beginning.
Three details quietly change what a report is worth in a deal. First, scope: a report can cover a single product or environment and exclude the systems that actually hold the acquired customer data. Second, type: a Type 1 report describes whether controls are suitably designed at a single point in time, while a Type 2 report tests whether those controls operated effectively over a period, and only the latter speaks to how the business actually runs. Third, exceptions: the auditor's findings in the body of the report frequently matter more than the opinion on the cover.
A report scoped to the wrong systems, dated eighteen months ago, or carrying unresolved exceptions does not give a buyer the assurance the seller thinks it bought. Treat the report as one input to verify, not a conclusion to accept. The companion question of whether a SOC 2 report is enough to prove a target is secure deserves a direct, honest answer during diligence.
- Confirm the scope covers the systems and data the deal is actually about.
- Check whether it is Type 1 or Type 2, and read the period covered, not just the date issued.
- Read the exceptions and management responses, then ask what changed since.
- For deals touching healthcare or government, expect SOC 2 to be necessary but not sufficient on its own.
Contracts that promised more than the company delivered
Customer contracts are where security and privacy commitments turn into binding obligations, and they are a reliable source of buried risk. A target may have signed enterprise customers by agreeing to data protection addendums, breach notification windows, audit rights, encryption standards, or sub-processor restrictions, then never built the operational reality to match.
Every gap between what was promised and what is actually done is a latent liability the buyer inherits. A forty-eight-hour breach notification clause means little if the company has no incident response plan capable of meeting it. An audit-rights clause is a problem if the company has no evidence to show an auditing customer.
These gaps also limit the upside. If marquee contracts contain change-of-control or assignment restrictions, the revenue a buyer is paying for may not transfer cleanly. Reviewing the gap between contractual commitments and operational reality is one of the highest-return exercises in diligence, and one sellers can run on themselves first.
Access, offboarding, and the people-shaped risks
Technical controls get the attention, but some of the most telling findings are about people and process. Who has access to production data, and is that list current? Are former employees and contractors actually offboarded? Is there multi-factor authentication on the systems that matter, or only where it was convenient?
These are not exotic concerns. They are the basics, and they are exactly what a careful buyer probes because they reveal whether security is a managed discipline or an afterthought. A target where access reviews happen on a schedule, departures trigger deprovisioning, and privileged accounts are controlled looks like a business that can be integrated safely. A target where the answer to who has access is unclear looks like a remediation project wearing a revenue stream.
- Stale access and incomplete offboarding signal weak governance more than weak technology.
- No incident response plan is a red flag precisely because incidents are inevitable and the question is readiness.
- A short list of basics done consistently beats an impressive tool stack used inconsistently.
What sellers and buyers should each do early
The encouraging part is that almost none of this requires heroics. It requires doing the unglamorous work before the deal forces it, when the cost is low and the leverage is high.
For sellers, the goal is to walk into the data room with the answers already assembled. For buyers, the goal is to scope diligence around the obligations attached to the data, not just the functioning of the product. Both sides benefit from treating privacy and security as a value question, not a checkbox.
- Sellers: build a current data map, refresh privacy impact assessments, reconcile contractual commitments against operational reality, and verify your SOC 2 scope covers the right systems.
- Sellers: fix the cheap, obvious gaps (access reviews, offboarding, MFA, an incident response plan) before a buyer finds them.
- Buyers: scope diligence to the data and obligations, verify reports rather than accept them, and price remediation realistically into the model.
- Both: bring privacy and security expertise in early, before the letter of intent rather than during the closing scramble.
The quiet work is the deal work
Deal value does not usually disappear in a single dramatic event. It seeps out through a data map nobody can produce, a SOC 2 report that covers the wrong systems, contracts that promised what the company never built, and access lists no one can vouch for. Each finding is small. The accumulation is not.
The same discipline that protects the price also accelerates the deal. A seller who can answer the hard questions on day one signals a well-run business and shortens diligence. A buyer who knows where to look avoids both overpaying and being surprised after close. In an acquisition, the unglamorous privacy and security work is not a side task. It is the deal work, done early enough to count.
Related reading
- What is privacy and security due diligence in an acquisition
- Is a SOC 2 report enough to prove an acquisition target is secure