Post

M&A Privacy Due Diligence: DPDPA, GDPR, and CCPA Compared

M&A Privacy Due Diligence: DPDPA, GDPR, and CCPA Compared

As the global M&A landscape continues to evolve, privacy considerations have moved from a niche concern to a critical component of due diligence. For businesses operating in or looking to acquire entities in India, the Digital Personal Data Protection Act, 2023 (DPDPA) now forms the bedrock of these considerations, requiring a fresh comparative lens against established frameworks like the EU’s General Data Protection Regulation (GDPR) and California’s Consumer Privacy Act (CCPA), as amended by the CPRA. Understanding these differences is crucial for mitigating post-acquisition privacy risks.

Legal Basis and Consent Post-Acquisition

A fundamental aspect of privacy due diligence in M&A is the legal basis for processing personal data, particularly how existing consent transfers or needs to be re-established. Under the DPDPA, a Data Fiduciary (equivalent to a data controller) must process personal data lawfully, primarily based on the Data Principal’s (data subject’s) consent (Section 6). The purpose for which data was collected must be clear and specific (Section 6(1)(a)). Post-acquisition, if the acquiring entity intends to process data for new purposes, fresh consent may be required. While DPDPA introduces “deemed consent” for certain legitimate uses, such as employment or public interest (Section 7), M&A transactions typically necessitate a careful review of consent validity for ongoing processing.

In contrast, the GDPR similarly mandates a lawful basis for processing, with consent (Article 6(1)(a)) being one of several options, alongside legitimate interests (Article 6(1)(f)), contract necessity, or legal obligation. An acquiring entity under GDPR must ensure that the original legal basis remains valid for continued processing or establish a new one. The GDPR’s emphasis on transparency (Article 5(1)(a)) means data subjects must be informed of changes to processing activities, which an M&A often entails.

The CCPA/CPRA approaches this differently. While it doesn’t explicitly focus on “legal basis” like DPDPA or GDPR, it grants consumers specific rights over their personal information. Crucially for M&A, the CCPA includes an exception where the transfer of personal information as part of a merger, acquisition, bankruptcy, or other transaction where a business sells, transfers, or spins off all or a portion of its assets is generally not considered a “sale” or “sharing” requiring an opt-out (Section 1798.140(ad)(2)(D)). This provides some relief during the transaction itself, though the acquiring entity must still comply with all other consumer rights, including notice at collection (Section 1798.100(b)) and purpose limitation post-acquisition. The DPDPA is silent on such a specific carve-out for M&A, implying that general consent and purpose limitation principles apply throughout.

Risk Assessments and Accountability Frameworks

India’s DPDPA introduces the concept of a “Significant Data Fiduciary” (SDF) (Section 10), which is determined based on factors like the volume and sensitivity of personal data processed, risk to Data Principals, and potential impact on India’s sovereignty. An M&A transaction could potentially elevate an entity to SDF status, triggering additional obligations such as appointing a Data Protection Officer (DPO) (Section 10(2)(a)), conducting Data Protection Impact Assessments (DPIAs) (Section 10(2)(b)), and undertaking periodic audits (Section 10(2)(c)). This is a stricter, more prescriptive approach for specific entities.

The GDPR also mandates DPIAs (Article 35) when processing is likely to result in a high risk to the rights and freedoms of natural persons. This is a risk-based assessment, not tied to a specific “SDF” designation. M&A activities, especially those involving new technologies or large-scale data processing, frequently trigger a GDPR DPIA. Both DPDPA and GDPR emphasize accountability, requiring Data Fiduciaries/controllers to demonstrate compliance (DPDPA Section 8; GDPR Article 5(2), Article 24).

The CCPA/CPRA, while requiring businesses to implement reasonable security procedures and practices (Section 1798.81.5(c)), does not have an explicit, mandatory DPIA requirement or a direct equivalent to the DPDPA’s SDF or GDPR’s DPO for all businesses. Instead, it focuses on consumer rights and opt-out mechanisms. This makes the DPDPA and GDPR frameworks generally more prescriptive regarding proactive risk assessments and governance structures.

Cross-Border Data Transfers and Localisation

Cross-border data transfers are a critical area where DPDPA significantly diverges from GDPR and introduces unique considerations not found in CCPA. Under DPDPA, the Central Government has the power to notify countries or territories to which a Data Fiduciary may transfer personal data (Section 16). This “whitelist” approach implies that transfers to unlisted countries would be prohibited, potentially making international M&A more complex if the acquiring entity or its data processing infrastructure resides in a non-notified country. This is a potentially stricter and less flexible mechanism than GDPR.

The GDPR, in contrast, offers a range of mechanisms for international data transfers (Chapter V, Articles 44-50), including adequacy decisions (Article 45), Standard Contractual Clauses (SCCs) (Article 46(2)(c)), and Binding Corporate Rules (BCRs) (Article 47). These mechanisms provide more avenues for transfers to countries without an adequacy decision, offering greater flexibility for multinational corporations.

Beyond the DPDPA, Indian businesses in specific sectors, particularly financial services, must contend with sector-specific data localisation requirements. The Reserve Bank of India (RBI) Circular on Storage of Payment System Data (2018) mandates that all payment system data generated in India must be stored only within India. Similarly, RBI’s Master Direction on Outsourcing of Financial Services (2023) also has implications for data handling. These RBI rules are significantly stricter than anything in GDPR or CCPA, which generally do not impose data localisation mandates. The CCPA does not have specific provisions governing cross-border data transfers, focusing instead on consumer rights within California.

Data Breach Management

All three frameworks impose obligations regarding data breach notifications, though with varying thresholds

This post is licensed under CC BY 4.0 by the author.