M&A Privacy Due Diligence: Navigating DPDPA, GDPR, and CCPA in 2026
In the dynamic landscape of mergers and acquisitions (M&A), privacy due diligence has evolved from a niche concern to a make-or-break factor. With India’s Digital Personal Data Protection Act, 2023 (DPDPA) now fully operational, Indian businesses engaging in M&A, whether as acquirers or targets, must meticulously compare their obligations against established global frameworks like the EU’s General Data Protection Regulation (GDPR) and California’s Consumer Privacy Act (CCPA), as amended by the CPRA. As of August 2026, understanding these nuances is critical for mitigating legal, reputational, and financial risks.
Foundational Principles and Lawful Processing in M&A
A core aspect of privacy due diligence involves establishing a lawful basis for processing personal data post-acquisition. The DPDPA introduces a distinct approach. Under Section 6, processing must be for a lawful purpose and based on consent, or fall under a “legitimate use” outlined in Section 7. Crucially for M&A, Section 8(8) of the DPDPA provides for “deemed consent” for processing necessary for “any merger or acquisition, de-merger, amalgamation or similar arrangement” where the data fiduciary is not the acquirer. This explicit provision offers a clear pathway for data transfer during M&A within India, provided notice is given.
In contrast, the GDPR, under Article 6, requires a lawful basis such as consent or legitimate interest. For M&A, legitimate interest (Article 6(1)(f)) is frequently invoked, necessitating a balancing test between the acquiring entity’s interest and the data subjects’ rights and freedoms. This can be more complex and open to interpretation than DPDPA’s explicit deemed consent. The CCPA, as amended by the CPRA, addresses M&A through specific exemptions. Personal information transferred as an asset in a merger, acquisition, or similar transaction is generally not considered a “sale” or “share” if the acquiring entity assumes the same obligations regarding the data (CPRA §1798.140(ad)(2)(C)). This offers a practical carve-out similar in intent to DPDPA’s deemed consent but framed as an exemption from “sale” rather than a positive basis for processing.
Cross-Border Data Transfers and Localization Considerations
The transfer of personal data across borders presents one of the most significant divergences. The DPDPA, in Section 16, empowers the Central Government to restrict the transfer of personal data to notified countries or territories. As of 2026, while specific restrictions may be in place, the DPDPA itself does not prescribe specific transfer mechanisms (like Standard Contractual Clauses or Binding Corporate Rules) for permissible transfers. This silence means that for transfers from India to non-restricted jurisdictions, the primary DPDPA focus remains on the data fiduciary’s accountability and security safeguards (Section 10), rather than explicit transfer tools. However, other Indian regulations, such as the Reserve Bank of India (RBI) guidelines for payment data localization or specific sectorial rules under the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, may still impose strict data localization requirements, making India potentially stricter in specific sectors.
The GDPR, conversely, maintains a highly prescriptive regime for international data transfers (Articles 44-50). Any transfer of personal data outside the European Economic Area must rely on an adequacy decision (Article 45), Standard Contractual Clauses (SCCs, Article 46(2)(c)), Binding Corporate Rules (BCRs, Article 46(2)(b)), or specific derogations (Article 49). This often necessitates extensive legal review and implementation of transfer agreements during M&A involving EU data. The CCPA/CPRA, primarily focused on consumer rights within California, does not have an equivalent framework for cross-border data transfers. Its emphasis is on ensuring consumer rights and protections apply regardless of where the data is ultimately stored, rather than regulating the transfer mechanisms themselves.
Accountability, Security, and Enforcement
Accountability and security are paramount across all regimes, though with varying emphasis. The DPDPA places significant obligations on Data Fiduciaries, including implementing reasonable security safeguards (Section 10(2)), ensuring data retention is limited to the necessary period (Section 10(3)), and notifying the Data Protection Board of India and affected data principals in case of a data breach (Section 17). For “Significant Data Fiduciaries” (SDFs), Section 19 mandates additional duties like conducting Data Protection Impact Assessments (DPIAs) and appointing an independent data auditor, making Indian law particularly stringent for larger entities. The DPDPA also carries substantial penalties (Schedule 1), with potential for director exposure, signaling a serious enforcement environment.
The GDPR’s accountability principle (Article 5(2), Article 24) is foundational, requiring organizations to demonstrate compliance. It mandates DPIAs (Article 35) for high-risk processing, the appointment of a Data Protection Officer (DPO, Article 37) for certain entities, and breach notification (Articles 33-34). GDPR fines (Article 83) are well-known for their severity. The CCPA/CPRA requires businesses to implement reasonable security procedures and practices (CPRA §1798.150) but does not mandate DPIAs or DPOs. Breach notification is governed by California’s general security breach law. Enforcement by the California Privacy Protection Agency (CPPA) and the Attorney General focuses on consumer rights and compliance with the Act’s provisions.
Practical Takeaway
For Indian businesses, GCs, and DPOs involved in M&A, a multi-faceted approach to privacy due diligence is indispensable. Start by mapping all data flows and identifying the jurisdictional nexus of personal data involved. Leverage DPDPA’s “deemed consent” (Section 8(8)) for domestic M&A but ensure comprehensive notice to data principals. For any target company processing EU data, meticulously verify GDPR-compliant cross-border transfer mechanisms (SCCs, BCRs) and assess their robustness post-Schrems II. When dealing with US entities, confirm the CCPA’s M&A exemptions are met, particularly regarding assuming the same data obligations. Beyond legal frameworks, scrutinize the target’s data security posture, incident response plans, and data retention policies against DPDPA’s Section 10 requirements. Finally, consider whether the combined entity will qualify as a Significant Data Fiduciary under DPDPA, triggering additional obligations like DPIAs and independent audits from day one. Proactive, integrated privacy due diligence is not just about compliance; it’s about safeguarding asset value and ensuring business continuity in a globally interconnected data economy.