M&A Privacy Due Diligence: Navigating DPDPA, GDPR, and CCPA
Mergers and acquisitions (M&A) inherently involve extensive data sharing, making privacy due diligence a critical, complex undertaking. With the Digital Personal Data Protection Act, 2023 (DPDPA) now fully operational, Indian entities engaging in M&A, whether as acquirers or targets, must anchor their strategies in its framework while also navigating the stringent requirements of global regimes like the GDPR and CCPA. This comparative analysis highlights key considerations for an India-first audience.
Lawful Basis for Data Sharing in M&A Due Diligence
The foundation of any data processing activity, including sharing data during M&A due diligence, rests on a lawful basis. The DPDPA provides a distinct advantage for Indian entities in this regard. Section 7(e) explicitly identifies “merger, amalgamation, or acquisition” as a “legitimate use” for processing personal data, provided it is “necessary for that purpose.” This clear statutory recognition simplifies the legal basis for sharing employee, customer, and vendor data during due diligence within India, making the DPDPA potentially looser than its European counterpart on this specific point.
In contrast, the GDPR, under Article 6, typically relies on “legitimate interests” (Article 6(1)(f)) for M&A due diligence. This requires a careful balancing test between the legitimate interests of the acquiring or target entity and the rights and freedoms of data subjects, which can be a more nuanced and potentially challenging assessment. Consent (Article 6(1)(a)), while an option, is often impractical to obtain from all data subjects during M&A.
The CCPA, while not requiring a “lawful basis” in the GDPR sense, permits the sharing of personal information for “business purposes” (Cal. Civ. Code § 1798.140(e)). Importantly, transfers of personal information as part of a merger where the acquiring entity assumes the obligations to comply with CCPA are generally not considered a “sale” or “sharing” requiring opt-out (Cal. Civ. Code § 1798.140(ad)(2)(D)). This provides a clear path, focusing more on consumer notice and rights rather than a pre-defined legal ground for processing.
Cross-Border Data Transfer Frameworks
One of the most significant differentiators lies in cross-border data transfer rules. The DPDPA, under Section 16, adopts a “permissive until restricted” approach. It states that the Central Government may restrict cross-border transfers to certain countries or territories through notification. Crucially, until such notification occurs, cross-border transfers are generally permitted, subject to other DPDPA obligations. This makes the DPDPA’s general stance on international data transfers looser than the GDPR.
The GDPR, conversely, imposes strict requirements for international transfers of personal data outside the European Economic Area (Chapter V, Articles 44-50). These typically necessitate an adequacy decision from the European Commission (Article 45), Standard Contractual Clauses (SCCs) (Article 46(2)(c)), or Binding Corporate Rules (BCRs) (Article 46(2)(b)), making it a stricter regime for data flowing out of the EU.
The CCPA does not have specific cross-border data transfer mechanisms akin to the GDPR. Its focus remains on the rights of California residents, irrespective of where their data is stored or processed, provided the entity meets the CCPA’s applicability thresholds.
Data Minimization, Security, and Principal Rights
All three frameworks emphasize data minimization, robust security, and data principal rights, though with varying degrees of prescription. The DPDPA mandates data fiduciaries to process personal data only for a specified purpose and to collect only such data as is necessary for that purpose (Section 6(3)). It also requires reasonable security safeguards to prevent data breaches (Section 9). Data principals are granted rights such as access to information, correction, erasure, and grievance redressal (Sections 11-14).
Similarly, the GDPR champions data minimization (Article 5(1)(c)) and requires appropriate technical and organisational measures to ensure a level of security appropriate to the risk (Article 32). Data subject rights (Articles 12-22) are extensive, including the right to access, rectification, erasure, and data portability.
The CCPA requires businesses to implement reasonable security procedures and practices appropriate to the nature of the personal information (Cal. Civ. Code § 1798.81.5(d)). It grants California consumers rights to know, delete, correct, and opt-out of the sale or sharing of their personal information (Cal. Civ. Code § 1798.120-121). While the principles are similar, the DPDPA’s and GDPR’s emphasis on accountability and specific processing principles can be more prescriptive in their implementation details.
Specific Indian Nuances and Enforcement
Beyond the DPDPA, Indian businesses must also contend with sectoral regulations, which can be stricter. For instance, the Reserve Bank of India (RBI) mandates data localisation for payment system data, requiring all data relating to payment systems to be stored only in India (RBI/2017-18/153, DPSS.CO.PD.No.1633/02.14.008/2017-18). This means due diligence involving financial sector targets requires careful verification of data storage practices, a requirement not directly found in GDPR or CCPA. While the DPDPA largely supersedes the IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, the spirit of data protection and specific sectoral overlays remain crucial.
Enforcement under the DPDPA, handled by the Data Protection Board of India (Section 19), carries substantial penalties for non-compliance (Section 33, Schedule 1), aligning with the trend of significant fines seen under GDPR (Article 83) and CCPA (Cal. Civ. Code § 1798.155).
Practical Takeaway
For Indian businesses, GCs, and DPOs involved in M&A, a multi-layered approach to privacy due diligence is indispensable. While the DPDPA offers a clear “legitimate use” for M&A data sharing and a currently permissive stance on cross-border