How Mergers and Acquisitions Complicate DPDP Data Inventories
An acquired company's data inventory is rarely as clean as the diligence deck suggests. Here is what actually needs checking before and after close.
Why data inventories break down in M&A
An acquired company's personal data inventory — if one exists at all — was built to answer that company's own questions, using its own categories and its own assumptions about legal basis. Merging it into the acquirer's inventory isn't a copy-paste exercise; it's a reconciliation of two different data models that were never designed to align.
Worse, many smaller acquisition targets have no real inventory at all, just institutional knowledge scattered across a few people who may not stay through integration. Diligence needs to test for that gap directly rather than accepting a vendor list or a policy document as a proxy for an actual inventory.
The diligence-phase questions that matter
Before close, get specific answers on the target's legal basis for its core data sets — is collection resting on consent under Section 6 or a claimed Section 7 legitimate use, and does that basis actually hold up. Ask whether the target has ever had a breach, what its vendor contracts say about sub-processing, and whether any of its data involves children or crosses borders in ways that could trigger Section 16 restrictions.
Where the target claims Significant Data Fiduciary status or is close to the threshold, confirm whether it has been meeting the Section 10 obligations — resident DPO, independent audits, periodic DPIA — since a gap here becomes the acquirer's problem the moment the deal closes.
Post-merger integration priorities
Immediately after close, prioritize reconciling consent records and legal bases before merging customer databases outright. Combining two customer lists without checking that each contact's original consent or legitimate use basis still supports the acquirer's intended processing purposes is one of the most common post-merger compliance failures.
Treat the acquired company's systems as an unassessed vendor environment until proven otherwise — apply the same security and access review you would to a new third-party processor, since inherited systems often carry inherited gaps that predate the deal.
Where to go next
Run the acquired entity through the Personal Data Inventory and Vendor Assessment tools as part of integration, treating the results as a baseline rather than assuming the target's own documentation is complete or current.