A practical guide to data privacy due diligence — how PE, search funds, and M&A buyers size lawful-processing risk, rights operations, transfers, and enforcement exposure before specialist counsel deep-dives the data room.
Data privacy due diligence is the workstream that asks whether personal data is processed lawfully, transparently, and in a way that survives close. It is not a synonym for cybersecurity. Cyber asks whether systems can be breached. Privacy asks whether the business is allowed to collect and use the data it has, whether individuals can exercise rights, and whether regulators or class plaintiffs have a clean path to post-close pain.
Scope expands for consumer apps, adtech, marketplaces, healthcare, fintech, HR-tech, B2B SaaS with end-user telemetry, and any company with EU/UK users or multi-state U.S. consumer data. Enterprise B2B sellers still need vendor DPAs, employee data hygiene, and product telemetry review. Light "we only have business emails" stories often fail under scrutiny.
| Pillar | What you prove | Typical owners |
|---|---|---|
| 1. Data map & inventory | Systems, purposes, categories, volumes, retention, owners | Privacy + engineering + legal |
| 2. Lawful basis & notices | Consent/contract/legitimate interests, policies, cookies, product UX | Privacy counsel + product |
| 3. Rights & ops (DSAR) | Access, deletion, correction, portability, opt-out workflows | Ops + support + privacy |
| 4. Transfers & vendors | Cross-border tools, SCCs, DPAs, sub-processors, sales of data | Legal + procurement |
| 5. Incidents & enforcement | Breach log, regulator contact, complaints, class risk | Legal + security + privacy |
| 6. Close & go-forward | SPA privacy reps, post-close program, budget, DPO/roles | Deal counsel + buyer privacy |
| Stage | Typical work | Access needed | Decision use |
|---|---|---|---|
| Pre-LOI screen | Public policy/cookie review, app permissions, breach news, sector risk | Public only | Kill or price privacy risk early |
| Post-LOI data room | ROPA, DPIAs, DPAs, breach register, transfer tools, complaints | VDR | Confirm underwriting; plan holdbacks |
| Specialty deep dive | Counsel review of high-risk products, prior enforcement, dark patterns | Counsel + product demos | Structure indemnities and fixes |
| Pre-close / day-1 | Reps schedule, budget, DPO/privacy owner, remediation plan | Board/ops authority | Fund path + compliance continuity |
Traditional privacy diligence (privacy counsel + multi-regime review) often starts around $15K–$100K+ for middle-market multi-jurisdiction targets and scales with adtech, health data, or prior enforcement. A structured public-information pack at $49 (or $39.20 with DI20-WELCOME) helps deal teams triage privacy-heavy names before funding full specialty scopes.
| Severity | Signal | Why it matters |
|---|---|---|
| Deal-killer | Unlawful sale/share of personal data at material scale | Enforcement + class + product redesign |
| Deal-killer | EU/UK data transferred without valid transfer mechanism | Stop-processing risk; hard remediation |
| Deal-killer | Material undisclosed breach with active regulator inquiry | Unknown fine and reputation load |
| High | No usable processing inventory / ROPA | Unknown footprint; integration landmines |
| High | DSAR / deletion backlog or systematic non-compliance | Statutory clocks; class catalyst |
| High | Children's data or sensitive categories without controls | Heightened regimes (COPPA, HIPAA, etc.) |
| Watch | Stale privacy policy vs product reality | Usually fixable; still a signal of weak ops |
| Watch | Vendor DPAs missing for low-risk tools only | Admin debt if core vendors are covered |
| Approach | Typical cost | Timeline | Best use |
|---|---|---|---|
| Public first-pass pack | $49 / target | Minutes to same day | Screen many names before LOI |
| Counsel privacy memo (single regime) | ~$10K–$35K | 1–2 weeks | Clear primary jurisdiction |
| Multi-regime privacy DD + product review | $25K–$100K+ | 2–4 weeks | Consumer/global data-heavy targets |
| Forensic / breach residual review | Deal-specific | Parallel to confirmatory | Prior incidents or open inquiries |
Use as a buyer workplan. Tag items Deal-Killer / High / Watch as evidence arrives. Groups below mirror how deal teams staff the privacy workstream.
| Workstream | Primary question | Overlap with privacy |
|---|---|---|
| Cybersecurity DD | Can systems be compromised? | Breach impact, access control, encryption |
| Legal DD | What contracts and liabilities bind the company? | DPAs, customer MSAs, litigation |
| Regulatory DD | What licenses and supervisors govern the business? | Sector privacy rules, consent orders |
| Privacy DD | Is personal data processed lawfully and accountably? | Core: inventory, rights, transfers, notices |
Before LOI, teams rarely get a full ROPA. They still can: (1) read public privacy and cookie notices against the live product; (2) note multi-jurisdiction language and high-risk data types; (3) search for breach disclosures and enforcement news; (4) score whether the business model depends on data sale, heavy tracking, or sensitive categories; (5) shortlist names that need early privacy counsel vs names that can wait for confirmatory. A $49 structured pack is built for that triage layer — not as a substitute for counsel opinions or certifications.
Order a structured first-pass diligence pack on a named target, or start with a free brief. Specialist privacy counsel still owns multi-regime opinions — use public screening to spend that budget on the right shortlist.