Author: Suhani Arora
College: Svkm’s NMIMS, School Of Law, Mumbai
LinkedIn Profile: https://www.linkedin.com/in/suhani-arora-a62902257
To the Point
Every due diligence checklist used in Indian M&A practice runs through more or less the same set of boxes: title to shares or assets, pending litigation, tax exposure, labour compliance, intellectual property ownership. Data protection has never had a permanent line of its own on that list, usually surfacing, if at all, as a paragraph tucked inside the IT or IP annexure. That has to change now that the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025 are actually operative, not theoretical. A target company today does not just bring assets, employees and contracts to the table; it brings a data fiduciary status, a consent architecture built by someone else, and a penalty exposure that can run into hundreds of crores if that architecture does not hold up. What corporate lawyers tend to assume by habit, that data simply vests in the acquirer the way any other asset does on a scheme of arrangement or a business transfer, is not something the DPDP Act actually guarantees. This article looks at why that gap matters, where it shows up in a transaction, and what a due diligence process built for 2026 needs to look like.
Use of Legal Jargon
The vocabulary of Indian M&A practice and the vocabulary of the DPDP Act now have to sit inside the same due diligence report, and the two do not always translate cleanly into each other. A share purchase agreement transfers control of the corporate entity; a business transfer agreement moves specific assets and liabilities, often on a slump sale basis; a scheme of arrangement requires NCLT sanction under Sections 230 to 232 of the Companies Act, 2013. None of these instruments, by itself, settles who the data fiduciary is once the deal closes, or whether the consent the target originally collected from its data principals’ travels with the business or has to be refreshed. The DPDP Act works off its own closed set of categories: data fiduciary, data principal, consent manager, and, for entities crossing a threshold of volume or sensitivity of processing, Significant Data Fiduciary, a status that brings its own Data Protection Officer requirement and audit obligations. A due diligence report that flags “IP and technology” risk without separately assessing consent architecture, breach history and SDF exposure is incomplete by the standard this statute sets. On the documentation side, the practical response sits in the usual toolkit: representations and warranties tied specifically to DPDP compliance, a disclosure schedule that itemises the target’s actual data processing activities rather than gesturing at “applicable law,” indemnity clauses sized against the Act’s own penalty schedule, and, where the risk cannot be priced with confidence before signing, an escrow or holdback tied to a post-closing compliance audit. Whether a sandbagging clause should protect an acquirer who signs with knowledge of a live compliance gap is itself becoming a genuine negotiating point in Indian technology and fintech deals, where data exposure is often the single largest contingent liability on the table.
The Proof
Section 7 of the DPDP Act sets out what the Act calls “certain legitimate uses” – the situations in which a data fiduciary can process personal data without going back to the data principal for consent. It is a closed list: voluntary provision of data for a specified purpose, delivery of state subsidies and benefits, compliance with a legal obligation or a court order, medical emergencies, disaster response, and employment-related processing, among a handful of others. Nowhere on that list is there anything resembling a merger, an acquisition, or a change of corporate control. Contrast this with the ground many Indian lawyers instinctively reach for when advising on a cross-border deal – the GDPR’s “legitimate interest” basis under Article 6(1)(f), which EU counsel have used, with varying degrees of comfort, to justify continued processing of a target’s customer data after an acquisition. The DPDP Act has no equivalent balancing test. If the consent a target originally collected was tied to a specific purpose and a specific notice naming that data fiduciary, processing the same data for the same purpose under new ownership may still call for either fresh consent or a genuine legal argument that the identity of the controlling entity was immaterial to what the data principal agreed to. Most Indian share purchase agreements, at present, do not address this at all; they assume the customer base transfers the way inventory does.
The second layer is Significant Data Fiduciary status. A target that processes personal data at a volume or sensitivity that brings it within the government’s SDF criteria inherits, on acquisition, obligations that go well beyond consent management: appointment of a Data Protection Officer based in India, periodic Data Protection Impact Assessments, and independent data audits. The compliance runway for these obligations has been structured through a phased implementation timeline following the notification of the DPDP Rules. As the Government has indicated that compliance timelines may evolve over time, an acquirer who discovers SDF exposure only after signing may find that the available compliance window is shorter than anticipated. Diligence conducted before signing, not after, is the point at which this status can genuinely be negotiated into price or structure rather than fought out through an indemnity claim eighteen months later.
A third complication sits in Section 16, which governs the transfer of personal data outside India. The provision adopts what practitioners have taken to calling a negative list model: transfer is permitted to any country the Central Government has not specifically restricted by notification. As of mid-2026, no country has been placed on that list, which gives cross-border structures – an Indian target routing customer data through a Singapore or US-based processor, for instance – a permissive environment to operate in today. But Rule 15 gives the government open-ended authority to impose conditions on transfers generally, not only to notify restricted countries, and the Act contains no grandfather clause protecting arrangements that were compliant when they were first built. A due diligence exercise that confirms cross-border transfer is “currently legal” without mapping where the data physically goes, and under what contractual safeguards, is answering last year’s question rather than the one that matters for a deal closing in the months ahead.
Finally, there is the question of what an acquirer inherits the moment a deal closes. Under Rule 7 of the DPDP Rules, a data fiduciary that suffers a personal data breach must notify the Data Protection Board without delay and follow up with a full report within seventy-two hours, and separately notify every affected data principal – a dual obligation with no materiality threshold, which is stricter than the GDPR’s equivalent, where notification to individuals can be skipped if the breach is not judged to carry a high risk. If a target’s incident response infrastructure cannot meet that clock, the acquirer inherits the shortfall the day the deal closes, along with a Schedule that caps penalties for a failure of reasonable security safeguards at ₹250 crore and for a failure to notify a breach at ₹200 crore. Pricing that risk properly requires an actual breach history review going back several years, not a single warranty stating that the target “has not suffered a material data breach,” a sentence precise enough to survive a warranty claim while telling an acquirer almost nothing about real exposure.
Abstract
This article examines a structural gap in Indian merger and acquisition practice: due diligence frameworks built around the Companies Act, SEBI regulations and standard commercial risk categories have not yet caught up with the compliance architecture that the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025 impose on any business that processes personal data, which in India’s current digital economy is functionally every business of any scale. The Act’s closed list of “legitimate uses” under Section 7 does not recognise a merger or business transfer as an independent basis for processing personal data without consent, which unsettles the assumption, carried over from ordinary asset transfer principles, that a customer or user database vests automatically in the acquirer. Layered on top of that gap are Significant Data Fiduciary obligations that can attach to a target without warning, a cross-border transfer regime under Section 16 that is permissive today but structurally unstable, and a breach notification obligation under Rule 7 with no materiality threshold and penalties running as high as ₹250 crore. Drawing on the constitutional foundation laid in Puttaswamy, the Competition Commission of India’s 2024 order against Meta and WhatsApp, and the UK Information Commissioner’s Office’s 2020 penalty notice against Marriott, this piece argues that data protection diligence needs to become a distinct, statute-literate workstream in Indian deal practice, with its own representations, its own disclosure schedule, and its own place in how transaction risk gets priced.
Case Laws
Three decisions, from three different regulators and three different jurisdictions, map the shape of this risk better than commentary alone can.
Justice K.S. Puttaswamy (Retd.) v. Union of India, (2017) 10 SCC 1, is the constitutional starting point. A nine-judge bench of the Supreme Court held that the right to privacy is protected under Articles 14, 19 and 21 of the Constitution, and specifically recognised informational privacy, control over the dissemination of one’s own personal information, as part of that right. The DPDP Act is, in a fairly direct sense, Parliament’s statutory answer to that judgment, and its consent-centric design traces back to the Court’s insistence that individuals retain a meaningful say over how their data is used, against both state and private actors. For M&A purposes, the relevant takeaway is why Section 7 was drafted as a closed list rather than an open-ended reasonableness test: a broader, GDPR-style legitimate interest provision was considered during the drafting process and dropped, partly because it sat uneasily with the proportionality standard Puttaswamy set for any interference with informational privacy.
The second is In Re: Updated Terms of Service and Privacy Policy for WhatsApp Users, decided by the Competition Commission of India on 18 November 2024, which fined Meta Platforms roughly ₹213 crore and directed WhatsApp to stop conditioning access to its service on users accepting data-sharing with its parent company. The case did not arise under the DPDP Act, since the relevant conduct predated its enforcement, but it is the clearest domestic precedent for a regulator treating mandatory data-sharing between a subsidiary and its controlling parent as actionable in its own right, precisely the fact pattern that arises whenever an acquirer wants a target’s data principal base folded into its own systems after closing. The Delhi High Court, in earlier rounds of the same dispute, had already described the underlying privacy policy as placing users in a take-it-or-leave-it position. Read together, the CCI order previews how an Indian regulator is likely to treat post-acquisition data integration under a statute that, unlike the Competition Act, now carries dedicated penalties for exactly this kind of conduct.
The third is the UK Information Commissioner’s Office’s 2020 penalty notice against Marriott International, arising from a breach at Starwood Hotels that went undetected from 2014 through 2018, spanning Marriott’s 2016 acquisition of the Starwood group. The ICO’s final penalty, reduced to £18.4 million from an initially proposed £99 million, rested on a finding that Marriott’s due diligence before the acquisition, and its ongoing oversight of Starwood’s systems afterward, fell short of what the GDPR’s accountability principle required. The ICO was explicit that due diligence in a corporate acquisition is not a one-off exercise completed before signing; the obligation to understand what personal data has been acquired, and how well it is protected, continues after closing. Nothing in the DPDP Act’s text directly imports that standard, but the Marriott notice is the precedent Indian counsel already reach for when explaining to a client why the data protection workstream does not end the day the SPA is executed.
Conclusions
None of these calls for a wholesale redesign of Indian M&A practice. It calls for a fourth or fifth-line item on a checklist that already runs to several pages, sitting alongside tax, labour and IP, and taken just as seriously once it is there. In practice, that means confirming a target’s data fiduciary and SDF status before signing rather than after, mapping where personal data actually travels rather than accepting a one-line assurance that transfers are “compliant,” reviewing breach history over a period long enough to catch what a target’s own incident response team might have missed, and drafting representations and indemnities specific to the DPDP Act’s own penalty structure rather than borrowed wholesale from a generic “compliance with applicable law” clause. The DPDP Rules were notified in November 2025, with key compliance obligations being introduced through a phased implementation timeline extending through May 2027, which gives Indian deal lawyers a genuine window to build this practice properly rather than reactively, the way GDPR due diligence in Europe was largely built after Marriott and British Airways had already been fined. Given how consent-driven and penalty-heavy this statute is, that window is worth using now, while it is still open.
