Can a data breach the seller never disclosed become a liability I inherit?
It can, and the risk again depends heavily on deal structure. In a share sale, liability connected to a past data breach — regulatory exposure, claims from affected individuals, contractual liability to business partners — generally stays with the corporation, since it's the same legal entity that experienced the breach, whether or not it was ever disclosed to you before closing. In a properly structured asset sale, liability for a breach that happened entirely before closing can generally be left with the selling entity, but this depends on how clearly your purchase agreement addresses it, since a breach isn't always a clean, easily identified "liability" the way an unpaid invoice is.
There's also an ongoing risk regardless of structure: if the seller never properly addressed the breach's cause, the same vulnerability may still exist in systems or practices you're acquiring, meaning you could inherit not the old liability, but a live, ongoing risk of a fresh incident under your own ownership.
Ask specifically about any past data breaches or security incidents, get representations and warranties addressing this, and have your own IT or security review assess whether the underlying vulnerability was actually fixed. A Treadstone business lawyer can help draft protections around undisclosed past incidents.
Key takeaways
- A share sale generally keeps past breach liability with the continuing corporate entity.
- A properly drafted asset sale can leave old breach liability with the seller, if addressed clearly.
- An unfixed underlying vulnerability can create a fresh risk for you, separate from old liability.
- Ask directly about past incidents and have your own IT review confirm the cause was actually fixed.