TREADSTONE LAW · ONTARIO · DIGITAL LEGAL SERVICES · EST. MMXXI ·TSL
Home/Articles/Buying & Selling a Business
№ 102 Buying & Selling a Business

Cybersecurity and Data Privacy Due Diligence When Buying a Business in Ontario

Learn what an Ontario business buyer should check about a target's data practices and past breaches before taking on its customer data.

Buying & Selling a Business5 min readTSLBy the Treadstone Law team · OntarioUpdated 2026-07
All articles
Key takeaways
  • When you buy a business, you're generally also acquiring — or, in an asset purchase, arranging to receive — its customer records, employee files, and often the systems and vendors that…
  • - [ ] What kinds of personal information does the business collect — customers, employees, or both — and where is it stored?
  • Federal privacy law does include specific provisions that generally allow personal information to be shared between a buyer and seller for due diligence purposes, and to complete a…

Buying a business today usually means buying a customer database, employee records, and whatever systems hold them — even when the business itself has nothing to do with technology. A restaurant with a loyalty program, a clinic with patient files, a retailer with an e-commerce list: all of them carry data risk that doesn't show up on a balance sheet the way inventory or equipment does.

Data privacy due diligence asks a simple question before you take that data on: does the target actually handle it responsibly, and are there past problems you're about to inherit?

Why Customer and Employee Data Is Part of Due Diligence

When you buy a business, you're generally also acquiring — or, in an asset purchase, arranging to receive — its customer records, employee files, and often the systems and vendors that store them. That data comes with legal obligations attached to it under Canada's federal private-sector privacy law, which generally requires businesses to collect, use, and disclose personal information responsibly and to safeguard it appropriately. A data practice problem inherited from the seller doesn't stay the seller's problem once you're the one holding the data.

There's also a practical dimension separate from legal compliance: a poorly secured customer database, an outdated point-of-sale system, or a history of phishing incidents can represent real operational risk to the business you're about to run.

What to Ask About the Target's Data Practices

Share Sale vs Asset Sale: Different Privacy Questions

QuestionShare PurchaseAsset Purchase
Does the buyer simply inherit the seller's existing data practices?Yes — the same corporation, and its existing consents and practices, continueNot automatically — the buyer is generally receiving the data as part of the asset transfer, not stepping into the seller's shoes
Does transferring customer data as part of the sale raise its own privacy question?Less directly, since the corporate entity doesn't changeYes — moving personal information from the seller to a new, separate business is itself a use of that data worth thinking through carefully
Does past history of a breach transfer with the deal?Yes, along with the corporation's other liabilitiesDepends on what liabilities the asset purchase agreement specifically assumes

Federal privacy law does include specific provisions that generally allow personal information to be shared between a buyer and seller for due diligence purposes, and to complete a genuine sale of a business, without requiring fresh consent from every individual customer — provided the information is used only for purposes related to the transaction and is kept secure. Exactly how that applies to a specific deal is a fact-specific question worth confirming with a lawyer rather than assuming.

Past Breaches and Incidents

Protecting Yourself in the Purchase Agreement

Frequently asked questions

Does a small, non-tech business really need to worry about this?

Yes, to some degree — almost every business holds some customer or employee personal information, even if it's just a client list or payroll records. The scale of the review should match the scale of the risk, but the question is rarely irrelevant entirely.

What if the seller never mentions a past data breach and I find out about it later?

This is exactly what representations, warranties, and indemnities in the purchase agreement are meant to address — but prevention through direct questions before closing is far better than trying to recover losses afterward.

Do I need consent from every customer to transfer their data as part of an asset purchase?

Not necessarily. Federal privacy law includes provisions generally allowing personal information to move between parties to complete a legitimate business transaction, subject to conditions like using it only for transaction-related purposes and keeping it secure. Whether a specific transfer fits within those provisions is worth confirming with a lawyer rather than assuming either way.

Should I bring in an IT specialist as well as a lawyer?

For any business where data or technology systems are meaningfully important to operations, yes — a lawyer addresses the legal and contractual side, while a technical specialist can assess whether the systems themselves are secure and current.

This article is general information, not legal advice. Reading it does not create a lawyer-client relationship. Ontario laws, tax rates, and government programs change, and how the law applies depends on your specific facts. For advice about your situation, speak with a licensed Ontario lawyer. Treadstone Law is licensed by the Law Society of Ontario — reach us at 1-844-900-1070 or start a file online.

This is a business purchase or sale question

Start a file online — flat, published fees, reviewed by a licensed Ontario lawyer before a dollar is owed.

ContactStart a File →