- When you buy a business, you're generally also acquiring — or, in an asset purchase, arranging to receive — its customer records, employee files, and often the systems and vendors that…
- - [ ] What kinds of personal information does the business collect — customers, employees, or both — and where is it stored?
- Federal privacy law does include specific provisions that generally allow personal information to be shared between a buyer and seller for due diligence purposes, and to complete a…
Buying a business today usually means buying a customer database, employee records, and whatever systems hold them — even when the business itself has nothing to do with technology. A restaurant with a loyalty program, a clinic with patient files, a retailer with an e-commerce list: all of them carry data risk that doesn't show up on a balance sheet the way inventory or equipment does.
Data privacy due diligence asks a simple question before you take that data on: does the target actually handle it responsibly, and are there past problems you're about to inherit?
Why Customer and Employee Data Is Part of Due Diligence
When you buy a business, you're generally also acquiring — or, in an asset purchase, arranging to receive — its customer records, employee files, and often the systems and vendors that store them. That data comes with legal obligations attached to it under Canada's federal private-sector privacy law, which generally requires businesses to collect, use, and disclose personal information responsibly and to safeguard it appropriately. A data practice problem inherited from the seller doesn't stay the seller's problem once you're the one holding the data.
There's also a practical dimension separate from legal compliance: a poorly secured customer database, an outdated point-of-sale system, or a history of phishing incidents can represent real operational risk to the business you're about to run.
What to Ask About the Target's Data Practices
- [ ] What kinds of personal information does the business collect — customers, employees, or both — and where is it stored?
- [ ] Has the business ever experienced a data breach, ransomware incident, or unauthorized access, disclosed or not?
- [ ] Does the business have a written privacy policy, and does actual practice match what it says?
- [ ] Who has access to sensitive systems and data, and how is that access controlled?
- [ ] Are third-party vendors (payment processors, cloud providers, marketing platforms) involved in handling the data, and what do those vendor agreements say about data protection?
- [ ] Is the business's technology current, or running on outdated systems that carry known vulnerabilities?
Share Sale vs Asset Sale: Different Privacy Questions
| Question | Share Purchase | Asset Purchase |
|---|---|---|
| Does the buyer simply inherit the seller's existing data practices? | Yes — the same corporation, and its existing consents and practices, continue | Not automatically — the buyer is generally receiving the data as part of the asset transfer, not stepping into the seller's shoes |
| Does transferring customer data as part of the sale raise its own privacy question? | Less directly, since the corporate entity doesn't change | Yes — moving personal information from the seller to a new, separate business is itself a use of that data worth thinking through carefully |
| Does past history of a breach transfer with the deal? | Yes, along with the corporation's other liabilities | Depends on what liabilities the asset purchase agreement specifically assumes |
Federal privacy law does include specific provisions that generally allow personal information to be shared between a buyer and seller for due diligence purposes, and to complete a genuine sale of a business, without requiring fresh consent from every individual customer — provided the information is used only for purposes related to the transaction and is kept secure. Exactly how that applies to a specific deal is a fact-specific question worth confirming with a lawyer rather than assuming.
Past Breaches and Incidents
- A disclosed past breach isn't automatically a deal-breaker, but it needs a clear answer: what happened, what data was affected, how it was handled, and what's been fixed since.
- An undisclosed breach discovered after closing is a much bigger problem — both because it suggests a pattern of poor practices, and because you may now bear responsibility for a problem you didn't cause or know about.
- Ask specifically about ransomware, phishing incidents affecting staff, and any regulatory complaints or inquiries — not just headline-level "have you ever been hacked" questions.
Protecting Yourself in the Purchase Agreement
- Representations and warranties confirming the target's data practices, compliance with applicable privacy law, and disclosure of any past breaches or incidents.
- An indemnity for losses arising from undisclosed data issues that surface after closing.
- A technical review of key systems where the business depends heavily on customer data or e-commerce, separate from the legal review.
- Vendor agreement review, confirming third-party providers handling the data have their own adequate protections in place.
Frequently asked questions
Does a small, non-tech business really need to worry about this?
Yes, to some degree — almost every business holds some customer or employee personal information, even if it's just a client list or payroll records. The scale of the review should match the scale of the risk, but the question is rarely irrelevant entirely.
What if the seller never mentions a past data breach and I find out about it later?
This is exactly what representations, warranties, and indemnities in the purchase agreement are meant to address — but prevention through direct questions before closing is far better than trying to recover losses afterward.
Do I need consent from every customer to transfer their data as part of an asset purchase?
Not necessarily. Federal privacy law includes provisions generally allowing personal information to move between parties to complete a legitimate business transaction, subject to conditions like using it only for transaction-related purposes and keeping it secure. Whether a specific transfer fits within those provisions is worth confirming with a lawyer rather than assuming either way.
Should I bring in an IT specialist as well as a lawyer?
For any business where data or technology systems are meaningfully important to operations, yes — a lawyer addresses the legal and contractual side, while a technical specialist can assess whether the systems themselves are secure and current.
This is a business purchase or sale question
Start a file online — flat, published fees, reviewed by a licensed Ontario lawyer before a dollar is owed.