Privacy due diligence checklist for M&A, with a data licensing lens
A privacy due diligence checklist for M&A should request the target's data map, current and past privacy notices, consent records, vendor and customer data agreements, security incident log, retention schedule and state, country and sector footprint. Sell-side advisors should add licensing questions: existing data licenses, AI-training restrictions in customer contracts, and archives at risk of deletion.
What belongs on a privacy due diligence checklist for M&A?
A privacy due diligence checklist for M&A should cover seven areas: the data map, notices and public promises, consents, vendor and customer data agreements, security incidents, retention, and the target's state, country and sector footprint. Buyers' counsel will ask about each one in confirmatory diligence, usually as numbered items on a request list with a data room folder behind each.
This version adds an eighth area that most request lists leave out: the licensing lens. It asks whether any company data is already licensed, whether customer contracts bar AI-training use, and which archives are about to be deleted. Those answers change what a buyer will ask to see, and they tell a sell-side advisor whether the client holds records that could be licensed through SourceX before or after closing.
Why should the sell side run privacy diligence first?
A privacy gap the buyer finds becomes a price or indemnity discussion; the same gap found by the seller during preparation becomes a task with a deadline. Running the list while the CIM is being drafted gives the client time to update a notice, paper a missing vendor agreement or document an old incident.
Timing matters in owner-led companies in particular:
- The answers are spread across the CFO, the IT manager, an outside MSP, HR and outside counsel, and collecting them takes longer than most owners expect.
- The purchase agreement's privacy representations and disclosure schedules are drafted from what diligence finds, so a documented answer set can shorten that negotiation.
- If the buyer is using representations and warranties insurance, expect the underwriter to ask privacy and security questions as well.
- An existing or planned data license has to be disclosed; the guide to disclosing an existing data license in due diligence covers how.
The privacy and data protection request list
Each item asks for a document or a written answer, never for the underlying personal data. Number the items to match your request list or data room index.
Data map and systems
- Inventory of systems holding personal information or business records (CRM, ERP, email, chat, helpdesk, HR, call recording, file shares), with an owner and the years of history in each
- Categories of personal information per system: business contacts, employee records, consumer data, health or financial information
- Systems retired in recent years, and where their exports are stored now
Notices, policies and public promises
- Current and prior website privacy policies, with the dates each was in effect
- Employee privacy notices, acceptable-use and monitoring policies
- Any public statement that the company does not sell or share data, and where it appears
- The California notice at collection, if the CCPA applies: California's statute requires a business to tell consumers, at or before collection, which categories of personal information it collects, why, whether it sells or shares them, and how long it keeps them
Consents and recordings
- Marketing consent and opt-out records
- Call recording notices and scripts, plus the states where callers are located
- Log of consumer privacy requests (access, deletion, opt-out) and how each was answered
Vendors, processors and customers
- Data processing agreements and service provider terms for every vendor that touches personal information; under the same statute, a business that sells or shares personal information, or discloses it to a service provider or contractor, needs a written agreement limiting use to specified purposes
- Customer MSAs and DPAs covering data ownership, confidentiality, permitted use and deletion on termination
- Any clause barring use of customer data for AI or machine learning, or for any purpose beyond delivering the services
Security and incidents
- Written information security program and the most recent assessment or penetration test summary
- Incident log for the lookback period, with any notices sent to individuals, regulators or customers
- Cyber insurance policy and claims history
- Open regulator inquiries, complaints or litigation involving personal data
Retention, deletion and holds
- Retention schedule and evidence that it is followed
- Automatic deletion rules in email, chat and helpdesk tools
- Active legal holds and who manages them
Footprint and sector rules
- States and countries where customers, employees and contractors are located
- Privacy laws counsel has assessed as applicable; the CCPA, for example, reaches for-profit businesses doing business in California that meet any one of three tests, based on annual gross revenue, the volume of California residents' personal information bought, sold or shared, or the share of revenue earned from selling or sharing it (California Attorney General)
- Sector rules that may apply: health, financial, children's, biometric or government-contract data
The licensing lens
- Existing data licenses, data-sharing or resale agreements, with term, exclusivity, field of use and change-of-control terms
- Any past use or license of company records for AI training
- Customer or vendor terms that restrict AI-training use, listed by counterparty
- Systems scheduled for migration, shutdown or deletion before or after closing
- Who could authorize a license (owner, CEO, CFO or another authorized representative) and whether board or lender consent would be needed
When should each part of the list go out?
Prepare the privacy answers before marketing starts, release them at confirmatory diligence, and handle the licensing lens privately with the owner throughout.
| Deal stage | Privacy items to have ready | Licensing-lens action |
|---|---|---|
| Preparation, before the CIM | Data map, policies, retention schedule | Ask the owner the five licensing-lens questions privately |
| Teaser and IOIs | Nothing shared yet; fix gaps quietly | Decide with the owner whether to explore a license before, after or outside the sale |
| LOI and confirmatory diligence | Full request list answered in the data room | Disclose any existing license; respect exclusivity and no-shop terms |
| Signing | Privacy representations and disclosure schedules final | Check interim operating covenants before any new material contract |
| Closing and integration | Buyer's plan for legacy systems | Preserve complete exports before old systems are retired |
How to read the answers
Most findings point to one of three outcomes: fix before marketing, disclose and move on, or keep the licensing track closed.
| Result | What it means | Next action |
|---|---|---|
| Clean notices and contracts, years of records, no prior license | Low privacy friction and a possible licensable asset | Run a fit screen and raise timing with the owner |
| Policy promises the company never sells or shares data | Buyers will test whether the promise covers a transfer; licensing may still work for records without personal data | Have counsel read the policy history; see whether a no-sale promise blocks a license |
| Customer contracts restrict use of customer data | Those records may be excluded; the company's own operating records may not be | Build a clause inventory by customer for deal counsel |
| An existing data license is in force | It must be scheduled and may limit both the buyer and any new license | Disclose it and check exclusivity and change of control |
| A system is about to be retired | Years of records could disappear before anyone decides | Take a complete export first; decide on licensing later |
| Open incident or regulator matter | Raises representation and indemnity questions | Let counsel resolve it before any licensing conversation |
| Records are mostly consumer personal data or patient records | Little room for a license | Tell the owner now and leave licensing out of the sale plan |
The licensing questions most request lists miss
Existing licenses. A data license can be a material contract. Reddit's February 2024 Form S-1, for example, disclosed data licensing arrangements entered into in January 2024 with an aggregate contract value of $203.0 million over terms of two to three years (Reddit Form S-1). That is a multi-year contract total at a public company, not annual revenue, but the diligence point carries to private targets: exclusivity, field-of-use limits and change-of-control terms travel with the company. For SourceX, data already licensed for AI training is a red flag, so the answer also tells you whether an introduction makes sense.
AI-training restrictions. Some newer MSAs and DPAs add language barring use of customer data to train models. Read whether the clause attaches only to customer data and deliverables, or to every record the company creates while serving that customer. Internal tickets, SOPs and project histories can fall on either side depending on the drafting.
Archives at risk. A buyer's integration plan can retire the seller's CRM, helpdesk or email tenant soon after closing. A complete export taken first keeps the option open for whoever owns the company next; SourceX works with operating, acquired and wound-down companies as long as the data still exists.
Which findings stall a license, even if the sale proceeds?
None of these has to stop a sale. Each one narrows or delays what can be licensed, so flag it to the owner early.
- The records mostly describe the target's own customers, as at many agencies and outsourcers, and those customers never agreed to reuse.
- Consumer personal information or patient records dominate, with no HIPAA authorization or de-identification behind them.
- Deletion jobs already ran, or no one on staff can run an export.
- An earlier AI-training license covers the same material.
- Peak headcount stayed below 50 full-time employees (contractors excluded).
- The owner rules out an exclusive AI-training term.
- The seller is in bankruptcy and its privacy policy limits transfers; the consumer privacy ombudsman guide explains the court process.
How to introduce the client without touching the data room
- Raise licensing with the owner as a separate question, outside the sale process and the data room.
- Agree with the owner and deal counsel on timing: before signing, after closing, or not at all. An LOI no-shop clause or interim operating covenants can restrict new material contracts.
- Share your referral link, which takes the owner to sourcex.si/apply with your code attached, or submit the company through the referral form with its name, a contact and basic fit details only. Nothing from the data room or this checklist passes through you.
- SourceX checks size, history, data breadth and rights directly with the authorized sponsor.
- The company completes a data inventory, and de-identification and redaction rules are agreed before any work starts.
- Price and terms are agreed with the company, buyers review, and records move only after an executed agreement and the company's authorization.
The how it works page shows the full sequence. Partners earn 25% of the eligible platform fees SourceX actually collects from the referred company's licensing deals, up to $100,000 per referred company, payable only after the buyer pays and SourceX receives its fee; no reward is guaranteed, and it is never deducted from the client's proceeds. If your engagement letter or firm policy addresses third-party compensation, disclose the arrangement to the client and check those terms first; the M&A advisor partner page covers role-specific questions. Sponsor-backed targets may already have run the PE legal checklist for portfolio data monetization.
This is general information, not legal, tax or financial advice. Confirm with your own counsel, tax adviser or professional body before acting.
Next step
Add the five licensing-lens items to your next request list. If a client's answers come back clean, run the company fit checker for a preliminary, non-binding read, then register as a partner and send the owner your referral link. Owners can also apply directly at sourcex.si/apply.
- Step 1Share your linkSend your personal link to a company you know.
- Step 2Company appliesThe company applies itself at /apply.
- Step 3Buyer selects and paysThe buyer selects and pays for the data and SourceX receives its fee.
- Step 4You get your rewardYour share of SourceX fees becomes payable.
Common questions
Who on the seller's side usually answers a privacy diligence request list?
In an owner-led company the answers tend to be spread out: the CFO holds vendor and customer contracts, the IT manager or outside MSP holds system and security details, HR holds employee notices, and outside counsel holds policy history and any regulator correspondence. Assign each section of the list to a named person early and set an internal deadline ahead of the data room opening.
Should the data room include samples of personal data to prove compliance?
No. Privacy diligence is answered with documents and summaries: policies, contracts, logs, retention schedules and counts of requests and incidents. Putting raw personal data into a data room creates a new disclosure that the company's notices may not cover. If a buyer asks for samples, counsel should decide what, if anything, is shared and in what redacted form.
Does an exclusive AI-training license make a company harder to sell?
It adds a contract the buyer will review, so it must be disclosed with its term, exclusivity and field of use. Through SourceX the company keeps ownership of its data and licenses it for an agreed term rather than selling it, but deal counsel should still decide whether a license fits before signing, after closing, or outside the process entirely.
Can a company with a past data breach still license its records?
A past incident does not automatically rule it out. What matters is whether the incident is closed, whether any regulator matter or litigation is still open, and whether the records in question carry the same exposure. Counsel should resolve open matters first, and the incident history will form part of any rights review before a license is agreed.
How far back should privacy diligence look?
There is no single rule; the buyer's counsel sets the lookback period in the request list, and it varies by deal and risk area. For licensing the relevant window is different: it is the full span of records the company still holds, because long, connected histories across several systems are what make operating records useful to AI labs and data buyers.
Is the M&A advisor responsible for the privacy review behind a data license?
No. The advisor makes the introduction and shares only basic fit information. The company, its counsel and SourceX handle the inventory, rights review, redaction rules and contracting, and no records are delivered without an executed agreement and the company's authorization. The advisor never exports, uploads or describes confidential records at any stage.
Related pages
- How to disclose an existing data license in M&A due diligence
- Our privacy policy says we do not sell data. Can we still license records?
- Consumer privacy ombudsman: selling personal data in bankruptcy, and the alternative
- How SourceX US company data referrals work
- Referral opportunities for M&A advisors
- Portfolio company data monetization: a legal checklist for PE teams
Free resources
- Time value of money calculator — Future and present value with optional regular payments.
- Business DSCR calculator — Debt service coverage from cash flow and loan terms.
- MCP ROI calculator — Estimate hours saved, implied savings and first-year ROI from MCP.
- All free tools · MCP resource center
By SourceX Partnerships Team · Published 2026-10-09 · Updated 2026-10-09
Know a US company with valuable proprietary data?
Become a referral partner from anywhere we support, get your link and introduce an owner or authorized decision-maker.
Refer a company →I own a business
Explore licensing your company's data to AI developers worldwide. Start a short assessment; no uploads needed.
Start an assessment