Skip to content

Private equity and portfolios

Market research roll-ups: does respondent consent transfer to the buyer?

By SourceX Editorial · Reviewed by Noah Loul ·

Short answer

Respondent consent generally travels with a market research acquisition only as far as its original wording: the buyer usually steps into the seller's promises, not a broader permission. Data collected for research can typically keep serving that research, while new uses such as AI training licenses need checking against panel terms, study consent screens and privacy notices with counsel.

Key takeaways

  • An acquisition usually moves the data and the promises attached to it; it does not enlarge what respondents agreed to.
  • Check consent at three levels: panel membership terms, study-level consent screens and the privacy notice in force at collection.
  • Client-commissioned study data is often controlled by the client contract, whatever the respondent agreed.
  • FTC positions in past business sales show regulators expect a buyer to honor the seller's privacy promises.

Respondent consent usually transfers in a limited sense: the acquirer can generally keep using data for the purposes respondents agreed to, but the consent does not stretch to purposes they never saw. In a stock purchase the agency that collected the data stays the same legal entity, while in an asset purchase or a later consolidation the data moves to a new entity, often under a business-transfer clause in the privacy notice. That clause typically permits the move itself, not new uses.

Regulators have framed this question before in business sales. In a May 2015 letter about the RadioShack bankruptcy, the FTC's consumer protection director recommended that customer data go only to a buyer in substantially the same line of business that agrees to be bound by the seller's privacy policy and obtains affirmative consent before material changes. In March 2025, the FTC chairman wrote in the 23andMe bankruptcy that any purchaser should agree to be bound by the company's privacy policies. Those were bankruptcy sales, but the principle is the one acquirers should plan around.

Consent in a research business lives in three layers, plus the contracts that sit around them. A panel member agrees to membership terms, then to each study's consent screen, all under whatever privacy notice was live at the time. Client contracts and sample supplier agreements then limit what the agency itself may do with the results.

Each layer can be narrower than the others, and the narrowest one usually governs. That is why diligence has to map consent text to specific panels and studies rather than read one current privacy notice.

Three layers of consent to check
LayerWhere it livesWhat to look for
Panel membership termsSign-up flow, member terms, archived versionsStated purposes, sharing with affiliates and successors, retention, any mention of AI or model training
Study-level consentSurvey intro screens, screeners, recording consent scriptsPurpose statements, recording and quotation permissions, promises to report only in aggregate
Privacy notice at collectionArchived website versions, change logsBusiness-transfer clause, secondary use language, opt-out mechanics
Client contract for the studyMSA and statement of workWho controls raw data, recordings and verbatims; reuse restrictions
Sample supplier termsSample and panel provider agreementsLimits on respondent IDs and responses supplied by the partner

Where research codes and client contracts narrow reuse#

Research codes and client contracts often narrow reuse further than privacy law alone. Many agencies commit to industry codes, such as those published by ESOMAR or the Insights Association, that set expectations about keeping research separate from non-research uses. Check which codes each acquired agency has signed up to, what its own published commitments say, and whether respondents were told about them.

Client contracts are the other limit. In commissioned research the client frequently owns the deliverables and sometimes the raw data, recordings and verbatims, leaving the agency with rights to its methods and tools. Qualitative work adds voice and video, which raise their own consent and identifiability questions.

New uses after closing, including AI training#

New uses after closing are where respondent consent most often falls short, and AI training or data licensing is the clearest example. FTC staff warned in February 2024 that a company adopting more permissive data practices, such as using consumers' data for AI training, and telling them only through a surreptitious, retroactive change to its terms or privacy policy may be engaging in unfair or deceptive practices.

The options usually discussed with counsel are to keep legacy data within its original purpose, to de-identify or aggregate it to a standard that applicable law treats as outside personal information, to ask active panelists for fresh, optional consent going forward, or to exclude legacy studies altogether. Laws that may apply include state privacy laws such as CCPA, GDPR for respondents outside the US, and COPPA where any study involved children; each is assessed deal by deal.

Diligence checklist for panels and studies#

A consent diligence checklist turns these questions into documents the buyer can review before signing, or immediately after closing if the deal moved fast.

The hardest item is usually the first one. Agencies rarely archive old versions of their panel terms, so the buyer may need web archive captures, old survey exports or email confirmations to reconstruct what members saw. Where the text cannot be found, treat that panel's data as limited to its original research purpose until counsel says otherwise.

  • Collect every version of the panel terms and privacy notice, with the dates each was live.
  • Map each panel and major study to the consent text respondents actually saw.
  • Flag data from minors, health topics or other sensitive categories separately.
  • Pull client MSAs and statements of work and record who controls raw data, recordings and verbatims.
  • Review sample supplier agreements for limits on respondent IDs and responses.
  • Check business-transfer and successor clauses in notices and terms.
  • Confirm that past withdrawals, deletion requests and opt-outs were honored.
  • Ask whether any respondent data has already been sent to AI tools or outside vendors.

Illustrative: an insights platform buys a qualitative agency#

Illustrative: a fictional PE-backed insights platform acquires a qualitative agency with years of recorded B2B interviews and focus groups. The agency's recording consent scripts allowed internal analysis and anonymized quotes in client reports, and most client contracts give the client ownership of recordings and transcripts.

The platform's counsel concludes that the recordings stay inside the agency for their original purpose and are excluded from any AI licensing discussion. The platform updates its panel terms with an explicit, optional consent for de-identified use in AI development, applied only to new members and new studies. Its own internal research methods, proposal library and project reviews, with client and respondent details removed, become the records it evaluates for licensing instead.

How SourceX treats research data from acquired agencies#

SourceX treats respondent data as the most constrained record family in a research business. In the SourceX five-step transaction of Supply, Rights, Preparation, Approval and Delivery, the Rights step maps consent at each layer before any study is considered, client-controlled data is usually carved out, and Preparation removes personal and confidential details. Each package carries a SourceX Evidence Packet recording provenance, licensing rights, permitted use, the privacy record and release authorization, and the supplier approves every step.

The initial fit check collects metadata only: which panels and studies exist, the years they cover, the consent versions on file and the client contract types involved. No respondent records are shared at that stage, and studies whose consent text cannot be located are set aside rather than prepared.

Frequently asked questions

Does a business-transfer clause in the privacy notice cover AI training?

Usually not by itself. A business-transfer clause typically lets the company disclose data to a successor in a merger or sale; it does not add new purposes. Whether a later use such as AI training fits depends on the purposes respondents were told about, which counsel should review.

Can two panels be merged after an acquisition?

Sometimes, where both panels' terms allow sharing with affiliates or successors and members are told clearly. Inviting members of one panel to studies under another brand may need notice or fresh consent. Plan the merger with counsel and give members a simple way to opt out.

Is de-identified survey data free of consent limits?

Not automatically. Whether data counts as de-identified depends on the definition in the applicable law and on controls against re-identification. Open-ended answers, recordings and small B2B samples are hard to de-identify, and client contracts may still restrict use even after identifiers are removed.

What did the Toysmart case show about selling customer data?

In July 2000 the FTC sued the failed online retailer Toysmart.com to block the sale of customer data collected under a policy promising never to share personal information with third parties. The customer list was ultimately destroyed rather than sold, an early sign that privacy promises can follow data through a sale.

Who should sign off on reuse of acquired research data?

General counsel or outside privacy counsel, the research quality or ethics lead, and the platform executive sponsoring the use. Where client contracts require it, the client must also agree. Record each decision with the consent text it relied on.

Sources

  • In a May 2015 letter to the RadioShack consumer privacy ombudsman, FTC Bureau of Consumer Protection Director Jessica Rich recommended that customer data be transferred only to a buyer in substantially the same line of business that agrees to be bound by RadioShack's privacy policy and to obtain consumers' affirmative consent before making material changes. Source
  • On March 31, 2025, FTC Chairman Andrew N. Ferguson sent a letter to the U.S. Trustee in the 23andMe bankruptcy stating that any purchaser should expressly agree to be bound by and adhere to 23andMe's privacy policies and applicable law. Source
  • On February 13, 2024, FTC staff warned that a company that adopts more permissive data practices, such as using consumers' data for AI training, and tells consumers only through a surreptitious, retroactive change to its terms of service or privacy policy may be engaging in unfair or deceptive practices. Source
  • In July 2000, the FTC sued the failed online toy retailer Toysmart.com to block the sale of customer data collected under a privacy policy promising that personal information would never be shared with third parties, and the customer list was ultimately destroyed rather than sold. Source

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify