Skip to content

Private equity and portfolios

Privacy promises after an acquisition: can the buyer use old data in new ways?

By SourceX Editorial · Reviewed by Noah Loul ·

Short answer

An acquirer generally cannot use old data in new ways just because it now owns the company. Personal data collected under the target's earlier privacy notice usually stays bound by that notice, and regulators such as the FTC may treat a material retroactive change without consent as deceptive. Map each record set to the notice in force at collection.

Key takeaways

  • A change of ownership transfers the records and, generally, the promises attached to them.
  • A business-transfer clause in a privacy notice usually permits moving data in a deal, not using it for new purposes.
  • Material new uses of previously collected personal data generally call for fresh notice and often affirmative consent.
  • B2B records are also governed by customer contracts and data processing terms, which can be stricter than the notice.
  • Tag records by collection period and notice version in the first months after closing.

Does an acquisition reset the privacy promises attached to old data?#

An acquisition does not reset the privacy promises attached to old data; the acquirer generally steps into them. Whether the deal is a stock purchase or an asset purchase, the records arrive with the notice under which they were collected, and the new owner is expected to honor it.

Most privacy notices include a business-transfer clause saying personal data may be transferred in a merger, acquisition or sale of assets. That clause typically covers the move itself. It does not, on its own, authorize the buyer to use the data for purposes the original notice never described, such as combining it with the buyer's marketing lists or licensing de-identified records to AI developers.

Why a new privacy policy may not reach old records#

A new privacy policy may not reach old records because notice operates at the moment of collection. Regulators such as the FTC may treat a material change applied retroactively, without the person's agreement, as a deceptive or unfair practice, and counsel commonly look for affirmative consent before applying a materially different use to data gathered under an older promise.

The FTC has said so in public. In a 2015 letter in the RadioShack bankruptcy, the director of its Bureau of Consumer Protection recommended that customer data transfer only to a buyer in substantially the same line of business that agreed to be bound by RadioShack's privacy policy and to obtain consumers' affirmative consent before making material changes. In February 2024, FTC staff warned that a company adopting more permissive data practices, such as using consumers' data for AI training, and announcing them only through a surreptitious, retroactive change to its terms or privacy policy may be engaging in unfair or deceptive practices. That staff post is guidance, not a rule, but it signals how regulators may view a new owner's change of course.

State privacy laws such as the CCPA, and the GDPR where EU personal data is involved, add concepts like notice at collection and purpose limitation that point the same way. Which laws may apply depends on whose data is in the records, where those people live and what kind of business holds it, and that is assessed deal by deal with counsel.

The working rule is to treat each record set as carrying the notice that was live when it was collected, and to apply a new policy only to data collected after it took effect, unless consent covers the older records.

Is the new use material? Questions counsel will ask#

Whether a new use is material depends on how far it departs from what people were told. The table frames common post-acquisition uses and the questions each raises; the answer for any company depends on its own notices and facts.

Is the new use material? Questions counsel will ask
Proposed useWhy it may differ from the original promiseWhat to check
Running the same service under new ownershipUsually closest to the original purposeBusiness-transfer clause and any change in who processes the data
Internal analytics to improve the serviceOften described in notices, sometimes narrowlyWording on service improvement and analytics
Combining with the acquirer's customer data for marketingMay introduce a new purpose and new recipientsMarketing, sharing and sale language, plus opt-out records
Training an internal AI modelOlder notices rarely mention model trainingPurpose descriptions and any automated decision language
Licensing de-identified records to AI developersInvolves a third party and a new purposeSharing language, de-identification standard, customer contracts
Sharing identifiable personal data with third partiesLikely the largest departureConsent records and the state and foreign laws that may apply

How to find the notices in force#

Finding the notices in force is an archaeology project, and it is far easier in the first months after closing, while the target's staff, CMS and email platform are still in place. Assign one owner and keep the evidence in a single folder.

  • Collect every version of the website privacy notice from the CMS history, legal files or web archives, with the dates each was live.
  • Capture in-app notices, sign-up flows, checkout pages and cookie banners, which may differ from the website notice.
  • Pull consent and opt-out logs from the CRM, the email platform and any consent management tool.
  • Gather customer contract templates and data processing agreements, with their effective dates.
  • Find employee handbook sections and monitoring notices covering email, chat and call recordings.
  • Build a table matching each record set and date range to the notice and contract versions that governed it.

B2B records follow contracts as well as notices#

B2B records follow customer contracts as well as privacy notices, and the contract is often the tighter limit. A support ticket from a business customer can contain the names and messages of that customer's employees, and the master agreement may say the company processes that data only to provide the service.

Where the target acted as a service provider or processor for its customers, the customer, not the target, may control the purposes for which the data can be used. That position can rule out new uses of some record families entirely, whatever the target's own privacy notice says, so read the data processing agreements before planning any new use.

Options when the old promise does not cover the new use#

When the old promise does not cover a planned use, the acquirer still has several routes, and they can be combined. A common pattern is a forward-looking notice for new data plus a narrower, de-identified scope for historical records that counsel has reviewed.

  • Limit the new use to records collected after an updated notice took effect.
  • Ask for consent from the people or customers whose older records you want to include.
  • Remove personal and confidential details so records no longer qualify as personal data, assessed against the applicable legal standard.
  • Exclude record families governed by processor terms or restrictive customer contracts.
  • Focus on company-owned operational content, such as internal procedures, job notes and engineering workflows.

Illustrative: a platform inherits a decade of service records#

Illustrative: a fictional home services platform acquires a regional plumbing company whose ServiceTitan account holds many years of jobs, estimates, invoices and technician notes. The plumbing company's website notice changed twice before closing, and the oldest version said customer information would be used only to schedule and perform service.

The platform's counsel maps record sets to notice periods. Older records stay in use for operations and warranty work only. The scope for a later licensing review is limited to technician notes and job outcomes with customer names, addresses and phone numbers removed, plus newer records collected under the updated notice, and counsel signs off on each scope before anything is exported.

How SourceX handles inherited promises#

In the SourceX five-step transaction, the Rights step maps record sets to the notices and contracts that governed them, and the Preparation step removes personal and confidential details before anything is released. The privacy record in the SourceX Evidence Packet documents which notice versions apply and how each record set was treated, so the supplier's counsel approves with the full picture.

SourceX does not decide what the law allows for a given company. Its role is to make the inputs visible: which notice periods each record set spans, which customer contracts and processing terms apply, and which records were excluded or de-identified. The supplier's counsel makes the call, and the supplier approves every step before release.

Frequently asked questions

Can we email customers a new privacy policy after closing and move on?

A notice of change helps for data collected afterward. For material new uses of older data, an email alone may not be enough, and counsel often look for affirmative consent. The answer depends on the change, the laws that may apply and what the original notice said.

Does de-identification solve the old-notice problem?

It can narrow it. Properly de-identified data may fall outside some privacy obligations, but standards differ by law and contracts may still restrict use. California's definition, for example, requires more than technical masking: the business must take reasonable measures against re-association, publicly commit not to re-identify, and contractually bind any recipients to the same terms. Document the method used and have counsel confirm it fits the applicable standard before relying on it.

What if the target never had a privacy notice?

Treat that as a finding to escalate, not an open door. The absence of a notice does not mean any use is allowed, and state laws may have required one. Counsel should assess the exposure and the safest scope for any new use.

Does it matter whether we bought stock or assets?

It can affect which entity holds the obligations and whether customer contracts need assignment, but in both structures the records generally carry their original promises. Ask counsel how the structure affects contracts and data processing agreements.

Do employee communications follow the same rule?

Broadly, yes. Email, chat and call recordings carry whatever employee notices and policies applied when they were created, and some states add their own rules on monitoring and recordings. Gather the handbook and monitoring notice history alongside the customer-facing notices, and have counsel assess which laws may apply.

Should the acquirer merge privacy notices across add-ons?

A single forward-looking notice simplifies operations, but keep every old version and its dates. Harmonizing notices going forward does not change what governs records already collected, and that history will be needed for any later review.

Sources

  • In a May 2015 letter to the RadioShack consumer privacy ombudsman, FTC Bureau of Consumer Protection Director Jessica Rich recommended that customer data be transferred only to a buyer in substantially the same line of business that agrees to be bound by RadioShack's privacy policy and to obtain consumers' affirmative consent before making material changes. Source
  • On February 13, 2024, FTC staff warned that a company that adopts more permissive data practices, such as using consumers' data for AI training, and tells consumers only through a surreptitious, retroactive change to its terms of service or privacy policy may be engaging in unfair or deceptive practices. Source
  • Under Cal. Civ. Code § 1798.140(m), as amended by the CPRA, deidentified information requires the business to take reasonable measures to ensure it cannot be associated with a consumer or household, publicly commit not to reidentify it, and contractually obligate any recipients to comply. Source

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify