Privacy and preparation
Privacy promises made by an acquired company: do they still bind legacy data?
By SourceX Editorial · Reviewed by Noah Loul ·
Short answer
Privacy promises made by an acquired company generally keep governing the legacy data collected under them, even after the acquirer rewrites the policy. The working rule: records stay bound by the notice in effect when they were collected. Before licensing an acquired archive, find every old notice, date it, and map it to the records it covers.
Key takeaways
- Legacy records are generally governed by the privacy notice in effect when they were collected, not by the acquirer's current policy.
- A business transfer clause usually permits the data to move in a deal; it rarely permits new uses such as licensing.
- Materially new uses of already-collected personal data may call for notice and affirmative consent, which is impractical for most archives.
- De-identification or exclusion is usually the practical route for records collected under restrictive promises.
- Customer contracts and data processing agreements can bind the same records even where the old notice is silent.
Why do an acquired company's privacy promises survive the deal?#
An acquired company's privacy promises survive the deal because the people in its records shared their information on the strength of those promises, not the acquirer's. Closing a transaction changes who owns the company or its assets. It does not change what customers, users and website visitors were told when they handed over their details.
US regulators have applied this idea when records change hands. In July 2000 the FTC sued to stop the failed online retailer Toysmart.com from selling customer data collected under a policy that promised never to share it, and the customer list was ultimately destroyed rather than sold. In May 2015 the FTC's consumer protection director recommended that RadioShack's customer data go only to a buyer in substantially the same line of business that agreed to be bound by RadioShack's privacy policy and to get affirmative consent before making material changes. In March 2025 the FTC chairman wrote in the 23andMe bankruptcy that any purchaser should expressly agree to be bound by the company's privacy policies.
Those were bankruptcy sales, but the same logic generally carries into ordinary acquisitions. California's privacy law, for example, does not treat a transfer of personal information in a merger or acquisition as a sale, yet expects an acquirer that materially changes how it uses or shares that information, in a way inconsistent with the promises made at collection, to give notice first. Many other state laws limit processing to purposes the business disclosed or compatible ones. Which rules apply to a given archive is assessed deal by deal with counsel.
Deal structure changes the mechanics, not the principle. In a stock purchase the acquired entity still exists and its promises remain its own. In an asset purchase the records move to a new owner, which generally takes them subject to the promises under which they were collected.
What a business transfer clause does and does not allow#
A business transfer clause allows personal information to move to a buyer as part of a merger, acquisition or asset sale. Most privacy notices include one, and it is often the reason an archive could change hands at all.
The clause rarely says the buyer may use the information for new purposes. Read it next to the use and sharing sections of the same notice: if those sections limit use to providing the service, the transfer clause does not widen them. Some notices add that any buyer will honor the existing policy, which makes the limit explicit rather than implied.
Which promises in an old notice limit a data license?#
The promises that limit a data license are the ones about purpose, sharing and sale. Read each old notice line by line and flag language that restricts who may receive information and why, because that language decides whether a record family can be licensed as is, only after de-identification, or not at all.
| Language in the old notice | What it may limit | What to check |
|---|---|---|
| We do not sell your personal information | Licensing personal information for value, which some state laws may treat as a sale | Whether the licensed package still contains personal information after preparation |
| We use your information only to provide and improve our services | Uses beyond operating the product, including third-party AI training | Whether de-identified records fall outside the promise as written |
| We share information only with service providers acting for us | Any transfer to a licensee that is not a service provider | Who would receive the package and on what terms |
| We delete your data when you close your account | Records of former customers that should have been purged | Whether deletion actually happened and what the retention schedule said |
| We process customer data on behalf of our customers | Records held as a processor under customer contracts | Customer agreements and data processing agreements, not just the notice |
| We may transfer information in a merger or acquisition | Nothing beyond the transfer itself | Whether the clause also commits a buyer to the existing policy |
How do you find the notices that applied when records were created?#
Finding the notices that applied means rebuilding a dated history of every version the acquired company published. Acquired companies rarely keep a clean archive, so expect to assemble the history from several sources and to record gaps rather than guess at them.
Log each version with its effective date, where you found it and how confident you are in that date. A version history with honest gaps is more useful in a rights review than a tidy one built on assumptions.
- Public web archives: snapshots of the old privacy page, terms of service and signup screens, with capture dates.
- The website repository or CMS revision history, which often shows the exact day a policy page changed.
- The acquisition data room: disclosure schedules, privacy representations and any listed complaints or regulator inquiries.
- Legal and compliance drives, including redlines, board materials and outside counsel memos about policy updates.
- In-product text: signup checkboxes, consent screens, cookie banners and chat pre-forms, which can carry promises the policy lacks.
- Customer contracts and data processing agreements, which can bind records more tightly than any public notice.
Map each notice to the archive it covers#
Mapping notices to archives means tagging every record family with the notice versions in effect across its date range. Support tickets from one era may sit under a permissive notice while signup data from a later redesign sits under a strict one.
For an acquired software company the mapping usually covers helpdesk tickets in Zendesk or Intercom, CRM histories in Salesforce or HubSpot, product analytics, marketing lists and engineering records in Jira or GitHub. Engineering and internal workflow records often hold little customer personal information, which is why they tend to clear review faster than customer-facing archives.
| Record family | Whose information it holds | Usually governed by |
|---|---|---|
| Helpdesk tickets and chats | Customer users and their contacts | Privacy notice, terms and customer contracts in force at the time |
| CRM activity and logged email | Prospects, customer contacts, sales staff | Website notice, marketing consents, employee notice |
| Product usage and analytics | End users of customer accounts | Terms of service, in-app notices and data processing agreements |
| Jira issues, code reviews, releases | Mostly employees and contractors | Employee notices, contractor agreements, open-source licenses |
| Slack and internal documents | Employees, sometimes quoted customers | Employee notice and acceptable use policy |
Can a new privacy policy fix the gap for old records?#
A new privacy policy generally fixes the gap only for records collected after it takes effect. Updating the notice is still worth doing, because it sets clean terms for future data, but it does not quietly rewrite what earlier customers were told.
Regulators have also warned against trying. In February 2024 FTC staff wrote that a company adopting more permissive data practices, such as using consumers' data for AI training, and telling people only through a surreptitious, retroactive change to its terms or privacy policy may be engaging in unfair or deceptive practices.
For legacy records collected under restrictive promises, groups usually choose among three routes. They can seek fresh notice and consent, which is rarely practical for former customers. They can de-identify records so the licensed package no longer contains personal information, while still honoring customer contracts. Or they can exclude the record family and license only what the old notice comfortably allows.
Watch for promises that reach beyond personal information. A line such as we never share your conversations may be read as covering the content of tickets, not just the names in them, so de-identification alone may not settle it.
Illustrative: a holding group reviews an acquired scheduling platform#
Illustrative: a fictional vertical software holding group acquires a crew scheduling platform used by landscaping contractors. The group COO wants to include the platform's records in a data licensing program alongside two sister companies.
The team rebuilds three notice versions from web archive snapshots and the platform's git history. The earliest notice said support conversations would be used only to provide the service. A later version, written well before the acquisition, added product improvement and de-identified research as uses. Contracts with the largest accounts included confidentiality terms covering all customer content.
The decision: engineering records in Jira and GitHub proceed to preparation, support tickets from the later notice period proceed only after de-identification and a check against the large-account contracts, and tickets from the first period are excluded. The outcome is a smaller package that every reviewer can trace back to a specific notice.
How SourceX handles legacy notices#
SourceX treats notice history as part of the Rights step in the SourceX five-step transaction: Supply, Rights, Preparation, Approval and Delivery. The fit check uses metadata only, such as systems, date ranges and known restrictions, so no records move while the notice history is rebuilt.
For each package that proceeds, the SourceX Evidence Packet records provenance, licensing rights, permitted use, the privacy record and release authorization, including which notice version governed each record family. The acquired company's authorized signer approves the scope before anything is delivered.
Frequently asked questions
Does it matter whether we bought stock or assets?
It changes the paperwork more than the principle. In a stock deal the acquired entity keeps its own obligations. In an asset deal the records transfer, and the buyer generally takes them subject to the promises made at collection. The purchase agreement may also contain privacy representations and covenants worth reading before any license.
What if the acquired company was bought out of bankruptcy?
Then the sale process may already have set the rules. Under the Bankruptcy Code, if the debtor's privacy policy barred transferring personal information to unaffiliated parties, the trustee generally may not sell that information unless the sale is consistent with the policy or the court approves it after a consumer privacy ombudsman is appointed and a hearing is held. Read the sale order and any ombudsman report alongside the old notices.
What if we cannot find the notice that applied in a given period?
Treat the period as unknown, not permissive. Records from an undocumented period are usually excluded or de-identified more conservatively until a version turns up. Former employees, the old website host, marketing agencies and outside counsel files are often the best places to recover missing versions.
Do old promises expire after enough time passes?
Privacy notices rarely include an expiry, and the passage of time does not generally release a business from what it told people. Retention promises can cut the other way: if the notice said records would be deleted, keeping and licensing them may conflict with that promise.
Should we contact former customers before licensing their records?
Usually only if counsel concludes consent is needed and the package will contain their personal information. Most groups find it cleaner to de-identify or exclude those records. Reaching out can make sense when a customer contract, rather than a notice, is the barrier.
Do the acquired company's promises cover records about its own employees?
Employee records are governed by employee notices, handbooks and employment law rather than the customer privacy policy, so review them separately. Engineering and operations records still contain employee names and messages, which is why they usually go through the same de-identification step.
Sources
- In July 2000 the FTC sued Toysmart.com to block the sale of customer data collected under a privacy policy promising personal information would never be shared with third parties; the customer list was ultimately destroyed rather than sold. Source
- In May 2015 FTC Bureau of Consumer Protection Director Jessica Rich recommended that RadioShack customer data be transferred only to a buyer in substantially the same line of business that agrees to be bound by RadioShack's privacy policy and to obtain affirmative consent before material changes. Source
- On March 31, 2025, FTC Chairman Andrew N. Ferguson wrote to the U.S. Trustee in the 23andMe bankruptcy that any purchaser should expressly agree to be bound by and adhere to 23andMe's privacy policies. Source
- On February 13, 2024, FTC staff warned that adopting more permissive data practices, such as using consumers' data for AI training, and disclosing them only through a surreptitious, retroactive change to terms or a privacy policy may be unfair or deceptive. Source
- Under 11 U.S.C. 363(b)(1), if a debtor's privacy policy prohibits transferring personally identifiable information to unaffiliated persons, the trustee may not sell it unless the sale is consistent with the policy or the court approves after appointment of a consumer privacy ombudsman and notice and a hearing. Source
Related resources
See if your company qualifies
A short company assessment. No data uploads are needed.