Skip to content

Privacy and preparation

Sell-side data room checklist: privacy and data documentation buyers now ask for

By SourceX Editorial · Reviewed by Noah Loul ·

Short answer

A sell-side data room checklist for privacy and data covers five folders: a data inventory and system map, privacy notice history, contracts that govern data, security and incident history, and a record of data assets with the rights to use them. Build it before the process starts; missing notice history is usually the slowest gap to repair.

Key takeaways

  • Organize the privacy section into five folders so buyer counsel finds answers without a long request list.
  • Archive every past privacy policy version with its effective dates; reconstructing them late is slow.
  • List customer DPAs and contracts with data-use limits, because they decide what a buyer can do with the data.
  • Present each incident with what changed afterward, not just the incident itself.
  • Document any data licensing, inbound or outbound, with the rights and approvals behind it.

What the privacy and data section should contain#

The privacy and data section of a sell-side data room should let buyer counsel answer three questions quickly: what personal and business data the company holds, which promises and contracts govern it, and what has gone wrong before. Acquirers that see AI uses for the data add a fourth: which datasets have value of their own, and who has the right to use them.

Five folders cover those questions for most lower-middle-market companies. The checklist below lists what belongs in each, and the illustrative example shows how one portfolio company assembled them before a sale.

Folder 1: data inventory and system map#

The data inventory is the index the rest of the section depends on. Without it, buyer counsel has to infer what data exists from contracts and policies, which produces longer request lists and slower answers.

Retired systems deserve their own line. A help desk replaced years ago may still be readable, and buyers want to know whether it holds personal data, who controls it and when it will be deleted.

  • Every system holding customer, employee or operational records, with its owner and vendor.
  • Record categories in each system, such as tickets, CRM activity, job records, payroll or applicant files.
  • Personal data categories in each system and whether any sensitive categories appear.
  • Retention rules and what actually happens at expiry, including archived and retired systems.
  • Main data flows: integrations, exports to vendors and transfers outside the United States.
  • Records of processing activities, if GDPR or a similar law applies to the business.

Folder 2: privacy notices and their history#

Privacy notice history matters because the notice in force when data was collected shapes what the company may do with it. A current policy alone does not tell a buyer what customers, users or employees were told at the time.

Old promises can follow the data into a transaction. In the 2015 RadioShack bankruptcy, the FTC recommended that customer data move only to a buyer in substantially the same line of business that agreed to be bound by RadioShack's privacy policy, and state attorneys general led by Texas objected to the sale by citing the policy line "We do not sell our mailing list." A buyer's counsel reads your archived notices with that history in mind.

Folder 2: privacy notices and their history
DocumentWhy buyer counsel asksCommon gap
Current website privacy policyBaseline for present practicesDoes not match what systems actually collect
Prior policy versions with effective datesDetermines the promises attached to older recordsOld versions overwritten and never archived
Employee and applicant noticesGoverns HR, recruiting and internal communication recordsNever written, or buried in a handbook
Cookie and tracking disclosuresCovers analytics and advertising dataTags added by marketing without a notice update
Consumer request and opt-out logsShows rights requests were handledRequests answered by email with no record kept
Privacy terms in contracts and product screensCustomer-specific promises can override the policyScattered across order forms and MSAs

Folder 3: contracts that govern data#

Contracts often restrict data more tightly than privacy law does. Customer agreements may limit use of customer data to providing the service, prohibit aggregation or require deletion at termination, and those terms follow the records into a sale.

Include customer data processing agreements and MSA data clauses, vendor DPAs and the subprocessor list, terms from AI tools that process company data, and every agreement under which the company licenses data in or out. A one-page summary that flags non-standard data terms saves buyer counsel from reading every order form.

Flag change-of-control and assignment clauses that touch data. Some customer contracts require consent before customer data moves to a new owner or a new processor, and those consents take time to collect.

Folder 4: security and incident history#

Security and incident history tells buyers whether past problems were handled and closed. Include the incident log, breach notifications sent to individuals or regulators, regulator correspondence, recent penetration test summaries with remediation status, cyber insurance claims and any independent security reports.

Present each incident with its root cause and what changed afterward. A documented fix reads very differently from an unexplained entry, and it answers the follow-up question before buyer counsel asks it.

Include the security answers given on the current cyber insurance application as well. Buyer counsel often compares them with the data room, and an answer on the application that contradicts the incident log or the access controls described elsewhere will draw questions.

Folder 5: data assets and the rights to use them#

The data assets folder describes datasets that may carry value beyond running the business, such as support histories, engineering records or job and quality records, together with the rights analysis behind them. It also discloses existing data licenses, internal AI uses and known restrictions.

A recognized vocabulary helps here. The Data & Trust Alliance's Data Provenance Standards include use metadata for confidentiality classification, consent documentation location, privacy-enhancing technologies applied and license to use, which maps closely to what diligence teams ask about a dataset.

Put exclusivity and term at the top of the folder. An exclusive license on a dataset, or a continuing obligation to deliver refreshed records, can limit what a buyer may do with the same records after closing, so summarize those terms before the detail.

Folder 5: data assets and the rights to use them
ItemWhat to include
Dataset descriptionsSystem, record family, date range, approximate scale and how records link
Rights analysisOwnership, customer and vendor restrictions, and notice coverage for each dataset
Existing data licensesCounterparty type, scope, term, exclusivity and deletion obligations
Preparation recordsRedaction logs and privacy records for any dataset already prepared
Internal AI useTools or models trained or tuned on company data, and the terms that apply

Illustrative: preparing the folder for an industrial distributor#

Illustrative: a fictional sponsor is preparing to sell an industrial distributor that runs NetSuite, Salesforce and a help desk it replaced several years earlier. The operating partner asks the CFO and outside privacy counsel to build the five folders before the banker launches the process.

The inventory work finds the retired help desk still readable and full of customer contact details, so it is documented with an owner and a retention decision. Prior privacy policies are reconstructed from archived web captures and the website platform's revision history. The data assets folder records a completed pilot license of order exception records, with its Evidence Packet attached.

When buyer counsel's request list arrives, most privacy questions point to an existing document, and the follow-ups focus on two customer contracts with data-use limits rather than on missing basics.

How SourceX documentation fits a sale process#

Where a portfolio company has licensed data through SourceX, the SourceX Evidence Packet records provenance, licensing rights, permitted use, the privacy record and release authorization for each package. That record can go into the data assets folder as it stands.

For companies that have not licensed data, the metadata-only fit check at the start of the SourceX five-step transaction can help draft dataset descriptions without sharing files and without committing the company to a license during a sale.

Frequently asked questions

When should the privacy folder be built?

Before the process starts, ideally when the sponsor sets a sale timeline. Reconstructing notice history, collecting DPAs and documenting retired systems takes longer than most other data room sections, and gaps found early can be fixed rather than explained.

What if we cannot find old privacy policy versions?

Try web archive captures, your website platform's revision history, legal's email files and old marketing site repositories. Document what you found and what remains unknown. A candid gap note is better than an undated policy presented as the historical version.

Should a data licensing program in progress be disclosed?

Generally yes, because buyers will ask about data uses and existing licenses. Disclose its scope, status and obligations, and consider pausing new commitments such as exclusivity during the sale so the buyer is not surprised by terms it cannot change.

Who should own the privacy folder?

Usually the CFO or general counsel, with outside privacy counsel reviewing. IT supplies the system map and incident records, and the operating partner keeps the folder on the sale timeline. One owner should confirm the folder is complete.

Do lower-middle-market targets need records of processing activities?

That turns on the company's locations and on whose personal data its systems hold. GDPR may require them for some businesses, and US state laws carry their own obligations. Counsel should confirm which apply, but a simple inventory helps either way.

Should the data room itself contain personal data?

As little as possible. Share summaries, samples with personal details removed and redacted contracts rather than raw exports, and keep HR files and customer contact lists out unless counsel says a specific item is needed. Use restricted folders for anything sensitive that must be shown.

Sources

  • The Use group of the Data & Trust Alliance Data Provenance Standards includes elements for confidentiality classification, consent documentation location, privacy-enhancing technologies applied and license to use. Source
  • In May 2015 the FTC recommended that RadioShack customer data be transferred only to a buyer in substantially the same line of business that agrees to be bound by RadioShack's privacy policy. Source
  • State attorneys general led by Texas objected in 2015 to the proposed sale of RadioShack's customer data, citing the privacy policy statement "We do not sell our mailing list." Source

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify