Skip to content

Private equity and portfolios

Stock purchase vs asset purchase: what happens to data rights

By SourceX Editorial · Reviewed by Noah Loul ·

Short answer

In a stock purchase, data rights generally stay with the acquired company, so its records, contracts, privacy notices and restrictions carry over without a transfer. In an asset purchase, only the databases, customer records and contracts listed in the agreement move, and some need consents. In both structures the buyer inherits the limits on use, not just the records.

Key takeaways

  • A stock purchase changes who owns the company, not who owns the records, so data and its obligations stay inside the acquired entity.
  • An asset purchase moves only what the agreement identifies, so databases, books and records, and system accounts need to be listed.
  • Privacy notices and customer contracts limit what a buyer may do with records in either structure.
  • Anti-assignment clauses matter most in asset deals; change-of-control clauses can matter in stock deals.
  • The structure decides which entity is the supplier, and who signs, for any later data license.

What is the core difference for data?#

The core difference is what the buyer acquires. In a stock purchase, the buyer acquires the equity of the target company, and the company keeps owning everything it owned before closing, including its databases, system accounts, contracts and obligations. In an asset purchase, the buyer acquires specific assets from the seller, and anything not identified in the agreement generally stays behind.

For a general counsel, that means two different diligence questions. In a stock deal the question is what restrictions the company already carries. In an asset deal it is also whether the records and the rights to use them were actually transferred and documented.

What carries over in each structure#

The table compares how common data-related items are typically treated. It describes general patterns only; the purchase agreement, the underlying contracts and applicable law decide the actual result in each deal.

Two rows cause most surprises in asset deals. System accounts look like a technical detail, but a CRM or helpdesk subscription is a contract in the seller's name, and losing it can mean losing the history inside it. Seller copies matter later: a buyer that plans to license records exclusively cannot easily do so if the seller kept an unrestricted copy of the same archive.

What carries over in each structure
ItemStock purchaseAsset purchase
Databases and system recordsStay with the companyTransfer only if listed, often as books and records or data
Customer records and CRM historyStay with the companyTransfer if listed; personal information may need privacy review
SaaS accounts and admin accessStay in the company's nameNeed assignment or a new account, often with vendor consent
Customer and vendor contractsStay in place; change-of-control clauses may applyNeed assignment; anti-assignment clauses may require consent
Privacy notices and consentsContinue to bind the companyTravel with the records as limits on use
Employee email and HR recordsStay with the companyTransfer is limited and often needs separate review
Code and other IPStay with the companyTransfer through an IP assignment schedule
Seller copies after closingNot usually an issueSeller may retain copies unless the agreement limits it

Where asset deals lose data#

Asset deals lose data when the schedules describe the business but not its records. A purchase agreement can list equipment, inventory, trade names and customer contracts in detail and still say nothing clear about the CRM history, the helpdesk archive or the shared drives that hold years of project files.

Other gaps are practical. The seller's SaaS subscriptions may be in its own name and lapse after closing. Excluded assets may include a parent's shared systems in a carve-out. A transition services agreement may provide access for a limited period without any obligation to export history. And unless the agreement says otherwise, the seller may keep copies of transferred records, which can affect any later exclusivity the buyer wants to offer.

Restrictions travel with the records#

Restrictions travel with the records in both structures. A buyer of the company, or of its assets, generally takes records subject to the promises made when they were collected: privacy notices given to customers and website visitors, confidentiality clauses in customer contracts, employee notices about monitoring, and vendor terms that govern data held in their platforms.

Transfers of personal information deserve particular care in asset deals. Depending on what the seller's privacy notice said and where customers live, state privacy laws such as the CCPA and consumer protection rules may apply to the transfer and to later uses. Which laws apply, and what they require, is assessed deal by deal with counsel.

Regulators have shown how they view consumer data in a sale. In a May 2015 letter about the RadioShack bankruptcy sale, the FTC's consumer protection director recommended that customer data not be sold as a standalone asset and that it go only to a buyer in substantially the same line of business that agrees to be bound by the existing privacy policy. That was a bankruptcy matter with consumer records, but the logic is a useful test for any asset deal: the promises made at collection tend to follow the records.

Mergers and change-of-control clauses#

Mergers are a third structure with their own effects on data. In many mergers the target's assets and obligations pass to the surviving entity by operation of law, and in a reverse triangular merger the target survives as a subsidiary, which resembles a stock purchase for data purposes.

Whether a merger or stock sale counts as an assignment under a particular contract depends on that contract's wording and its governing law. Some customer and vendor agreements define a change of control as an assignment requiring consent; others are silent. Read the clause in each material contract rather than relying on the structure alone.

A data rights checklist for the deal team#

The checklist below covers the data items deal counsel should confirm before signing, whichever structure is used. Answering them before closing is much easier than reconstructing them when a data license or a later sale raises the question.

  • Identify which legal entity holds each system, account and record family.
  • In an asset deal, list databases, books and records, system accounts and data rights in the transferred assets schedule.
  • Confirm whether the seller may retain copies, and for what purposes.
  • Map anti-assignment and change-of-control clauses in material customer and vendor contracts.
  • Collect the privacy notices and employee notices in force when records were created.
  • Check vendor terms for account transfer and export rights.
  • Set export obligations and formats in any transition services agreement.
  • Record existing data licenses the target has granted and whether they need consent to survive.

Illustrative: two add-ons, two structures#

Illustrative: a fictional logistics platform buys two add-ons in the same year. The first, a freight brokerage, is acquired by stock purchase. Its TMS history, load board records and carrier communications stay with the brokerage entity, along with its customer contracts and privacy notice, and nothing needs to be assigned. Counsel checks two large shipper agreements with change-of-control clauses and obtains consent.

The second, a family-owned warehouse operation, is acquired as assets. The first draft of the agreement lists racking, forklifts and customer contracts but not the WMS history. Counsel adds books and records, the WMS database and system accounts to the schedule, limits the seller's retained copies to tax and legal purposes, and requires a full export in the transition services agreement. A later licensing review finds both histories documented and owned by the right entities.

How SourceX reviews deal structure during rights review#

SourceX looks at deal structure in the Rights step of the SourceX five-step transaction: Supply, Rights, Preparation, Approval and Delivery. For acquired companies, the review asks which entity holds the records, how they arrived there and which acquired contracts still limit their use.

The answers are recorded in the provenance and licensing rights sections of the SourceX Evidence Packet, so a buyer of the license and any future acquirer of the company can see the chain from the original business to the current supplier.

Frequently asked questions

Does the buyer get customer data in an asset purchase?

Only what the agreement transfers. If customer records, CRM history or databases are not listed, or are listed as excluded assets, they generally stay with the seller. Even when they transfer, privacy notices and customer contracts continue to limit how the buyer may use them.

Can the seller keep a copy of data after an asset sale?

Often, unless the agreement restricts it. Sellers commonly keep records for tax, accounting and legal purposes. If the buyer wants exclusive use of the history, for example to license it later, the agreement should limit retained copies and their permitted purposes.

Do we need customer consent to move personal information in an asset deal?

It depends on what the seller's privacy notice promised, the laws that apply to those customers and the type of information. Some transfers may be permitted as part of a business sale; others may need notice or consent. Counsel assesses this deal by deal.

What if the purchase agreement says nothing about data?

Then the answer depends on how the transferred assets are described and on general contract principles, which can leave real doubt. Where data matters, a short confirmatory assignment or amendment that lists the records and system accounts can remove the ambiguity.

Does deal structure affect who signs a later data license?

Yes. After a stock purchase, the acquired company usually remains the supplier and its officer signs. After an asset purchase, the buyer entity that received the records signs, provided the transfer and the restrictions attached to it have been documented.

Sources

  • In a May 2015 letter to the RadioShack consumer privacy ombudsman, the FTC's Bureau of Consumer Protection Director recommended that customer data not be sold as a standalone asset and be transferred only to a buyer in substantially the same line of business that agrees to be bound by RadioShack's privacy policy. Source

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify