Mergers and acquisitions (M&A) inevitably involve the transfer of valuable corporate assets—and among the most sensitive of these are databases containing personal data. Whether these datasets relate to healthcare professionals, employees, customers, suppliers, or business partners, their transfer raises questions under data protection law.
What is the role of consent in data transfers during M&A? What are the data protection obligations when data changes hands?
1. Consent in M&A: Is It Always Necessary?
A common concern in M&A transactions is whether companies must obtain fresh consent from data subjects when personal data is transferred to the acquiring entity. In many cases under Italian and EU law, the answer is no, thanks to the principle of continuity of processing.
The Italian Data Protection Authority (the Garante per la protezione dei dati personali) has clarified this position in several decisions, including Decision No. 97/2015. According to the Garante, when an M&A transaction involves a transfer of a business or business unit, the applicable provisions of the Italian Civil Code—specifically Articles 2558, 2559, 2560, and 2112—establish a legal succession framework.
Under this framework:
- The acquiring company automatically steps into the legal position of the seller.
- All contractual relationships, rights, and obligations transfer seamlessly.
- This includes data processing activities connected to those relationships.
As a result, the transfer of personal data does not require new consent, provided that:
- The data continues to be used for the same purposes for which it was originally collected.
- The processing remains within the expectations of the data subjects.
This principle reflects a pragmatic balance between business continuity and data protection, avoiding unnecessary disruption to commercial operations.
2. Privacy Notice Obligations: the Role of Article 14 GDPR
Even when consent is not required, the GDPR imposes strict transparency obligations.
When personal data is not collected directly from the data subject—as is typically the case in M&A transactions—the acquiring company must provide a privacy notice pursuant to Article 14 GDPR.
This obligation has been reinforced by the Garante in Decision No. 285/2022 and earlier guidance, including the 2009 guidelines on mergers and demergers.
3. How to Provide a Privacy Notice: Simplified Approaches
Given the potentially large number of individuals involved, providing individual notices can be challenging. Fortunately, the Garante has recognized simplified methods of compliance, including:
- Publication of the privacy notice on the websites of both the transferring and acquiring companies.
- Deferred individual communication, such as sending an email at the first available opportunity.
These approaches, confirmed in Decisions No. 664/2015 and No. 97/2015, strike a balance between practicality and transparency, especially in large-scale transactions.
4. Key Takeaways for M&A Practitioners
To ensure compliance when transferring databases in an M&A context, companies should:
· Rely on the principle of continuity of processing, where applicable. This avoids unnecessary consent collection if legal succession applies.
· Provide Article 14 GDPR privacy notices to affected individuals. Simplified communication methods when dealing with large datasets can be used.
You must be logged in to post a comment.