CIPP-US - Limits on Private-Sector Collection and Use of Data - Section 2.6

Explain privacy due diligence obligations in mergers, acquisitions, and divestitures, including the assessment of data asset liabilities and transfer mechanisms.

Explain how M&A due diligence must assess a target's data asset liabilities, including past breach exposure, regulatory investigations, and contractual privacy representations and warranties, before a transaction closes. Recognise that FTC guidance expects the acquirer to honour the original privacy promises made to consumers absent affirmative consent for material changes.

M&A due diligenceData asset liabilityFTC guidance on M&APrivacy representations and warranties

Practice question for this objective

Free sampleLimits on Private-Sector Collection and Use of Datahard

During due diligence for an asset purchase, the acquirer's privacy team discovers that the target collected customer email addresses under a privacy notice that promised the data would never be shared with or transferred to third parties. The acquirer plans to fold those email lists into its own marketing programme post-closing. Under the FTC's approach to privacy in mergers and acquisitions, what is the most defensible position the acquirer should take regarding that data?

  • ATreat the closing as an automatic exception that lets the acquirer use the data under its own newer privacy notice, since the original entity will cease to exist.
  • BHonour the original promise and continue to use the email data only in ways consistent with the notice under which it was collected unless affected consumers are given notice and a chance to opt out. Correct
  • CUse the data freely because privacy promises in a notice are aspirational statements that the FTC does not treat as enforceable commitments.
  • DDelete the email addresses immediately, since any post-closing use of data collected under a restrictive notice is per se unlawful regardless of consumer choice.
Recognise that privacy promises made at collection travel with the data in an acquisition and constrain a successor's reuse absent consumer notice and choice. The FTC has consistently treated a privacy notice as a Section 5 commitment that binds the entity holding the data, including a successor, so a buyer that repurposes data contrary to the collection-time notice without offering notice and choice risks a deception claim.

Why A is wrong: This is tempting because corporate dissolution feels like it severs old obligations, but the FTC has treated promises made to consumers as travelling with the data, so a successor cannot wipe them out simply by closing the deal.

Why B is correct: Correct: the FTC has signalled that a buyer inherits the privacy commitments under which data was collected, so material changes generally require notice and consumer choice rather than silent repurposing.

Why C is wrong: This misstates FTC practice, which treats unfulfilled privacy promises as deceptive acts under Section 5, so a notice commitment is enforceable rather than merely aspirational.

Why D is wrong: Deletion is overcautious and not required as a per se rule; the FTC framework permits continued use consistent with the original notice or a changed use accompanied by notice and choice, so this absolute position is wrong.

See more CIPP-US practice questions, answers explained.

More in this domain

Back to all Limits on Private-Sector Collection and Use of Data objectives, or the CIPP-US cert hub.

Examworthy is not affiliated with or endorsed by IAPP. Original, blueprint-aligned practice material only.