When Data Changes Hands: Implications of DPDPA in Business Transfer Agreements
- Dwaipayan Dey, Kushagra Keshav
- 1 day ago
- 6 min read
[Dwaipayan and Kushagra are students at West Bengal National University of Juridical Sciences and National Law University Odisha, respectively.]
In this era of digitalisation, personal data has become one of the most commercially significant assets exchanged during business transfers. Resultantly, in the transfer of a business undertaking as a going concern through a business transfer agreement (BTA), the customer databases, analytics, and profiles often form a significant part of the transactional value. Yet for the large part of India’s corporate history, there has been an absence of a legislative machinery that specifically interrogates such transfer of digital personal data.
Â
The Digital Personal Data Protection Act 2023 (DPDPA) changes this notion. It does not treat personal data as a passive appendage to the undertaking. Instead, it treats every use, disclosure, transfer, storage or adaptation of digital personal data as processing and fixes responsibility on the data fiduciary. Therefore, now a BTA does not merely transfer an asset bundle, instead it creates a privacy event that must be justified under DPDPA. However, what makes DPDPA’s intervention particularly complex is the absence of a specific statutory architecture around BTA transactions and the questions it leaves unanswered. This is what will be discussed in this article.
Â
The Consent Portability Question: Does a BTA Transfer the Consent along with Data?
Section 6(1) of DPDPA constructs consent as a personal and purpose-specific instrument. Crucially, consent is to be strictly confined to a defined purpose and a fresh consent must be obtained if the purpose changes. DPDPA further vests the data principal with an unqualified right to withdraw consent under Section 6(4), upon which the data fiduciary must cease processing. This architecture, therefore, implicitly embeds a foundational principle that consent is not a transferable commodity.
Â
A BTA fundamentally disrupts this foundational principle. The acquiring company becomes a new data fiduciary, one to whom the data principal neither consented to provide their data nor anticipated the same. The target company’s original consent notice under Section 5(1) of DPDPA could not have identified the acquirer during collection. Therefore, the data moves but the legal basis for its processing does not.
Â
At this juncture, Section 17(1)(e) of DPDPA demands attention because it is the statute’s only direct response to mergers and acquisitions (M&A) and transfer of undertakings. Section 17(1)(e) exempts court or tribunal-approved M&A and transfers from certain processing obligations under Chapter II, including the consent framework. However, this exemption operates with a critical limitation. A BTA implemented as a slump sale is a contractual transaction not requiring authoritative approval unless it is embedded within a larger scheme of share arrangement. Consequently, a standard BTA falls entirely outside Section 17(1)(e) of DPDPA. So, the full force of DPDPA’s consent framework applies to a BTA.
The question then becomes whether the legitimate uses exception under Section 7 of DPDPA can be stretched to cover this gap. Section 7(a) permits processing where a data fiduciary processes data for the specified purpose for which the data principal voluntarily provided it. But, this provision is wholly inapt in the context of BTAs as it does not envisage transfer of data through a commercial agreement.Â
Â
Thus, the only legally defensible position for a BTA outside the Section 17(1)(e) exemption is that the acquiring company must obtain fresh consent from all data principals before it can lawfully process the acquired data. This is operationally extremely arduous but legally unavoidable under the current statute.
Â
The Successor Liability Question: Who Answers for the Target’s Data Liabilities Post-Closing of a BTA?
Along with the consent portability problem, an equally troubling issue pertains to the transfer of the target’s data liabilities post the closing of BTA. This is because DPDPA contains no provision addressing whether an acquirer inherits the regulatory and penalty exposure of the target company for pre-transfer violations.
Â
This silence produces a peculiar paradox when placed alongside Section 17(1)(e). For exempted M&A scenarios, if the consent and processing obligations of Chapter II are suspended in favour of the acquirer, the question then arises that on what legal basis will the Data Protection Board of India assert jurisdiction over the acquirer for the target's pre-BTA violations of those very suspended obligations. For non-exempted BTAs, the problem is different but equally unresolved. While the acquirer may step into the role of data fiduciary over the acquired data, the DPDPA’s penalty provisions are structured as prospective obligations on the data fiduciary committing the violation and not on its successors. Also, there is no continuing violation doctrine or economic continuity principle embedded in the statute to make the acquirer liable.
Â
When compared to the European Union’s General Data Protection Regulation (GDPR), the position is much different. The Court of Justice of the European Union has developed a doctrine of economic succession under which the acquirer can become liable for the seller’s regulatory violations even when they took no part or were unaware of the infringement. A practical expression of this principle was observed in the Marriott-Starwood enforcement action by the UK Information Commissioner’s Office (ICO). The ICO held that the GDPR’s accountability requirement encompasses carrying out proper due diligence in corporate acquisitions to assess not only what personal data has been acquired but how it is protected. Further, acquiring a pre-existing security incident through a corporate transaction can trigger regulatory liability for the acquirer.
Â
So, the DPDPA’s silence on this question is essentially a legislative lacuna. Consequently, the general principle under Sections 230-232 of the Companies Act 2013 that upon amalgamation, all property, liabilities, and pending legal proceedings of the transferor vest in the transferee offers a contextual bridge, though operating on a distinct legislative plane from the DPDPA. Furthermore, the principles of Sections 230-232 are applicable to the exempted M&A under DPDPA, with nothing to guide the non-exempted BTAs.
A Comparative Lens: What the European Data Protection Board’s Asset Deal Framework Teaches India
Before examining the comparative frameworks, one must differentiate between the two principal modalities of corporate acquisition, i.e., share deal and asset deal. In share deals, the acquiring entity acquires shares in the target company. Alternatively, in an asset deal, the same acquiring entity purchases tangible and intangible assets of the seller company.
Currently, the European Data Protection Board (EDPB) has not published a dedicated guideline for regulating asset deals. However, it may be distilled from an official statement and the EDPB’s guidelines on a lawful basis under GDPR. In its statement of privacy implications of mergers, the EDPB invoked the accountability principle under Article 5(2) of GDPR and mandated the transacting parties to conduct full and transparent assessment of the data protection requirements and privacy implication before consummating M&As. The EDPB’s Guidelines 1/2024 on Processing of Personal Data based on Article 6(1)(f) GDPR establish the principle of accountability, where the determination of a lawful basis of processing personal data falls non-delegably upon the controller undertaking that processing. Relatively, Article 14 of the GDPR underscores the existence of explicit consent of data subjects when the sensitive data is being processed between a transferor and transferee. For the asset deal context, it is imperative that the data subjects be given the reasonable opportunity to object.Â
In India, the difficulty crystallises in the context of private BTAs involving transfer of sensitive data of data principals as part of an asset deal. Unlike a share deal, wherein the legal identity of the data fiduciary remains undisturbed and the original consent framework survives intact, an asset deal on the other hand alters the fiduciary relationship. Thus, DPDPA’s omission of any analogous framework to that of GDPR creates a regulatory vacuum on how to structure the transfer of personal/sensitive data in a BTA.
Way ForwardÂ
This regulatory vacuum in India is not irremediable. Instead, certain suggestions can be implemented to bring BTAs within a compliant and risk proof data governance framework:Â
Contractual layering
The burden befalls on the contracting parties to address the regulatory vacuum. Drawing inspiration from the ICO Data Sharing Code of Practice, the acquirers can verify the original purpose behind data collection and determine how the data principals will be notified of the change and their right to object. Additionally, data protection warranties, acquirer-facing indemnities, and pre-closing data protection audits can be contractually incorporated.Â
Legislative reforms
DPDPA should inculcate a deemed consent framework for BTA scenarios modelled on the business asset transaction exception under Part 4 of the Singapore’s Personal Data Protection Act 2012 (PDPA), as explained in the PDPC’s Advisory Guidelines on Key Concepts in the PDPA. This permits personal data transfer without consent provided that the affected individuals are notified and given an opportunity to withdraw their consent. In fact, the 2022 Data Protection Bill had included the recognised ground of deemed consent, which was subsequently removed.Â
Additionally, successor liability with a due-diligence defence, extension of Section 17(1)(e)Â exemption to BTAs, and a transaction size-based consent compliance framework can be introduced.
Conclusion
The DPDPA recognises personal data as a right-bearing asset and not a passive commercial commodity. However, the consent portability problem and the successor liability lacuna are not just peripheral inconsistencies; instead, they constitute structural gaps that must be corrected.
The comparative frameworks discussed above: (i) the EDPB’s accountability-first approach, (ii) the ICO’s due diligence mandate, and (iii) Singapore’s statutory business asset transaction exception, together show that these are solvable problems. India, therefore, must adopt such mature data protection frameworks. Until then, Indian BTAs transferring personal data will remain a contingent liability in search of a regulatory answer.