Table of Contents
Due Diligence Examination and Its Participants
From the perspective of capital companies, the possibility of acquiring another company is an extremely important issue. Various types of transactions may occur in the market, for example, one company acquires another by purchasing a majority stake in the share capital (share deal), acquiring an organized part of the enterprise (asset deal), or merging companies by acquiring the assets of one company in exchange for issuing shares to the shareholders of the acquired company (merger by acquisition) or merging by creating a new company. These transactions are often preceded by an examination of the potential investment known as due diligence (due diligence).

Due diligence is therefore a comprehensive examination of the acquired company (the seller) by the investing company (the buyer), involving the collection and verification of information significant from the perspective of the transaction participants. Such an examination may take the form of a legal and financial audit, during which the legal status of the company is assessed (from corporate matters to legal-environmental issues, as well as personal data) and financial matters (correctness of accounting records, financial reporting, tax risks).
Due diligence is usually conducted by a professional entity. It is often the case that this is a specialized law firm or its department. However, other entities may also be involved in the audit: IT specialists, accountants, tax advisors, patent attorneys, financial analysts, etc.
In practice, to provide documentation to the buyer/auditor, solutions such as virtual data rooms (VDR) are used, which allow for the sharing of documents with the entities conducting the examination and – if they come from trusted providers and are properly configured – can ensure the confidentiality of information and control over their sharing.
It follows from the above that the due diligence process requires access to a rich repository of documents and information (employee documents, administrative decisions, accounting documents, policies and procedures, invoices, contracts, etc.). Moreover, many entities can be identified as involved in this process. For simplicity, I will refer to them as follows:
- Buyer – e.g., investor, acquiring entity, etc.,
- Seller – company seeking an investor, acquired entity, etc.,
- Auditor – professional entity conducting due diligence on behalf of the Buyer,
- VDR – provider of virtual data room.
Implications for Due Diligence Arising from Personal Data Protection Law
From the perspective of personal data protection law, the issues of due diligence investigations have two main aspects: the organization of the investigation itself and the security of personal data during its course, as well as the examination of the data protection system by the Buyer (e.g., acquirer) at the Seller's (e.g., acquired company's) premises.
Organization of the Investigation from the Perspective of GDPR
At the preparation stage for the investigation, it is essential to remember the principles of data protection by design and by default, which impose on data controllers the obligation to design the process and implement such technical and organizational measures (e.g., pseudonymization) that effectively realize the principles of data protection (e.g., minimization), the requirements set by GDPR, and the rights of individuals whose data is being processed.
In light of the above, it should be noted that the first step is to establish the legal bases for processing and the roles of all entities involved in the entire process.
In practice, various configurations of entities and data flows may arise. In my article, I will present the following case: the Buyer enters into a preliminary agreement with the Seller regarding the potential acquisition of a majority stake in the company. After signing the letter of intent/NDA/due diligence regulations, the Buyer enters into an agreement with the Auditor. Subsequently, the Seller enters into a VDR service agreement and provides the requested documents therein. After the audit is conducted, the Auditor and the Buyer lose access rights, and the documents are deleted.
In practice, the above relationship may take two configurations, in which:
- The Buyer is a separate data controller, and the Auditor is a data processor (assuming it is not a law firm bound by professional secrecy);
- The Buyer is a data processor, and the Auditor is a further data processor (so-called sub-processor).
In the initial configuration, both the Seller and the Buyer will be separate data controllers, as each will decide on the purposes and means of processing. There is no doubt that the Seller is the primary data controller of the personal data processed within its organization: employee data, data contained in various commercial and accounting documents, etc. Subsequently, the Seller makes decisions regarding the sharing of this data based on its legitimate interest. At the moment of data sharing – via the VDR – the Buyer becomes the second data controller (this will not be a co-controller relationship). The Buyer, as a separate data controller, will have full discretion in determining the purposes and means of processing personal data; however, it is also burdened with the obligations of a data controller arising from the GDPR, e.g., the information obligation towards the data subjects. Furthermore, after the completion of the due diligence process, the legitimate interest of the Buyer will cease to be a legal basis for processing.
An important variable in the scenario I mentioned at the outset is the situation when the Auditor is a professional entity subject to specific regulations, such as a law firm, which, due to the necessity of ensuring the provision of legal assistance in accordance with the laws regulating the practice of a given legal profession (including professional secrecy and data retention periods) and codes of professional ethics, will be a separate data controller.
Below is a diagram of the configuration with three data controllers:

In the ADO-ADO relationship, the basis for the processing of data by the Buyer is generally Article 6(1)(f) of the GDPR, although it should be noted that legitimate interest does not serve to legalize every processing when other letters of Article 6(1) of the GDPR do not apply; this basis is not a key but a key that must fit within the framework of the legitimate interest criteria, which consist of the following elements:
- The ADO (here: the Buyer) pursues a legitimate interest (here: to know and confirm all facts affecting the interests of the Buyer in a given transaction);
- The processing must be necessary for the realization of the given legitimate interest (most personal data contained in contracts, invoices, employee documentation, etc. may prove to be unnecessary);
- the interests or fundamental rights and freedoms of the data subject are not overriding (legitimate interest assessment).
The data controller should take into account the intensity of the interference with the rights and freedoms of the individual, as well as their characteristics, such as age. Reasonable considerations of the data subject should be taken into account to expect that processing for a given purpose may occur.
If the balance of interests weighs in favor of the data subject, the data controller wishing to continue processing should implement appropriate technical and organizational measures to shift the balance of interests in their favor, for example, through pseudonymization or anonymization.
Thus, the relationship between data controllers – data controllers is associated not only with issues related to informing the data subjects but also with determining the legal basis for processing under the conditions of Article 6(1)(f) in connection with Recital 47 of the GDPR.
Moreover, the parties have full freedom to establish mutual contractual obligations.
It therefore seems possible to design a due diligence investigation in which there will actually be a data controller-data processor relationship (in terms of information provided by the Seller), which in the case of entities not covered by professional secrecy will result in a lack of specific obligations towards the data subjects.
As a result, with the correct definition of the subject and scope of the entrustment in the relevant agreements and the configuration of the tools used, as well as appropriate personal data security measures, including their pseudonymization or anonymization, and adequate minimization to the data necessary for the purpose of due diligence, a GDPR-compliant relationship can be established between the entities, in which the Seller will be the data controller, the Buyer and VDR will be data processors in relation to the Seller, and the Auditor will be a sub-processor in relation to the Buyer.

Due diligence investigation regarding personal data protection based on the ICO decision concerning Marriott International Inc.
Since the entry into force of the GDPR, sanctions for violations of personal data protection have significantly increased, therefore the entity acquiring another company should, during due diligence (in terms of formal-legal and technical aspects), take into account the personal data protection system, and thus the Buyer should request from the Seller documentation on personal data protection, in particular the records of processing activities, the register of all categories of processing activities, data protection policies, risk analysis reports and DPIAs, breach registers, data processing agreements, etc.
Furthermore, due diligence should aim at a thorough verification of the technical and organizational measures currently and previously employed by the Seller.
An example illustrating the risks associated with acquiring a company without conducting thorough due diligence in the area of personal data security is the fine imposed by the UK supervisory authority ICO in the amount of £18.4 million on Marriott International Inc.
Facts
- In 2014, unknown perpetrators installed a piece of code known as a “web shell” on the server resources of the Starwood hotel network, which is a form of backdoor access to the server's system shell.
- The web shell allowed hackers remote access to the system, through which they could install RATs (Remote Access Trojans) within the Starwood resources. The Trojans enabled the attackers to gain access to system administrator privileges.
- Subsequently, the hackers installed the Mimikatz credential thief in the Starwood system, through which they accessed individual user accounts, increasing the extent of system penetration and ultimately allowing them to execute their own commands within the Starwood systems.
- Between 2015 and 2016, hackers placed additional files on the Starwood servers that allowed for the theft of data contained within the hotel network's resources.
-
In September 2016, Marriott acquired Starwood (through a merger of companies). Initially, the systems of both networks were separate; however, Marriott planned to integrate the Starwood system into its own systems.
Free knowledge about GDPR.
Use it freely!Webinars, articles, guides, training, snapshots, and assistance. Welcome to the ODO 24 knowledge base.I'M IN - After the acquisition process was completed, hackers placed memory scraper malware on the servers, which can intercept data contained, among other things, in payment terminals.
- In 2018, hackers conducted further activities on Marriott's servers, which triggered an alert from the data security software, activating Marriott's internal procedures that resulted in notifying the ICO of the breach on November 22, 2018. On November 30, the hotel chain began informing individuals whose data may have been affected by the attack.
- The data breach involved a wide range of data, including in unencrypted form: guest ID, name, gender, date of birth, VIP status, membership in a loyalty program, email address, country code in the passport, as well as full passport numbers, phone and fax numbers, expiration date of the payment card, flight number, etc. In encrypted form, 18,500,000 passport numbers and 9,100,000 payment card numbers were leaked.
- According to Marriott, approximately 339,000,000 records belonging to guests were breached. About 30,100,000 records belonged to individuals residing in the EEA. The fine imposed by the ICO amounted to £18,400,000.
Due Diligence of Personal Data Systems in Light of the ICO Decision
The Commissioner emphasized in her decision that, in principle, due diligence is conducted prior to or shortly after an acquisition; however, this is not the only circumstance that determines the need for such an assessment. Due diligence regarding personal data is not a one-time activity.
Marriott should be aware that the GDPR came into effect on May 25, 2018, and ensure that its security systems were ready for the regulation's implementation; however, after the regulation came into force, Marriott continued to process data using faulty systems.
According to the ICO, the data controller has a continuous obligation to ensure that the technical and organizational measures it employs are compliant with the GDPR. Even if thorough due diligence was conducted during the acquisition of the second company, which took place before May 25, 2018, this does not exempt the data controller from the ongoing obligation to ensure compliance with the GDPR.
The decision noted that Marriott only conducted a PCI DSS audit, which is limited in scope and does not cover all systems and actions that should be taken in the given circumstances. The audit conducted by Marriott was deemed insufficient by the ICO—thorough due diligence of the data protection system should also include the adequacy of monitoring systems within the network.
In this regard, Marriott violated Article 5(1)(f) of the GDPR, i.e., the principle of data integrity and confidentiality, as well as Article 32 of the GDPR, which resulted in the imposition of the aforementioned fine.
Summary
Due diligence is not a simple process, especially from the perspective of personal data protection. The very organization of the process of examining the acquired company can pose a challenge for any entity involved in this process. However, it is possible to design the privacy examination in such a way that data is processed securely, and the principles of processing are effectively implemented at every stage of due diligence, while maintaining a business-friendly approach.
Buyers should, however, remember that the examination must be conducted diligently, as upon acquiring the Seller, the Buyer becomes the data controller of the data that previously remained under the control of the acquired entity, and consequently – is responsible for the security of the processed data.
The example of the British fine imposed on Marriott demonstrated that inadequate due diligence can have very severe consequences for the Buyer.


