THE ASSET TRANSFER TRAP: NAVIGATING THE INTERSECTIONS OF CORPORATE RESTRUCTURING AND THE DPDPA.

ABSTRACT

Corporate acquisitions have traditionally treated customer and employee data as just another business asset that could be transferred along with the company. However, the Digital Personal Data Protection Act, 2023 (DPDPA) has fundamentally changed this approach by recognizing companies as custodians not owners of personal data. This shift creates what the article describes as the “Asset Transfer Trap,” where personal data cannot automatically move to a new owner unless the legal requirements of consent and purpose limitation are satisfied.

The article explains that while court-approved mergers receive a statutory exemption under Section 17(1)(e), private transactions such as slump sales and business transfer agreements do not. As a result, businesses may need to obtain fresh consent from every individual before using transferred personal data, significantly reducing the commercial value of acquisitions if many users decline or ignore consent requests.

It further highlights how the DPDPA transforms due diligence and transaction planning. Companies must adopt privacy-conscious practices, redesign contractual protections, strengthen representations and warranties, and allocate data-related risks through tailored indemnities and conditions precedent. Ultimately, the article argues that successful corporate restructuring now depends not only on financial and commercial considerations but also on responsible data governance and regulatory compliance. In the post-DPDPA era, personal data is no longer merely an asset to be transferred it is a legal responsibility that can determine the success or failure of an entire transaction.

INTRO: The Shift from “Asset” to “Fiduciary”

For decades, corporate mergers and acquisitions (M&A) operated on the assumption that data was a business asset like any other. Customer databases, employee records, and transaction histories were routinely treated as valuable commercial property, transferred alongside factories, intellectual property, or inventory during business acquisitions. Whether through a Business Transfer Agreement (BTA) or a slump sale under Section 2(42C) of the Income Tax Act, 1961, personal data formed an integral part of the transaction, with little distinction between physical assets and digital information. Buyers valued these databases for their commercial potential, relying on metrics such as Customer Acquisition Cost (CAC) and Lifetime Value (LTV), and expected to integrate them seamlessly into their own operations immediately after closing the deal.

The Digital Personal Data Protection Act, 2023 (DPDPA), however, fundamentally reshapes this long-standing approach. Inspired by the Supreme Court’s decision in Justice K.S. Puttaswamy (Retd.) v. Union of India (2017), which recognised informational privacy as a fundamental right under Article 21 of the Constitution, the Act shifts the legal focus from ownership to stewardship. Under Section 2(i), companies are no longer regarded as owners of personal data but as Data Fiduciaries entrusted with processing such data only for the specific purposes authorised by the Data Principal. Consequently, when a business changes hands, personal data does not automatically accompany the transfer of corporate assets. Instead, it remains legally tied to the consent and purpose for which it was originally collected.

This transformation creates a significant operational challenge for private corporate restructurings, including asset purchases, Business Transfer Agreements, and slump sales that occur outside court-approved restructuring schemes. Since these transactions generally fall outside the exemptions provided under the DPDPA, businesses cannot freely transfer user consent along with the acquired assets. The result is the “Asset Transfer Trap,” where the inability to lawfully migrate personal data threatens business continuity, weakens the commercial value of acquisitions, and introduces a new layer of regulatory risk into modern corporate transactions.

The Section 17(1)(e) Paradox (Court vs. Private Deals)

Section 17(1)(e) of the Digital Personal Data Protection Act, 2023 (DPDPA) reflects the legislature’s attempt to reconcile corporate restructuring with data protection obligations. Recognising that mergers, amalgamations, and demergers often require the seamless transfer of operational data, the provision does not apply to data processing done as part of such restructuring schemes from most obligations under Chapters II and III of the Act, subject to the security safeguards prescribed under Section 8. However, this exemption is available only where the restructuring scheme has been approved by a court, tribunal, or another authority competent under law. While this qualification ensures regulatory oversight, it also creates a significant gap between judicially sanctioned restructurings and the far more common private corporate transactions.

This distinction gives rise to what may be described as the Section 17(1)(e) paradox. Court-approved schemes under Sections 230–232 of the Companies Act, 2013, which are supervised by the National Company Law Tribunal (NCLT), benefit from the statutory exemption and permit the transfer of personal data without obtaining fresh consent. In contrast, private acquisitions, Business Transfer Agreements (BTAs), and slump sales under Sections 2(42C) and 50B of the Income Tax Act, 1961, are completed solely through contractual arrangements and do not require judicial approval. Although these transactions are commercially efficient and widely used, they fall outside the scope of Section 17(1)(e), leaving them fully subject to the DPDPA’s compliance requirements.

As a result, the transfer of customer databases in private transactions is no longer treated as an automatic consequence of acquiring the business. Before personal data can be transferred to the buyer, the seller must comply with the notice requirement under Section 5 by informing every Data Principal about the proposed transfer and its purpose, while Section 6 requires obtaining fresh, free, specific, informed, and unambiguous consent from each individual. This represents a conscious departure from the draft Digital Personal Data Protection Bill, 2022, which had recognised broad “deemed consent” for mergers, acquisitions, and corporate restructurings. By limiting this relaxation to court-approved schemes in the final Act, the legislature has signalled that private commercial transactions are not entitled to the same regulatory flexibility. Consequently, if users refuse or fail to provide fresh consent following a private acquisition, the buyer may be legally prevented from processing the acquired database, significantly undermining the commercial value of the transaction and exposing businesses to the very “Asset Transfer Trap” that the DPDPA has created.

The Purpose-Limitation Bottleneck

One of the defining features of the Digital Personal Data Protection Act, 2023 (DPDPA) is its insistence that personal data be processed only for the specific purpose for which it was originally collected. Section 4(1)(a) permits a Data Fiduciary to process digital personal data only for a lawful purpose backed by the Data Principal’s consent. This principle is reinforced by Section 5(1)(i), which requires every request for consent to be accompanied by a clear and specific notice explaining the categories of personal data being collected and the precise purpose for which it will be processed. Further strengthening this framework, Section 6(1) mandates that consent must be free, specific, informed, unconditional, and unambiguous. Together, these provisions eliminate the long-standing practice of relying on broad or vaguely worded privacy policies that authorised future or undefined uses of personal data. Once the purpose disclosed in the notice has been fulfilled, or the processing begins to serve a materially different objective, the original consent ceases to provide a valid legal basis for further processing.

This statutory framework creates a significant obstacle during private corporate acquisitions, where the commercial objective is rarely limited to preserving the acquired business in its existing form. Instead, buyers typically seek to integrate the acquired company’s customer base into a broader digital ecosystem to enable cross-selling, behavioural analytics, and the delivery of new products and services. Consider a common transaction involving a food delivery platform that collects users’ names, phone numbers, GPS locations, and dietary preferences solely to facilitate food and grocery deliveries. If the platform is subsequently acquired through a private slump sale by a conglomerate intending to incorporate those users into its fintech, lending, or digital payments ecosystem, the legal basis for processing immediately comes into question. The consent originally obtained was limited to food delivery services, and extending the same data to credit assessment, financial advertising, or lending operations amounts to a classic case of purpose creep. Since the nature and objective of processing have fundamentally changed, the original consent cannot legitimise the buyer’s intended use of the data.

The consequences are particularly severe because, upon completion of the acquisition, the buyer assumes the role of a successor Data Fiduciary without inheriting the original consent for its new processing purposes. As the transaction falls outside the exemption under Section 17(1)(e), the buyer must issue fresh notices under Section 5 and obtain new, affirmative consent under Section 6 from every affected user before integrating the acquired database into its own ecosystem. In practice, however, consumer response rates to privacy notices are often low. Many users ignore consent requests, actively opt out, or discontinue using the service altogether. As illustrated below, if only two million out of ten million users provide fresh consent, the remaining eight million records become legally unusable and, under Section 8(7), may ultimately require deletion once the original purpose has expired. The result is the “Asset Transfer Trap” in its most tangible form: a substantial portion of the very database that justified the acquisition may disappear after closing, significantly eroding transaction value while exposing the buyer to regulatory penalties for any unauthorised processing.

The Due Diligence Dilemma (The Data Room Problem)

Due diligence is a cornerstone of every corporate restructuring, enabling prospective acquirers to bridge the information gap between themselves and the target company before a transaction is completed. Traditionally, this process has involved granting buyers extensive access to corporate records through Virtual Data Rooms (VDRs), allowing them to assess the target’s financial health, operational risks, liabilities, and overall valuation. In data-driven businesses, this review often extends beyond financial documents to include employee records, customer transaction histories, user databases, and other commercially valuable information containing significant volumes of personal data. Until recently, the disclosure of such information during due diligence was regarded as a routine aspect of corporate practice, with little consideration given to its implications under data protection law.

The enactment of the Digital Personal Data Protection Act, 2023 (DPDPA), fundamentally changes this position. Section 2(x) defines “processing” broadly to include not only the collection and storage of personal data but also its sharing and dissemination. Consequently, uploading unredacted documents containing personal data to a third-party Virtual Data Room for review by a potential acquirer constitutes an independent act of data processing. This seemingly routine step creates a significant compliance challenge because the personal data was originally collected for entirely different purposes, such as managing employment relationships or providing goods and services to customers. Sharing that data with a prospective purchaser, who has no pre-existing relationship with the Data Principals, may exceed the purposes for which consent was originally obtained under Sections 4 and 5 of the Act. Although it may be argued that employee information disclosed during due diligence falls within the “employment purposes” exception under Section 7(i), this justification is difficult to sustain, as due diligence primarily serves the commercial objective of evaluating a transaction rather than facilitating employment-related functions.

The legal risk becomes even more pronounced if the proposed acquisition ultimately fails. Where negotiations collapse after sensitive personal data has already been shared with a prospective bidder, the target company may have disclosed the personal information of employees and customers to an unrelated third party without any continuing lawful basis for such processing. In these circumstances, what was once considered a routine due diligence exercise may amount to an unauthorised disclosure under the DPDPA, exposing the company to regulatory scrutiny by the Data Protection Board of India (DPBI) and significant financial penalties, including fines that may extend up to ₹250 crore for failure to implement adequate security safeguards.

The evolving regulatory landscape, therefore, requires a fundamental rethinking of traditional due diligence practices. Rather than relying on unrestricted Virtual Data Rooms, organisations are increasingly adopting what practitioners describe as “consent rooms” or privacy-centric diligence frameworks. These approaches prioritise data minimisation by ensuring that personal identifiers are anonymised or permanently masked before documents are shared, limiting contractual disclosures to carefully redacted samples, and reserving access to high-risk datasets for a restricted “clean team” operating under stringent confidentiality obligations. Such phased disclosure mechanisms enable buyers to conduct meaningful commercial due diligence while significantly reducing the risk of unlawful processing under the DPDPA. In the post-DPDPA era, effective due diligence is no longer measured solely by the quality of financial disclosure but equally by the robustness of data governance and privacy compliance throughout the transaction process.

Redefining Deal Documentation (A Guide for Practitioners)

The limitations imposed by Section 17(1)(e) fundamentally reshape the way corporate transactions must be documented. Since private restructurings and slump sales do not benefit from the statutory exemption available to court-approved schemes, the responsibility for managing the “Asset Transfer Trap” rests largely with transaction lawyers. Traditional boilerplate provisions that merely require parties to comply with applicable laws are no longer sufficient in the DPDPA era. Instead, Share Purchase Agreements (SPAs) and Business Transfer Agreements (BTAs) must be drafted with data protection as a distinct and high-risk transactional concern, ensuring that regulatory compliance is built into the transaction rather than addressed after closing.

A key aspect of this contractual shift is the expansion of Representations and Warranties (R&Ws). Generic assurances that the target company complies with applicable privacy laws provide little meaningful protection to an acquirer. Instead, buyers should insist on detailed representations confirming that all personal data was collected pursuant to valid notices under Section 5 and supported by free, informed, and unambiguous consent under Section 6. Sellers should also disclose whether any historical data breaches have occurred, whether proceedings are pending before the Data Protection Board of India (DPBI), and whether complete records of data processing activities have been maintained. In addition, because liability for data processors ultimately rests with the Data Fiduciary, the seller should confirm that valid Data Processing Agreements (DPAs) exist with all third-party service providers, including cloud service vendors, payroll processors, and software providers, and that these entities comply with the safeguards required under the DPDPA.

The DPDPA also necessitates a significant rethink of indemnity provisions. Unlike traditional privacy regimes that primarily compensate affected individuals, the Act empowers the DPBI to impose substantial regulatory penalties, including fines of up to ₹250 crore for failure to implement reasonable security safeguards under Section 8(5). Conventional M&A agreements typically cap indemnity claims at a fixed percentage of the transaction value, often between 10% and 20% of the enterprise valuation. Such limitations may prove commercially inadequate where potential regulatory exposure far exceeds the negotiated liability cap. Consequently, DPDPA-related breaches should be carved out from general indemnity limitations and classified as fundamental breaches, ensuring that the seller remains fully responsible for regulatory penalties, litigation costs, and other liabilities arising from pre-closing non-compliance.

Finally, data compliance should be incorporated into the transaction through carefully drafted Conditions Precedent (CPs). Rather than treating privacy compliance as a post-closing exercise, buyers should require critical remediation measures to be completed before the transaction is consummated. These measures may include issuing updated notices under Section 5, conducting fresh opt-in campaigns to obtain consent for future processing, and making the achievement of a predetermined consent threshold a condition for closing. Sellers should also be obligated to erase legacy or non-compliant datasets in accordance with Section 8(7) and provide an independent data audit confirming that obsolete or unlawfully retained personal data has been permanently removed. Embedding these obligations into the transaction documents ensures that regulatory risks are addressed before ownership changes hands, rather than becoming the buyer’s problem after completion.

CONCLUSION

The DPDPA marks a fundamental shift in the legal treatment of personal data within corporate transactions. Data can no longer be viewed merely as a transferable commercial asset; it has become a regulated legal responsibility that directly influences the structure, valuation, and viability of corporate acquisitions. From the limitations of Section 17(1)(e) to the principles of purpose limitation, consent, and lawful processing, the Act requires businesses to reassess long-established M&A practices. Due diligence must evolve from conventional data rooms to privacy-conscious compliance frameworks, while transaction documents must proactively allocate regulatory risks through robust representations, tailored indemnities, and data-specific conditions precedent. In this evolving regulatory landscape, the commercial success of an acquisition depends not only on the quality of its financial assets but also on the integrity of its data governance framework. Where lawful consent, compliance, and accountability cannot be demonstrated, the value of the underlying data and often the transaction itself may ultimately disappear.

CITATION & REFRANCES

·        The Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023)

  • The Companies Act, 2013 (Act No. 18 of 2013)
  • The Income Tax Act, 1961 (Act No. 43 of 1961)
  • The Indian Contract Act, 1872 (Act No. 9 of 1872)
  • Justice K.S. Puttaswamy (Retd.) v. Union of India, (2017) 10 SCC 1 (Supreme Court of India)
  • Ahlawat & Associates. (2026). Significance of Privacy Readiness and Due-Diligence Post-DPDP Rules in M&A Transactions. Corporate Practice Insights.
  • AMLEGALS Consultancy Services. (2026). The Anonymization Tightrope: Differentiating Pseudonymized Data from Permanent Irreversible Redaction. AMLEGALS Practice Notes.
  • DSK Legal. (2026). From Data Rooms to Consent Rooms: How M&A Due Diligence is Changing in 2026. DSK Legal Corporate Practice & Tax Review.
  • Esplora Legal. (2026). Section 17(2) Operational Crisis: Defining the Regulatory Framework Governing Slump Sale Under the Companies Act, 2013. Corporate and Business Law Journal.
  • Goyal, L., & Prasad, V. (2026). Strategizing EU and Indian Personal Data Governance in Mergers and Acquisitions: Legal Insights and Corporate Accountability. In O. Azeroual (Ed.), Centering Transparency and Trust in Data and AI Ecosystems (pp. 71–94). IGI Global Scientific Publishing. https://doi.org/10.4018/979-8-3373-6761-3.ch003
  • Human Elevation & Legal Partners. (2026). Forensic Due Diligence: Data Privacy, Escrows, and Risk Allocation under the DPDPA Regime. Indian Corporate and M&A Law Guide.
Ashwin Pathak
Author: Ashwin Pathak