M&A Data Liability Calculator India | <a href="https://amlegals.com/data-privacy/">DPDPA</a> Successor Liability Assessment | ₹250 Crore Penalty Risk
Vibe Data Privacy M&A Data Liability Assessment

When You Acquire a Company,
You Acquire Its Data Liabilities

Under DPDPA 2023, acquiring companies inherit data protection obligations of the target. Non-compliant consent mechanisms, security gaps, and unreported breaches become the acquirer's responsibility. The Data Protection Board can impose penalties up to ₹250 Crore.

₹250 CrDPDPA Maximum Penalty
£18.4MMarriott Fine (Inherited Breach)
4 YearsBreach Undetected Post-Acquisition

The Marriott-Starwood Case

A precedent for M&A data liability

In 2016, Marriott acquired Starwood Hotels for $13.6 billion. Undiscovered during due diligence: a breach ongoing since 2014 affecting 339 million guest records. The breach remained undetected until September 2018.

UK ICO fined Marriott £18.4 million for failing to implement adequate security measures post-acquisition. The fine was reduced from an initial £99 million notice, but established that acquirers bear responsibility for inherited data security failures.

Under DPDPA Section 8(5), Data Fiduciaries must implement reasonable security safeguards. Section 8(6) requires breach notification to the Data Protection Board and affected individuals.

Estimated Liability

₹150Crore
60%of DPDPA Max
₹0Cap: ₹250 Cr
Formula
Deal Value×Risk %×Sector×0.5=Liability
Low60High

Breakdown

VariableValueBasis
Transaction (A)₹500 CrConsideration
Risk Score (B)60%Assessment
Sector (C)1.2×Sensitivity
Base Factor (D)0.5Standard
Raw₹180 CrA×B×C×D
Final₹150 CrCapped ₹250 Cr
Transaction₹500 CrTarget value
Liability₹150 Cr30% of deal
Risk Score60/100Medium
Value Erosion30%ROI Impact
Methodology

Five-Layer Liability Assessment

LAYER 01

Consent Archaeology

Verify consent validity under DPDPA Section 6 requirements

Score45%
LAYER 02

Flow Cartography

Map data movement across systems and processors

Score62%
LAYER 03

Retention Analysis

Identify data held beyond purpose under Section 8(7)

Score78%
LAYER 04

Processor Audit

Assess Data Processor compliance per Section 8(2)

Score55%
LAYER 05

Breach Detection

Identify unreported incidents per Section 8(6)

Score38%

DPDPA Statutory Framework

Section 8(5) — Security Safeguards

Data Fiduciaries must implement reasonable security safeguards. Failure attracts penalty up to ₹250 Crore.

Section 8(6) — Breach Notification

Mandatory notification to Data Protection Board and affected individuals. Penalty up to ₹200 Crore for non-compliance.

Assess Acquisition Risk

Data protection gaps in target companies create liability exposure. Pre-closing assessment identifies risks for negotiation and structuring.

 

Disclaimer & Confirmation

As per the rules of the Bar Council of India, law firms are not permitted to solicit work and advertise. By clicking on the “I AGREE” button below, user acknowledges the following:

    • there has been no advertisements, personal communication, solicitation, invitation or inducement of any sort whatsoever from us or any of our members to solicit any work through this website;
    • user wishes to gain more information about AMLEGALS and its attorneys for his/her own information and use;
  • the information about us is provided to the user on his/her specific request and any information obtained or materials downloaded from this website is completely at their own volition and any transmission, receipt or use of this site does not create any lawyer-client relationship; and that
  • We are not responsible for any reliance that a user places on such information and shall not be liable for any loss or damage caused due to any inaccuracy in or exclusion of any information, or its interpretation thereof.

However, the user is advised to confirm the veracity of the same from independent and expert sources.