Why it matters
For many online and consumer businesses, the email list, the SMS list or the customer database is one of the most valuable assets. Sellers often point to list size and email revenue to support the price. That value depends on two things: whether the business was allowed to collect and use the data in the first place, and whether you can keep using it after the sale.
The rules differ by country and by channel. The EU and UK data protection regimes require a lawful basis for using personal data, with separate rules for electronic marketing. South Africa's POPIA generally requires consent for electronic direct marketing, with a limited exception for existing customers. Canada's anti-spam law and Australia's Spam Act also require consent for commercial email and messages, and expect the sender to be able to prove it. In the US, federal email rules work mainly on an opt-out basis, but automated marketing calls and texts generally need prior written consent, and some states add their own privacy laws.
Data gathered without valid consent creates three problems for a buyer. The list you can lawfully use may be much smaller than the list you were shown, and the revenue it drives shrinks with it. A regulator can fine the business or order it to stop using the data. And in an asset sale the data passes to a new owner, so the purposes it was collected for, and what customers were told, need to cover that change. The UK regulator, the ICO, expects both sides of an acquisition to check these points as part of due diligence.
Price in the part of the list you may lose. Winning consent back is harder than it sounds: in the UK, for example, the ICO treats an email asking people to agree to marketing as sent for direct marketing purposes, so it is caught by the same rules. Warranties about data protection compliance help, but they will not restore a list you cannot use. Take advice from a privacy lawyer in each country where the customers are.
In an asset sale you buy selected assets of a business; in a share sale (a stock sale in the US) you buy the company itself, with its full history. The choice shapes risk, tax and what needs consent.
Due diligence is the investigation a buyer carries out before committing to a purchase, testing the finances, contracts, legal position and operations against what the seller has described.
Warranties are the seller's statements of fact about a business in the purchase agreement; indemnities are promises to reimburse specific losses. Together they decide who bears risks that diligence could not rule out.
How to spot it
- Sign-up forms use pre-ticked boxes, or bury marketing consent in the terms of purchase.
- Parts of the list were bought, rented, scraped or collected through competitions run with partners.
- There are no records of when, where and how each contact signed up.
- Email platform reports show high complaint rates, or the provider has issued warnings.
- The privacy notice is missing, generic, out of date or silent about a sale of the business.
- Customer data sits in personal accounts or spreadsheets with no access controls.
- Security incidents were handled informally and never recorded.
Questions to ask the seller
- How was each part of the list collected, and what did people agree to when they signed up?
- Can you show consent records, with date, source and wording, for a sample of contacts?
- Has any part of the list been bought, rented, shared or imported from another business?
- How much revenue comes from email, SMS or calls to the database?
- Have you had complaints, regulator enquiries or security incidents involving customer data?
- Does your privacy notice allow customer data to pass to a buyer of the business?
Documents to request
- Current and past privacy notices and cookie policies, with the dates each applied
- Copies or screenshots of every sign-up form and checkout consent wording
- An export of consent records for a sample of contacts
- Email and SMS platform reports showing list growth, unsubscribes, bounces and complaints
- Contracts with data processors, list providers and marketing agencies
- A log of security incidents, complaints and correspondence with regulators