Data Privacy in M&A: Navigating Compliance under India’s DPDP Act

In this article, the authors examine how India’s Digital Personal Data Protection Act, 2023, reshapes compliance in mergers and acquisitions, making data privacy a central concern alongside financial due diligence. Drawing from global precedents such as the Marriott-Starwood breach, the authors highlight how obligations like consent-based processing, purpose limitation, and heavy penalties significantly affect acquirers. They further propose practical measures, data mapping, privacy impact assessments, and third-party evaluations to help companies mitigate risks and adapt international best practices to the Indian regulatory landscape. Continue reading Data Privacy in M&A: Navigating Compliance under India’s DPDP Act