A due diligence DPDP checklist helps an acquirer or investor uncover a target company's data-protection liabilities before a deal closes. It examines whether the target has lawful consent and notice practices, adequate security safeguards, a breach history, vendor data-sharing agreements, and any pending complaints or Data Protection Board exposure. Because penalties reach up to ₹250 crore and can attach to the business post-acquisition, undiscovered DPDP gaps are a material diligence risk that CA firms and advisors should screen for as standard.
A target's DPDP gaps become the acquirer's liability. Screen for them before the deal closes — here is the diligence checklist and a quick risk read.
Data-protection liability travels with a business. When an acquirer buys a company, it typically inherits that company's obligations and exposure — including unresolved breaches, pending complaints, and the risk of Data Protection Board penalties that reach up to ₹250 crore for serious security failures. A target that looked clean on the financials can carry a material, undocumented DPDP liability that only surfaces after the deal. That is why data-protection diligence has moved from a nice-to-have to a standard workstream in Indian transactions.
The screening logic is practical: does the target have documented lawful processing, a clean or disclosed incident history, and managed vendor relationships? Weakness in any of these is a signal to dig deeper, quantify the remediation cost, and reflect it in price, reps and warranties, or conditions precedent. For a data-intensive target, this diligence can materially change deal terms.
CA firms already run financial and tax diligence on deals, which makes DPDP a natural extension of the same mandate. The advisor is well placed to request the right documents, spot the gaps, and translate them into a remediation cost the deal team can act on. Adding a DPDP diligence module to a transaction service is both a client-value add and a new billable line.
For the deeper technical review — assessing security safeguards, breach exposure and processor risk — advisors can bring in Niti Bharat through the CA referral partnership. We handle the specialist diligence and remediation scoping at fixed prices (₹75K–₹3.2L), the advisor keeps the deal relationship, and the firm earns a 15 percent commission on delivered work.
A full M&A DPDP diligence request list, a red-flag scoring sheet, and sample data-protection reps and warranties for the deal agreement.
One real DPDP development explained in plain English, one practical how-to, one number from our own assessment data. Nothing else — no daily noise, no sales pitch.
No spam. Unsubscribe with one click, anytime.