What DPDP due diligence should a CA firm run on an M&A transaction? On any M&A transaction, a CA firm should run DPDP due diligence from both sides: the buyer needs to identify inherited data-protection liabilities — invalid consent, undisclosed breaches, non-compliant vendor contracts, children's-data exposure — before they become the acquirer's problem, while the seller needs a disclosure schedule and data-room checklist to present its DPDP posture honestly and avoid post-closing indemnity claims. Data-protection liabilities under the DPDP Act 2023 transfer with the business and can carry penalty exposure up to Rs 250 crore, so an unscoped or ignored DPDP gap is a live valuation and indemnity issue. This M&A DPDP Due Diligence Pack gives a CA firm both buyer-side and seller-side checklists, a data-liability register, a red-flag matrix and disclosure-schedule templates.
Run structured DPDP due diligence on any deal — buy-side liability discovery, sell-side disclosure schedule, a data-liability register and a red-flag matrix your firm applies in the data room.
Data-protection liability in an M&A deal is rarely on the balance sheet, which is exactly why it needs a structured diligence framework. Under the DPDP Act 2023, obligations and exposures attach to the business and its data-processing activities — so in a share purchase or merger they transfer to the acquirer along with everything else, and even in an asset purchase the acquired customer data carries its consent history and any defects with it. The framework screens seven liability zones: consent validity across the customer base, undisclosed or under-remediated breaches, vendor and processor contract gaps, children's-data exposure, cross-border transfer arrangements, marketing and profiling practices, and over-retention of personal data.
Each zone is assessed for two things: the probability a defect exists and the penalty exposure if it does — mirroring how a CA already thinks about contingent liabilities. A consent architecture that was never valid across a ten-lakh-strong customer base is a materially different finding from a single stale vendor contract, and the framework forces that distinction to be made explicitly and priced into the deal, rather than buried in a generic 'data protection: to be reviewed' line in the diligence report.
The data-liability register is the central working document of the diligence. It is a single schedule listing every DPDP finding, with columns for the liability zone, the specific defect, the evidence sighted, the estimated remediation cost, the potential penalty ceiling that applies, and the recommended treatment — whether the finding is a price-chip (reduce consideration), an indemnity item (seller warrants and indemnifies), a condition precedent (must be fixed before closing), or an accepted post-closing remediation. This register is what turns a qualitative 'there are some data issues' into a quantified, negotiable position.
For the seller, the same register run pre-emptively becomes the basis of an honest disclosure schedule — surfacing known issues on the seller's own terms rather than letting the buyer discover them and reprice or walk. For the buyer, it is the evidence base for the representations and warranties negotiation. Because a CA firm is already the trusted diligence provider on the financial and tax side, extending the register to cover DPDP is a natural scope expansion that clients increasingly expect as enforcement approaches in May 2027.
Risk areas prioritised for this deal:
Data-protection risk has moved from a footnote to a material diligence item in Indian M&A. With the DPDP Act 2023 in force and full enforcement expected around May 2027, a target's data-processing defects are no longer theoretical — they are quantifiable contingent liabilities that transfer to the acquirer and can carry penalty exposure up to Rs 250 crore for a security-safeguard failure. A buyer that closes without DPDP diligence is acquiring an unpriced liability; a seller that goes to market without a clean data-room story risks a late-stage reprice or a broken deal.
For CA firms, this is a natural and lucrative extension of existing transaction advisory work. The firm already runs financial, tax and legal-coordination diligence; adding a structured DPDP workstream, anchored by a quantified data-liability register, deepens the engagement and differentiates the firm from advisors who still treat data protection as a single line in the legal opinion. Buyers increasingly expect it, and sellers who prepare for it close faster and on better terms.
The buyer's goal is discovery: find the inherited liabilities before signing, quantify them, and convert them into price chips, indemnities or conditions precedent. The seller's goal is control: surface known issues on the seller's own terms through a disclosure schedule, narrow the warranties, and avoid post-closing indemnity claims. The same underlying framework serves both, but the checklists, templates and negotiating posture differ — which is why this pack ships both the buyer-side checklist and the seller-side disclosure schedule rather than a single generic list.
Where a deal surfaces DPDP defects that must be remediated before or shortly after closing, the target or acquirer will need specialist build-out on a tight timeline. Niti Bharat delivers fixed-price DPDP remediation engagements (Rs 75,000-Rs 3.2 lakh) and works with CA advisory firms under a referral partnership (15% commission), so your firm can close the diligence loop end-to-end — from finding the gap to fixing it — without losing control of the client relationship.
One real DPDP development explained in plain English, one practical how-to, one number from our own assessment data. Nothing else — no daily noise, no sales pitch.
No spam. Unsubscribe with one click, anytime.