Data Privacy Diligence in M&A: GDPR and CCPA Risks
A detailed legal analysis of data privacy diligence in M&A transactions: scoping controller and processor relationships, data mapping, GDPR lawful basis, EU-to-US transfers under SCCs and the Data Privacy Framework, Schrems II DTIAs, CCPA/CPRA and state privacy patchwork, HIPAA, GLBA, COPPA, BIPA, DPA vendor flow-downs, ad-tech diligence, post-close privacy notice integration, breach notification timelines, and remediation planning.
Apr 18, 2026