News and developments
Data as a Risk-Weighted Asset: Rethinking Valuation in Indian M&A under the DPDP Act
Introduction
For a long time, data in Indian M&A transactions was treated as a peripheral asset listed alongside operational resources but rarely influencing deal value or viability. That stance is no longer tenable. In the modern digital economy, data has taken on an important role as a key driver of commerce in revenue generation models, customer acquisition, and competitive advantage. At the same time, the enactment of the Digital Personal Data Protection Act, 2023 (“DPDP Act”), read with the Digital Personal Data Protection Rules, 2025, has fundamentally altered the legal character of data. Personal data is no longer a passive corporate resource; it is a risk-weighted asset, one that carries measurable upside in valuation, but also significant regulatory exposure.
For dealmakers, this shift has direct implications. Due diligence outcomes, purchase price adjustments, representations and warranties and indemnity structures are now influenced by data quality, provenance, consent architecture and compliance history. In several transactions, data-related risks can materially affect deal feasibility itself. Understanding how data intersects with valuation and regulatory liability is therefore essential to both deal structuring and post-closing risk management.
The DPDP Act in the M&A Context
The DPDP Act is India’s first comprehensive data protection framework governing the processing of digital personal data. It applies to data collected digitally, as well as data collected offline and subsequently digitised, and has extraterritorial reach where processing relates to offering goods or services to individuals in India. In the context of M&A, this broad scope means that both domestic targets and foreign entities with Indian-facing operations fall within its regulatory ambit.
The Act imposes primary obligations on “Data Fiduciaries” – the entities who decide the purpose and means of processing personal data, which is analogous to controllers under global data protection regimes. Such obligations include obtaining valid and informed consent, providing clear privacy notices, enabling data principal rights (such as access, correction and erasure) and implementing “reasonable security safeguards.” From an M&A perspective, these requirements have direct implications on the transferability and usability of data assets post-acquisition. For instance, lack of consent or purpose limitation can make it unlawful for the acquirer to use acquired datasets, reducing their economic value.
The enforcement framework revolves around the Data Protection Board of India, which is authorized to levy heavy financial penalties. The penalty regime is very strict, ranging from ₹250 crore for inadequate security measures, ₹200 crore for any failure in breach notification obligations or violations related to children’s data, ₹150 crore for violation of Significant Data Fiduciaries and a remaining ₹50 crore for all other violations. For acquirers, these penalties represent quantifiable contingent liabilities that must be assessed during due diligence and appropriately allocated through contractual protections.
Implementation of the DPDP regime is phased. The Data Protection Board became operational in November 2025, the Consent Manager framework is to be activated in November 2026 and the full compliance obligations will apply from May 2027. But this transitional timeline does not defer risk, it creates a forward-looking liability horizon. Acquirers are making sure to include the potential costs of fixing past non-compliance issues and the risk of future enforcement actions when they are dealing with data-heavy businesses in a transaction.
In effect, the DPDP Act has embedded regulatory risk directly into the economic calculus of M&A transactions. Data can no longer be evaluated purely as an intangible asset, it must be assessed as a legally conditioned resource, where value is inseparable from compliance.
Why the Act Turns Data Into a "Risk-Weighted" Asset
Two features of the DPDP Act specifically reshape how data behaves as a balance-sheet item in a transaction.
First, the Act treats personal data as tethered to the individual, not the enterprise. A target company's customer database, however commercially valuable, cannot simply be transferred, repurposed, or bundled into an asset sale the way a trademark or a lease can be. Consent obtained for one purpose does not automatically travel with the data to a new controller pursuing a different purpose. This means the "value" ascribed to a data asset in a term sheet is conditional, realisable only if the underlying consent and purpose trail can support the acquirer's intended use.
Second, liability is inherited, not waived, at closing. Where a share sale is used, the acquired company continues as the same legal person and carries forward every historical compliance gap such as undisclosed breaches, stale consents, uncontracted processors as a live liability sitting inside the entity being bought. Even in an asset or business transfer, processing the target's customer and employee data during diligence and integration itself triggers fresh consent or notice obligations. The result is that "data" on a term sheet is simultaneously an asset line and a contingent liability line, and diligence teams are now expected to quantify both.
How the Act Reshapes Due Diligence
Data diligence in Indian M&A has moved from a peripheral IT checklist item to a workstream that runs in parallel with financial and legal diligence, often determining deal viability itself. A rigorous exercise today typically covers five areas.
Data Mapping
The acquirer identifies what personal data the target actually holds, its volume, sources, and sensitivity along with the specific purpose for which each dataset was originally collected. This inventory is then tested against the Act's purpose-limitation and data-minimisation principles to flag data that is being held or used beyond its original consent basis.
Consent Audits
Under Section 6 of the DPDP Act, consent must be free, specific, informed, unconditional, and unambiguous. Pre-2023 consent structures in India were often bundled into broad terms of service, falling short of this standard. As a result, an acquirer may find that the target’s data cannot be lawfully used or transferred without a large-scale re-consent exercise, significantly eroding its immediate commercial value.
Breach History Review
The DPDP Act mandates prompt breach notification to the Data Protection Board of India and affected individuals, with penalties of up to ₹250 crore for non-compliance. In M&A, undisclosed or poorly handled breaches are treated as significant contingent liabilities, often leading to stricter representations, warranties and targeted indemnities.
Vendor and Processor Review
Under Section 8 of the DPDP Act, a Data Fiduciary remains responsible for processing even when outsourced to third parties. This requires close scrutiny of vendor arrangements such as cloud, HR, and payment providers and robust Data Processing Agreements aligned with statutory obligations, including clear data deletion requirements.
Significant Data Fiduciary Exposure
Entities may be classified as Significant Data Fiduciaries based on factors such as data volume, sensitivity, and risk. Buyers assess whether the target or combined entity will qualify, as this triggers additional obligations like appointing a Data Protection Officer, conducting audits, and undertaking Data Protection Impact Assessments adding to compliance costs.
Sharing identifiable customer or employee data with a prospective buyer is itself an act of "processing" under the Act. This is why diligence teams increasingly rely on clean-team protocols, anonymised or aggregated datasets in early rounds, and staged disclosure of identifiable data only once deal certainty increases. It also means that if a transaction is called off, any personal data already shared during diligence must ordinarily be deleted, unless retention is legally justified.
Valuation Consequences
When data due diligence shows gaps with the target’s data practices, it can lower the price the buyer is willing to pay. On the other hand, if the target already has strong DPDP compliance in place, it may be valued more highly because the buyer expects fewer legal and remediation costs after closing. In practice, this price difference is usually handled through common deal terms. For example, the buyer may pay a lower upfront price, hold back part of the money until certain issues are fixed, or ask for stronger protections from the seller about data compliance.
Purchase-price adjustments: the headline price is reduced to reflect the expected cost of fixing identified gaps such as weak consent records, mismatched processing purposes, or unremediated security safeguards.
Escrow holdbacks and data-specific indemnities: a portion of the consideration is held back, or the seller gives a dedicated indemnity, to cover breach-response costs and remediation sized to the actual exposure uncovered in diligence rather than treated as part of a generic contingency buffer.
Expanded representations and warranties: Sellers may need to make more detailed assurances about valid consents, undisclosed incidents, retention and deletion practices, and compliance of data processing agreements with applicable law.
Earn-outs and Deferred Consideration: A portion of the purchase price is deferred and linked to the target achieving defined post-signing compliance such as curing deficient consent frameworks or completing pending Data Protection Impact Assessments. This structure is increasingly preferred by buyers over upfront price reductions where compliance gaps are remediable but not yet resolved.
Together, these mechanisms help dealmakers convert an otherwise abstract compliance risk into concrete, negotiable deal terms.
Structuring the Deal Around the Act
Section 17(1)(e) of the Act carves out a narrow but important exemption: court- or tribunal-approved corporate restructurings, schemes of arrangement, mergers, amalgamations, demergers, and undertaking transfers sanctioned by the National Company Law Tribunal are exempt from certain consent requirements that would otherwise apply. Share purchases and asset/business transfers enjoy no equivalent relaxation, which means straightforward acquisitions are the transaction structures most exposed to the Act's consent architecture. This is already influencing structuring choices as parties are weighing whether a court-driven scheme, rather than a conventional share or business acquisition, better avoids the cost and delay of re-obtaining consent from potentially millions of data principals. Even within an exempted scheme, however, the disclosure of personal data at the pre-approval diligence stage is not automatically covered, so counsel cannot treat the exemption as a blanket shield.
Cross-border transfers require a separate analysis. The DPDP Act generally permits overseas transfers unless the Central Government later restricts a particular country or territory by notification. That said, sector-specific laws may impose stricter localisation requirements, and those stricter rules will continue to prevail where applicable. This means foreign acquirers and group structures must still test cross-border data flows carefully, especially where sector-specific data localisation rules or other regulated categories are involved.
Post-Merger Integration and Practical Safeguards
Post-closing integration is one of the most operationally challenging stages of a transaction, involving the integration of two separate compliance histories, IT systems and governance frameworks. Harmonising data governance structures, consolidating IT systems, and aligning privacy notices require careful sequencing rather than a one-time exercise.
Where systems are not immediately merged, parties increasingly rely on transitional data-sharing arrangements to ensure lawful processing, avoiding informal or non-compliant data flows. Employee data presents a distinct consideration: while the DPDP Act recognises employment-related processing as a legitimate use, organisations must still adhere to data minimisation, maintain accuracy, and update notices as workforce policies are harmonised.
Breach response frameworks must also be unified early. As per Rule 7 of the DPDP Rules, 2025, a breach must be notified to the Data Protection Board without undue delay from the time of its discovery and a detailed report must be submitted within 72 hours. Running parallel incident-response systems inherited from pre-merger entities risks missing these timelines, making a single, tested protocol essential from day one.
Governance structures must also scale with the combined entity. Where the threshold for Significant Data Fiduciary status is crossed, the appointment of a Data Protection Officer and, where necessary, a fresh Data Protection Impact Assessment becomes critical once systems and data flows are fully integrated. Immediate post-closing priorities should be reconciled data maps, harmonised consent frameworks and aligned vendor contracts to ensure readiness for regulatory scrutiny, rather than a delayed, reactive compliance approach.
Mr. Ketan Joshi, Associate Partner
MAHESHWARI & CO., Advocates & Legal Consultants
