SaaS privacy due diligence tests whether the company can prove it had permission to collect, use, share, retain, and transfer customer data. California made the cost of a broken proof chain concrete in 2026, when its eighth CCPA enforcement action imposed $12.75 million in civil penalties.
A buyer is not grading the privacy policy on your website. The buyer is comparing promises across contracts, product behavior, vendors, consent records, and deletion workflows. If those records conflict, the finding can change the purchase agreement even when no regulator has contacted you.
What Buyers Test in SaaS Privacy Due Diligence
The first request is a policy. The real test is the evidence behind it.
Buyers usually start with six connected records. They ask for a current data map, customer data processing agreements, the subprocessor list, privacy notices, consent records, and the log of access or deletion requests. They then test whether each record describes the same system.
This is what I call the Data Promise Gap. It is the distance between what the company promised, what the product did, and what the records can prove. I score each flow at three levels. Green means the promise, behavior, and proof match. Yellow means the use is permitted but one document or control is incomplete. Red means the use lacks permission, conflicts with a contract, or cannot be proven.
| Buyer test | Evidence requested | Failure signal |
|---|---|---|
| Collection | Notices, consent records, product screens | Data collected before notice or consent |
| Use | Data map, processing purposes, internal access | Analytics or model training exceeds the stated purpose |
| Sharing | Subprocessor list, vendor contracts, API flows | Undisclosed vendor or missing processing terms |
| Retention | Retention schedule, deletion logs, backups | Policy promises deletion that systems cannot complete |
| Transfer | Customer contracts, transfer terms, change provisions | Customer data cannot move or be repurposed after close |
The Federal Trade Commission showed why evidence at the supplier level matters. Its 2026 proposed order against Kochava covered data linked to hundreds of millions of mobile devices. The order requires a supplier assessment program to confirm consent, incident reports for prohibited sharing, and a documented retention schedule. The Commission approved the proposed order by a vote of 2 to 0.
A seller should apply the same logic before launch. Do not stop at asking whether a vendor signed a data processing agreement. Confirm what the vendor receives, why it receives it, where the data goes next, and whether deletion reaches that vendor.
GDPR and CCPA Create Different Proof Problems
GDPR diligence starts with the lawful basis for each processing purpose. It also tests controller and processor roles, records of processing, data subject requests, transfer mechanisms, retention, and any required impact assessments. A customer contract that calls the SaaS company a processor does not settle the issue if the company uses customer data for its own analytics or product training.
European regulators are looking directly at transparency. In March 2026, the European Data Protection Board said 25 data protection authorities would examine controller compliance with GDPR information duties during the year. That makes stale notices and incomplete processing records current enforcement issues, not theoretical ones.
CCPA diligence asks whether the company meets the law’s scope, whether it sells or shares personal information, whether opt out signals work, and whether service provider contracts contain the required limits. It also tests whether the company can honor access, correction, deletion, and limitation requests across its systems.
California’s 2026 deletion platform can send one consumer request across more than 575 registered brokers. Buyers should expect deletion evidence to receive more scrutiny as these rights become easier to exercise.
The central seller question is not whether GDPR or CCPA appears in a policy. It is whether the company can trace one real user through collection, use, sharing, export, and deletion. That single record test often exposes the gaps faster than a folder of legal memos.
How Privacy Findings Change SaaS Acquisition Terms
Not every gap cuts price. Every unresolved gap needs an owner.
Buyers sort findings by cost, uncertainty, and transferability. A missing vendor agreement with a cooperative provider may be fixed before signing. An unknown population of records collected without valid permission is harder to bound. A customer contract that restricts transfer may require consent before close.
The remedy follows the Data Promise Gap score. Green flows move into ordinary disclosure. Yellow flows get a dated cure plan or a closing condition. Red flows require a decision about specific indemnity, escrow, discontinued use, customer consent, or price. Materiality, transaction structure, insurance, and buyer risk tolerance still control the final term.
This is where privacy connects to the broader deal process. A privacy promise may appear again in the seller’s representations and warranties. A known exposure may influence escrow and indemnification terms. A required customer consent can become one of the items that controls what happens between LOI and close.
California’s 2026 General Motors settlement is a useful warning. Regulators alleged that the company sold location and driving data from hundreds of thousands of Californians without proper knowledge or consent. The remedy did not stop at a fine. It also restricted future data use and required a documented privacy program.
The most dangerous privacy finding is not a missing document. It is a data practice the buyer cannot lawfully continue after close.
The Seller Privacy Room to Build Before Launch
I would prepare the privacy room in four passes. First, map personal data from collection through deletion. Second, match each flow to a purpose, legal basis, customer promise, and vendor contract. Third, sample real requests and consent records. Fourth, list every gap with an owner and completion date.
Keep the room narrow. Start with the current data map, privacy notices, data processing agreement forms, subprocessor inventory, transfer terms, request log, incident history, retention schedule, consent evidence, and impact assessments. Add customer specific documents only when they matter to the buyer’s review.
Do not bury open issues. Label them. A buyer can underwrite a defined cleanup plan with dates and responsible people. The buyer discounts a vague assurance that counsel is reviewing it.
Build a separate incident file. Include the incident register, forensic reports, customer and regulator notices, insurance notices, contractual notice duties, remediation evidence, and open corrective work. A clean summary must explain why each event was or was not reportable.
The same rule applies across diligence. Your M&A data room should make the proof chain easy to follow. Your SOC 2 report may support security controls, but it does not prove lawful collection, valid consent, or compliant sharing.
Frequently Asked Questions
What privacy documents do SaaS buyers request?
Buyers usually request a data map, privacy notices, customer data processing agreements, subprocessor contracts, consent records, request logs, incident history, retention rules, and cross border transfer terms. The strongest file connects those records to actual product and vendor data flows.
Can a privacy issue reduce a SaaS sale price?
Yes. A buyer may reduce price when the cost or legal exposure cannot be bounded. More defined gaps often move into a closing condition, a specific indemnity, or an escrow holdback instead.
Does SOC 2 cover GDPR and CCPA compliance?
No. SOC 2 can support evidence about security and operational controls. It does not prove that every data use has a lawful basis, that consumer opt outs work, or that customer data can transfer after an acquisition.
How early should a SaaS seller prepare for privacy diligence?
Start before the sale process, while contracts and system behavior can still be reconciled without buyer pressure. A focused review several months before launch gives the team time to repair vendor terms, consent records, deletion workflows, and customer promises.
What happens if a seller discovers an old data incident?
Document the event, the notification analysis, any customer or regulator contact, insurance notices, forensic findings, and completed remediation. An explained incident with closed corrective work is easier to underwrite than an incomplete record or an issue disclosed late.
Next Steps
If customer data is central to your SaaS value, test whether that data can survive buyer diligence before you launch the sale.
