Data Protection as a Valuation Variable
In the pre-DPDPA era, data protection due diligence in Indian M&A transactions was a compliance checklist item — a two-page section in a 200-page due diligence report. Post-DPDPA, with penalties reaching ₹250 crore per contravention type, data protection non-compliance creates contingent liabilities that materially affect enterprise valuation.
The Liability Transfer Problem
When a foreign company acquires an Indian entity or enters a joint venture, it inherits the target's existing data processing obligations. If the target was collecting personal data without DPDPA-compliant consent, the acquirer does not get a fresh start — it inherits the non-compliance. Every record of personal data collected without valid consent is a continuing contravention that survives closing. The acquirer must either obtain fresh consent from every Data Principal or delete the non-compliant data.
Due Diligence Scope Under DPDPA
Comprehensive DPDPA due diligence must cover: (a) Data inventory — what personal data the target holds, from how many Data Principals, for what purposes. (b) Consent architecture — whether existing consent mechanisms satisfy Section 5 notice and Section 6 consent requirements. (c) Cross-border transfers — whether data routing complies with Section 16. (d) Vendor contracts — whether Data Processor agreements satisfy Section 8(2). (e) Children's data — whether Section 9 obligations are implemented. (f) Breach history — whether prior breaches were notified under Section 8(6). (g) SDF status — whether the target is or could be designated a Significant Data Fiduciary.
Warranties and Indemnities
Transaction agreements must include specific DPDPA warranties: that the target is in material compliance with the Act, that no breach notification obligations are outstanding, that all necessary consents have been obtained, and that no proceedings before the Data Protection Board are pending or threatened. Indemnities should cover: penalties imposed for pre-closing contraventions, costs of remediation (including obtaining fresh consent), and claims by Data Principals for pre-closing processing.
Joint Venture Considerations
Joint ventures create a specific DPDPA problem: who is the Data Fiduciary? If the JV entity processes personal data, it is a Data Fiduciary in its own right. But if the JV partners also receive that personal data, they become separate Data Fiduciaries (or Data Processors, depending on the arrangement). The JV agreement must clearly allocate: (a) which entity is the Data Fiduciary for each processing purpose, (b) on what basis personal data is shared between JV partners, (c) who is responsible for consent management and notice obligations, and (d) who bears liability for breaches.
Escrow and Holdback Considerations
Given the potential magnitude of DPDPA penalties, acquirers should consider: (a) a specific data protection indemnity escrow, (b) holdback provisions tied to a post-closing data protection audit, and (c) price adjustment mechanisms linked to the cost of achieving DPDPA compliance where the target is materially non-compliant.

