Data privacy has become a real due diligence workstream. How GDPR findings turn into contingent liabilities, revenue risk and remediation cost a buyer must price.
A target can pass every financial sanity check you throw at it - clean EBITDA bridge, defensible working capital, comfortable net debt - and still be carrying a nine-figure exposure that never appears in the databook. The exposure is its personal data. Any business that holds customer or employee records, which is to say essentially every business, carries data privacy obligations that have hardened over the past decade into a genuine, specialist diligence workstream. It sits closest in spirit to IT due diligence, but the risk it addresses - regulatory, contractual and reputational rather than technical - is distinct enough to deserve its own treatment, and increasingly its own line in the risk matrix that feeds the deal team's decision to sign.
You will not run the privacy assessment yourself as a financial due diligence analyst. That is specialist legal and privacy work. What you must be able to do is recognise when a target's profile demands one, and translate the finding it produces into a number the deal can act on. That translation - from a legal or compliance observation into a financial adjustment - is the same cross-workstream skill that separates a competent FDD analyst from a technician who can only tie out a trial balance.
For years, data protection was treated as a box-ticking exercise handled somewhere in the legal annex. Two things changed that. First, the penalty regimes acquired real teeth. Under the General Data Protection Regulation (GDPR), the most serious infringements can attract fines calculated as a percentage of global annual turnover - not a fixed nominal cap, but a figure that scales with the size of the business. That structure is precisely what makes the exposure material to a deal: a penalty sized against revenue can be a meaningful fraction of enterprise value for a consumer business with a large customer database.
Second, enforcement moved from theoretical to routine. Regulators across Europe now issue substantial fines with enough regularity that a buyer can no longer assume "it won't happen to us". The combination - large potential penalties, actually enforced - is why data privacy migrated from a compliance afterthought to a diligence item the deal team explicitly wants assessed before signing, particularly on any transaction involving a large consumer base or the processing of sensitive personal data (health, financial, biometric, children's data).
Treat data privacy the way you treat any other contingent exposure: not as a compliance checkbox, but as a potential cash cost with a probability and a magnitude that belongs in the same conversation as litigation and tax.
A privacy review is broader than "do they have a cookie banner". A competent assessment works through the full lifecycle of personal data inside the business and asks, at each stage, whether the target can demonstrate compliance rather than merely assert it. The core areas:
The last point matters disproportionately. A target that has had a breach and handled it well demonstrates governance maturity. A target that has had a breach and buried it is carrying both the original exposure and the aggravating factor of non-disclosure, which regulators treat harshly.
The reason a financial analyst needs to care is that privacy findings do not stay in the legal report. They land in three places that touch your numbers directly.
Contingent liability sizing. A known but unresolved breach, or a live regulatory investigation, is a contingent liability that must be quantified alongside your other litigation and regulatory exposures. It belongs in the same schedule you use to capture pending claims and tax disputes - see how these thread into the broader tax risks in FDD work, where the discipline of sizing a probabilistic exposure is identical. The mechanics are the same whether the trigger is a VAT reassessment or a GDPR fine: estimate the range, weight it, and decide whether it belongs as a price chip, an indemnity, or a specific warranty in the sale and purchase agreement.
Revenue quality. Some business models depend on using personal data in ways that sit close to the compliance boundary - aggressive marketing use of customer data, resale of enriched profiles, behavioural targeting. If a tightening regulatory environment or a specific enforcement action would impair that revenue, it is a forward-looking risk that belongs in the same conversation as your revenue quality analysis, even though the root cause is legal rather than accounting. A revenue stream that only works while regulators look the other way is not high-quality revenue, however clean it looks in the ledger.
Remediation cost. Bringing a genuinely non-compliant practice up to standard - data mapping, new consent infrastructure, process redesign, sometimes a wholesale re-permissioning of the customer base - is real forward-looking cost. It is analogous to the "must-spend" catch-up capital expenditure you would flag in an IT or operational review, and it should feed the buyer's post-close investment plan rather than being waved away as someone else's problem.
Here is how a single finding propagates across those three lenses on an illustrative consumer subscription target:
| Privacy finding | FDD workstream affected | Illustrative financial impact |
|---|---|---|
| Unresolved breach, regulator notified | Contingent liability | £4.0m estimated fine exposure, 50% weighted = £2.0m provision |
| 35% of marketing list lacks valid consent | Revenue quality | Re-permissioning likely to shrink active base; haircut renewal assumptions |
| No data mapping, manual erasure process | Remediation cost | £0.6m one-off build + £0.15m p.a. ongoing compliance |
None of those numbers exists in the target's own reporting. Each one moves the price.
Take a hypothetical direct-to-consumer business with £30m of revenue and reported EBITDA of £6.0m. The privacy review surfaces three issues. Watch how they translate into an equity value adjustment that a purely financial read would have missed entirely.
| Item | Basis | Adjustment |
|---|---|---|
| Reported EBITDA | Management accounts | £6.0m |
| Marketing revenue reliant on non-consented data | ~£1.2m revenue at 40% margin, at risk | (£0.5m) sustainable EBITDA haircut |
| Ongoing compliance headcount (currently absent) | 1.5 FTE + tooling | (£0.15m) run-rate EBITDA |
| Adjusted sustainable EBITDA | £5.35m | |
| Breach fine provision (contingent) | 50% × £4.0m | (£2.0m) net debt-like / price chip |
| Remediation build (one-off) | Data mapping + consent infra | (£0.6m) below-the-line / completion adjustment |
On a 9x multiple, the £0.65m of recurring EBITDA impact alone is worth roughly £5.85m of enterprise value, before the £2.6m of one-off and contingent items land as deductions in the equity bridge. A buyer who priced off the headline £6.0m EBITDA and ignored the privacy report would be overpaying by an amount that dwarfs the cost of commissioning the review in the first place. That asymmetry is the entire argument for taking the workstream seriously.
There is a softer but genuinely useful read here too. A target that cannot clearly answer basic questions - what personal data do you hold, where is it stored, on what legal basis was it collected - is signalling weak data governance generally. In practice that correlates with weaker financial controls and looser record-keeping discipline across the board. It is rarely a coincidence when a business is disorganised about its data and slower than expected to produce a clean trial balance or a reconcilable revenue file.
So the privacy review doubles as a diagnostic of management quality. When the answers come back vague, treat it as a prompt to tighten your own scrutiny elsewhere, and to sharpen the red flags you raise for the deal team. Disorganisation clusters; a target that is sloppy in one control environment is rarely immaculate in another.
Privacy sits alongside the other specialist streams - tax, legal, commercial, IT - that surround the financial core of a diligence exercise. The financial analyst is often the integration point, because the specialist findings only become decision-useful once they are expressed in the currency of the deal. Understanding where privacy plugs into the overall financial due diligence process - and how its outputs feed the risk section of the report and ultimately the negotiation - is what turns a siloed legal observation into a lever the buyer can actually pull.
Interviewers rarely expect a financial candidate to be a GDPR specialist. What impresses is showing you understand why it matters to a deal and how you would handle it in the numbers. If asked how you would treat a data privacy issue on a live deal, a strong answer sounds like this:
"I wouldn't try to run the privacy assessment myself - that's specialist legal and privacy work. My job is to flag when the target's profile warrants one and then translate whatever comes back into the numbers. So the first thing I'd look at is the profile: large consumer database, sensitive data categories, any history of aggressive data monetisation or a prior breach. Those are the triggers. If the specialist review then surfaces something material - say an unresolved breach with a regulator involved - I'd treat the potential fine as a contingent liability, size a weighted range, and decide with the deal team whether it belongs as a price chip, an indemnity or a specific warranty. Separately, if any revenue depends on data practices that a regulator might curtail, I'd haircut that revenue in my sustainable EBITDA rather than take it at face value, and I'd build the cost of getting compliant into the buyer's post-close plan. The through-line is the same as any other risk: estimate the exposure, weight it, and make sure it actually moves the price rather than sitting unpriced in an appendix."
That answer works because it stays in your lane, demonstrates the translation skill, and lands on the number - which is what the interviewer is really testing.
You will not sign off a GDPR assessment as an FDD analyst, and you should not pretend to. The valuable skill is narrower and more durable: recognising the profile that warrants a dedicated privacy review - large consumer data holdings, sensitive categories, prior breaches, aggressive monetisation - and knowing how to convert whatever the specialists find into a contingent liability, a revenue haircut, or a remediation cost the buyer can actually price. A privacy finding left in the legal appendix changes nothing. The same finding, sized and dropped into the equity bridge, changes the deal. The analyst who can move it from one place to the other is the one the deal team keeps close.
The Transaction Services Interview Programme (€119.99, one-time) includes a dedicated module on translating specialist findings - data privacy, tax, legal - into contingent liabilities and equity-bridge adjustments, with worked examples and sample interview answers. Enrol today.
Hundreds of candidates prepared their interviews with this programme. Those who landed the role have one thing in common: they worked the cases before walking into the room.