← all articles

What happens to your data when a company is acquired

You signed up for an app, a fitness tracker or a note-taking tool because you trusted that company. then one morning an email arrives saying it has been acquired. the logo changes, the terms get a refresh, and the company holding your data is no longer the one you chose.

I run small online businesses out of Singapore, and I have been on both sides of this. I have bought assets with customer lists attached, and I have been a customer whose service got swallowed. the short version: your data is usually treated as a business asset, and it moves with the deal. this article explains how that works, what protects you, and what does not.

what it is

An acquisition is when one company buys another, either by purchasing its shares or by purchasing some or all of its assets. in both cases, the customer data the target company holds often comes along.

“Your data” here means everything the company holds about you: your email, name and phone number, your purchase history, your usage logs, photos or documents you uploaded, and anything it inferred about you. some of it you gave directly. some of it was collected in the background.

There are three common shapes:

  • merger or share purchase: the company stays the same legal entity, just with new owners. your data never technically moves, but the people who control it change.
  • asset purchase: the buyer picks specific assets, such as the product, the brand and the user database. the data is transferred to a different legal entity.
  • bankruptcy sale: a company in financial trouble sells what it has, including data, to pay creditors. this is the most stressful version for users because the timeline is short and the seller is under pressure.

how it works

When a deal is planned, the buyer does due diligence. that means the seller opens its books, including a description of what data it holds, how it was collected and what promises were made to users. a buyer paying for a user base wants to know whether it can legally use that base.

The key document is the privacy policy that was in force when you signed up. many policies include a clause saying that if the company is involved in a merger, acquisition or sale of assets, personal information may be transferred to the successor. if that clause is there, the transfer is generally allowed without asking you again. I wrote more about how far those promises go in what a privacy policy actually commits a company to.

After closing, three things typically happen:

  • the new owner takes over as the data controller, or as the “organisation” in Singapore terms, and becomes responsible for the data.
  • accounts are migrated or merged into the buyer’s systems, sometimes with a new login.
  • the privacy policy and terms of service get replaced, usually with a notice period and a “continuing to use the service means you accept” line.

The legal rules differ by place, but the pattern is similar:

  • in the EU and UK, the GDPR requires a lawful basis and transparency, and a new controller has to tell you about itself. the UK regulator publishes guidance at ico.org.uk.
  • in California, the CCPA as amended treats a transfer in a merger or acquisition as a permitted disclosure, but the new owner has to honour the privacy promises that applied when the data was collected, or give notice first. the state attorney general’s overview is at oag.ca.gov/privacy/ccpa.
  • in Singapore, the Personal Data Protection Act has specific provisions for business asset transactions, which let personal data be shared for a merger or acquisition under conditions, including that the data is only used for the purpose it was originally collected for. the Personal Data Protection Commission explains this at pdpc.gov.sg.
  • in the US more broadly, the FTC has said that a buyer cannot simply discard the promises a company made. in 2014, when Facebook announced it would acquire WhatsApp, the agency wrote to both companies reminding them that WhatsApp’s privacy promises had to be honoured unless users gave affirmative consent to changes.

This is not legal advice, and details vary by country and by deal. but the shape holds: the data can move, the old promises are supposed to follow it, and enforcement depends on someone noticing a breach.

why it matters

You agreed to one company’s practices. the buyer may have a very different business, for example an ad network buying a quiet utility app. the data is the same, but the incentives around it are not.

The WhatsApp case is the textbook example. in 2016, two years after the deal, WhatsApp changed its terms to share users’ phone numbers with Facebook. in 2017 the European Commission fined Facebook 110 million euros for giving misleading information about whether that kind of matching was possible during the acquisition review. the original promise was not forever.

data is often the reason for the purchase

Sometimes the buyer wants the code or the team. but in many deals the user base and the data around it are the main asset. when a company’s revenue is small and its user list is large, you should assume the list is part of what is being valued.

bankruptcy sales move fast

The clearest recent case is 23andMe, the genetic testing company, which filed for Chapter 11 in March 2025. millions of customers had submitted DNA samples and health-related data. the sale of that data became a public fight involving state attorneys general and customers asking for deletion, before the business was sold in mid-2025 to a nonprofit run by its co-founder. I would point to that case for one reason: genetic data cannot be changed like a password. if it ends up somewhere you did not expect, there is no reset.

the new owner inherits the old data, and the old mistakes

Data does not get cleaner in a transfer. if the original company kept more than it should have, the buyer now holds it. old backups, forgotten logs and stale uploads all become the new company’s problem, and yours. the same applies to what chat tools retain. see what a chatbot keeps after you close the tab for how long that tail can be.

common misconceptions

“my data is deleted if the company shuts down.” not reliably. a shutdown can end the service while the data sits on servers, in backups, or in an asset sale. deletion only happens if someone actually does it, and nobody is guaranteed to be left whose job that is.

“the company can’t sell my data if the policy says it won’t.” it is more nuanced. a promise like “we never sell your data” is meant to bind the company, and regulators like the FTC treat it as binding on a successor too. but a transfer in an acquisition is often not legally classed as a “sale” in the ordinary sense. read the exact wording, including any carve-out for mergers. the difference between “we do not sell your data” and “we do not sell your data except in a business transfer” matters.

“the new owner has to ask me again.” usually it does not. in many regimes, a notice is enough, and continued use counts as acceptance. some rules require fresh consent for materially different uses, but a notice by email that you never opened is how most people end up agreeing.

“it only matters for big tech.” small companies get acquired constantly, and their privacy practices tend to be thinner and less audited. a hardware company with a camera, for instance, can be bought by someone with a very different retention approach. what a smart doorbell records and who can request it is a good example of how much a single device can accumulate before any ownership change.

where to go from here

If you want to act on this, here is what I would do, in order of effort.

  • read the notice when it arrives. an acquisition email usually says what changes and gives a deadline for opting out or deleting. if it does not, check the company’s blog or help centre.
  • delete or export before the switch. if you are not going to use the service under the new owner, request deletion or download a copy of your data now. how to set up encrypted backups that you can actually restore covers keeping your own copy safely.
  • understand what metadata the company keeps even when content is protected. metadata explained: what encryption does not hide shows why contact lists and timestamps can matter as much as message bodies.
  • use fewer services that need your real details. if an AI tool or utility does not need your main email and phone number, give it less. our sister site AI Tool Gazette covers the tools that tend to get acquired quickly, and what their terms say.

For more explainers like this one, the blog index has the full list.

One last practical note. I keep a short list of every service I have given real data to, with the date I signed up and whether I have exported anything. when an acquisition notice lands, I can decide in five minutes instead of guessing. it is dull, but it works better than any setting I know of.

Written by Xavier Fok

disclosure: this article may contain affiliate links. if you buy through them we may earn a commission at no extra cost to you. verdicts are independent of payouts. last reviewed by Xavier Fok on 2026-10-04.

from the team
Want a real mobile IP, not a datacenter VPN endpoint?

Shared VPN exit nodes get flagged and blocked. Singapore Mobile Proxy runs real 4G/5G mobile IPs that give you a residential-grade address carriers still trust.

see how it works →
read on
More from The Privacy Wire

VPN and tool reviews, realistic opsec guides, and privacy news for people who want to protect their data.

browse all articles →