Article · June 17, 2026

Transferring customer data in M&A under the PDPL: what's required?

PDPL guidance for transferring customer data in M&A: due diligence, consent, notices, evidence retention, and a practical checklist.

consent.vn Editorial6 min read

Quick answer

In an M&A transaction, customer data cannot be “transferred along” like ordinary assets. The business must determine controller/processor roles, the transfer purpose, the legal basis, notify customers, and retain proof of consent or other lawful grounds as required.

What is transferring customer data in a company M&A under the PDPL?

This refers to the seller, buyer, or M&A advisor accessing, sharing, copying, or handing over customers’ personal data during negotiation, due diligence, and closing. Under the Personal Data Protection Law (Law 91/2025/QH15), this must have a clear purpose, comply with data processing principles, and rely on an appropriate legal basis.

In Vietnamese practice, data often includes names, phone numbers, emails, purchase history, contracts, receivables, customer service call recordings, or identifiers in the CRM. For SMEs, the risk often does not lie in “selling the company,” but in sending the entire database to the buyer without filtering, anonymization, or customer notice.

When does transferring customer data trigger obligations under the PDPL?

Obligations arise as soon as personal data is reviewed, disclosed, or transferred to a third party in M&A, including during due diligence. If the data can identify an individual directly or indirectly, the business must handle it under the rules, regardless of whether the deal has been signed.

The important point is to separate 3 stages:

  • Pre-transaction due diligence: only share minimal data, prioritizing anonymized, aggregated, or sanitized datasets.
  • Signing and closing: determine who will be the data controller after the merger.
  • Post-M&A operational transfer: update notices, privacy policies, and customer request handling mechanisms.

Is customer consent required when transferring data in M&A?

Often it may be required, but not everything must rely solely on consent. Under the rules, the business must identify the legal basis that fits the transfer purpose. If using consent, it must be voluntary, specific, demonstrable, and customers must understand who their data is being transferred to and for what purpose.

For M&A transactions, many businesses assume “a clause in the service contract is enough.” This is risky because generic clauses do not replace transparent notices or specific consent when the scope of use changes. If data is transferred to a new legal entity, purposes change, or processing scope expands, review the legal basis and notice documentation.

  1. Review data to be transferred:

    list each customer data group, classify basic data, sensitive data, operational data, and data to exclude.

  2. Minimize data before sharing:

    in due diligence, only provide anonymized extracts, aggregated revenue, churn rates, sample contracts with personal data redacted.

  3. Identify the legal basis:

    decide which parts rely on consent, which on performance of contract, or legitimate interests under the rules and internal documentation.

  4. Update notices to customers:

    state the data recipient, purpose of transfer, data scope, retention period, and contact channel for feedback.

  5. Retain evidence:

    keep data export logs, handover minutes, notice emails, consent content, and the relevant privacy policy version.

  6. Lock in the post-deal mechanism:

    determine who receives DSARs, who handles deletion/rectification, and who is accountable if violations arise.

What should M&A due diligence do to avoid “leaking” customer data?

Design due diligence with data minimization in mind. The seller should only provide data sufficient for the buyer to assess company value, not open the entire CRM or support tickets if unnecessary.

A safer structure is:

  • Aggregated data by customer segment, region, revenue.
  • Sample contracts with names, IDs, phone numbers redacted.
  • A list of complaints/claims that is tokenized.
  • Sensitive data shared only when truly necessary and with additional safeguards.

If using a data room, set role-based access, log downloads, apply watermarks, and implement a process to revoke access after due diligence ends.

Can the buyer immediately use customer data after taking over the company?

Do not automatically assume it’s allowed. After a merger or acquisition, the buyer should check what notices and policies governed the original data collection, and whether customers need updated notices about the change of the controlling legal entity.

If the new company changes brand, operating entity, or moves to a different CRM, the business must ensure customers are informed about who is processing the data, how to contact them, and how customers can request access, correction, deletion, or restriction of processing in accordance with the rules.

What are the risks if you forget to notify or overshare?

Risks can include customer complaints, remedial orders, administrative penalties under the implementing decree when the law is in effect, and, in serious cases, criminal liability. The enforcement authority is the Ministry of Public Security (A05).

Businesses should treat M&A as a data compliance problem, not only a transaction legal issue. Common mistakes include: emailing the buyer a customer list without encryption; using a data room without download controls; an SPA without data clauses; and failing to update the privacy policy after closing.

Short template for use in M&A transactions

You can use the following notice for customers or partners:

"We hereby inform you that [Company name] is/has been conducting an M&A transaction with [Name of the relevant legal entity]. Some personal data of customers may be transferred for due diligence and/or to continue providing services, in accordance with personal data protection law. The data processed includes [short list]. You can contact [email/contact point] to exercise your rights to access, rectify, object, or make other requests as provided by law."

How should SMEs prepare before selling the company?

SMEs should complete four tasks in advance: build a data inventory; cleanse and anonymize data before due diligence; review existing notices and consents; and standardize contracts with employees, agents, and CRM providers to avoid data exposure during handover. If you have a cookie banner, lead forms, or a consent capture system, retain versioned, timestamped evidence of consent.

It’s not always applied mechanically like that. The business must determine an appropriate legal basis under the rules and, if relying on consent, have specific, demonstrable consent.
Avoid it. In practice, share only minimal data, prioritizing anonymization or aggregation to reduce personal data exposure risk.
Typically you should update notices/privacy policies if there is a change in the data controller, processing purposes, or contact channels.
Under the rules, a data breach must be notified within 72 hours of discovery.

If you are building an M&A process, consent.vn can help retain consent evidence, manage cookie banners, and streamline DSAR flows so legal and engineering teams share a single source of data.

Source: the Personal Data Protection Law (Law 91/2025/QH15); Decree 13/2023/ND-CP — thuvienphapluat.vn; Ministry of Public Security (A05) — bocongan.gov.vn

Get started — set up in 5 minutes.

Need help with PDPL compliance?

Get started