How it works in a data room
The law, explained by the California Attorney General, applies to for-profit businesses that meet thresholds on revenue or on the volume of California consumers’ information they handle. In a transaction, the target’s customer and employee data may fall within scope. The data room provider generally acts as a service provider under a contract that limits how it can use the information. Sellers also review the target’s own compliance: privacy notices, opt-out handling and records of consumer requests.
Why it matters in a deal
The statute allows personal information to be transferred as part of a merger or acquisition, but the acquirer must keep honoring the promises made to consumers. Diligence therefore checks whether the target’s practices are compliant and how data is shared during the process. Limiting uploads to what is needed, applying redaction to personal data in samples, and keeping customer lists aggregated until late stages all reduce exposure. For companies also selling in Europe, the overlap with the GDPR is worth mapping. The United States guide covers the wider state privacy picture.
Example
A San Diego direct-to-consumer brand with 400,000 California customers prepares for a sale. Its advisers upload a privacy compliance folder with notices, request logs and vendor contracts, but share customer analytics only in aggregated form. Named customer data is released to the winning buyer’s integration team after signing, under the purchase agreement’s data protection terms.