Customer Data and GDPR When a SaaS Business Changes Hands
How personal data rules apply when a SaaS business changes hands: what to share during due diligence, the lawful basis for the transfer, processors and telling users.
A SaaS business holds personal data by its nature: user accounts, emails, billing details, usage logs and support conversations. When the business is sold, that data has to move to a new owner, and the rules on personal data come with it. In the EU, the General Data Protection Regulation sets those rules; the UK has its own version, and many other countries have similar laws. This guide explains how a SaaS sale GDPR review works in practice: what to share during due diligence, the basis for transferring data, processors, international transfers and telling users.
This is general information, not legal advice. For a real sale, especially one involving EU or UK users, take advice from a data protection specialist. For the overall process, see our guide on how to sell a SaaS business.
Key takeaways
- Share aggregated or anonymised data during due diligence, under an NDA, and keep personal data for closing.
- The UK’s ICO says data sharing should be part of due diligence in a merger or acquisition, including the lawful basis.
- Buyers should review the data inventory, privacy notice, processors, international transfers and past incidents.
- The new owner must use the data in ways consistent with what users were told.
- Tell users about the change, update the privacy notice and review processor contracts after closing.
Why personal data matters in a sale
For a SaaS buyer, the user base is a large part of what’s being bought. But personal data isn’t an ordinary asset. Under the GDPR, an organisation that decides why and how personal data is used, the “controller”, must have a lawful basis for each use, be transparent with the people concerned, keep the data secure and use it only for the purposes it was collected for. When the business changes hands, the buyer becomes responsible for meeting those obligations from then on, and inherits any problems that weren’t fixed.
The UK Information Commissioner’s Office puts it directly in its data sharing guidance: if a merger or acquisition means data is transferred to a different controller, data sharing should be considered as part of due diligence, including what data is transferred, why it was collected, the lawful basis for sharing it and whether any of these change.
Sharing data during due diligence
Buyers need evidence, but they rarely need individual customers’ details to get it. A good approach:

- Start with aggregated metrics: user counts, revenue, churn and usage trends, with no personal data.
- Use an NDA before sharing anything detailed. Our guide to NDAs when buying a business explains what to include.
- Use anonymised or sample data where the buyer needs to see structure, such as a database schema or a sample of records with identifiers removed.
- Limit access to the people who need it, through a secure data room rather than email.
- Agree what happens to shared data if the deal doesn’t complete, such as deleting it.
Read-only access to dashboards, for example a restricted API key for billing data or a viewer role in analytics, lets buyers verify numbers without receiving copies of personal data.
What buyers should review

- Data inventory: what personal data is held, where it’s stored, how long it’s kept and why.
- Privacy notice: what users were told about how their data is used, including any mention of a sale or change of ownership.
- Lawful basis: for each purpose, such as providing the service, billing or marketing emails, and any consents collected.
- Processors: the services that handle data on the business’s behalf, such as hosting, email and analytics, and whether contracts with them are in place.
- International transfers: where data goes outside the EU or UK and which safeguards are used.
- Security: access controls, encryption, backups and how staff and contractors access data.
- Incidents: past breaches, how they were handled and any complaints or regulator contact.
- User requests: how access and deletion requests are handled, and any outstanding ones.
The basis for the transfer
Moving personal data to a new owner is itself a use of that data, so it needs a lawful basis under the GDPR. In many business sales, organisations rely on legitimate interests, weighing the business’s interest in the transfer against users’ interests, while the data continues to be used for the same purposes. Specific consents, such as marketing consent, may need extra thought, because consent given to one company doesn’t automatically cover another. This is exactly where specialist advice pays for itself.
The key principle is continuity: the new owner should use the data for the same purposes users were told about. If the buyer plans to use it differently, for example to market other products, that needs its own basis and, often, clear information to users first.
Processors and sub-processors
Most SaaS products rely on many processors: cloud hosting, email delivery, analytics, support desks, payment providers. The GDPR requires a contract with each processor setting out how it handles data. In a sale, check that these contracts exist, decide which services the buyer will keep, and plan how accounts and contracts move to the new owner. Payment providers have their own processes; our guide to moving Stripe subscriptions explains one.
Staff and contractor data
If the sale includes a team, their personal data moves too: contracts, payroll details and HR records. The ICO’s guidance on employment records gives similar advice for this data: consider it in due diligence, establish what’s being transferred and why, identify the lawful basis, tell workers about the change and remind them of their rights, and document the decisions. Contractors’ details, such as bank information for invoices, need the same care.
Mobile apps and connected services
Many SaaS products have mobile apps, browser extensions or integrations, each with its own data flows: analytics SDKs, crash reporting, push notification tokens. Include them in the data inventory. App stores also show privacy details for each app, which the new owner must keep accurate after the transfer. Our guides to buying and selling a mobile app cover the store-specific steps.
International transfers
If the buyer is outside the EU or UK, or will move data to servers elsewhere, the GDPR’s rules on international transfers apply. Transfers outside the EU need a recognised mechanism, such as an adequacy decision for the destination country or appropriate safeguards like standard contractual clauses. Plan this before closing, not after, because it may affect where the buyer can host the product.
Beyond the GDPR
The GDPR is often the strictest regime a small SaaS business deals with, but it’s rarely the only one. The UK has its own version, and many other countries and US states have privacy laws with their own rules on notices, user rights and sharing data in a sale. Check which laws apply based on where users are, not just where the business is registered. Planning for the strictest regime that applies, and documenting your decisions, usually covers most of the others too.
Security during the handover
The handover itself is a moment of risk: accounts change hands, access keys are shared and databases are copied. Move data using encrypted channels, never as email attachments. Create new credentials for the buyer rather than sharing the seller’s, and remove the seller’s access once the transfer is complete. Rotate API keys, database passwords and encryption keys after closing. Our guide to handing over passwords and 2FA covers account access in detail.
What the sale agreement should cover
- Seller statements that data has been collected and used lawfully, and that known incidents have been disclosed.
- A list of systems and processors holding personal data.
- How and when personal data will be transferred, and by whom.
- Who handles user requests and complaints received around the change.
- What the seller must delete after the transfer, and by when.

After closing: telling users and tidying up
Transparency is a core GDPR principle. After the sale, tell users who now runs the service, update the privacy notice with the new controller’s details, and make sure contact routes for data requests work. Update processor contracts in the new owner’s name. The seller should delete copies of personal data they no longer need, keeping only what they must for legal reasons such as tax records.
If a past breach comes to light
Due diligence sometimes turns up an incident that wasn’t handled properly. Under the GDPR, controllers must report certain personal data breaches to the regulator, where feasible within 72 hours of becoming aware of them. If a buyer finds an unreported incident, take advice before closing: it may need to be reported, and it may affect the price, the agreement’s protections or whether to proceed.
For sellers: preparing a data file
Sellers who prepare in advance make the SaaS sale GDPR review quick and keep personal data safe. Before you list, put together a short data file: what personal data you hold and why, your privacy notice and its history, a list of processors with links to their data processing terms, where data is hosted, how you handle user requests, and a summary of any incidents and how you handled them. Fix gaps you find, such as a missing processor contract or an out-of-date privacy notice, before buyers ask. A clear file shows buyers the business is well run, which supports the price.
Common mistakes to avoid
- Sending full customer exports to buyers early in the process.
- Assuming marketing consents automatically carry over to a new owner.
- Forgetting processors that hold data, such as support desks or backups.
- Leaving the privacy notice in the seller’s name after closing.
- Keeping copies of personal data after a deal falls through.
A worked example
The details below are made up to show the method.
Ines is buying a scheduling SaaS with 8,000 users, many in the EU. During due diligence, the seller shares aggregated metrics, a database schema and anonymised samples through a data room under an NDA, and gives read-only access to billing and analytics. Ines reviews the privacy notice, the list of twelve processors and the contracts with each, and finds that hosting is in the EU and the email provider uses standard contractual clauses.
The agreement includes the seller’s data statements, a processor list and a transfer plan. At closing, accounts and databases move to Ines’s company. Ines emails users to introduce the new owner, updates the privacy notice and confirms the seller has deleted their copies.
SaaS sale GDPR: the checklist
- Only aggregated or anonymised data shared before signing, under an NDA.
- Data inventory, privacy notice and lawful bases reviewed.
- Processor contracts checked and transfer plan agreed.
- International transfers and safeguards confirmed.
- Security, incidents and outstanding user requests reviewed.
- Data terms included in the sale agreement.
- Personal data transferred securely at closing.
- Users told, privacy notice updated, contact routes working.
- Seller’s leftover copies deleted.
Ready to find your next asset?
Browse listings with verified numbers, ask sellers your questions before you offer, and agree every step in a free Deal Room.
Frequently asked questions
Can I share customer data with a potential buyer?
Share as little as possible before signing: aggregated metrics and anonymised samples under an NDA. Personal data generally moves at closing, with a lawful basis.
Do users need to consent to the sale?
Not always. Many sales rely on legitimate interests for the transfer, with the data used for the same purposes. Specific consents, such as marketing consent, need extra thought. Take specialist advice.
Who is responsible for the data after the sale?
The new owner, as the controller, from the transfer onwards, including any issues that weren’t fixed.
Do we need to tell users about the sale?
Transparency is a core GDPR principle, so tell users who now runs the service and update the privacy notice.
What if the buyer is outside the EU?
The GDPR’s international transfer rules apply, such as an adequacy decision or safeguards like standard contractual clauses.
Does the GDPR apply if the business isn’t in the EU?
It can, if the service offers goods or services to people in the EU or monitors their behaviour. Check with an adviser.
How should a seller prepare for the SaaS sale GDPR questions?
Prepare a short data file: the data you hold and why, your privacy notice, processors and their contracts, hosting locations, how you handle requests and any past incidents.