Cybersecurity Due Diligence in M&A Transactions

Bond Schoeneck & King – As more states pass data privacy laws and cybersecurity incidents continue to dominate the headlines, cybersecurity-related due diligence has become critical for purchasers. At a minimum, a buyer should request from a seller: a description of the target business’s data security infrastructure; categories of personally identifiable information (PII) collected by the business; descriptions of the business’s practices regarding the use, collection, transfer, storage and sharing of PII; and copies of the business’s policies related to the collection of data in jurisdictions with data privacy laws.