18
Thu, Apr
38 New Articles

The Impact of Data Protection Compliance on M&A Transactions

The Impact of Data Protection Compliance on M&A Transactions

Hungary
Tools
Typography
  • Smaller Small Medium Big Bigger
  • Default Helvetica Segoe Georgia Times

In recent years, innovative Hungarian companies are increasingly attracting foreign professional and financial investors who seek their state-of-the-art products and services.

As investors increasingly focus due diligence on a target’s regulatory compliance – relative to innovative companies, increasingly on data protection and IT security – practical data protection compliance gaps become evident. Their evolution since the implementation of the General Data Protection Regulation (GDPR) and potential impact on M&A transactions gives rise to practical considerations.

Technology companies were perhaps more focused on the need to achieve substantive – rather than merely formalistic – compliance with privacy laws. Yet due diligence often reveals fundamental weaknesses in the privacy documentation, even of tech sector companies. The reasons can be traced back to both a lack of data privacy-focused compliance resources and the incredibly rapid growth of companies.

The Hungarian enforcement of the GDPR also seems to have played a role in the relative levels of compliance achieved to date. The level of data protection fines imposed by the Hungarian supervisory authority in recent years is nowhere near the level of fines imposed by authorities in other EU countries. In Hungary, the highest fine imposed to date was HUF 100 million, while fines up to hundreds of millions of euros are not uncommon elsewhere in the EU. Although the Hungarian supervisory authority is keen to use fines as a compliance motivating tool, the level of fines to date seems not to have yet encouraged small and medium-sized companies to invest more in GDPR compliance. Because a significant proportion of the authority’s proceedings are initiated based on complaints from data subjects, legal compliance is often limited to preparing privacy notices. Yet often, for instance, the business procedures for responding to data subjects’ requests or data breaches are not well established, giving rise to exposure of yet more data subject claims.

In addition to planning, designing, and operating data protection compliant business processes, it is important that data controllers also comply with specific obligations under data protection legislation. A key element of that compliance – which is one of the starting points for legal due diligence – is the record of data processing activities. One of the important new features of the GDPR is that supervisory authorities no longer record data processing activities – rather, the data controllers and processors themselves are required to do so. In many cases, even in companies with a relatively mature data protection regime, this type of record-keeping is either missing or does not meet legislative requirements. In addition to being obviously noncompliant with the law, the absence of a register makes a company’s data management practice non-transparent and, therefore, more difficult for a potential buyer to assess.

Stating an appropriate legal basis for data processing activities and complying with the administrative burden of the chosen legal basis also seems to give rise to a considerable substantive challenge for companies. Consent is often the chosen legal basis for data processing, yet it is inappropriate in many instances, such as in employment relationships, where it is not a permitted legal basis because of the hierarchical relationship between the parties. In the case of direct marketing, companies often refrain from asking their customers for consent, fearing that doing so would significantly reduce their marketing campaigns’ effectiveness. Inadequate processes for record of consents and consent withdrawals also create significant compliance exposure – those processes are essential to comply with data controller accountability requirements. In the case of legitimate interest, a regular problem is the absence of the interest balancing test, which, based on current administrative practice, automatically renders the processing unlawful, regardless of the actual existence of a legitimate interest.

Establishing internal processes alongside appropriate policies and regulations will greatly enhance legal compliance and meet the accountability requirement mentioned above. Regular data protection training for employees and business partners is an integral part of achieving in practice a process that is legally compliant.

Data protection compliance can make a transaction significantly smoother, resulting in fewer closing conditions and reducing the risks associated with reps and warranties and indemnifications, which will be reflected in the pricing of the transaction.

By Csaba Vari, Head of IP/Tech Practice Group, Baker McKenzie

This Article was originally published in Issue 9.3 of the CEE Legal Matters Magazine. If you would like to receive a hard copy of the magazine, you can subscribe here.

Hungary Knowledge Partner

Nagy és Trócsányi was founded in 1991, turned into limited professional partnership (in Hungarian: ügyvédi iroda) in 1992, with the aim of offering sophisticated legal services. The firm continues to seek excellence in a comprehensive and modern practice, which spans international commercial and business law. 

The firm’s lawyers provide clients with advice and representation in an active, thoughtful and ethical manner, with a real understanding of clients‘ business needs and the markets in which they operate.

The firm is one of the largest home-grown independent law firms in Hungary. Currently Nagy és Trócsányi has 26 lawyers out of which there are 8 active partners. All partners are equity partners.

Nagy és Trócsányi is a legal entity and registered with the Budapest Bar Association. All lawyers of the Budapest office are either members of, or registered as clerks with, the Budapest Bar Association. Several of the firm’s lawyers are admitted attorneys or registered as legal consultants in New York.

The firm advises a broad range of clients, including numerous multinational corporations. 

Our activity focuses on the following practice areas: M&A, company law, litigation and dispute resolution, real estate law, banking and finance, project financing, insolvency and restructuring, venture capital investment, taxation, competition, utilities, energy, media and telecommunication.

Nagy és Trócsányi is the exclusive member firm in Hungary for Lex Mundi – the world’s leading network of independent law firms with in-depth experience in 100+countries worldwide.

The firm advises a broad range of clients, including numerous multinational corporations. Among our key clients are: OTP Bank, Sberbank, Erste Bank, Scania, KS ORKA, Mannvit, DAF Trucks, Booking.com, Museum of Fine Arts of Budapest, Hungarian Post Pte Ltd, Hiventures, Strabag, CPI Hungary, Givaudan, Marks & Spencer, CBA.

Firm's website.

Our Latest Issue