Privacy obligations when customer data changes hands in a sale
Customer information is not simply another asset on the list; federal and, in some sectors, provincial privacy law both govern how it can transfer.
Almost every small business sale involves a customer list, and almost no seller treats it with the same care they apply to the equipment schedule or the lease. That gap is worth closing, because personal information about customers is governed by privacy legislation that keeps applying after a change of ownership, and a buyer who assumes a customer database transfers the same way a delivery van does can be badly wrong about what they are actually entitled to do with it.
The federal floor: PIPEDA
The Personal Information Protection and Electronic Documents Act, PIPEDA, sets the federal baseline for how private-sector organizations across most of Canada collect, use, and disclose personal information, and the Office of the Privacy Commissioner of Canada has published detailed guidance on how it operates. A business sale involves disclosing customer information to a buyer during due diligence and then transferring it outright at closing, both of which touch obligations under this framework, including limits on how information collected for one purpose can be used for another and expectations around what customers were actually told when their information was first collected. A handful of provinces have their own private-sector privacy statutes recognized as substantially similar to PIPEDA, which changes which specific law applies to a business operating mainly within that province, without changing the underlying idea that personal information carries obligations through a sale rather than losing them at the moment of transfer.
Where a sector-specific statute adds another layer
Certain sectors carry their own, additional privacy regime layered on top of the general private-sector rules, and healthcare is the clearest example. In Ontario specifically, the Personal Health Information Protection Act, PHIPA, governs how health information custodians, a category that includes many medical, dental, and other healthcare practices, handle patient records, and it imposes its own conditions on transferring that information when a practice changes hands. This is an Ontario-specific statute; other provinces regulate health information through their own equivalent legislation, which is not identical to Ontario’s even where the underlying goals are similar, so a buyer or seller of a healthcare practice outside Ontario should not assume PHIPA’s specific rules apply to them.
What this actually changes about how a deal runs
- What can be disclosed to a prospective buyer during due diligence, and whether de-identified or aggregated data is sufficient before a deal is far enough along to justify sharing full customer records
- Whether a confidentiality agreement, on its own, is enough to satisfy applicable privacy obligations, or whether additional safeguards or notice to customers are genuinely required
- What happens to customer consent on a change of ownership, since consent given to one organization for one stated purpose does not automatically carry the same weight once a different organization owns the relationship
- Sector-specific records, health information most notably, but also information gathered under other regulated relationships, which can carry retention, access, and transfer obligations beyond the general privacy framework
What a well-run transfer of customer data actually looks like
A well-run transfer generally starts by separating what a prospective buyer genuinely needs to evaluate the business from what can wait until the deal is far enough along, under a signed confidentiality agreement, to justify handing over complete customer records. Aggregated figures, revenue by customer segment, retention rates, average account value, often answer a buyer’s early questions without exposing individually identifiable information at all, and only the later stages of diligence, once a deal looks likely to close, typically require the fuller picture. Sellers who have never actually audited what personal information the business holds, how long it has been kept, and what customers were told when it was first collected, are often surprised by what turns up once someone looks closely, which is one more reason this is worth reviewing well before a buyer’s counsel starts asking the same questions from the outside.
Why this belongs in due diligence, not an afterthought
A buyer’s counsel reviewing a target business increasingly treats privacy compliance as a genuine diligence item, not a courtesy check, precisely because the risk does not disappear at closing; it transfers along with the data. Sellers who can show they collected and handled customer information properly in the first place tend to make this part of diligence considerably shorter, while sellers who cannot are often the ones facing late-stage questions that slow a deal down at exactly the point neither side wants new issues surfacing.
Sources
Every rule, program detail and figure referenced in this article traces to a primary source. Links were last checked on the dates shown.
- 01Office of the Privacy Commissioner of CanadaGovernmentThe Personal Information Protection and Electronic Documents Act (PIPEDA)
- 02Treadstone LawLegal commentaryCybersecurity and Data Privacy Due Diligence When Buying a Business in Ontario
- 03Treadstone LawLegal commentaryBuying & Selling a Business
- 04Business Development Bank of CanadaIndustryHow to sell your business
Deavo is an advertising and listings platform, not a brokerage, law firm or valuation firm. This page is general information, not legal, tax, accounting or valuation advice, and rules differ by province. Confirm anything you rely on with a qualified professional before you act on it.