Is Customers Data Just Another Asset When Companies Are Sold?
When a company is bought or sold, or is part of an acquisition, we usually hear about shareholders, investors and executives. But in most cases now there is another valuable asset quietly changing hands:
YOUR PRIVATE INFORMATION.
Across Ireland, and globally companies are being sold, acquired or absorbed into larger international businesses. Along with the offices, contracts and equipment, customer databases can become part of the deal. Names, addresses, contact details, payment histories and account information may all move from one company to another.
And the customer? Often, they are simply informed after the deal is done or not at all.
That raises a very simple question: When did our personal information become a corporate asset that can be traded without our consent?
Under GDPR, companies may have some legal grounds to transfer customer data during a business sale. Lawyers can point to legitimate interests, contractual necessity and continuity of service. But legal permission and public trust are not the same thing.
Why should a company have more rights than you in a transaction when you are a party to the sale?
It shouldn't.
For the average customer, it can feel like this: you trusted one company with your personal information, that company was sold, and suddenly your data is in the hands of someone else. Worse, it may not stop there. Your information can be shared, sold, or distributed to data brokers and countless other third parties, who may use it for targeted advertising, online tracking, profiling, and other forms of privacy intrusion. All this can happen in the background without your knowledge.
1. A person’s personal or business information is not inventory.
2. Not stock.
3. Not a commodity to be passed around in a corporate transaction.
If customer data helps create the value of a company, why are customers completely excluded from that value?
A buyer may effectively be paying for access to thousands of established customer relationships and the information connected to them. In some cases, the customer database may be among the most valuable, or the only valuable assets being purchased. The people who created that value, however, in most cases receive nothing.
That may seem to be legally permissible, but legality is not the same as legitimacy.
GDPR: A Meaningful Standard – Protection in Principle, Control in Practice? Or Not.
The gap between GDPR in principle and GDPR in practice becomes impossible to ignore. If a company can transfer your personal information to a new owner without asking you first, then what control do you really have? Where is the GDPR?
This is not simply a legal question. It is a question of trust, ethics and respect.
Companies may have legitimate reasons for transferring data during an acquisition but the fact remains each customer no matter how big the database, is a person.
Time to Rethink the Rules
When personal data materially contributes to the value of a sale, customers have to receive both recognition and financial compensation.
These suggestion may make corporate Ireland uncomfortable. They should.
Our Data. Our Rights. Our Choice.
If GDPR is truly about putting people at the centre of data protection, then it must do more than provide legal and moral cover for just corporate convenience. It must give people involved meaningful rights when the companies they trusted change ownership.
Because the real question is no longer just who owns the company?
It is this:
Who owns the value created by our personal data? And why are we the only stakeholders left without a choice treated as assets to be bought and sold once a company has extracted all the value it can from us?
_____________
Which rights do individuals have under the GDPR?
The GDPR provides the following rights to data subjects, i.e. individuals whose data is processed:
- Right to be informed
- Right of access
- Right to rectification
- Right to erasure (right to be forgotten)
- Right to restriction of processing
- Right to data portability
- Right to object
- Right not be subject to a decision based solely on automated processing
Please note that some of those rights do not apply in all situations, you can see the data subject rights for each legal basis table for more information.
The data controller is under an obligation to respond to requests of data subjects who exercise their rights and must facilitate the exercise of these rights. The data processor must assist the data controller in this task.
source: https://www.edpb.europa.eu/sme/be-compliant/respect-individuals-rights_en



