Skip to content

Cookies on Loupe

Essential cookies keep Loupe working and are always on. With your agreement, Loupe also loads analytics to count visits and see which pages and tools are used. There is no advertising tracking. You can change your choice at any time from cookie settings. Read the cookie policy

Loupe home

Customer data collected without valid consent

An email list or customer database is only worth what you can lawfully use after the sale. If consent was never valid, part of the list, and the revenue it drives, may have to go.
Category
Legal and compliance
Applies to
SaaS, Ecommerce, Content, App, Marketplace, Agency or services, Healthcare, Retail, Hospitality, Other
Severity
Price it in
Last updated
Author
Loupe editorial
Reviewer
Not yet reviewed

Why it matters

For many online and consumer businesses, the email list, the SMS list or the customer database is one of the most valuable assets. Sellers often point to list size and email revenue to support the price. That value depends on two things: whether the business was allowed to collect and use the data in the first place, and whether you can keep using it after the sale.

The rules differ by country and by channel. The EU and UK data protection regimes require a lawful basis for using personal data, with separate rules for electronic marketing. South Africa's POPIA generally requires consent for electronic direct marketing, with a limited exception for existing customers. Canada's anti-spam law and Australia's Spam Act also require consent for commercial email and messages, and expect the sender to be able to prove it. In the US, federal email rules work mainly on an opt-out basis, but automated marketing calls and texts generally need prior written consent, and some states add their own privacy laws.

Data gathered without valid consent creates three problems for a buyer. The list you can lawfully use may be much smaller than the list you were shown, and the revenue it drives shrinks with it. A regulator can fine the business or order it to stop using the data. And in an asset sale the data passes to a new owner, so the purposes it was collected for, and what customers were told, need to cover that change. The UK regulator, the ICO, expects both sides of an acquisition to check these points as part of due diligence.

Price in the part of the list you may lose. Winning consent back is harder than it sounds: in the UK, for example, the ICO treats an email asking people to agree to marketing as sent for direct marketing purposes, so it is caught by the same rules. Warranties about data protection compliance help, but they will not restore a list you cannot use. Take advice from a privacy lawyer in each country where the customers are.

Asset sale versus share sale

In an asset sale you buy selected assets of a business; in a share sale (a stock sale in the US) you buy the company itself, with its full history. The choice shapes risk, tax and what needs consent.

Due diligence

Due diligence is the investigation a buyer carries out before committing to a purchase, testing the finances, contracts, legal position and operations against what the seller has described.

Warranties and indemnities

Warranties are the seller's statements of fact about a business in the purchase agreement; indemnities are promises to reimburse specific losses. Together they decide who bears risks that diligence could not rule out.

How to spot it

  • Sign-up forms use pre-ticked boxes, or bury marketing consent in the terms of purchase.
  • Parts of the list were bought, rented, scraped or collected through competitions run with partners.
  • There are no records of when, where and how each contact signed up.
  • Email platform reports show high complaint rates, or the provider has issued warnings.
  • The privacy notice is missing, generic, out of date or silent about a sale of the business.
  • Customer data sits in personal accounts or spreadsheets with no access controls.
  • Security incidents were handled informally and never recorded.

Questions to ask the seller

  • How was each part of the list collected, and what did people agree to when they signed up?
  • Can you show consent records, with date, source and wording, for a sample of contacts?
  • Has any part of the list been bought, rented, shared or imported from another business?
  • How much revenue comes from email, SMS or calls to the database?
  • Have you had complaints, regulator enquiries or security incidents involving customer data?
  • Does your privacy notice allow customer data to pass to a buyer of the business?

Documents to request

  • Current and past privacy notices and cookie policies, with the dates each applied
  • Copies or screenshots of every sign-up form and checkout consent wording
  • An export of consent records for a sample of contacts
  • Email and SMS platform reports showing list growth, unsubscribes, bounces and complaints
  • Contracts with data processors, list providers and marketing agencies
  • A log of security incidents, complaints and correspondence with regulators

Sources

  1. Due diligence when sharing data following mergers and acquisitions (opens in a new tab). Information Commissioner's Office, 16 September 2026.
  2. Identify direct marketing (opens in a new tab). Information Commissioner's Office, 20 August 2025.
  3. Protection of Personal Information Act 4 of 2013 (section 69) (opens in a new tab). South African Government, 19 November 2013.
  4. Guidance note on direct marketing in terms of the Protection of Personal Information Act 4 of 2013 (opens in a new tab). Information Regulator (South Africa), December 2024.
  5. Getting consent to send email (opens in a new tab). Innovation, Science and Economic Development Canada, 1 April 2019.
  6. Avoid sending spam (opens in a new tab). Australian Communications and Media Authority, 16 September 2026.
  7. CAN-SPAM Act: a compliance guide for business (opens in a new tab). Federal Trade Commission, 16 September 2026.
  8. Telemarketing (opens in a new tab). Federal Communications Commission, 16 September 2026.

Want this checked properly on a real listing?

A dossier checks the listing's figures, registrations and risks, with a source and confidence for every finding. Open a listing in the feed and request a dossier from its page.

  • Dependence on one marketing channel

    When most customers arrive through one ad platform, marketplace, search engine or partner, a change you cannot control can cut revenue quickly.

    Severity: price it inCustomers and revenue
  • Fake or incentivised reviews

    Ratings built on fake reviews, or on reviews customers were rewarded for without saying so. The reputation you think you are buying may not survive scrutiny from platforms or regulators.

    Severity: deal breakerOnline and platforms
  • Code quality and security debt in software

    Software that works today but is hard to change, poorly tested, built on unsupported components or open to attack. The cost of putting it right falls on the buyer.

    Severity: price it inOnline and platforms
  • Domains or accounts held in personal names

    The domain, social profiles, app store, advertising or payment accounts belong to the owner or a freelancer rather than the business. They may not pass to you unless the deal says so.

    Severity: fixableOnline and platforms
  • Buying an online business: SaaS, ecommerce and content compared

    SaaS, ecommerce and content businesses are sold on the same marketplaces, but they earn money differently, fail differently and are valued differently. This guide compares the metrics, risks and diligence for each.

    9 minutes to read
  • Due diligence: what to check and in what order

    A sequence for due diligence that tests what could end the deal first, while it is still cheap to find out, and leaves the detailed and expensive work until the deal looks sound.

    10 minutes to read
  • How small businesses are valued

    Most small businesses are valued as a multiple of their earnings. This guide explains how the earnings basis is chosen, why size and quality move the multiple, and why an asking price is not a sale price.

    11 minutes to read
  • Online business diligence for SaaS, ecommerce and content

    The checks that matter most when a business lives online: live account access, traffic, platforms, ownership of digital assets, code and the revenue behind the dashboards.

    About 120 minutes
  • Diligence document request list

    The documents to ask for once terms are agreed in principle, grouped by area so the seller can fill a data room in order and you can see what is still missing.

    About 30 minutes
  • Asset sale versus share sale

    In an asset sale you buy selected assets of a business; in a share sale (a stock sale in the US) you buy the company itself, with its full history. The choice shapes risk, tax and what needs consent.

  • Warranties and indemnities

    Warranties are the seller's statements of fact about a business in the purchase agreement; indemnities are promises to reimburse specific losses. Together they decide who bears risks that diligence could not rule out.

  • Customer acquisition cost

    Customer acquisition cost is the average sales and marketing spend needed to win one new customer over a period. It shows whether growth can be repeated and at what price.

  • Customer lifetime value

    Customer lifetime value estimates the total gross profit a business earns from an average customer over the whole relationship. It is a model built on assumptions, not a record.

  • Due diligence

    Due diligence is the investigation a buyer carries out before committing to a purchase, testing the finances, contracts, legal position and operations against what the seller has described.

Live listings where this applies

No live listings match these topics right now. Browse the feed to see everything that is for sale.