KWP: prioritise GPDR in acquisitions
Every business knows that smart investment stimulates growth, but few actively prioritise GDPR in acquisitions and only half of businesses are compliant. GDPR came into force in May 2018, introducing the need for much more rigid and robust data protection standards. This means that those who hand over their data are entitled to a higher level of protection, but unfortunately, this doesn’t always transpire. So what can go wrong if you fail to meet the GDPR, and what solutions are there to ensure your business is fully compliant?
Retrospective approach to GDPR
The new GDPR coming into effect in 2018, and since then, 89,271 data breaches have been reported. There have also been various examples of businesses paying the price for inadequate data protection for breaches occurring prior to 2018, which shed light on why it’s imperative that businesses need to prioritise GDPR in acquisitions.
In 2014, Starwood Hotels suffered a hack which enabled hackers to gain access to all the clients’ data, including financial information. Unaware of the breach, Marriott bought Starwood Hotels in 2016 and failed to carry out the appropriate due diligence around data protection, and specifically data security. The data theft was only discovered in 2018 under the new GDPR, resulting in the ICO (Information Commissioner’s Office) issuing the intention to fine Marriott £99m.
This penalty (due to be confirmed this month) could have been easily avoided if the Marriott chose to prioritise GDPR in the acquisition. What was meant to be an investment to strengthen and grow the business turned into a significant liability.
There are some serious lessons to be learned from this case; it’s not only about avoiding the significant cost of clear up and fines but also valuing your clients and customers enough to have the appropriate protections in place. If your business is involved in acquisitions, it’s all too easy to assume that the existing owner has the responsibility of selling a fully GDPR compliant company, but as soon as you have ownership, the responsibility of the data protection within the business becomes your problem, so the need to prioritise GDPR as part of your due diligence in acquisitions is essential.
What precautions can you take?
The consequences of a poor approach to GDPR, as illustrated by the Marriott story, shouldn’t put you off investing in acquisitions altogether. Acquisitions come with many benefits, including stronger market power, new competencies and recourses, and more access to capital. However, if you altogether fail to prioritise GPDR in acquisitions, the benefits can essentially become null and void.
One of the most effective GDPR precautions you can take is effective due diligence. As part of this, buyers and investors should require more contractual protection in the form of . If you are looking to invest or acquire, due diligence should also include data protection (data security is a fundamental part of this).
Increase the value of your business
If you’re looking to sell your business rather than but one, there is much to be gained in prioritising GDPR as a means of increasing the value of your business. In one study, 41% of organisations cited GDPR compliance as giving them a fresh competitive advantage, 37% said it could reduce pre-existing sale delays, and 36% claimed that their appeal to prospective investors had increased. Overall, the level of investment it may take to achieve GDPR compliance is far outweighed by the return on investment (ROI) in the form of increased capital value.
What’s the solution?
If you want to avoid the pitfalls of GDPR, or are conscious that you need to prioritise GPDR in acquisitions, it is well worth investing in compliance consultancy services . Outsourcing your GDPR needs is a highly cost-effective way to achieve compliance, and is well worth the investment when the other option is running the risk of the expensive implications. If you want to ensure your business is fully GDPR compliant, you can get a free-of-charge consultation here.
Conclusion
Although many businesses see GDPR as a pain, it’s also a necessity. The perceived pain it takes to achieve GDPR compliance is of no comparison to the pain of being fined a large sum of money as well as a loss of trust from customers or clients and brand damage that could take years to recover from (if at all). In fact, if you use compliance consultancy services, the pain of achieving GDPR can be removed entirely. If you prioritise GPDR in acquisitions now, you can rest assured in the knowledge that your business investments won’t be coming back to haunt you.
If you want to understand how to achieve GDPR compliance to protect your investments and acquisitions, get in touch with The Compliance Consultancy. We will be happy to answer any of your questions.
Leave A Comment