Field Notes

question

What happens to data consent when a company is split or sold?

A person consents to a company collecting something for a stated purpose. The company is then split, sold, or wound up, and the dataset ends up in the hands of an entity the person never chose, pursuing purposes they were never asked about. What, if anything, does the original consent still constrain?

The vault does not currently hold an answer, and it has accumulated enough instances that the gap has become conspicuous.

Why it matters here

This wiki’s privacy analysis mostly assumes a stable relationship between a person and a named company: what was collected, why, on what legal basis, and how to get it deleted. Data minimization works from that frame, and so does most enforcement the vault records.

Corporate succession breaks the frame without breaking any rule. Each step can be lawful and disclosed while the aggregate outcome is one no participant would have agreed to at the start. That makes it a poor fit for the vault’s existing tools, which are aimed at conduct rather than at structure.

What the vault already holds

  • Niantic Spatial. Location scans contributed to a mobile game under an opt-in feature and broad terms of service trained models that a spun-off company now markets to defense and intelligence buyers. The company’s position is that the scans were voluntary and that Pokemon Go data no longer flows to it; neither statement addresses whether a 2020 player agreed to anything resembling the 2026 use.
  • 23andMe. The vault covers the breach and its enforcement, not the later disposition of the genetic database. The same succession question applies and has not been researched.

Two instances is enough to name the question. It is not enough to answer it, and the second is not yet written up in the form the question needs.

What is already known

Consent is not the only lawful basis, and much of what happens in a corporate transfer is likely governed by contract, legitimate interests, and the rules on controllers and processors rather than by the consent the user remembers giving. Purpose limitation under GDPR Article 5 constrains processing incompatible with the original purpose, and a “materially different purpose” test plausibly exists in guidance the vault has not read.

The Training data provenance problem compounds it. Where the transferred asset is a trained model rather than a dataset, even establishing what was inherited is difficult, so a remedy aimed at the data may not reach the artefact.

What would settle it

  • Find whether GDPR guidance or case law addresses purpose limitation across a corporate transfer, as distinct from a change of purpose within one controller.
  • Establish whether any regulator has treated a spin-off as an event requiring renewed consent, or has declined to.
  • Check what happened to the 23andMe database through the company’s financial difficulties, and whether any authority intervened on consent grounds.
  • Determine whether an erasure right reaches a model trained before the transfer, or only the training corpus.

The outcome that would change the vault’s analysis is a finding either way on the second point. If regulators treat succession as a consent-relevant event, then the corporate structure of a privacy-sensitive business becomes a thing to evaluate before trusting it. If they do not, then disclosure at collection time is doing all the work, and the practical advice that follows is different.

Do not resolve this by asserting that the terms of service permitted it. That is the answer to a different question — whether the transfer was lawful — and it is the answer both companies in the Niantic case already gave.

Built on 1 source (1 external).

Working out connections…