Privacy Due Diligence: GDPR & CCPA Signals
A company's privacy practices used to be a footnote in diligence. They aren't anymore — regulators have handed out fines in the hundreds of millions, and a target's sloppy data handling can become the acquirer's liability overnight. The good news is that a company tells you a lot about its privacy posture in documents that are, by law, public: its privacy policy chief among them.
The privacy policy is a disclosure, so read it like one
A privacy policy isn't marketing; under GDPR and CCPA it's a legally-required disclosure of what data a company collects, why, on what legal basis, and who it shares with. Read it the way you'd read a risk factor. Vague, boilerplate policies that could belong to any company are a signal in themselves — they often mean privacy hasn't been thought through, not that there's nothing to disclose.
GDPR: the signals that matter
For any company touching EU personal data, look for the substance the GDPR requires: a clear legal basis for processing (consent, legitimate interest, contract), a real mechanism for data-subject rights (access, deletion, portability), a named data protection officer or EU representative where required, defined retention periods, and — critically — how the company handles international transfers of EU data now that the old frameworks keep shifting. Silence on transfers is a red flag for any company with EU users and U.S. servers.
CCPA/CPRA: the California layer
For California consumers, the questions shift slightly: does the company honor the right to know, delete and correct; does it offer a "Do Not Sell or Share My Personal Information" mechanism; how does it treat sensitive personal information. A company that sells or shares data has specific obligations, and whether it meets them is visible in how its policy and its cookie banner are actually built.
The cookie banner tells on the company
One of the fastest tells is the consent experience. A compliant banner lets users refuse non-essential cookies as easily as they accept them, and it doesn't drop tracking cookies before consent. A banner with only an "Accept" button, or one that loads trackers on arrival, reveals a gap between the policy's promises and the site's behavior — and that gap is exactly what regulators look for.
Disclosure isn't the same as practice
A polished privacy policy proves a company can write one, not that it lives by it — the real test is whether stated practices match actual behavior, which needs more than a document review. Use the public disclosures to score the posture and flag the gaps and contradictions, then verify the high-stakes items directly. This is general information, not legal advice; privacy law is jurisdiction-specific and evolving.