Share deal: continuity of the company, not of data use
From a data protection perspective, a share deal is not a free pass. Although the target company remains the same legal entity and therefore, in principle, remains the controller for its data processing activities, the investor does not automatically acquire its own right of access or use in relation to operational data. Disclosure in the data room, later reporting lines, central platforms or group-wide analyses are already separate processing operations that must be reviewed in terms of purpose, necessity, role model and security.
In the aerospace and defense sector, further limits apply. Technical data may be contractually allocated to the customer, an OEM, an authority or a consortium. They may be subject to confidentiality levels, export controls, location requirements or special security requirements. A change of control may trigger notification, consent or review obligations outside data protection law. The question of whether the target continues to exist after closing is therefore only the first step, not the answer to whether its data can be used.
Information security Is part of product and delivery capability
For technical data, confidentiality is only one dimension. Incorrect versions, manipulated parameters, incomplete change histories or unavailable PLM, test and maintenance systems can impair approval evidence, production decisions and safe maintenance. Data integrity and availability are therefore directly linked to revenue, liability risk and delivery capability.
Information security due diligence must look at office IT, engineering networks, development and test environments, production and OT-adjacent systems, remote maintenance, cloud services and supplier access together. An attacker or flawed privileged access can not only steal data, but also change configurations, delay development programmes or make it harder to resume operations.
Which data assets drive enterprise value
Sector-specific data asset valuation should capture technical, operational and regulatory evidence separately. The following are particularly relevant:
- Design, CAD, PLM and configuration data, including versions and change history.
- Test, qualification, certification and evidence data with robust traceability.
- Digital twins, simulation models and engineering libraries.
- Maintenance, MRO, reliability and condition data for predictive maintenance.
- Supplier, material, quality and serial number data along the supply chain.
- Security, incident and vulnerability data, as well as information on cyber resilience.
- Contractual and rights information that determines whether and how data may be reused or disclosed to third parties.
The value of data increases with uniqueness, reliability, long-term utility and direct connection to revenue or cost savings. It decreases when files exist without context, rights labelling, version history or technical readability. For long-running platforms, it is also crucial whether data remain migratable and traceable over decades.
Risk areas in M&A due diligence
| Risk area | Typical issue | Impact on valuation |
|---|---|---|
| Rights and restrictions | Technical data may be used only for a specific programme, customer or jurisdiction. | Synergies and data monetisation may fall away; the addressable market becomes smaller. |
| Data integrity | Changes, test conditions or serial-number references are not documented without gaps. | Evidence must be reconstructed; certification and liability risks increase. |
| Cybersecurity | Legacy systems, external remote maintenance, unclear privileged accounts or unpatched environments. | Immediate investment, business interruption and potential incident consequences reduce enterprise value. |
| Data residency and access | Cloud, support or adviser access conflicts with location or security requirements. | Planned platform synergies can only be realised to a limited extent or with additional costs. |
| Supply chain | Data originate from suppliers whose rights, security and availability are not adequately safeguarded. | Third-party risk and dependency increase the risk discount. |
| Obsolescence | Proprietary formats, old PLM systems or missing documentation make migration and long-term archiving more difficult. | High replacement cost and extended integration timelines. |
| ISMS scope | The ISO 27001 certification covers only office IT or individual sites; engineering, test labs, OT-adjacent systems or critical suppliers are excluded. | The claimed security maturity does not cover the value-bearing data assets; scope expansion and remediation make integration more expensive. |
Cyber due diligence is a value review, not just compliance
In this sector, a security weakness can directly destroy data value. This affects not only personal data, but also trade secrets, technical specifications and operational systems. Cybersecurity due diligence should therefore look at identities, privileged access, segmentation, vulnerability management, supplier access, backup, restart capability and incident history together.
It is particularly telling whether the target knows its critical data classes and actually controls access accordingly. A formal data governance framework without technical enforcement offers little protection. Conversely, clear classification with robust logging can strengthen digital trust and therefore the seller’s negotiating position.
Reviewing ISO/IEC 27001: scope, effectiveness and sector-specific gaps
ISO/IEC 27001:2022 provides a risk-based framework for an information security management system. In M&A due diligence, however, the certificate is only the starting point. The review must determine whether the scope includes the relevant entities, sites, engineering networks, PLM and lifecycle systems, test environments, cloud services and service processes. A clean office scope says little about the security of value-bearing technical data assets.
In addition, customer, programme, confidentiality, export, location or other sectoral requirements may go beyond ISO 27001. Due diligence should therefore reconcile the ISMS with the specific data classes, contracts and operating conditions. Relevant evidence includes, in particular, risk analysis, Statement of Applicability, risk treatment, internal audits, management review, corrective actions, vulnerability management, incident response, restart and restore tests, and the management of critical suppliers.
| ISO 27001 review area | Expected evidence | Relevance for data valuation |
|---|---|---|
| Scope and boundaries | Sites, engineering, test, production, service and cloud environments within the scope. | Core systems outside the scope increase remediation, integration time and outage risk. |
| Classification and access | Data classes, roles, segregation, privileged access, encryption and logging. | Effective controls protect IP, traceability and permissible use options. |
| Vulnerability and incident | Patch and exception processes, monitoring, incident history, exercises and lessons learned. | Open vulnerabilities and untested response increase incident and operational risk. |
| Supply chain and remote access | Critical providers, security requirements, remote access, sub-processors and exit rules. | Third-party risk can dominate product, service and restart costs. |
| Continuity and improvement | Backups, restore tests, restart objectives, audits, management review and corrective actions. | Demonstrated resilience reduces outage discounts and protects long-term data availability. |
Data protection in the data room: less Is more
Even in a pure share deal, disclosure in the data room remains a separate review point. Personal data may be contained in maintenance reports, incident tickets, access logs, supplier contacts or test documentation. For the investment decision, aggregated maturity metrics, anonymised incident statistics, system lists and samples are usually sufficient. Names, access credentials, operational network details or complete security-critical documents should not be disclosed broadly.
- Multi-stage data room with sector-specific approval levels.
- Clean team for particularly sensitive technical, competitive or security-relevant information.
- No operational credentials, secrets or exploitable attack information in the data room.
- Traceable logging, download restrictions and erasure if the process is aborted.
- Separate review of cross-border access and of the groups of persons on the investor side.
- Provide the ISO certificate, scope, high-level Statement of Applicability information and audit status in a controlled manner; detailed vulnerability or attack information only through the clean team.
Opportunities: data as an engineering and aftermarket lever
If technical data are properly controlled, significant opportunities arise. Digital twins and linked lifecycle data can shorten development cycles, focus testing efforts and make changes more traceable. MRO and condition data enable predictive maintenance, better spare parts planning and new service offerings. Supply chain and quality data can reduce scrap, downtime and procurement risks.
The central value-creation lever is enterprise data governance: consistent classification, data lineage, clear data ownership, defined exchange formats and tiered security controls. These foundations not only increase operational efficiency. They also create the conditions for responsibly using data for simulation, analytics and AI governance. A robust ISO 27001 scope can also accelerate customer assessments, supplier qualification and the integration of new sites. The value lies in demonstrable control of risks, not in the certificate alone.
Data valuation: from gross value to risk-adjusted value
Income approach
The income-based approach values additional cash flows from maintenance services, higher availability, less scrap, faster development cycles or better proposal quality. For long product lifecycles, realistic useful lives and discounting are particularly important.
Replacement and reproduction cost
For test series, operating data and engineering libraries curated over many years, the effort required to collect the data again may be enormous. However, the cost approach must take into account whether reproduction would be technically, practically and legally possible at all. Non-repeatable data can have high strategic value.
Rights, security and integrity discount
Costs for rights clearance, reclassification, security remediation, ISMS scope expansion, format migration and traceability reconstruction must be deducted from the gross value. In addition, a risk discount must be applied for cyber incidents, production or service outages, supplier dependency, export and location restrictions, restart deficits or uncertain long-term readability.
Review programme for data due diligence and technology due diligence
- Which datasets are business-critical for products, certifications, maintenance and delivery capability?
- Which classifications, export, location, confidentiality or customer restrictions apply?
- Can rights, origin, version, approval and change history be traced for each critical dataset?
- Which systems store critical data, how long are they supported and how has restart capability been tested?
- Who has privileged access: internally, at the supplier, at the customer or at the cloud and service provider?
- Which incidents, vulnerabilities, reportable events or regulatory findings exist?
- Which sites, engineering, test, production and service environments are within the scope of the ISO 27001 certification?
- Are the Statement of Applicability, risk treatment, audit findings and corrective actions current and aligned with the critical data classes?
- When were incident response, backup, restore and restart last tested under realistic conditions?
- Which synergies require migration, cross-border access or a shared platform?
- Which investments are required to reach the target level for cyber resilience and operational resilience?
The results should be consolidated into a shared governance, risk and compliance view. The investor does not need isolated lists, but a prioritisation: which risks threaten closing, purchase price, ongoing programmes, customer relationships or the planned value creation?
Deal protection and 100-Day plan
In the purchase agreement, known gaps can be addressed through specific warranties, indemnities, covenants and conditions. Relevant statements include those relating to data rights, classification, cyber incidents, critical third parties, completeness of technical documentation and compliance with material security requirements.
- Day 1: no automatic group, network or identity releases; confirm and log critical access, remote maintenance and privileged accounts.
- By day 30: create a critical data register with owner, system, protection class, jurisdiction and rights profile; map the ISO 27001 scope, risk register and open findings against the value-bearing environments.
- By day 60: prioritise and close privileged accounts, external access, critical vulnerabilities, segmentation and backup/recovery gaps; perform a restore test.
- By day 100: adopt a target picture for PLM, engineering and lifecycle data, as well as the ISMS and ISO 27001 scope, including a migration, integration and long-term archiving plan.
- Value-creation KPIs: data integrity, traceability, system availability, restore success rate, patch and access-review coverage, open high risks, security maturity and share of usable lifecycle data.
Conclusion: The most valuable dataset is the dataset under control
In an aerospace and defense share deal, data valuation is inseparable from usage rights, data integrity, information security and cybersecurity. The company itself remains in place, but the planned use may be limited by contracts, security requirements, jurisdictions and technical legacy issues. Integrated data due diligence therefore reviews ISO 27001 not as a tick-box exercise, but as an evidence-based ISMS. This makes risks relevant to the purchase price and turns opportunities from engineering efficiency to aftermarket services into robust assumptions.
FAQ: share deal, data protection and data valuation
#1 Why is traditional IT due diligence not enough?
Because the value of technical data depends on more than systems. Rights, classification, traceability, long-term readability, third parties and specific usage restrictions must be assessed together.
#2 May the PE sponsor centrally analyse technical data after closing?
Not automatically. Access must be designed according to roles, purpose, confidentiality, jurisdiction and, where applicable, further sectoral requirements. Particularly sensitive data may have to remain within the target.
#3 How are digital twins valued?
Through expected cash flows and cost savings from development, maintenance and availability, as well as through replacement cost. Rights, quality, security and integration risks are deducted.
#4 Which red flag has the strongest effect on the purchase price?
A critical dataset without traceable rights, versions and traceability, especially where it is indispensable for approval, operation or maintenance.
#5 Is an ISO 27001 certificate sufficient for cyber due diligence?
No. Scope and operational effectiveness are decisive. A certificate may cover office IT while engineering, test, production or service environments are outside the scope. Sectoral and contractual security requirements must also be reviewed.