02.09.2026

Share Deal in a consulting firm: data valuation, information security and ISO 27001

In consulting firms, a large share of enterprise value lies in methodologies, project experience, client knowledge and reusable information assets. These intangible assets are often stored in cloud platforms, knowledge bases, project tools and AI applications. Whether this becomes scalable know-how or a costly legacy burden depends on integrated data due diligence covering data protection, information security, ISO 27001, rights review and data governance.

Arrange a no-obligation initial consultation
Your ISiCO-Expert:
Dr Jan Scharfenberg
Partner Information Security, Managing Director

Why the share deal does not resolve the data question

From a data protection perspective, a share deal is not a free pass. Although the target company remains the same legal entity and therefore, in principle, remains the controller for its data processing activities, the investor does not automatically acquire its own right of access or use in relation to operational data. Disclosure in the data room, later reporting lines, central platforms or group-wide analyses are already separate processing operations that must be reviewed in terms of purpose, necessity, role model and security.

In a consulting firm, this distinction is particularly important: the acquisition of shares does not change confidentiality commitments towards clients or the purpose limitation applicable to personal data. Copyright, contractual restrictions and requirements protecting confidential information also remain in place. Data that could only be processed for a specific project before closing does not automatically become a freely available group or training dataset as a result of the change of control.

The key risks in private equity due diligence

Risk area What can go wrong in the share deal Impact on valuation
Client rights Project files contain confidential information; contracts do not permit reuse or permit it only for narrowly defined purposes. Expected data monetisation and cross-selling effects must be reduced or removed entirely.
Know-how dependency Knowledge resides in people’s heads, mailboxes or local drives and is not documented as an organisational asset. High key-person and integration discount; replacement cost increases.
Data protection and purpose limitation Customer, contact or expert data are to be used for new analyses, group-wide CRM use or AI training. Use may be unlawful or only possible after adjusting processes, information notices and legal bases.
Cybersecurity and access rights Historically grown permissions, open project folders or insufficient logging increase the risk of data leakage. Remediation budget, potential incident costs and reputational risks reduce enterprise value.
Data quality Inconsistent taxonomies, duplicates, missing versioning and unclear data provenance prevent analytics. Time to value is extended; integration and cleansing costs increase.
ISMS and ISO 27001 A certificate covers only parts of the organisation; scope, Statement of Applicability, risk treatment or open audit findings are not up to date. The assumed level of security maturity is not reliable; remediation, certification and integration costs increase the risk discount.

The data room is already a maturity test

Serious GDPR due diligence does not require maximum transparency, but controlled evidence. In an early phase, aggregated metrics on project types, sectors, recurring revenue, client concentration, usage rights and knowledge assets are sufficient. Later, pseudonymised samples or clean-team analyses may be added. Lists of names, complete project files or sensitive client documents should be included in the data room only in exceptional cases and with a clear justification of necessity.

  • Need-to-know and time-limited roles instead of blanket data-room permissions.
  • Redaction, aggregation and pseudonymisation before personal data are disclosed.
  • Download restrictions, watermarks, logging and defined erasure periods.
  • Separate clean teams for information that is particularly sensitive from a competition or client-engagement perspective.
  • Documented decision as to why specific data are necessary for the investment decision.

ISO/IEC 27001:2022 defines requirements for a risk-based information security management system. A valid ISO 27001 certificate can accelerate information security due diligence and reduce information asymmetries. However, it does not prove the security of all data assets or the effectiveness of every individual control. The decisive question is which entities, locations, services, cloud platforms and knowledge systems are actually included in the certified scope.

The review should cover at least the ISMS scope, risk analysis, risk treatment plan, Statement of Applicability, internal audits, management review, corrective actions, incident history, access recertifications and backup and restore tests. After closing, new group services, platforms or data flows may change the context and the risk assessment. It should therefore be clarified at an early stage whether the scope, risk treatment and, where necessary, communication with the certification body need to be adjusted.

ISO 27001 review area Expected evidence Relevance for data valuation
ISMS scope Entities, locations, services, SaaS, cloud and knowledge platforms within the scope. A narrow scope may leave key synergies and data assets outside the assessment.
Risk analysis and treatment Current risk register, owners, deadlines, risk acceptances and budget. Open high risks become quantifiable remediation and integration costs.
Statement of Applicability Selected controls, justified exclusions and implementation status. Shows whether the claimed security maturity matches the business model and client risks.
Operational effectiveness Access reviews, logs, vulnerability management, incident response, backup and restore evidence. Effective controls reduce outage, leakage and recovery risks.
Suppliers and improvement SaaS inventory, security assessments, exit rules, audit findings and corrective actions. Third-party risk and open findings determine the risk discount and 100-day budget.

ISO 27001 audit rule

A certificate without a defined scope, up-to-date risk treatment and operational evidence must not automatically reduce the security risk discount. Value is created through proven effectiveness, not through the logo on the website.

 
 

Opportunities: data governance makes know-how scalable

The opportunity does not lie in consolidating as many legacy files as possible. Value is created when enterprise data governance turns scattered knowledge into a robust operating model. This includes clear data ownership, consistent metadata, approval processes for reuse, technical access concepts and a traceable lifecycle for project knowledge.

A well-managed consulting firm can thereby accelerate its service delivery, make quality more consistent, calculate proposals more precisely and develop new data-based products. Examples include anonymised industry benchmarks, repeatable diagnostic tools, subscription-based insights or AI-supported research. However, these opportunities require client rights, data protection, protection of confidential information and AI governance to be built into product design from the outset. An appropriate ISO 27001 scope can also facilitate tenders, vendor onboarding and client reviews. The commercial benefit arises only if certification and day-to-day working practices are aligned.

Value creation rather than data hoarding

A curated collection of 5,000 legally usable, structured and up-to-date knowledge objects can be more valuable than an unmanaged repository containing a million files. Data maturity and digital trust are therefore value drivers in their own right.

 
 

How data in a consulting firm is valued

For business data valuation, at least three perspectives should be combined. A single model is rarely sufficient because consulting know-how is highly dependent on context and rights.

1. Income-based approach

The starting point is additional or secured cash flows: higher recurring revenue, faster project delivery, better utilisation, cross-selling, higher proposal win rates or new data products. These effects are forecast over a realistic period and discounted. It is crucial to include only those effects that can be achieved with the existing usage rights and the actual data quality.

2. Cost and replacement-cost approach

Replacement cost shows the effort that would be required to collect, structure, tag, quality-assure and technically provide a comparable knowledge asset. However, it provides only a plausibility floor: knowledge that was expensive to create is not automatically market-relevant or legally usable.

3. Risk and usability discount

Costs for rights clearance, data cleansing, security, migration and governance must be deducted from the gross economic value. This also includes closing ISO 27001 findings, cleaning up permissions, DLP and logging measures, restore capability and supplier assurance. In addition, a risk discount must be applied for unclear legal bases, insufficient documentation, client concentration, low currency, potential incident consequences or a high dependency on individual knowledge holders.

Data due diligence: the right questions for the investment case

  1. Which data and knowledge assets specifically contribute to revenue, margin, client retention or product development?
  2. Who owns which rights in methodologies, templates, benchmarks and project results?
  3. Which client restrictions prevent reuse, consolidation or AI training?
  4. How are data provenance, version, approval status, erasure period and responsibility documented?
  5. Which security incidents, open permissions or uncontrolled exports exist?
  6. Which entities, locations, services and knowledge platforms fall within the scope of the ISO 27001 certificate?
  7. Are the Statement of Applicability, risk treatment plan, audit findings and corrective actions current and funded?
  8. How are privileged access, external SaaS services, backup, restore and incident response operationally tested?
  9. What costs and timelines are required to turn the existing asset base into AI-ready data?
  10. Which synergies can genuinely be realised within the target company in the share deal, and which require new data flows into the group?

The results should not be confined to a data protection report. They must be linked with commercial due diligence, technology due diligence and the value-creation plan. This makes it clear whether an expected revenue lever is realistic, whether a purchase-price discount is required or whether specific remediation should be planned as a closing condition or 100-day measure.

Purchase agreement and 100-day plan

In a share deal, known risks can be reflected through warranties, disclosures, indemnities and specific covenants. Particularly value-relevant are assurances on usage rights, data protection incidents, client restrictions, data quality, open-source and third-party content, and the completeness of the material data assets.

  • Day 1: no blanket group integration; limit investor access, privileged accounts and external sharing to what is strictly necessary.
  • By day 30: create a data and knowledge asset inventory with rights, purposes, protection class and owners; map the ISO 27001 scope and open findings against the target operating model.
  • By day 60: close critical permission, sharing, SaaS, logging and backup/restore gaps and schedule high-risk corrective actions.
  • By day 100: adopt an integrated target picture for the ISMS, data governance, reuse, data products and secure AI applications; expand the certification scope if necessary.
  • Value-creation KPIs: utilisation rate of curated assets, reuse rate, data quality, access-review coverage, restore success rate, open high risks, incident response time and number of data products approved from both a legal and security perspective.

Conclusion: know-how is only an asset if it remains usable

In a share deal involving a consulting firm, the transaction form alone does not determine the value of data. Value is created only if the target has its information assets under control legally, technically and organisationally. Integrated M&A due diligence combines data protection, chains of rights, information security due diligence, ISO 27001, data quality and commercial usability. This turns abstract know-how into a robust value driver and prevents an uncontrolled archive from becoming an unexpected purchase-price risk.

Your solution for the best data protection

Trust is the foundation of every good business relationship. Strengthen your relationships with customers by leveraging our expertise in data protection. This will give your company a strong competitive advantage, allowing you to focus fully on your business.

Book your appointment now

FAQ: share deal, data protection and data valuation

#1 Do data automatically transfer to the investor in a share deal?

No. The target company remains the same legal entity and, as a rule, remains the controller. Investor access, group-wide consolidation or migration are separate processing operations and require a clear concept for roles, purposes and security.

#2 How can the value of consulting know-how be measured?

By combining expected data-related cash flows, avoided replacement costs and a discount for rights, data protection, security, quality and integration risks.

#3 May project files be used for AI training?

Not automatically. In particular, client contracts, purpose limitation, personal data, protection of confidential information, copyright and usage rights, and the AI governance of the specific model must be reviewed.

#4 What is the biggest red flag in due diligence?

A high claimed data value without a robust chain of rights, without a structured asset map and without evidence that the data are current, secure and legally usable for the planned use.

#5 Is an ISO 27001 certificate sufficient evidence of good information security?

No. The certificate is a relevant indication of an established ISMS, but it applies only to the stated scope. Private equity should additionally review risk treatment, the Statement of Applicability, audit findings and operational evidence such as access reviews, incident tests and restore tests.