Skip to main content
Code auditCheck every pull request for privacy riskWebsite auditCatch scripts and vendors that appear in productionInth AgentAsk what changed and follow the answer to its sourceCookie consentFast consent that lives in your codebase
AboutHandbookBlogOSS
AI feature reviewsFundraising Due DiligencePrivacy impact reviewsEnterprise customer reviewsCookie and tracking audits
Pricing
Sign inRun a free scan
Run a free scan
Back to the blog

Published September 7, 2026

How privacy governance shows up in startup due diligence

WD

Will De Ath

Head of Growth

Privacy governance often becomes visible during M&A, fundraising, and enterprise sales. This guide explains how Inth helps startups prepare consent, tracking, and product evidence before diligence starts.

Topic
Guides
Reading time
14 min read

Privacy governance becomes visible when another party needs to trust how your product handles data. That usually happens during M&A, fundraising, or an enterprise sales review. The request may arrive as a diligence questionnaire, a data room checklist, a security review, or a redline to your data processing agreement.

Inth helps teams prepare the product evidence behind those answers. It keeps consent rules, regional behavior, script loading, consent records, and configuration history close to the application, so legal, security, and customer teams can verify what happened instead of reconstructing it from vendor dashboards. It does not replace counsel or a full privacy program, but it gives startups a stronger evidence base for the diligence questions that appear first.

This guide explains where those requests come from, what evidence teams usually need, and how Inth can help developers make privacy artifacts easier to produce. It is legal information, not legal advice. Ask counsel to review the final position for your company, jurisdictions, and data uses before you rely on it in a transaction.

What you will be able to prepare

By the end, you should be able to:

  • Recognize the privacy questions that appear in M&A, fundraising, and enterprise procurement.
  • Separate legal requirements from market diligence expectations.
  • Organize a privacy evidence folder around product behavior.
  • Use Inth to support consent, tracking, regional rules, and configuration evidence.
  • Capture data-processing metadata in a way that supports legal, security, and sales reviews.
  • Identify the areas that need legal review before a deal process starts.

Why diligence asks for privacy evidence

Diligence is an evidence exercise. A policy says what the company intends to do. A privacy program shows how the company knows what data it collects, why it collects it, where it goes, who can access it, when it is deleted, and how users can exercise rights.

For EU and UK data protection, this evidence layer is part of the accountability model. The GDPR requires controllers to be responsible for, and able to demonstrate, compliance with core data protection principles. The European Data Protection Board describes accountability in the same way and points to records of processing, data protection by design, and DPIAs as examples of evidence. The UK ICO also says organizations should keep evidence of compliance steps, including processing records, policies, contracts, security measures, DPIAs, and breach records.

In the US, the position is more fragmented. There is no single federal GDPR equivalent for all startups. Some obligations come from state privacy laws, sector rules, consumer protection law, customer contracts, and security commitments. For example, the FTC Safeguards Rule requires covered financial institutions to maintain a written information security program, written risk assessments, service provider oversight, an incident response plan, and written reporting to the board or equivalent body.

The practical result is similar across deal types: the other side wants to see whether your product and your governance records match. Inth helps with that match for consent and tracking behavior by moving banners, preferences, regional logic, script loading, and consent records into product infrastructure developers can review.

The three diligence moments that expose privacy gaps

M&A

An acquirer wants to know what privacy risk it is buying. The diligence team may ask whether the company can lawfully use the data after closing, whether consent or notice limits future use, whether customer contracts restrict transfers, and whether prior incidents or complaints could create liability.

M&A diligence can also create its own information-sharing risk. The FTC has warned parties to share only the information needed for diligence, tailor materials to diligence issues, use clean teams or third-party consultants for competitively sensitive information, redact or aggregate sensitive information, restrict data room access, and destroy information when required. That guidance is about competition law, not privacy law, but the same operational discipline helps when a data room contains customer, employee, or usage data.

A startup entering an M&A process should expect requests for:

  • Data maps and system inventories.
  • Customer and user data categories.
  • Privacy notices in force over time.
  • Records of consent, opt-outs, and withdrawal where consent is used.
  • Data processing agreements with customers and vendors.
  • Subprocessor lists and change-notice procedures.
  • Incident and breach records.
  • DPIAs, privacy impact assessments, or similar risk reviews for high-risk processing.
  • Retention schedules and deletion procedures.
  • AI or automated decision-making records where product features use personal data for model training, inference, scoring, or profiling.

Inth supports the consent and tracking part of this package. During diligence, a team can point to versioned consent configuration, regional rules, script gating, and consent records instead of saying that consent was handled manually across the app. That does not answer every M&A question, but it reduces uncertainty around a common set of web and product data flows.

Fundraising

Investors usually run lighter privacy diligence than an acquirer, but the questions grow as the round size, customer base, and regulated exposure grow. A seed investor may ask for the privacy policy, security posture, and any known incidents. A growth investor may ask for more formal evidence, especially if the company sells to regulated customers, processes sensitive data, operates in the EU or UK, or depends on large third-party data sets.

Fundraising diligence often focuses on business risk:

  • Can the company sell into its target market without privacy blockers?
  • Are there unresolved regulatory complaints, customer claims, or breach issues?
  • Does the company have the rights it needs to use training data, analytics data, or customer content?
  • Will privacy obligations slow enterprise sales?
  • Are promised controls implemented or only described in documents?

Inth gives founders and operators a more concrete answer for consent-dependent product behavior. They can show how the product manages banners, preference centers, regional rules, scripts, and records, then explain what still sits with legal, security, or data governance owners. Investors may not expect a mature privacy office. They do expect clear ownership, a credible path to improvement, and no hidden gaps that change the risk profile of the deal.

Enterprise deals

Enterprise privacy review is usually the first diligence process many startups feel. It appears during vendor onboarding, security review, procurement, and contract negotiation. The customer wants to know whether your product can handle its data under its legal, security, and internal policy requirements.

Common enterprise requests include:

  • A data processing agreement.
  • A subprocessor list.
  • Details about hosting location and cross-border transfers.
  • Security questionnaire responses.
  • SOC 2 or ISO 27001 evidence, if available.
  • Access control, encryption, logging, and incident response details.
  • Deletion and return procedures at contract end.
  • Privacy request support, such as access, deletion, correction, and opt-out workflows.
  • Cookie, analytics, session replay, and marketing pixel details.
  • AI feature disclosures, training-data limits, and customer content controls.

Inth is directly relevant when the review turns to cookies, analytics, pixels, tag managers, session replay, and consent records. It helps teams control when scripts run and keep consent evidence ready for legal, security, and customer teams. That makes enterprise answers more repeatable because the evidence comes from the way the product is configured, not from a one-off spreadsheet created during the sales cycle.

Enterprise review turns privacy governance into revenue infrastructure. If your team can answer the same questions quickly and consistently, deals move with fewer escalations.

The evidence folder to build before anyone asks

A useful diligence folder is organized by decision evidence, not by department. These five sections work for most startup reviews. Inth does not replace every folder, but it helps prepare evidence across each one where consent, tracking, regional behavior, and script execution affect the answer.

1. Data inventory and purpose evidence

Start with the systems that collect, store, process, or receive personal data. For each system, record the data categories, purposes, sources, recipients, retention periods, owner, and jurisdictional notes.

For GDPR or UK GDPR, many organizations need records of processing activities. Even where a full ROPA is not strictly required, a processing inventory is often the practical foundation for notices, contracts, rights handling, retention, and risk reviews. Avoid claiming that every company must maintain a ROPA. The rule has scope and exception details that counsel should confirm.

Inth helps keep one part of the inventory honest: the scripts and consent-dependent services running in the app. If analytics, pixels, session replay, or other third-party tools depend on region and preference choices, Inth can help show which categories exist, when scripts are allowed to run, and how the configuration changed.

A developer-owned registry can connect that runtime evidence to the wider processing inventory:

type DataCategory =
  | "account"
  | "billing"
  | "usage"
  | "support"
  | "device"
  | "marketing"
  | "sensitive";

type ProcessingPurpose =
  | "provide_service"
  | "security"
  | "billing"
  | "analytics"
  | "marketing"
  | "support"
  | "ai_feature";

type DataFlow = {
  system: string;
  owner: string;
  categories: DataCategory[];
  purposes: ProcessingPurpose[];
  source: "user" | "customer_admin" | "product" | "third_party";
  recipients: string[];
  retention: string;
  regions: string[];
  evidenceSource: "inth" | "data_warehouse" | "vendor_contract" | "manual_review";
  legalReviewTicket?: string;
};

export const dataFlows: DataFlow[] = [
  {
    system: "product-analytics",
    owner: "growth-engineering",
    categories: ["usage", "device"],
    purposes: ["analytics"],
    source: "product",
    recipients: ["analytics-vendor"],
    retention: "13 months",
    regions: ["US", "EU"],
    evidenceSource: "inth",
    legalReviewTicket: "PRIV-142",
  },
];

This registry is not a complete legal record by itself. It gives privacy, security, and sales teams a source of product truth they can review and export.

2. Transparency, consent, and rights evidence

A privacy notice is only one part of transparency. Diligence teams may also ask how the company collects consent, records opt-outs, responds to privacy rights requests, and reflects product changes in notices.

Prepare evidence for:

  • Privacy notices and notices at collection.
  • Cookie and tracking disclosures.
  • Consent records and withdrawal flows where consent is used.
  • Global Privacy Control, sale or share opt-out, and sensitive data limitation workflows where applicable.
  • DSAR procedures, response templates, and logs.
  • Product releases that changed data use.

This is where Inth should be part of the core diligence pack. Inth manages banners, preferences, regional rules, script loading, and consent records in code. Its value in diligence is not only that a banner exists. It is that teams can verify which consent experience applied, which scripts were controlled, and which records support the answer.

California’s CCPA materials from the Attorney General describe notice at collection and privacy policy content, including categories of personal information, purposes, collection, use, sharing, selling, and consumer rights. The details depend on whether the law applies to the business and the relevant processing.

3. Risk and design reviews

DPIAs and privacy impact assessments are often misunderstood as paperwork after a feature ships. They are more useful before launch, when the team can still change the design.

Under GDPR and UK GDPR, DPIAs are required before processing that is likely to result in a high risk to individuals. The ICO calls DPIAs an accountability tool and a legal requirement for high-risk processing. The EDPB describes DPIAs as written assessments that identify safeguards and help demonstrate compliance.

Inth can support risk review by making consent-dependent behavior visible in the product. If a release adds a new analytics vendor, changes a marketing pixel, introduces session replay, or changes regional consent rules, the privacy review can refer to Inth configuration and records as evidence. Counsel still decides whether a DPIA or similar assessment is required.

For a startup, a review record should connect the product change to the privacy decision:

type PrivacyReview = {
  feature: string;
  release: string;
  dataFlows: string[];
  riskLevel: "low" | "medium" | "high";
  requiresDpia: boolean;
  requiresCustomerNotice: boolean;
  evidenceSources: string[];
  mitigations: string[];
  approvers: string[];
};

export const reviews: PrivacyReview[] = [
  {
    feature: "workspace-risk-score",
    release: "2026.02",
    dataFlows: ["audit-log-events", "user-profile"],
    riskLevel: "high",
    requiresDpia: true,
    requiresCustomerNotice: true,
    evidenceSources: ["privacy-review-ticket", "inth-consent-configuration"],
    mitigations: [
      "exclude message content from scoring",
      "store score explanation for admin review",
      "add customer setting to disable feature",
    ],
    approvers: ["legal", "security", "product"],
  },
];

This pattern also helps with AI features. Avoid broad claims that US law always requires AI impact assessments. The obligation depends on the jurisdiction, sector, and use case. California has adopted rules for certain covered businesses and certain processing activities involving risk assessments, cybersecurity audits, and automated decision-making technology, with phased compliance details. Counsel should confirm whether those rules apply.

4. Vendor and contract controls

Vendors are a common diligence blocker because they touch data outside your product boundary. Enterprise customers and acquirers want to know which vendors receive personal data, what they do with it, and whether your contracts support the commitments you made to users and customers.

For EU and UK controller-processor relationships, Article 28 GDPR requires a contract or other legal act with processor obligations. EDPB guidance describes required topics such as documented instructions, confidentiality, security, subprocessor controls, assistance with rights, breach support, deletion or return, audits, and information needed to demonstrate compliance.

A practical vendor record should include:

  • Vendor name and product.
  • Processing role, such as processor, subprocessor, controller, or service provider.
  • Data categories and purposes.
  • Hosting regions and transfer mechanism notes.
  • Contract status and DPA link.
  • Subprocessor approval status.
  • Security review status.
  • Renewal owner.

Inth helps close the gap between the vendor list and what runs in the app. SDKs, analytics tools, support tools, error monitoring, session replay, email tools, and AI services can enter the product through engineering paths before procurement catches up. When those services depend on consent, Inth gives the team a control point and evidence source for script loading and preference behavior.

5. Security, incidents, and governance

Privacy diligence overlaps with security diligence because confidentiality, integrity, and availability affect personal data risk. Prepare the documents that show how the company manages that risk:

  • Written security program.
  • Access control policy.
  • Encryption and key management summary.
  • Logging and monitoring summary.
  • Incident response plan.
  • Breach notification playbook.
  • Breach or incident register.
  • Security training records.
  • Board or management reporting where required or expected.

Some US rules are sector-specific. The FTC Safeguards Rule, for covered financial institutions, requires a written information security program based on a written risk assessment, service provider oversight, an incident response plan, and written reports to the board or equivalent governing body. Do not generalize that rule to every startup.

Inth can support governance evidence by keeping consent records and configuration history available to the teams that answer security, legal, and customer reviews. That matters when the question is whether tracking controls were implemented, whether a change was reviewed, or whether a customer-facing commitment matches product behavior.

How Inth helps developers reduce diligence work later

Developers cannot own the legal conclusions alone. They can make the evidence accurate. Inth helps by turning consent and tracking controls into application infrastructure instead of a separate compliance layer that drifts from the product.

Use Inth as the evidence source for consent-dependent behavior. Manage banners, preferences, regional rules, script loading, and consent records in code. Keep those changes close to pull requests and release notes so a future diligence answer can point to a reviewed product change.

Add privacy metadata where the product already defines data. If your application has event schemas, model definitions, API contracts, or warehouse tables, add fields for purpose, retention, sensitivity, downstream recipients, and evidence source. Make those fields reviewable in code review.

Tie releases to privacy review tickets. If a feature introduces a new category of personal data, a new recipient, a new purpose, a new script, a new consent category, or a new automated decision, link the pull request to the review record. The goal is traceability from product change to governance decision.

Keep runtime inventories honest. Consent tools, tag managers, analytics SDKs, marketing pixels, session replay, error monitoring, and AI services can drift from the written inventory. Inth reduces that drift for consent-dependent scripts by giving developers a controlled place to manage when those scripts run and what records support the decision.

Build export paths for common evidence. For example, generate a vendor list, data-flow summary, and retention table from maintained metadata rather than rebuilding them from Slack threads during diligence.

type DiligenceExportRow = {
  system: string;
  dataCategories: string;
  purposes: string;
  recipients: string;
  retention: string;
  regions: string;
  evidenceSource: string;
};

export function buildDiligenceExport(flows: DataFlow[]): DiligenceExportRow[] {
  return flows.map((flow) => ({
    system: flow.system,
    dataCategories: flow.categories.join(", "),
    purposes: flow.purposes.join(", "),
    recipients: flow.recipients.join(", "),
    retention: flow.retention,
    regions: flow.regions.join(", "),
    evidenceSource: flow.evidenceSource,
  }));
}

This export still needs legal and security review before it goes into a diligence room. It reduces the chance that teams answer from memory.

Where Inth fits, and where it does not

Inth helps prepare evidence for the privacy controls that live closest to the product: consent, preferences, regional rules, script loading, and consent records. Those controls touch M&A, fundraising, and enterprise diligence because they affect how the company explains tracking, analytics, marketing, and user choice.

Inth should sit alongside other governance records:

  • Counsel owns legal applicability, lawful basis, DPIA conclusions, contract language, and disclosure strategy.
  • Security owns security controls, incident response, access management, and audit evidence.
  • Product and engineering own data-flow accuracy, release traceability, and runtime behavior.
  • Inth supports the consent and script-control evidence those teams need to answer diligence questions.

That division of work is useful in a deal process. It lets a startup say what Inth proves, what other systems prove, and what legal review has confirmed.

What to review with counsel before a process starts

Some topics should not wait until a buyer, investor, or customer asks about them:

  • Whether GDPR, UK GDPR, CCPA/CPRA, sector laws, or state privacy laws apply.
  • Whether the company needs a ROPA or equivalent processing record.
  • Whether high-risk processing requires a DPIA or similar assessment.
  • Whether consent, legitimate interests, contract, or another lawful basis supports each purpose.
  • Whether the company can use customer data for analytics, AI features, model training, benchmarking, or product improvement.
  • Whether subprocessors, transfers, and customer DPAs match product reality.
  • Whether privacy notices match actual collection, sharing, selling, tracking, and retention practices.
  • Whether any past incidents, complaints, or user-rights failures need disclosure in diligence.

These questions can change deal terms. They can also change product design. Inth gives the review a clearer product record for consent and tracking behavior, but counsel still needs to validate the legal conclusions.

Source links

  • Inth, developer-first cookie consent
  • Regulation (EU) 2016/679, GDPR
  • European Data Protection Board, be compliant
  • European Data Protection Board, data controller or data processor
  • ICO, guide to accountability and governance
  • ICO, records of processing and lawful basis
  • FTC, Safeguards Rule: what your business needs to know
  • 16 CFR Part 314, Standards for Safeguarding Customer Information
  • California Attorney General, California Consumer Privacy Act
  • California Privacy Protection Agency, CCPA updates, cybersecurity audits, risk assessments, ADMT, and insurance regulations
  • NIST Privacy Framework
  • FTC, avoiding antitrust pitfalls during pre-merger negotiations and due diligence

What you can do next

You can now:

  • Map the privacy questions that appear during M&A, fundraising, and enterprise sales.
  • Build a diligence folder around data inventory, rights, risk reviews, vendors, and incidents.
  • Use Inth to support consent, tracking, regional rules, script loading, and consent-record evidence.
  • Add product metadata that makes privacy evidence easier to export.
  • Identify legal-review topics before a deal process starts.

Next, assign an owner for each evidence folder and compare the written record against the product. Start with the systems that collect data directly from users or send data to third-party vendors. Then use Inth to bring consent-dependent scripts and records under developer-owned control before the first diligence request arrives.

Newer article · 01How to add LinkedIn Insight Tag to Next.js with c15tAdd LinkedIn Insight Tag to a Next.js App Router project with c15t so the tag loads only after marketing consent, then track custom conversions safely.Guides/6 min readOlder article · 03How to add Google Tag Manager to Next.js with c15tAdd Google Tag Manager to a Next.js App Router project with c15t, then use Consent Mode v2 so GTM-managed tags wait for the right consent state.Guides/8 min read

Related

Review your privacy governance evidence with Inth

Notes from building privacy into the product

Notes from building Inth. Sent occasionally.

Inth connects what your company promised to what engineers just shipped.

Platform

  • Code audit
  • Website audit
  • Inth Agent
  • Consent banner
  • Pricing

Use Cases

  • Privacy Impact Review
  • AI Feature Reviews

Company

  • About
  • Blog
  • Open source
  • Contact

Resources

  • Documentation
  • GitHub
  • Cookiebench
  • Status

© 2026 Inth. All rights reserved.

  • Contact us
  • Privacy
  • Cookies
  • Terms