Data Not Dating: Trump Administration Reversal of Merger Signals National Security Implications of Data

Poyner Spruill LLP

Poyner Spruill LLP

Amidst the thicket of federal regulators that populate Washington is the obscure Committee on Foreign Investment in the United States (CFIUS). Founded on the eve of World War II, CFIUS is an inter-agency task force. Its mandate is to evaluate mergers between American and foreign firms that may have national security implications.

The typical CFIUS intervention involves defense contractors or vendors. For example, it barred a Chinese investor from acquiring American chipmaker Lattice Semiconductor. In the same vein, it blocked a merger between Singapore’s Broadcom and American Qualcomm.

CFIUS does not, however, typically concern itself with citizens’ dating lives. But in April 2019, it made an exception. Media reported that the Chinese owners of gay dating app Grindr were seeking buyers under CFIUS pressure. CFIUS was apparently concerned by the sensitive personal data Grindr has on millions of American citizens.

Grindr holds considerable sensitive personal information on its users. That information includes their identities, locations, and some health information such as HIV status. The implicit concern was that Grindr’s owners could use the data to blackmail American citizens. Americans with security clearances would be particularly vulnerable.

The incident marks the first time CFIUS has reversed an acquisition premised solely on the data held by the acquired entity. Indeed, CFIUS rarely reverses a consummated transaction.

The episode is thus noteworthy for three reasons. First, it is the first time that personal data protection has been found to be a national security issue. Washington has sent a strong signal that it is expanding the traditionally narrow view of national security concerns to personal data.

Second, this expansion suggests that foreign companies operating businesses with access to sensitive personal data can expect scrutiny. For example, CFIUS ultimately approved a deal between Genworth and China Oceanwide Holdings—but only after the companies appended significant mitigation measures to alleviate privacy concerns.

Finally, the episode demonstrates yet another consideration that companies must factor into data collection practices. Even companies in traditionally benign areas, such as dating services, must be cautious with data collection. Excessive access to sensitive data can engender unforeseen consequences, such as a fire sale divestment prompted by a visit from the Men In Black.

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations.

© Poyner Spruill LLP | Attorney Advertising

Written by:

Poyner Spruill LLP

Poyner Spruill LLP on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide

This website uses cookies to improve user experience, track anonymous site usage, store authorization tokens and permit sharing on social media networks. By continuing to browse this website you accept the use of cookies. Click here to read more about how we use cookies.