Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The policy states that personal information collected from customers may be disclosed to potential buyers or transferred to acquiring entities in connection with mergers, acquisitions, or the sale of Walgreens stores or assets, and that customer information is treated as a transferred business asset in such transactions.
This analysis describes what Walgreens's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes that customer personal information, including all categories described in the policy, may be disclosed during the evaluation phase of a potential transaction and transferred to a new entity following an acquisition, without requiring separate individual consent at the time of transfer.
Under this provision, all categories of personal information Walgreens has collected about a customer, including sensitive personal information and health-related retail purchase data, may be transferred to another entity as a business asset in the event of a merger, acquisition, or asset sale. The policy does not describe a mechanism for consumers to opt out of data transfer in this context.
Cross-platform context
See how other platforms handle Data Transfer in Mergers and Acquisitions and similar clauses.
Compare across platforms →Monitoring
Walgreens has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"As we continue to develop our business, we might sell or buy stores or assets, or engage in mergers, acquisitions or sale of company assets. Personal information may be disclosed in connection with the evaluation of or entry into such transactions or related business arrangements, or in the course of providing transition of services to another entity as permitted by law. In such transactions, customer information generally is one of the transferred business assets. Additionally, in the event that Walgreens or substantially all of its assets are acquired, customer information will likely be one of the transferred assets as is permissible under law.Excerpt from Walgreens's Privacy Policy
1. REGULATORY LANDSCAPE: This provision engages CPRA, which requires that personal information transferred in a business transaction continue to be used in a manner consistent with the privacy policy under which it was collected, and that consumers be notified if the acquiring entity intends to use the data in a materially different manner. The FTC has examined data transfers in business transactions as a potential unfair practice when the acquiring entity's data practices differ materially from those disclosed at collection. HIPAA separately requires that protected health information transferred in a merger be subject to the same privacy protections. 2. GOVERNANCE EXPOSURE: Medium. The provision is standard in commercial privacy policies, but the breadth of data categories at issue, including biometric data, precise geolocation, and health-related retail purchase data classified as Sensitive Personal Information under CPRA, elevates the compliance significance of any transaction in which these categories are transferred. Due diligence in any transaction should include assessment of whether the acquiring entity's privacy practices are compatible with the notice provided to consumers. 3. JURISDICTION FLAGS: California requires that consumers receive notice and, in some circumstances, an opportunity to opt out if the acquiring entity intends to use personal information in a manner materially inconsistent with the original policy. The nineteen additional states listed in the policy may impose analogous notification or compatibility requirements under their respective privacy laws. 4. CONTRACT AND VENDOR IMPLICATIONS: Transaction counsel should assess whether the transfer of biometric data, precise geolocation classified as sensitive, and health-related retail purchase data in a merger or acquisition triggers state-specific consent or notification obligations beyond standard data asset transfer disclosures. Non-disclosure agreements with potential buyers should include data use restrictions consistent with the current privacy policy's stated purposes. 5. COMPLIANCE CONSIDERATIONS: In the event of a planned transaction, compliance teams should assess whether pre-close data sharing with potential buyers during due diligence constitutes a disclosure that requires notice under applicable state privacy laws. Post-close, the acquiring entity should conduct a privacy policy compatibility assessment before using transferred data for new or expanded purposes.
This provision establishes that customer personal information, including all categories described in the policy, may be disclosed during the evaluation phase of a potential transaction and transferred to a new entity following an acquisition, without requiring separate individual consent at the time of transfer.
Under this provision, all categories of personal information Walgreens has collected about a customer, including sensitive personal information and health-related retail purchase data, may be transferred to another entity as a business asset in the event of a merger, acquisition, or asset sale. The policy does not describe a mechanism for consumers to opt out of data transfer in this …
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Walgreens.