Sharing Customer Data During M&A Due Diligence: NDAs, Data Rooms and Privacy Safeguards

Due diligence can get a little tricky. A potential buyer needs enough information to understand what they’re buying, but that doesn’t mean they should get free access to everything in your customer database.

Customer contracts, revenue figures and other customer information can all come up during the process, so the question becomes: how much do you actually need to share?

Due diligence can justify sharing certain customer information, but there still need to be limits around what is shared, who can access it and what they can do with it.

That becomes even more important if the buyer is a competitor, or your business handles sensitive or regulated customer information.

Before Sharing Customer Data, Check What You’re Allowed To Disclose

A buyer might want to know who your biggest customers are, how long they have been with the business, what they spend or what their contracts say.

All of that can be relevant to working out what the business is worth. However, before uploading customer information to a data room, it’s worth asking a different question first: are you actually allowed to share it?

There isn’t a single comprehensive federal privacy law that applies to every US business and every type of customer data. Depending on where your customers are located, what kind of information you hold and what industry you operate in, federal laws, state privacy laws and sector-specific rules may all come into play.

Your own legal documents matter too.

For example, take a look at your Privacy Policy. What does it say about how customer information can be used or disclosed, and is the proposed disclosure consistent with those promises? Some Privacy Policies also specifically address transfers connected with a merger, acquisition or sale of the business.

Your customer contracts may contain confidentiality or data-use provisions that limit what can be shared with third parties. If you process information on behalf of another business, the relevant Data Processing Agreement may also place limits on how that information is handled.

The fact that you hold customer information does not necessarily mean you have an unrestricted right to pass it on.

A well-known US example is the FTC's action against Toysmart.com. Toysmart had told customers that their personal information would never be shared with third parties. When the company later ran into financial trouble, it attempted to sell its customer database as an asset.

The FTC challenged the proposed sale under Section 5 of the Federal Trade Commission Act because it was inconsistent with the privacy promises Toysmart had made. The eventual settlement placed strict conditions on any transfer of the customer information, including requiring a qualifying buyer to take on Toysmart's existing privacy commitments.

The point isn’t that customer information can never move with a business. It’s that an M&A transaction doesn’t automatically wipe away the promises and obligations that already apply to that information.

Some state privacy laws also specifically deal with business transfers.

For example, the California Consumer Privacy Act (CCPA) recognizes certain transfers of personal information made as part of a merger, acquisition, bankruptcy or similar transaction where the third party assumes control of all or part of the business. However, the information still needs to be handled consistently with the law, and additional notice requirements can arise if the new owner materially changes how the information is used or shared in a way that is materially inconsistent with earlier promises.

Colorado's privacy law similarly excludes from its definition of a “sale” certain transfers of personal data as an asset in a proposed or actual merger, acquisition or similar transaction where the third party assumes control of all or part of the controller's assets.

These transaction-specific provisions shouldn't be treated as a blanket exemption for every disclosure of customer information made during due diligence. The particular law, the type of information involved and the promises or contracts already in place still need to be considered.

If your business handles particularly sensitive or regulated information, there may be another layer of rules to work through. Depending on the business, this could include HIPAA in certain healthcare contexts, the Gramm-Leach-Bliley Act for covered financial institutions, COPPA for certain children's online data or state consumer health-data laws.

This is an area where a State Privacy Law Readiness Review or tailored legal advice can be useful before due diligence gets underway.

Put An NDA In Place Before You Start Sharing

Once you know what information can be disclosed, the next question is what the buyer is allowed to do with it.

This is where a Non-Disclosure Agreement (NDA) comes in.

An NDA can make it clear that information is being provided for one purpose: assessing the proposed transaction. It can also set boundaries around who can see the information, whether it can be shared with advisers, how it must be protected and what happens to it if the deal never goes ahead.

For example, the agreement might restrict a potential buyer from approaching customers directly without the seller's approval. It may also require confidential documents to be returned or destroyed if negotiations end.

These details matter because an M&A process can involve much more sensitive information than an ordinary commercial conversation. A generic NDA that simply says “keep this confidential” may not properly address how information is actually going to move through the due diligence process.

It’s worth having your Non-Disclosure Agreement prepared or reviewed with the proposed transaction in mind.

There is also an important limit to remember here: an NDA controls what the buyer can do with information once it receives it, but it does not itself make an otherwise prohibited disclosure lawful.

If a customer contract, privacy obligation or applicable law restricts disclosure, signing an NDA with the buyer doesn't override that restriction.

You Don't Need To Put Everything In The Data Room

Once due diligence begins, it can be tempting to think that more information is always better.

Usually, it makes more sense to ask what the buyer actually needs at each stage.

Say a potential buyer wants to know whether the business depends too heavily on a handful of customers. Early in the process, it might be enough to tell them that your ten largest customers account for a certain percentage of annual revenue.

They may not need the names, contact details and complete account history of those customers straight away.

As the deal progresses, more detailed information may become necessary. This is where a controlled virtual data room can help.

Rather than emailing spreadsheets around or giving someone broad access to a shared drive, a data room can put some boundaries around the information being reviewed. Depending on the platform and the transaction, that could include limiting access to particular people, restricting downloads, keeping access records or removing access when it is no longer needed.

Information can also be shared in stages. Some customer details may be aggregated, anonymized or redacted before they are made available, with more detailed information provided later where there is a genuine reason for the buyer to see it.

This can help reduce unnecessary disclosure while still giving the buyer enough information to properly assess the business.

Where customer information is also competitively sensitive - particularly where the potential buyer is a competitor - stronger controls may be appropriate. FTC guidance on pre-merger information sharing recommends measures such as limiting information to what is genuinely needed, masking customer identities and redacting sensitive material where appropriate.

The practical takeaway is fairly simple: a buyer may need enough information to verify the value and risks of the business, but that does not mean opening every customer file on day one.

Be Extra Careful If The Buyer Is A Competitor

Things can become more sensitive if the company looking at your business is also a competitor.

Customer identities, individual pricing, margins, upcoming renewals and future commercial plans could all help a buyer assess the business. But they could also give a competitor information it would never normally have access to.

This means privacy and confidentiality aren't the only issues to consider. Until the deal closes, the buyer and seller remain separate businesses, and exchanging competitively sensitive information can raise antitrust concerns.

Where that information genuinely needs to be reviewed, one option is a clean team. This is a limited group - such as outside advisers or designated personnel - who can review particularly sensitive information without making it available to the buyer's wider commercial team.

The FTC recommends clean teams and other safeguards where competitors need to exchange competitively sensitive information during a proposed transaction. In particular, people responsible for competitive pricing, planning or strategy generally shouldn't be given clean-team access to information they could potentially misuse.

If a potential buyer is also a competitor, it’s worth getting legal advice about the information-sharing process before detailed customer, pricing or strategy information changes hands.

What Happens To Customer Data If The Deal Goes Ahead?

There is an important difference between letting a buyer review customer data during due diligence and actually transferring that data when the business is sold.

During due diligence, the buyer is generally looking at information to decide whether to proceed with the transaction and on what terms.

Once the deal closes, the question becomes what customer information is actually moving to the buyer and what they can do with it.

The purchase agreement or other transaction documents should deal with this properly. Depending on the structure of the deal, that might be a Business Sale Agreement, Asset Purchase Agreement, Stock Purchase Agreement, Membership Interest Purchase Agreement or another acquisition document.

Where customer data is an important business asset, the agreement may need to address what information is being transferred, privacy compliance, representations and warranties about how information has been collected and handled, and any steps the parties need to take before or after closing.

For a business or asset sale, a Business Sale Agreement can also set out which assets and liabilities are being transferred and how responsibility is allocated between the buyer and seller.

The structure of the transaction can make a difference.

In an asset sale, customer lists, databases and customer contracts may be among the specific assets being transferred from one entity to another. In a stock or membership-interest sale, the entity holding the information may stay the same even though ownership of that entity changes.

Customer contracts should be checked as well. An asset transfer may require consent where a contract restricts assignment, while an equity transaction may still trigger a change-of-control clause even though the contracting entity itself remains the same.

These provisions can affect whether an important customer relationship moves cleanly with the transaction, so they shouldn't be left until the closing date.

Existing privacy obligations also continue to matter. California, for example, recognizes certain transfers of personal information as part of M&A transactions, but if the new owner later materially changes how the information is used or shared in a way that is inconsistent with promises made when it was collected, additional notice requirements can apply.

So, customer data shouldn't simply be treated as another folder being handed over at closing. The contracts, privacy commitments and transaction structure all need to line up with what the parties are actually trying to transfer.

What If The Deal Falls Through?

Of course, not every business sale makes it to closing.

By that stage, the potential buyer may have spent weeks or months looking at information they would never normally have access to. That's why what happens after due diligence should be considered before it begins.

Your NDA and due diligence arrangements should address what happens to confidential information if negotiations end. Data-room access can be removed, documents may need to be returned or destroyed and the buyer's confidentiality obligations can continue even though there is no longer a potential deal.

Where competitively sensitive information has been shared, the FTC also recommends clear document-destruction requirements at the end of due diligence and follow-up to make sure those requirements are followed. This can extend to internal analyses created from particularly sensitive information where the parties' confidentiality arrangements require it.

This is particularly important where the unsuccessful buyer is a competitor. A failed acquisition shouldn't become an opportunity for another business to keep using customer, pricing or strategy information it only received because a deal was being considered.

A little preparation before the data room opens can make the due diligence process much easier.

Review your Privacy Policy, customer contracts and any Data Processing Agreements to understand what information can be disclosed and whether any restrictions need to be addressed.

Put an appropriate Non-Disclosure Agreement in place before confidential information changes hands, and check customer contracts for confidentiality, assignment or change-of-control provisions that could affect the transaction.

If particularly sensitive information needs to be shared, additional data-room protocols, clean-team arrangements or other confidentiality protections may also be appropriate.

Then, if the transaction moves ahead, make sure the Business Sale Agreement or other purchase documents properly deal with the customer information being transferred and the parties' respective responsibilities.

Getting these documents reviewed before due diligence starts can be much easier than discovering a privacy or contractual restriction halfway through the process.

Key Takeaways

Due diligence is supposed to give a potential buyer enough information to properly assess the business - not unrestricted access to everything the business knows about its customers.

Before sharing customer information, check your privacy obligations, Privacy Policy, customer contracts and any other restrictions that apply to the data.

Then think about how that information is being shared. An appropriate NDA, staged disclosure and a controlled data room can all help limit unnecessary access.

If the buyer is also a competitor, additional safeguards may be needed before customer-specific, pricing or other competitively sensitive information is disclosed.

If the deal goes ahead, make sure the transaction documents properly address the customer data and contracts being transferred. If it doesn't, the confidentiality and deletion requirements agreed at the start should give the parties a clear way to close the due diligence process.

If you're preparing for a business sale or acquisition, Sprintlaw can help review the contracts, privacy documents and confidentiality arrangements involved so your due diligence process has the right protections in place from the start. You can reach us at (888) 449-8437 or team@sprintlaw.com for a free, no-obligations chat.

Alex Solo
Alex SoloCo-Founder

Alex is Sprintlaw's co-founder and a legal technology leader. He holds law and media degrees from the University of Sydney and has been recognized by Australasian Lawyer, Lawyers Weekly and the Sydney Young Entrepreneur Awards for his work building Sprintlaw and improving access to business legal support.

Need legal help?

Get in touch with our team

Tell us what you need and we'll come back with a fixed-fee quote - no obligation, no surprises.

Need support?

Need help with your business legals?

Speak with Sprintlaw to get practical legal support and fixed-fee options tailored to your business.