Skip to content
Insights
Seller guide · 4 min read

What an M&A non-disclosure agreement should cover

The agreement protects the information and sets the rules of engagement. The second job is the one sellers underweight, and it matters more than the standard confidentiality wording.

What the agreement is protecting

Before any confidential material leaves the building, a prospective buyer signs a non-disclosure agreement. In an M&A process it does two jobs: it protects the information, and it sets the rules of engagement for everything that follows.

The second job is the one sellers underweight. A well-drafted agreement determines who inside the buyer can see what, whether they can approach your staff, and whether the mere fact that you are exploring a sale can be disclosed. Those provisions matter more in practice than the general confidentiality wording, which is broadly standard.

The provisions that do the work

The definition of confidential information should cover written and oral disclosure, everything derived from it, and the existence of the process itself. That last point is easy to omit and expensive to omit, because in a live process the fact that an asset is for sale is itself market-moving information.

Permitted disclosure needs care. The buyer legitimately needs to share material with advisers, lenders and an internal deal team. The agreement should allow that while requiring each recipient to be bound equivalently, and should restrict the buyer's team to named individuals with a need to know. A list of names is far more effective than a general obligation, because it creates a record.

Non-solicitation of employees is the provision that matters most in technology transactions, where the team is a large part of what is being sold. Twelve to twenty four months is the usual range. Without it, a bidder who withdraws has just been given an annotated list of your best engineers.

Return or destruction of materials at the end of the process, with a certification requirement. Retention of one archival copy for compliance is normal and reasonable.

Term and survival. Two to three years is typical for general confidential information. Trade secrets should be protected for as long as they remain secret, which means indefinitely.

Standstill provisions

In a public company context, or where the buyer could accumulate a stake, a standstill prevents the counterparty from buying shares, soliciting proxies or making an unsolicited approach for a defined period.

In private transactions the equivalent concern is different but real. A bidder who has seen your data room and then approaches your largest customer, or your chairman directly, is doing something the general confidentiality wording does not clearly prohibit. Address it explicitly.

Where sellers go wrong

Using a generic template. A commercial confidentiality agreement does not contain non-solicitation, named-team restrictions or standstill language, and a process run on one is a process with no control over information flow.

Accepting a buyer's paper without reading the changes. Inbound approaches often arrive with an agreement drafted by the buyer, and three things are worth checking every time: exclusivity or standstill language buried in the confidentiality terms, non-solicit provisions that run only one way, and information rights that let the counterparty keep and use what they learn indefinitely if no transaction happens.

Inconsistent terms across bidders. In a competitive process, a bidder who negotiated weaker obligations has an advantage over the ones who did not. Use one form and resist deviation.

Treating signature as the control. It is not. The control is what you disclose, to whom, and when.

Competitors and clean teams

Where a bidder is a direct competitor, the agreement alone is insufficient. Stage the disclosure: no customer names, no unit pricing and no product roadmap in the first round.

For the most sensitive material, a clean team arrangement puts the information in the hands of the buyer's outside advisers only, who report conclusions rather than underlying data to their client. It is more common in regulated and antitrust-sensitive deals but it works anywhere the counterparty is a rival.

The working assumption should be that a competitor retains what they learn regardless of what the document says. Not because they intend to breach it, but because information cannot be un-learned by the people who read it, and proving that a later decision was informed by it is close to impossible.

What enforcement actually looks like

These agreements are enforceable, and breaches are hard to prove and harder to quantify. By the time you can demonstrate that a counterparty used your customer list, the commercial damage is done and the remedy is a claim rather than a restoration.

That reality should shape behaviour rather than the drafting. The agreement is a deterrent and a framework. The protection is a disciplined process: a small named group on the other side, staged disclosure, a data room with per-user permissions and an audit trail, and no material released before there is a reason to release it.

A seller who relies on the document alone has protection on paper. A seller who controls the flow has protection in fact.

Editorial Team · Published for orientation, not as advice on a specific transaction. Any figure cited is orientation, not a valuation. See market notes.

Considering a transaction

Talk to an advisor, not a form.

Confidential, success-based, no retainer.