CGPH Banque d’affaires
Inside M&A: The Legal Architecture of a Deal · Part 01

The NDA: Where the Deal Really Begins

Andrea Battista LL.M.8 min readEdition of 2026-09-22

What this chapter covers

What an M&A confidentiality agreement actually protects, who is allowed access to what, how particularly sensitive information is handled, and where standstill undertakings fit.

Key takeaways

  • Confidentiality in M&A protects a commercial position, not only a set of documents.
  • Access rules — who may see what, and when — matter as much as the confidentiality promise itself.
  • Particularly sensitive information can be staged, restricted or handled through a limited group.
  • Standstill and non-solicitation undertakings extend the agreement well beyond secrecy.
  • The NDA is the first allocation of risk in the transaction.

When people think about the contracts that define an M&A transaction, attention usually goes straight to the Share Purchase Agreement.

That is understandable. The SPA ultimately determines what is being acquired, at what price, subject to which conditions and with what allocation of risk between buyer and seller.

But the legal architecture of an M&A deal normally begins much earlier.

Before valuation is agreed, before due diligence starts and often before the potential buyer has received any meaningful information about the target, the parties will typically enter into a Non-Disclosure Agreement, or NDA.

At first sight, its function appears simple: the seller provides confidential information and the prospective buyer agrees to protect it.

In practice, an M&A NDA can do considerably more. It establishes the framework within which information can move between the parties and can influence how the entire due diligence process is organised.

In other words, the NDA is not merely a confidentiality form. It is often the first agreement that determines how the deal itself will be run.

Why confidentiality matters differently in M&A

An acquisition process creates a particular problem.

To decide whether to acquire a business, a potential buyer needs access to information that the seller would ordinarily never disclose outside the company.

This may include financial forecasts, margins, customer concentration, commercial contracts, pricing policies, employee information, intellectual property, disputes, financing arrangements and strategic plans.

Yet at that stage there is no certainty that the transaction will ever complete.

The buyer may withdraw. The seller may select another bidder. Due diligence may identify an issue. Financing may not become available. The parties may simply fail to agree on valuation.

The result is a fundamental asymmetry:

information is transferred before ownership is transferred.

The NDA is designed to manage that risk.

Importantly, confidentiality in an M&A context is not only about preventing disclosure to third parties. It is also about preventing the information from being used for purposes unrelated to the contemplated transaction.

A potential buyer might never publicly disclose confidential information and nevertheless derive a commercial advantage from knowing the target’s pricing, customers or business strategy.

For this reason, a properly drafted NDA will usually restrict both disclosure and use, allowing the information to be used only for evaluating, negotiating and potentially completing the transaction.

What does an M&A NDA actually protect?

The starting point is the definition of Confidential Information.

The seller will generally want this definition to be broad enough to cover information disclosed in writing, orally, through management presentations or through a virtual data room.

It may also extend to analyses, reports and internal documents prepared by the buyer on the basis of the information received.

In some transactions, even the existence of the proposed deal can itself be confidential.

A premature disclosure that a company is considering a sale may affect employees, customers, suppliers, lenders or other stakeholders. The NDA may therefore restrict disclosure of the negotiations themselves, as well as the identity of the parties involved.

At the same time, the definition cannot sensibly capture everything.

Customary exclusions normally apply to information that is already public, was lawfully known to the recipient before disclosure, is independently developed or is legitimately obtained from another source.

The purpose is not to create an unlimited restriction. It is to protect information that genuinely derives from the transaction process.

Who gets access?

The potential buyer rarely evaluates the deal alone.

An acquisition may require input from directors, employees, lawyers, accountants, tax advisers, consultants, banks, debt providers, insurers and other specialists.

The NDA therefore normally permits disclosure to a defined class of Representatives, often where they have a genuine need to know the information for purposes of the transaction.

This creates an important legal question: who bears responsibility if one of those representatives breaches confidentiality?

But there is also a practical issue.

If the NDA is drafted too narrowly, the buyer may struggle to involve the people required to perform due diligence or arrange financing.

If it is drafted too broadly, sensitive information may circulate unnecessarily.

The right balance depends on how the transaction is actually expected to proceed.

This is one of the first points at which legal drafting and transaction advisory overlap: the document should protect the seller without creating a framework that makes the deal operationally difficult to execute.

Beyond confidentiality: access, employees and counterparties

An M&A NDA may also regulate conduct that goes beyond the simple treatment of documents.

During due diligence, a buyer can acquire detailed knowledge about key employees, customers, suppliers and commercial relationships.

The seller may therefore seek restrictions on soliciting employees or contacting customers and suppliers without prior consent.

The rationale is straightforward.

An uncontrolled approach to an important customer may reveal the existence of the deal. Contacting senior employees too early may create uncertainty within the business. Direct discussions with suppliers may undermine the seller’s control over the process.

These restrictions therefore serve both a legal and a transaction-management purpose.

The NDA establishes the legal boundary. The deal team decides how access should actually be managed within that boundary.

When particularly sensitive information requires more protection

Not all information presents the same level of risk.

This becomes especially relevant where the prospective buyer is also a competitor of the target.

To value the company properly, the buyer may legitimately want access to customer-level profitability, pricing, margins, product pipelines or other commercially sensitive information.

But providing that information directly to the buyer’s commercial management may itself create competition-law and business risks.

One possible solution is a clean team.

Particularly sensitive information can be restricted to external advisers or specifically designated individuals who review the underlying data and provide the wider transaction team with aggregated or appropriately filtered conclusions.

This allows the seller to provide deeper access without unnecessarily exposing the business.

From an advisory perspective, this is a useful example of a broader principle: good deal structuring is rarely about eliminating risk completely. It is about creating a framework in which the risk becomes manageable enough for the transaction to continue.

What about standstill provisions?

Standstill provisions are often associated with M&A NDAs, particularly in public-company transactions, although they are not a universal feature of private deals.

In broad terms, a standstill prevents a prospective acquirer from taking steps to acquire or increase control over the target without its consent. Its purpose is to allow the target to share sensitive information during the transaction process without giving the bidder an opportunity to use that access to pursue an unsolicited acquisition.

Depending on the deal, a standstill may restrict the bidder from acquiring shares in the target, launching an unsolicited takeover offer, seeking to influence the composition of the board, supporting a proxy contest or proposing an uninvited merger or other change-of-control transaction.

From the target’s perspective, the provision helps preserve control over the sale process. From the bidder’s perspective, however, it can become restrictive if circumstances subsequently change.

For that reason, standstills may include a fall-away provision, under which the restrictions cease to apply if a specified event occurs — for example, if a third party launches or publicly announces a competing takeover proposal. This allows the original bidder to re-enter the process rather than remaining contractually sidelined while another buyer pursues the target.

The scope, duration and exceptions of a standstill therefore need to reflect the ownership structure of the target, whether its securities are publicly traded, the identity of the bidder and the competitive dynamics of the transaction. As with the NDA more generally, the provision should be tailored to the deal rather than simply imported from a precedent.

The advisory perspective: protect the company without obstructing the deal

The strongest possible NDA is not necessarily the best NDA.

An agreement that is too permissive may expose the seller. An agreement that is excessively restrictive may prevent a serious buyer from completing proper due diligence and ultimately reduce its willingness to proceed or the price it is prepared to offer.

The legal document therefore needs to work together with the transaction process.

In practice, advisers may need to decide not only what the NDA says, but also:

- when access to the virtual data room should begin;

- which members of the buyer’s team should have access;

- whether certain information should only be released at a later stage;

- whether clean-team arrangements are appropriate;

- when management meetings should take place;

- whether customers or suppliers may be contacted; and

- whether particularly sensitive information should only be disclosed once the bidder has demonstrated sufficient commitment to the deal.

These are not all contractual provisions.

But they determine how the contractual protection provided by the NDA works in practice.

A well-run process often uses staged disclosure: enough information is provided for the buyer to progress its analysis, while the most commercially sensitive materials are released only as the transaction becomes more credible.

This can protect the seller without preventing a genuine bidder from reaching an informed investment decision.

What happens if the transaction fails?

Many potential M&A transactions never reach closing.

The NDA must therefore contemplate from the beginning what happens if discussions end.

It will normally address the return or destruction of confidential materials, often subject to practical exceptions for regulatory requirements, professional record-keeping and automatic IT backups.

This matters because information may no longer exist only in the data room.

It may have been downloaded, circulated internally, included in advisers’ reports or incorporated into valuation and diligence work.

The larger the transaction team, the more important it becomes to ensure that post-termination obligations are realistic and capable of being implemented.

The first allocation of risk in the deal

The SPA will eventually allocate many of the transaction’s most important risks: price risk, warranty risk, closing risk and post-closing liability.

The NDA deals with a different issue at a much earlier stage.

It asks:

how much access should one party receive to another company’s business before either side has committed to the transaction?

Answering that question requires more than confidentiality boilerplate.

It requires legal protection, an understanding of how the due diligence process will operate and sufficient commercial judgment to avoid protecting the information so aggressively that the transaction itself becomes unworkable.

That is why the NDA should not be treated as the administrative document signed before the "real" M&A work begins.

By defining what can be disclosed, who can receive it, how it can be used and how the parties interact during the process, the NDA sets the first boundaries of the deal.

And in that sense, it is where the M&A transaction really begins.