21.8.2019

M&A: As Buyer Liabilities Increase, Due Diligence Must Cover New Ground

Data breaches, cartels, money laundering, bribery… In today’s world, there are a number of risks that may go unseen in a traditional due diligence review. This has led to the rise of compliance due diligence, which seeks to address these issues as part of the M&A process. In Germany, law firm Hengeler & Mueller and the Goethe-Universität of Frankfurt recently carried out a survey about compliance due diligence among German investors and corporate executives responsible for M&A. According to the results, 95% of them find that buyers are increasingly aware of compliance risks. Three quarters found that compliance due diligence was a relevant part of the M&A process, and 85% thought that it had become increasingly important in recent years.  The factors that favour carrying out compliance due diligence included previous violations by the target company, business in high-risk countries or a high number of clients in the public sector.

Liability May Arise on Grounds of Stakes Already Sold

The foreword of the survey report cites a case that illustrates the importance of compliance for buyers. The buyer in this case was a large international investment bank that had been a shareholder and the indirect parent company of a cable manufacturer, which was subsequently found to have participated in a cartel. The European Commission fined the cable manufacturer 100 million euros. Roughly a third of the total was jointly and severally payable by the company and the investment bank as its former owner. According to the Commission, the investment bank had exercised decisive influence in the cable company and could therefore be considered liable for the cartel, even though there was no evidence that the bank’s representatives had been aware of the cartel plans or had participated in the cartel’s implementation. This position was confirmed by the Court of Justice of the European Union.

Buyers Cannot Afford to Neglect Data Protection

This July, the British Information Commissioner’s Office issued a notice of its intention to impose a fine of 110 million euros on a major accommodation group for breaches of data protection law. The group had suffered a cyber attack that could be traced back to a corporate acquisition made in 2016: the target company’s information systems had become vulnerable well before the merger. The ICO found that the buyer had not carried out sufficient due diligence upon the acquisition. In a statement, Information Officer Elizabeth Denham said:

‘The GDPR makes it clear that organisations must be accountable for the personal data they hold. This can include carrying out proper due diligence when making a corporate acquisition,  and putting in place proper accountability measures to assess not only what personal data has been acquired, but also how it is protected.’

‘Personal data has a real value so organisations have a legal duty to ensure its security, just like they would do with any other asset.  If that doesn’t happen, we will not hesitate to take strong action when necessary to protect the rights of the public.’

The ICO’s decision is not final, but it sends a strong message to companies considering an acquisition. Buyers must carefully inspect how the target has addressed data protection. It is possible that they will no longer be able to fulfil their duty of care with a customary desktop analysis completed with management interviews. Instead, European data protection authorities may require a thorough assessment of the technical security and adequacy of the target’s data systems. The General Data Protection Regulation has been enforceable for a bit over a year now, and authorities have taken the initiative and imposed fines for non-compliant processing of personal data in several dozens of cases.

Look Deep

Neglected compliance risks can be costly for buyers in M&A. Violations may undermine the profitability of a deal and permanently damage the buyer’s reputation. Moreover, authorities are eager to intervene in suspected breaches.

Properly addressing compliance risks in due diligence helps avoid unpleasant surprises. In addition to reviewing documents, we recommend that buyers have a separate compliance session with the compliance officers of the seller or the target. This helps grasp the target’s performance and identify operations that warrant a further review.

Latest references

We advised Topfoods Oy, a Triton-backed Geia Group company, on its acquisition of Oy Delice Plus Ab, a Finnish supplier of cakes and pastries. Through the acquisition, Topfoods strengthens its retail business and further reinforces its position in the cakes and pastries segment. Founded in 2008, Topfoods supplies selected food products to professional kitchens, the retail sector, and the food industry. 
Case published 4.9.2026
We advised HANZA on the divestment of its Nivala and Sievi operations. The transaction was part of HANZA’s larger strategic reorganisation, where the company optimised its Finnish manufacturing cluster. Founded in 2008, HANZA is a Swedish mechanical engineering and electronics contract manufacturing company listed on the Nasdaq Stockholm main list. HANZA has approximately 5,000 employees and annual sales of SEK 10 billion. 
Case published 3.9.2026
We advise Korona Invest and the other shareholders of Innoflame Oy on the sale of Innoflame to Sponsor Capital. The transaction makes Sponsor Capital the new majority owner of Innoflame. Korona Invest has been a shareholder of Innoflame since 2021 and, together with the other selling shareholders, has over the past five years supported the company’s growth, development and several strategically significant corporate transactions, through which Innoflame has strengthened its position as Finland’s leading product media company. The ownership change is intended to support Innoflame’s next phase of growth, including its ambition to build a significant European product media company with the capability to expand rapidly into new markets. The transaction is conditional to the customary closing conditions such as authority approvals. Innoflame is one of Finland’s leading product media specialists, helping its clients build a unified brand experience by offering the design, sourcing and management of product media as a single integrated service. Korona Invest is a Finnish private equity firm founded in 2006, specialising in buyout and growth investments in domestic small and medium-sized enterprises. It makes both majority and minority investments, structuring each project to suit the company’s growth strategy. 
Case published 27.8.2026
We advised Hopeasalmen Telakka Oy, part of Marina Group, on the acquisitions of Iisiveneily and Porvoon Venekorjaamo. The transactions form part of Marina Group’s expansion into the Finnish marina and boatyard sector, strengthening its position under the Quattro Marine brand. Following the acquisitions, Quattro Marine’s Finnish operations comprise Hopeasalmen Telakka, which operates boatyard facilities in Helsinki’s Mustikkamaa and in Tolkkinen, Porvoo, together with Iisiveneily and Porvoon Venekorjaamo. Marina Group is a Norwegian marina and boatyard consortium owned by the private equity sponsor Norvestor. It has grown rapidly through acquisitions to become the Nordic region’s largest boating services provider, having acquired 24 marinas and boatyards across Norway, Sweden and Finland within roughly a year.
Case published 24.8.2026