Breaches of Non-Disclosure Agreements (NDAs) in Corporate Acquisitions (M&A) and Recovery of Contractual Penalties
In corporate acquisitions, a non-disclosure agreement is one of the principal safeguards that defines the limits of the flow of information between buyer and seller. When financial statements, customer lists, pricing models, employee data, and growth plans are disclosed to a buyer, negotiations may not yet have resulted in a binding acquisition agreement. At this stage, a breach of an M&A non-disclosure agreement may undermine not only bargaining power, but also company value and transaction security.
The abbreviation NDA, derived from the English term ‘non-disclosure agreement’, is widely used in practice. In the event of a breach, the speed of the initial response is as important as the contractual wording in stopping the flow of information, preserving evidence, and, where necessary, recovering the contractual penalty.
Why Is an NDA More Than a Standard Confidentiality Document in an M&A Process?
In a corporate acquisition, the parties do not possess the same information or face the same risks. The seller must disclose detailed data to demonstrate the company’s commercial value. The buyer, meanwhile, will wish to review that data with its directors, financiers, lawyers, and other advisers in order to assess the transaction’s economic and legal risks.
Accordingly, a well-drafted NDA does more than state that ‘information shall be kept confidential’. It regulates, in operational terms, the purpose for which the information may be used, the persons to whom it may be disclosed, the actions permitted in the data room, and the manner in which documents must be returned or destroyed when negotiations end.
The risk is particularly acute in potential transactions between competitors. If the transaction is not completed, information obtained about prices, customers, or strategic plans may influence competitive conduct. Establishing an independent, restricted-access review team (clean team) reduces this risk by ensuring that sensitive data are disclosed only to designated individuals.
What Should an Effective NDA Expressly Regulate?
When a dispute arises, the first question is often, ‘Does the information disclosed fall within the agreement’s definition of confidential information?’ An overly broad definition may give rise to disputes about enforceability, whereas an unduly narrow definition may leave critical information unprotected. The definition should be tailored to the structure of the transaction and the actual information held in the data room.
Scope and Exclusions of Confidential Information
In addition to written documents, the scope may include oral presentations, information obtained during site visits, data-room notes, analyses, and work product derived from confidential data. Clear exclusions should, however, be defined for information that is publicly available, was already known lawfully to the buyer, was obtained from a third party without a duty of confidentiality, or was developed independently.
The agreement should also specify the notification procedure to be followed if disclosure is required by law, a court order, or a request from a competent authority. If prior notice is not legally permissible, the agreement may require the disclosure to be limited to the mandatory extent and appropriate records to be maintained.
Permitted Purpose and Authorized Recipients
The ‘permitted purpose’ should make clear that the information may be used solely to evaluate the specified M&A transaction. The use of confidential data for another acquisition strategy, customer solicitation, staff recruitment, or commercial negotiations may be prohibited separately.
The categories of directors, employees, affiliates, financing providers, and advisers who may receive the information should be identified. The agreement should leave no uncertainty as to their confidentiality obligations or who will be responsible for their breaches. Article 116 of the Turkish Code of Obligations, concerning liability for persons engaged in performance, may also be relevant depending on the circumstances.
Data Room, Duration, and Post-Transaction Obligations
Permissions to download, print, take screenshots, and export data from a virtual data room may be restricted by role. Rules governing the retention period for access logs, the use of watermarks, and the prohibition on sharing user accounts should also be aligned across the NDA and the data-room protocol.
Closing access when negotiations end may not be sufficient on its own. The agreement should address the return or destruction of downloaded copies, advisers’ working files, and backups, together with written confirmation of that process. In determining the duration of confidentiality obligations, a distinction may be drawn between routine transaction documents and trade secrets that retain their value over a long period.
What Conduct May Constitute an NDA Breach?
A breach is not limited to the public disclosure of a document. Depending on the wording of the agreement and the circumstances, the following conduct may also constitute a breach:
- Failure to destroy copies after the transaction has ended
- Disclosing the negotiations or offer price despite a prohibition on public statements
- An adviser sending a document to a personal email account or saving it on an unsecured device
- Sharing a confidential presentation with an employee or affiliate who is not an authorized recipient
- Using a customer list downloaded from the data room for purposes other than evaluating the transaction
- Allowing a competing bidder to access sensitive pricing, capacity, or customer data outside the clean team
Not every suspicious use automatically constitutes a breach. Whether the information falls within the agreement, the applicable exclusions, the authority to disclose, the permitted purpose, and the mandatory-disclosure provisions must be considered together. This distinction is fundamental to the legal review that should precede a claim for a contractual penalty.
The Legal Consequences of an NDA Breach May Arise on Several Levels
An NDA breach will often constitute a breach of contract. Under Article 112 of the Turkish Code of Obligations, loss arising from failure to perform an obligation properly may be claimed unless the debtor proves that it is not responsible. Article 113 is relevant to remedying a breach of an obligation not to act; Article 115 should also be considered in relation to agreements that exclude liability for gross fault in advance.
A contractual claim is not the only option. The unlawful disclosure of information constituting a trade secret may, where the conditions are met, amount to unfair competition under Article 55 of the Turkish Commercial Code. Article 56 of the same Code provides for remedies including declaratory relief, an injunction, removal of the unlawful circumstances, and damages. Where urgent protection is required, an interim injunction may be sought under Article 61 and Articles 389–391 of the Code of Civil Procedure.
For unfair-competition claims, Article 60 of the Turkish Commercial Code provides for a limitation period of one year from the date on which the party entitled to sue learns that the claim has arisen and, in any event, three years from the date on which the right arose. The limitation period applicable to a contractual-penalty claim must be determined separately according to its legal nature.
If due diligence files contain customer, employee, or director data relating to natural persons, the Personal Data Protection Law must also be considered. The legal basis for sharing the data, purpose limitation, access security, and any data-breach notification may create obligations independent of the NDA. Whether the parties act as a ‘data controller’ or ‘data processor’ must be determined by reference to the actual flow of data.
The disclosure of trade, banking, or customer secrets may also give rise to criminal liability where the elements of Article 239 of the Turkish Penal Code are satisfied. Not every NDA breach, however, automatically constitutes a criminal offence. The criminal-law assessment must separately consider the nature of the information, how it was obtained, the act of disclosing or providing it, and the perpetrator’s intent.
What Conditions Govern the Recovery of a Contractual Penalty?
The mechanism commonly referred to as a ‘penalty clause’ is regulated in the Turkish Code of Obligations as a ‘contractual penalty’. Its purpose is to strengthen performance of the obligation by allowing the creditor, in the event of a breach, to claim a predetermined amount without having to calculate its loss.
The scope of the NDA is determined within the freedom of contract provided by Article 26 of the Code, subject to the limits on absolute nullity under Article 27.
Article 179 of the Turkish Code of Obligations regulates the relationship between the contractual penalty and performance of the principal obligation. The clause should therefore do more than specify an amount: it should explain whether the penalty may be claimed in lieu of performance or in addition to performance, and which breach triggers the claim. Will each disclosure of confidential information to an unauthorized person constitute a separate breach, or will the same series of events be treated as a single breach? If a daily penalty applies, how will its start and end points be determined? The agreement should answer these questions.
Under Article 180 of the Code, the creditor may require payment of the agreed penalty even if it has suffered no loss. This is a significant advantage for a party that cannot yet quantify the financial effect of a data leak. If the actual loss exceeds the amount of the penalty, the excess may be claimed separately; for that portion, however, the loss and the debtor’s fault must be proved.
The penalty amount may be agreed freely, subject to the validity of the principal obligation and penalty clause, the scope of the breach, and review under Article 182 of the Turkish Code of Obligations. Article 22 of the Turkish Commercial Code generally prevents a merchant debtor from seeking a reduction merely because the agreed penalty is excessive. This does not make every penalty clause unquestionably valid; mandatory law, contractual validity, and the circumstances must still be examined.
If the M&A parties are merchants, the prudent-businessperson standard under Article 18(2) of the Turkish Commercial Code also applies to foreseeable risks at the time of contracting. The contractual penalty should therefore be negotiated in light of the transaction value and the parties’ status.
Points That Should Not Be Left Unclear in a Contractual Penalty Clause
- The amount, currency, and exchange-rate conversion date
- Whether an aggregate cap applies to a single series of events
- The governing law and the venue for court proceedings or arbitration
- The method of notification, addresses, and arrangements for electronic service
- When the penalty becomes due and payable and whether formal notice is required
- The relationship between the contractual penalty and claims for damages or excess loss
- The definition of the breach that triggers the penalty and the criteria for application per breach
- Whether the obligations to continue performance, stop the leak, and destroy materials will survive
A vague or disproportionate provision may make recovery more difficult. Linking the amount to the transaction value, the importance of the information, and likely breach scenarios produces a more predictable outcome.
What Should Be Done Within the First 24–48 Hours of Discovering a Breach?
Acting quickly may prevent the leak from spreading and digital evidence from being lost. The initial response plan may follow this sequence:
- Stop access: Suspend the relevant data-room account and disable downloading and sharing, but do not delete the logs.
- Preserve the evidence: Preserve data-room logs, emails, messages, device records, watermarked copies, and permissions lists in an unalterable form.
- Map the breach to the agreement: Link the leaked information to the provisions on definitions, exclusions, permitted purpose, and representative liability.
- Plan the notification and formal notice: Following the contractual procedure, send a notice requiring the breach to cease, copies to be returned or destroyed, and evidence to be preserved. Where necessary, expressly reserve all rights and the penalty claim.
- Assess the need for interim relief: If publication, customer contact, or transfer to a competitor is imminent, prepare documents establishing a prima facie case for an interim injunction.
- Review ancillary obligations: Separately assess whether there is a personal-data breach, competition law issue, or regulatory notification.
- Centralize communications: Prevent inconsistent statements by employees, advisers, and directors; keep media and counterparty communications recorded and consistent.
At this stage, unlawful methods such as gaining unauthorized access to the counterparty’s device or account must not be used. The manner in which evidence is obtained may be as important as its content in subsequent litigation or arbitration.
How Should Recovery of a Contractual Penalty Be Pursued?
The recovery process generally begins with a review of the valid NDA and the enforceable penalty clause. It is then necessary to determine which provision the breach triggered, whether the conduct can be attributed to the debtor or a person for whom responsibility was assumed, whether the penalty is due and payable, and whether the notification requirements have been satisfied. The due date and formal notice should be considered together with Article 117 on default.
The evidence file should contain not only the leaked document, but also records showing who viewed it and when. Data-room access logs, watermarks, email metadata, user permissions, meeting minutes, confidentiality markings, and return or destruction confirmations should be considered together. The integrity of digital evidence must be preserved; where necessary, expert examination or court-ordered preservation of evidence should be considered.
Depending on the dispute-resolution mechanism in the agreement, the claim may be pursued through litigation or arbitration; where the conditions are met, enforcement proceedings for a monetary claim may also be available. Although loss need not be proved separately for a contractual penalty, the breach, the triggering event, and the accrual of the right to claim must still be established. If excess loss, damages for unfair competition, or another remedy is sought, the legal basis and evidential requirements for each must be established separately.
A contractual penalty does not, on its own, stop the leak. An injunction and interim relief to prevent dissemination of the information, damages to compensate for the loss suffered, and orders for return, destruction, or restriction of access to remedy the unlawful consequences should be considered together.
Common Contractual and Response Mistakes
A generic NDA template may give the parties a false sense of security. Common problems include an imprecise definition of confidential information, a failure to establish advisers’ liability clearly, and no provision stating how many times the penalty will apply to a particular event.
Sending only a formal notice after the breach may also be insufficient. A delayed notice issued while access remains open or evidence is being deleted may increase the loss. The NDA should be designed in conjunction with the data room, the transaction timetable, and the actual working model; the technical and legal teams should know their response responsibilities in advance.
Legal Protection with Esenyel Partners
Uncontrolled information sharing in an M&A process may result in customer loss, a reduction in transaction value, regulatory scrutiny, and protracted disputes. An uncertain NDA or a contractual-penalty clause that is difficult to prove may narrow the company’s options even further after a breach emerges.
Esenyel Partners manages the process comprehensively, from preparing confidentiality agreements for corporate acquisitions and structuring data-room and clean-team rules to investigating breaches, preserving evidence, seeking interim injunctions, and recovering contractual penalties.
Contact us to share confidential information securely in your M&A transaction or to respond promptly and proportionately to an existing NDA breach.
Contact
| Selçuk Esenyel Founding and Managing Partner Tel: +90 212 397 19 91 Mobile: +90 506 792 76 90 | Semih Sander Partner semih.sander@esenyelpartners.com Tel: +90 212 397 19 91 Mobile: +90 532 590 92 32 |
| Hande Ertuğrul Counsel hande.uygun@esenyelpartners.com Tel: +90 212 397 19 91 Mobile: +90 539 896 46 82 | |