The situation
Samir and Tarek had built their business the slow way: two franchise territories became six, six became fourteen, and after twelve years they owned and operated a group of quick-service restaurant locations across eastern Ontario. Growth by opening new units was getting harder — good sites were scarcer and construction costs had climbed — so when a Kingston-based food distribution company came up for sale, they saw a different kind of expansion. The business supplied packaged goods and refrigerated inventory to restaurants across the region, including several of their own locations. Owning it would mean controlling a piece of their own supply chain and picking up dozens of other restaurant accounts along the way.
The seller was Ming, who had built the distribution business over two decades and was ready to retire. The two sides reached an informal understanding on price — an enterprise value in the neighbourhood of $65 million — and agreed to move toward a formal deal. Before either side would see the other's real numbers, contracts, or customer lists, Treadstone Law was retained to negotiate the confidentiality agreement, commonly called an NDA (non-disclosure agreement), that would govern the diligence process. This is the document that opens the data room: the secure online repository where a seller uploads financial statements, supplier contracts, leases, and other sensitive material for the buyer's team to review.
What the NDA had to get right
Getting the NDA right before a single document was uploaded mattered more than either client initially appreciated. A confidentiality agreement is not boilerplate — its scope determines what can be done with the information once it is seen, and by whom. Treadstone's team pushed on three points in particular.
First, the definition of "Representatives" — the people on the buyer's side permitted to access the data room. Samir and Tarek wanted to bring in an outside financial consultant they had worked with informally on past expansions, someone who was not a full-time employee and not bound by any existing employment agreement to keep client matters confidential. The NDA was drafted to require that any such Representative sign a separate confidentiality undertaking before receiving access, and that Samir and Tarek remain responsible for that person's conduct as if it were their own.
Second, permitted use. The agreement restricted use of the data room contents strictly to evaluating the proposed transaction — not for any competing business purpose, and not for approaching the target's customers or suppliers independently of the deal. Third, a standstill and non-solicitation period: for two years, neither side could poach key employees identified during diligence, regardless of whether the deal closed. These are standard protections in a mid-market transaction, but standard only works if it is actually followed once the excitement of reviewing real numbers takes over.
What we did
- Negotiated the NDA before requesting data room access. Treadstone insisted the agreement be fully signed, including the Representative undertaking requirement, before Samir and Tarek's team received credentials. Sellers under time pressure sometimes accept a looser process; Ming's counsel agreed to hold the line, which turned out to matter later.
- Vetted and documented every Representative. The outside financial consultant was added by name, signed the required undertaking, and was logged as an authorized user. This created a clear paper trail of exactly who was permitted to see what, and when their access began.
- Identified the breach quickly once it surfaced. About six weeks into diligence, Ming's team noticed that a regional competitor had suddenly become unusually well-informed about the distribution business's margins and its largest supply contracts — details that were not public and had only been shared in the data room. Ming's lawyer raised it directly with Treadstone rather than escalating publicly first, which preserved the option of a quiet resolution.
- Traced the source internally. Working with Samir and Tarek, Treadstone reviewed the data room's access logs and confirmed that the outside consultant had shared several financial summaries with a friend who did informal advisory work for the competitor — without either client's knowledge or authorization. It was not malicious in the sense of a planned leak; it was careless, done in a casual conversation about market conditions. Under the NDA, it did not matter which — the consultant's conduct was attributed to Samir and Tarek because he was their Representative.
- Cut off access immediately and secured written confirmation. The consultant's data room credentials were revoked the same day. Treadstone obtained a signed certification from him confirming what had been shared, to whom, and that no further copies existed — required under the NDA's breach provisions and useful evidence of good faith if the matter escalated further.
- Opened direct communication with the seller's counsel before any legal notice was sent. Because the breach was disclosed and addressed proactively rather than discovered independently by Ming's side, Treadstone was able to negotiate the consequences rather than simply defend against a claim. This is the difference a tightly drafted, promptly followed NDA makes: it converts what could become a claim for damages or an application for a court injunction into a negotiated resolution.
- Negotiated the remedy as part of the ongoing deal rather than as separate litigation. Ming was understandably angry and considered walking away entirely. Treadstone worked with Samir and Tarek to offer meaningful concessions — a modest reduction in the agreed purchase price to reflect the competitive harm already done, an extended and strengthened non-solicitation commitment, and a one-time payment to cover Ming's legal costs in investigating the breach — in exchange for continuing toward closing rather than terminating the agreement and pursuing a claim.
The outcome
The deal closed roughly four months later than originally planned, at a purchase price reduced by about $2.4 million from the figure the parties had shaken hands on before the breach. Samir and Tarek also absorbed the cost of the compensation payment to Ming and the legal fees on both sides tied to investigating and resolving the incident. The competitor who received the leaked information did not end up bidding on the business, and no further disclosure occurred once the consultant's access was cut off — the damage, while real, did not compound.
The relationship between the parties, strained badly in the weeks after the breach, recovered enough to close the transaction on workable terms. That outcome was not guaranteed. A looser NDA — one that did not clearly define Representatives, did not make Samir and Tarek responsible for their advisor's conduct, and did not require prompt written certification on breach — would have left Ming with a much stronger argument to walk away entirely, and would have left Samir and Tarek with far less leverage to negotiate a landing. The agreement did not prevent the mistake. It did determine who bore responsibility for it, how quickly it could be addressed, and what it ultimately cost.
Samir and Tarek now run a formal policy across their own group: any outside advisor added to a data room during a transaction is briefed in person, not just asked to sign a document, before receiving access.
What you can learn from this
- A confidentiality agreement should name and bind every person who will see the data room, including outside consultants and advisors who are not full-time staff — not just the primary parties to the deal.
- Making the buyer contractually responsible for its Representatives' conduct is what turns a careless leak by an advisor into something the buyer can be held to account for, and something it therefore has strong reason to prevent.
- Disclosing a breach to the other side proactively, before it is discovered independently, preserves options for a negotiated resolution instead of a legal claim or a collapsed deal.
- Data room access logs are not just an IT convenience — they are often the only way to establish quickly who saw what and when, which shapes how fast a breach can be contained.
- A well-drafted NDA does not stop every mistake from happening. It determines how much a mistake costs and who pays for it when one does.
This is a mergers & acquisitions problem we handle
Start a file online — flat, published fees, reviewed by a licensed lawyer before a dollar is owed.