TREADSTONE LAW · ONTARIO · DIGITAL LEGAL SERVICES · EST. MMXXI ·TSL
Home/Case Studies/Mergers & Acquisitions
№ 181 Case Study — Mergers & Acquisitions

Three Shareholders, Three Countries, One Overdue Breach Notice

Zhen, Folake, and Ama were selling their home care scheduling company from three time zones away, and what worried them was not the price. It was what would happen to them personally if a buyer found something they had not disclosed.

Mergers & Acquisitions8 min readCampbellford, OntarioPrivacy compliance gaps
All Mergers & Acquisitions case studies
ClientZhen, Folake, and Ama, selling shares in a Campbellford home care scheduling company from outside Ontario
The issueA past privacy breach that was never formally reported, discovered before the buyer's own diligence could find it
ServiceVendor due diligence conducted entirely by video and document exchange across three time zones
ResolutionClear win — the gap was disclosed on the sellers' own terms, and the deal closed with no personal liability exposure

The situation

What Zhen was afraid of was not that the deal would fall through. It was that six months after closing, with the money spent and the company gone, a letter would arrive naming him personally for something he had signed off on without fully understanding. That fear sat with him through every call about the sale, long before anyone found a reason for it.

Zhen, a welder by trade, had put early savings into a small home care scheduling company alongside two friends nearly a decade earlier, back when it was three people and a spreadsheet coordinating personal support workers for elderly clients around Campbellford. Folake, a registered nurse, had joined as a shareholder soon after and had done more of the hands-on operational work over the years. Ama, the third shareholder, had moved overseas for a family reason five years in and had stayed involved from a distance ever since, checking in on financials remotely and attending board discussions by video call at odd hours. The company had grown into a real business, coordinating care schedules and medical information for several hundred clients across the region, and a regional healthcare services group had made an offer to buy it outright for roughly $22 million.

The three shareholders wanted different things from the exit. Zhen, now in his fifties, wanted to be fully out and reinvest elsewhere. Folake wanted a clean break from day-to-day operations but was open to a short consulting arrangement with the buyer. Ama, still overseas, mainly wanted certainty that the transaction would not leave her exposed to a lawsuit years after she had stopped being involved in daily decisions. None of them lived near Campbellford anymore, and the entire process, from the first term sheet to the closing signatures, would have to happen without any of them setting foot in Ontario.

The purchase agreement, as buyers typically require, would include a set of representations and warranties about the company's compliance with privacy law, covering how client health information had been collected, stored, and handled over the years the shareholders had owned it. Signing those representations without knowing whether they were actually true was the specific risk that had been sitting with Zhen since the term sheet stage.

What the review found

Before advising the shareholders to sign representations about the company's privacy compliance history, we conducted a vendor-side review of that history ourselves, examining the company's records against what its written policies and prior client communications said had happened, rather than accepting the shareholders' recollection of events several years old. The company handled personal health information as part of coordinating care, which put it squarely within Ontario's health privacy framework, and that framework requires notifying affected individuals, and in some circumstances a regulator, when a breach involving that kind of information occurs.

The review found one incident from about three years earlier that had not been closed out properly. A scheduling coordinator, no longer with the company, had mistakenly attached the wrong client's care file to an email sent to a family member, exposing that second client's medical information to someone with no right to see it. The company had caught the error within a day, contacted both families involved directly, and updated its internal procedures to prevent a repeat. What it had not done was complete the formal notification steps the privacy framework calls for when this kind of exposure happens, a step that appeared to have been missed rather than deliberately skipped, likely because whoever handled it at the time treated the direct call to both families as sufficient and did not realize a further formal step still applied.

This was not a catastrophic breach in scale, one client's file reaching one wrong recipient, contained within a day and with no evidence the information was ever misused. But an incomplete notification history is exactly the kind of gap a sophisticated buyer's own diligence team is trained to look for, particularly in a company whose entire value depends on the trust clients place in how it handles sensitive medical information. Finding it themselves, after the shareholders had already signed a representation stating the company's privacy obligations had been met in full, would have turned a fixable oversight into a signed misstatement, and a signed misstatement is a very different problem from an honest, documented gap.

The practical consequence Zhen had been worried about, personal exposure discovered after the money was gone and spent, was precisely what an undisclosed gap like this could produce, because the shareholders individually stood behind those representations in the purchase agreement, not the company alone. A buyer who later discovered an undisclosed compliance gap would have grounds to pursue the individual shareholders directly for the resulting loss, years after closing, with the practical difficulty for Zhen, Folake, and Ama of mounting a defence from three different countries.

What we did

  1. Requested the company's full incident history before drafting any representations. Rather than accepting the sellers' general understanding of the company's compliance record, which had been shaped by memory rather than documentation, we asked for every recorded privacy incident, however minor, going back as far as the company's records existed, and cross-checked that list against its own written policies for what should have followed each one. That comparison, not the sellers' recollection, was what eventually surfaced the gap.
  2. Identified the incomplete notification as a gap, not a violation to hide. Once the missed step was found, we advised the shareholders plainly that the honest and lower-risk path was disclosure to the buyer before signing, not silence in the hope the buyer would never ask. A sophisticated buyer's own diligence team reviews exactly this kind of record as a matter of course, and the risk of being caught concealing a known gap was far higher than the risk of disclosing one already fixed.
  3. Completed the overdue notification steps before disclosure. Rather than disclose an open, unresolved gap, we had the company complete the notification process that should have happened three years earlier, contacting both affected families formally and documenting that the steps had now been carried out properly. Closing the loop before disclosure meant the buyer would be reviewing a finished correction rather than an outstanding obligation someone still had to deal with after closing.
  4. Drafted a specific, narrow disclosure schedule. The purchase agreement's representations were qualified against a disclosure schedule describing exactly what had happened, when it was caught, when the families were contacted, and when the outstanding notification steps were finally closed out. Drafting it with that level of specificity meant the sellers were not signing a blanket statement that no gap had ever existed in the company's history, which would have been false, but a precise account the buyer could verify.
  5. Negotiated the buyer's response by video call across three time zones. With Zhen, Folake, and Ama in different parts of the world, every negotiating session on this point was scheduled around all three, often at inconvenient hours for at least one of them, to keep every shareholder informed and aligned before any position was agreed with the buyer rather than presenting them with a done deal.
  6. Limited the warranty exposure tied to the disclosed item. We negotiated a specific carve-out capping any claim related to the disclosed incident at a fixed amount, kept separate from the general warranty cap so it would not erode the protection available for anything else. Fixing that number before closing meant the shareholders' exposure on this one known issue was bounded in advance, rather than left open for the buyer's lawyers to argue about later.
  7. Prepared each shareholder individually for the buyer's follow-up questions. Anticipating that the buyer's team would want to speak directly with whoever had handled the original incident, we briefed Folake, who had been closest to operations at the time, in detail on what had happened, who had been contacted, and what had already been fixed. Preparing her answers to match the written disclosure exactly mattered because any inconsistency between what she said aloud and what the schedule described in writing would have undercut the credibility of the whole disclosure.
  8. Confirmed the company's current privacy procedures separately from the disclosed incident. To reassure the buyer the gap was historical rather than ongoing, we had the company document its current notification procedures in writing and confirm that no similar incident had occurred in the years since the fix was implemented. Giving the buyer a clean, verified present alongside a disclosed and corrected past made it easier for their diligence team to treat the incident as a closed chapter.

The outcome

The buyer's own diligence team flagged the same three-year-old incident independently, roughly two weeks after the disclosure schedule was delivered, and found that the sellers had already identified it, completed the outstanding notification steps, and disclosed it in writing before being asked. That sequence changed the entire tone of the conversation. Instead of a buyer discovering a gap the sellers had missed or hidden, the buyer's team was reviewing a problem the sellers had already found and fixed.

The deal closed at the originally agreed price, with the narrow, capped carve-out around the disclosed incident as the only change to the standard representations. No general price reduction followed, and no broader indemnity was demanded once the buyer's counsel confirmed the notification gap had been closed properly and the exposure was limited to one identified event years in the past.

Zhen's specific fear, the letter arriving after the money was spent, did not happen, and the reason it did not happen was that the gap was found and dealt with before anyone signed anything stating it did not exist. Folake stayed on briefly under a consulting arrangement with the buyer, and Ama received her share of the proceeds without any condition tied to future cooperation on a claim that never materialized. All three shareholders got what they had actually wanted from the exit, on the terms each had asked for at the outset.

What you can learn from this

  • Before signing representations about a company's compliance history, verify that history yourself. A representation you have not checked is a promise you cannot actually back up.
  • A missed regulatory step, caught and corrected before a buyer finds it, is a manageable disclosure item. The same gap discovered by the buyer afterward becomes a credibility problem for the entire deal.
  • Complete an overdue compliance step before disclosing the underlying gap, not after. Disclosure of a closed issue reads very differently than disclosure of an open one.
  • A narrow, specific disclosure schedule protects sellers better than either silence or a vague blanket admission. Describe exactly what happened and exactly what was done about it.
  • Selling from a distance does not have to mean less oversight. Structure the negotiation calendar around every shareholder's time zone so no one signs off on something they have not actually reviewed.
This case study is entirely fictional. It does not describe any real client, file, or matter handled by Treadstone Law, and it is not a real file with details changed. All names, people, properties, businesses, dollar amounts, dates, and events are invented, and any resemblance to a real person, business, or situation is coincidental. Fictional scenarios like this one illustrate the kinds of legal issues people in Ontario commonly face and how a lawyer can help. They are general information, not legal advice — no two matters unfold the same way, and nothing here predicts the outcome of any real case. Reading a case study does not create a lawyer-client relationship. If you are facing something similar, speak with a lawyer about your specific circumstances.

This is a mergers & acquisitions problem we handle

Start a file online — flat, published fees, reviewed by a licensed lawyer before a dollar is owed.

ContactStart a File →