The situation
The number on the table was just under six million dollars, and for Samir and Nadia it represented more money than either of them had ever seen attached to anything they had built. Samir worked full time as a personal support worker, visiting clients in their homes across the Grimsby area, and in his off hours he had built a simple scheduling application to help coordinate visits for a small roster of clients he and a few colleagues served. Nadia, who supervised the front desk at a hotel, had helped him turn the tool into something other small home-care providers could use too, handling the parts of the business Samir had no time for between shifts, from invoicing to the handful of customer service calls that came in each week.
What started as a side project became a modest division held inside a small parent company the two of them had incorporated together, licensing the scheduling software to a growing list of independent home-care providers across the region. Neither of them had ever run a business of this size before, and neither had been through a sale process, when a US-based health-technology company approached them wanting to acquire the division outright and fold its client base into its own platform. The offer arrived almost out of nowhere, through a cold introduction from a mutual industry contact, and both of them treated it with a mixture of excitement and disbelief for the first several weeks.
The buyer's interest was genuine and the number they offered reflected real value in the client list and the software, not a token gesture. It represented, for both Samir and Nadia, a life-changing sum against the modest wages they each still earned from their day jobs. But the deal came with a condition neither Samir nor Nadia had anticipated: the buyer wanted to migrate the entire client database, including personal information about home-care recipients, onto its own servers located in the United States, and its diligence team wanted to confirm the data had been collected and stored in a way that made that transfer lawful before they would close.
That was the point at which the deal, which had felt close to done, stalled, and where Samir first called our office, uncertain whether the problem the buyer's team had described was fixable at all.
What was actually at stake
The scheduling application had been built quickly and grown faster than its original design anticipated. Client information, including scheduling details that revealed sensitive facts about individuals' health and daily routines, had been collected under consent language that was thin by the standards a larger, more careful buyer would expect, and some of that data had at one point been backed up to a general-purpose cloud storage account without clear documentation of where the servers hosting it were actually located. Samir had set that account up years earlier, before the business was anything more than a favour to a handful of clients, and had never revisited the choice as the client list grew into the thousands.
For the buyer, the risk was straightforward: taking on a database of personal health-adjacent information without confidence in how it had been collected and secured exposed them to compliance risk the moment they took control of it, and moving that data across the border compounded the exposure. The buyer's own compliance team could not sign off on the migration until the gap was closed, and their internal policy, developed after an unrelated incident at another one of their acquisitions years earlier, required an independent review before any personal information involving vulnerable individuals crossed into their systems.
That review measured the division's practices against the standard set by Ontario's personal health information privacy law, since a portion of the data the division held touched on personal health information collected in the course of coordinating care visits, even though the division itself was a scheduling tool rather than a regulated health information custodian. The review itself was the buyer's own institutional process, carried out by outside privacy counsel the buyer retained specifically for the acquisition, and it was not something either side could accelerate simply because a sale was waiting on it. There was no government body whose sign-off the deal depended on, but the buyer's own standard was thorough enough that it functioned like one. Bilal, who led compliance on the buyer's side, was sympathetic to the pressure the delay put on Samir and Nadia but was equally clear that his own team had no authority to shortcut a review it had commissioned to protect itself.
For Samir and Nadia, the stakes went beyond the six-million-dollar figure. If the deal collapsed, they would be left holding a business with a database they now knew did not meet the standard a sophisticated buyer expected, with no guarantee another buyer would come along on similar terms, and with real exposure if a client ever raised a complaint about how their information had been handled in the meantime, exposure that existed whether or not any sale ever closed.
What we did
- Audited the data flows end to end. Before responding to the buyer's diligence request, we mapped exactly what personal information the division collected, where it was stored, who could access it and under what consent language, which gave us an accurate picture instead of relying on Samir and Nadia's best recollection of a system that had grown informally over several years.
- Identified and closed the storage gap immediately. The general-purpose cloud account with undocumented server locations was migrated to a properly configured, documented hosting arrangement within weeks, before the buyer's privacy counsel even began their formal review, rather than waiting to see whether the gap would be flagged first. Acting before the buyer raised it showed good faith, narrowed the scope of what the review actually had to examine, and gave Samir and Nadia a concrete fix to point to instead of an open problem.
- Rewrote the consent and privacy notice language going forward. The original consent wording had not clearly addressed cross-border storage or third-party transfer, so we updated it to meet the standard the buyer's compliance team needed to see before it would sign off on the migration. We were careful not to word the new consent as though historical clients had already agreed to terms they had never seen, since overstating past consent would have created a new problem for the buyer's counsel to find.
- Prepared the compliance file the buyer's privacy counsel required. Their review called for a detailed account of the data collected, the safeguards in place, and the proposed cross-border arrangement, measured against the standard Ontario's personal health information privacy law would expect of a custodian; we built that file to be thorough enough to avoid a second round of questions, since each round would add months to an already slow process.
- Managed the deal timeline around a process we could not control. With the buyer's own compliance review running on its own schedule, we negotiated an extension to the closing deadline with the buyer's counsel that kept the deal alive without requiring Samir and Nadia to accept a lower price for the delay, framing the extension as protecting the buyer's own compliance position rather than a favour to the sellers.
- Negotiated interim indemnity protection for the sellers. While the review was pending, we secured terms limiting Samir and Nadia's personal exposure if a historical client complaint arose before closing, capping how much of any future claim could fall back on them individually rather than on the business itself. That mattered because the delay was entirely outside their control, and neither of them should have had to absorb open-ended personal risk just because the buyer's own review was taking months longer than planned.
- Coordinated the data migration plan with the buyer's technical team. Once the buyer's privacy counsel signed off, we worked through the actual transfer mechanics with the buyer's counsel to ensure the migration happened under the terms the review had approved, rather than reverting to whatever the buyer's technical team found administratively easiest once the pressure to close finally lifted. Locking down the mechanics in writing meant the approved safeguards travelled with the data instead of getting quietly simplified in the rush to finish.
- Briefed Samir and Nadia on what the sale agreement's ongoing obligations meant for them personally. Because the indemnity terms and the transition period both carried real, if bounded, exposure past closing, we walked through in plain terms what could still go wrong after the money changed hands and what steps they should take if a former client ever raised a concern, so neither of them was caught off guard by a routine question mistaken for a legal problem.
The outcome
The buyer's compliance review took several months longer than either side had originally planned for, pushing the closing date well past the date Samir and Nadia had once hoped to have the money in hand. The deal held together through that delay, and it closed at the price originally negotiated, with no reduction tied to the compliance gap that had caused the holdup, which was the outcome that mattered most given how much of that number the two of them were counting on.
Samir and Nadia did carry the interim indemnity exposure during the months the review was pending, which meant they lived with some continuing personal risk for a period longer than they had expected to still be exposed for, though that exposure never materialized into an actual claim from a client. The consent language rewrite also meant the division's ongoing operations, while the sale was pending, ran under stricter, more conservative terms than either of them had used before, which slowed down onboarding of a few new provider clients during that window and meant a modest, temporary dip in the division's monthly revenue right when both of them most wanted the numbers to look strong.
The buyer, for its part, absorbed the cost of a longer diligence and integration timeline than it had budgeted for, and Bilal's team had to explain the delay internally more than once as the review dragged past its initial estimate. Neither side got the fast, clean close either had originally pictured.
Once the sale closed, both Samir and Nadia stepped back from day-to-day operation of the division, with Samir returning full time to his personal support work and Nadia to her role at the hotel, this time with the proceeds of a sale that reflected the value of what they had actually built rather than a discounted price for a problem that never should have been allowed to sit unaddressed as long as it had. Samir has since said the months of delay taught him more about running a business properly than the years before it did.
What you can learn from this
- A side project that grows into a business can carry compliance gaps nobody meant to create; audit how personal data is actually stored before a buyer's diligence team finds it first.
- When personal information touches health details, expect the buyer's own privacy and compliance review to run on a timeline you don't control, and build that into your expectations early.
- Closing a compliance gap before a buyer flags it in writing shows good faith and often prevents the buyer from using the gap to renegotiate price.
- A closing delay caused by a compliance process outside anyone's control is not, on its own, a reason to accept a lower price. Negotiate the extension, not the discount.
- If you must operate under interim risk while a deal is pending, get that risk bounded in writing rather than simply hoping nothing goes wrong before closing.
This is a mergers & acquisitions problem we handle
Start a file online — flat, published fees, reviewed by a licensed lawyer before a dollar is owed.