The situation
The number on the table was roughly seven million dollars. That was the price Aditya, the founder of a Renfrew industrial supply and equipment rental business, had agreed with the two employees who wanted to buy him out: Shalini, who ran operations and also held a small portfolio of commercial rental properties on the side, and Kaveh, a surgeon and old friend of the family who was putting in a significant share of the purchase capital as a passive partner. The three of them had spent months negotiating a number that worked for everyone, and Aditya had a firm reason to want it signed by a specific date tied to his own retirement plans. Once that date was fixed, it did not move, because the financing Kaveh had arranged was itself conditional on closing inside that window, and letting it slip meant reopening the entire funding package from scratch.
Shalini and Kaveh were not buying blind. They had reviewed the financials, walked the warehouse, and spoken to key customers with Aditya's permission. What they had not done, because nobody on their side had thought to, was look closely at how the business actually handled the personal information it held: customer account records, delivery addresses, payment histories, and a fairly detailed employee file system that Aditya had built up over thirty years without much thought for who could see it or how long it was kept. To Aditya, this was simply how the business had always run. To a buyer stepping into his shoes, it was an inherited liability nobody had priced.
Before final financing could close, our office was brought in to run a sale-readiness audit, the kind of review a buyer's own lawyers would normally run against a seller. Aditya's team had not commissioned one, and had no obligation to. Shalini and Kaveh asked us to run it on their own side instead, quietly, so that if there was a problem, they would be the ones to find it first rather than discover it in the middle of financing approval, when a discovery like that tends to trigger exactly the kind of delay their fixed date could not absorb.
The compressed timeline was the entire shape of the engagement. There was no room to spread the review over the usual number of weeks a readiness audit might take on a business this size. Everything that needed checking had to be checked in days, and anything that needed fixing had to be fixed in the same window, because the closing date was not going to bend for either side, and both Shalini and Kaveh had already given notice at their existing roles on the strength of the deal going through on schedule.
Where it went wrong
The audit turned up a pattern rather than a single mistake. The business kept full customer records, including payment card details from years-old transactions that had never been purged, on a shared internal drive with no access controls beyond a single shared password that most of the staff knew and had known for years. Employee files, including medical notes from past accommodation requests and old disciplinary records, sat in the same folder structure as general business documents, readable by anyone with a login, from the newest warehouse hire to a part-time bookkeeper who had left the company two years earlier and, as it turned out, still had an active password. None of it had ever been misused, as far as anyone could tell, but none of it had ever been protected either, and the two facts are not the same thing.
The business also had contracts with two outside vendors, a payroll processor and a delivery logistics company, that received personal information as part of their day-to-day work but had no written terms governing how that information had to be handled, secured, or deleted once the relationship ended. Aditya had signed those agreements a decade earlier on a handshake basis that had never been formalized in writing, and neither vendor had ever been asked what happened to the data once it left the business's hands.
This mattered for a specific reason that went beyond tidiness. Going forward, a buyer stepping into Aditya's shoes would take on legal responsibility for how that personal information was handled, and would be bound by the limits of whatever consents the business had actually obtained from customers and employees over the years — thin, decades-old consents meaning thin permitted use of the list. Responsibility for how the information had been handled before closing was Aditya's to carry, not something a buyer simply inherited by taking over the business, which is exactly why a sale like this calls for privacy representations and an indemnity from the seller rather than leaving the point to be sorted out afterward. If Shalini and Kaveh's own financing lawyers, or a future buyer's counsel further down the line, had found these gaps during formal due diligence rather than a quiet internal audit, the standard response is to treat it as a live risk: a price reduction, an escrow holdback pending remediation, or in some cases a flat request to delay closing until it was fixed, none of which was available to either side given the fixed date and the conditional financing riding on it.
There was also a narrower risk specific to the employee files. Employers are generally expected to keep sensitive personal information, including medical and disability-related records, separate and secured from general business files, and the absence of that separation was the kind of gap that could have drawn a complaint from a current or former employee regardless of who owned the business by the time it surfaced.
None of this was deliberate concealment. Aditya had simply run the business the way many small operators do, informally, for three decades, and nobody had ever asked him to change it until the sale put someone else's name on the risk.
What we did
- Ran the audit as a compressed sprint, not a standard review. With a closing date that could not move and financing conditional on hitting it, we scoped the review to the categories of risk most likely to affect financing approval or give a buyer's lawyer grounds to object, rather than attempting an exhaustive line-by-line review of every document in the business, so the highest-risk gaps surfaced first and got fixed first while lower-priority items waited for after closing.
- Mapped every place personal information was stored or shared. We had Shalini walk us through every system, shared drive, filing cabinet, and outside vendor that touched customer or employee data, building a plain-language inventory in a single afternoon that let us see the full scope of the exposure at once instead of finding new problems one at a time as the deadline got closer.
- Restricted access to the shared drive immediately. Before anything else, we had the business separate customer and employee files into access-controlled folders and revoked the login the former bookkeeper still held two years after leaving, closing off the most obvious point of unauthorized access within a single day. Every hour that shared password sat unchanged was another hour the exposure could quietly grow, and stopping it first meant the rest of the remediation could proceed on the compressed timeline without racing against a live, ongoing risk.
- Purged data that no longer needed to be kept. Old payment card details and stale customer records that served no ongoing business purpose were identified and securely deleted rather than merely archived, because retaining information nobody needed only expanded the target for a future breach or a buyer's objection. The deletion reduced the size of the problem a buyer's lawyer could later point to and reduced Shalini and Kaveh's own future liability once they took over ownership of what remained.
- Drafted written data-handling terms for both outside vendors. We negotiated short written agreements with the payroll processor and the delivery company covering how information could be used, secured, and deleted once the relationship ended, because an oral handshake gives a buyer's lawyer nothing to review and nothing to rely on if something later goes wrong. Replacing a decade of informal understanding with signed terms gave Shalini and Kaveh documents a financing lawyer could actually read, understand, and sign off on within the available time.
- Built a short data-handling policy for the business itself. A plain, one-page policy set out who could access what, how long records were kept, and what happened to employee medical information specifically, because a business this size did not need a lengthy compliance manual, only clear rules that staff would actually read and follow. Having something concrete and dated gave Shalini and Kaveh a document they could hand to their financing lawyers as proof the gap had already been closed before anyone on the other side asked about it.
- Documented the whole remediation for the closing file. Every fix was logged with the date it was made and who made it, so that if anyone later asked what had been done and when, the answer was on paper rather than resting on memory, which mattered because the closing date left no time to redo any part of the work under pressure.
- Briefed Shalini and Kaveh on what to say if it came up. We prepared a short, honest explanation they could give their own lender or any adviser who asked about data practices, covering what had been found, what had been fixed, and when, so neither of them would be caught improvising an answer under pressure. Framed this way, the remediation read as proactive good management discovered and corrected on their own initiative, rather than something being hidden, minimized, or only fixed because someone else had forced the issue.
The outcome
The deal closed on the date Aditya needed, at the price the three of them had already agreed, with none of the usual last-minute renegotiation over a problem found too late in the process. Because the audit was run on Shalini and Kaveh's own initiative rather than forced on them by an outside party, they controlled both the pace of the fix and the story around it. Nobody had to explain to a lender or a skeptical co-investor why a known gap had been left open right up to closing.
The cost was mostly time and attention during an already compressed window, plus the modest legal fees for drafting the two vendor agreements, the internal policy, and the access changes to the shared drive. There was no price reduction, no escrow holdback, and no delay to the financing, which is broadly the outcome a readiness audit is meant to produce: nothing dramatic happens, because the problem never reaches the point where it needs a dramatic response from either side.
Shalini and Kaveh took ownership of a business with clean, documented data practices from day one, rather than inheriting thirty years of informal habits along with the warehouse and the customer list. That mattered to Kaveh in particular, whose surgical practice had already made him cautious about how personal records get handled, and it gave him a concrete answer when his own financing contact asked routine questions about the target company's governance.
Aditya, for his part, left the sale without a lingering data-handling liability trailing behind him into retirement, which was not something he had thought to ask about until the audit raised it. He later said the review had been the one part of the sale that cost him nothing and worried him least, largely because he never had to hear about it going wrong.
What you can learn from this
- If you are buying or selling a business, ask for a data-handling review before financing deadlines force a rushed one — problems found early can be fixed quietly, problems found late become negotiating leverage for the other side.
- Personal information a business has collected over years, especially payment and employee medical records, becomes the buyer's liability to manage going forward, and the buyer is bound by the limits of whatever consents the seller actually obtained, whether or not anyone has thought about it that way.
- Informal handshake arrangements with vendors who handle personal data on your behalf should be put in writing well before a sale, not discovered as a gap during due diligence.
- A fixed closing date does not mean skipping the review, it means scoping the review to the highest-risk items first so the most serious gaps get fixed within the time available.
- Running your own readiness audit as a buyer, rather than waiting for the other side to find problems, keeps you in control of the timeline and the fix instead of reacting to someone else's discovery.
This is a buying & selling a business problem we handle
Start a file online — flat, published fees, reviewed by a licensed lawyer before a dollar is owed.