How should the buyer define the scope?
Start with the investment thesis: what is the buyer acquiring and where does the value sit? For a technology target, software rights, customer contracts, product security and the team may be decisive. In a services business, key people, contractual liability and customer concentration may matter more. For a regulated business, permits and operational compliance can determine whether the transaction is viable.
The scope also depends on structure. In a share deal, the buyer acquires shares while the target remains party to its contracts, owner of its assets and liable for its obligations. The review therefore covers the target’s legal position and history within the agreed parameters. In an asset deal, the key question is whether selected assets, contracts, rights, employees and permits can transfer effectively and which liabilities follow them. The acquisition process is explained in Sale of shares in a Polish limited company — procedure.
How should materiality and red flags be defined?
The parties should agree a monetary threshold for contracts, disputes and liabilities. It should not replace qualitative judgment. A low-value agreement may contain an exclusivity restriction that blocks growth, while a free licence may be essential to the entire product.
A red flag is not every irregularity or missing document. It should be an issue capable of affecting the decision, structure, value or ability to close. A useful classification distinguishes:
- deal blockers or matters requiring action before signing;
- issues to be cured before closing;
- risks requiring contractual protection;
- operational matters for post-closing remediation; and
- information gaps that cannot yet be assessed.
Which areas normally require review?
The exact scope depends on the target, but it commonly includes corporate matters, title to shares, material contracts, finance and security, employment and B2B contractors, intellectual property, property and assets, disputes, data protection, compliance, permits and insurance.
Particular attention should be paid to change-of-control provisions, transaction-related termination rights, third-party consents and assignment restrictions. The buyer should also verify whether the target validly acquired the rights to its core product from employees, contractors and suppliers. Possession of files or use of a system does not prove the right to sell or continue developing it.
Tax, financial, technical, cybersecurity or environmental work may require other advisers. Workstreams should be coordinated so that a material issue does not fall between teams.
How should the data room and Q&A process be managed?
The data room should have an index, logical folders and an access history. The buyer should maintain one list of missing materials and questions, distinguishing between a document that has not yet been uploaded and confirmation that it does not exist. Management explanations are important but do not always replace evidence.
The most sensitive information can be disclosed in stages. Employee, customer and user data should be limited, anonymised or aggregated until identification is necessary. In deals between competitors, access to prices, margins, strategy and customer lists may require a clean team or comparable restrictions.
The seller should prepare its documentation and risk narrative in advance, as discussed in How to prepare a Polish company for legal due diligence. The buyer should nevertheless verify completeness and significance independently.
How the issue appears in practice
Hypothetical example: acquiring a SaaS business without complete rights to the code
A buyer plans to acquire all shares in a Polish SaaS company. Its principal application generates most revenue and one key customer accounts for 30% of sales. The data room contains repositories and developer invoices, but agreements with two former contractors do not validly transfer rights to their code. The key customer agreement permits termination on a change of control. It is not enough to label these as “IP and contract risks”. Closing should be conditional on completing the chain of title and obtaining appropriate customer consent or confirmation. If the IP issue cannot be fully cured, the buyer may require a specific indemnity, a holdback and a plan to replace the affected module. Customer-loss risk should affect valuation and the price mechanism, not only a general contracts warranty.
How should findings affect the transaction documents?
The report should not end with a description. The parties must select the appropriate mechanism:
- condition precedent where the deal should not close without consent, a permit or a specified action;
- pre-closing covenant where the seller can correct a document, obtain consent or resolve an issue;
- price or payment adjustment where the matter affects value or creates an identifiable cost;
- representation and warranty where the buyer requires confirmation of a state of affairs and a remedy if it is incorrect;
- specific indemnity where a known risk should be allocated under separate rules rather than the general liability cap;
- escrow or holdback where the buyer needs an effective source of recovery; or
- post-closing integration action where remediation can safely occur under the buyer’s control.
Legal basis
- Act of 15 September 2000 — Polish Commercial Companies Code.
- Act of 23 April 1964 — Polish Civil Code.
- Act of 20 August 1997 on the National Court Register.
- Act of 16 April 1993 on Combating Unfair Competition, in particular Article 11.
- Regulation (EU) 2016/679 (GDPR), to the extent personal data is disclosed during the review.
This article provides general information and does not constitute legal advice for a specific matter. The appropriate solution depends on the facts, documents and business objective.
Summary
Buy-side legal due diligence is a decision tool, not an archive of target issues. Its scope should reflect the deal and business model, and its output should directly shape structure, price, closing conditions, liability and integration planning.
