Buy a software company and you do not, in the end, buy its code or its customers. You buy the paper that says it owns them — and in the IT sector that paper is most of the value.
A physical business shows you what you are buying: the plant, the stock, the deeds. An IT target shows you a product and a revenue line, but the assets underneath are intangible and contingent — a repository, a dataset, a book of subscriptions, a stack of third-party dependencies. Each exists, legally, only as well as a document says it does. Diligence in this sector is therefore not an audit of what the company has; it is a reading of what it actually holds.
What you actually buy
The same idea that governs how a product is built governs how it is bought: every layer the company ships casts a legal shadow, and the deal lives in whether the two line up. Read the target as a stack and put each layer to its question — who assigned the code, whether the data is lawful to move, whether the contracts survive a new owner. The price is an opinion about the answers.
Start with the code, because it is where IT deals most often quietly fail. Under Romanian copyright law (Law 8/1996, art. 74), the economic rights in software written by an employee in the course of their duties vest in the employer by default — a rare statutory gift. The gift stops at the payroll. An independent contractor, a founder who coded before the company existed, an agency in another country: each keeps authorship unless a written assignment moved it, and Romanian law wants that assignment in writing. A target can ship a product for years on code it does not fully own, and nobody notices until the buyer’s counsel asks for the chain.
The other layers rhyme. Open-source components carry their own licences into the product — a copyleft term can oblige you to release code you meant to keep closed, which is a value question, not a footnote. The data the company holds is an asset only while it is lawful to hold and to move: a GDPR basis for each use, and — since Schrems II (Case C-311/18) and now under the 2023 EU–US Data Privacy Framework — a clear answer on any US-touching transfer. The customer contracts, on which the whole price rests, have to survive a change of owner, which turns on their change-of-control and assignment clauses. And the product’s regulatory perimeter — the AI Act, NIS2, DORA where the customers are financial entities — can switch obligations on the day the buyer takes control.
Share or assets — and who carries the past
How the deal is built decides what crosses and what clings. In a share purchase the company itself changes hands: its contracts, its IP and its liabilities stay exactly where they are, because nothing is assigned — clean for transfer, but every latent liability comes along, priced or not. Anti-assignment clauses generally do not fire, since the counterparty is unchanged, though change-of-control clauses can. In an asset purchase the buyer chooses what to take and leaves known liabilities behind — but now each contract and each IP right has to be transferred, and many will need the counterparty’s consent. The cleaner balance sheet is paid for in a consent campaign.
As a comparative matter, cross-border technology deals are often papered on an English-law share purchase agreement with warranty-and-indemnity insurance standing behind the warranties; that allocation is market practice, read here from a Romanian standpoint rather than as English-law advice. One duty binds both regimes from the first day: the diligence itself processes personal data. A data room full of employee files and customer records is a controller’s act — minimised, lawful-based, access-logged — not a free-for-all because a deal is on.
Reading the mirror
A diligence report is not a list of everything wrong; a list paralyses. It is a routing decision. Every finding resolves into one of three places — back to the table, into the price, or onto a watch list — and the skill is the sorting: knowing that an unassigned founder’s copyright belongs in the first bucket and a soft data-retention gap usually in the third.
The move
General information on Romanian and EU law as it bears on technology M&A, not legal advice, and no lawyer–client relationship is created. English-law points are comparative analysis by a solicitor (non-practising), not English-law advice. Deal structure, IP and data questions turn on the specific facts and the current text of the instruments cited; any live transaction needs advice on its own facts.
Acquiring or selling an IT company? Read its legal architecture before the letter of intent is signed.
Free brochure
The IT-acquisition diligence guide
A one-page brief on this topic, sent straight to your inbox.
Facing this on a live document?
Book a 30-minute clinic
A quick read on your exact seam — by a lawyer qualified on both sides of it. No charge for the first look.
Your details go to Răzvan Alexandru Olaru (raz@olawru.com) and are held under a lawyer’s professional secrecy (Legea nr. 51/1995 & the Statutul profesiei de avocat) and the corresponding SRA confidentiality rules, processed in line with the GDPR. See our Privacy Policy and GDPR Statement.