All insights Legal architecture · M&A

The Legal Architecture of an IT Acquisition

Buy a software company and you do not buy its code or its customers — you buy the paper that says it owns them. Five layers where an IT deal’s value actually lives, and how each one is read.

Răzvan Alexandru Olaru26 June 20267 min read

Buy a software company and you do not, in the end, buy its code or its customers. You buy the paper that says it owns them — and in the IT sector that paper is most of the value.

A physical business shows you what you are buying: the plant, the stock, the deeds. An IT target shows you a product and a revenue line, but the assets underneath are intangible and contingent — a repository, a dataset, a book of subscriptions, a stack of third-party dependencies. Each exists, legally, only as well as a document says it does. Diligence in this sector is therefore not an audit of what the company has; it is a reading of what it actually holds.

What you actually buy

The same idea that governs how a product is built governs how it is bought: every layer the company ships casts a legal shadow, and the deal lives in whether the two line up. Read the target as a stack and put each layer to its question — who assigned the code, whether the data is lawful to move, whether the contracts survive a new owner. The price is an opinion about the answers.

WHAT IT SHIPSTHE RIGHT IT HOLDSCode & IPthe product & the repoWho assigned it?employee default · contractor in writingDatausers, logs, modelsLawful to hold & move?GDPR basis · US transfer to testCustomersthe recurring revenueDo the contracts survive?change-of-control · assignmentVendors & OSSthe dependency chainWhat’s in the chain?subprocessors · copyleft licencesPerimeterwhat the product touchesWhich regimes switch on?AI Act · NIS2 · DORA
An IT acquisition is the purchase of a legal architecture: each layer the target ships must be matched by the right it actually holds. The code-and-IP layer is where these deals most often quietly fail.

Start with the code, because it is where IT deals most often quietly fail. Under Romanian copyright law (Law 8/1996, art. 74), the economic rights in software written by an employee in the course of their duties vest in the employer by default — a rare statutory gift. The gift stops at the payroll. An independent contractor, a founder who coded before the company existed, an agency in another country: each keeps authorship unless a written assignment moved it, and Romanian law wants that assignment in writing. A target can ship a product for years on code it does not fully own, and nobody notices until the buyer’s counsel asks for the chain.

The other layers rhyme. Open-source components carry their own licences into the product — a copyleft term can oblige you to release code you meant to keep closed, which is a value question, not a footnote. The data the company holds is an asset only while it is lawful to hold and to move: a GDPR basis for each use, and — since Schrems II (Case C-311/18) and now under the 2023 EU–US Data Privacy Framework — a clear answer on any US-touching transfer. The customer contracts, on which the whole price rests, have to survive a change of owner, which turns on their change-of-control and assignment clauses. And the product’s regulatory perimeter — the AI Act, NIS2, DORA where the customers are financial entities — can switch obligations on the day the buyer takes control.

Share or assets — and who carries the past

How the deal is built decides what crosses and what clings. In a share purchase the company itself changes hands: its contracts, its IP and its liabilities stay exactly where they are, because nothing is assigned — clean for transfer, but every latent liability comes along, priced or not. Anti-assignment clauses generally do not fire, since the counterparty is unchanged, though change-of-control clauses can. In an asset purchase the buyer chooses what to take and leaves known liabilities behind — but now each contract and each IP right has to be transferred, and many will need the counterparty’s consent. The cleaner balance sheet is paid for in a consent campaign.

As a comparative matter, cross-border technology deals are often papered on an English-law share purchase agreement with warranty-and-indemnity insurance standing behind the warranties; that allocation is market practice, read here from a Romanian standpoint rather than as English-law advice. One duty binds both regimes from the first day: the diligence itself processes personal data. A data room full of employee files and customer records is a controller’s act — minimised, lawful-based, access-logged — not a free-for-all because a deal is on.

Reading the mirror

A diligence report is not a list of everything wrong; a list paralyses. It is a routing decision. Every finding resolves into one of three places — back to the table, into the price, or onto a watch list — and the skill is the sorting: knowing that an unassigned founder’s copyright belongs in the first bucket and a soft data-retention gap usually in the third.

FROM ONE FINDING, THREE EXITSA findingfrom the readWEIGHWalk awaydeal-breaker — not what it’s sold asPrice or warrantyindemnity · escrow · price chipNote & monitorlogged · watched where law moves
Diligence is a routing decision, not a list: each finding lands as a walk-away, a price-or-warranty adjustment, or a monitored risk.

The move

Before the letter of intent is signed, map the IP assignment chain — every employee and every contractor whose work is in the product — against what the repository actually ships. Where the chain is unbroken, you have an asset. Where it breaks, you have your first warranty, your first price adjustment, or your reason to walk.

General information on Romanian and EU law as it bears on technology M&A, not legal advice, and no lawyer–client relationship is created. English-law points are comparative analysis by a solicitor (non-practising), not English-law advice. Deal structure, IP and data questions turn on the specific facts and the current text of the instruments cited; any live transaction needs advice on its own facts.

Acquiring or selling an IT company? Read its legal architecture before the letter of intent is signed.

Free brochure

The IT-acquisition diligence guide

A one-page brief on this topic, sent straight to your inbox.

Facing this on a live document?

Book a 30-minute clinic

A quick read on your exact seam — by a lawyer qualified on both sides of it. No charge for the first look.

Your details go to Răzvan Alexandru Olaru (raz@olawru.com) and are held under a lawyer’s professional secrecy (Legea nr. 51/1995 & the Statutul profesiei de avocat) and the corresponding SRA confidentiality rules, processed in line with the GDPR. See our Privacy Policy and GDPR Statement.