Selling a company confidentially: a leak-prevention protocol
A practical protocol for limiting leaks during a company sale: blind teaser, NDA, phased access, personal data, clean teams and incident response.
Author
Capittal Research
Equipo editorial M&A
Editorial review
Equipo M&A Capittal
Financial, tax and legal review
Updated
22 August 2026
Content reviewed as markets evolve

Confidentiality in a company sale is not guaranteed by one NDA: it is protected by limiting who knows about the transaction, what each person receives and how long access remains open. The realistic objective is not zero risk. It is to stop a prospective buyer from identifying the company or using sensitive information before demonstrating genuine interest and capacity.
A phased confidentiality protocol
| Stage | Reasonable information | Main control |
|---|---|---|
| Preparation | Data map, buyer list and materials not yet distributed | Small internal team, code name and separate permissions |
| Initial approach | A sufficiently anonymised teaser | Exclude combinations of facts that identify the company |
| After the NDA | Identity, aggregated financial information and memorandum | Purpose limitation, authorised recipients and download logs |
| Indicative offer | Redacted contracts, customer concentration and gradual operating detail | Folder-level access and questions channelled through the adviser |
| Exclusivity and confirmatory review | Identifying information needed to complete due diligence | Need-to-know, a clean team where appropriate and access removal at the end |
The sequence must be adapted to the sector and the buyer. A teaser does not have to wait for an NDA if it is genuinely blind, but the NDA should precede disclosure of identity and information capable of causing competitive harm. The guide to designing the whole confidential sale process covers the wider organisation; this article focuses on leak controls.
What a blind teaser must hide
Removing the name and logo is not enough. A combination of town, exact revenue, headcount, certifications, largest customer or founding year can identify an SME within minutes. Before circulation, test whether someone familiar with the industry can reidentify the company.
- Use reasonable ranges for scale and geography when exact data would identify.
- Describe customers by segment rather than by name.
- Hold back unique milestones, products or certifications until a later stage.
- Give each recipient a code and preserve the version sent.
What an NDA does—and does not—do
An NDA defines protected information, permitted purpose, authorised recipients, exceptions, duration and return or destruction. It may also restrict direct contact with employees, customers and suppliers. It cannot physically prevent a leak or make every restriction enforceable: non-solicitation and non-compete terms need separate review for scope and legality.
Spain’s Trade Secrets Act 1/2019 requires, among other elements, reasonable steps by the holder to keep information secret. Classifying documents, restricting recipients, logging access and removing permissions help both prevention and evidence.
What changes when the buyer is a competitor
A competitor may need data to value the business, but should not receive unfiltered future prices, live quotations, customer-level strategy, disaggregated costs or plans that are unnecessary for the transaction. The European Commission’s Horizontal Guidelines explain the competition risks of information exchange and the use of restricted teams or clean teams.
Options include aggregation, anonymisation, historical information, delayed customer identification or analysis by advisers who do not make day-to-day commercial decisions. A clean team is not merely a label: its members, permitted inputs, aggregated outputs and ban on passing sensitive data to the operating team must be defined.
Personal data and employee communication
Named payroll, appraisals, medical leave and disciplinary data should not be open by default. The GDPR requires a lawful basis, purpose limitation, data minimisation, security and limited retention. Aggregated or pseudonymised data is normally more appropriate in early stages.
There is also no universal rule that employees are told “after signing”. In a share sale the same company remains the employer; a transfer of an economic entity that retains its identity may fall under Article 44 of the Spanish Workers’ Statute, with information and, where applicable, consultation duties. Labour communications must follow the actual structure of the deal.
How to respond to a suspected leak
- Contain: suspend the affected access without deleting evidence.
- Preserve: retain logs, emails, versions and the list of people with access.
- Classify: identify trade secrets, personal data, competitively sensitive information and contractual issues.
- Decide: coordinate legal counsel, data leads and management before accusing or communicating.
- Correct: change permissions, narrow the perimeter and document the response.
If personal data may be compromised, the assessment must consider GDPR notification duties. If the source has not been established, a premature accusation can compound the harm.
Checklist before opening the data room
- Document inventory and sensitivity classification.
- A named owner who approves each access level.
- An NDA signed by the correct entity and identified recipients.
- Separate folders, time-limited permissions and activity logs.
- Minimised personal data and redacted contracts where possible.
- A specific protocol for competitors and external advisers.
- An exit plan: revoke, return or destroy while preserving necessary evidence.
The sell-side mandate should allocate responsibility for buyer screening and information release. Due diligence can be rigorous without giving everything to everyone on day one.
Sources consulted
Frequently asked questions
Common questions on this topic.
Does an NDA guarantee that there will be no leaks?+
No. It creates contractual duties, but prevention also requires anonymisation, limited recipients, phased disclosure, access logs and permission removal.
Can a teaser be sent before the NDA is signed?+
Yes, if it is sufficiently anonymised. Identity and sensitive information should wait until an NDA is in place and access is genuinely needed.
What information should a competitor not receive early?+
Future prices, live bids, customer-level strategy, disaggregated costs and unnecessary data. Aggregation, anonymisation, historical data or a clean team can be used.
When should employees be told?+
It depends on the deal structure, legal duties and the people needed for the process. There is no universal timing that works for every transaction.
Can personal information be included in the data room?+
Only with a lawful basis, purpose and suitable safeguards. It must be minimised; aggregation or pseudonymisation is often preferable in early stages.
What happens to information when a buyer leaves the process?+
Access should be revoked, return or destruction required under the NDA, necessary logs retained and the information received by that party documented.

![Sell 100% of a company or a stake: how to decide [2026]](/_next/image?url=https%3A%2F%2Ffwhqtzkkvnjkazhaficj.supabase.co%2Fstorage%2Fv1%2Fobject%2Fpublic%2Fcase-studies-images%2Fblog%2Fes-capittal-opina-vender-todo-o-parte-empresa.jpg%3Fv%3D1784563278626&w=3840&q=72)
![Selling a company to a competitor: risks and clean teams [2026]](/_next/image?url=https%3A%2F%2Ffwhqtzkkvnjkazhaficj.supabase.co%2Fstorage%2Fv1%2Fobject%2Fpublic%2Fcase-studies-images%2Fblog%2Fes-capittal-opina-vender-a-un-competidor.jpg%3Fv%3D1784563279311&w=3840&q=72)