I. Common mistakes relating to confidentiality clauses in corporate mergers

In M&A practice, confidentiality clauses in corporate mergers are often underestimated or drafted inadequately, leading to numerous legal and commercial risks. Common mistakes include:

  • Unclear definition of the scope of confidential information: Many agreements merely refer generally to “confidential information” without specifically listing or categorizing such information, thereby making it difficult to determine breaches in the cases of disputes.
  • Failure to clearly specify the confidentiality period: The absence of provisions governing the duration of confidentiality obligations makes it difficult for parties to apply or terminate such obligations reasonably after completion of the transaction.
  • Lack of mechanisms for handling breaches: Many clauses fail to clearly stipulate sanctions, compensation levels, or remedial measures in cases of unauthorized disclosure.
  • Failure to bind relevant third parties: Information during the merger process is often shared with consultants, auditors, and relevant personnel, yet corresponding confidentiality undertakings are not always required.
  • Failure to distinguish between confidentiality and data transfer obligations: Some agreements do not clearly regulate the use, storage, or transfer of data after the merger, thereby increasing the risk of violating data protection laws.

II. Understanding confidentiality clauses in corporate mergers

1. What is a confidentiality clause in a corporate merger, and what is its primary purpose?

In corporate merger transactions (M&A), a confidentiality clause is a contractual provision under which the parties undertake not to disclose or improperly use confidential information accessed during the negotiation, due diligence, and implementation stages of the transaction.

The primary purposes of such clauses are:

  • To protect sensitive information such as financial data, customer information, contracts, technology, and business strategies throughout the M&A process;
  • To prevent the disclosure or exploitation of information for unfair competitive purposes;
  • To minimize legal risks and ensure security and transparency for the corporate merger transaction.

2. What types of information are commonly required to remain confidential under confidentiality clauses in corporate mergers?

  • Financial and accounting information: Financial statements, revenues, expenses, liabilities, cash flow, and financial plans.
  • Customer and partner information: Customer lists, contracts, transaction terms, and pricing policies.
  • Business operation information: Development strategies, expansion plans, business models, and internal operating procedures.
  • Legal and contractual information: Existing contracts, disputes, legal obligations, and corporate legal records.
  • Technological and technical information: Technical know-how, software, system data, manufacturing processes, and proprietary technologies.
  • Human resources information: Organizational structures, salary and bonus policies, and main personnel data.

Clearly identifying the scope of confidential information helps minimize risks of data leakage during negotiations and protects the parties’ interests in the corporate merger transaction.

3. How is the validity period of confidentiality clauses in corporate mergers typically regulated?

In M&A practice, the duration of confidentiality obligations in corporate merger transactions is usually flexibly agreed upon by the parties, commonly in the following manners:

  • During the entire negotiation and due diligence process: Confidentiality obligations commence when access to information is granted and continue until the transaction is completed or negotiations are terminated.
  • After completion of the transaction or termination of negotiations: Many agreements continue to impose confidentiality obligations for a specified additional period (commonly from one to five years) to further protect sensitive information.
  • Indefinite duration for certain categories of special information: With respect to trade secrets, technology, or core enterprise data, confidentiality obligations may continue until such information no longer retains its confidential nature.

The duration of confidentiality obligations in corporate mergers is not fixed by law but depends on the parties’ agreement; however, the prevailing approach is to maintain confidentiality obligations both during and after the transaction in order to maximize protection of enterprise information.

4. How do confidentiality clauses in corporate mergers differ from ordinary non-disclosure agreements (NDAs)?

Although both confidentiality clauses in corporate mergers and non-disclosure agreements (NDAs) aim to protect confidential information, they differ significantly in terms of scope and purpose.

  • Scope of application: NDAs are generally executed independently in various situations such as business cooperation, service engagements, or preliminary negotiations, whereas confidentiality clauses in corporate mergers form part of M&A agreements and are directly associated with merger transactions.
  • Purpose: NDAs primarily protect information exchanged during preliminary discussions, while confidentiality clauses in M&A transactions protect information throughout the due diligence process, negotiations, and even after completion of the transaction.
  • Degree of enforceability: Confidentiality clauses in corporate mergers are typically stricter and accompanied by data control mechanisms, post-merger responsibilities, and obligations applicable to multiple related parties, including third parties such as consultants and auditors.

III. Legal provisions relating to confidentiality clauses in corporate mergers

1. How must confidentiality clauses in corporate mergers comply with legal regulations on personal data protection?

In corporate merger transactions, confidentiality clauses involving personal data must strictly comply with the Law on Personal Data Protection 2025, particularly the following provisions:

  • Principles of data processing: Under Clauses 2 and 4 Article 3, personal data may only be collected and used within the defined scope and purposes, and appropriate technical and management measures must be implemented to protect data and prevent leakage or misuse during M&A due diligence and negotiations.
  • Rights of data subjects: Under Clauses 1 and 2 Article 4, data subjects have the rights to be informed, consent, withdraw consent, request deletion, or restrict data processing. Therefore, confidentiality clauses in mergers must establish clear mechanisms for receiving and implementing such rights.
  • Prohibited acts: Under Clauses 4 and 7 Article 7, unlawful processing of personal data, as well as acts of appropriation, disclosure, or loss of personal data, are prohibited.
  • Data transfer in corporate mergers: Under Point c Clause 1 Article 17, the transfer of personal data in cases of corporate mergers is considered lawful, provided that it complies with applicable laws and is not treated as the sale of data.

2. If confidentiality clauses in corporate mergers involve customers’ personal data, what regulations on data processing must be complied with?

Where confidentiality clauses in corporate mergers involve customers’ personal data, the processing of such data must strictly comply with the provisions of the Law on Personal Data Protection 2025, specifically as follows:

  • Customers’ rights over personal data: Under Clause 1 Article 4, customers have the right to be informed, correct, delete, restrict processing of, or object to the processing of their personal data.
  • Customer consent: Under Clauses 2 and 4 Article 9, personal data may only be lawfully processed with the clear and voluntary consent of the data subject.
  • Collection and use of data: Under Clause 1 Article 11, personal data may only be collected with the consent of the data subject, except where otherwise provided by law.
  • Data transfer in mergers: Under Point c Clause 1 Article 17, the transfer of personal data in cases of corporate mergers is lawful but must be implemented for proper purposes, without altering the nature of the intended data use, and while ensuring information security.
  • Obligations relating to confidentiality and data security: Under Clauses 1 and 2 Article 37, both data controllers and data processors are responsible for implementing technical and organizational measures to protect data, prevent unauthorized access, and bear liability in cases of violations.

3. What legal consequences commonly arise when a party breaches confidentiality clauses in a corporate merger?

Breaches of confidentiality clauses in corporate mergers, particularly where personal data is involved, may result in serious legal consequences under the Law on Personal Data Protection 2025, including:

  • Administrative sanctions: Under Clauses 1 and 5 Article 8, organizations and individuals violating regulations on personal data protection may be subject to administrative sanctions, with fines of up to 3 billion VND for ordinary violations in this sector.
  • Criminal liability: Under Clause 1 Article 8, where the violation shows signs of criminal conduct such as appropriation, trading, disclosure, or unlawful use of personal data, the violating party may be subject to criminal prosecution in accordance with criminal law provisions.
  • Liability for damages: Under Clause 1 Article 8, parties causing damage to data subjects or related parties through violations must fully compensate for damages in accordance with civil law.
  • Remedial measures: Under Clause 4 Article 23, competent authorities may require cessation of the violation, implementation of remedial measures, recovery, or deletion of unlawfully processed data in order to minimize risks spreading throughout the M&A transaction.
  • Impact on the merger transaction: in practice, confidentiality breaches may also lead to suspension or cancellation of the transaction, or contractual disputes arising from violations of confidentiality obligations undertaken in the M&A agreement.

IV.  Questions regarding confidentiality clauses in corporate mergers

1. Should a confidentiality clause in a corporate merger transaction include procedures for notification in the case of a data security breach? Why?

A confidentiality clause in a corporate merger transaction should expressly provide for notification procedures in the case of a data security breach, as it constitutes a mandatory legal obligation and plays a critical role in risk management in practice.

Specifically, pursuant to Clause 1 Article 23 of the Law on Personal Data Protection 2025, where a personal data breach is detected and such breach may affect the lawful rights and interests of data subjects, the data controller or data processor must notify the competent authority within the prescribed timeframe and coordinate in handling the incident. In addition, based on Clause 4 Article 23, relevant parties are obligated to cooperate in preventing violations and remedying consequences immediately upon discovering any data-related incident.

2. When drafting a confidentiality clause for a merger involving foreign-invested enterprises, what conditions under investment law should be taken into consideration?

When drafting a confidentiality clause in a merger transaction involving foreign-invested enterprises, particular attention must be paid to compliance with regulations governing conditional business investment sectors and market access conditions applicable to foreign investors under the Law on Investment 2025. Specifically:

  • Pursuant to Clause 1 Article 7 of the Law on Investment 2025, where a business activity falls within a conditional business investment sector, the implementation of investment activities, including M&A transactions and information processing during the merger process, must satisfy all statutory conditions imposed for reasons of national defense, security, public order, social safety, and public health. Therefore, the confidentiality clause must not be drafted in a manner exceeding the legally prescribed business conditions.
  • Pursuant to Clause 2 Article 7, investment conditions may only be prescribed by laws, resolutions of the National Assembly, ordinances, Government decrees, or international treaties. Accordingly, confidentiality commitments in merger transactions must not create conditions contrary to or beyond those prescribed by law for conditional business sectors.
  • Pursuant to Clause 1 Article 8 of the Law on Investment 2025, foreign investors are generally entitled to market access conditions equivalent to domestic investors unless otherwise restricted. Therefore, the sharing, transfer, or processing of data during a merger transaction must remain within the scope of permissible market access.
  • Further, under Clause 3 Article 8, market access conditions may include limitations on investment activities, ownership ratios, or requirements concerning business partners. Accordingly, confidentiality clauses must ensure that the rights of foreign investors to access information are not expanded beyond statutory limitations.

3. How should confidentiality clauses in corporate merger transactions regulate dispute resolution mechanisms and compensation under current law?

In merger transactions, confidentiality clauses should establish clear dispute resolution mechanisms and compensation obligations to ensure enforceability and legal certainty in any case of a breach.

  • Regarding dispute resolution mechanisms: The clause should ideally provide for a tiered dispute resolution process, prioritizing good-faith negotiation between the parties. If no settlement is reached, it can be handled through commercial arbitration or competent courts. 
  • Regarding liability for damages: Under Article 13 and Article 360 of the Civil Code 2015, a party breaching confidentiality obligations must compensate for damages where all required elements are satisfied, including: The existence of a breach, actual damages, a causal relationship between the breach and the damages, and fault on the part of the breaching party. 
  • Regarding contractual sanctions (if agreed): Under Article 418 of the Civil Code 2015, the parties may agree on contractual sanctions in addition to compensation for damages, provided that the amount is expressly stipulated in the agreement to avoid future disputes concerning enforcement.

4. If unauthorized use of trade secrets is discovered after a merger due to the absence of a proper confidentiality clause, what legal remedies are available?

Where unauthorized use of trade secrets arises after a merger due to the absence of, or deficiencies in, confidentiality provisions, the affected enterprise may pursue the following legal remedies:

  • Request cessation of the infringing acts and seek urgent interim measures: The aggrieved party may require the infringing party to immediately cease using, exploiting, or disclosing the trade secrets and may also request the application of interim urgent measures under civil procedural law to prevent further damages.
  • Initiate legal proceedings for damages: Under Articles 584 and 585 of the Civil Code 2015, any person causing damage through infringing acts must compensate for all actual losses incurred. Such damages may include financial losses, lost profits, and costs incurred in mitigating consequences.
  • Request handling under competition law and intellectual property law: Unauthorized use of trade secrets may be handled as an act of unfair competition involving misappropriation of confidential business information, while mechanisms for protection of intellectual property rights in trade secrets may also apply.
  • Review liabilities arising within the M&A transaction itself: If the breach originates from confidentiality obligations during the merger process, the parties may review the M&A agreement to determine liabilities arising from contractual breaches and apply contractual sanctions or claim compensation (if agreed).

V. Are you looking for a reputable legal expert to assist with issues relating to confidentiality clauses in corporate mergers?

In mergers and acquisitions transactions, the drafting and management of confidentiality clauses play a critical role in protecting trade secrets, customer data, and minimizing legal risks following the transfer of ownership and operations.

NPLaw is a specialized legal advisory firm in the areas of corporate law, investment, and M&A transactions, regularly assisting clients in reviewing agreements, designing confidentiality clauses, establishing post-merger data-processing mechanisms, and handling disputes arising from merger transactions. With extensive practical experience in corporate transactions, NPLaw helps ensure that confidentiality clauses are drafted comprehensively, comply with applicable laws, and remain practical and enforceable in implementation.

The above information is provided for reference purposes only. Should you require detailed advice regarding a specific case, please contact NPLaw for immediate legal assistance.