Article, Series
17 min read

1. Why tech deals are different

31 August 2026

Introduction to The Tech Deal series

In most deals you can point at what the purchaser is buying. Premises, equipment, stock, a fleet, a licence on a register. In tech deals you cannot: the value sits in assets you can’t touch, may not fully own, and sometimes can’t transfer.

Here is what that means in practice. A purchaser agrees to pay eight times revenue for a software company. Then three things surface. The component underneath the fastest-growing part of the product is licensed for on-premise use only, so the cloud migration the growth case rests on falls outside the field of use the licensor agreed to. Part of the core code was written by freelancers who never assigned their intellectual property (IP) rights. And the dataset that carries most of the value was assembled without a firm legal basis, so it may not lawfully be used for what the purchaser bought it to do. None of this was in the information memorandum (IM) or on the balance sheet. All of it was findable in week two of diligence. The gap between the price and what actually transfers is the subject of this series.

A quick word on where I sit, because it shapes the series. I’m a corporate M&A lawyer in Amsterdam, and I usually get the call when a term sheet is taking shape and someone has to turn intentions into a transaction. For two years before returning to private practice I was head of legal at a listed IT group, running its M&A and its buy-and-build programme from the inside. The in-house vantage point is different: you are there long before a term sheet exists, and still there long after closing, when the company has to live with the negotiated outcome and operates and integrates what it bought.

The series is written from the deal table rather than from either side, and follows a tech transaction in the order it happens. Letter of intent (LOI), valuation, due diligence, the share purchase agreement (SPA) and the risk allocation it contains, warranty and indemnity (W&I) insurance, and closing. Then buy-and-build, preparing for an exit, and the disputes that may arrive no matter how clearly the SPA was drafted. Along the way I’ll bring in people who sit in other chairs: a private equity investor who prices, acquires and builds these businesses, a technical diligence specialist who assesses the codebase, the architecture and the engineering capability behind it, and a W&I broker who negotiates the policy and sees where the claims land.

Four companies travel through the series as worked examples. They are fictional, composites of patterns across the Dutch market, and the full note is at the foot of this post*. Nevelo is a VC-backed SaaS scale-up with an annual recurring revenue (ARR) story and a new AI assistant. Deverel Software is a founder-owned software house from 2002, perpetual licences and a codebase that lives in the founder’s head, and whose IT contracts were last checked by a lawyer in 2014. Quantiro is an AI pricing platform whose real asset is its dataset. Velmeth Systems is the reminder that tech isn’t only software: a photonics manufacturer that may count as “sensitive technology”. Same three questions for all four: what is the asset, do you own it, and will it transfer?

The three properties

Three characteristics do the work, and every distinctive feature of a tech transaction traces back to one of them.

Intangibility

The core assets are code, datasets, trade secrets, know-how: things that can’t be counted or inspected the way you count machines or inventory. A warehouse can be walked through and a production line can be watched running. You can stand in the data centre and learn nothing at all, because the racks say nothing about what runs on them, who wrote it, whether it does what the company says it does, or whether the service stays up when one of them fails. Answering that takes a code audit, an architecture review, and in the end some reliance on the engineers who built it. What the purchaser is buying is a description of something it cannot see, and the whole diligence exercise is an attempt to test the description in the IM.

Possession is not title

Even where the asset exists and is used daily, title may be cloudy or split. Parts of Deverel’s core product were written between 2003 and 2012 by nine freelancers who never signed IP assignments, and by default under Dutch copyright law that code belongs to them, not to the company. Nobody at Deverel has thought about it in twenty years. Why would they, the software works and nothing has ever happened to make anyone look: no complaint, no claim, no freelancer coming back.

A purchaser’s lawyer will think about it in week two of diligence. The same question runs the other way, into the components and services the product is built on but does not own. The company has the asset in hand; the title is complicated.

Transfer relies on third party cooperation

Change-of-control clauses let customers walk on a sale. Nevelo has two enterprise customers, together 14% of its ARR, with precisely that right. Customers rarely invoke the right for the change of control alone, but they often use it as a bargaining chip. Licensed IP may not be reassignable without the licensor’s consent, and a licence written for one deployment model rarely stretches to the next. Quantiro’s dataset was partly assembled without a clear legal basis, and that defect travels with the data, so what the purchaser acquires is the revenue and the exposure in one asset.

And the people who built the code can’t be transferred by contract at all. They can only be persuaded to stay. Retention packages, vesting, non-competes: terms that exist because the most valuable asset has a notice period.

The four arenas

These three properties show up in four places in every tech deal.

Valuation

Traditional M&A runs on a settled measure: a multiple of EBITDA. The EBITDA definition is usually heavily negotiated because every wording change moves the price. Tech deals are no different, only the abbreviation is shorter. ARR is where the valuation fight happens. A growing software company is priced on revenue instead, and more precisely on annual recurring revenue, weighted for how fast customers leave (churn) and how much existing customers grow (net revenue retention).

That sounds like a finance question. It is also, and perhaps mainly, a drafting question. From the moment a multiple attaches to “recurring revenue”, the negotiation compresses into one question: what counts as recurring?

One number shows why. Suppose Nevelo’s AI assistant, priced per use rather than per subscription, generates €750,000 a year. Is that recurring revenue? At a multiple of eight, that single classification question is worth €6 million. Both figures are illustrative; the mechanism is not. No clause in the SPA is fought over harder than that definition, and it is routinely settled in the wrong document. A purchaser meets this problem once per deal, always at the same moment. The multiple and the metric go into the LOI in a single line; the definition waits for the SPA, by which point the price is anchored and defining recurring revenue properly reads as a retrade rather than as drafting. Which is precisely the argument the seller will make.

A separate point is that purchasers in this sector defer more of the price than in any other. In the 2026 CMS European M&A Study, earn-outs appear in 44% of technology, media and communications deals, 12 percentage points up in a single year and the highest of any sector, against a 27% average across the study’s 601 European transactions. The legal fights that follow are usually about shape more than size: whether the deferred slice pays gradually on a pro rata basis or only on hitting a predefined threshold, and what the purchaser must do or cannot do with the business while the earn-out period runs, holding the controls while the seller holds the exposure. We’ll spend three posts in the valuation arena and later in this series on the earn-out mechanism as well.

The due diligence investigation

Due diligence on a traditional target is mainly a legal, financial and tax exercise. On a tech target it has a fourth dimension: the technology itself. Serious purchasers scan the codebase, audit the architecture and review security posture, and those findings land on the deal table next to the legal ones. Technical debt becomes a price discussion and a line in the purchaser’s investment case, because nobody rebuilds an architecture between signing and closing. I have seen a deal stop there. Legal and financial diligence came back clean; the technical review found debt deep enough that the purchaser walked away. What a set of warranties cannot do is stand in for the review itself. A warranty allocates the consequences of something turning out to be untrue; it cannot tell a purchaser whether the architecture will carry the growth plan it is paying for. That question has to be looked at by someone qualified to look, and no amount of contractual drafting substitutes for having done so.

The legal workstream, meanwhile, organises itself around four pillars. None of the four is unique to technology. What changes is the weight: in a tech deal these four workstreams are the subject matter.

  • IP ownership. Does the company own the code its developers and freelancers wrote, the patents on its file, and the know-how that makes the product work? At Deverel the honest answer is: only partly.
  • Licences, in both directions. Inbound: the open-source components and platform services the product is built on, each with terms nobody has read since 2014. Outbound: the customer contracts the revenue sits in, some giving the customer rights precisely when the company is sold. Either side can hold the deal hostage.
  • Data and privacy. Half of Quantiro’s valuation is its dataset. Was it lawfully built, and may it lawfully be used for what the purchaser plans to do with it? A dataset assembled without a proper legal basis is a liability with a valuation attached.
  • AI. Who owns AI-generated code, may Nevelo train its assistant on customer data, and what has the company contractually committed to customers about what the assistant will do?

Each of the four gets its own post in the diligence module, and each returns at the SPA stage. The technical workstream becomes a fifth there: the lawyers do not run that review, but they decide what the contract does with what it finds.

Regulatory aspects, in two layers

For decades the only regulator at the average Dutch M&A table was the competition authority, the Autoriteit Consument & Markt, and only above turnover thresholds most tech deals never reached. That has changed. In a tech deal there is now a real chance that someone who is not a party to the transaction decides whether it completes, and when. The risk arrives in two very different shapes.

The first layer is deal-shaping: national-security investment screening. The Netherlands screens acquisitions of companies holding “sensitive technology”, a category expected to widen from 2027 to include artificial intelligence and biotech among others, alongside existing categories such as quantum, semiconductors and photonics. The regime is young and its perimeter is still moving, which is why it is the arena deal teams are least practised at spotting. A second, sectoral track sits beside it for telecommunications, catching companies that would never call themselves telecoms operators; other regulated sectors have tracks of their own. For Velmeth a filing is near certain and shapes the whole timetable; for most B2B software it does not bite at all. You can’t know which without running the analysis, and that belongs in the first week. A required filing is not something a deal can close around. The transaction stands still until clearance arrives, and completing without it exposes the parties to penalties and to the acquisition being unwound. Post #6 runs the regulatory triage.

The second layer is broad and close to universal: the compliance rulebook. The GDPR has been the floor since 2018 and is no longer the only one, with the Data Act, the NIS2 cyber rules, the Cyber Resilience Act and the AI Act on top of it, each on its own timetable and some still phasing in. These rarely stop a deal, but they shape what diligence finds, what the warranties must cover, and sometimes the price. Each is treated in its own right later in this series, rather than scattered through it. Screening decides whether a deal completes. These rules decide what the business may do afterwards. Most targets were built before they existed, so the question is not only whether the company is compliant today but whether the roadmap the purchaser is paying for survives contact with them. A purchaser who finds out afterwards has paid for a roadmap it now has to redraw, and carries the exposure for whatever ran non-compliant in the meantime.

The contract

The SPA is where diligence findings become some party’s problem in writing. Once each workstream reports, the purchaser has to decide, finding by finding, what it simply accepts, what it wants reflected in the price, what it takes a warranty on, what it wants indemnified, what goes into escrow, and what has to be fixed before closing or committed to afterwards, all within the commercial reality of what a seller is willing to accept based on the agreed LOI. Two of those instruments are routinely confused. A warranty is a statement about the business that gives the purchaser a claim if it proves untrue, so it carries what nobody found. An indemnity takes a risk both sides already know about, names it, and says who pays. Disclosure is what moves a problem from the first to the second, and it cuts both ways: it takes the issue outside the warranty, so the seller has every reason to disclose, and it leaves the purchaser with no cover on that point until it negotiates a specific indemnity which the seller will try to resist or minimise. What the purchaser gets in exchange is the information itself. Five posts in this series do exactly this: take one diligence workstream at a tech target at a time and work out how its findings translate into the SPA.

Why this matters, whichever chair you sit in

None of this is a niche concern. Technology, media and communications is the largest single sector in European dealmaking, and has been for several years running: Mergermarket recorded 3,872 TMT transactions across EMEA in 2025, more than any other sector and roughly a fifth of everything announced.

From the purchaser’s chair, and especially that of a fund pursuing buy-and-build, the four arenas compound. You are building a repeatable process, and a flaw in the platform does not stay the size it was. If the platform you are bolting add-ons onto has faulty IP ownership, licences that restrict freedom to operate, or a dataset or model with bad provenance, you have not bought a platform. You have bought a liability that expands with every acquisition, and a diligence approach that wrongly assumes the target owns its code will fail serially rather than once. And unlike a competition filing, investment screening looks at the target alone rather than at the combined business, and it has no turnover threshold. So it is not an analysis you run once for the platform. It runs again on every add-on, however small, and any one of them may turn out to be notifiable. That changes the structure of that deal, its timetable and what it costs to do. On a bolt-on scoped to sign and close in six weeks, a clearance period sets the timetable.

From the seller’s chair the same list reads as a preparation checklist. Every issue above is cheaper to fix twelve months before a process than twelve days into one. Quantiro’s provenance problem can’t easily be repaired, but the seller can quantify and price it before the purchaser does. Deverel’s freelancer code is fixable, and what each signature costs depends on when it is asked for. A freelancer still on the payroll is a phone call. One who left eight years ago, asked while a purchaser’s lawyer waits on the answer, is a negotiated cheque. The founder has known for two years. He hasn’t started.

That is the view from the purchaser’s chair and from the seller’s. Here is mine. Before any legal analysis I want a working picture of the thing itself: what the software does, which parts the company built and which it assembled elsewhere, where the data comes in and where it goes, and what it depends on to keep running. The business case goes on top of that, not the other way round, because commercial descriptions tend to be vague in exactly the places the contract has to be precise. My own test is whether I can explain it back to the CTO in plain words without being corrected. It is the quickest way I know to surface what the technical people assumed was obvious and never said.

Then I work backwards from what the purchaser plans to do with it after closing. Diligence tests the documents against what the target does today; they also have to be tested against what it does not do yet and what the purchaser intends to do. The seller’s plan is not the purchaser’s plan, and every licence and consent in the data room was written for the seller’s current one.

Where it starts: week one, not week four

The four arenas share one feature: they reward whoever runs the analysis early. Before your next tech deal moves past the LOI, four questions belong in week one.

  • What is the right metric for this business (ARR, usage, maintenance, EBITDA), and do you want it defined in the LOI or deliberately left open until diligence has reported? Either is defensible, provided you have anticipated the pros and cons. Leaving it undecided is not.
  • Does the company actually own what it sells, the code, the data, the models, or does it depend on freelancers, licences and APIs it doesn’t control?
  • Will those assets move with the deal, or do change-of-control rights, licence consents or data-use limits stand in the way?
  • Does the target touch a screened technology, under the sensitive-technology rules or a sectoral regime?

Answered early, most of what follows in this series is preparation. Deferred, the same four questions return as a price chip, a contractual risk allocation, a closing condition, or a claim.

These are practitioner’s letters, not legal advice. The aim is that you recognise the issues early enough to ask the right questions. One sentence will keep coming back, so I’ll leave it here: in tech M&A, the value sits in assets you can’t touch, may not fully own, and sometimes can’t transfer. The four questions above are the ones that decide how much of that value actually arrives. Ask them in week one, and the rest of this series is preparation. See you at Post #2, the LOI.

*The four companies in this series are fictional: composites of patterns across the Dutch market, not portraits of any real business. Their problems, however, are entirely real.

Back
1. Why tech deals are different