Confidentiality Agreement for Selling a Business: Customer Data
On this page 4 sections
The buyer has signed a confidentiality agreement and now wants a raw customer export, customer names, or copies of customer contracts. The agreement governs the evaluation, but signing it alone doesn’t determine how much customer data you should provide.
Ask what the buyer needs to verify, then choose the least-exposing format that still gives a reliable answer. To test customer concentration, the buyer may need revenue by account without the names. To review a contract term, it may need a redacted executed copy rather than the full agreement.
Summaries, customer codes, masking, redaction, staged release, and data-room permissions can reduce exposure. None guarantees anonymity or legal compliance, especially when the buyer can combine records to identify a customer. Take extra care if the buyer competes with your company or the intended viewers work in day-to-day competitive roles.
Your agreement, the transaction facts, and applicable privacy and competition laws set the boundaries. Within them, decide what to provide, who should see it, and what will happen to every copy if the sale ends.
When should you disclose customer names to a buyer?
Start with aggregated, coded, or redacted evidence. Hold customer names until the buyer explains why it needs them; no milestone automatically unlocks those identities.
Use transaction milestones to reconsider access rather than grant it automatically. In Morgan & Westfield’s buyer-screening process, an NDA and information memorandum come first, more financial information may follow, and fuller diligence comes after an LOI. Its confidentiality guidance says a seller may hold customer or employee names until late in diligence or, in some deals, until after a definitive agreement. That sequence can help you stage the decision, but it doesn’t set the timing for your sale.
A name connects otherwise limited figures to a live commercial relationship. A coded schedule may show that your largest customer represents a material share of revenue. Add the name, pricing, discounts, contract terms, sales opportunities, or projections, and the buyer has customer-specific intelligence instead of an anonymous concentration figure. That matters most when the buyer competes with your company.
Ask which diligence issue the identities will resolve and why coded or redacted information falls short. The answer separates necessary verification from convenience and helps limit the detail traveling with the name. The buyer may need the identity without also receiving account-level pricing, projections, or opportunity data.
Test masking across the whole diligence file. The Tower International clean-team agreement, for example, barred reports from including details that would let people outside the clean team work backward to customer-specific information. Several limited records may reveal an account together even when none names it alone.
Once the buyer has justified access to customer identities, decide who actually needs to see them.
Who inside the buyer’s organization should see customer data?
Don’t open the file to the buyer’s entire organization. Let a limited group inspect the underlying customer data and give the wider deal team only a cleaned report or approved summary. Set those roles before uploading the detail; a later restriction can’t undo access already given.
The Calpine and LS Power agreement allowed representatives to receive information if they participated directly in the evaluation or needed it for that purpose. Other transactions created a clean team: a screened group allowed to inspect sensitive detail while other buyer personnel received approved summaries or redacted conclusions.
Under the Tower International agreement, the wider team could receive reports after the clean team summarized, aggregated, redacted, or otherwise cleaned customer information and outside antitrust counsel reviewed the result. A Skullcandy and Incipio agreement separated detailed pricing, volume, discounts, rebates, margins, costs, and opportunities from counsel-approved summary or aggregate information.
The Sharps clean-team agreement excluded people in specified day-to-day competitive roles while they had access to clean-team information. Other buyer personnel could receive reports only after aggregation or redaction and outside antitrust-counsel approval. These filed agreements governed their own transactions; they don’t prescribe the structure for another sale.
We would settle four questions before detailed customer information moves: Who needs the raw detail? What decision will that person make? What output can the wider buyer team receive? Who checks it before it leaves the controlled group?
A clean team is one possible control, not an automatic requirement or guarantee. If the buyer competes with your company, ask qualified advisers to assess the material and intended viewers as part of your broader plan for selling a business to a competitor.
Control downloads as well as viewers. FTC staff identifies download limits as one possible safeguard in competitor diligence, but a restriction can’t retrieve earlier downloads, working copies, email attachments, or reports made from the data. Each new recipient or copy gives you more to find and control if the deal ends.
What happens to customer data if the sale does not proceed?
Closing the data room ends one route to the information. It doesn’t retrieve downloaded files, remove attachments from inboxes, or locate reports and working copies built from customer data.
Plan the closeout before releasing the information. Read the agreement’s return, destruction, and retention provisions for the trigger, timing, and copies covered. The Calpine agreement used a 30-day return-or-destroy process after a written request. The Sharps agreement required return or destruction where technically and reasonably possible, with exceptions for certain archives. The Tower agreement addressed documents, reports, and backup material separately. Your agreement may treat working copies and archives differently.
If the deal fails, follow the information wherever it went. Cooley’s guidance on failed M&A diligence explains that a recipient may need to separate confidential files and emails from ordinary internal material, then collect, sequester, return, or destroy them under the governing obligations.
- End active access to the data room and shared systems.
- Identify downloads, email attachments, reports, and working copies containing customer information.
- Apply the agreement’s return, destruction, sequestration, or retention terms.
- Treat backup or archival material separately from ordinary working copies when the agreement does.
We would start by finding every copy that left the data room, then follow the agreement’s terms for each one.
Filed confidentiality agreements and legal guidance10 sources
- American Bar Association — Trade Secret Diligence in Mergers and Acquisitions
The progressive incremental disclosure concept and the limited-purpose evaluation context for sensitive information. Limit: The practitioner article is not a model agreement, legal opinion, or universal rule for customer-identity disclosure. Accessed 2026-08-17.
- Morgan & Westfield — Maintaining Confidentiality in M&A
Aggregation, redaction, staged release at transaction milestones, and later disclosure of customer or employee names. Limit: The advisory firm describes its process, not what another agreement permits or when every seller must disclose identities. Accessed 2026-08-17.
- Federal Trade Commission — Avoiding Antitrust Pitfalls During Pre-Merger Negotiations and Due Diligence
Fact-dependent use of aggregation, redaction, masking, screened recipients, staging, download limits, and operational closeout. Limit: The non-exhaustive staff guidance provides no safe harbor or transaction-specific antitrust conclusion. Accessed 2026-08-17.
- Goodwin — Antitrust and Your Deal—Pre-Closing
Redaction of customer names, pricing, material nonstandard contract terms, and sensitive customer-specific information before closing. Limit: The law-firm guidance is not a universal rule, counsel clearance, or a release sequence for every transaction. Accessed 2026-08-17.
- Morgan & Westfield — Process for Screening Buyers When Selling a Business
A practitioner sequence in which an NDA and information memorandum precede additional financial information, LOI, and fuller diligence. Limit: The process is one advisory firm’s practice and does not create a disclosure entitlement or universal calendar. Accessed 2026-08-17.
- U.S. Securities and Exchange Commission — Tower International Clean Team Confidentiality Agreement
Transaction-specific treatment of customer information, re-identification risk, cleaned reports, designated viewers, and backup material. Limit: The filed agreement is not a template, market standard, legal recommendation, or rule for another sale. Accessed 2026-08-17.
- U.S. Securities and Exchange Commission — Calpine and LS Power Confidentiality Agreement
Transaction-specific limits to representatives involved in the evaluation and a written-request return-or-destroy process. Limit: The filed 2014 agreement is not a current market standard, model, or recommendation for another transaction. Accessed 2026-08-17.
- U.S. Securities and Exchange Commission — Skullcandy and Incipio Clean Team Agreement
Separation of detailed customer and vendor information from approved summary or aggregate outputs for selected buyer personnel. Limit: The transaction-specific agreement does not establish that its categories, counsel process, or clean-team structure govern another sale. Accessed 2026-08-17.
- U.S. Securities and Exchange Commission — Sharps Clean Team Confidentiality Agreement
Exclusion of specified day-to-day competitive roles, cleaned reports, and technically reasonable return or destruction with archive exceptions. Limit: The filed 2022 agreement is transaction-specific and supplies no universal clean-team or closeout requirement. Accessed 2026-08-17.
- Cooley — From Negotiation to Litigation—Limiting Trade Secret Liability When M&A Deals Fail
Locating, separating, collecting, sequestering, returning, or destroying confidential working copies after failed diligence. Limit: The guidance does not state what the reader’s agreement requires or establish that complete deletion is possible. Accessed 2026-08-17.
Read the editorial standards or report a correction.