Single Blog Title

This is a single blog caption

Legal Due Diligence in Turkish M&A Transactions: Corporate Records, Hidden Liabilities, Data Protection and Deal Protection

Introduction

Legal due diligence is one of the most important stages of acquiring shares, assets or a business in Turkey. Its purpose is not merely to confirm that the target company exists. A properly conducted review should identify the rights the buyer will acquire, the liabilities that will remain within the target company and the legal obstacles that may prevent or delay completion.

In a share acquisition, the legal identity of the target company ordinarily remains unchanged. Its existing debts, contracts, employees, licences, disputes and regulatory exposure therefore remain within the company after the shares are transferred. The buyer may acquire not only an operating business but also historical liabilities that were not reflected accurately in the financial statements.

In an asset acquisition, the buyer may select specific assets and liabilities. However, the transfer of real estate, vehicles, contracts, intellectual property, licences and employees may require separate legal procedures.

Legal due diligence should therefore be designed according to the proposed transaction structure, the target’s business sector, the buyer’s commercial objectives and the risks that may affect the purchase price.

What Is Legal Due Diligence?

Legal due diligence is the systematic examination of a target company, business or asset before a transaction is completed.

The review generally seeks to determine:

  • Whether the seller legally owns the shares or assets;
  • Whether the seller has authority to complete the transaction;
  • Whether the target company has been properly established and managed;
  • Whether its corporate decisions are valid;
  • Whether shares are pledged, attached or subject to third-party rights;
  • Whether the company has undisclosed debts or legal exposure;
  • Whether material contracts will continue after the transaction;
  • Whether regulatory approvals are required;
  • Whether the target owns the assets and intellectual property it claims to own;
  • Whether the purchase price should be reduced, retained or protected through indemnities.

Due diligence is not intended to replace financial, tax or technical review. The most effective process coordinates legal findings with financial, accounting, tax, operational, environmental and commercial investigations.

Buy-Side and Sell-Side Due Diligence

Due diligence may be conducted for the buyer or the seller.

Buy-side due diligence

Buy-side due diligence is carried out on behalf of the prospective purchaser. Its objective is to identify legal risks before the buyer becomes contractually committed or before the purchase price is paid.

The buyer’s lawyers examine the documents provided by the seller, conduct public registry searches, submit questions and prepare a report identifying material risks.

The findings may affect:

  • Whether the transaction proceeds;
  • The transaction structure;
  • The purchase price;
  • Closing conditions;
  • Seller warranties;
  • Specific indemnities;
  • Escrow or retention arrangements;
  • Post-closing undertakings.

Vendor due diligence

Vendor due diligence is conducted for the seller before the company is offered to potential purchasers.

The process may identify deficiencies that can be corrected before the sale, such as:

  • Missing corporate resolutions;
  • Inaccurate share ledgers;
  • Unregistered intellectual property;
  • Expired licences;
  • Informal related-party agreements;
  • Unresolved employee issues;
  • Missing contract signatures;
  • Incomplete data-protection documentation.

A vendor report may also provide several bidders with a common information base. However, buyers will normally still conduct their own verification and may not rely exclusively on the seller’s report.

Establishing the Scope of Review

The due diligence scope should be determined before the virtual data room is opened.

A complete review of every document may be unnecessary for a small transaction but essential in a regulated or high-value acquisition. The parties may apply materiality thresholds based on:

  • Contract value;
  • Annual revenue;
  • Number of employees;
  • Litigation amount;
  • Asset value;
  • Regulatory significance;
  • Duration of contractual obligations;
  • Strategic importance.

Certain matters should not be excluded merely because their immediate monetary value appears limited. For example, an invalid licence, unresolved ownership dispute or unlawful processing of customer data may threaten the continuation of the business.

The review period should also be defined. Corporate records may require examination from incorporation, while commercial contracts and litigation may be reviewed for a more limited period.

The Data Room and Document Request List

The seller generally provides documents through an electronic data room. The data room should be organised according to clearly defined categories and contain complete, current and searchable documents.

A typical request list covers:

  • Corporate records;
  • Shares and shareholders;
  • Financial and tax documents;
  • Material contracts;
  • Employment;
  • Litigation and enforcement;
  • Real estate and leased premises;
  • Intellectual property and technology;
  • Licences and regulatory matters;
  • Data protection;
  • Insurance;
  • Environmental matters;
  • Related-party transactions;
  • Financing and security;
  • Compliance.

Documents should not be uploaded without explanation. The seller should disclose missing documents, expired arrangements, oral agreements and matters that are not recorded in formal corporate files.

The buyer should also verify important information independently rather than relying solely on the data room.

Corporate Status and Trade Registry Review

The corporate review confirms the target company’s legal existence, ownership structure and decision-making history.

The Turkish Commercial Code No. 6102 regulates commercial companies, corporate bodies, share capital, management, representation, statutory books, mergers, demergers and company liability. Corporate records should therefore be checked against both the law and the company’s articles of association.

The review commonly covers:

  • Articles of association and amendments;
  • Trade registry certificates;
  • Turkish Trade Registry Gazette announcements;
  • MERSİS records;
  • Share ledger;
  • General assembly resolutions;
  • Board or managers’ resolutions;
  • Signature circulars and declarations;
  • Statutory commercial books;
  • Capital increase and reduction documents;
  • Share certificates;
  • Shareholder agreements;
  • Beneficial ownership information.

MERSİS is the central electronic system used for company and commercial enterprise registration procedures and for maintaining central registry information. Publicly accessible registry information should be compared with the records provided by the target. (Ticaret Bakanlığı)

Verification of Share Ownership

The buyer must confirm that the seller validly owns the shares and has the legal power to transfer them.

The review should determine:

  • Whether the shares were validly issued;
  • Whether the capital was fully paid;
  • Whether share certificates exist;
  • Whether shares are registered or bearer;
  • Whether bearer-share notifications were completed;
  • Whether the seller is recorded in the share ledger;
  • Whether the shares are pledged, attached or subject to usufruct;
  • Whether transfer restrictions apply;
  • Whether another shareholder has a pre-emption or first-refusal right;
  • Whether third-party approval is required.

For limited liability companies, the transaction documents should be examined in light of the statutory written-form, notarisation and general assembly approval requirements.

For joint-stock companies, the type of share, existence of share certificates, articles of association and share-ledger records may materially affect the transfer procedure.

Corporate Authority and Representation

A company may have validly appointed directors or managers but defective representation records.

The review should verify:

  • Current board members or managers;
  • Duration of their appointments;
  • Representation powers;
  • Joint or individual signature rules;
  • Internal directives;
  • Registered authorised representatives;
  • Limitations on signing authority;
  • Powers of attorney;
  • Bank signatories.

A transaction signed by a person without proper authority may create validity or enforcement disputes. The buyer should also ensure that former directors, managers and bank users will lose access at closing where control is changing.

Capital and Shareholder Funding

The buyer should determine whether the target has outstanding capital commitments or informal shareholder financing.

The review should cover:

  • Paid and unpaid capital;
  • Shareholder loans;
  • Capital advances;
  • Additional payment obligations;
  • Related-party debts;
  • Dividends declared but not paid;
  • Unlawful distributions;
  • Shareholder withdrawals;
  • Guarantees given for shareholders or affiliates.

Amounts presented as shareholder loans should be supported by written agreements and banking records. Informal funding arrangements may later be characterised differently for tax, corporate or insolvency purposes.

Material Commercial Contracts

Material contracts often determine whether the target’s business will continue after the acquisition.

The buyer should review:

  • Customer agreements;
  • Supplier and distribution agreements;
  • Agency agreements;
  • Franchise agreements;
  • Licensing and technology agreements;
  • Construction and service contracts;
  • Lease agreements;
  • Outsourcing arrangements;
  • Consultancy agreements;
  • Government contracts;
  • Financing documents;
  • Guarantees;
  • Settlement agreements.

Particular attention should be given to provisions concerning:

  • Change of control;
  • Assignment;
  • Prior consent;
  • Termination;
  • Exclusivity;
  • Minimum purchase commitments;
  • Price adjustment;
  • Automatic renewal;
  • Penalties;
  • Liability limitations;
  • Non-compete obligations;
  • Governing law;
  • Arbitration and jurisdiction.

A share transfer may not technically assign the target’s contracts because the contracting entity remains the same. Nevertheless, change-of-control clauses may allow the counterparty to terminate, renegotiate or require consent.

Related-Party Transactions

Transactions between the target and its shareholders, directors, group companies or family members require special scrutiny.

These may include:

  • Loans;
  • Management services;
  • Property leases;
  • Trademark licences;
  • Procurement arrangements;
  • Cash-pooling;
  • Employee secondments;
  • Guarantees;
  • Asset transfers;
  • Informal expense allocations.

The buyer should determine whether these arrangements are on arm’s-length terms and whether they will continue after closing.

Where the target depends on property, personnel, intellectual property or services supplied by the seller’s group, transitional arrangements may be required. Otherwise, the acquired company may lose essential operational support immediately after closing.

Financing and Security Documents

The target’s financing arrangements may restrict the transaction or expose the buyer to unexpected repayment obligations.

The review should cover:

  • Loan agreements;
  • Credit facilities;
  • Leasing;
  • Factoring;
  • Bonds and other debt instruments;
  • Shareholder loans;
  • Mortgages;
  • Movable pledges;
  • Share pledges;
  • Account pledges;
  • Guarantees and sureties;
  • Letters of guarantee;
  • Financial covenants.

Financing agreements may include change-of-control provisions or mandatory prepayment obligations. The buyer should identify required lender consents before signing or make them conditions precedent to completion.

Security searches should also be conducted through the appropriate registries.

Tax and Public Debt Exposure

Tax review is normally carried out with specialised tax advisers, but legal due diligence should identify the existence and procedural status of tax risks.

The review should cover:

  • Corporate tax;
  • Value-added tax;
  • Withholding tax;
  • Stamp tax;
  • Customs duties;
  • Social security premiums;
  • Municipal liabilities;
  • Tax inspections;
  • Tax settlement procedures;
  • Pending tax litigation;
  • Tax penalties;
  • Restructured public debts.

A certificate showing no currently payable tax debt does not necessarily confirm that the company has no historical exposure. An ongoing or future tax inspection may relate to earlier accounting periods.

The share purchase agreement should therefore contain appropriate tax warranties, indemnities and cooperation provisions.

Employment and Social Security Review

Employee liabilities frequently become significant post-closing costs.

The employment review should examine:

  • Employee lists;
  • Employment contracts;
  • Salary and bonus arrangements;
  • Accrued annual leave;
  • Overtime;
  • Severance and notice exposure;
  • Remote-working arrangements;
  • Independent contractors;
  • Senior-management agreements;
  • Collective bargaining agreements;
  • Union matters;
  • Workplace policies;
  • Social security declarations;
  • Occupational health and safety;
  • Pending employee claims.

In a share acquisition, the legal employer ordinarily remains the same company. Employment agreements therefore continue unless the transaction is followed by separate employment actions.

The review should identify employees who are essential to the business and determine whether change-of-control bonuses, retention arrangements or resignations may arise.

Litigation and Enforcement Proceedings

The buyer should identify both existing proceedings and circumstances likely to produce future claims.

The review may include:

  • Civil and commercial lawsuits;
  • Labour cases;
  • Consumer disputes;
  • Administrative proceedings;
  • Tax litigation;
  • Arbitration;
  • Enforcement files;
  • Bankruptcy proceedings;
  • Criminal investigations involving the company or management;
  • Interim injunctions;
  • Attachments;
  • Regulatory investigations.

Information provided by management should be compared with UYAP records, enforcement records, external counsel confirmations and financial provisions.

The absence of a formal lawsuit does not eliminate risk. Customer complaints, employee notices, regulatory correspondence and contractual defaults may indicate potential claims.

Real Estate and Leased Premises

The target may own or lease real estate essential to its operations.

For owned property, the review should cover:

  • Land registry ownership;
  • Mortgages and attachments;
  • Easements;
  • Rights of use;
  • Zoning;
  • Construction licences;
  • Occupancy permits;
  • Expropriation risk;
  • Environmental restrictions;
  • Property tax;
  • Pending title disputes.

For leased premises, the buyer should examine:

  • Lease term;
  • Renewal;
  • Rent increases;
  • Security deposits;
  • Assignment and change-of-control provisions;
  • Sublease rights;
  • Termination;
  • Registration or annotation;
  • Outstanding rent and service charges.

A business may be commercially dependent on a facility that is owned by the seller or a related party. In such cases, the post-closing lease terms should be agreed before completion.

Intellectual Property

The buyer should verify that the target owns or validly licenses the intellectual property necessary for its operations.

The review should cover:

  • Trademarks;
  • Patents;
  • Utility models;
  • Industrial designs;
  • Copyright;
  • Software;
  • Domain names;
  • Databases;
  • Trade secrets;
  • Know-how;
  • Social-media accounts.

It should be confirmed whether employees, founders, consultants or external developers assigned their rights to the company.

A company may pay for software development without receiving full ownership of the source code or intellectual property. Similarly, a trademark used by the target may actually be registered in the name of a founder or another group company.

The report should distinguish between registered rights, contractual licences and unregistered business assets.

Information Technology and Cybersecurity

Technology due diligence is no longer limited to software ownership.

The buyer should investigate:

  • IT infrastructure;
  • Software licences;
  • Cloud services;
  • Hosting agreements;
  • Source-code access;
  • Cybersecurity incidents;
  • Backup and recovery;
  • Access controls;
  • Business-continuity planning;
  • Third-party processors;
  • Customer-facing platforms;
  • Open-source software.

A serious data breach or dependency on an unlicensed system may create substantial operational and regulatory exposure.

Cybersecurity representations should be supported by technical testing where the company’s value depends materially on its technology platform.

Personal Data Protection

M&A data rooms may contain employee, customer, supplier and management information. Disclosure of these documents constitutes personal-data processing and, in some cases, transfer to third parties.

Under the Turkish Personal Data Protection Law No. 6698, personal data must be processed for specified and legitimate purposes, remain relevant, limited and proportionate, and be protected through appropriate technical and organisational measures. The law also regulates domestic transfers, international transfers and special categories of personal data. (Kişisel Verileri Koruma Kurumu)

Due diligence teams should therefore consider:

  • Whether personal data are genuinely necessary;
  • Whether documents can be anonymised or redacted;
  • Whether access should be limited to designated reviewers;
  • Whether health, biometric or criminal-record data are included;
  • Whether the data room is hosted outside Turkey;
  • Whether data will be downloaded;
  • Whether access logs are maintained;
  • Whether documents will be deleted after the process.

Where data are transferred abroad, the conditions under Article 9 and the applicable international-transfer regulation must be satisfied. Appropriate safeguards may include the standard contracts published by the Personal Data Protection Board, and signed standard contracts must be notified to the Authority within the prescribed period. (Kişisel Verileri Koruma Kurumu)

Regulatory Licences

Companies operating in regulated sectors may require licences, permits or approvals that cannot be assumed to continue automatically after a change in ownership.

Relevant sectors may include:

  • Banking;
  • Insurance;
  • Payment services;
  • Energy;
  • Telecommunications;
  • Capital markets;
  • Private education;
  • Healthcare;
  • Aviation;
  • Media;
  • Defence;
  • Mining;
  • Food and pharmaceuticals.

The review should determine:

  • Whether the required licence exists;
  • Whether it is current;
  • Whether conditions are being complied with;
  • Whether there have been inspections or sanctions;
  • Whether a change of control requires prior approval;
  • Whether the licence can be transferred;
  • Whether foreign ownership restrictions apply.

Regulatory approval should be included as a condition precedent where required.

Competition Law and Merger Control

An acquisition may require prior authorisation from the Turkish Competition Authority where it results in a permanent change of control and the applicable turnover thresholds are exceeded.

Article 7 of Law No. 4054 prohibits mergers and acquisitions that significantly impede effective competition, and the merger-control communiqué regulates the transactions requiring prior approval. (Rekabet Kurumu)

The notification thresholds were amended in February 2026. The relevant individual Turkish turnover threshold was increased from TRY 250 million to TRY 1 billion, the combined Turkish turnover threshold from TRY 750 million to TRY 3 billion and the worldwide turnover threshold from TRY 3 billion to TRY 9 billion. The special regime for technology undertakings was also revised. (Rekabet Kurumu)

The review should consider control rather than only the percentage of shares being acquired. Minority rights, veto powers, board appointment rights and shareholders’ agreements may create sole or joint control.

Where notification is required, the parties should not complete or implement the transaction before Competition Board approval.

Anti-Corruption, Sanctions and Compliance

Compliance due diligence should assess whether the target has been involved in unlawful payments, improper benefits, bid manipulation, money laundering, sanctions violations or other misconduct.

The review should cover:

  • Compliance policies;
  • Gifts and hospitality;
  • Government interactions;
  • Intermediaries and agents;
  • Public tenders;
  • Political exposure;
  • Whistleblowing reports;
  • Internal investigations;
  • Sanctions screening;
  • Beneficial ownership;
  • Suspicious transactions.

The buyer should investigate unusual commission payments, cash transactions, consultant arrangements and payments to entities lacking a clear commercial function.

A contractual warranty is not a sufficient substitute for investigation where red flags already exist.

Environmental and Occupational Risks

Manufacturing, energy, construction, mining and industrial businesses may carry material environmental exposure.

The review may cover:

  • Environmental permits;
  • Waste management;
  • Emissions;
  • Soil and groundwater contamination;
  • Hazardous materials;
  • Environmental fines;
  • Workplace accidents;
  • Occupational safety inspections;
  • Remediation obligations.

Environmental liabilities may remain with the target even where the conduct occurred before the acquisition.

Technical and environmental experts should be engaged where the business operates industrial facilities or owns potentially contaminated land.

Insurance

The buyer should determine whether the target’s insurance coverage corresponds to its actual risk profile.

The review should cover:

  • Property insurance;
  • Employer liability;
  • Professional liability;
  • Product liability;
  • Cyber insurance;
  • Directors’ and officers’ liability;
  • Business interruption;
  • Vehicle insurance;
  • Environmental coverage.

Policies should be examined for exclusions, deductibles, claims history, change-of-control provisions and unpaid premiums.

The existence of insurance does not necessarily mean that a particular historical claim will be covered.

Identifying Red Flags

A due diligence report should distinguish between routine deficiencies and transaction-critical issues.

Common red flags include:

  • Seller cannot prove ownership of the shares;
  • Share certificates or corporate books are missing;
  • Shares are pledged or attached;
  • Capital has not been fully paid;
  • Corporate resolutions are invalid or incomplete;
  • Material contracts permit termination upon a change of control;
  • Required regulatory licences are absent or expired;
  • Major assets are owned by shareholders rather than the company;
  • Intellectual property is registered to founders or contractors;
  • Significant tax or social security exposure exists;
  • Employees are paid partly outside payroll;
  • Litigation is not reflected in the financial statements;
  • Customer data are processed unlawfully;
  • Related-party debts cannot be reconciled;
  • Essential property is occupied without a valid lease;
  • Competition clearance has not been assessed.

A red flag does not always require abandonment of the transaction. It may instead justify restructuring, price adjustment, pre-closing remediation or specific contractual protection.

Due Diligence Report

The report should be practical and linked to the transaction documents.

It may be prepared as:

  • A full descriptive report;
  • An exceptions-only report;
  • A red-flag report;
  • A legal-risk matrix;
  • A combination of written analysis and schedules.

Each material finding should ordinarily explain:

  1. The relevant fact;
  2. The applicable legal risk;
  3. The potential commercial impact;
  4. The recommended action;
  5. Whether the issue should be resolved before or after closing;
  6. The contractual protection required.

A report that merely lists documents without explaining their legal significance provides limited transactional value.

Translating Findings into Transaction Protection

Due diligence findings should be reflected in the share purchase or asset purchase agreement.

Possible protections include:

Conditions precedent

Certain matters must be resolved before closing, such as:

  • Competition Authority approval;
  • Regulatory consent;
  • Release of share pledges;
  • Lender consent;
  • Corporate authorisation;
  • Renewal of essential licences;
  • Execution of key contracts;
  • Termination of related-party arrangements.

Representations and warranties

The seller may give contractual statements regarding:

  • Ownership of shares;
  • Corporate authority;
  • Financial statements;
  • Taxes;
  • Employees;
  • Contracts;
  • Litigation;
  • Assets;
  • Intellectual property;
  • Data protection;
  • Compliance;
  • Regulatory licences.

Specific indemnities

Known risks should normally be covered by specific indemnities rather than only general warranties.

Examples include:

  • Pending tax assessment;
  • Identified employee claim;
  • Unlicensed software;
  • Existing litigation;
  • Environmental contamination;
  • Historical regulatory breach;
  • Disputed property title.

Escrow and retention

Part of the purchase price may be retained or deposited in escrow to secure potential claims.

The agreement should regulate the retained amount, period, release conditions and claim procedure.

Price adjustment

Where the risk is quantifiable, it may be reflected directly in the purchase price or completion accounts.

Limitations of Due Diligence

Legal due diligence cannot eliminate all transaction risks.

The review is limited by:

  • Accuracy of the seller’s disclosure;
  • Availability of public records;
  • Scope and materiality thresholds;
  • Time constraints;
  • Undocumented oral arrangements;
  • Concealed misconduct;
  • Future regulatory changes;
  • Unidentified claims.

The buyer should therefore combine due diligence with contractual warranties, indemnities, security arrangements and post-closing controls.

The seller should also prepare a detailed disclosure letter. A general data-room disclosure clause may not provide adequate protection where material risks have not been specifically identified.

Practical Legal Due Diligence Checklist

Before acquiring a Turkish company or business, the buyer should ordinarily:

  1. Confirm the transaction structure.
  2. Establish the review scope and materiality thresholds.
  3. Prepare a detailed document request list.
  4. Verify corporate existence and shareholder ownership.
  5. Review corporate approvals and representation powers.
  6. Identify share pledges, attachments and transfer restrictions.
  7. Examine material contracts and change-of-control clauses.
  8. Review financing and security arrangements.
  9. Conduct tax and public-debt analysis.
  10. Assess employment and social security exposure.
  11. Search litigation and enforcement records.
  12. Verify ownership of real estate and key assets.
  13. Review intellectual property and technology.
  14. Assess personal-data and cybersecurity compliance.
  15. Confirm regulatory licences and permits.
  16. Conduct merger-control analysis.
  17. Investigate compliance and related-party transactions.
  18. Identify environmental and occupational risks.
  19. Prepare a prioritised legal report.
  20. Translate findings into the transaction documents.

Conclusion

Legal due diligence is not a procedural formality. It is the principal mechanism through which a buyer determines what it is actually acquiring and which liabilities may remain after completion.

A Turkish company may appear commercially successful while carrying defective share records, unpaid public debts, terminable customer contracts, employee exposure, disputed assets, unregistered intellectual property or regulatory deficiencies.

The review should therefore combine corporate records, public registry searches, contractual analysis, litigation searches and management questions. Material findings should directly affect the purchase agreement, purchase price, conditions precedent, warranties, indemnities and closing mechanics.

Early and properly structured legal due diligence allows the buyer to make an informed decision, negotiate effective protection and reduce the risk of discovering critical liabilities only after ownership has changed.

 

Leave a Reply

Call Now Button