Buy-side legal due diligence checklist for startup acquisitions
Hello, this is Legal Agent.
When a company acquires a startup, the diligence window is short but the scope is broad: shareholding, intellectual property, labor practices, personal data and key contracts all need review within days rather than weeks. For the buyer, legal due diligence is less about checking documents than about deciding whether the business can actually be taken over.
What buy-side due diligence is for
Legal due diligence identifies legal risk before a deal closes and feeds that risk into price, deal structure and closing conditions. In a startup acquisition, the areas that matter most often differ from a typical mid-size M&A deal: the history of share issuances, stock options and who owns the source code behind the product tend to carry more weight, and gaps such as missing board minutes or accounts still registered to a founder personally are common.
Why the weak points double as the company's value
A startup's value is often inseparable from its legal rights. If the product and customer base are the business, the buyer needs to know whether customer contracts survive a change of control or require consent to assign. Capitalization is another pressure point: prior funding rounds may have created preferred shares or shareholder agreements whose consent rights, drag-along or deemed-liquidation provisions can reshape the deal structure. IP ownership deserves the same scrutiny: code written by a founder personally or by a contractor before incorporation should have been properly assigned to the company. Labor practices, including long hours and the line between employment and outsourced work, can also generate liabilities once the buyer applies its own labor standards after closing.
Three areas to prioritize in a short window
With limited time, the first pass should cover capitalization and consent requirements, IP ownership across founders and contractors, and key contracts with change-of-control clauses. Personal data handling, licenses, and any disputes or complaints round out the review. Even informal complaints raised only by email or chat matter here, since a data-dependent business needs continued lawful use of that data after closing.
Risk differs by side of the table
For the buyer, the risk is that the rights and contracts underpinning the target's value cannot be relied on after closing. For the seller, the risk is that findings reduce price or add closing conditions. Imperfect internal practices are common at startups, and what matters is being able to explain their background and remediation rather than concealing them. The task on both sides is separating critical risk from fixable gaps, rather than producing a long list with no sense of priority.