Treadstone Associates
Case File · Going to Market

A data room leak that reached a competitor

Anonymised, illustrative composite. The confidentiality agreement was signed and standard. What it did not anticipate was who was actually on the other side of it.

Treadstone Associates · Updated 2026

At a glance

  • • Mid-market process, 14 initial parties under NDA, narrowed to 6 round-2 bidders with data-room access.
  • • One round-2 bidder, accessing through an unrelated holding-company name, was in fact affiliated with a direct product-market competitor.
  • • Access logs showed 340 documents — including the full current customer list and unit-economics folder — downloaded in 47 minutes, well ahead of the scheduled release stage.
  • • Access was revoked within a day of detection; the remaining five bidders continued under a rebuilt, staged clean-team disclosure protocol.

The situation

A sell-side process for a mid-market business narrowed from fourteen NDA-signed parties to six round-2 bidders granted staged access to a virtual data room. One of the six accessed the process through a holding-company name unconnected, on its face, to any operator in the seller’s industry — standard practice for a strategic buyer that prefers not to signal its interest early.

The problem

A routine review of the bidder’s advisory team, prompted by an unrelated conflict check ahead of exclusivity, revealed that the holding company was a special-purpose vehicle controlled by a direct competitor in the seller’s core product line — a relationship the bidder had not disclosed and the seller’s advisor had not caught at the NDA stage. By the time this surfaced, the bidder had already had data-room access for eleven days.

The numbers

An audit of the data room’s access logs found the bidder’s advisor had downloaded 340 documents in a single 47-minute session on day two of access — including the complete current customer list and the full unit-economics folder, both scheduled under the process’s own staging plan for release only to a final-round bidder under enhanced protections, not to all six round-2 participants. The typical pattern among the other five bidders was a handful of documents reviewed per day over the eleven-day window, not a bulk download in under an hour.

The rule that decided it

What made this more than a confidentiality-agreement breach is who received the data. The Competition Act’s general conspiracy offence, section 45(1), makes it a criminal offence for a person to conspire, agree or arrange with “a competitor… with respect to a product” to fix or control prices, allocate customers or markets, or control production or supply — punishable, under s.45(2), by up to fourteen years’ imprisonment or a fine at the court’s discretion. Precision matters here, because the offence is easy to overstate: s.45 requires a conspiracy, agreement or arrangement, and a bidder unilaterally downloading files is not one. No one in this process was fixing prices. Three things make the exposure real anyway. First, s.45(3) allows a court to “infer the existence of a conspiracy, agreement or arrangement from circumstantial evidence, with or without direct evidence of communication.” Second, the Competition Bureau’s Competitor Collaboration Guidelines warn that “an agreement that involves a unilateral disclosure or exchange of information between competitors can impair competition by reducing uncertainties regarding competitors’ strategies,” and that information about “current or future activities” raises greater concern than historical data — which is what a live customer list and current unit economics are. Third, where no criminal agreement is made out, the civil route survives: s.90.1 lets the Tribunal make an order where an agreement between competitors “prevents or lessens… competition substantially in a market”, with no criminal standard to meet. The same Guidelines note that the acquisition itself would be assessed under the merger provisions in s.92 and following rather than under s.45 or s.90.1 — so the exposure here is not the deal, it is the data. That is why sophisticated sale processes wall off competitively sensitive material behind a clean team — external advisors only, aggregated or redacted figures until a final round, full detail released only once exclusivity and enforceable confidentiality are locked in.

The outcome

The seller’s advisor revoked the bidder’s data-room access within a day of the ownership connection being confirmed and removed the bidder from the process entirely rather than attempt to continue under tighter restrictions. The remaining five bidders had their access rebuilt under a revised, staged protocol: granular customer and pricing data released only to a single final-round bidder post-exclusivity, reviewed on the seller’s side by external counsel before release, with all round-2 material limited to aggregated figures. The process continued and closed roughly seven weeks later than originally scheduled, with the seller’s counsel documenting the incident and the remediation in case the disqualified bidder’s conduct became relevant later.

A teaser that identified the seller before any bidder was even shortlisted shows the same risk at an earlier stage of the same process — see a teaser that gave away the vendor’s identity. For how a financing screen ended a different deal before any data room was even opened, see walking away in week two on a single number.

What it would have cost otherwise

Had the ownership connection gone undetected, the competitor would have retained current pricing and a complete customer list gathered under the pretence of a genuine acquisition interest — commercially damaging on its own, and, if the bidder had gone on to coordinate any pricing or customer-allocation decision using that information, a fact pattern capable of exposing everyone who exchanged it to the Competition Act’s conspiracy provisions, not merely to a breach-of-contract claim under the NDA.

The tell

The tell was the download pattern, not the holding-company name itself — unrelated acquisition vehicles are common and not inherently suspicious. A 47-minute, 340-document bulk download of exactly the material scheduled for final-round-only release, against a background rate of a handful of documents a day from every other bidder, is the kind of access-log anomaly a staged data room is built to surface, provided someone is actually watching the logs.

Takeaways

  • • Verify beneficial ownership behind every bidder’s acquisition vehicle, not just the name on the NDA — a competitor can bid through an unrelated holding company.
  • • Stage data-room access so granular pricing and customer data release only to a final-round bidder under enhanced protections, not to the full round-2 field.
  • • Monitor data-room access logs for download patterns that outpace every other bidder — a bulk download of scheduled-for-later material is a detectable anomaly.
  • • A competitor bidder with unrestricted access to current pricing and customer data is a Competition Act information-exchange risk, not only a confidentiality-agreement issue — s.45 needs an agreement, but s.45(3) allows one to be inferred from circumstantial evidence, and s.90.1 imposes no criminal standard at all.

Sources

  • Competition Act s.45 — Conspiracies, agreements or arrangements between competitors — the offence is committed by a person who, “with a competitor of that person with respect to a product, conspires, agrees or arranges” to fix prices, “allocate sales, territories, customers or markets,” or control supply. s.45(2) sets the penalty at up to 14 years’ imprisonment or a fine in the court’s discretion; s.45(3) permits inference from circumstantial evidence; s.45(4) provides the ancillary-restraints defence. Establishes both the exposure and its limit — an agreement is required.
  • Competition Act s.90.1 — Order — the civil counterpart: the Tribunal may make an order where an agreement or arrangement between competitors “prevents or lessens, has prevented or lessened or is likely to prevent or lessen competition substantially in a market.” No criminal standard, and no administrative monetary penalty available under this section.
  • Competition Bureau — Competitor Collaboration Guidelines — the Bureau’s own treatment of information exchange: a “unilateral disclosure or exchange of information between competitors can impair competition by reducing uncertainties regarding competitors’ strategies and diminishing each firm’s commercial independence,” and such activity “may be sufficient to prove that an agreement was concluded… for the purpose of subsection 45(1).” Also confirms that current or forward-looking information raises greater concern than historical data, and that an acquisition of control is generally assessed under the merger provisions in s.92 and following, not under s.45 or s.90.1.
  • Treadstone Law — Using a data room when selling a business in Ontario — on point for the controls that caught this: role-based permissions, where “different users — the buyer, their lawyer, their accountant — can be given access to only the folders relevant to their role”; an audit trail letting the seller “see exactly who accessed which documents and when”; watermarking; and view-or-download restrictions on sensitive material. It does not address competitor bidders or the Competition Act — that is the statutory layer above it.
  • Treadstone Law — Staged disclosure when selling a business in Ontario — supports the remediation: a three-stage release in which the second stage carries only “general information about the customer base, supplier relationships, and workforce, without necessarily naming every party,” so that “the most sensitive material is only shown once a buyer has demonstrated real commitment.”

See where AI pays off first in your business.

A 30-minute call is enough to tell you whether AI pays for itself here.