Table of Contents
ToggleKey Takeaways
- Cross-border M&A adds regulatory review, currency and tax exposure, and integration risk to a deal that already carries commercial risk, and most of the delay comes from the regulatory side.
- CFIUS handled 347 covered transactions in 2025 and cleared roughly two thirds inside the initial review window, so the tail cases are where deal timelines break.
- Cross-border due diligence needs local advisors in each jurisdiction, because disclosure norms and record quality differ far more than most first-time acquirers expect.
- Data sovereignty now decides who can open a file. Under the US Data Security Program, giving a bidder’s team in a country of concern access to bulk US personal data can itself be a prohibited transaction.
- The legal basis for EU to US transfers is intact but under appeal, so transfer mechanisms in a live deal deserve a check rather than an assumption.
- Staged access, permission groups set by jurisdiction, and in-platform redaction handle most of these restrictions, provided the room is structured before bidders arrive.
Cross-border M&A is a merger or acquisition where the buyer and the target sit in different countries. The deal logic is the same as any other acquisition. What changes is the number of parties who can stop it, tax it, or restrict what the buyer is allowed to see, and how much of that has to be worked out before diligence opens rather than after.
Cross-border M&A gets described as domestic M&A with extra paperwork. That framing survives right up to the moment a bidder’s counsel in Shanghai asks for access to the customer database, and someone on the seller’s side has to decide whether granting that login breaks a US regulation.
This piece covers the drivers, the risks that actually stall international deals, how due diligence changes across jurisdictions, and the data rules that now determine who may open which document. The data transfer rules changed considerably over the last eighteen months, and the consequences for a live deal are more concrete than most coverage suggests.
What Is Cross-Border M&A?
Cross-border M&A is a transaction in which the acquirer and the target are based in different countries, whether structured as a share purchase, an asset purchase, a merger, or a joint venture. The distinction matters because the deal picks up a second set of company, tax, employment, competition, and data laws, and often a foreign investment review on top. The structure you choose changes which of those apply.
Volume is concentrated rather than broad. Cross-border activity reached US$1.05 trillion in the first seven months of 2026, the highest January to July total since 2007, with the US and UK together accounting for nearly half of all cross-border target activity, according to LSEG. Deal value is rising in a market where the number of transactions is falling, which means the deals being done are larger and are drawing more scrutiny per deal.
Why Companies Buy Across Borders
The strategic case rarely changes much from deal to deal:
- Market access. Buying a local operator with distribution, licences, and customer relationships beats building the same thing over five years.
- Technology and talent. Engineering teams, patents, and manufacturing capability that cannot be recruited at speed in the home market.
- Diversification. Spreading revenue across currencies and economic cycles, which is also what makes the currency exposure real.
- Supply chain control. Moving production closer to demand, or away from a jurisdiction that has become a tariff or sanctions risk.
Worth noticing which of these attracts attention. A buyer acquiring distribution in a neighboring market rarely troubles a regulator. A buyer acquiring semiconductor design, health data, or anything adjacent to critical infrastructure will be reviewed, and should plan the process around that from the first approach.
What Actually Stalls a Cross-Border Deal
Four categories cause most of the delay, and they are not equally weighted. Regulatory review sets the timetable; the others set the price.
| Risk | What it looks like | Where it lands |
|---|---|---|
| Regulatory and foreign investment | CFIUS or an equivalent screening regime, merger control in several jurisdictions, sanctions and export controls | Timeline, and occasionally the deal itself |
| Data and privacy | Transfer restrictions, localization rules, and limits on who may access which files | Diligence design and disclosure scope |
| Tax and structuring | Withholding tax, transfer pricing, permanent establishment, repatriation of cash | Net price and post-close cash flow |
| Currency and political | FX movement between signing and closing, capital controls, changes of government | Price adjustment mechanisms and financing |
| Cultural and operational | Management retention, works councils, union consultation, and differing reporting norms | Integration and realized value |
Table 1: The main risk categories in cross-border M&A and where each one shows up.
These risks do not arrive in sequence. Tax structuring depends on the acquisition vehicle, the vehicle depends on regulatory approvals, and the approvals depend on what the buyer discloses about its own ownership. Deal teams that work through them one at a time lose months. Working through them in parallel means the diligence record has to answer three different sets of questions from the same document set, which is a demand on how the room is organized rather than on how many documents it holds.
How CFIUS and Other Regulators Shape the Timeline
In the US, the Committee on Foreign Investment in the United States reviews transactions that give a foreign party control of, or certain rights in, a US business. Its scope now covers sensitive personal data of US citizens as well as critical technology and critical infrastructure, which is why software and healthcare deals end up in front of it alongside defense assets.
The 2025 numbers are useful for planning. According to the CFIUS Annual Report to Congress for calendar year 2025, the Committee handled 347 covered transactions, made up of 207 written notices and 140 declarations, up from 325 the year before. Roughly two thirds cleared within the initial 30-day declaration assessment or 45-day notice review. The rest went longer, 51 notices were withdrawn and refiled, and 10 transactions were abandoned after withdrawal. Read that as a two-track distribution: most deals clear on schedule, and the ones that do not can lose a quarter or the deal.
Outside the US, merger control filings in the EU, UK, China, and a growing list of national screening regimes each carry their own thresholds and clock. Export controls sit alongside them. If the target holds technical data controlled under ITAR or the EAR, sharing those files with a foreign national can constitute an export whether or not anyone leaves the country, which is a diligence problem before it is a closing problem.
| Did You Know
CFIUS filings rose to 347 covered transactions in 2025 from 325 in 2024, driven by a roughly 21 percent increase in declarations, and government shutdowns tolled review deadlines past 120 days across three lapses in appropriations. Timeline risk is not only about the merits of your deal. Source: US Treasury, CFIUS Annual Report to Congress for CY2025 |
How Cross-Border Due Diligence Differs
The workstreams look familiar. Financial, legal, tax, commercial, HR, IT. What changes is that each one needs a local reviewer, because the same document means different things in different systems.
- Financial records. Statements prepared under local GAAP need bridging to the acquirer’s reporting basis, and audit quality varies widely by market.
- Employment. Works councils, consultation requirements, and statutory severance can carry costs and timing obligations with no domestic equivalent.
- Contracts. Change-of-control provisions, governing law, and enforceability of non-competes differ by jurisdiction, so a clause that is routine at home may be void or unusually powerful abroad.
- Corruption and sanctions. Third-party agents, distributors, and government-adjacent customers need screening under the FCPA and equivalent regimes, and the exposure transfers with the business.
- Records themselves. Documents arrive in other languages, sometimes as scans of signed originals, and translation and OCR quality become a real constraint on review speed.
Practical consequence for the due diligence process: the reviewer population is larger, more fragmented, and more geographically spread than in a domestic deal. A seller can easily end up with 150 or more named users across buyers, local counsel in four countries, accountants, and technical consultants. Permissioning that group correctly is where the data rules below stop being abstract.
Data Sovereignty Now Decides Who Can Open the File
The most consequential shift in cross-border M&A over the past two years is that data rules moved from being a post-close integration problem to being a diligence-day-one problem. Three regimes matter most for deal teams.
The US Data Security Program
The Justice Department’s Data Security Program, implementing Executive Order 14117, took effect on April 8, 2025, with enforcement from July 2025 and full compliance obligations from October 2025. It prohibits or restricts transactions that give countries of concern, currently China including Hong Kong and Macau, Cuba, Iran, North Korea, Russia, and Venezuela, or persons connected to them, access to bulk US sensitive personal data or government-related data.
Two features of the rule catch deal teams off guard. Access is defined broadly enough that it does not matter whether access controls actually let someone read the data, and the thresholds apply even where the data has been de-identified, anonymized, pseudonymized, or encrypted. In practice that means adding a bidder’s analyst in a country of concern to a data room holding bulk personal data is the thing being regulated, not the eventual transfer of the database at closing.
Where EU to US transfers stand right now
Sharing EU personal data with a non-EU buyer needs a lawful transfer basis: an adequacy decision, standard contractual clauses, or binding corporate rules, with a transfer impact assessment behind it. The EU to US route currently runs on the Data Privacy Framework, which the General Court upheld in September 2025. That judgment is under appeal at the Court of Justice, and the European Data Protection Board wrote to the Commission in July 2026 asking it to reassess the framework. Nothing has been struck down, and two predecessor frameworks were, so a live deal is worth checking against current status rather than a memo written in 2024.
Rules that keep data inside a country
China’s Data Security Law and PIPL require security assessment before certain data leaves the country, and treat unauthorized foreign access to strategic data as a national security matter. India’s DPDP Act permits transfers by default while reserving the power to restrict destinations. Saudi Arabia, the UAE, Brazil, and others impose their own transfer conditions. The pattern across all of them is the same: some subset of the target’s data cannot leave, so the diligence design has to work around it rather than through it.
| Common Mistake
Treating a data room login as neutral. Under the US Data Security Program, access is assessed without regard to whether security measures actually prevent the person from reading the data, and the rule applies even to encrypted or de-identified records. The permission grant is the regulated event. Source: US Department of Justice, National Security Division, 28 CFR Part 202, linked above. |
How to Build the Room Around the Rules
None of this stops a deal. It changes how the room is built, and the work belongs at setup rather than mid-process, because retrofitting permissions after 60 users are already inside is how mistakes happen.
- Map the data before the room opens. Identify which categories are restricted, by which regime, and for which counterparties. This is a legal exercise, and it determines the folder structure.
- Build permission groups around nationality and clearance, not just bidder identity. A single bidder may need two groups: one for its cleared US team and one for its overseas reviewers.
- Stage disclosure by deal phase. Corporate records and historical financials support a credible offer. Employee data, account-level customer revenue, and controlled technical material can wait for exclusivity and, where relevant, regulatory clearance.
- Redact inside the platform. Personal identifiers and controlled specifications should be removed before a file becomes visible to a restricted group, with an administrator preview confirming what the other side will see.
- Use clean teams for the rest. Where a bidder genuinely needs analysis of restricted data, an independent reviewer under confidentiality obligations can look and report conclusions rather than contents.
- Keep the access record. The question a regulator or counsel asks later is who accessed which document, from where, and when. That answer has to come from a log, not from memory.
| Requirement | What it needs in the room | What goes wrong without it |
|---|---|---|
| Restricted access by party | Permission groups per counterparty and per jurisdiction, with rights cascading to subfolders | A reviewer in a restricted jurisdiction is given a login that should never have existed |
| Staged disclosure | Folder-level release tied to deal phase | Sensitive data reaches a competitor bidder that later withdraws |
| Selective redaction | In-platform redaction with an administrator preview | Redactions applied offline leave recoverable text in the file |
| Evidence of access | Exportable logs at document, user, and group level | No defensible answer months later when the question arrives |
| Control after download | Revocation of downloaded files and identity-carrying watermarks | Copies stay with parties who walked away from the deal |
Table 2: Translating cross-border data restrictions into data room configuration.
| Setting up a room for bidders in several jurisdictions?
If the structure has to separate reviewers by country before the process opens, it is worth scoping the configuration with someone who builds these daily. Get an Enterprise Quote. |
What Breaks After the Deal Closes
Deal value is realized or lost after closing, and cross-border integration carries failure modes a domestic deal does not. Systems consolidation runs into the same transfer restrictions that constrained diligence, so a single global HR or CRM instance may not be lawful without further work. Employment integration runs through local consultation requirements. Management retention is harder when the acquirer’s incentive structures do not translate.
Diligence documentation is what makes integration cheaper. Teams that keep the document set, the question and answer history, and the access logs intact after closing start post-merger integration with a reference set rather than a rebuild, which matters more when the integration team sits in a different country from the people who ran the deal.
What a Data Room Has to Do in a Cross-Border Deal
A cross-border process asks a data room to do something narrower than most feature lists describe: give different people different views of the same document set, prove afterwards who saw what, and keep control of files that have already been downloaded. Consumer file sharing does none of the three, which is the honest reason enterprise file sharing platforms and data rooms are not interchangeable for this work.
In CapLinked, access is granted to groups rather than to individuals, so a deal team can separate a bidder’s cleared reviewers from its overseas team and apply view, download, and upload rights per folder. PDF redaction runs inside the platform, with an administrator preview showing exactly what a non-administrator will see. CapLinked’s digital rights management layer, FileProtect, converts protected documents to PDF on download, blocks printing and re-sharing, and allows access to be revoked afterwards, which is the control that matters when a bidder withdraws mid-process. The Activity Tracker report logs views, downloads, and viewing duration by group, by document, and by named individual, and exports to CSV at every level. The structured question and answer module, EZ Q&A, keeps diligence questions and their answers inside the room with an exportable record, rather than scattered across counsel inboxes in four time zones.
For transactions touching US defense or government work, CapLinked also runs a deployment on AWS GovCloud (US), Amazon’s US-only cloud region for government and defense workloads, where administrative access is restricted to US persons. Teams use it for ITAR, DFARS, and CMMC-aligned document sharing. The GovCloud deployment inherits the security posture of that environment and supports aligned controls. CapLinked does not issue certification, and using the platform does not make your own compliance program compliant. Across both environments, the controls are 256-bit encryption at rest and in transit, enforceable two-factor authentication, IP whitelisting, SAML-based single sign-on, and SOC 2 or SSAE 18 Type II attestation, all set out on the security page and worth checking against your own control matrix. If it helps to test the structure against a real document set before a process opens, the enterprise configuration and published pricing are both public, and you can start a 14-day free trial to build the room first.
What to Check Before You Choose a Platform
Whichever platform ends up running the room, five questions decide whether it holds up once bidders in different countries are inside it. Ask them before the process opens rather than in week three.
- Can access be split below bidder level? One bidder often needs two groups, one for cleared reviewers and one for overseas staff, with different folders visible to each.
- Does redaction happen inside the platform? Redacting offline and re-uploading leaves recoverable text in more file formats than most teams expect.
- Can you export the access record yourself? A log you have to request through support is not much use when counsel asks who opened a file in March.
- What happens to downloaded files when a bidder exits? Either the platform can revoke them or it cannot, and the answer changes what you are willing to release before exclusivity.
- How fast can a reviewer be removed? When a regulator changes what a party may see, removing access has to take minutes, not a support ticket.
A first-time international seller will not have opinions on all five. A banker running a third cross-border mandate this year will have opinions on all five, and usually a story about the one that failed.
Cross-Border M&A Questions People Ask Most
What is cross-border M&A?
Cross-border M&A is a merger or acquisition where the buyer and the target are based in different countries. It adds foreign investment review, multi-jurisdiction merger control, tax structuring, and data transfer restrictions to a standard deal process.
What are the biggest challenges in cross-border M&A?
Regulatory review usually sets the timeline, while tax structuring, currency movement, and data transfer restrictions shape the price and the diligence design. Cultural and employment differences then decide how much value survives integration.
How does cross-border due diligence differ?
Each workstream needs local advisors, because accounting standards, employment law, contract enforceability, and record quality vary by jurisdiction. Translation and document search quality also become real constraints on review speed.
What is CFIUS and when does it apply?
CFIUS reviews foreign investment in US businesses touching critical technology, critical infrastructure, or sensitive personal data. It handled 347 covered transactions in 2025, clearing about two thirds within the initial review period.
How do data sovereignty laws affect M&A?
They determine which documents can leave a jurisdiction and who may access them. Under the US Data Security Program, granting data room access to parties in a country of concern can itself be a restricted transaction.
Can EU data be shared with a US buyer?
Yes, with a lawful transfer basis such as the Data Privacy Framework or standard contractual clauses, plus a transfer impact assessment. The framework is valid and under appeal, so confirm current status during the deal.
What should a data room do in a cross-border deal?
Separate access by counterparty and jurisdiction, stage disclosure by deal phase, redact inside the platform, log every view and download for export, and revoke access to downloaded files when a party exits.


