Legal position last verified: 1 September 2026.
Acquiring or partnering with a Turkish company is not merely a share purchase agreement. Ownership and authority records, ETDS, material contracts, workforce, licences, merger control, privacy and cyber incidents, and post-closing integration must be connected to one transaction thesis. Due diligence should convert findings into price, conditions, warranties, indemnities and closing decisions.1234
This guide is for foreign strategic investors, private equity, corporate-development teams, joint-venture partners and transaction counsel.
Core conclusion: Good due diligence is a decision tool, not a risk catalogue: every finding should lead to cure before closing, pricing, indemnity, security or a no-deal decision.
Who is this guide for?
This guide is for foreign strategic investors, private equity, corporate-development teams, joint-venture partners and transaction counsel.
Decision summary in one minute
| Workstream | Core question | Transaction outcome |
|---|---|---|
| Corporate | Are shares and authority valid? | Transfer/closing condition |
| Contracts | Any change-of-control rights? | Consent/termination/indemnity |
| Workforce | Key people and liabilities? | Retention/price adjustment |
| Data/cyber | Incidents and technical debt? | Escrow/plan/warranty |
| Licences | Can activity continue? | Condition/restructure |
| Competition | Is filing required? | Standstill |
| Tax/finance | Hidden liability? | Price/security |
| Integration | Day-one readiness? | TSA/100-day plan |
1. Ownership, ETDS and authority chain
Share ledgers, ETDS records, trade registry, articles and corporate resolutions should be consistent. Registered shares, limited-company interests, pledges, usufructs, options and pre-emption rights require separate verification.56
Authority review should include internal directives, banking mandates, powers of attorney and actual contracting practice. Every required closing resolution should be assigned in the closing checklist.78
2. Material contracts and change of control
Customer, supply, finance, licence, distribution, lease and technology agreements are classified by revenue, dependency and change-of-control impact. An incomplete data room is not evidence of no risk; missing records need disclosure and tailored indemnity.9
Pre-closing consents should be separated from post-closing notices, avoiding gun-jumping or premature transfer of customer relationships.10
3. Workforce, management and incentives
Severance, leave, overtime, bonus, union, health and safety, key-person and foreign work-permit exposures are quantified. Management-change and retention effects require a communications plan.1112
Ownership of employee-created software, inventions and confidential know-how should not be assumed; contracts, policies and delivery records are reviewed.1314
4. Privacy, cybersecurity and technology debt
VERBIS, processing inventory, international transfers, critical processors, unresolved breaches and Board proceedings are material. A “no incidents” statement should be tested against logs, insurance, helpdesk and vendor records.1516
Software licensing, open source, cloud lock-in, backups, access, penetration tests and product vulnerabilities affect value. Findings should drive post-closing budget and transition services, not only warranties.1718
5. Merger control and transaction timetable
Change of control, turnover thresholds and technology-undertaking rules should be tested against current communiqué and guidance. A notifiable transaction should not close before clearance.1920
Due diligence information sharing needs clean teams and controls for competitively sensitive data. Full-functionality and parent coordination require separate joint-venture analysis.2122
6. SPA, security and post-closing
Findings are translated into warranties, specific indemnities, price adjustment, escrow, holdback, insurance or conditions precedent. Double recovery and vague disclosure should be avoided.2324
Day-one authority, banking, data access, employee communications, customer consents and a 100-day remediation plan should be ready before closing. Integration teams must inherit the diligence findings.2526
Documents and evidence the company should prepare
- Registry, articles and ETDS records
- Shares, security, options and UBO table
- Management and signature authority
- Material-contract and consent matrix
- Workforce/permit/incentive risk table
- Privacy, cyber and technology file
- Licences and regulatory approvals
- Merger filing and closing checklist
Contract and governance controls
- Representations and warranties
- Disclosure standard
- Specific indemnity
- Price adjustment
- Escrow/holdback
- Covenants and ordinary course
- Conditions precedent
- MAC and termination
- Merger clearance/gun-jumping
- Post-closing and TSA
Red flags and recurring mistakes
- Mismatch between share ledger and registry
- Treating missing data as no risk
- Ignoring change-of-control consent
- Leaving privacy/cyber findings to boilerplate warranties
- Taking control before merger clearance
- Failure to hand diligence findings to integration
Three practical scenarios
1. Acquisition of a technology company
Open source, customer data and cloud contracts drive value. The buyer uses specific IP and cyber indemnities, founder retention and a 100-day security plan.
2. 50/50 joint venture
Governance, veto, budget, deadlock, competition-sensitive information and exit are designed in the shareholders’ agreement, and full-functionality is tested for merger control.
3. Target operating under a sector licence
Where change of control requires prior approval, it becomes a condition precedent. No management instruction is given before clearance, and interim covenants stay within ordinary-course limits.
A 30–60–90-day implementation plan
Days 1–30 — scope and visibility
- Build the M&A and joint venture scope and role matrix.
- Collect the relevant contracts, permissions, data and decision records.
- Assign owners to urgent gaps and threshold questions.
Days 31–60 — evidence and contracting
- Complete missing permissions, policies, schedules and records.
- Obtain management approval for the decision matrix.
- Test group-company and supplier flows against the chosen model.
Days 61–90 — testing and governance
- Run a practical scenario or tabletop exercise.
- Report open risks with owners and closure dates.
- Establish annual and event-driven review triggers.
Frequently asked questions
What does legal due diligence cover?
Corporate, contracts, workforce, licences, litigation, competition, privacy, cyber, IP and other material target-specific areas.
Why do ETDS records matter?
They are central evidence for current share and general assembly records.
Is an indemnity enough for every risk?
No. Some findings require pre-closing cure, price, escrow or a no-deal decision.
When is merger clearance required?
It depends on change of control and current turnover/technology-undertaking thresholds.
Can the transaction close before clearance?
Notifiable transactions generally should not close or transfer control before clearance.
Can a data breach affect valuation?
Yes. Regulatory, customer, remediation and reputation costs may affect price and security.
Who should receive the diligence report?
Only authorised decision teams under confidentiality and competition controls.
When should post-closing planning begin?
Before closing, using diligence findings to build day-one and 100-day plans.
Conclusion
M&A diligence creates value when findings drive transaction economics. From ETDS to cloud contracts, each material issue should connect to closing, price, indemnity or integration action.
Legal information notice
This article provides general information only. It is not a legal opinion for a particular company, transaction, tax position, licence application or dispute. Applicable sector, tax, employment and regulatory rules require a fact-specific review.
Bibliography
- Türk Ticaret Kanunu No 6102 — https://www.mevzuat.gov.tr/mevzuatmetin/1.5.6102.pdf
- Ticaret Bakanlığı — 1 Ocak 2026 Sonrası ETDS Zorunluluğu — https://ticaret.gov.tr/haberler/1-ocak-2026-tarihinden-sonra-kurulacak-sirketlerde-elektronik-ticari-defter-sistemi-zorunlu-olacak
- Rekabet Kurumu — Birleşme ve Devralma Mevzuatı Güncellemesi — https://www.rekabet.gov.tr/tr/Guncel/birlesme-ve-devralma-mevzuati-guncellendi-f454d2c51e07f11193f50050568585c9
- Human Resources, Organisational Learning and Due Diligence in M&A — https://doi.org/10.1108/DLO-07-2021-0120
- Türk Borçlar Kanunu No 6098 — https://www.mevzuat.gov.tr/mevzuatmetin/1.5.6098.pdf
- İş Kanunu No 4857 — https://www.mevzuat.gov.tr/mevzuatmetin/1.5.4857.pdf
- Uluslararası İşgücü Kanunu No 6735 — https://www.mevzuat.gov.tr/mevzuatmetin/1.5.6735.pdf
- Kişisel Verilerin Korunması Kanunu No 6698 — https://www.mevzuat.gov.tr/mevzuatmetin/1.5.6698.pdf
- Controller–Processor Roles in Cloud Computing — https://doi.org/10.1093/idpl/ipad023
- Rekabetin Korunması Hakkında Kanun No 4054 — https://www.mevzuat.gov.tr/mevzuatmetin/1.5.4054.pdf
Footnotes
-
Türk Ticaret Kanunu No 6102 https://www.mevzuat.gov.tr/mevzuatmetin/1.5.6102.pdf accessed 1 September 2026. Company, branch, agency, representation, commercial books, management and liability provisions.↩︎
-
Ticaret Bakanlığı — 1 Ocak 2026 Sonrası ETDS Zorunluluğu https://ticaret.gov.tr/haberler/1-ocak-2026-tarihinden-sonra-kurulacak-sirketlerde-elektronik-ticari-defter-sistemi-zorunlu-olacak accessed 1 September 2026. Requirement for newly established companies to keep their share ledger and general-meeting book in ETDS.↩︎
-
Rekabet Kurumu — Birleşme ve Devralma Mevzuatı Güncellemesi https://www.rekabet.gov.tr/tr/Guncel/birlesme-ve-devralma-mevzuati-guncellendi-f454d2c51e07f11193f50050568585c9 accessed 1 September 2026. Recent changes to merger-notification thresholds and procedures.↩︎
-
Human Resources, Organisational Learning and Due Diligence in M&A https://doi.org/10.1108/DLO-07-2021-0120 accessed 1 September 2026. Peer-reviewed analysis of M&A due diligence and post-closing integration risks.↩︎
-
Türk Ticaret Kanunu No 6102 https://www.mevzuat.gov.tr/mevzuatmetin/1.5.6102.pdf accessed 1 September 2026. Company, branch, agency, representation, commercial books, management and liability provisions.↩︎
-
Ticaret Bakanlığı — 1 Ocak 2026 Sonrası ETDS Zorunluluğu https://ticaret.gov.tr/haberler/1-ocak-2026-tarihinden-sonra-kurulacak-sirketlerde-elektronik-ticari-defter-sistemi-zorunlu-olacak accessed 1 September 2026. Requirement for newly established companies to keep their share ledger and general-meeting book in ETDS.↩︎
-
Türk Ticaret Kanunu No 6102 https://www.mevzuat.gov.tr/mevzuatmetin/1.5.6102.pdf accessed 1 September 2026. Company, branch, agency, representation, commercial books, management and liability provisions.↩︎
-
Ticaret Bakanlığı — 1 Ocak 2026 Sonrası ETDS Zorunluluğu https://ticaret.gov.tr/haberler/1-ocak-2026-tarihinden-sonra-kurulacak-sirketlerde-elektronik-ticari-defter-sistemi-zorunlu-olacak accessed 1 September 2026. Requirement for newly established companies to keep their share ledger and general-meeting book in ETDS.↩︎
-
Türk Borçlar Kanunu No 6098 https://www.mevzuat.gov.tr/mevzuatmetin/1.5.6098.pdf accessed 1 September 2026. Contract, representation, services, liability, termination and compensation provisions.↩︎
-
Türk Borçlar Kanunu No 6098 https://www.mevzuat.gov.tr/mevzuatmetin/1.5.6098.pdf accessed 1 September 2026. Contract, representation, services, liability, termination and compensation provisions.↩︎
-
İş Kanunu No 4857 https://www.mevzuat.gov.tr/mevzuatmetin/1.5.4857.pdf accessed 1 September 2026. Employer, employment-contract, working-time, termination and workplace provisions.↩︎
-
Uluslararası İşgücü Kanunu No 6735 https://www.mevzuat.gov.tr/mevzuatmetin/1.5.6735.pdf accessed 1 September 2026. Work-permit, exemption, application and sanctions framework.↩︎
-
İş Kanunu No 4857 https://www.mevzuat.gov.tr/mevzuatmetin/1.5.4857.pdf accessed 1 September 2026. Employer, employment-contract, working-time, termination and workplace provisions.↩︎
-
Uluslararası İşgücü Kanunu No 6735 https://www.mevzuat.gov.tr/mevzuatmetin/1.5.6735.pdf accessed 1 September 2026. Work-permit, exemption, application and sanctions framework.↩︎
-
Kişisel Verilerin Korunması Kanunu No 6698 https://www.mevzuat.gov.tr/mevzuatmetin/1.5.6698.pdf accessed 1 September 2026. Controller/processor roles, processing conditions, transfers, security and registry obligations.↩︎
-
Controller–Processor Roles in Cloud Computing https://doi.org/10.1093/idpl/ipad023 accessed 1 September 2026. Allocation of roles in cloud services and the foreign-controller issue.↩︎
-
Kişisel Verilerin Korunması Kanunu No 6698 https://www.mevzuat.gov.tr/mevzuatmetin/1.5.6698.pdf accessed 1 September 2026. Controller/processor roles, processing conditions, transfers, security and registry obligations.↩︎
-
Controller–Processor Roles in Cloud Computing https://doi.org/10.1093/idpl/ipad023 accessed 1 September 2026. Allocation of roles in cloud services and the foreign-controller issue.↩︎
-
Rekabetin Korunması Hakkında Kanun No 4054 https://www.mevzuat.gov.tr/mevzuatmetin/1.5.4054.pdf accessed 1 September 2026. Restrictive agreements, dominance, mergers and acquisitions, and sanctions.↩︎
-
Rekabet Kurumu — Birleşme ve Devralma Mevzuatı Güncellemesi https://www.rekabet.gov.tr/tr/Guncel/birlesme-ve-devralma-mevzuati-guncellendi-f454d2c51e07f11193f50050568585c9 accessed 1 September 2026. Recent changes to merger-notification thresholds and procedures.↩︎
-
Rekabetin Korunması Hakkında Kanun No 4054 https://www.mevzuat.gov.tr/mevzuatmetin/1.5.4054.pdf accessed 1 September 2026. Restrictive agreements, dominance, mergers and acquisitions, and sanctions.↩︎
-
Rekabet Kurumu — Birleşme ve Devralma Mevzuatı Güncellemesi https://www.rekabet.gov.tr/tr/Guncel/birlesme-ve-devralma-mevzuati-guncellendi-f454d2c51e07f11193f50050568585c9 accessed 1 September 2026. Recent changes to merger-notification thresholds and procedures.↩︎
-
Türk Borçlar Kanunu No 6098 https://www.mevzuat.gov.tr/mevzuatmetin/1.5.6098.pdf accessed 1 September 2026. Contract, representation, services, liability, termination and compensation provisions.↩︎
-
Human Resources, Organisational Learning and Due Diligence in M&A https://doi.org/10.1108/DLO-07-2021-0120 accessed 1 September 2026. Peer-reviewed analysis of M&A due diligence and post-closing integration risks.↩︎
-
Türk Borçlar Kanunu No 6098 https://www.mevzuat.gov.tr/mevzuatmetin/1.5.6098.pdf accessed 1 September 2026. Contract, representation, services, liability, termination and compensation provisions.↩︎
-
Human Resources, Organisational Learning and Due Diligence in M&A https://doi.org/10.1108/DLO-07-2021-0120 accessed 1 September 2026. Peer-reviewed analysis of M&A due diligence and post-closing integration risks.↩︎
