Due diligence in the Netherlands: what a buyer must investigate

Magnifying glass over financial charts and reports on a desk, illustrating a due diligence investigation

A due diligence investigation in the Netherlands is the structured examination a buyer, investor or financier carries out before committing to a transaction, in order to establish what a business is really worth and which risks travel with it. Dutch law prescribes no fixed programme, but it attaches hard consequences to the outcome. What the seller should have disclosed but kept quiet can make the agreement voidable for error under article 6:228 of the Dutch Civil Code (Burgerlijk Wetboek); what the buyer could reasonably have discovered and simply did not investigate normally stays with the buyer. Due diligence therefore decides not only the price, but also which warranties you can still invoke a year after completion.

What a due diligence investigation actually is

A due diligence onderzoek is a fact-finding exercise, not an audit. An auditor looks backwards and confirms that historical figures have been recorded in accordance with accounting standards. A due diligence team asks a different, forward-looking question: given everything this company has signed, borrowed, promised, employed, built and litigated, what will it cost the buyer after completion, and what should therefore change in the price, in the timetable or in the contract.

That difference matters in practice. A clean audit opinion says nothing about a distribution agreement that terminates on a change of control, about a pension arrangement that has been underfunded for years, or about a permit that expires six months after the deal closes. Those are the findings that move a purchase price, and they only surface if someone reads the underlying documents rather than the summary the seller prepared.

The investigation is normally run by the buyer, at the buyer's cost, after a letter of intent and a confidentiality agreement have been signed. Increasingly, sellers run their own vendor due diligence first, so that they can control the narrative and shorten the buyer's process. Either way the exercise is the same: identify the facts, quantify the exposure, and decide what to do about it.

Lawyers reviewing due diligence documents for a Dutch acquisition

The workstreams and what each one is looking for

Most transactions are broken down into parallel workstreams, each staffed by its own specialists. The table below sets out the standard division and the findings that typically justify a price adjustment or a specific indemnity.

Workstream

Primary focus

Findings that change the deal

Financial

Quality of earnings, working capital, net debt, off-balance-sheet commitments.

Non-recurring items presented as structural profit, hidden guarantees, customer concentration.

Legal

Title to the shares or assets, corporate records, contracts, permits, litigation.

Change-of-control clauses, defective share transfers, pending proceedings, missing permits.

Employment

Contracts, collective labour agreement, pensions, works council, key personnel.

Wrongly applied collective agreement, unfunded pension liabilities, no works council advice obtained.

Tax

Filing history, open positions, rulings, fiscal unity, transfer pricing.

Disputed positions, expired rulings, exposure that survives the transfer. Run with a tax adviser.

Property and environment

Ownership and lease titles, zoning, soil condition, environmental permits.

Contamination, use in breach of the zoning plan, leases that end on a change of control.

IT and data protection

Licences, source code ownership, security incidents, processing of personal data.

Software built by contractors without an assignment of rights, unreported data breaches.

Regulatory and compliance

Sector licences, sanctions screening, anti-money-laundering procedures, competition law.

Missing merger clearance, an unfiled notification under the investment screening rules.

ESG

Emissions and waste, supply chain conditions, governance and anti-corruption policies.

Liabilities that only become visible once sustainability reporting obligations bite.

Not every deal needs every workstream at full depth. A minority participation in a software company justifies a hard look at intellectual property, data protection and shareholder arrangements, while a manufacturing site demands soil investigation and permits. Scoping is a decision, and it should be a documented one: the areas you deliberately leave out are the areas where a warranty or an indemnity has to do the work instead.

How Dutch law divides the risk between seller and buyer

The legal reason for due diligence in the Netherlands is that Dutch law splits the burden of a defect between the parties. The seller has a duty to disclose (mededelingsplicht) and the buyer has a duty to investigate (onderzoeksplicht), and the way a court balances the two determines who carries a defect that only becomes visible after completion.

The starting point is that negotiating parties stand in a relationship governed by good faith. Since the Supreme Court's Baris/Riezenkamp judgment of 1957 it has been settled that each party must take the other party's reasonable interests into account during negotiations, which means informing yourself and, at the same time, not allowing the other side to contract on a false assumption. In later case law the Supreme Court has consistently held that where both duties collide, the seller's duty to speak generally prevails over the buyer's duty to look. A seller who knew about a defect cannot usually escape liability by arguing that the buyer should have found it.

That priority is not absolute, and it weakens exactly where most transactions sit. A professional buyer, advised by lawyers and accountants, with access to a data room and a question-and-answer procedure, is expected to use them. If the information was in the data room and the buyer did not read it, the buyer is unlikely to be heard afterwards.

The remedies if the picture turns out to be wrong

Three routes are available under Dutch law once a buyer discovers that the company is not what it appeared to be. Each has its own threshold and its own consequence.

  • Error (dwaling), article 6:228 BW. An agreement concluded under the influence of an incorrect assumption can be annulled if the assumption was caused by information from the other party, if the other party should have disclosed the true position, or if both parties made the same mistake. Article 6:230 BW allows the court to modify the effects of the contract instead of annulling it, which in practice usually means a price reduction.

  • Fraud (bedrog), article 3:44 BW. Where the seller deliberately gave false information, deliberately concealed a fact he had a duty to disclose, or used another artifice to induce the transaction, the agreement is voidable and damages are available alongside.

  • Non-conformity, article 7:17 BW. A sale can also relate to property rights, including shares, under article 7:47 BW, and the conformity rule applies to the extent that this fits the nature of the right. In a share transaction the object sold is the shares, so a buyer who wants the condition of the underlying business to be a contractual quality has to say so in the agreement. That is precisely what warranties are for.

There is a trap attached to the third route. Under article 7:23 BW a buyer must notify the seller within a reasonable period after discovering a defect, or after the moment the defect should reasonably have been discovered, and a claim then lapses two years after that notification. Buyers who spend a year building a file before writing their first letter regularly lose the claim on this point alone. General contractual claims are in any event subject to the five-year limitation period of article 3:307 BW.

Share deal or asset deal: the structure changes the investigation

The single decision that most affects the scope of a due diligence investigation is whether the buyer acquires the shares in the company or a defined set of assets and liabilities. The two structures allocate historic risk in opposite directions.

In a share deal the buyer steps into an existing company with its entire past attached. Every contract, permit, tax position, employment relationship and dormant claim stays where it is, because the legal entity does not change. Nothing needs to be transferred individually, which is administratively simple, but it means the investigation has to be broad: anything you do not find, you buy. Transfer of shares in a Dutch private limited company (besloten vennootschap) requires a notarial deed executed before a civil-law notary in the Netherlands under article 2:196 BW, and the notary will want to see an unbroken chain of title, which is why gaps in the shareholders' register are a genuine deal issue rather than a formality.

In an asset deal the buyer picks what it wants. Liabilities that are not expressly assumed remain with the seller, which reduces exposure, but each element has to be transferred in its own way. Contracts do not follow automatically: a transfer of contract under article 6:159 BW requires a deed and the cooperation of the counterparty, so a supplier or landlord effectively holds a veto and may use it to renegotiate. Permits are often personal to the holder and have to be reapplied for or transferred with the competent authority's consent.

Employees are the exception that catches buyers out. Where an asset deal amounts to a transfer of an undertaking within the meaning of articles 7:662 and following of the Civil Code, the employees working in that undertaking transfer to the buyer automatically, with their existing terms and conditions, whether or not the parties wanted that result. The former employer remains jointly liable for a year for obligations that arose before the transfer. You cannot cherry-pick a workforce, and an employment due diligence that treats staff as a schedule to be negotiated is looking at the wrong problem. Our article on refusing a transfer of undertaking sets out how this works from the employee's side.

Comparing a share deal and an asset deal during due diligence in the Netherlands

The legal files that decide the price

Legal due diligence is where most value is won or lost, because the findings are usually binary: either the buyer will own the intellectual property after completion or it will not, either the lease survives the transaction or it does not. Four areas produce the majority of serious findings in Dutch transactions.

Corporate records and title

The first task is to establish that the seller can actually sell what it is offering. That means reading the articles of association rather than the extract from the trade register, checking the shareholders' register against the deeds of issue and transfer, and confirming that every past resolution that needed shareholder or supervisory board approval was in fact taken. Dutch articles frequently contain a transfer restriction, an offer obligation or a drag-along and tag-along arrangement, and a shareholders' agreement may add consent rights that survive the sale. Where a company has minority shareholders, their statutory position is far stronger than many foreign buyers expect, as our guide to minority shareholders in the Netherlands explains.

Contracts and change of control

Commercial contracts are reviewed for three things: what the company has committed to, for how long, and what happens when ownership changes. Change-of-control clauses give a counterparty a right to terminate or renegotiate, and in a business built on a handful of customer or distribution agreements a single such clause can remove a large part of the value the buyer is paying for. The same applies to bank facilities, leases, franchise arrangements and licences. Where a critical clause is found, the practical answer is usually a condition precedent: no completion until the counterparty has confirmed in writing that it will not exercise the right.

Employment, the works council and pensions

Employment findings are rarely dramatic individually and often significant in aggregate. The recurring questions are whether a collective labour agreement applies and has been applied correctly, whether the pension arrangement is properly funded and documented, whether fixed-term chains have inadvertently become permanent contracts, and whether key employees are bound by enforceable non-competition clauses. Since Dutch law imposes strict written-form requirements on non-competition clauses, a clause that looks protective on paper is frequently unenforceable in practice.

Procedurally, article 25 of the Works Councils Act (Wet op de ondernemingsraden) gives a works council the right to advise on a proposed transfer of control over the undertaking, and that advice must be sought at a moment when it can still influence the decision. Asking after signing is not asking. In addition, the SER Merger Code obliges parties to notify the relevant trade unions before an agreement is reached. Neither step blocks a transaction, but skipping them creates a challengeable decision and a poor start with the workforce.

Permits, property, data and clearances

For asset-heavy businesses the environmental and permit file is the risk. Soil investigation, historic contamination, the actual use of a site against its zoning designation and the expiry dates of environmental permits all belong in the report, because remediation obligations attach to the site and to the operator rather than to whoever caused the problem.

Two clearances deserve specific attention in Dutch deals. Where the parties' turnover exceeds the thresholds in the Competition Act (Mededingingswet), the concentration must be notified to the Netherlands Authority for Consumers and Markets (ACM) and may not be implemented before clearance; the ACM publishes the thresholds in force. Separately, the Investments, Mergers and Acquisitions Security Screening Act (Wet veiligheidstoets investeringen, fusies en overnames), in force since 1 June 2023, requires acquisitions of control in vital providers and in undertakings holding sensitive technology to be notified to the Bureau Toetsing Investeringen, and the transaction may not be implemented until that assessment has been completed. Missing either notification is not a technical slip: it exposes the parties to fines and, in the worst case, to unwinding the transaction.

Finally, the investigation itself processes personal data. Employment files, customer records and management assessments fall under the General Data Protection Regulation, so the standard practice is to anonymise or aggregate personnel data, disclose individual files only for a small group of key employees, and use a clean team where competitively sensitive information is involved.

Customer due diligence under the Wwft is a separate statutory duty

The term due diligence is used in Dutch practice for two entirely different things, and confusing them is expensive. Transactional due diligence is voluntary and commercial. Customer due diligence under the Anti-Money Laundering and Anti-Terrorist Financing Act (Wet ter voorkoming van witwassen en financieren van terrorisme, Wwft) is compulsory, continuous and enforced by regulators.

The Wwft designates banks, insurers, payment institutions, investment firms, trust offices, accountants, tax advisers, civil-law notaries, estate agents, traders in goods and, in defined circumstances, lawyers as institutions with gatekeeper duties. Article 3 Wwft requires them to carry out client investigation before entering into a business relationship or executing a transaction: establish and verify the identity of the client, identify the ultimate beneficial owner and take reasonable measures to verify that identity, establish the purpose and intended nature of the relationship, and monitor it on a continuing basis. The depth of the investigation is risk-based, and enhanced measures apply to politically exposed persons and to relationships involving higher-risk jurisdictions.

Article 16 Wwft adds the reporting duty: an unusual transaction must be reported to the Financial Intelligence Unit Nederland without delay after it becomes known. The threshold is deliberately low, because unusual is not the same as suspicious, and the institution is not permitted to inform the client that a report has been made. Supervision is divided among De Nederlandsche Bank, the Netherlands Authority for the Financial Markets, the Financial Supervision Office and the Tax Administration's Wwft supervision bureau, with the local bar association supervising lawyers. Enforcement ranges from a formal instruction to substantial administrative fines and, in serious cases, criminal prosecution, and the measures imposed on financial institutions and trust offices are published.

Two practical points recur. First, the ultimate beneficial owner register kept in the trade register is no longer open to the public: after the Court of Justice of the European Union struck down general public access in its judgment of 22 November 2022, access in the Netherlands is limited to competent authorities, the Financial Intelligence Unit and, under conditions, institutions performing client investigation under the Wwft. Institutions therefore cannot rely on a register search alone and must document their own verification. Second, sanctions screening under the Sanctions Act 1977 runs alongside the Wwft and is a separate obligation with its own reporting line. Our guide to money laundering rules in the Netherlands sets out the framework in full.

Sustainability due diligence: what the CSDDD will require

Environmental, social and governance findings have moved from a reputational annex to a valuation item, and European legislation is the reason. The Corporate Sustainability Reporting Directive already obliges large companies to report on sustainability matters, which means a buyer can increasingly test claims against published data rather than management assurances.

The Corporate Sustainability Due Diligence Directive goes further and makes the investigation itself mandatory. It was substantially amended by Directive (EU) 2026/470, published in the Official Journal on 26 February 2026. In its amended form the directive applies to EU companies with more than 5,000 employees and a net worldwide turnover above 1.5 billion euro, and to non-EU companies generating turnover above that figure within the European Union. Member States must transpose it by 26 July 2028, and the obligations apply to companies from 26 July 2029. The amended text works in two steps: a scoping exercise on the basis of reasonably available information, followed by in-depth assessment only where adverse impacts are most likely and most severe. The mandatory European civil liability regime was removed, so liability will follow national law, with a review clause revisiting the point in 2031.

None of this is yet in force in Dutch law, and no buyer should be told otherwise. What it does mean is that a target which will fall within scope, or which supplies a customer that does, needs to be able to show where its inputs come from and how it monitors conditions in its chain. Where that evidence does not exist, the cost of building it belongs in the business plan.

How the process runs and how long it takes

A due diligence investigation follows a fixed sequence, and the discipline of that sequence is what keeps it from becoming an open-ended document review. The stages below describe how a well-run process moves from a letter of intent to a report that a board can decide on.

Timeline of a due diligence investigation in a Dutch acquisition

It starts with scope. Before a single document is requested, the buyer decides what the transaction is meant to achieve and which risks would actually change the decision. A full acquisition of a manufacturing group justifies every workstream; a minority investment in a software company may justify only intellectual property, data protection, key contracts and the shareholder arrangements. Scope determines cost, and an unscoped investigation is the most reliable way to spend a large budget on findings nobody acts on.

Next comes the team and the paperwork that protects it. A confidentiality agreement is signed, a letter of intent records the price mechanism, the exclusivity period and whether the parties are bound to anything, and the buyer assembles legal, financial and, where relevant, technical and environmental specialists. Under Dutch law a letter of intent is not automatically non-binding: if negotiations have reached a stage where the other party could reasonably expect an agreement to follow, breaking off can give rise to liability, so what the document says about withdrawal matters.

The request list follows, organised by workstream, and the seller uploads the documents to a virtual data room. From that point the process runs on the question-and-answer log. Every request, every answer and every missing document is recorded, because that log is the evidence of what the buyer was told and when. It is also the raw material for the disclosure letter, which determines exactly which warranties the seller has qualified.

Analysis is where the workstreams have to talk to each other. A termination right spotted by the legal team only becomes a valuation issue once the financial team has attached a revenue figure to the contract concerned. That is why weekly findings sessions across all advisers produce better outcomes than parallel reports delivered at the end.

The report closes the process. A usable due diligence report is short at the front and detailed at the back: a summary of the findings that could change the decision, each with an estimated exposure, a likelihood and a proposed remedy, followed by the underlying analysis. Findings without a proposed remedy are of limited use to the person who has to sign.

On timing, there is no fixed rule. A focused review of a small Dutch company is typically a matter of weeks. A cross-border transaction with multiple subsidiaries, regulatory clearances and a real estate portfolio runs for several months. The variable that dominates the timetable is almost never the buyer's advisers: it is how quickly and how completely the seller fills the data room.

Turning findings into contract protection

A finding only has value once it has been converted into something enforceable. Dutch share purchase agreements use a standard toolkit, and the choice between the instruments depends on whether the risk is unknown, known, or known and quantified.

Warranties (garanties) are contractual statements about the state of the company on which the buyer is entitled to rely. They cover the unknown: the buyer did not find a problem, and if one nonetheless emerges the seller pays. Their reach is defined by the disclosure letter and the data room, because whatever has been fairly disclosed is normally carved out. This is the point at which the question-and-answer log becomes decisive, and it is why a buyer should insist that only specifically disclosed items qualify a warranty, rather than the entire contents of the data room.

An indemnity (vrijwaring) deals with the known. Where the investigation has identified a specific exposure, such as a pending tax dispute, an environmental clean-up obligation or an employment claim, the seller undertakes to reimburse that exposure in full, without the buyer having to prove loss or breach. Indemnities are usually not subject to the thresholds and caps that limit warranty claims.

Where the exposure is known and quantifiable, the cleanest solution is often the simplest: reduce the price. Alternatives are an escrow account holding part of the consideration for an agreed period, a deferred payment, or an earn-out that ties part of the price to future performance. Where the parties want to close the gap without a long negotiation, warranty and indemnity insurance transfers the warranty risk to an insurer, and the underwriter will want to see the due diligence reports before it will write the policy. A thin investigation therefore reduces the cover available, which is a further reason not to economise on scope.

Finally, the limitation architecture deserves as much attention as the warranties themselves. Purchase agreements set their own notification windows, de minimis thresholds, baskets and caps, and those contractual periods are typically much shorter than the statutory five years. Diarise them on the day of completion. A buyer who discovers a breach in month thirteen of a twelve-month warranty period has, for practical purposes, no claim.

Mistakes that cost buyers money

The same errors recur in due diligence in the Netherlands across sectors and deal sizes, and none of them are sophisticated.

The most common is starting too late. Due diligence that begins after the price has been agreed in a letter of intent is negotiating from a weak position, because every finding then reads as an attempt to renegotiate rather than as a fact that was always there.

The second is accepting summaries. Sellers produce contract overviews, and those overviews are often accurate about term and price and silent about termination rights. Read the contracts that matter.

The third is treating procedural steps as formalities. Works council advice, trade union notification, merger clearance and investment screening each have their own timing, and each of them can delay completion by weeks if it is picked up late. They belong in the timetable from day one, not in the closing checklist.

The fourth is failing to close the loop. A finding that is recorded in a report but not reflected in the price, in a warranty, in an indemnity or in a condition precedent has cost money to discover and protects nobody. Every red flag should be traceable to a line in the agreement.

The fifth is losing the file. After completion, the data room, the question-and-answer log and the disclosure letter are the evidence base for any claim. They should be archived in a form that can still be opened and relied upon years later, together with a note of when each contractual period expires.

For transactions in the technology sector, where intellectual property and data are the substance of the deal, our article on mergers and acquisitions in the tech sector goes into the specific pitfalls. A broader overview of the field is collected in our Dutch corporate law guides, and our wider practice in Dutch business law is set out on our website.

Frequently asked questions about due diligence

Three questions come up in almost every first meeting about a due diligence investigation. The short answers are below.

How long does a typical Due diligence investigation take?

There’s really no “one-size-fits-all” answer here. The timeline depends entirely on the complexity of the deal, the size of the target company, and just how deep you need to dig.

A fairly straightforward review of a small business might be done and dusted in a few weeks. On the other hand, a major, cross-border merger and acquisition can easily stretch out for several months. Honestly, the biggest factor that sways the timeline is how cooperative the seller is—how quickly and completely they open up the data room with all the necessary information.

What is the difference between Due diligence and an audit?

While both involve poring over company records, their fundamental goals are worlds apart. It helps to think of it as the difference between a historian looking at the past and a strategist planning for the future.

An audit is almost entirely backward-looking. Its main job is to verify that a company's historical financial statements are accurate and line up with accepted accounting standards. It’s all about confirming what has already happened.

Due diligence, however, is firmly forward-looking. It’s a much broader investigation designed to sniff out and weigh up future risks and opportunities tied to a specific business deal. It goes far beyond the numbers to cover legal, operational, and strategic areas to get a real sense of future performance.

Who is responsible for performing Due diligence?

The responsibility for kicking off and managing the due diligence process lies squarely with the acquiring or investing party. At the end of the day, they're the ones taking on the risk.

But actually carrying it out? That’s always a team effort. The investigation team is usually a mix of in-house experts from the buyer's finance, legal, and operations departments.

The seller’s main responsibility is to cooperate fully by providing accurate and timely information. This partnership is absolutely crucial for a smooth and effective due diligence process.

To cover all the bases, this core team is almost always supported by external specialists. We’re talking about lawyers, specialised accountants, environmental consultants, and IT experts who bring deep, focused expertise to the table. The seller makes this possible by organising all the requested documents in a secure virtual data room.

Law & More advises buyers, sellers, investors and management teams on due diligence in the Netherlands, from scoping the investigation and running the data room to translating the findings into warranties, indemnities and a price that reflects what you are actually acquiring. We also assist financial institutions and professional firms with their client investigation and reporting duties under the Wwft. If you are preparing a transaction or have received a set of findings you are not sure how to act on, please contact our lawyers.

Need Legal Assistance?

Contact Law & More for expert guidance on your legal matters. Our multilingual team is ready to help.

Related articles

{ "@context": "https://schema.org", "@type": "FAQPage", "mainEntity": [ { "@type": "Question", "name": "What are

A legal demerger in the Netherlands (juridische splitsing) is a corporate restructuring governed by Title

This page is part of Law and More guide to handling business disputes in Dutch

A startup term sheet sets out the proposed terms of an investment before the definitive

Enforcing an intellectual property right in the Netherlands is quicker and more effective than most

Explore tripartite agreements and gain comprehensive understanding of their significance, functions, and implications in the

Stay Updated on Dutch Law

Subscribe to our newsletter for the latest legal insights, regulatory updates, and practical advice.