Board Meetings
Data sovereignty in M&A: How boards protect confidentiality and information flow

Sensitive deal information is only as secure as the channels used to move it. During M&A, board packs, valuation details, legal advice, meeting minutes, board approvals, and follow-up actions can move across many people in a short period of time.
Data sovereignty gives the board a practical control lens: where the information is hosted, who can access it, how it is protected, and what evidence exists when a regulator, auditor or counterparty asks how the record was managed.
In this article, we explore:
- How the regulatory landscape is shifting and how boards can keep ahead
- How boards can ensure data sovereignty throughout multi-deal M&A
- Practical guidance on controls that boards should have in place
- The ways Sherpany supports boards in maintaining data sovereignty when it matters most

Confidentiality is a control and legal liability issue
In a deal, confidentiality does not fail only when a system is breached. It can fail when the wrong participant keeps access after a role changes, when a board pack is downloaded to an unmanaged device, or when minutes are circulated outside the authorised group.
These are not only operational weaknesses. Boardroom participants, committee members and advisers may be bound by confidentiality duties, insider information rules, NDAs or engagement terms. Uncontrolled access or onward sharing can therefore expose the organisation and individuals to regulatory, contractual and reputational consequences.
The control model should cover three assets: the documents used for preparation, the decisions taken in the meeting and the record that remains afterwards. Each asset needs clear ownership, a permitted audience, permitted actions, a retention period and evidence of who accessed or approved it.
This turns confidentiality from a policy statement into a provable governance process. If access is restricted, activity is logged and records are retained, the board is better placed to show that sensitive information was handled within an authorised and auditable flow.
Growing regulatory pressure points towards stronger controls
Regulatory pressure is already intense, and the direction of travel is clear. GDPR, DORA, NIS2, FINMA, BaFin, ISO 27001 and TISAX do not all apply to every company, but they point towards the same expectation: sensitive information needs controlled access, tested resilience, supplier oversight and retained evidence.
That pressure is not static. DORA is of recent application for financial entities and ICT third-party risk, while NIS2 is strengthening cybersecurity expectations across critical sectors in the EU. In the UK, the Cyber Security and Resilience Bill is under discussion and would extend cyber obligations to a wider set of digital supply-chain actors, including managed service providers, data centres and critical suppliers.
Other upcoming frameworks point in the same direction. The EU Cyber Resilience Act is being phased in with mandatory cybersecurity requirements for products with digital elements, while parts of the EU AI Act are also coming into force, with requirements around governance, logging, risk management and human oversight.
For M&A governance, the lesson is practical. Boards should not wait for every rule to apply directly before tightening meeting controls, because regulatory pressure is moving towards provable security, controlled suppliers, incident readiness and auditable records.
Three controls boards should require
1. Access rights that follow the deal perimeter
Need-to-know access should be applied at document and meeting-room level. A board member, advisor or executive should see only the materials needed for their role, and access should change immediately when that role changes.
Practical controls include restricted groups, time-bound access, and a documented access matrix for board packs, legal papers, minutes and circular resolutions.
2. Document controls that travel with the file
Confidentiality should not depend on a single folder. Sensitive documents need controls for download, print, watermarking, offline access and device revocation.
These controls reduce the number of uncontrolled copies and support an auditable trail. They also help company secretaries and legal teams respond faster when a document must be withdrawn, replaced or restricted.
3. Evidence for decisions and post-meeting actions
In M&A, the record is as important as the meeting. Decisions, recusals, restrictions on communication, conditions for approval and follow-up actions should be captured in a structured record.
Minutes should be finalised quickly, signed digitally where relevant, and made available only to authorised recipients. That discipline supports data sovereignty because the decision record stays connected to the controlled environment.
Operating model for Company Secretaries
Company secretaries can turn these principles into a repeatable meeting governance model. Before each M&A meeting, they should confirm the access group, document classification, permitted actions and review status of each participant.
The meeting room should contain only the approved pack and current versions. Drafts, side papers and late additions should enter the same controlled process, not a parallel channel.
After the meeting, they should close the loop: finalise minutes, record decisions and restrictions, assign actions, revoke temporary access and preserve audit evidence. The practical test is whether the organisation can show, without reconstructing email chains, what information was available, who accessed it and which record became final.
For regulated groups, the same model should connect to vendor risk and outsourcing controls. A platform used for M&A meeting governance should be assessed not only on features, but on hosting location, encryption, access controls, operational resilience, support access and assurance evidence.
That evidence should be available before the deal timeline creates pressure. Once a live transaction begins, teams have little time to redesign controls.
Sherpany’s approach to sensitive M&A meeting data
For M&A governance, the question is not only whether a platform can share board packs. The question is whether the provider can prove how it protects access, evidence, continuity and customer data when the information is highly confidential. Sherpany is built for regulated organisations that need this level of proof, including financial services firms and large enterprises handling sensitive boardroom information.
Sherpany’s trust model starts with transparency and independent assurance. The platform maintains ISO 27001:2022 and ISAE 3000 Type II certifications, with ISAE control effectiveness certified annually by BDO Switzerland since 2015. Its ISO 27001 scope covers development, maintenance and day-to-day platform operation, not only physical data centres.
For financial services teams, this matters because supplier risk is part of the governance process. Sherpany is designed to help customers adhere to GDPR, FADP, FINMA regulations, DORA, NIS2 and banking secrecy rules. It also undergoes independent audits against FINMA outsourcing requirements and BaFin, and maintains TISAX compliance for organisations exchanging sensitive information across supply chains.
This assurance translates into the meeting process itself. M&A materials, committee papers, approvals, minutes and post-meeting records can be kept in one controlled environment, with granular access rights, document-level restrictions, watermarking, controlled download and print settings, and audit trails. This keeps confidentiality tied to the governance process rather than scattered across email, chat and local folders.
Sherpany also provides stronger evidence when decisions need to be reconstructed later. Digital Circular Resolutions keep time-sensitive approvals inside an auditable process, while controlled approval and signing workflows protect the integrity of minutes. Once minutes are approved and signed, organisations have a clearer record of what was approved, by whom and when, reducing the risk of uncontrolled changes or competing versions.
Control also extends to Sherpany’s own access to customer data. Employees do not access customer data as standard practice, support sessions require customer authorisation, are time-bound and logged, and backend access uses strong authentication, just-in-time privileges and session recording. These controls are particularly relevant where board records, deal papers and sensitive approvals must remain confidential.
Trust is not limited to published certifications. Sherpany works with independent security partners, conducts regular third-party penetration tests, and has a formal policy that allows customers to conduct their own penetration tests of the platform. Customers can also review Sherpany’s current security posture through the Trust Center, which supports a transparent and inspectable approach to security.
Security and compliance evidence that support data sovereignty
Sherpany supports data sovereignty through a combination of technical controls, operational discipline and independent assurance. Access is protected with 2FA, Single Sign-On via SAML 2.0, strong password policies, rate limiting, session timeout, concurrent session control, IP whitelisting and authentication logging. Data in transit is encrypted with SSL-TLS-256, while mobile access is protected through sandboxing, local data protection, Mobile Device Management controls, screenshot prevention and device access revocation.
Sensitive content is protected at document level. Each customer document is encrypted with AES-GCM-256 and a dedicated key, managed through a secure vault with logged, monitored and audited access limited to authorised staff. Sherpany also processes AI-related meeting information within its secure Swiss infrastructure, without sending data to third-party cloud AI providers or training models on customer data.
The same control model extends to evidence and continuity. Sherpany provides audit trails for file and user activity, replicates security-relevant logs to tamper-resistant storage, and supports resilience through geo-redundant Swiss data centres, real-time replication, encrypted daily backups and regular restore testing. Internal access to customer data is restricted, with customer-authorised support sessions, time limits, logging, strong authentication, just-in-time privileges and session recording.
This is backed by compliance evidence relevant to regulated organisations and large enterprises. Sherpany is designed to help clients adhere to GDPR, FADP, FINMA, DORA, NIS2 and banking secrecy requirements, and maintains certifications and attestations including ISO 27001:2022, ISAE 3000 Type II, FINMA Outsourcing, BaFin Outsourcing and TISAX. Its ISO 27001 scope covers development, maintenance and day-to-day platform operation, which matters because data sovereignty depends on people, processes and software controls, not only hosting location.
This legal structure also matters when considering CLOUD Act exposure. Sherpany is a Swiss company incorporated under Swiss law, and customer contracts are governed by Swiss law and GDPR. It is therefore not subject to US disclosure obligations in the same way as a US provider: Sherpany can only comply with requests that are consistent with Swiss law and GDPR, for example where a foreign order has been confirmed through the appropriate Swiss legal process. Where a request conflicts with Swiss law or GDPR, Sherpany cannot comply with it.
Secure your board’s most valuable asset today
Data is indisputably your board’s most valuable asset. Data sovereignty in M&A, therefore is not a technical footnote, but is how your board controls the movement, access, and evidence of sensitive information across the entire meeting lifecycle.
Boards should assess whether every M&A-related meeting follows the same rules: restricted access, protected documents, auditable actions, controlled minutes and compliant retention. When those controls are applied through a secure platform, confidentiality and information flow become easier to govern.
Sherpany gives Company secretaries, boards and regulated organisations a practical way to apply those controls across M&A meeting governance. The result is a more controlled record of sensitive information, decisions and actions at the points where deal risk is most concentrated.
Visit the Sherpany Trust Centre to learn more about our approach to security, and if you would like to discuss Sherpany in the context of your board, book a free consultation with one of our meeting experts today.
About the author
Ludovico Peruzzi
Ludo Peruzzi is Security Officer at Sherpany. He's responsible for ensuring the highest standards of security and implementing best practice for our customers, stakeholders, and our team.