With this penultimate part of our series, we are inexorably approaching the end, and we would like to at least briefly address the often rather underestimated aspect of post-acquisition company integration: compliance and confidentiality (or also "Corporate Compliance").
Therefore, in this article we will explain:
- what does compliance actually mean,
- why it is important to update a company's compliance framework after its acquisition, which legal areas it covers - with a focus on ESG and NIS2 - and
- what are the consequences of so-called non-compliance.
Especially as a result of recent developments in compliance, thanks to the adoption of new SCRD guidelines, which expanded the scope of ESG reporting, or the discussed amendments to the Act on Cybersecurity following the NIS2 directive, this is a very topical topic. Individual duties should not be underestimated! So let's look at the issue of compliance.
What is compliance?
The term "compliance" has no accurate equivalent in the Czech language. However, it deals with compliance or compliance with legal regulations. It thus refers to the processes and procedures that ensure that the company complies with all relevant laws, regulations, standards or codes of ethics. Includes creating internal policies and procedures, which prevent and detect violations of laws and regulations, thereby protecting the company from legal consequences and reputational damage.
Why is it important to update compliance after an acquisition?
After the acquisition of a new company, it is crucial to review and update its compliance programs to ensure that it complies with all applicable legal requirements and standards, even after its ownership changes. Here are a few reasons:
- Legal compliance: Ensuring that the practices of the newly acquired company are in line with the compliance standards and legal requirements of the parent company, which is necessary to prevent legal risks.
- Risk management: A compliance update helps identify and mitigate potential risks that may have been overlooked or that arise from the integration of a new entity.
- Reputation protection: Maintaining robust compliance protects a company's reputation by ensuring ethical business practices and legal compliance.
- Operational efficiency: A single compliance framework streamlines operations and ensures consistency across the entire business group.
Areas of compliance
Compliance covers a wide range of legal and other regulatory areas. First, we take a cross-sectional look at some basic areas of compliance:
- Criminal liability of legal entities or liability for misdemeanors: Even a company, as a legal entity, can be responsible for criminal acts (as well as misdemeanors) committed by its members. A properly set compliance program and compliance with prescribed legal and internal procedures can ensure that the company will not be held responsible for any criminal acts (or misdemeanors).
- GDPR: It is important not to forget that the company handles data not only of customers and business partners, but also of employees or members of statutory bodies. It is necessary to observe the rules for handling them, their management and their storage.
- AML: Some companies are also subject to AML obligations within the scope of their selected activities. And that either on the part of the obliged person or as a person identified and subsequently controlled. We are happy to help you with AML!
- Whistleblowing: It is necessary to have an internal system set up for potential whistleblowers to make a report. It is prohibited to take retaliatory measures against whistleblowers for reporting illegal activities. It is also necessary to identify the appropriate person to whom company members can contact.
Due to the recent or upcoming changes in compliance in the case of ESG reporting and cyber security, we will further focus on the most important news in these areas:
1. Environmental, social, governance (ESG)
What is ESG? ESG criteria are a set of standards for a company's operations that sustainability-oriented investors use to evaluate potential investments. Environmental criteria consider how a company acts as a steward of nature, social criteria examine how it manages relationships with employees, suppliers, customers and communities, and governance factors relate to corporate governance, audits, internal controls and shareholder rights.
Why is compliance with ESG rules important?
- Attracting investors: ESG compliance is increasingly important for investors seeking sustainable and ethical investments.
- Regulatory requirements: Compliance with ESG criteria helps to meet legal obligations and avoid sanctions.
- Brand reputation: It enhances the company's image and builds consumer confidence.
Steps to ensure compliance with ESG:
- Evaluation of current practices: Evaluate the existing ESG practices of the newly acquired company.
- Integration of ESG policies: Develop and integrate comprehensive ESG policies and procedures.
- Reporting and monitoring: Report regularly on ESG performance and continuously monitor and improve practices.
Changes in ESG?
As you may have already noticed and as we already indicated in the introduction, the obligations in the field of ESG compliance will expand considerably. A new EU directive was adopted (Corporate Sustainability Reporting Director, abbreviated CSRD) which on the one hand expands the range of obliged entities and on the other hand sets much more comprehensive and stricter conditions for reporting. However, due to its scope, we are preparing a separate large article on this topic, so be sure to follow us in the future!
2. Directive on Network and Information Security (NIS2)
What is NIS2? NIS2 is an EU directive that aims to raise the level of cybersecurity in member states by introducing stricter cybersecurity risk management requirements and reporting obligations for critical infrastructure sectors.
Why is NIS2 compliance important?
- Cyber Security: Increases the company's resistance to cyber threats and attacks.
- Legal compliance: Non-compliance can lead to significant financial penalties.
- Business Continuity: It ensures the safety and continuity of essential services.
Steps to ensure compliance with NIS2:
- Risk assessment: Conduct a comprehensive risk assessment to identify potential cyber threats.
- Implementation of security measures: Adopt appropriate security measures and protocols.
- Incident reporting: Establish a clear incident reporting process to comply with NIS2 requirements.
- Training: Provide cybersecurity training to employees on a regular basis.
Consequences of non-compliance
Failure to meet various compliance standards can have serious consequences for a company, including:
- Financial penalties: Failure to comply can result in significant fines and legal consequences.
- Damage to reputation: Violations and non-compliance can damage a company's reputation, leading to loss of customer trust and lost business opportunities.
- Operational barriers: Regulatory sanctions can disrupt a company's operations and lead to costly legal disputes (eg, losing a license to operate a certain type of transport can be catastrophic for a transport company).
- Loss of investor confidence: Investors may limit their support, which will affect the company's financial stability and growth prospects.
záver
Compliance programs take time. And that also, or rather precisely, within the framework of the acquisition of the company. By understanding the importance of compliance, updating compliance programs post-acquisition, and focusing on its key areas, companies can mitigate risk, protect their reputation, and ensure long-term stability. Remember that paying close attention to compliance not only protects a company legally, but also increases its overall integrity and can, in turn, bring many opportunities.
In the final part of our series, we will summarize the most important and briefly think about ways to ensure the company's growth even in the long term.
Do you need advice or representation at purchase of the company? Do you have any questions about our series or the topic of compliance? Contact us! We have many years of experience in buying companies!

JUDr. Ing. Jan Vych, attorney and partner