[codicts-css-switcher id=”346″]

Global Law Experts Logo
global law experts default thumbnail cover news

How to Handle Software Licences & IT Due Diligence in Swedish M&A (2026)

By Global Law Experts
– posted 2 hours ago

Who this guide is for: corporate buyers, sellers, in-house counsel and M&A advisers working on Swedish M&A where software, IT contracts and personal data are material to the deal. Read on for a practical playbook covering transferability, third-party consents, IT due diligence tasks and contractual risk allocation.

Software licence transfer Sweden is now one of the most under-appreciated closing risks in Swedish M&A, and 2026 has sharpened its edge. Continued digitalisation, heavy dependence on SaaS platforms and elevated deal activity mean that the fate of a target’s software estate can determine whether a transaction closes on time or slips. Buyers frequently discover late in the process that a business-critical licence cannot move without a third party’s blessing, or that personal data flows have never been mapped. This guide is a practitioner-led playbook, not a marketing summary, designed to help transaction teams identify transferability, secure consents, run disciplined IT due diligence and allocate GDPR risk in the sale documents.

Intro, why software licences are a closing risk in Swedish M&A

Modern Swedish businesses run on licensed software: enterprise resource planning systems, customer relationship platforms, hosted analytics, embedded tooling and open-source components woven through proprietary code. Each of these carries contractual terms that may or may not survive a change of ownership. When those terms are ignored until the final weeks, they create a scramble that can push completion back or force uncomfortable price adjustments. A software licence transfer Sweden analysis therefore belongs early in the deal timetable, not as an afterthought.

The key takeaways for any transaction team are:

  • Transferability is contractual first. Whether a licence can move depends chiefly on the wording of the licence agreement, read against Swedish contract and copyright law.
  • Consents drive the timetable. Anti-assignment and change-of-control clauses can require vendor consent that takes anywhere from days to several weeks, or is refused outright.
  • SaaS behaves differently. Multi-tenant hosted services and click-through EULAs raise distinct issues from perpetual on-premise licences.
  • GDPR sits alongside licensing. Data mapping, lawful basis and processor arrangements must be tested during due diligence and allocated in the agreement.
  • Documentation protects value. Reps, indemnities, escrow and transitional service arrangements are the practical tools that bridge remaining risk.

Can software licences be transferred in an acquisition in Sweden?, legal principles and practical tests

The starting point in Swedish law is freedom of contract. Under the Contracts Act (Lag (1915:218) om avtal och andra rättshandlingar på förmögenhetsrättens område), parties are broadly free to agree the terms on which rights and obligations are created, and those terms govern how a licence may be dealt with. A well-drafted licence will state expressly whether it is transferable, whether assignment requires the licensor’s consent, and whether a change of control in the licensee triggers any right for the licensor to terminate or re-price.

Layered on top of contract is copyright. Software is protected as a literary work under the Copyright Act (Lag (1960:729) om upphovsrätt till litterära och konstnärliga verk), and the economic rights in software vest in the author or the party to whom they have been assigned. A licence is a permission to use those rights on defined terms; it does not itself transfer ownership of the underlying intellectual property. Understanding this distinction is essential to a sound software licence transfer Sweden assessment: you are usually moving the benefit of a permission, not the copyright itself.

Transferability, contract versus legal restriction

There are two questions to separate. First, does the licence permit transfer as a matter of its own terms? Second, is any transfer restricted by the position of the underlying IP owner? In a straightforward asset acquisition, the buyer wants the target’s rights under a licence to pass to it. If the licence is silent on transfer, the general position under Swedish contract principles is that the benefit of a contract may often be assigned, but the burden, the licensee’s ongoing obligations, cannot be transferred to a third party without the counterparty’s consent. That is why anti-assignment and consent clauses matter so much in practice.

Where the transaction is structured as a share sale rather than an asset sale, the contracting entity does not change and, in principle, its licences continue undisturbed. The exception is the change-of-control clause: many enterprise and SaaS agreements treat an indirect change of ownership as a trigger requiring notice or consent, precisely to prevent parties from side-stepping anti-assignment provisions through a share deal. Reading for those triggers is the heart of a software licence transfer Sweden review.

Types of licences: perpetual versus subscription, on-premise versus SaaS

The commercial form of the licence shapes the analysis:

  • Perpetual on-premise licences. Often the most transfer-friendly, but frequently subject to explicit assignment restrictions and maintenance contracts that must move alongside the licence to preserve support.
  • Subscription licences. Term-limited and typically tied to named entities or user counts; renewal and re-pricing rights may be triggered by a transfer.
  • SaaS and cloud services. Delivered on multi-tenant infrastructure under standard terms; the “licence” is really a service subscription, and the provider’s consent is usually the contractual gatekeeper for any assignment or change of control.

Assignment vs novation vs licence retention, which mechanism and why

Once you know a licence needs to move, choose the right legal mechanism. The three practical options are assignment, novation and retention (leaving the licence where it sits, typically in a share deal or through a transitional arrangement). Each has different legal effects, consent requirements and timelines.

Assignment vs novation vs licence retention, at a glance

Feature Assignment Novation Licence retention
Legal effect Transfers the benefit of the contract to the buyer; burden generally stays with the original party unless consented Extinguishes the old contract and creates a new one between vendor and buyer on the same terms Contract remains with the original entity; benefit reaches the buyer indirectly (share deal or TSA)
Requirements (consent/signature) Assignor and assignee sign; licensor consent needed if the contract requires it All three parties must sign, vendor, original licensee and buyer No new signatures where the entity is unchanged; a TSA needs the parties to that agreement
Impact on continuing obligations Original party may remain liable for the burden; buyer gains rights only Clean break: original party released, buyer takes on all rights and obligations Original entity retains obligations; risk of leakage if the group is later restructured
Use case Simple licences where the licensor is neutral about the counterparty Enterprise and SaaS contracts where the vendor insists on approving the new customer Share deals; interim arrangements pending consent
Typical timeline Fast where no consent needed; add weeks if consent required Longer, requires vendor engagement and signature by all parties Immediate in a share deal; a TSA can be negotiated in parallel

When to prefer novation

Novation is the cleanest outcome where a vendor wants a direct contractual relationship with the buyer and where the original licensee must be released from ongoing liability. Because novation replaces the old contract with a new one, it removes the ambiguity that assignment can leave about who owes what. The trade-off is time and leverage: novation needs the vendor’s active co-operation and signature, so it should be started early in a software licence transfer Sweden process.

When assignment is sufficient

Where the licence permits assignment without consent, or the licensor is indifferent to the identity of the counterparty, a straightforward assignment is faster and simpler. It suits low-value or commoditised licences and situations where the seller is content to retain residual liability, or where indemnities in the sale agreement cover any residual exposure.

SaaS-specific considerations

For SaaS, retention or novation usually dominates over assignment. Because the service is delivered on shared infrastructure under standard terms, the provider controls provisioning and billing; a buyer cannot simply “step into” the account without the provider’s involvement. In a share deal, the subscription often continues seamlessly unless the terms contain a change-of-control trigger. In an asset deal, expect the vendor to require a fresh order form or a novation to its current standard terms, which may differ from the legacy terms the target enjoyed.

Third-party consents, triggers, practical timelines and negotiation tactics

Consents are where deal timetables live or die. Every material software licence transfer Sweden checklist should flag which agreements require third-party approval before they can move, because those approvals cannot be manufactured on the buyer’s schedule.

Reading clauses for consent triggers

Consent obligations tend to appear in a small number of recurring clauses. Look for:

  • Anti-assignment clauses. Prohibiting assignment “in whole or in part” without the licensor’s prior written consent.
  • Change-of-control clauses. Treating a direct or indirect change in the licensee’s ownership as a deemed assignment or a termination trigger.
  • Sublicence restrictions. Preventing the licensee from extending the benefit to affiliates or new group members without approval.
  • Territorial and entity limits. Restricting use to named legal entities or defined jurisdictions.
  • Termination-for-convenience rights. Giving the vendor a walk-away right that can be exercised on a transaction.

Not every clause requiring “consent not to be unreasonably withheld” carries the same risk. Where the contract disciplines the vendor’s discretion, the buyer has a stronger position; where consent is at the vendor’s absolute discretion, the commercial relationship and negotiating leverage become decisive.

Practical tactics when consent is refused or delayed

Practitioner experience suggests consent timelines range from immediate acknowledgement to several weeks or more, and enterprise contracts with layered approval chains can take considerably longer. Where consent is slow or refused, the following tactics keep the deal moving:

  • Escalate upstream early. Engage the vendor’s account team before signing, and identify who internally can authorise a novation.
  • Use transitional services. Where the seller retains the contract for a period, a transitional services agreement (TSA) can allow the buyer to use the software lawfully while consent is finalised.
  • Deploy escrow. Hold back part of the consideration against the risk that a consent is not obtained, releasing it on delivery.
  • Insert reliance carveouts. Structure the deal so that non-transfer of a non-critical licence does not become a condition to completion.
  • Consider conditional completion. Make completion of a specific workstream contingent on receipt of a named consent, while completing the balance of the transaction.

The overriding lesson from practice is that the earlier consents are triggered, the more optionality the parties retain. Leaving them to the closing checklist removes the room needed to negotiate alternatives.

IT due diligence Sweden checklist for buyers, what to inspect, request and test

Disciplined IT due diligence Sweden is the foundation of a defensible software licence transfer Sweden position. The objective is to build a complete inventory, understand transferability, quantify risk and design the contractual protections that follow. Prioritise findings using a simple red / amber / green scheme so the deal team can focus on what genuinely threatens value.

Contract inventory template

Build a structured register of every material software and IT contract. For each agreement capture:

  • Counterparty and product. Vendor name, product, and whether it is business-critical.
  • Licence type. Perpetual, subscription, SaaS, open-source or embedded.
  • Assignment and change-of-control terms. Whether consent is required and on what standard.
  • Term, renewal and termination. Expiry dates, auto-renewal, notice periods and termination-for-convenience rights.
  • Support and maintenance. Whether maintenance travels with the licence and what SLAs apply.
  • Fees. Recurring charges, uplift mechanics and any transfer or re-pricing rights.

Red flags include contracts that cannot be located, expired agreements still in daily use, and licences whose terms are silent, silence often means an argument, not a clear answer.

Technical evidence to request

Contract paper alone is not enough. Request and test the operational evidence:

  • Source code access and escrow. Whether escrow arrangements exist for business-critical software and whether they are current and enforceable.
  • Vendor solvency. Financial health of key vendors, given the continuity risk if a supplier fails.
  • SLA and liability caps. Service levels, credits and the ceiling on vendor liability, which shapes the buyer’s residual exposure.
  • Hosting and cross-border processing. Where data is hosted, which sub-processors are used and whether processing leaves the EU/EEA.
  • Sub-licensing. Whether affiliates rely on licences held by a single group entity.

Open-source and third-party components

Open-source exposure is a recurring blind spot. Copyleft licences can require disclosure or redistribution of derived source code, which may be incompatible with a buyer’s commercialisation plans. Request a software bill of materials, identify the licences governing each component, and flag any obligations that could contaminate proprietary code. Where the target has built products on third-party components, verify that the licence terms permit the intended use post-close. This intersects directly with IP transfer in M&A: the buyer needs comfort that it is acquiring a clean chain of rights, not a latent infringement claim.

GDPR & personal data risks in M&A, steps during due diligence and allocation in agreements

GDPR M&A Sweden analysis runs in parallel with the licensing review because software estates are the machinery through which personal data is processed. The General Data Protection Regulation (Regulation (EU) 2016/679), supplemented in Sweden by the Data Protection Act (Lag (2018:218) med kompletterande bestämmelser till EU:s dataskyddsförordning), defines the roles of controller and processor and imposes obligations that survive the change of ownership. A share deal generally leaves the controller unchanged, but an asset deal can shift who determines the purposes and means of processing, and that shift must be justified and documented.

Data mapping & DPIAs during due diligence

The practical foundation is a data map. Establish what personal data the target holds, where it sits, which systems process it and which third parties are involved. Verify the lawful basis for each processing activity and confirm that Article 28 processor agreements are in place with vendors who process on the target’s behalf. Where processing is likely to result in a high risk to individuals, check whether data protection impact assessments have been carried out. For data leaving the EU/EEA, confirm that an appropriate transfer mechanism is in place.

The European Data Protection Board (EDPB) publishes guidance that clarifies these obligations, and the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY) sets out its expectations for how organisations should handle personal data, including in the context of transactions.

Representations and warranties, sample wording

Diligence findings should feed directly into the sale agreement. A GDPR representation gives the buyer a contractual foothold if the target’s compliance is misstated. The following is illustrative:

Sample, for discussion only: “The Company has at all times complied in all material respects with applicable data protection laws, including Regulation (EU) 2016/679, has valid lawful bases for its processing of personal data, has entered into written processor agreements meeting the requirements of Article 28 with all relevant processors, and has not received any enforcement notice, complaint or correspondence from a supervisory authority in relation to its processing activities.”

Post-close remediation & transitional measures

Rarely is a target perfectly compliant. Where gaps are found, agree a remediation plan: updated processor agreements, refreshed privacy notices, corrected transfer mechanisms and, where necessary, notification of a supervisory authority. Transitional data-sharing arrangements between seller and buyer must themselves rest on a lawful basis and a compliant data-sharing agreement, so that the migration of systems does not itself create a breach. Building these steps into a covenant, backed by a specific indemnity for identified data protection risks, is the pragmatic way to close the gap without derailing the deal.

Contractual protections for buyers and sellers, reps, indemnities, escrow and W&I

The sale agreement is where residual software licence transfer Sweden risk is priced and allocated. A layered approach combines robust representations, tiered indemnities, escrow and, where appropriate, warranty and indemnity (W&I) insurance.

Escrow, when and how

Escrow serves two distinct purposes. First, a source code escrow protects continuity of business-critical software: the code is deposited with an independent agent and released to the buyer on defined trigger events, such as vendor insolvency or failure to maintain. Second, a completion escrow holds back part of the purchase price against identified risks, a pending consent, an unresolved data protection gap or a disputed licence position, releasing it once the risk is retired. A sample escrow instruction might read:

Sample, for discussion only: “The Escrow Agent shall release the Retention Amount to the Buyer upon receipt of written confirmation that [named vendor] has executed a novation of the [named] licence in favour of the Buyer, or, failing such confirmation by [date], to the Seller, save to the extent a Claim has been notified in accordance with this Agreement.”

W&I insurance practicalities for licence and IP risk

W&I insurance can bridge the gap where a seller resists giving broad indemnities, transferring warranty risk to an insurer. It is most useful for unknown, general exposures rather than identified, specific risks, insurers typically exclude matters that diligence has already flagged as problematic. A refused licence consent that both parties know about will usually be excluded, which is precisely why escrow and specific indemnities remain the tools for known issues. A novation consent condition can be captured in the agreement as follows:

Sample, for discussion only: “Completion of the transfer of the [named] Software Contract is conditional upon the Buyer, the Seller and [named vendor] having entered into a deed of novation in the agreed form, and if such condition is not satisfied by the Long Stop Date, the provisions of Clause [x] (transitional licence) shall apply.”

Practical timeline & playbook for closing, buyer and seller checklist

A clear timeline turns the software licence transfer Sweden analysis into deliverable actions:

  • LOI to signing. Build the contract inventory, identify consent triggers, begin data mapping and open early conversations with critical vendors.
  • Signing to completion. Issue consent and novation requests, negotiate any TSA, finalise escrow arrangements and agree the GDPR remediation plan. Track consent responses against the long-stop date.
  • Completion. Execute novations that are ready, activate escrow, and confirm which licences transfer at close and which sit under transitional arrangements.
  • Post-close 0–90 days. Complete outstanding consents, migrate SaaS accounts, execute the data-sharing wind-down, close out remediation items and release escrow amounts as conditions are met.

Case studies and quick precedents, anonymised examples

The following anonymised examples reflect practitioner experience and are offered as illustrative lessons rather than legal advice.

Example 1, consent refused, creative settlement. On an asset deal, a business-critical enterprise vendor declined to consent to assignment on the buyer’s timetable. Rather than delay completion, the parties agreed a transitional licence under which the seller retained the contract for a fixed period, sub-permitting use to the buyer, backed by an escrow of part of the consideration. The novation was completed within the transitional window, and the escrow was released. The lesson: a refused consent is not fatal if the deal architecture allows for a bridge.

Example 2, SaaS multi-tenant transfer via novation. A target relied on a multi-tenant SaaS platform whose terms treated the acquisition as a change of control. Because provisioning and billing sat with the provider, assignment was impossible; the workable route was a tripartite novation onto the provider’s current standard terms. Engaging the provider’s account team before signing meant the novation was executed at completion. The lesson: start SaaS vendor engagement before, not after, the deal is announced.

Conclusion and next steps

A structured software licence transfer Sweden approach converts a potential closing crisis into a managed workstream. Start with the contract inventory, identify consent triggers early, choose the right mechanism, assignment, novation or retention, and run GDPR analysis in parallel with the licensing review. Where risk remains, escrow, transitional arrangements and carefully drafted reps and indemnities keep the deal on track. For tailored advice on a software licence transfer Sweden matter, IT due diligence Sweden or GDPR risk allocation in your transaction, contact the attributed expert through the Global Law Experts profile linked below.

Swedish M&Amp;A: Software Licence Transfer And It Due Diligence

Need Legal Advice?

This article was produced by Global Law Experts. For specialist advice on this topic, contact Göran Andersson at Hellström, a member of the Global Law Experts network.

Sources

  1. EU General Data Protection Regulation (Regulation (EU) 2016/679)
  2. Integritetsskyddsmyndigheten (IMY), Swedish Authority for Privacy Protection
  3. Riksdagen, Avtalslagen (Lag 1915:218), Contracts Act
  4. Riksdagen, Upphovsrättslagen (Lag 1960:729), Copyright Act
  5. PRV, Swedish Intellectual Property Office
  6. Sveriges advokatsamfund, Swedish Bar Association
  7. European Data Protection Board (EDPB)

FAQs

Can software licences be transferred in an acquisition in Sweden?
Often yes, but it depends on the licence terms and whether third-party consent is required. In a share deal, contracts usually continue unless a change-of-control clause is triggered. In an asset deal, transferability turns on the assignment provisions. Run a quick check of each agreement for anti-assignment, change-of-control and consent language.
No. If the licence is expressly transferable, or silent on transfer and structured as a share deal, consent may not be needed. Where the agreement contains an anti-assignment clause, a change-of-control trigger or a consent requirement, the vendor’s approval is typically necessary before the licence can move.
Timelines vary from immediate acknowledgement to several weeks, and complex enterprise approvals can take longer. Accelerate the process by engaging the vendor’s account team before signing, identifying the internal approver early, and preparing a transitional licence or escrow as a fallback if consent is delayed.
Prioritise a complete contract inventory, assignment and change-of-control terms, support and SLA arrangements, IP ownership and open-source exposure, data flows and cross-border processing, and any source code escrow. Grade each finding red, amber or green so the team can concentrate on what threatens deal value.
Carry out data mapping, verify the lawful basis for each processing activity, confirm Article 28 processor agreements are in place, and check transfer mechanisms for any data leaving the EU/EEA. Then reflect the findings in specific representations, covenants and, where risks are identified, a dedicated indemnity in the purchase agreement.
ofac 50 percent rule usa
By Global Law Experts

posted 26 minutes ago

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

How to Handle Software Licences & IT Due Diligence in Swedish M&A (2026)

Send welcome message

Custom Message