Alycia M. Vivona
Partner
she/her/hers
Business Vantage Point Blog
Go to Business Vantage Point BlogAsset Purchase or Merger? Pennsylvania Superior Court Clarifies the Limits of De Facto Merger Doctrine
March 26, 2026A key advantage to structuring an M&A transaction as an asset purchase, rather than a stock purchase or merger, is the buyer’s ability to limit the liabilities of the target that the buyer agrees to assume under the deal documents. But even the most careful drafting can be defeated if a court imposes successor liability on the buyer based on the equitable doctrine of de facto merger. Just over one year ago, in Campbell v. WeCare Organics, 2025 PA Super 44 (Pa. Super. Ct. Feb. 25, 2025), the Pennsylvania Superior Court provided a helpful review of the circumstances under which Pennsylvania’s de facto merger doctrine would — and would not — impose successor liability after an asset purchase. The Dispute In 2014, Jonathan Campbell entered into a waste-hauling contract with WeCare Organics LLC. Two years later, Denali Water Solutions LLC purchased the core business assets of WeCare, with WeCare retaining certain customer contracts and equipment. WeCare also retained its debt to Campbell for unpaid amounts due under the hauling contract. Campbell sued both WeCare and Denali in 2019, asserting that Denali was liable for WeCare’s unpaid debt under the de facto merger doctrine. The trial court agreed with Campbell and granted summary judgment against Denali in 2024. On Denali’s appeal, the Pennsylvania Superior Court reversed and remanded the case for further proceedings. The De Facto Merger Test Citing the Pennsylvania Supreme Court’s decision in Fizzano Brothers Concrete Products v. XLN, 42 A.3d 951, 954 (Pa. 2012), the Superior Court began by confirming the general rule that the buyer of a corporation’s assets does not assume the seller’s debts solely by reason of the purchase. The court then identified five exceptions to this general rule: If the buyer expressly or implicitly agreed to assume the debt. If the transaction amounted to a consolidation or a de facto merger. If the buyer is merely a continuation of the seller. If the buyer fraudulently entered into the transaction to escape liability. If the transfer was without adequate consideration and no provisions were made for creditors of the seller. Proceeding to its specific analysis of the de facto merger doctrine, the Superior Court identified the four factors that would contribute to a finding of successor liability: Continuity of ownership between the seller and buyer. Cessation of the seller’s ordinary business and dissolution as soon as practically and legally possible. The buyer’s assumption of liabilities ordinarily necessary for the uninterrupted continuation of the seller’s business. Continuity of management, personnel, physical location and general business operations between the seller and the buyer. The Superior Court noted the Pennsylvania Supreme Court’s admonition that these factors are not to be applied mechanically, but that they should serve to guide the reviewing court in its determination of whether a de facto merger has occurred. The Superior Court’s Analysis Denali conceded the third and fourth factors in the de facto merger analysis, acknowledging that it had assumed a significant portion of WeCare’s liabilities and that there was significant continuity of management, operations and facilities between WeCare and Denali. The appeal, and the Superior Court’s analysis, turned on the first two factors. Continuity of Ownership While recognizing the Fizzano court’s holding that continuity of ownership could be shown through forms of stockholder interest beyond a direct exchange of shares, including promissory notes, the Superior Court characterized as an issue of first impression the question of whether the asset purchase agreement’s requirement that Denali enter into a three-year executive employment agreement with WeCare’s founder, Jeffrey LeBlanc, coupled with a payment of cash for LeBlanc’s indirect ownership interests in WeCare, would be sufficient to establish continuity of ownership for purposes of the de facto merger doctrine’s first factor. The trial court had reasoned that the executive employment agreement was a type of alternative merger consideration contemplated by Pennsylvania’s merger statute and held that Campbell had established continuity of ownership between WeCare and Denali as a matter of law. The Superior Court reversed. Relying on Fizzano’s holding that continuity of ownership requires “some sort of” proof that the seller’s shareholders retained an ownership interest in the successor entity, the court held that LeBlanc’s employment agreement did not, as a matter of law, constitute an ownership interest in Denali because it did not provide him with equity in Denali. The court further explained that successor liability is justified under the de facto merger doctrine when it prevents one or more equity holders of a seller from retaining the benefits of ownership of the transferred assets after those assets have been cleansed of liabilities through the sale, leaving the creditors of the seller without any remedies to collect their debts. The court could not conclude as a matter of law that LeBlanc’s employment agreement was the equivalent of an ownership interest in Denali, so Campbell had not established this prong of the de facto merger test for purposes of his motion for summary judgment. Prompt Cessation of Ordinary Business and Dissolution The Superior Court then turned to the question of whether WeCare had ceased its ordinary business and dissolved as soon as practically and legally possible, as required by the second factor of the de facto merger doctrine. In essence, a merger provides for one company to survive while the other party to the merger ceases to exist. Thus, the second prong of the de facto merger doctrine requires not only that the seller’s ordinary business activities cease, but that they cease more or less contemporaneously with the sale. The court emphasized that the timing in question is when the seller’s ordinary operations cease, not when the seller entity is formally dissolved. The Superior Court acknowledged that WeCare was undisputedly “defunct” as of August 2020, but it pointed to several facts indicating that WeCare and Denali did not intend for WeCare to cease all business activities after the closing of the asset sale in October 2016: The asset purchase agreement did not require WeCare to dissolve. WeCare represented that it would be a solvent “ongoing business” at closing. WeCare retained certain customer contracts and equipment after the sale. LeBlanc was permitted to remain as WeCare’s president, notwithstanding his employment with Denali. WeCare wrote to its vendors in March 2017 stating it had sold only a portion of its business and was preparing for its upcoming season. The court therefore held that there was a genuine issue of material fact as to whether WeCare maintained post-closing business operations at a level sufficient to negate the cessation of ordinary business and dissolution prong of the de facto merger test. Since Denali might be able to prove on remand that the second prong of the de facto merger test had not been satisfied, the Superior Court reversed the trial court’s summary judgment for Campbell. Applying the Superior Court’s Lessons By clarifying two of the four factors that comprise the de facto merger doctrine, the Superior Court’s opinion suggests ways in which buyers can reduce their risk of incurring successor liability under that doctrine. First, a buyer will increase its risk of successor liability if the consideration for an asset purchase includes any issuance of the buyer’s equity to the seller or its owners. This is true even if the equity issuance is based on an agreement other than the asset purchase agreement, such as an executive employment agreement with the seller’s founder. At the same time, a court may find that non-cash consideration that allows the seller’s owners to retain the benefits of ownership of the transferred assets after the sale (such as promissory notes or employment agreements) is sufficient to establish continuity of ownership under the first prong of the de facto merger doctrine. Buyers can reduce their risk of successor liability by avoiding such types of consideration in their asset purchase transactions. In addition, the Superior Court makes clear that a de facto merger should not occur if the parties allow the seller to continue to conduct a portion of its business after the asset sale. This may be accomplished by allowing the seller to retain certain non-core assets or by providing for reinvestment of at least a portion of the sale proceeds into the seller’s ongoing business. Even if the seller ultimately becomes insolvent, the buyer is more likely to be insulated from successor liability if the seller’s creditors can pursue recovery against an operating seller entity after the asset sale. By contrast, requiring the seller entity to dissolve after closing of the asset sale would increase the buyer’s risk of successor liability. The parties’ business needs will ultimately determine both the nature of the consideration and the scope of the assets transferred in an asset purchase, but buyers would be well advised to consider the factors that could lead to successor liability under the de facto merger doctrine when structuring their transactions.
Chancery Court Addresses Appraisal Rights in Delaware Short-Form Mergers in Case with Key Lesson for Counsel
February 24, 2026Under Section 253 of the Delaware General Corporation Law (DGCL) and Section 18-209(i) of the Delaware Limited Liability Company Act (DLLCA), a parent company owning at least 90% of the outstanding shares of a Delaware corporation has the right to merge with that subsidiary without approval of the board of directors or stockholders of the subsidiary. This mechanism — used to eliminate the shareholdings of the subsidiary’s minority stockholders without their consent, or even over their objections — is referred to by various names, including short-form merger, parent-subsidiary merger, cash-out merger, freeze-out merger, squeeze-out merger, and (in the M&A context) triangular merger. While minority stockholders cannot prevent a short-form merger, they can challenge the consideration paid for their shares in the merger by demanding an appraisal under Section 262 of the DGCL. In the recent case of Abraham v. Estate of Wirtz, 2025 WL 3625719, the Delaware Court of Chancery resolved a motion to dismiss with respect to an exercise of appraisal rights in a short-form merger — and reinforced a key lesson for counsel of both controlling and minority stockholders. Delaware Court of Chancery Weighs In In Abraham, Wirtz Corp. owned, directly and indirectly, 97% of the outstanding shares of American Mart Corp., a Delaware corporation. Wirtz caused American Mart to merge with its newly formed subsidiary American Mart Co. LLC (AMLLC) under Section 18-209(i) of the DLLCA, with the retail investors who owned the remaining 3% of American Mart receiving merger consideration equal to $357 per share. One of those retail investors, David Abraham, claimed that the merger consideration undervalued his shares of American Mart by up to 19 times and demanded an appraisal under Section 262 of the DGCL. AMLLC rejected Abraham’s appraisal demand on the grounds that it failed to comply with Section 262, and Abraham sued. Requirements Under Section 262 The court agreed with AMLLC that Abraham had not properly exercised his appraisal rights, noting that: Appraisal is a minority stockholder’s sole recourse in a short-form merger absent fraud or illegality. Exercise of appraisal rights requires strict compliance with Section 262 of the DGCL. A good-faith effort to comply is not sufficient. A controlling stockholder does not have to establish the entire fairness of a short-form merger; the controlling stockholder must only satisfy its duty of disclosure. To satisfy its duty of disclosure under Section 262, a controlling stockholder must provide minority stockholders with a notice of appraisal rights that includes (1) a correct copy of the appraisal statute and (2) sufficient information for the minority stockholder to determine whether seeking appraisal is worthwhile. The controlling stockholder’s notice need not repeat the procedures that are outlined in the statute. Abraham’s appraisal demand failed to satisfy the requirements of Section 262 in part because it did not identify the record owner of the shares beneficially owned by Abraham. The court would not excuse this failure even though all American Mart shares not owned by Wirtz were held in street name by Cede & Co., so AMLLC knew the identity of the record owner. A “quasi-appraisal” remedy is only available when the controlling stockholder breaches its duty of disclosure, not when a minority stockholder’s demand for appraisal fails to comply with Section 262. Once AMLLC satisfied its duty of disclosure, the remedy of quasi-appraisal was no longer available, and the burden fell on Abraham to exercise his appraisal rights in accordance with Section 262. Because Abraham failed to strictly satisfy the statutory requirements, he was not entitled to an appraisal. A Final Surprise But, after shooting down all of Abraham’s arguments under Section 262, the court had a final surprise: The merger may not have been valid after all, since AMLLC may not have in fact owned the shares of American Mart at the time of the merger. Based on statements in the notice of appraisal rights, Abraham argued that affiliates of Wirtz other than AMLLC owned 90% of the shares of American Mart at the time of the merger and that, as a result, AMLLC could not have validly completed the merger under Section 18-209(i) of the DLLCA. Rather than simply respond that AMLLC did, in fact, own the American Mart shares, AMLLC argued that it had the right to complete the short-form merger as an affiliate of the 90% owner, Wirtz. The court rejected this “confounding” argument — stating that the short-form merger statute does not support that interpretation — and held that Abraham stated a claim for violation of Section 18-209(i) while limiting Abraham’s relief to targeted discovery into AMLLC’s share ownership at the time of the merger. The Upshot: Counsel Must Check, and Double-Check, All Statutory Requirements Abraham had no appraisal remedy for the purported undervaluing of his American Mart shares because he failed to include certain straightforward statements in his appraisal demand. And notwithstanding the careful preparation and distribution of an eight-page, single-spaced notice of appraisal rights, Wirtz may see the short-form merger invalidated if it failed to ensure that the shares of American Mart were in fact transferred to the newly formed AMLLC before consummation of the merger. These undesirable results — not to mention the costs of litigation — could have been avoided by strict compliance with the applicable statutes. Thus, this case serves as a reminder of counsel’s responsibility to carefully review, and ensure compliance with, all statutory requirements when advising clients on short-form mergers.
Beware the Boilerplate: Integration Clauses Can Have Unintended Consequences
August 26, 2025An integration clause is a boilerplate provision that provides that a written contract contains the entire agreement of the parties. (A typical integration clause would read: “This Agreement constitutes the entire agreement between the parties with respect to its subject matter and supersedes all prior oral and written negotiations and agreements with respect to such subject matter.”) Most integration clauses refer only to one contract — the contract in which the integration clause appears — as constituting the parties’ entire agreement. In such cases, the integration clause serves to confirm the parties’ intention for the written contract to be a fully integrated statement of their agreement such that the parol evidence rule would preclude a court from considering extrinsic evidence of that meaning to resolve any dispute between the parties. But in transactions that are documented with more than one contract, the integration clause often references all of the related contracts as making up the parties’ entire agreement. For example, the integration clause in an acquisition agreement for an M&A transaction might read: “This Agreement (including the Schedules and Annexes) and the Ancillary Agreements (including any schedules and annexes to the Ancillary Agreements) constitute the complete, integrated agreement among the Parties with respect to the subject matter of this Agreement and such Ancillary Agreements.” This was the integration clause at issue in the recent Delaware Supreme Court case Thompson Street Capital Partners IV v. Sonova United States Hearing Instruments, 2025 WL 1213667 (Del. Apr. 28, 2025), which we examined in detail in a prior post. A ’Unitary Contractual Scheme’ As we previously described, the Delaware Court of Chancery held that Sonova United States Hearing Instruments LLC’s notice of a potential indemnification claim was sufficient to prevent a release of escrowed funds under the parties’ escrow agreement. (See Thompson Street Capital Partners IV v. Sonova United States Hearing Instruments, 2024 WL 1251150 (Del. Ch. Mar. 25, 2024).) The Delaware Supreme Court reversed, finding that the notice also had to satisfy the notice requirements for the bringing of an indemnification claim under the merger agreement between the parties. The court based its decision on the fact that the integration clause in the merger agreement referenced not only the merger agreement but also “Ancillary Agreements,” which included the escrow agreement. The court found that the merger agreement and the escrow agreement were to be read together as a “unitary contractual scheme” under which both the general notice requirements in the escrow agreement and the specific notice requirements in the merger agreement were to be given effect. Thus, the parties’ inclusion of the ancillary agreements in the merger agreement’s integration clause had the surprising effect of imposing on the escrow release additional notice requirements that did not appear in the escrow agreement itself. ‘Entire Agreement and Understanding’ A similar decision from last year is VEP Biotech v. Quadrant Biosciences, 5:23-CV-1428 (GTS/ML) (N.D. N.Y. Sep 19, 2024), which involved a note purchase agreement and related convertible promissory notes. Under the note purchase agreement, Quadrant Biosciences Inc. agreed to issue and sell, and VEP Biotech Ltd. agreed to purchase, three convertible notes if certain enumerated conditions were met, although only the first of the notes was ever issued. After the note’s maturity, Quadrant admitted that it had failed to repay the amount due but raised as an affirmative defense the fact that VEP had previously breached its obligation to purchase the two additional notes under the note purchase agreement. The U.S. District Court for the Northern District of New York examined several provisions in the note purchase agreement and the convertible note, including the integration clause in the note purchase agreement that stated the note purchase agreement and the convertible notes “embody the entire agreement and understanding between [VEP] and [Quadrant] and supersede all prior agreements and understandings relating to the subject matter.” VEP argued that, notwithstanding the integration clause, breach of the note purchase agreement would not excuse Quadrant from performance of its unconditional obligation under the convertible note, but the court did not agree. Rather, the court found that because the terms and conditions of the note purchase agreement included VEP’s purchase of the second and third convertible notes, the court could not say that the first note was an unconditional promise to pay notwithstanding VEP’s noncompliance with the note purchase agreement. Accordingly, the court held that Quadrant’s affirmative defense was sufficient to prevent an entry of judgment on the pleadings, and VEP’s motion for such a judgment was denied. A Note of Caution These two cases highlight unintended consequences that can result when an integration clause provides for two or more related contracts to be treated as the parties’ entire agreement. As in Thompson, requirements under one contract may be imposed on a party’s performance under a related contract. And, as in VEP Biotech, a breach of one contract may adversely affect a party’s ability to enforce its rights under a related contract. In all events, an integration clause that encompasses more than one contract can render unambiguous terms of one contract ambiguous when considered in conjunction with the terms of related contracts. Counsel must proceed with caution to draft contracts that avoid such unintended consequences.
Delaware Chancery Court Examines ‘Reasonable Efforts’ in Chordia Decision
March 5, 2024Most contracts will straightforwardly require the parties to take or refrain from taking specified actions. However, some contracts require that a party attempt to bring about a result that may or may not be within the party’s control. Such provisions are commonly qualified so that the party will not have breached the provision, even if the goal is not achieved, so long as the party has used its “reasonable efforts” to bring about the desired result. Because the steps that a party must take to satisfy a reasonable-efforts requirement will depend on the facts and circumstances surrounding the obligation, lawyers may struggle to advise their clients on what is required to satisfy such an “efforts clause.” In the recent case of Chordia v. Lee, the Delaware Court of Chancery reviewed the factors to be considered in analyzing an efforts clause while holding that a majority stockholder had failed to use its reasonable efforts to carry out the terms of a stockholders’ agreement. What Happened in Chordia? Zenith Electronics LLC, an indirect, wholly owned subsidiary of major appliance and consumer electronics company LG Electronics Inc., purchased a controlling interest in ad tech company Alphonso Inc. in 2020. Although Alphonso’s founders wanted to retain control of the company so that they could drive it toward an initial public offering, the founders and other Alphonso stockholders (the key holders) ultimately settled for significant upfront cash together with some heavily negotiated minority protections. The key holders’ minority protections were intended principally to preserve liquidity for their minority interests in Alphonso. Specifically, the parties entered into a stockholders’ agreement that gave the key holders a demand registration right exercisable after December 2025 and a right to annual tender offers in 2024, 2025 and 2026. These liquidity rights were protected, in turn, by the combination of (1) a right of the key holders to appoint up to three of the seven directors on Alphonso’s board and (2) a prohibition on any change to the registration right or the scheduled tender offers absent the consent of at least one director appointed by the key holders. The key holders’ right to appoint directors to the Alphonso board was subject to two conditions. First, they had to retain collective ownership of at least 10 percent of Alphonso’s outstanding shares. Second, at least one of the key holders had to remain as an officer or employee of Alphonso. LG Electronics had the right to terminate the stockholders’ agreement in its entirety if all key holders ceased to serve as officers and employees of Alphonso. The stockholders’ agreement further provided that Alphonso’s board — controlled by four LG Electronics-appointed directors — retained the exclusive right to terminate the employment of Alphonso’s officers and any of its employees with annual compensation of $500,000 or more, which applied to five of the key holders (the executive key holders). As the court noted, “Given these mechanics, it might seem that [the key holders’ right to appoint Alphonso directors] requires protection of its own.” That protection, according to the key holders, was to be found in the stockholders’ agreement’s efforts clause, which read: Alphonso “agrees to use its reasonable efforts, within the requirements of applicable law, to ensure that the rights granted under this Agreement are effective and that the Parties enjoy the benefits of this Agreement. Such actions include, without limitation, the use of [Alphonso’s] reasonable efforts to cause the nomination and election of the directors as provided in this Agreement.” Not long after the closing, friction developed between LG Electronics and the executive key holders, including LG Electronics’ realization that a sale of Alphonso pursuant to the key holders’ liquidity rights would be inconsistent with LG Electronics’ long-term objective of incorporating Alphonso’s technology into LG Electronics’ products. By mid-2022, LG Electronics sought ways to terminate the stockholders’ agreement and eliminate its obligations to the key holders. At the end of the year, Alphonso’s board held a special meeting at which the board (1) terminated the employment of the five executive key holders and (2) elected a new interim CEO, who immediately fired the two remaining key holders who were neither officers nor employees with annual compensation of $500,000 (the non-executive key holders). Later that day, Zenith signed a written consent (the December consent) removing all Alphonso directors who had been appointed by the key holders. On March 30, 2023, the key holders filed a complaint seeking an order pursuant to Section 225 of the Delaware General Corporation Law that Zenith’s removal of the directors appointed by the key holders pursuant to the December consent was invalid and, therefore, those directors remain members of Alphonso’s board. The court agreed with the key holders. Chancery Court Examines Efforts Clause with Four-Factor Analysis After determining that a court hearing a case under Section 225 of the Delaware General Corporation Law could decide an appropriately tailored breach of contract claim, the court conducted an analysis that “begins and ends with the ‘reasonable efforts’ provision in the Stockholders’ Agreement.” Specifically, the court focused its analysis on four questions: “(1) which parties are required to use reasonable efforts, (2) toward whom reasonable efforts must be used, (3) the scope of the obligation imposed by the words “reasonable efforts,” and (4) whether the party that must use reasonable efforts acted in the manner required by the obligation toward those to whom reasonable efforts must be used.” Which Parties Must Use Reasonable Efforts? Turning to the first of these questions, the court, while noting the “truism that a corporation acts through individuals,” nonetheless also noted that “the Stockholders’ Agreement itself distinguishes in various instances between Alphonso and the Board,” treating the board and Alphonso as distinct parties with differing rights and obligations. This distinction was so prevalent that “in some instances the Stockholders’ Agreement refer[red] separately to the Board and Alphonso in the same provision.” Under these circumstances, the court adopted the defendants’ approach and interpreted the rights and obligations under the stockholders’ agreement as applying separately to Alphonso and to its board. This was important because the efforts clause, by its terms, applied only to Alphonso and not to the board. In determining which human agents’ actions should be attributed to Alphonso, the court relied on the theory that a corporation acts through its officers and held that the interim CEO, in particular, acted for Alphonso. (In a footnote, the court indicated that it would reach the same result on the alternate theory that the acts of a corporation’s officers, acting within the scope of their authority, are imputed to the corporation itself.) Thus, the court determined that the board was free to exercise its bargained-for contract right to terminate the five executive key holders and appoint Alphonso’s new interim CEO without regard to the efforts clause. By contrast, when the interim CEO terminated the non-executive key holders, the interim CEO was acting for Alphonso and had to comply with the corporation’s reasonable-efforts obligation. Toward Whom Must Reasonable Efforts Be Used? The court next concluded that Alphonso owes its reasonable efforts with respect to the appointment of Alphonso’s directors for the benefit of the two non-executive key holders. The efforts clause required Alphonso “to ensure that the rights granted under [the stockholders’ agreement] are effective and that the Parties enjoy the benefits of” [the stockholders’ agreement].” As parties to the stockholders’ agreement, all of the key holders were generally entitled to the benefit of Alphonso’s reasonable-efforts clause, but the efforts clause did not apply to the actions of the board. Accordingly, when the board exercised its right to terminate the executive key holders as directors, officers and employees, only the two non-executive key holders retained the right to appoint up to three members of Alphonso’s board, subject to the conditions that they hold at least a 10 percent interest in Alphonso and that at least one of them remain an employee of the corporation. In other words, the fact that the board had the right to terminate the executive key holders without regard to the efforts clause meant that the non-executive key holders were the ultimate beneficiaries of Alphonso’s reasonable efforts. But Alphonso, through the interim CEO’s immediate termination of the employment of the non-executive key holders, denied them any opportunity to exercise their right to appoint directors, in violation of the efforts clause. What Is Meant by ‘Reasonable Efforts’? Noting that Delaware interprets various efforts clauses (best efforts, reasonable best efforts, reasonable efforts, commercially reasonable efforts, etc.) as having the same general meaning, the court clarified that absent a specific contractual definition, Delaware courts will interpret such provisions as creating “an affirmative obligation on the parties to take all reasonable steps.” Because this is an affirmative obligation, a party may breach an efforts clause by failing to use any efforts, i.e., by doing nothing. Beyond that, the court identified two specific factors that Delaware courts have indicated should be examined in determining whether a party has breached an efforts clause: “whether the party subject to the clause (i) had reasonable grounds to take the action it did and (ii) sought to address problems with its counterparty.” Did the Party Bound by the Efforts Clause Act in the Manner Required? Applying the first of the above factors, the court concluded that Alphonso had no grounds for terminating the non-executive key holders while it owed them a specific and affirmative obligation to undertake reasonable efforts to ensure their ability to appoint directors to its board. Notwithstanding that the non-executive key holders were “at will” employees of Alphonso, the court noted that the efforts clause under the stockholders’ agreement provided them a measure of employment security so that they could continue to exercise their right to appoint directors under the stockholders’ agreement: “Given that the rights were conditioned on employment, which was a condition within Alphonso’s control, Alphonso committed itself to use reasonable efforts in that regard to ensure the rights were effective.” It is particularly telling that, in contrast to the disruptive actions of the executive key holders, the non-executive key holders cooperated with Alphonso even after their termination, including volunteering to assist with knowledge transfer to other Alphonso employees. Turning to the second factor, the court noted that Alphonso had “many less drastic alternatives to terminating the remaining Key Holders,” such as asking them to appoint new directors or negotiating with them for another resolution. The court noted that reasonable actors who are subject to an efforts clause would typically seek to discuss an issue and its potential resolution with the party to whom efforts are owed. “But here, there is not a shred of evidence demonstrating that Alphonso or [the interim CEO] gave any consideration to the [non-executive key holders’] rights, much less interacted with them in any meaningful way prior to their terminations,” the court noted. Because Alphonso neither had reasonable grounds for the termination of the non-executive key holders nor attempted to work with them to arrive at a solution short of termination, the court held that Alphonso breached its obligations under the efforts clause. The court goes on to note that, while some discussions occurred between the executive key holders and the LG Electronics-appointed directors on Alphonso’s board, those discussions cannot satisfy Alphonso’s obligation to use reasonable efforts to protect the rights of the non-executive key holders, who were not party to those discussions. Effect of Alphonso’s Breach of the Efforts Clause The non-executive key holders had a right to appoint directors to Alphonso’s board so long as certain conditions were met, including the continued employment of at least one non-executive key holder. In the absence of the efforts clause, Alphonso’s termination of both non-executive key holders would have resulted in failure of the condition and would have terminated the non-executive key holders’ right to appoint directors. But the stockholders’ agreement required Alphonso to use its reasonable efforts to protect the non-executive key holders’ right to appoint directors, which limited Alphonso’s right to terminate their employment. Since Alphonso’s breach of the efforts clause caused the failure of the condition, the court held that the condition must be excused. Referring to the “prevention doctrine” from the Restatement (Second) of Contracts, the court noted that “when a promisor’s non-performance of a contractual duty materially contributes to the non-occurrence of a condition, the condition is excused.” Applying this doctrine to the current facts, the court found that (1) Alphonso’s non-performance of its obligations under the efforts clause resulted in the termination of the non-executive key holders and (2) that termination not only contributed to, but effectively eliminated, the non-executive key holders’ right to appoint certain Alphonso directors, which was necessary to protect their liquidity rights under the stockholders’ agreement. Accordingly, the court held that the condition that at least one key holder remain employed by Alphonso was excused, and the key holders were entitled to designate directors of Alphonso in accordance with the stockholders’ agreement, notwithstanding the termination of their employment. Because the December consent was adopted by the LG Electronics-appointed directors without the participation of directors appointed by the non-executive key holders, it was declared invalid. What Are the Key Takeaways from the Court’s Decision? Framework for Drafting and Interpreting Efforts Clauses This opinion provides a helpful framework not only for interpreting efforts clauses but also for drafting them. When an efforts clause appears in an agreement, the agreement should answer at least three of the court’s questions: (1) which specific party or parties are bound by the efforts clause; (2) toward whom, or for whose benefit, must reasonable efforts be used; and (3) what reasonable steps should the party take in furtherance of the stated goal (using specific examples if possible). When an efforts clause is interpreted, this framework expands to include a fourth inquiry — whether the party that must use reasonable efforts acted in the manner required by the obligation — which can, in turn, be answered through an examination of (1) whether the party had reasonable grounds to take the action it did and (2) whether the party sought to address problems with the party to whom the efforts obligation was owed. This framework allows counsel to provide clients with meaningful guidance as to their rights and responsibilities when asked about efforts clauses, rather than vaguely responding, “It depends.” Distinguishing Between an Entity and the Individuals Who Act for the Entity One key element of this decision is the distinction between Alphonso and its board of directors, each of which has different rights and obligations under the stockholders’ agreement. Such a dichotomy can arise in any agreement to which both an entity and one or more of its constituents (e.g., stockholders, directors, officers or employees) are parties, such as stockholders’ agreements, limited liability company agreements, executive employment agreements, etc. Care should be taken to clearly delineate the individuals who have authority to act on behalf of the entity under such an agreement, and that delineation should take into account both the fiduciary duties of directors, which prevent directors from delegating their rights to vote on board decisions, and potential conflicts of interest of all of the parties.Retrospective: U.S. Cybersecurity and Privacy Developments in 2023
February 6, 2024For much of 2023, it seemed like barely a week would pass by without a new data breach or privacy violation finding its way into the headlines, making it clear that the threat actors of the world have not given up. In response, last year saw several significant federal and state regulatory developments in the cyber and privacy landscape. Regulators will remain focused on these issues and how they might be addressed. Federal Regulatory Developments U.S. Securities and Exchange Commission The U.S. Securities and Exchange Commission (SEC) took a number of aggressive regulatory and enforcement positions in 2023. The agency began the year by suing law firm Covington & Burling to obtain the names of almost 300 clients impacted by a 2020 cyberattack attributed to a nation-state actor. A district court ruling in July required Covington to disclose the identities of seven clients whose material nonpublic information was exposed through the hack. One of those clients has anonymously proceeded to contest the disclosure of its identity. That same month, the SEC finalized new rules for disclosures regarding cybersecurity risk management, strategy, governance and incident response for public companies subject to the reporting requirements of the Securities Exchange Act of 1934. The new rules require companies to disclose material cybersecurity incidents under Item 1.05 on Form 8-K. The SEC also initiated litigation against SolarWinds Corp. and its chief information security officer (CISO) in October — the SEC’s first action against a CISO. The SEC alleges the company and its CISO defrauded investors by overstating the company’s cybersecurity practices and understating or failing to disclose known risks in filings made with the commission. The litigation related to these charges is ongoing. The SEC has not yet finalized its 2022 proposed rulemaking for other securities market participants (such as broker-dealers, clearing agencies, registered investment advisers and investment companies) for cybersecurity risk management, strategy, governance and incident response. The expectation is that the commission will try to finalize the rules this year. Federal Trade Commission Early in the year, the Federal Trade Commission (FTC) initiated several litigations related to alleged Children’s Online Privacy Protection Act (COPPA) violations, including against Microsoft, educational technology provider Edmodo and Amazon. Microsoft agreed to pay $20 million to settle charges related to its illegal collection and retention of personal information from children who signed up for its Xbox Live service. Edmodo agreed to a $6 million civil penalty for its collection of personal data from children, the use of that data in advertising and the unlawful outsourcing of COPPA compliance responsibilities to schools. The FTC’s litigation against Amazon remains ongoing. The FTC also began to enforce the Health Breach Notification Rule in 2023 with respect to the unauthorized sharing of health information in violation of an organization’s privacy policy. The FTC settled with GoodRx, a telehealth and prescription drug discount provider, on a no-admit/no-deny basis for $1.5 million in February. In May, the FTC settled with another entity, Easy Healthcare Corp., for $100,000. In June, the FTC reached a settlement with 1Health.io over allegations the company left sensitive generic and health data unsecured, deceived consumers about their ability to get their data deleted and made retroactive changes to the company’s privacy policy without adequately notifying and obtaining consent from customers whose data the company had already collected. These acts constituted unfair or deceptive acts or practices in violation of Section 5(a) of the Federal Trade Commission Act. 1Health.io agreed to pay $75,000 and take additional remedial actions to address the violations. The FTC settled with BetterHelp Inc. in July over allegations that the company revealed consumers’ sensitive data to third parties for advertising purposes after promising in its privacy policy to keep such data private. The company also failed to employ reasonable measures to safeguard the health information it collected from consumers, such as failing to train its employees on how to protect the information when using it for advertising; failing to provide consumers with the proper notice as to the collection, use and disclosure of their health information; and failing to limit contractually the manner in which third parties could use consumers’ health information. BetterHelp agreed to pay $7.8 million and to take additional remedial actions to address the violations. At the start of the fourth quarter, the FTC approved an amendment to the Safeguards Rule (16 CFR 314) of the Gramm-Leach-Bliley Act requiring non-banking financial institutions (such as mortgage brokers, motor vehicle dealers and payday lenders) to report certain data breaches and other security events to the agency. The FTC must be alerted as soon as possible — and no later than 30 days after discovery — of a breach involving the information of at least 500 consumers where unencrypted customer information has been acquired without the authorization of the individual to which the information pertains. After the FTC sought to impose additional privacy requirements against Meta Platforms Inc. (formerly Facebook Inc.) for alleged violations of its prior 2012 and 2020 privacy settlements, the company sued the FTC to contest the constitutionality of the commission’s in-house proceedings and sought an injunction against the FTC’s reopening of the 2020 order. A district court judge rejected Meta’s arguments in November, and Meta has appealed that decision to the U.S. Court of Appeals for the D.C. Circuit. In December, the FTC proposed changes to the COPPA Rule that would place additional restrictions on the use and disclosure of children’s personal information and the ability of companies to monetize children’s data. The proposed rule includes: (1) separate opt-in for targeted advertising; (2) prohibition against conditioning a child’s participation in an activity on the collection of personal information; (3) additional requirements around the use of information in support of a website’s internal operations; (4) limitations on the use of push notifications to encourage children to remain online; (5) codification of the FTC’s guidance on education technology; (6) increased accountability for COPPA safe harbor programs; (7) a requirement for a written children’s personal information security program; and (8) a limit on the retention of personal information to the period necessary to fulfill the specific purpose for which it was collected. The FTC settled with Rite Aid Corp. in December over the company’s use of facial recognition technology for surveillance purposes. Rite Aid allegedly deployed artificial intelligence (AI)-based facial recognition technology in an effort to identify customers who engaged in shoplifting or other problematic behavior. However, the company failed to implement reasonable measures to prevent harm to consumers who were erroneously accused of wrongdoing because the facial recognition technology falsely flagged them. The FTC’s order banned Rite Aid from using the technology for five years and required other programmatic changes to be addressed. Consumer Financial Protection Bureau In October, the Consumer Financial Protection Bureau (CFPB) proposed the Personal Financial Data Rights rule. This rule is intended to provide consumers with more control over their financial data and to effectuate sharing of data at a consumer’s direction across companies — so-called “open banking.” The rule would require banks and other providers to: (1) make personal financial data available at no charge to consumers or their agents through dedicated digital interfaces that are safe, secure and reliable; and (2) recognize a consumer’s legal right to grant third parties access to information associated with credit card, checking, prepaid and digital wallet accounts. Companies receiving data under the rule face strict limitations on what they can do with the information. They are not permitted to collect, use or retain data to advance their own commercial interests through actions like targeted or behavioral advertising. U.S. Department of Health and Human Services The U.S. Department of Health and Human Services (HHS)’s Office for Civil Rights issued a proposed rulemaking in April intended to strengthen Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule protections by prohibiting the use or disclosure of protected health information to bring criminal, civil and/or administrative proceedings against patients, providers and others involved in the provision of legal reproductive healthcare, including abortion. At the beginning of November, the American Hospital Association (AHA) sued HHS over a rule prohibiting the use of certain online tracking technologies that would result in impermissible disclosures of protected health information to tracking technology vendors or other HIPAA rule violations. In its suit, the AHA claimed the HHS rule exceeded the government’s statutory and constitutional authority, failed to satisfy the agency rulemaking requirements and harmed the population it purported to protect. The AHA also noted that the government’s own healthcare providers continued to deploy the prohibited technologies on their websites. The litigation remains ongoing. Also in November, a nonprofit academic hospital in New York settled with HHS over its sharing of protected health information of COVID-19 patients with a national media outfit in 2020. The hospital had disclosed the information of three patients without first obtaining their written authorization. It agreed to pay an $80,000 penalty and to take remedial actions to address the violations. Executive Office of the President of the United States President Joe Biden issued an executive order in October intended to address the development of AI, also referred to as language models/generative pre-trained transformers. The White House had previously acted in this space in 2022 through the publication of “Blueprint for an AI Bill of Rights” and in a February executive order directing executive agencies to take further steps to combat algorithmic discrimination, among other things. The October executive order establishes new standards for AI safety and security. It requires certain developers of “any foundation model that poses a serious risk to national security, national economic security or national public health and safety” to notify the U.S. government and to share safety test results and other critical information. It also calls upon the National Institute of Standards and Technology (NIST) to develop standards, tools and tests to help ensure that AI systems are safe, secure and trustworthy. The order also called for: (1) new standards for biological synthesis screening to protect against the risks of using AI to engineer “dangerous biological materials”; (2) the establishment of “standards and best practices for detecting AI-generated content and authenticating official content”; (3) the establishment of an “advanced cybersecurity program to develop AI tools to find and fix vulnerabilities in critical software”; and (4) additional work by the National Security Council and White House Chief of Staff to guide the U.S. military and intelligence community in their use of AI. The executive order also calls upon Congress to pass bipartisan data privacy legislation. The House and Senate have previously conferred on such legislation but it has yet to pass. The executive order also directs: (1) the prioritization of “federal support for accelerating the development and use of privacy-preserving techniques”; (2) research and development on technologies to preserve individuals’ privacy; (3) strengthening “privacy guidance for federal agencies to account for AI risks”; and (4) the development of “guidelines for federal agencies to evaluate the effectiveness of privacy-preserving techniques, including those used in AI systems.” The executive order directs agencies to ensure the “collection, use and retention of data is lawful, is secure, and mitigates privacy and confidentiality risks.” It also specifies numerous steps to be taken by specific agencies to bolster privacy protections and mitigate privacy risks potentially exacerbated by AI. These include the development of AI standards that may include “best practices regarding data capture, processing, protection, privacy, confidentiality, handling and analysis.” The deadlines in the executive order direct executive agencies to perform most of this work during 2024. Federal Communications Commission The Federal Communications Commission (FCC) adopted updated data breach notification rules in December for telecommunications carriers and relay service providers. The new regulations would require notice of breaches to be provided to the FCC as well as the U.S. Secret Service and the FBI. Notification would not need to be provided in those instances where the affected entity could reasonably determine that no harm to consumers is likely to occur due to the breach. That same month, the FCC announced that it had signed memoranda of understanding with the attorneys general of Connecticut, Illinois, New York and Pennsylvania to share expertise and resources and coordinate efforts in conducting privacy, data protection and cybersecurity-related investigations to protect consumers. U.S. Department of Defense Not content to sit on the sidelines, the U.S. Department of Defense ended 2023 by proposing a new version of its Cybersecurity Maturity Model Certification program (CMMC 2.0). The proposed rule expands on prior 2019 and 2021 proposals and calls for a tiered model of cybersecurity standards (depending on the type and sensitivity of the information), as well as assessment requirements to allow for the verification of cybersecurity standards. These standards and requirements are to be implemented through the department’s contracts. State Regulatory Developments Data Privacy Laws Last year began with one state, California, having a comprehensive data privacy regime in place and another state, Nevada, having certain privacy protections in effect. Privacy acts took effect in Colorado, Connecticut, Utah and Virginia during the year. Nine more states have data privacy regimes that will go into effect between July 1, 2024, and January 1, 2026: State Law Effective Date Florida Digital Bill of Rights July 1, 2024 Oregon Consumer Privacy Act July 1, 2024 Texas Data Privacy and Security Act July 1, 2024 Montana Consumer Data Privacy Act October 1, 2024 Delaware Personal Data Privacy Act January 1, 2025 Iowa Consumer Data Protection Act January 1, 2025 New Jersey Data Privacy Act January 15, 2025 Tennessee Information Protection Act July 1, 2025 Indiana Consumer Data Protection Act January 1, 2026 As of publication, at least another nine states have active privacy bills in their legislatures. New York State Department of Financial Services The New York State Department of Financial Services updated its cybersecurity regulations on November 1. The revised regulations: (1) strengthen governance requirements; (2) require additional controls to prevent unauthorized access and prevent or mitigate the spread of an attack; (3) impose requirements for more regular risk and vulnerability assessments, as well as more robust incident response, business continuity and disaster recovery planning; (4) contain updated notification requirements (including a requirement to report ransomware payments); and (5) include updated direction for companies to invest in at least annual training and cybersecurity awareness programs. The intent is to build out the robustness of an organization’s cybersecurity program and to ensure it has adequate resources. My Health, My Data Act In April, Washington state passed a new act that expands privacy protections for personal health data falling outside of HIPAA. The My Health, My Data Act requires consent or necessity for collecting and processing consumer health data. Regulated entities must obtain separate consent or meet the same necessity standard to share the data. The sale of data requires a written and signed authorization from the consumer. The act contains a definition of consumer health data that is significantly broader than what is typically considered health-related data. (For example, “data that identifies a consumer seeking healthcare services” is covered by the act.) Non-small-business regulated entities must comply with the act beginning March 31, 2024, and small businesses must comply beginning June 30, 2024. The act provides for a private right of action, which means that plaintiffs will likely begin testing its boundaries soon after it goes into effect. California Privacy Protection Agency The California Privacy Rights Act of 2020 established a new state agency, the California Privacy Protection Agency (CPPA), which the state is transitioning much of its administrative apparatus to for consumer privacy issues. The CPPA has not been content to accept the existing regulatory structure and is emerging as an aggressive actor with further ideas for regulation. In November, the CPPA proposed draft regulations that would define new protections against the use of automated decision-making technologies (ADMT), defined as “any system, software or process — including one derived from machine-learning, statistics or other data-processing or AI — that processes personal information and uses computation as whole or part of a system to make or execute a decision or facilitate human decision-making.” The new regulations would apply to situations where AMDT is used for: (1) decisions about employment or compensation; (2) profiling employees, contractors, applicants or students; (3) profiling consumers in publicly accessible places (such as through facial-recognition technology or automated emotion assessment); and (4) profiling consumers for behavioral advertising. Under the draft regulations, businesses are required to provide pre-use notices; allow consumers to opt out, except in certain cases, such as protecting life and safety; and provide information about how the business uses ADMT to make a decision about a consumer. In December, the CPPA voted to advance a legislative proposal to require browser vendors to include a feature that allows users to exercise their California privacy rights through opt-out preference signals. Currently, only three browsers (Mozilla Firefox, DuckDuckGo and Brave) offer native support for these signals. Given that several states either currently or will soon require businesses to honor browser privacy signals to opt out of the sale of personal data, it is likely that other states will support this effort. The CPPA suffered a setback in June when it received an unfavorable ruling that it could not enforce regulations it had created until a year after they had been finalized. This ruling delays the enforcement of the CPPA’s initial set of rules, covering topics such as privacy notice requirements and responses to consumer opt-out requests, until March 29, 2024. Looking Forward Expect this pattern of stimulus and response to continue through 2024, with regulators continuing to expand their authority to address perceived cybersecurity and privacy threats. Perhaps the greatest spur to regulators will be the continued use of AI. Given the privacy concerns raised by many of these technologies, it does not take an oracle to foresee that a great deal of additional regulation will likely be forthcoming as the world adjusts to the use of these tools.Delaware Corporate Fiduciary Duties Versus Covenants Not to Sue
May 17, 2023In the recent case New Enterprise Associates 14, L.P. et al. v. Rich et al., the Delaware Court of Chancery denied the defendants’ motion to dismiss a breach of fiduciary duty claim notwithstanding that the plaintiffs had previously agreed not to sue the defendants based on the precise claim at issue. The plaintiffs, minority investors in a Delaware corporation, had signed a voting agreement under which the defendants agreed not to sue the majority – including for breach of fiduciary duties – if the majority proceeded with a drag-along sale that satisfied certain requirements. The court characterized its decision as “grapp[ling] with a conflict between two elemental forces of Delaware corporate law: private ordering and fiduciary accountability.” Private ordering, which is based on “the contractarian nature of Delaware corporate law,” refers to restrictions on the exercise of stockholder rights that are imposed by a corporation’s charter and bylaws or by a stockholder agreement. By contrast, fiduciary accountability refers to the fiduciary duties that may be tailored but not waived under Delaware law. The court noted that while fiduciary duties and private ordering ordinarily operate in harmony, they pulled in opposite directions in this case, requiring the court to reconcile the conflict. Ultimately, the court concluded that as a matter of public policy, private ordering could not shield defendants from liability for intentional breaches of fiduciary duties, such as bad faith. Accordingly, the court held that the plaintiffs could prevail – notwithstanding their covenant not to sue – if the plaintiffs are able to prove that the defendants’ breaches of fiduciary duty constituted intentional harm. In light of this narrow avenue for the plaintiffs’ possible success on the merits, the defendants’ motion to dismiss was denied. This decision could have significant consequences for companies that rely on drag-along provisions, fiduciary duty waivers and/or covenants not to sue that appear in letters of transmittal, employee stock grants or other documents that could be viewed as imposing these restrictions on less sophisticated investors. Background The plaintiffs were investment funds that held a minority interest in Fugue, Inc., a startup that found itself in desperate need of capital. Following an unsuccessful sale process, Fugue agreed to a recapitalization in which the defendants purchased shares of Fugue’s preferred stock that carried powerful management rights. In connection with the recapitalization, Fugue and most of its stockholders entered into a voting agreement based on the National Venture Capital Association’s model form. The voting agreement contained (i) a drag-along provision that obligated the signatory stockholders to support a sale of Fugue if the sale was approved by the board of directors and a majority of the preferred stockholders and (ii) a covenant not to sue the directors or their affiliates in connection with a sale of the company that met the requirements of the drag-along provision. Three months after the recapitalization, when Fugue was no longer in severe financial distress and had received an expression of interest from a potential acquirer, Fugue’s new board of directors approved an “amendment” to the recapitalization pursuant to which certain preferred stockholders, including the defendants, purchased additional Fugue shares at the same distressed price as in the original recapitalization. Additionally (as described in more detail in the court’s companion opinion issued March 9), the directors granted themselves millions of options with a strike price set at one-tenth of the value of the common stock implied by the recapitalization. When the sale of Fugue closed, the preferred stockholders received consideration reflecting a return of almost 750%, while the option holders received a return of 3,200%. These returns came at the expense of Fugue’s original investors, prompting those original investors to sue the defendants for breach of their fiduciary duties. The defendants argued that the claims based on the sale must be dismissed since the sale satisfied the requirements of the drag-along provision in the voting agreement under which the plaintiffs had agreed not to sue for such claims. The Court’s Decision The court noted initially that the plaintiffs had argued neither that the covenant not to sue was ambiguous nor that it was induced by fraud or overreaching by the defendants. Rather, the plaintiffs relied on the “short and sweet” argument that the covenant not to sue was facially invalid simply because “[u]nder well-settled law, parties cannot waive fiduciary duties of loyalty in Delaware corporations.” Examining this argument in detail, the court proceeded to distinguish each statutory provision and case law precedent cited in support of the plaintiffs’ position, concluding that: The [plaintiffs] have advanced one reasonable interpretation of the law, but it is a stark account that elevates fiduciary accountability above all else, fails to explore the permissible bounds of fiduciary tailoring and ignores the difference between limitations in the constitutive documents of an entity and limitations in a stockholder-level agreement. The [plaintiffs’] absolutist framing pays no heed to the importance of private ordering, which is another fundament of Delaware entity law. Turning to the arguments in favor of enforcing the covenant not to sue, the court began by examining fiduciary tailoring in the contexts of trust law and agency law, under which the court determined that the covenant not to sue would be upheld. Expanding its analysis to Delaware corporate law, the court found support for the tailoring of fiduciary duties and the validity of covenants not to sue in various sections of the Delaware General Corporation Law – including notably Section 102(b)(7) regarding exculpation, Section 141(a) regarding limits on board authority and Section 145 regarding indemnification and insurance. The court also found support for the enforceability of the covenant not to sue in the common law doctrines of contractual preemption of fiduciary claims and advance ratification of interested transactions as well as in the equitable doctrine of laches. Finally, the court noted that the enforceability of a limitation on stockholder rights is greatest when the limitation appears in a stockholder agreement rather than in the corporate charter or bylaws. These considerations supported the court’s determination that the covenant not to sue falls within the realm of private ordering and is not facially invalid as a waiver of the defendants’ fiduciary duties. The court then quickly dispatched three additional arguments against enforcing the covenant, concluding that (i) the right to sue for breach of fiduciary duty is not “too big” to waive, (ii) enforcing a provision like the covenant not to sue does not threaten Delaware’s corporate brand and (iii) upholding a provision like the covenant not to sue does not collapse the distinction between corporations and limited liability companies. Having determined that the covenant not to sue was not facially invalid, the court turned to the Delaware Supreme Court’s decision in Manti Holdings, LLC v. Authentix Acquisition Co., 261 A.3d 1199 (Del. 2021) and the Chancery Court’s decision in In re Altor Bioscience Corp., C.A. No. 2017-0466-JRS (Del. Ch. May 15, 2019), which required the court to look beyond the facial validity of the covenant not to sue to determine whether it was valid as applied. Based on these cases, the court developed a two-part analysis. The first part requires that the provision be narrowly tailored to address a specific transaction that otherwise would constitute a breach of fiduciary duty – “If the provision is not sufficiently specific, then it is facially invalid.” The covenant not to sue in the instant case satisfied this requirement because it applied only to drag-along transactions meeting a specific list of criteria. The second part of the analysis requires the provision to survive close scrutiny for reasonableness. In deciding that the covenant not to sue was in fact reasonable, the court pointed to the following non-exclusive factors: “(i) a written contract formed through actual consent, (ii) a clear provision, (iii) knowledgeable stockholders who understood the provision’s implications, (iv) the [plaintiffs’] ability to reject the provision and (v) the presence of bargained-for consideration.” By contrast, the court identified several scenarios where a claim of reasonableness of a fiduciary duty waiver or covenant not to sue would face “deep skepticism and a steep uphill slog,” including an agreement binding a retail stockholder, an employee stock grant, a dividend reinvestment plan, an employee stock compensation plan and a stock transmittal letter. After determining that Delaware corporate law regarding fiduciary tailoring and private ordering permits the enforceability of a covenant not to sue for breach of fiduciary duties so long as the covenant is sufficiently specific and its application survives the court’s strict scrutiny for reasonableness, the court appeared ready to grant the defendants’ motion to dismiss. But one final consideration caused the court to decide for the plaintiffs. Citing the Restatement (Second) of Contracts §195, the court noted that a contract term that would exempt a party from tort liability for harm caused intentionally by the party is unenforceable on the grounds of public policy. Further noting that a claim for breach of fiduciary duty is an equitable tort, the court held that, “To the extent the [covenant not to sue] seeks to prevent the [plaintiffs] from asserting a claim for an intentional breach of fiduciary duty, then the [c]ovenant is invalid – not as an impermissible form of fiduciary tailoring, but because of policy limitations on contracting.” Thus, the plaintiffs’ agreement not to sue the defendants in connection with the drag-along sale would be enforceable, notwithstanding the defendants’ receiving an outsized share of the sale consideration, unless the plaintiffs could prove that the harm to them was intentional. If the defendants acted in good faith or even with reckless disregard for the best interests of the company, then the covenant not to sue would protect them. Takeaways and Practice Pointers The court rejected the argument that a waiver of duties of corporate fiduciaries is invalid on its face. It affirmed that Delaware corporate law generally permits tailoring of fiduciary duties and that private ordering through stockholder agreements among sophisticated investors will generally be enforceable if the provisions are specific and reasonable, but the court drew the line at covenants not to sue for bad faith or other intentional harm. The covenant not to sue for fiduciary duty breach at issue in this case might be unenforceable if plaintiffs can prove intentional harm, but absent such proof, the plaintiffs’ covenant not to sue for defendants’ breaches of corporate fiduciary duties would be enforceable. This case reinforces the following practice pointers: Waivers of fiduciary duties, including covenants not to sue, must be drafted clearly and unambiguously. The waiver should relate to a specific transaction or a narrowly defined subset of transactions; an overly broad scope risks unenforceability. Waivers of fiduciary duties and covenants not to sue may only be upheld against sophisticated investors who are represented by counsel, and clients should be alerted to the potential difficulty of enforcing such provisions against employee option holders or less sophisticated stockholders in a company sale. Similarly, caution should be used when relying on fiduciary duty waivers or covenants not to sue when such provisions appear in plans or documents that are presented to investors as non-negotiable. Effective private ordering should be in exchange for valuable consideration and part of a bargained-for exchange. Limits on stockholder rights, such as waivers of fiduciary duties and covenants not to sue, will not protect clients from liability for bad faith or other intentional harm.