
Mergers and Acquisitions (M&A)
Support for deals in telecoms, data and payment sectors
Telecoms M&A requires specialist regulatory input from the outset. Acquiring or selling an operator, payment service provider or data-intensive business means working within the Communications Act 2003, the UK GDPR, the Payment Services Regulations 2017 and the Telecommunications (Security) Act 2021. Corporate teams run deal mechanics; specialist regulatory counsel ensures the regulatory overlay is mapped, priced and integrated into the deal structure from day one.
Why telecoms M&A deals stall post-completion
Whether regulatory obligations transfer on completion depends on deal structure. In a share deal, the target entity retains its regulatory status: General Conditions, SMP conditions, spectrum licences, numbering allocations and Code Powers all remain with the company. The buyer acquires the shares and inherits those obligations through its ownership of the entity. Change of control provisions in spectrum licences or other regulatory instruments may be triggered, but the obligations themselves stay in place.
An asset deal works differently. Regulatory assets do not transfer automatically. A buyer must obtain its own Ofcom direction applying the Electronic Communications Code, because a direction under section 106 of the Communications Act 2003 applies to a named person and does not pass with the assets. The code rights under an existing Code agreement do assign to another operator, and paragraph 16 of Schedule 3A makes void any term that prevents or conditions that assignment, save that paragraph 16(2) preserves a term requiring the assignor to enter into a guarantee agreement. Numbering allocations can be transferred to the buyer, but only with Ofcom’s consent, which is not automatic and requires a formal application. If consent is not given, the numbers must be surrendered and the buyer must apply for fresh allocation, creating service continuity risk. Spectrum licences may need to be varied or reissued. This distinction can drive deal structure: where the target holds material regulatory assets that cannot easily be replicated, a share deal may be the only practical option even if an asset deal would otherwise be preferred for tax or commercial reasons.
The Communications Act 2003 imposes General Conditions on all electronic communications service providers. Where a target is subject to SMP services conditions under sections 87 to 91A, imposed following the market analysis in sections 78 to 86, those obligations transfer with the business in a share deal and constrain the buyer’s pricing, product bundling and network decisions. A target with cost orientation obligations cannot be immediately integrated into a buyer’s commercial model without triggering breach. Cost orientation is imposed by Ofcom under section 87 based on market dominance findings; it is not negotiable.
In a share deal, numbering allocation blocks remain with the target entity. The buyer must use allocated numbering in accordance with the original allocation conditions. Switching from geographic to functional numbering triggers a new allocation process with Ofcom. In an asset deal, the seller’s numbering allocations can be transferred to the buyer with Ofcom’s consent. The consent process takes time and is not guaranteed, so the transition plan must address the risk that consent is refused or delayed, and the buyer may need to apply for fresh allocations in parallel.
Data protection compliance becomes more complex in a transaction context. Due diligence scopes often examine the target’s ICO enforcement history and privacy notice compliance. What they rarely examine are the ongoing relationships: where the target acts as a controller, what data flows are required for integration, whether processor contracts with the buyer’s preferred vendors are feasible, and whether the seller’s international transfer mechanisms will work post-close. A buyer integrating a target into its own business processes usually becomes a joint controller or replaces existing processors. The buyer must then meet the transparency duties in Articles 13 and 14 UK GDPR for the populations concerned, update the privacy information, put Article 28 processor terms in place, and complete a data protection impact assessment under Article 35 where the processing is likely to result in a high risk.
Where the target is a payment institution, a buyer acquiring or increasing control must notify the FCA and obtain its approval before completing, under Part 12 of the Financial Services and Markets Act 2000 as applied by Schedule 6 to the PSRs 2017. In telecoms, there is no equivalent Ofcom change of control regime. Telecoms mergers are assessed by the CMA under the Enterprise Act 2002, with Ofcom providing sector-specific input on competition and spectrum issues. However, the buyer inherits all General Condition compliance obligations on completion and must be able to demonstrate ongoing compliance to Ofcom from day one.
The Telecommunications (Security) Act 2021 inserted section 105K into the Communications Act 2003 with effect from 1 October 2022. A provider of a public electronic communications network or service must inform Ofcom as soon as reasonably practicable of any security compromise that has a significant effect on the operation of the network or service, and of any compromise that puts a person in a position to bring about a further compromise of that kind. Where a target is subject to these obligations, the buyer inherits them on completion. The buyer’s security protocols must be capable of meeting the reporting and compliance requirements from day one.
Where regulatory risk is underestimated
Regulatory issues surface late in a regulated deal for reasons that are structural rather than accidental.
SPA risk allocation routinely fails to reflect regulatory reality. Warranties drafted using “material compliance” language do not capture the granularity of telecoms regulation. A warranty that “the Target has complied in all material respects with applicable law” may be technically accurate while leaving SMP obligations that cap wholesale pricing entirely undisclosed. That cap sets a ceiling on wholesale revenue and feeds straight into the valuation model. It should be identified in the data room, disclosed explicitly, and quantified in the price adjustment mechanism. Where a specific regulatory risk is identified and disclosed, the appropriate tool is often a specific indemnity rather than a broad warranty. Specialist regulatory input at the risk allocation stage prevents gaps.
Data protection due diligence scoped around the seller’s compliance history misses the buyer’s integration burden. A target with a clean ICO record passes due diligence. The buyer then discovers post-close that the target is a controller of customer personal data, the buyer’s standard processor contracts do not match existing vendor agreements, and the seller’s international transfer mechanism is now the buyer’s responsibility. The buyer cannot rely on the seller’s standard contractual clauses; it must put its own in place. That negotiation involves the seller’s vendors and is a common source of delay to day-one data migration. A regulatory due diligence workstream running in parallel with the corporate DD catches this early.
The regulatory compliance workstream is under-resourced. General Condition compliance, numbering block confirmation, Code Powers status and spectrum licence conditions are ongoing obligations that require interpretation and sometimes advance engagement with Ofcom or the CMA. If the buyer’s network integration plan conflicts with a numbering allocation condition or an SMP obligation, that conflict must be resolved before close.
| Common issue | Better approach |
|---|---|
| SPA warranties using generic material compliance language | Warranties reflecting specific SMP, numbering and spectrum obligations |
| Data protection DD limited to breach history | DD covering integration burden, Article 28 transitions and DPIA requirements |
| Regulatory compliance treated as a post-close workstream | Pre-signature DD identifying valuation-affecting regulatory obligations |
| CMA clearance timeline not reflected in conditions | Regulatory conditions with realistic long-stop dates and walk-away rights |
| Code Powers and numbering transfers left to integration | Ofcom engagement on transfers built into deal timeline |
Spectrum-licence transfers add a further regulatory layer in telecoms M&A. In an asset deal, a transfer may require Ofcom consent under the applicable transfer framework and licence terms. In a share deal, the licence remains with the target entity, but any notification, consent or change-of-control requirement depends on the specific licence and regulatory regime. The position should be checked early enough to build any required regulator process into the transaction timetable.
The National Security and Investment Act 2021 and UK merger-control regime require separate analysis. Mandatory NSIA notification does not apply to every acquisition of a communications provider. Under Schedule 5 to the Notifiable Acquisition Regulations 2021, a PECN or PECS provider falls within the communications description where the turnover of its relevant UK business for the relevant period is at least £50 million; other specified communications activities are covered separately. The acquisition must also meet the statutory control conditions. UK merger control may apply under the £100 million target-turnover test, the share-of-supply route, including the additional £10 million turnover condition, or the separate 33% and £350 million test with a UK-nexus condition.
For payments M&A, the Payment Systems Regulator does not operate a formal pre-acquisition clearance regime. Its powers under section 58 of the Financial Services (Banking Reform) Act 2013 are remedial: it can require disposal of interests in payment system operators, with Treasury consent, where necessary to prevent competition restrictions. A person who decides to acquire or increase control of an authorised payment institution must notify the FCA and obtain approval before completing, under Part 12 of the Financial Services and Markets Act 2000 as applied by Schedule 6 to the Payment Services Regulations 2017. The same regime applies to an electronic money institution through Schedule 3 to the Electronic Money Regulations 2011. A buyer of a regulated payments business runs three timetables at once. FCA approval of the change in control and, where the acquisition is notifiable, clearance under the National Security and Investment Act 2021 must both be obtained before completion. UK merger control is voluntary, so the buyer decides whether to notify the CMA, weighing the CMA’s power to open an own-initiative investigation into a completed merger against the delay a merger notice adds.
What good M&A regulatory practice looks like
Bratby Law works the regulatory questions at three points in the transaction: before signature, at risk allocation, and after completion.
Pre-signature due diligence identifies regulatory obligations that affect valuation: SMP conditions, numbering constraints, spectrum conditions, Code Powers status and Ofcom licence history. We produce a regulatory report section for the data room that spells out each obligation in plain language and flags the impact on the buyer’s commercial model.
Risk allocation reflects regulatory reality. Rather than broad “compliance” warranties, we specify which General Conditions must be met at completion, which numbering blocks must be confirmed, and what spectrum licences must be in force. Where regulatory DD identifies specific risks, we advise on appropriate indemnities. We map FCA qualifying holdings notification requirements under the PSRs 2017 if the target is a payment service provider, and NSIA mandatory notification if the target falls within a qualifying sector. For data protection, we include a specific condition that the buyer must have updated processor agreements before day-one data migration.
Clearance under the National Security and Investment Act 2021 and FCA approval of the change in control are conditions to completion, not integration tasks. After completion the sequence is the Code Powers assignment documentation, numbering confirmation, and the data protection controller transition.
How Bratby Law helps
On larger M&A transactions, we work as Specialist Co-counsel alongside the corporate lead firm. The corporate team handles deal mechanics, SPA negotiation and multi-jurisdictional coordination. We are responsible for the regulatory workstream: Ofcom, ICO, FCA and PSR analysis, NSIA mandatory notification assessment, regulatory due diligence, conditions precedent and warranty drafting on regulatory matters, and post-completion regulatory integration planning. We report to the lead partner and work to the deal timetable. There is no duplication of corporate work.
On smaller and mid-market telecoms M&A, we act as lead Advisor through our Direct Legal Advice model, handling both the regulatory and transactional work as a single team.
In both models, we draw on operator-side experience from four current fractional General Counsel appointments at telecoms, data and payments operators. We advise on the regulatory perimeter and material obligations before signature, draft regulatory conditions precedent, warranties and indemnities, integrate General Condition compliance, SMP obligations, numbering and spectrum constraints and TSA 2021 requirements into the transaction timeline, manage DPIA and processor agreement transitions, and structure the post-close regulatory workstreams.
Frequently asked questions about telecoms and payments M&A
Is there an Ofcom change of control regime for telecoms?
No. Ofcom has no formal change of control approval or notification regime for electronic communications providers. Telecoms mergers are assessed by the CMA under the Enterprise Act 2002. However, the buyer inherits all General Condition and SMP obligations on completion and must demonstrate ongoing compliance to Ofcom. If your post-completion integration plan conflicts with those obligations, the conflict must be resolved before close.
How do I assess the value impact of SMP conditions?
SMP conditions typically include cost orientation on wholesale pricing and non-discrimination obligations. Cost orientation caps wholesale revenue at underlying cost plus reasonable margin. Valuation models must account for this cap.
What data protection issues arise in telecoms M&A?
The target is likely a controller of customer and operational personal data. Data migration requires you to become joint controller or replace existing processors, triggering Article 28 UK GDPR requirements and potentially Article 35 DPIAs. The target’s historical SCCs transfer to you post-close and must be maintained or renegotiated.
How long does regulatory due diligence take?
The timetable for regulatory due diligence depends on the transaction, the scope of the regulated activities, the quality of the data room and whether regulator engagement is required. We agree a prioritised work plan at the outset and identify issues that could affect signing, conditions precedent or completion.
What if the target is subject to Code Powers agreements?
Code Powers under Schedule 3A Communications Act 2003 (the Electronic Communications Code) confer rights to install and maintain electronic communications apparatus on, under or over land. In a share deal the rights stay where they are, because the operator entity is unchanged. In an asset deal the code rights assign under paragraph 16 of Schedule 3A, but only to another operator, so the buyer needs its own Ofcom direction under section 106 before the assignment can take effect. We check the target’s Code Powers status and agreements, and advise on notifications to landowners and local authorities of the change in operator.
Do I need Ofcom consent to transfer a spectrum licence?
In an asset deal, a spectrum-licence transfer may require Ofcom consent under the applicable transfer framework and licence terms. In a share deal, the licence remains with the target entity, but any notification, consent or change-of-control requirement depends on the specific licence and regulatory regime. There is no universal Ofcom notification rule for every change in ultimate ownership.
When does NSIA mandatory notification apply to a telecoms or payments deal?
The National Security and Investment Act 2021 requires mandatory notification only where the target’s activities fall within a description in the Notifiable Acquisition Regulations 2021 and the acquisition meets the statutory control conditions. A target is not caught merely because it provides a PECN or PECS. For that part of the communications description, the turnover of the relevant UK business for the relevant period must be at least £50 million. Other communications and financial-market-infrastructure activities are covered by their own detailed definitions and thresholds. A notifiable acquisition completed without the Secretary of State’s approval is void under section 13(1), and the parties are exposed to criminal and civil penalties.
What PSR clearance is needed for a payments acquisition?
The PSR does not operate a formal pre-acquisition clearance regime. Its powers under section 58 of the Financial Services (Banking Reform) Act 2013 are remedial, allowing it to require disposal of interests where necessary to prevent competition restrictions. A person acquiring or increasing control of an authorised payment institution must notify the FCA and obtain approval before completing, under Part 12 of the Financial Services and Markets Act 2000 as applied by Schedule 6 to the Payment Services Regulations 2017. That approval and, where the acquisition is notifiable, NSIA clearance must both be in hand before completion. Notification to the CMA is voluntary, so the buyer takes a considered decision on whether to file.
Related transactions pages
See also our other transactions pages:
- Private equity
- SaaS and Cloud Services
- Subsea cables
- MVNOs and MVNEs
- Interconnection, peering and access agreements
- Network sharing and co-location agreements
- Digital Infrastructure Projects
- Data Commercialisation and Licensing
- NSIA Clearances
Independent directory rankings
Our specialist expertise is recognised in major independent legal directories:
- Chambers & Partners: Rob Bratby is ranked as a Band 2 lawyer in the UK Guide 2026 in the “Telecommunications” category: Chambers
- The Legal 500: Rob Bratby is listed as a Leading Partner for Telecoms in London (TMT: IT and Telecoms). The Legal 500
- Lexology: Rob Bratby is recognised in the Lexology Index as a Global Elite Thought Leader for telecoms and media, and as a Thought Leader for data privacy and protection: Lexology



See our Core Communication and TelXL case studies for examples of how we advise on corporate transactions.
