Introduction
Ireland's Screening of Third Country Transactions Act 2023 (Act) came into force on 6 January 2025. Most businesses understand that share acquisitions or asset purchases connected with critical infrastructure, critical technology, or sensitive information and involving foreign investors may require notification under the Act. What is less widely appreciated is that contracts such as operations and maintenance contracts, managed services agreements, and technology outsourcing arrangements, even where awarded by a public contracting entity through a public procurement process, can also fall within the scope of the Act. This article explains when that risk is likely to arise and what to watch for.
The mandatory notification test
A transaction must be notified to the Minister for Enterprise, Tourism and Employment where four criteria are all met:
- A third-country undertaking (i.e., from outside the EU, EEA and Switzerland) acquires control of an asset or undertaking in the State;
- The cumulative transaction value is at least €2 million;
- The parties are not all under common control; and
- The transaction relates to or impacts upon critical infrastructure, critical technologies, critical inputs, sensitive information, or media pluralism.
A service contract could satisfy these criteria in which case it would be mandatorily notifiable.
What counts as "control"?
Under section 2 of the Act, control of an asset includes ownership of, or the right to use, all or part of that asset. This means a contractual licence to access, operate or maintain a system can amount to "control" for screening purposes - even where title remains with the Irish asset owner, no shares change hands, and the arrangement is structured as a services contract.
Direct infrastructure contracts
Consider a contract by which a public body awards the operation and maintenance of a public transport network to a third country undertaking. The undertaking receives a contractual licence to access and use the network to perform services. Title to the network remains with the public body; the arrangement is a services contract, not a sale. Nonetheless, because the third country undertaking acquires the right to use transport infrastructure the transaction may be notifiable. This is because critical infrastructure includes transport infrastructure, as well as energy, water, health, communications, media, data processing or storage, aerospace, defence, electoral and financial infrastructure, and any land that may be used for such infrastructure.
Indirect infrastructure contracts: software and technology
A less obvious area of risk is contracts to develop, operate or support software systems or technology platforms that underpin critical infrastructure or hold sensitive data. A contract may fall within the Act where the provider is a third-country undertaking, and the arrangement gives it meaningful operational or use-rights over a system connected with critical infrastructure, critical technology, or sensitive information.
Key factors that distinguish a potentially notifiable arrangement from an ordinary IT services contract include:
- Exclusivity or long duration - particularly where the contract is difficult to terminate or replace.
- Operational control - where the provider hosts, administers, secures or has privileged access to the system.
- Access to sensitive data - including personal data, State data or operationally critical information.
- Strategic importance - where the system is essential to the continuity, safety or security of a critical service.
- Limited client oversight - where the client's ability to supervise, intervene or step in is constrained.
By contrast, a short-term, non-exclusive support contract with limited system access and ordinary termination rights is much less likely to be notifiable.
Consequences of non-compliance
If a contract is notifiable, the parties must ensure that it is notified before completion. A failure to notify is a criminal offence - the maximum penalties are €4 million and five years' imprisonment on indictment, and officers of a body corporate may be personally liable where the offence is committed with their consent, connivance or wilful neglect.
Also, the Minister may review transactions that should have been notified, but which were not notified, in order to prevent deliberate circumvention of the screening mechanism. The Minister is empowered to screen these transactions for a period up to 5 years after the completion of a transaction, and within 6 months of the Minister becoming aware of said transaction.
Key takeaways
The lessons for businesses are manifest:
- It is not just private M&A deals and acquisitions. Public service contracts, O&M contracts, outsourcing arrangements and technology contracts can trigger a notification obligation under the Act.
- Control of assets includes use-rights. A contractual right to access, operate or use critical infrastructure or a key system may suffice.
- Both parties are exposed. The standstill obligation applies to all parties to the transaction, including national public bodies.
- Assess early. Notification must be made at least 10 days before completion. Build screening analysis into procurement planning and contract negotiation from the outset.
For further information, please contact John Gaffney or your usual contact in Beauchamps LLP.