viabandwidthDatacenter

Guide

Sanctions risk in datacenter ownership chains: what acquirers miss

By Steven Higashi · Updated 2026-06-15

How does sanctions exposure reach datacenter acquisitions through ownership chains?

Sanctions exposure in datacenter acquisitions most commonly arrives through three paths that standard due diligence checklists miss: a clean-looking operating subsidiary whose ultimate beneficial owner is a sanctioned entity, a carrier or colocation counterparty in the facility's interconnect agreements that appears on a restricted-party list, and historical ownership by a since-sanctioned entity that transferred the asset without full novation of the underlying agreements. All three require looking beyond the immediate legal entity being acquired and examining the full ownership chain, the contract counterparties, and the asset's prior ownership history.

The structure of the problem

Most M&A diligence teams screen the target company against restricted-party lists as a routine compliance step and move on. What that screen typically catches is the obvious case: a company that is itself named on the OFAC SDN list or the BIS Entity List. What it systematically misses is the situation where the target company is clean but its controlling shareholder, its ultimate beneficial owner, a material counterparty to one of its key contracts, or a prior owner of the physical asset appears on a restricted-party list. In datacenter transactions those gaps are disproportionately large because the industry structure creates many opportunities for sanctionable interests to hold infrastructure through intermediary layers.

The datacenter sector in many markets outside the United States and Western Europe has historically been capitalised by state-adjacent investors, sovereign wealth vehicles, and large conglomerates with complex cross-border ownership structures. The operating entities those investors established often look entirely ordinary at the subsidiary level, with clean local registrations, standard MSLA and carrier agreements, and no individual named in the contract documents who appears on any list. The exposure only becomes visible when you trace the ownership upward to a layer that the target company did not volunteer in its disclosure schedule and that standard registry searches do not surface automatically.

Subsidiary structures designed to isolate assets

One of the most common patterns acquirers encounter is a datacenter operating entity that was structured specifically to hold assets in a jurisdiction where the ultimate parent would face restrictions. This is not necessarily evidence of intentional sanctions evasion; it can reflect legitimate asset protection or local-market requirements. But from a diligence standpoint the effect is the same: the clean subsidiary is the entity whose contracts you are acquiring, while the restricted interest sits at a remove that is not immediately visible in the contracts themselves.

The tell for this structure is a mismatch between the jurisdiction of the operating entity and the jurisdiction of its apparent commercial affiliates. A datacenter operator incorporated in a neutral jurisdiction whose directors, management team, and carrier counterparties all have connections to a sanctioned country is worth treating as a flag even if no individual entity in that chain is itself named on a list. Secondary sanctions risk, where a party is not named on a list but is sufficiently connected to a sanctioned person or entity that transacting with it creates exposure, has expanded significantly in recent years and requires a judgment call that goes beyond matching names against databases.

The practical remediation when this structure is discovered is usually either a price adjustment that accounts for the restricted-party risk premium, a requirement that the seller restructure the ownership chain before close to remove the concerning interest, or a decision not to proceed. What it cannot be is an undisclosed post-close problem, because regulators treat the acquiring party as having adopted the exposure the moment the transaction closes regardless of what was known at the time.

Carrier and interconnect counterparty risk

The carrier interconnect agreements associated with a facility are a source of sanctions exposure that almost no standard due diligence checklist addresses. Those agreements name the carriers whose networks are present in the building, the cross-connect provider, and the transit or peering counterparties. In many markets outside the major Western carrier hubs, at least some of those counterparties will be national or regional carriers that are state-owned or state-controlled, and a meaningful fraction of state-owned carriers in sanctioned or partially-sanctioned markets have affiliated entities on restricted-party lists even when the carrier itself has not been directly designated.

The practical question is not whether you can immediately terminate a carrier contract with a concerning counterparty after close, but whether the existing agreement creates a financial obligation or a continuing service relationship that would itself constitute a sanctionable transaction. The answer depends on the specific list, the specific counterparty, and the specific jurisdiction, but the general principle is that a pre-existing commercial relationship does not automatically immunise a post-acquisition continuation of that relationship, and OFAC in particular has been explicit that acquirers may need to apply for specific licences to wind down relationships that the target maintained with SDN-listed parties.

Screening carrier and cross-connect counterparties against restricted-party lists before close is therefore not an optional enhancement to a diligence process but a requirement in any acquisition that includes a facility with international carrier relationships. The carrier records available in internet registry databases and exchange point membership lists make this screening practical without requiring the target to volunteer the information, which is relevant because targets in competitive sale processes often resist producing carrier agreement details until late in the process.

Prior ownership and the asset transfer problem

A less commonly analysed vector for sanctions exposure is the prior ownership history of the physical asset. When a datacenter building changes hands, the underlying agreements governing the facility's operations, including master lease agreements, utility contracts, and in some cases carrier presence agreements, may follow the asset rather than the seller. If a prior owner held those agreements with counterparties that have since been sanctioned, and those agreements were not fully novated or terminated as part of the prior transfer, the acquiring party in a subsequent transaction may be inheriting obligations whose original counterparties are now restricted.

This is most relevant for facilities in markets that have experienced significant changes in the sanctions environment over a relatively short period. Facilities that changed hands in Eastern Europe, the Middle East, or parts of Southeast Asia in the years before significant sanctions expansions in those regions are worth specific attention, as are facilities that were originally developed by state entities and later privatised in markets where the privatisation process was incomplete or where state ownership was partially retained through preference shares or golden-share arrangements.

The practical check is to request the full chain of title for the physical asset and the assignment history for any material long-term agreements associated with the facility, and to screen each prior owner and each original counterparty against current restricted-party lists. That screen will occasionally surface an ancestor transaction that was entirely clean at the time but that creates a current exposure under expanded lists, and the disclosure obligation under most representations-and-warranties frameworks in a current-day acquisition would require that exposure to be disclosed and addressed even if it predates the seller's ownership.

Building sanctions diligence into the acquisition process

The most effective way to structure sanctions diligence in a datacenter acquisition is to treat it as a parallel workstream that begins at the same time as financial and legal diligence rather than as a closing checklist item. The entities to screen are the operating company, every entity in the ownership chain up to and including the ultimate beneficial owner, named directors and officers above a materiality threshold, all counterparties to material contracts, and prior owners of the physical asset. The lists to screen against at minimum are OFAC SDN, BIS Entity List, BIS Denied Persons List, EU consolidated financial sanctions, UN Security Council consolidated list, and OFSI for UK-nexus assets.

The network-level records available through internet registries add an independent verification layer that corporate documents alone cannot provide. The operator identity that the registry records confirm, the ownership chain they point toward, and the carrier relationships they document together constitute a set of independently verifiable facts that a well-structured diligence process should collect and reconcile against the seller's own disclosure before the parties reach the negotiation phase on reps and warranties. Gaps between what the registry records show and what the seller has disclosed are the most reliable indicator that the diligence process needs to go deeper before it is complete.

viabandwidth maintains verified operator records for thousands of facilities globally, cross-referenced against network evidence, corporate registry data, and sanctions databases. Searching the directory by operator or facility before engaging with a target can provide an independent baseline for the entities you expect to encounter and flag discrepancies before the formal diligence process begins.

FAQ

What is the most common sanctions risk in datacenter acquisitions?
A clean operating subsidiary whose ultimate beneficial owner is a sanctioned entity. The subsidiary itself passes name-match screening, but the restricted interest sits at a layer above that standard checks do not reach.
Do I need to screen carrier counterparties against sanctions lists?
Yes. Carrier interconnect agreements associate the facility with specific networks, and some of those networks in international markets are state-owned or state-controlled entities with affiliated parties on restricted-party lists. A continuing financial obligation to a sanctioned party post-acquisition is itself a potentially sanctionable transaction.
How far back should I look at prior ownership history?
Practically, as far back as the current form of the material agreements. If a long-term lease or carrier agreement has not been fully novated since a prior ownership change, the original counterparties are relevant even if they predate the current seller's ownership.
What is secondary sanctions risk?
Exposure that arises not because a party is directly named on a sanctions list, but because it is sufficiently connected to a sanctioned person or entity that transacting with it creates regulatory risk. This requires a judgment call beyond name-matching and is most relevant in markets where state-adjacent ownership is common.

Browse the directory

viabandwidth verifies 1,988 datacenter facilities against network evidence. How we verify.