The principle in plain words: whatever a target company tells one bidder, or one publicly identified potential bidder, it must tell any other bona fide bidder who asks, promptly and on equal terms, even if the board would rather that second bidder went away.
That one idea, paraphrased from Rule 21.3 of the Code, changes how a public company runs a data room. In a private sale the seller can show different bidders different things, steer its favourite with better access, and close the room whenever it likes. Once a listed or Code-governed company is in an offer period, it loses most of that freedom. The room becomes a regulated record, and the people running it need to think like compliance officers as well as deal managers.
This guide covers the parts of the Code and market abuse rules that touch the data room directly. It is not a substitute for the Code itself, which is published by the Takeover Panel, or for advice from the target’s financial adviser and lawyers, who will own the process.
Which companies does the Takeover Code apply to?
Broadly, the Code applies to offers for companies with their registered office in the United Kingdom, the Channel Islands or the Isle of Man whose securities are admitted to trading on a UK regulated market (such as the Main Market of the London Stock Exchange) or a UK multilateral trading facility (such as AIM). It can also apply to some public companies and a narrower group of private companies that are not traded, depending on their history and where they are managed. The Panel has adjusted that private company scope in recent years, so if your company is unlisted, ask your lawyers to confirm the position early rather than assume either way.
For a data room, the practical point is simple. If the Code applies, everything below applies, and the target’s advisers will want the room set up with it in mind from the first approach, not from the first announcement.
When does the offer period start, and why does it matter for the room?
An offer period usually starts with an announcement: either a possible offer under Rule 2.4 or a firm offer under Rule 2.7. Before that, approaches are made privately and diligence often begins in a small, tightly controlled room.
The trigger the room has to guard against is a leak. Once a potential offeror has approached the board, the Code requires an announcement if there is rumour and speculation about a possible offer, or an untoward movement in the share price. A careless download, a forwarded document or a conversation in the wrong place can be enough. If the market moves, the Panel can require an announcement within hours, and the target loses control of its own timetable.
When a potential bidder is publicly identified, Rule 2.6 gives it 28 days to either announce a firm intention to make an offer or say it does not intend to; this is the “put up or shut up” deadline. The Panel can extend it at the target board’s request. For the data room, those 28 days are the most intense period of the whole process: the bidder is racing to finish confirmatory diligence and line up financing, and every answer it receives may later have to be given to a rival as well.
What exactly does equality of information require?
Rule 21.3 and its notes are the heart of this. The main features, as they affect a data room:
- It is triggered by a request. The target does not have to volunteer information to a rival. A competing offeror, or a bona fide potential offeror that has been publicly identified or has told the target of its intention, has to ask.
- Requests must be specific. A less welcome bidder is not entitled to receive everything given to a competitor just by asking in general terms. It has to say what it wants to know. In practice that often means rival bidders submit questions or request lists that map closely to the favoured bidder’s index.
- Information must be given promptly and equally. If the first bidder received a document, the rival asking the same question receives the same document.
- Conditions must be no more onerous. The target can ask the rival to sign a confidentiality agreement and accept the same restrictions the first bidder accepted, but cannot impose harsher terms to slow it down.
- It covers more than documents. Management presentations, site visits and oral answers can all count as information given. A record of what was said in meetings matters as much as what was uploaded.
There are also points about management buyouts, where information given to the management team’s financing banks may need to be made available to a competing offeror. Advisers handle the edge cases; the room’s job is to make whatever the advisers decide easy to prove.
What does that mean for how the room is configured?
The practical consequences follow directly from the rule. The table below compares a typical private sale room with one run for a Code-governed target.
| Room setting | Private company sale | Code-governed public target |
|---|---|---|
| Different content for different bidders | Common, by design | Possible, but every difference must be justified and recorded |
| Access granted by | Seller and its adviser | Target’s adviser, with legal sign-off |
| Q&A answers | Shared or private at seller’s discretion | Logged so they can be replicated to a rival on request |
| Management meetings | Informal notes, if any | Attendance and content recorded |
| Download and print rights | Often allowed later in the process | Usually restricted throughout |
| Access list | Housekeeping | Feeds the insider list under UK MAR |
| Closing the room | When the seller decides | Not until the offer completes or lapses, and advisers agree |
Three settings deserve most attention.
Versioning. If a document is updated during the offer period, the room must show which version each bidder saw and when. A rival asking for “the latest management accounts” is entitled to what the first bidder had, not a better or worse version.
Q&A routing. Answers in a structured Q&A module should be tagged to the bidder and timestamped. When a rival’s question overlaps, the adviser can show the same answer was given. Several rooms in our UK comparison offer structured Q&A with full history, which is the feature that matters most here.
Group design. Build each bidder as its own permission group from day one, even if only one bidder exists. Adding a rival later is then a matter of copying a group’s permissions rather than reconstructing them.
How do insider lists and UK MAR interact with the room?
Information about a possible takeover is almost always inside information under the UK Market Abuse Regulation. The target (and the bidder, if it is listed) must keep insider lists of everyone with access to it, and must be able to produce them to the FCA. The FCA’s market abuse guidance sets out the obligations.
A good data room makes this easier because it already knows who has access. Before granting anyone entry, confirm with the target’s company secretary or legal team that the person is on the insider list, or add them. Export the room’s user list at regular intervals and reconcile it to the insider list; differences should be rare and explained.
The audit trail matters too. If a leak occurs and the Panel or the FCA asks questions, a record of who viewed which documents, and when, is evidence nobody wants to reconstruct from email.
How does the timetable shape what the room does?
For a contractual offer, the Code sets a clock that runs from publication of the offer document (Day 0), which normally follows the Rule 2.7 firm offer announcement within 28 days. The milestones below are the ones most relevant to the room; check the current Code for detail and exceptions, because the Panel has revised the timetable rules in recent years.
| Timetable marker | What happens under the Code | What the data room does |
|---|---|---|
| Rule 2.7 announcement | Firm intention to make an offer is announced | Stays open for the bidder’s financing parties and any rival who asks |
| Day 0 | Offer document published | Snapshot of what each bidder has seen; versions locked |
| Day 21 | Earliest first closing date | Rival requests answered on equal terms as they arrive |
| Day 39 | Usually the last day for the target to announce material new information, such as trading results | New material uploads only with adviser sign-off |
| Day 46 | Usually the last day for the offeror to revise its offer | Final bidder questions closed |
| Day 60 | Unconditional date: offer must be unconditional or lapse, unless extended | Archive exported and access withdrawn when advisers agree |
The contractual offer clock, and what the room does at each mark
Most recommended UK takeovers are now structured as schemes of arrangement under Part 26 of the Companies Act 2006 rather than as contractual offers. A scheme needs shareholder approval and court sanction, and its timetable is set around the shareholder meetings and court hearings rather than the Day 21 to Day 60 clock. The equality of information rule still applies, and the room’s job is the same: keep a clean, provable record until the deal completes or falls away.
How should the target run the room through an offer period?
The sequence below is what we see work for target-side advisers. It assumes a financial adviser leads the process and lawyers sign off on access.
Set up before the approach goes further
Open the room with a small initial group, confirm every user is on the insider list, restrict downloads and printing, and switch on dynamic watermarking so any copy is traceable to a named person.
Create one permission group per bidder
Even with a single bidder, give it its own group. Record every grant of access with a date, the approving adviser and the document set it covers.
Route all questions through structured Q&A
Ask the bidder to submit questions in the room rather than by email. Each answer is timestamped and tied to that bidder, so it can be replicated if a rival asks the same thing.
Record what is said outside the room
Log management presentations, site visits and calls, with attendees and the materials used. Upload the slides to the bidder's group so they form part of the information given.
Handle a rival's request on the same terms
When a competing offeror asks, check that its request is specific, offer it a confidentiality agreement no more onerous than the first bidder's, and give it the matching documents and answers promptly.
Lock versions at Day 0 and control late uploads
Take an export of what each bidder has seen when the offer document goes out. After that, add new material only with adviser and legal sign-off, mindful of the Day 39 restriction on new target information.
Close and archive when the advisers agree
When the offer completes, lapses or is withdrawn, export the full room with its audit trail, store the archive securely and withdraw every external user's access.
Does the bidder need a data room of its own?
Often, yes, though it looks different. A bidder offering cash must have its financial adviser confirm that resources are available to satisfy the offer in full, so its banks and the adviser need a place to review the financing documents, the bidder’s own accounts and the model behind the price. A bidder offering shares faces more: its own shareholders and the target’s will need information about it, and if the bidder is listed, the same insider list duties apply on its side.
A separate, small room for the financing workstream keeps those documents away from the target’s advisers and makes the bidder’s own record easier to produce if questions arise. It also helps if a management team is part of the bid, because information shared with the team’s lenders may need to be handled carefully under the Code. Keep the two rooms apart; mixing target information with bidder financing papers is a recipe for confusion when a rival appears.
Which data room features matter most in a public takeover?
The criteria shift compared with a private sale. Speed of setup still matters, but control and evidence matter more. The features that earn their place:
- Granular, group-based permissions that can be copied to a new bidder in minutes.
- A structured Q&A module with full history, tagging and export.
- Dynamic watermarking with the viewer’s name, and controls on downloading and printing.
- A complete audit trail that can be exported in a usable format for the Panel or the FCA.
- Two-factor login for every user, without exceptions for senior people.
- Single sign-on, if the target’s IT policy requires it for external systems.
Among the providers we review, iDeals, Datasite and Intralinks are established enterprise rooms with ISO 27001 and SOC 2 and, in our data, single sign-on. Ellty offers the same core toolkit (granular permissions, structured Q&A, dynamic watermarking, document rights control, a full audit trail and two-factor login) in a newer interface, though without single sign-on. Our methodology weights security and UK GDPR at 30% of the overall score for exactly this kind of use.
Whichever you choose, ask the provider where the room’s data will be hosted and which subprocessors handle it. We do not hold confirmed hosting regions for any vendor, and the answer matters for both UK GDPR and the target’s own risk committee.
Comparing rooms for a public deal? See how the providers score on security, deal tools and support.
See the UK rankingsWhat goes wrong most often?
The failures we hear about are rarely dramatic. A director emails a board pack to a bidder’s adviser outside the room, and nobody logs it. A management presentation includes a forecast that never makes it into the data room, so the rival who later asks cannot be given the same information. A document is quietly updated, and two bidders end up relying on different versions. An adviser grants access to a junior colleague who is not on the insider list.
Each of these is fixable, but each creates a gap in the record precisely when the Panel, a rival bidder or a regulator might ask to see it. The discipline is not complicated: everything given goes through the room, everything in the room is logged, and every user is on the list.
Questions people ask
Does Rule 21.3 mean a rival bidder sees the whole data room?
No. The rival must ask specific questions, and is entitled to the same answers and documents the first bidder received on those points. It cannot obtain everything simply by asking in general terms.
Can the target refuse a hostile bidder access to the data room?
It can refuse to provide information that has not been requested specifically, and it can require the same confidentiality terms the first bidder signed. It cannot impose harsher conditions to keep an unwelcome bidder out.
Does the Takeover Code apply to AIM companies?
Yes. The Code applies to companies with a registered office in the UK, the Channel Islands or the Isle of Man whose securities trade on a UK multilateral trading facility such as AIM, as well as those on the Main Market.
Do schemes of arrangement follow the Day 60 timetable?
Not in the same way. A scheme's timetable is built around shareholder meetings and court hearings, but the equality of information rule and the confidentiality obligations still apply to the data room.
How long should the target keep the data room archive?
Keep a full export with its audit trail at least until any disputes or regulatory questions about the offer have been resolved, and follow the retention policy your lawyers set for the transaction.