Independent data room comparisons for UK businessesPrices shown in GBP where publishedUpdated October 2026
DataRooms.uk Find my data room
Menu
security and compliance

UK GDPR in a data room: sharing personal data during due diligence

The problem usually arrives as a spreadsheet. Finance exports the payroll file with names, salaries, dates of birth and National Insurance numbers, someone drops it into the “Employees” folder, and by Friday six bidders and their advisers can download it. Nobody meant any harm, and the file is exactly what a buyer will eventually need. It is just far too much, far too early, for far too many people. This guide is about avoiding that moment without slowing the deal down.

Can a seller lawfully share personal data with bidders at all?

It can. Neither the UK GDPR nor the Data Protection Act 2018 stops a business from disclosing personal data to a prospective buyer. What they require is that the disclosure is fair, lawful and limited to what is necessary.

For almost every UK sale or investment, the lawful basis is legitimate interests under Article 6(1)(f). The seller has a genuine interest in selling, the buyer has a genuine interest in knowing what it is buying, and the question is whether those interests are outweighed by the rights of the employees, customers and suppliers whose details are in the files. The ICO’s guidance for organisations describes a three-part test: identify the interest, show the processing is necessary for it, then balance it against the individuals’ interests and reasonable expectations.

Write that test down. A one or two page legitimate interests assessment, dated before the room opens, is the single most useful document if a regulator, an employee or a nervous buyer later asks why their details were shared. Consent is the wrong tool here: you cannot realistically ask every member of staff to agree to a confidential sale, and consent that can be withdrawn mid-process would be unworkable.

Confidentiality agreements matter too. Every bidder should have signed an NDA that restricts use of the information to evaluating the deal, requires return or destruction if they walk away, and, ideally, contains specific data protection wording rather than a generic confidentiality clause.

Who is the controller and who is the processor in a data room?

Three parties touch the data, and their roles differ.

PartyUsual UK GDPR roleWhat that means in practice
The seller (target company)ControllerDecides what goes in, who sees it and why; carries the core compliance duty
Data room providerProcessorStores and serves files on the seller’s instructions; needs an Article 28 contract
Each bidder and its advisersSeparate controller once they hold copiesResponsible for their own use, security and deletion of what they download
Sell-side adviser running the roomUsually processor, sometimes joint controllerDepends on the engagement letter; agree it in writing

The processor relationship is the one sellers most often forget. Article 28 of the UK GDPR requires a written contract with any processor, covering instructions, confidentiality, security, sub-processors, assistance with individuals’ rights, deletion or return at the end, and audit. Reputable providers publish a data processing addendum; read it rather than assuming the click-through terms cover it.

Bidders become controllers in their own right as soon as they download or note anything. That is why the NDA, and the room’s settings on downloads and printing, carry so much weight: once a copy leaves the room, your control over it is contractual, not technical.

What should go into the room at each stage?

Most of the risk disappears once you accept that bidders do not all need the same thing at the same time. A staged approach is both good deal practice and the clearest way to show data minimisation.

Deal stageWho has accessPersonal data that is usually proportionateTypical form
Teaser and information memorandumMany potential buyersNone identifiableHeadcount, roles, aggregate payroll
First-round diligenceThree to eight biddersAnonymised employee list, top customer revenue by bandEmployee ID, role, salary band, start year
Second roundTwo or three biddersKey staff contracts with names redacted, customer contract termsRedacted copies, summaries of disputes
Preferred bidder, confirmatoryOne buyer and its advisersNamed key employees, full contracts where neededRestricted folder, view-only where possible
Pre-completion and TUPEBuyer and its HR advisersEmployee liability information where a transfer appliesNamed, in a locked folder with logging

A senior hire’s service agreement is a good test case. A first-round bidder needs to know that the chief technology officer has a 12-month notice period and a change-of-control bonus. It does not need her name, home address or bank details, so a redacted copy or a one-line summary does the job. The preferred bidder may need the signed original before exchange, and that is when it goes in.

Should this document go into the data room?

1 Does the document hold personal data about anyone?
No
Upload
Upload as is, with the usual folder permissions
Yes
2 Does a bidder need it at this stage of the deal?
No
Later
Hold it back until a later round or the preferred bidder
Yes
3 Is it health, union, biometric or criminal record data?
Yes
Restrict
Clean team or advisers-only folder, released late
No
4 Would an anonymised or summary version answer the question?
Yes
Clean
Redact or summarise first, then upload the cleaned copy
No
ControlUpload to a restricted folder with watermarks, view-only access and logging
Ask four questions in order; most personal data ends up summarised, delayed or restricted rather than uploaded as is. Source: the stage-by-stage approach in this guide.

How do you handle special category and criminal offence data?

Special category data under Article 9 covers health, racial or ethnic origin, religious beliefs, trade union membership, sexual orientation, genetic and biometric data. Criminal offence data has its own rules under Article 10. In a sale, it tends to hide in sickness absence records, occupational health reports, grievance files, DBS check results, trade union recognition files and some customer datasets in healthcare or financial services.

Sharing it needs an Article 9 condition as well as an Article 6 lawful basis, and the conditions in Schedule 1 of the Data Protection Act 2018 are narrower than legitimate interests. For most deals the honest answer is that buyers rarely need individual-level special category data before signing. They need to know the size of a problem, not the identities of the people in it.

A buyer needs to know there are four live grievances and one tribunal claim. It almost never needs the medical notes behind them.

So aggregate and summarise. “Three employees on long-term sick leave, combined cost about £90,000 a year” answers the commercial question. Where a buyer’s lawyers genuinely need the underlying file, say for a live employment tribunal claim, release it late, to named individuals on the buyer’s legal team, in a folder that blocks download and prints a watermark on every page.

What should the data room provider commit to in writing?

The provider’s paperwork is where the processor duties become real. These are the questions worth putting to any shortlist, and what a satisfactory answer looks like.

Question to askWhy UK GDPR caresA good answer looks like
Do you offer a data processing agreement?Article 28 requires a written contractA signed DPA or addendum covering all Article 28 terms
Where will this room’s files and backups be stored?Restricted transfers need safeguardsNamed countries or regions for primary storage and backups
Which sub-processors handle our data?You must authorise sub-processorsA published list with notice of changes
Can permissions be set per user and per folder?Security of processing, Article 32Granular controls, not just “view all” or “view none”
Is there a full audit trail we can export?Accountability, Article 5(2)Log of every view, download and permission change
How do you delete data when the room closes?Storage limitation and deletion on exitWritten timescale and confirmation of deletion
What certifications do you hold?Evidence of appropriate security measuresCurrent ISO 27001 certificate or SOC 2 report available under NDA

Most established rooms cover the technical points. In our data, every provider we review has a full audit trail, dynamic watermarking and bulk upload, and most combine two-factor login with document rights control that lets you withdraw access to downloaded files. The contractual points vary more, so ask for the documents rather than the sales summary. Our scores weight security and UK GDPR support at 30% for that reason, as set out in our methodology.

Where is the data stored, and does it leave the UK?

This is the question to ask every provider directly, because the answer is not something to infer from a company’s headquarters or marketing. A business headquartered in the UK may store your files elsewhere; one headquartered in the United States or Australia may offer a UK or EU region. We do not hold verified hosting locations for the providers we review, and you should not rely on anyone’s assumption either.

If files or backups leave the UK, the transfer must be covered by one of the UK’s mechanisms: UK adequacy regulations for the destination country, the International Data Transfer Agreement (IDTA) or the UK Addendum to the EU standard contractual clauses, backed by a transfer risk assessment. The UK has adequacy regulations for the EEA, and a UK extension to the EU-US Data Privacy Framework covers certified US organisations. Ask the provider which mechanism it relies on and for a copy of the relevant terms.

Remember remote access as well. Support staff in another country who can view your files involve a transfer too, even if the servers sit in London.

How do you prepare personal data before uploading it?

  1. Map where personal data sits

    Go through the draft index folder by folder and flag every document that names or identifies a person: HR, payroll, customer lists, disputes, pensions, board minutes and emails.

  2. Write the legitimate interests assessment

    Record the purpose (the sale or investment), why disclosure is necessary and how you have balanced it against the individuals' interests. Date it before the room opens.

  3. Decide the stage for each item

    Mark each flagged document for first round, second round or preferred bidder only. Anything special category or criminal record goes to the last stage by default.

  4. Anonymise or summarise early-stage versions

    Replace names with IDs, band salaries, remove contact and bank details, and produce summaries for disputes and absence. Keep the key that links IDs to names outside the room.

  5. Set permissions by bidder group

    Create groups per bidder and per adviser type, block download and print on sensitive folders, and switch on dynamic watermarks.

  6. Sign the processing agreement

    Put the provider's DPA in place, confirm storage locations and sub-processors, and file the answers with the deal records.

  7. Review the room before each new invitation

    Each time a new bidder or adviser joins, check their group's access against the stage they are at and what their NDA allows.

Two of these steps save the most trouble. Keeping the ID-to-name key outside the room means a misconfigured permission exposes a pseudonymised list rather than a named one. Reviewing access before each invitation catches the commonest real-world mistake, which is a new bidder being added to an existing group that already sees second-round material.

What happens to the personal data after completion or a failed deal?

Storage limitation applies to the deal as much as to day-to-day operations. When the process ends, three things should happen.

First, losing bidders must return or destroy what they hold, under the NDA, and ideally confirm it in writing. Revoking their room access the day they drop out stops further views; document rights control, where your provider supports it, can also cut access to files they have already downloaded.

Second, the room itself should be closed and archived. The seller and its lawyers will usually keep an archive copy to evidence what was disclosed, because it supports the disclosure letter and any later warranty claim. That is a legitimate reason to retain it, but set a retention period and restrict who can open it.

Third, on a completed sale the personal data passes to the buyer as the new controller of the business, or, in an asset sale with a TUPE transfer, the employee records move with the staff. The buyer then needs to tell employees and, where relevant, customers about the change of controller in a privacy notice.

Does the Data (Use and Access) Act 2025 change any of this?

The Data (Use and Access) Act 2025 amends parts of the UK GDPR and the Data Protection Act 2018, and its provisions are being brought into force in stages. Among other things it introduces a list of recognised legitimate interests and adjusts some rules on international transfers. None of the changes we have seen removes the need for a lawful basis, minimisation or a processing contract when personal data goes into a deal room. Check the current position with your lawyers or the ICO before relying on any new provision, because commencement dates matter and guidance is still being updated.

What mistakes do UK deal teams make most often?

A short list, drawn from the problems that come up repeatedly in UK processes:

  • Uploading the full HR folder in one go because it is “easier to organise later”.
  • Treating the NDA’s confidentiality clause as data protection compliance on its own.
  • Assuming the provider stores data in the UK because the sales team is based in London.
  • Leaving former bidders’ access live for weeks after they withdraw.
  • Keeping the archive indefinitely with no named owner.

None of these is difficult to fix. They mostly come from timing: the room is built in a rush, and the data protection thinking happens after the first bidders are already inside.

Comparing providers on security, audit trails and UK GDPR support? See how the main rooms score.

See the UK ranking

Questions people ask

Do I need employees' consent to put their data in a data room?

No. Consent is rarely appropriate for a confidential sale. The usual lawful basis is legitimate interests, supported by a written assessment and strict minimisation by deal stage.

Is the data room provider a controller or a processor?

Normally a processor acting on the seller's instructions. UK GDPR Article 28 requires a written contract with it, usually the provider's data processing agreement.

Can I share payroll data with bidders?

Aggregated or anonymised payroll data is usually fine early on. Named salary data should generally wait until a preferred bidder is chosen, and bank details and National Insurance numbers are rarely needed at all.

What if a data room provider stores files outside the UK?

That is a restricted transfer. It needs UK adequacy regulations for the destination, or the IDTA or UK Addendum with a transfer risk assessment. Ask the provider which applies and get it in writing.

Do we have to tell employees about the sale before sharing their data?

Not necessarily before the deal is announced, if your privacy notice covers disclosure in a sale and you have done a legitimate interests assessment. Take advice on the wording of your existing notices.