The problem usually arrives as a spreadsheet. Finance exports the payroll file with names, salaries, dates of birth and National Insurance numbers, someone drops it into the “Employees” folder, and by Friday six bidders and their advisers can download it. Nobody meant any harm, and the file is exactly what a buyer will eventually need. It is just far too much, far too early, for far too many people. This guide is about avoiding that moment without slowing the deal down.
Can a seller lawfully share personal data with bidders at all?
It can. Neither the UK GDPR nor the Data Protection Act 2018 stops a business from disclosing personal data to a prospective buyer. What they require is that the disclosure is fair, lawful and limited to what is necessary.
For almost every UK sale or investment, the lawful basis is legitimate interests under Article 6(1)(f). The seller has a genuine interest in selling, the buyer has a genuine interest in knowing what it is buying, and the question is whether those interests are outweighed by the rights of the employees, customers and suppliers whose details are in the files. The ICO’s guidance for organisations describes a three-part test: identify the interest, show the processing is necessary for it, then balance it against the individuals’ interests and reasonable expectations.
Write that test down. A one or two page legitimate interests assessment, dated before the room opens, is the single most useful document if a regulator, an employee or a nervous buyer later asks why their details were shared. Consent is the wrong tool here: you cannot realistically ask every member of staff to agree to a confidential sale, and consent that can be withdrawn mid-process would be unworkable.
Confidentiality agreements matter too. Every bidder should have signed an NDA that restricts use of the information to evaluating the deal, requires return or destruction if they walk away, and, ideally, contains specific data protection wording rather than a generic confidentiality clause.
Who is the controller and who is the processor in a data room?
Three parties touch the data, and their roles differ.
| Party | Usual UK GDPR role | What that means in practice |
|---|---|---|
| The seller (target company) | Controller | Decides what goes in, who sees it and why; carries the core compliance duty |
| Data room provider | Processor | Stores and serves files on the seller’s instructions; needs an Article 28 contract |
| Each bidder and its advisers | Separate controller once they hold copies | Responsible for their own use, security and deletion of what they download |
| Sell-side adviser running the room | Usually processor, sometimes joint controller | Depends on the engagement letter; agree it in writing |
The processor relationship is the one sellers most often forget. Article 28 of the UK GDPR requires a written contract with any processor, covering instructions, confidentiality, security, sub-processors, assistance with individuals’ rights, deletion or return at the end, and audit. Reputable providers publish a data processing addendum; read it rather than assuming the click-through terms cover it.
Bidders become controllers in their own right as soon as they download or note anything. That is why the NDA, and the room’s settings on downloads and printing, carry so much weight: once a copy leaves the room, your control over it is contractual, not technical.
What should go into the room at each stage?
Most of the risk disappears once you accept that bidders do not all need the same thing at the same time. A staged approach is both good deal practice and the clearest way to show data minimisation.
| Deal stage | Who has access | Personal data that is usually proportionate | Typical form |
|---|---|---|---|
| Teaser and information memorandum | Many potential buyers | None identifiable | Headcount, roles, aggregate payroll |
| First-round diligence | Three to eight bidders | Anonymised employee list, top customer revenue by band | Employee ID, role, salary band, start year |
| Second round | Two or three bidders | Key staff contracts with names redacted, customer contract terms | Redacted copies, summaries of disputes |
| Preferred bidder, confirmatory | One buyer and its advisers | Named key employees, full contracts where needed | Restricted folder, view-only where possible |
| Pre-completion and TUPE | Buyer and its HR advisers | Employee liability information where a transfer applies | Named, in a locked folder with logging |
A senior hire’s service agreement is a good test case. A first-round bidder needs to know that the chief technology officer has a 12-month notice period and a change-of-control bonus. It does not need her name, home address or bank details, so a redacted copy or a one-line summary does the job. The preferred bidder may need the signed original before exchange, and that is when it goes in.
Should this document go into the data room?
How do you handle special category and criminal offence data?
Special category data under Article 9 covers health, racial or ethnic origin, religious beliefs, trade union membership, sexual orientation, genetic and biometric data. Criminal offence data has its own rules under Article 10. In a sale, it tends to hide in sickness absence records, occupational health reports, grievance files, DBS check results, trade union recognition files and some customer datasets in healthcare or financial services.
Sharing it needs an Article 9 condition as well as an Article 6 lawful basis, and the conditions in Schedule 1 of the Data Protection Act 2018 are narrower than legitimate interests. For most deals the honest answer is that buyers rarely need individual-level special category data before signing. They need to know the size of a problem, not the identities of the people in it.
A buyer needs to know there are four live grievances and one tribunal claim. It almost never needs the medical notes behind them.
So aggregate and summarise. “Three employees on long-term sick leave, combined cost about £90,000 a year” answers the commercial question. Where a buyer’s lawyers genuinely need the underlying file, say for a live employment tribunal claim, release it late, to named individuals on the buyer’s legal team, in a folder that blocks download and prints a watermark on every page.
What should the data room provider commit to in writing?
The provider’s paperwork is where the processor duties become real. These are the questions worth putting to any shortlist, and what a satisfactory answer looks like.
| Question to ask | Why UK GDPR cares | A good answer looks like |
|---|---|---|
| Do you offer a data processing agreement? | Article 28 requires a written contract | A signed DPA or addendum covering all Article 28 terms |
| Where will this room’s files and backups be stored? | Restricted transfers need safeguards | Named countries or regions for primary storage and backups |
| Which sub-processors handle our data? | You must authorise sub-processors | A published list with notice of changes |
| Can permissions be set per user and per folder? | Security of processing, Article 32 | Granular controls, not just “view all” or “view none” |
| Is there a full audit trail we can export? | Accountability, Article 5(2) | Log of every view, download and permission change |
| How do you delete data when the room closes? | Storage limitation and deletion on exit | Written timescale and confirmation of deletion |
| What certifications do you hold? | Evidence of appropriate security measures | Current ISO 27001 certificate or SOC 2 report available under NDA |
Most established rooms cover the technical points. In our data, every provider we review has a full audit trail, dynamic watermarking and bulk upload, and most combine two-factor login with document rights control that lets you withdraw access to downloaded files. The contractual points vary more, so ask for the documents rather than the sales summary. Our scores weight security and UK GDPR support at 30% for that reason, as set out in our methodology.
Where is the data stored, and does it leave the UK?
This is the question to ask every provider directly, because the answer is not something to infer from a company’s headquarters or marketing. A business headquartered in the UK may store your files elsewhere; one headquartered in the United States or Australia may offer a UK or EU region. We do not hold verified hosting locations for the providers we review, and you should not rely on anyone’s assumption either.
If files or backups leave the UK, the transfer must be covered by one of the UK’s mechanisms: UK adequacy regulations for the destination country, the International Data Transfer Agreement (IDTA) or the UK Addendum to the EU standard contractual clauses, backed by a transfer risk assessment. The UK has adequacy regulations for the EEA, and a UK extension to the EU-US Data Privacy Framework covers certified US organisations. Ask the provider which mechanism it relies on and for a copy of the relevant terms.
Remember remote access as well. Support staff in another country who can view your files involve a transfer too, even if the servers sit in London.
How do you prepare personal data before uploading it?
Map where personal data sits
Go through the draft index folder by folder and flag every document that names or identifies a person: HR, payroll, customer lists, disputes, pensions, board minutes and emails.
Write the legitimate interests assessment
Record the purpose (the sale or investment), why disclosure is necessary and how you have balanced it against the individuals' interests. Date it before the room opens.
Decide the stage for each item
Mark each flagged document for first round, second round or preferred bidder only. Anything special category or criminal record goes to the last stage by default.
Anonymise or summarise early-stage versions
Replace names with IDs, band salaries, remove contact and bank details, and produce summaries for disputes and absence. Keep the key that links IDs to names outside the room.
Set permissions by bidder group
Create groups per bidder and per adviser type, block download and print on sensitive folders, and switch on dynamic watermarks.
Sign the processing agreement
Put the provider's DPA in place, confirm storage locations and sub-processors, and file the answers with the deal records.
Review the room before each new invitation
Each time a new bidder or adviser joins, check their group's access against the stage they are at and what their NDA allows.
Two of these steps save the most trouble. Keeping the ID-to-name key outside the room means a misconfigured permission exposes a pseudonymised list rather than a named one. Reviewing access before each invitation catches the commonest real-world mistake, which is a new bidder being added to an existing group that already sees second-round material.
What happens to the personal data after completion or a failed deal?
Storage limitation applies to the deal as much as to day-to-day operations. When the process ends, three things should happen.
First, losing bidders must return or destroy what they hold, under the NDA, and ideally confirm it in writing. Revoking their room access the day they drop out stops further views; document rights control, where your provider supports it, can also cut access to files they have already downloaded.
Second, the room itself should be closed and archived. The seller and its lawyers will usually keep an archive copy to evidence what was disclosed, because it supports the disclosure letter and any later warranty claim. That is a legitimate reason to retain it, but set a retention period and restrict who can open it.
Third, on a completed sale the personal data passes to the buyer as the new controller of the business, or, in an asset sale with a TUPE transfer, the employee records move with the staff. The buyer then needs to tell employees and, where relevant, customers about the change of controller in a privacy notice.
Does the Data (Use and Access) Act 2025 change any of this?
The Data (Use and Access) Act 2025 amends parts of the UK GDPR and the Data Protection Act 2018, and its provisions are being brought into force in stages. Among other things it introduces a list of recognised legitimate interests and adjusts some rules on international transfers. None of the changes we have seen removes the need for a lawful basis, minimisation or a processing contract when personal data goes into a deal room. Check the current position with your lawyers or the ICO before relying on any new provision, because commencement dates matter and guidance is still being updated.
What mistakes do UK deal teams make most often?
A short list, drawn from the problems that come up repeatedly in UK processes:
- Uploading the full HR folder in one go because it is “easier to organise later”.
- Treating the NDA’s confidentiality clause as data protection compliance on its own.
- Assuming the provider stores data in the UK because the sales team is based in London.
- Leaving former bidders’ access live for weeks after they withdraw.
- Keeping the archive indefinitely with no named owner.
None of these is difficult to fix. They mostly come from timing: the room is built in a rush, and the data protection thinking happens after the first bidders are already inside.
Comparing providers on security, audit trails and UK GDPR support? See how the main rooms score.
See the UK rankingQuestions people ask
Do I need employees' consent to put their data in a data room?
No. Consent is rarely appropriate for a confidential sale. The usual lawful basis is legitimate interests, supported by a written assessment and strict minimisation by deal stage.
Is the data room provider a controller or a processor?
Normally a processor acting on the seller's instructions. UK GDPR Article 28 requires a written contract with it, usually the provider's data processing agreement.
Can I share payroll data with bidders?
Aggregated or anonymised payroll data is usually fine early on. Named salary data should generally wait until a preferred bidder is chosen, and bank details and National Insurance numbers are rarely needed at all.
What if a data room provider stores files outside the UK?
That is a restricted transfer. It needs UK adequacy regulations for the destination, or the IDTA or UK Addendum with a transfer risk assessment. Ask the provider which applies and get it in writing.
Do we have to tell employees about the sale before sharing their data?
Not necessarily before the deal is announced, if your privacy notice covers disclosure in a sale and you have done a legitimate interests assessment. Take advice on the wording of your existing notices.