Solicitors use data rooms in two ways. Sometimes the firm administers a room for a client, typically on a sell-side transaction or a property disposal. More often, the firm’s lawyers work inside rooms set up by someone else. Both roles carry professional duties, and the choice of tool, and how it is configured, is part of how a firm meets them.
Where firms use rooms
| Matter type | Firm’s usual role | What the room does for the matter |
|---|---|---|
| Corporate sale | Seller’s counsel, often administrator | Stages disclosure, holds the record behind the disclosure letter |
| Acquisition | Buyer’s counsel, guest in the seller’s room | Source for the legal due diligence report and Q&A |
| Commercial property | Seller’s solicitor, administrator | Title, leases and replies to enquiries in one indexed place |
| Litigation and arbitration | Either party | Controlled exchange of disclosure documents, expert reports and bundles |
| Restructuring | Counsel to the company, lenders or an insolvency practitioner | Fast access for lenders and bidders under a tight timetable |
| Regulatory investigation | Counsel to the client | Organised production of documents with a full access record |
In litigation in the Business and Property Courts, disclosure is governed by Practice Direction 57AD, which puts weight on cooperation and proportionate searches. A room helps by giving both sides a single, versioned set of disclosed documents and a record of when each was provided.
Professional duties behind the choice
The SRA’s Code of Conduct requires solicitors to keep the affairs of current and former clients confidential unless disclosure is required or permitted by law or the client consents. Choosing how client information is shared is therefore not just an IT question. The SRA Code of Conduct for Solicitors is the reference, and many firms set out in their information security policy which matters must use a data room rather than email.
UK GDPR adds a second layer. Where the firm administers a room containing client personal data, it needs a written agreement with the provider covering processing, security and deletion. If a breach occurs, the controller may need to report it to the ICO within 72 hours, and the room’s audit trail will be the first thing anyone asks for.
Many clients, especially in financial services and the public sector, now ask their law firms to hold Cyber Essentials certification. That scheme covers the firm’s own systems, not the provider, so ask providers separately for their certifications and their answer on where data is hosted.
Why email is not enough for sensitive matters
Attachments are convenient, but once sent, the firm loses control of them. The comparison below sets out the gap.
Email attachments versus a data room: what a firm can control
Withdraw access after a document has been shared
EmailNo Data roomYesSee who opened which file, and when
EmailNo Data roomYesWatermark each copy with the reader's name
EmailNo Data roomYesKeep one current version of each document
EmailNo Data roomYesLog questions and answers against the documents
EmailPartly Data roomYesExport the whole record when the matter closes
EmailPartly Data roomYesOnce an attachment leaves the building it cannot be recalled or tracked; a room keeps the firm in control.
datarooms.ukFor law firms
For a routine exchange of a draft agreement, email is fine. For a disclosure exercise, a sale, or anything involving personal data in volume, the inability to withdraw or track documents is a real risk.
Being a good guest in someone else’s room
On the buy side, the firm’s lawyers are working in a room the seller controls, and every click is logged. Agree internally who will download and who will only view; some sellers watch download volumes closely. Route questions through the room’s Q&A rather than calling the seller’s counsel, so that answers are on the record. And keep the firm’s own copy of what was reviewed, because the room will close after completion and the diligence report must stand on its own.
Mistakes firms make
Common problems are procedural. Trainees are given administrator rights on live matters. Permission changes are made on request by phone with no record. Rooms are left open for months after a matter closes, with former counterparties still able to log in. And the final export is skipped, leaving the firm without a copy of what was disclosed if the matter comes back as a claim. A simple matter-closing checklist covering export, access removal and deletion confirmation solves most of this.
Paying for the room
Firms either pay per matter and recharge the client as a disbursement, or hold an annual agreement and allocate cost internally. Published monthly pricing makes per-matter quotes easier; enterprise rooms usually need a quote for each deal. Our cost guide covers the pricing models, and our M&A sector page explains how a sell-side room is typically staged.
Choosing a room your firm can use across matters? Our quiz weighs team size, security needs and deal type.
Start the quizQuestions people ask
Can a law firm recharge data room costs to the client?
Usually yes, as a disbursement agreed in the engagement letter. Some firms instead hold an annual agreement and absorb the cost, which suits firms running many matters a year.
Does using a data room satisfy the SRA confidentiality duty?
It helps, but the duty is about how the firm handles client information overall. The room must be configured properly, with the right people in the right groups and access removed when the matter closes.
Who is the data controller when a firm runs a room for a client?
It depends on the arrangement, but the firm and client both have responsibilities for personal data in the room, and the provider will usually act as a processor under a written agreement. Take advice on the specific matter.
Is Cyber Essentials enough to cover the data room?
No. Cyber Essentials covers the firm's own IT. Ask the data room provider for its own certifications, such as ISO 27001 or SOC 2, and where it hosts data.
