GDPR and virtual data rooms: what you need to know
On this page
- The short version
- Step 1: Confirm GDPR is in scope
- Step 2: Fix who is the controller and who is the processor
- Step 3: Sign the data processing agreement
- Step 4: Minimise the data before you share it
- Step 5: Record your lawful basis
- Step 6: Configure the room to meet Article 32
- Step 7: Be ready for data subject requests
- Step 8: Decide where the data is allowed to live
- Step 9: Set a deletion date, then hold the provider to it
- The 72-hour breach runbook
- Provider vetting checklist
This is a checklist, not an essay. A deal room holds the most sensitive files in a transaction: employee records, customer databases, salary schedules, shareholder registers, signed contracts.
Nearly all of it is personal data. That pulls the room inside the General Data Protection Regulation, and it turns compliance into a set of steps you work through before anyone is invited. Follow the sequence in order.
The short version
If you read nothing else, do these six things.
- Assume GDPR applies. If the data touches people in the EU or UK, it does.
- Sign an Article 28 data processing agreement before you upload anything.
- Minimise and pseudonymise the personal data first.
- Write down your lawful basis for showing it to bidders.
- Configure encryption, granular permissions, watermarking and audit logs.
- Set a hard deletion date for the day the deal closes or dies.
Step 1: Confirm GDPR is in scope
Check three things. Any single yes means the regulation applies.
- Does the target employ people in the EU or UK? Their HR files are personal data.
- Does it serve EU or UK customers? Client and prospect lists are personal data.
- Do the contracts, cap tables or diligence files name European individuals? That counts too.
Do not rely on your own location to opt out. Under Article 3, a US or Asian acquirer reviewing a European target is bound by GDPR through its extraterritorial scope. The trigger is the data, not the buyer’s head office.
One thing to flag early. Granting a bidder access to a folder of personal data is itself a disclosure, and that disclosure needs a lawful basis. You document it in Step 4.
Step 2: Fix who is the controller and who is the processor
Assign the roles on paper before you open the room. Get this wrong and it is painful to fix after an audit; it is trivial to fix now.
- You are the controller. You decide why and how the data is processed, and you carry primary accountability to the regulator.
- Your VDR vendor is the processor. It handles data only on your documented instructions.
- Each bidder becomes a separate controller once it receives personal data for its own assessment.
Because bidders become controllers in their own right, set out each party’s data protection duties in the process letter or NDA. Muddled roles are a common audit finding.
Keep two numbers in view as you set up. They define the downside.
A qualifying breach must be reported to the supervisory authority within 72 hours. Fines reach 20 million euros or 4% of global annual turnover, whichever is higher.
The fines are not theoretical. European regulators had issued more than 5.88 billion euros in GDPR penalties by early 2025, according to the CMS GDPR Enforcement Tracker, and inadequate security under Article 32 is a recurring cause.
A leaky deal room is exactly the kind of failure that draws enforcement.
Step 3: Sign the data processing agreement
Do this before a single file goes up. An Article 28 data processing agreement is the contract that makes your use of a provider lawful. Without it you are in breach the moment personal data enters the room, however strong the encryption.
Ask the provider for its DPA and subprocessor list up front. Then check the agreement locks down every item on this list.
- Subject matter, duration, nature and purpose of the processing.
- A commitment to process only on your documented instructions.
- Confidentiality obligations on everyone who touches the data.
- The Article 32 security measures the provider will maintain.
- Rules for engaging subprocessors, with notice and your right to object.
- Deletion or return of all data when the engagement ends.
Watch for three traps. A generic terms-of-service page is not a substitute for a signed DPA. Undisclosed subprocessors can quietly undermine your transfer position. And vague deletion language usually leaves backup copies untouched.
A vendor that cannot produce a DPA and a subprocessor list quickly is one you should not trust with a folder of employee records. The provider reviews for iDeals, Datasite and Ansarada note where each vendor publishes these documents.
Step 4: Minimise the data before you share it
Do not upload everything you have. The data minimisation principle in Article 5 says you share only what diligence needs. Work through the sensitive categories and cut or mask before you upload.
- Sort the index. Separate ordinary personal data (names, job titles, salaries) from special category data.
- Flag special category files. Health records in insurance folders and trade union membership in HR disputes carry stricter conditions under Article 9. They need an explicit Article 9 condition, not just a lawful basis under Article 6.
- Redact or pseudonymise for early-stage diligence.
- Reveal full detail only to a confirmed buyer, under stricter access.
Use this map to spot what is hiding in a typical index and how sensitive it is.
| Data category | Where it usually sits | GDPR sensitivity |
|---|---|---|
| Employee records, payroll, contracts | HR / people folder | Standard, high volume |
| Customer and prospect lists | Commercial / sales folder | Standard, often large |
| Shareholder and cap table details | Corporate / legal folder | Standard |
| Health, disability or grievance files | HR disputes / insurance | Special category (Art. 9) |
| Litigation and background checks | Legal / risk folder | Sensitive, sometimes special category |
If you run life sciences deals or anything in financial services, treat redaction as the default, not a nice-to-have.
Step 5: Record your lawful basis
Write it down while the reasoning is fresh, because a regulator can ask for it later.
- Pick the basis. For disclosure to bidders it is usually legitimate interest under Article 6.
- Run a balancing test. Weigh your interest in doing the deal against the rights of the people in the files.
- Save the assessment. Keep the document where you can produce it on request.
- For special category files, name the separate Article 9 condition you are relying on.
The five articles below do most of the work in a transaction. Your provider contract and your room configuration are judged against them.
| Article | What it requires | What it means for your room |
|---|---|---|
| Art. 5 | Data minimisation, purpose limitation, storage limits | Share only what diligence needs; set retention and deletion |
| Art. 6 / Art. 9 | A lawful basis, plus a condition for special data | Document legitimate interest; handle HR health files with care |
| Art. 28 | A written controller-to-processor contract | Signed DPA before go-live |
| Art. 32 | Security appropriate to the risk | Encryption, access control, watermarking, audit logs |
| Art. 33 | Breach notification within 72 hours | Provider alerts you fast; you alert the regulator |
Article references follow the EU GDPR. The UK GDPR mirrors them almost word for word. Confirm specifics with your counsel.
Step 6: Configure the room to meet Article 32
Article 32 is the one your technology answers directly. It is deliberately outcome-based: the law asks for security “appropriate to the risk” rather than a fixed checklist.
For a room holding thousands of personal records under a live deal, that bar is high.
Taking into account the state of the art […] the controller and the processor shall implement appropriate technical and organisational measures […] including […] the pseudonymisation and encryption of personal data.
Article 32(1), EU GDPR
The full text of Article 32 names encryption, resilience and regular testing as expected measures. That is precisely the feature set a purpose-built data room ships with and a shared drive does not.
Turn each of these on before anyone is invited.
- Encryption in transit and at rest. Non-negotiable. A generic drive may cover this; email attachments do not.
- Document-level access control. Grant by group and folder, not by handing over the whole room.
- Dynamic watermarking and view-only rendering. Deter copying and trace leaks back to a user.
- Two-factor authentication. Close the easiest door an attacker uses.
- Instant access revocation. Cut off a bidder in seconds when a stage ends.
- Configurable data residency. Pin hosting to a region so cross-border transfers stay in check.
- A complete audit trail. Log who viewed, downloaded or printed each file.
The audit trail earns a line of its own. Article 5(2) makes the controller responsible for demonstrating compliance, and a complete log is the single best evidence you can hold. Email and generic drives cannot produce it.
The audit trails explained and data room permissions guides cover the mechanics. The iDeals vs Datasite comparison lines up two of the deeper platforms on these features.
Run the whole sequence in one pass with the checklist below.
How to run a GDPR-compliant virtual data room
The core steps that keep a deal room defensible under GDPR.
Estimated time: 2h
-
Sign the data processing agreement
Execute an Article 28 DPA with your provider before uploading anything, covering subprocessors, security measures and deletion on termination.
-
Minimise and pseudonymise
Redact or pseudonymise personal data in early diligence, and reveal full detail only to a confirmed buyer under stricter access.
-
Set a lawful basis and record it
Document your legitimate interest assessment for disclosing personal data to bidders, and handle special category files under an Article 9 condition.
-
Lock down permissions and security
Grant folder-level access by group, turn on watermarking, view-only rendering, two-factor authentication and encryption before inviting anyone.
-
Plan retention and deletion
Agree how long the room stays open and get written confirmation the provider deletes all copies, including backups, when the deal closes or breaks.
-
Prepare your breach playbook
Know who alerts whom, so you can meet the 72-hour notification deadline if the provider reports an incident to you.
Step 7: Be ready for data subject requests
The people whose data sits in the room keep their GDPR rights throughout the deal, and you generally have one month to respond.
Build the room so these requests are answerable, not a scramble. Handle each type as follows.
- Access (Art. 15). The person can ask for a copy of their data and how it is used. Be able to locate and export their records fast.
- Erasure (Art. 17). They can ask for deletion where there is no overriding basis. Make sure deletion reaches the room and its backups.
- Objection (Art. 21). They can object to processing based on legitimate interest. Your balancing test from Step 5 has to withstand the challenge.
- Rectification (Art. 16). They can ask you to correct inaccurate data. Keep superseded versions traceable, not silently overwritten.
Rights are not absolute. Some are qualified during due diligence, so confirm any response with counsel.
The underlying point is simple. If you cannot say who holds a copy of a document, you cannot credibly answer an access or erasure request. Granular permissions and a searchable index matter for compliance as much as for control.
Step 8: Decide where the data is allowed to live
Keep it in the EU or EEA if you can, or in a jurisdiction covered by an adequacy decision.
GDPR restricts transfers outside the EEA unless the destination offers essentially equivalent protection, so hosting location is a compliance decision, not just a performance one. Work through it in order.
- Ask the provider where the room and its backups are hosted.
- If everything sits in the EEA, you are done; there is no transfer to solve.
- If any data lands in the United States, put a valid transfer mechanism in place before it leaves Europe.
Two mechanisms matter in practice.
- An adequacy decision. The EU-US Data Privacy Framework covers certified US organisations.
- Standard Contractual Clauses, backed by a transfer risk assessment.
Get this wrong and the exposure is real. In 2023 the Irish regulator fined Meta 1.2 billion euros for unlawful transfers to the US, the largest GDPR penalty on record at the time.
The European Data Protection Board publishes the current guidance on international transfers. Read it before you pick a region.
Many enterprise-grade providers, including options such as Ellty, let you pin hosting to an EU region, which removes the transfer question for European deals. The data residency guide and the data residency glossary entry explain how to check and lock a region.
One more wrinkle. Brexit gave the UK its own UK GDPR, which mirrors the EU regulation almost article for article and is enforced by the Information Commissioner’s Office. A deal touching both UK and EU data subjects can answer to two regimes at once.
The EU currently grants the UK an adequacy decision, keeping EU-to-UK flows unrestricted, but that decision is reviewed periodically and is not permanent. For cross-border deals, host in the EEA and treat UK GDPR as a parallel obligation.
Step 9: Set a deletion date, then hold the provider to it
Do not leave the room open indefinitely. The storage limitation principle in Article 5(1)(e) says you keep personal data no longer than necessary for the purpose, and once a deal closes or collapses, the diligence purpose is spent.
A room full of employee and customer records left open for months is processing without a purpose. That turns a minor breach into an expensive one.
Close it out cleanly.
- Agree the retention window inside the DPA.
- Trigger deletion the moment the deal closes or dies.
- Get written confirmation that deletion covers live files, exports and backups.
That written confirmation separates a defensible close-out from a liability sitting on someone’s server. If you reuse the platform across deals, the guide on migrating to a new data room covers clean hand-offs without leaving orphaned copies behind.
The 72-hour breach runbook
Decide who does what before anything goes wrong. Under Article 33, once you become aware of a personal data breach likely to risk people’s rights, you have 72 hours to notify the relevant supervisory authority. You may also have to tell the affected individuals under Article 34.
As the controller, that duty sits with you even if the failure happened on the provider’s infrastructure. That is why your DPA must require the provider to alert you without undue delay.
When an incident lands, work the runbook.
- Contain. Revoke access to the affected files immediately.
- Scope. Pull the audit trail and establish who saw which file, and when.
- Assess. Judge the risk to individuals’ rights and freedoms.
- Notify. Report to the supervisory authority inside 72 hours if the threshold is met.
- Tell the people. Notify affected individuals under Article 34 where the risk is high.
- Document. Record the incident and your decisions, whether or not you notify.
This is where a real data room earns its cost. Because every action is logged and access can be revoked instantly, you can scope an incident precisely and cut off exposure in seconds.
The UK regulator’s breach reporting guidance sets out what a notification must contain.
Provider vetting checklist
Ask hard questions before you commit, and get the answers in writing. A confident provider will have all of this ready. Evasiveness is itself a red flag.
Focus on five areas.
- Hosting and residency: can you choose an EU or EEA region, and where are backups stored?
- Certifications: does it hold current SOC 2 Type II and ISO 27001, and will it share the reports?
- Subprocessors: is there a public, current list, and how are you notified of changes?
- Deletion guarantees: does deletion cover backups, and how long does it take?
- Breach process: what is the committed notification window to you, and what does the alert include?
For the controls behind these questions, the VDR security features checklist and the certifications explained guide cover the fundamentals.
The ranked list for M&A filters providers for these criteria, and you can weigh certifications, hosting and pricing side by side on the pricing page.
Frequently asked questions
Does GDPR apply if my company is based outside the EU?
It can. GDPR has extraterritorial reach under Article 3, so if the personal data in your data room relates to people in the EU or UK, or if you are acquiring a European business, the regulation applies regardless of where your own company sits. Handling the room as if GDPR is in scope is the safe default for any cross-border deal.
Is a signed data processing agreement really mandatory?
Yes. Article 28 requires a written contract between the controller and any processor before personal data is processed. A provider's standard terms of service usually do not meet the requirement on their own, so ask for a dedicated DPA and check it covers security, subprocessors and deletion. Uploading personal data without one puts you in breach.
Can I store deal documents in a US-hosted data room?
Sometimes, but only with a valid transfer mechanism. That means the provider is certified under the EU-US Data Privacy Framework, or you rely on Standard Contractual Clauses supported by a transfer risk assessment. Where possible, choosing an EU-hosted region avoids the international transfer question altogether.
Who is liable if the VDR vendor causes a breach?
As the controller, you remain accountable to the regulator and to affected individuals, which is why your DPA should require the provider to notify you without undue delay so you can meet the 72-hour deadline. Processors can also face direct liability under GDPR, but that does not remove your own obligations.
Fix the roles, sign the contract, minimise the data, configure Article 32 controls, keep the audit trail close, and set a firm deletion date.
Handled that way, GDPR turns your data room from a convenience into a control, and your best evidence of compliance.