Growth & Capital Explained · UK · 2026

Preparing a Data Room: A Guide for UK Companies

An educational guide to what a data room is, the categories of documents companies typically organise for due diligence, and the data protection rules that apply when that information is shared.

Educational guide United Kingdom By SSV Alliance ~7 min read

This article is intended for business founders, company directors, investors and professional market participants.

In one line

A data room is an organised store of a company’s key documents, and preparing one well in advance is one of the most practical ways a company can support a smoother due diligence process.

Key takeaways
  • A data room is an organised repository — usually virtual — of the documents reviewed during due diligence.
  • Documents typically fall into five categories: corporate and governance, financial, legal, commercial, and team.
  • Articles of association and shareholders’ agreements are different documents — the former is a public statutory requirement, the latter a private optional contract.
  • Confidentiality is usually agreed first, commonly through an NDA and, where relevant, non-binding heads of terms, before sensitive access is opened.
  • Where personal data is involved, UK GDPR and the Data Protection Act 2018 govern how it is stored, accessed, and shared.
  • Access is generally controlled, using permissions, redaction, and audit logging rather than open, unrestricted sharing.
  • Preparing a data room early, as part of ongoing governance, is generally more manageable than assembling one under time pressure.
A secure virtual data room dashboard showing due diligence document categories and review progress

What a Data Room Is, and Why It Matters

A data room is an organised repository of the documents a company makes available to prospective investors, their advisers, or other professional counterparties during a due diligence process. Historically a physical room of paper files, today it is almost always a permissioned virtual folder structure that allows controlled, trackable access to sensitive information.

Its purpose is straightforward: due diligence involves reviewing a company across financial, legal, commercial, and operational dimensions, and a well-organised data room allows that review to happen efficiently, with a clear record of what was shared, with whom, and when.

Worth knowing

A data room is a tool for organisation and disclosure, not a marketing document. It should present accurate, verifiable information rather than promotional claims — the two serve different purposes in a company’s engagement with prospective investors.

The Document Categories Companies Typically Prepare

While the exact scope of a data room varies with company stage and the nature of the process, the documents generally fall into a consistent set of categories.

1

Corporate & governance

Articles of association, statutory registers, cap table, board minutes, and incorporation documents.

2

Financial

Historical accounts, management information, tax records, and the basis for any forward-looking assumptions.

3

Legal

Material contracts, leases, employment agreements, and intellectual property documentation.

4

Commercial & team

Market and customer evidence, organisational structure, and key personnel information.

An organised data room does not make a company more investable. It simply lets due diligence focus on substance rather than paperwork.

Corporate and Governance Documents, in Detail

Two documents are frequently confused, and a data room usually needs to distinguish them clearly.

DocumentNature
Articles of associationA statutory document every UK company must have on incorporation. It is filed publicly at Companies House and sets out the company’s internal rules.
Shareholders’ agreementAn optional, private contract between shareholders that is not filed publicly. It typically covers matters the articles do not, such as share transfer restrictions and reserved matters.
Statutory registersRecords such as the register of members and register of directors, which companies are required to maintain.
Cap tableA record of share ownership and how it may change under existing option or convertible instruments.
Confirmation statement (CS01)An annual filing confirming the company’s registered details, including its People with Significant Control (PSC), directors, and registered office, are correct and up to date.
PSC registerA record of individuals or entities holding significant control over the company, such as those owning more than 25% of shares or voting rights.

Because articles of association are already public via Companies House, and a shareholders’ agreement is private, a data room typically includes both so that a reviewer can see the complete governance picture in one place rather than piecing it together from separate sources.

UK company registers have also been evolving. Companies House guidance confirms that companies are moving toward maintaining certain statutory records, including the PSC register, centrally at Companies House rather than solely at the company’s own registered office, alongside wider reforms such as identity verification requirements for directors and PSCs. Because these requirements have changed in recent years and continue to develop, companies generally confirm the current position directly on gov.uk rather than relying on older summaries.

Confidentiality Before Due Diligence Begins

Before a company shares sensitive information, it is common practice for the parties to put a confidentiality arrangement in place first. A non-disclosure agreement (NDA) typically sets out what counts as confidential information, how it may be used, how long the obligations last, and what happens to the information once discussions end. This is generally regarded as good practice before opening data room access, not only once a due diligence process is well underway.

Separately, many capital raising discussions are preceded by heads of terms — a short document summarising the proposed commercial terms. Heads of terms are generally expressed to be “subject to contract” and non-binding in respect of the commercial terms themselves, although specific provisions such as confidentiality, costs, and governing law are often expressed to be binding. Their purpose is to record a shared understanding before the more detailed work of due diligence and legal documentation begins.

Worth knowing

Neither an NDA nor heads of terms are unique to any particular sector or type of transaction — they are standard features of confidential commercial discussions generally, and companies commonly take legal advice on their specific wording.

Data Protection: What Applies When Personal Data Is Involved

Data rooms often contain personal data — for example, in employment records, cap table details, or customer information. Where that is the case, UK GDPR and the Data Protection Act 2018 apply to how the data is stored, accessed, and shared, in the same way they would apply to any other transfer of personal data.

The Information Commissioner’s Office (ICO) sets out general expectations for due diligence involving personal data: organisations should consider the lawful basis for sharing, keep the disclosure proportionate to what the review genuinely requires, document the exercise, and use appropriately secure methods of transfer rather than, for example, unencrypted email.

Why this matters for founders

Data protection obligations sit alongside, not instead of, commercial and legal preparation. Redacting or limiting personal data to what is genuinely needed for a given stage of review is common practice, and companies with staff, customer, or supplier personal data in their records often take advice on this specifically.

How a Data Room Is Typically Organised

Modern data rooms are generally organised as a permissioned virtual folder structure, often mirroring the document categories described above, with a clear index and consistent file naming so reviewers can find what they need without repeatedly asking where something is. Well-organised data rooms commonly include a short introductory note explaining what has already been uploaded, what is still to follow, and a single agreed channel through which reviewers should raise questions — reducing the risk of the same query being answered inconsistently in different places.

Access is usually controlled rather than open: different recipients may see different sections depending on the stage of the process and their role, and it is common for platforms to apply document-level permissions, restrict downloading or printing of sensitive files, and log access activity to support a clear audit trail. Where documents contain sensitive commercial or personal information that is not relevant to every reviewer, companies often redact those specific details rather than withholding the document entirely.

Reviewers can include prospective investors themselves, alongside their legal, financial, and technical advisers, and — depending on the nature of the process — other professional counterparties. Structuring access this way helps ensure that sensitive information is seen only by those who need it, consistent with the data protection principles described in the previous section.

When to Start Preparing

A recurring theme in how companies describe their own due diligence experience is that documentation prepared in advance, as part of ongoing governance, tends to be far less disruptive than documentation assembled under deadline pressure once a specific process begins.

Many companies treat data room preparation as a continuous discipline: statutory registers kept current, contracts filed as they are signed, and financial records reconciled on a regular cycle, rather than a one-off exercise triggered by an approaching engagement with prospective investors.

Frequently Asked Questions

What is a data room?

An organised repository, usually virtual, of the documents a prospective investor or acquirer will want to review during due diligence. It typically covers corporate, financial, legal, commercial, and technical documentation, structured so reviewers can find what they need efficiently.

What documents typically go in a data room?

Common categories include corporate and governance records, financial records, legal agreements, commercial evidence, and team information. The exact contents vary with company stage and the nature of the process.

What is the difference between articles of association and a shareholders’ agreement?

Articles of association are a statutory document every UK company must have, filed publicly at Companies House. A shareholders’ agreement is a separate, optional, private contract between shareholders that is not filed publicly. Many companies hold both, and a data room typically includes each.

What is a non-disclosure agreement and when is it used?

A non-disclosure agreement (NDA) is a confidentiality arrangement that sets out what information is confidential, how it may be used, and how long the obligations last. It is common practice to put an NDA in place before sharing sensitive information, including before opening access to a data room.

Do data protection rules apply to a data room?

Yes. Where a data room contains personal data, UK GDPR and the Data Protection Act 2018 apply to how it is stored, accessed, and shared. Organisations sharing personal data as part of due diligence are generally expected to consider their lawful basis for sharing, document the exercise, and use appropriately secure methods of transfer.

When should a company start preparing a data room?

Many companies begin organising core documents well before any due diligence process starts, rather than assembling them under time pressure once a diligence request arrives. Maintaining an up-to-date data room as part of ongoing governance is common practice among well-prepared companies.

Who typically reviews a data room?

Reviewers can include prospective investors, their legal and financial advisers, and, depending on the transaction, other professional counterparties. Access is generally controlled and permissioned rather than open to all recipients.

How is access to a data room typically controlled?

Common controls include document-level permissions so different recipients see different sections, restrictions on downloading or printing sensitive files, redaction of information not relevant to a particular reviewer, and audit logging of who accessed what and when.

References

Institute of Directors. What are Articles of Association? Available at: iod.com

Information Commissioner’s Office. Due diligence when sharing data following mergers and acquisitions. Available at: ico.org.uk

Information Commissioner’s Office. Sharing personal data in databases and lists. Available at: ico.org.uk

Companies House. Guidance on company registers and statutory records. Available at: gov.uk

GOV.UK. Filing your company’s confirmation statement. Available at: gov.uk

LexisNexis. Heads of terms — equity (non-leveraged investment) checklist. Available at: lexisnexis.co.uk

Important information

Educational content, not advice. This article explains, in general terms, what a data room is and the categories of documentation UK companies typically prepare for due diligence. It is provided for information and education only and does not constitute legal, tax, regulatory, financial, or investment advice. Readers should take advice from appropriately qualified and, where relevant, FCA-authorised professionals on their own circumstances.

No offer or invitation. This communication does not constitute an offer or invitation to engage in investment activity, and does not relate to any specific company, security, or transaction.

Rules and requirements change. Statutory and data protection requirements referred to in general terms in this article are set by legislation and regulatory guidance and may change over time. Readers should confirm current requirements from official sources, including gov.uk and ico.org.uk.

About SSV Alliance. SSV Alliance Limited (FRN 1038330) is an Appointed Representative of Schmidt Research Partners Ltd (FRN 452684), which is authorised and regulated by the Financial Conduct Authority. SSV Alliance does not act as principal, and any regulated activities are undertaken under the supervision and authority of its Principal. Our activities include corporate advisory, transaction support and investor engagement activities undertaken within a regulated framework where required.

Keep learning with SSV Alliance

Our educational guides explain, in plain English, how UK companies grow, prepare, and navigate the corporate finance ecosystem — no jargon, no sales pitch.

Explore the educational guide series