How to structure a virtual data room for due diligence

Most data rooms are organised the way the seller's documents happen to be filed. The good ones are organised the way the buyer's questions arrive. Here is a structure that holds up.

A data room has one job: let a buyer's advisers answer their diligence questions quickly, without giving away more than the seller intends at any given stage. Most rooms fail at this not because of anything technical, but because they are organised around the seller's filing habits rather than the buyer's request list.

Here is a structure that consistently works, drawn from watching several hundred processes run.

Start from the request list, not the file server

Before creating a single folder, get the buy-side diligence request list — or a standard one from your advisers. Your top-level folders should map onto the workstreams that list is divided into, because those are the teams who will be reading.

A structure that reliably works:

  • 01 Corporate — constitutional documents, share registers, group structure, board minutes, prior transactions.
  • 02 Financial — statutory and management accounts, budgets, audit correspondence, tax filings.
  • 03 Commercial — customer and supplier contracts, standard terms, top-customer analysis.
  • 04 Employment — organisation chart, standard and senior contracts, benefits, pensions.
  • 05 Intellectual property and IT — registrations, licences in and out, key systems.
  • 06 Property — titles, leases, licences, dilapidations.
  • 07 Litigation — current, threatened and recently settled.
  • 08 Compliance and data protection — policies, records of processing, incident history.
  • 09 Insurance — policies and claims history.
  • 10 Environmental and health & safety — where relevant.

Ten top-level folders is about the limit. Beyond that, reviewers stop navigating and start searching, which means your structure has stopped doing any work.

Number everything, and never renumber

Every document gets a number on upload: 02.03.014. That number appears in the index, in Q&A responses, in the disclosure letter, and eventually in the completion bible. It must never change.

This is the single most common data room failure. Someone reorganises folder 04 in week three, everything renumbers, and every reference in every Q&A thread and draft disclosure letter is now wrong. Hours disappear into reconciliation, and confidence in the room drops for the rest of the process.

The discipline is simple: numbers are allocated once and are permanent. A withdrawn document has its number retired, not reused. A replaced document is uploaded as a new version under the same number, with the superseded version retained and visible — reviewers need to see that draft 4 replaced draft 3.

Name files so the index is readable without opening anything

A reviewer scanning two hundred rows should be able to tell what each document is. Adopt a convention and enforce it on upload:

02.03.014 — Management accounts — FY2025 Q3 — 2025-10-14

Number, type, subject or period, date. Dates in ISO format so they sort. No codenames, no FINAL_v3_updated_JB.pdf. Explanation belongs in the index note field, not the filename.

Stage the disclosure in tiers

Not everything should be visible to everyone from day one, and a room that forces that choice pushes sellers into withholding material entirely. Three tiers cover almost every process:

  • Tier 1 — open on admission. What a serious bidder needs for an indicative offer: corporate structure, historic financials, commercial overview.
  • Tier 2 — released on shortlisting. Named customer contracts, detailed employment terms, IP schedules, released per bidder.
  • Tier 3 — clean team or final bidder only. Pricing by customer, margin analysis, litigation strategy. Often view-only, watermarked, no download.

Set these tiers up as permission groups at the outset. Promoting a bidder should be one action, not an afternoon of per-folder permission editing — that is where mistakes get made.

Redact before upload, never after

Redact properly — flattened, underlying text removed, not a black rectangle over live text — and upload only the redacted version. Never upload the unredacted document intending to restrict access to it. Permissions are a control, not a substitute for keeping material out of the room.

Keep the unredacted originals outside the room, in your own files, with a note of which number they correspond to.

Run Q&A inside the room, threaded to documents

Questions arriving by email defeat the entire structure. They lose their link to the document, they are answered inconsistently by whoever picks them up, and at completion nobody can reconstruct what was actually said.

Q&A should sit in the room, attached to the document number it concerns, with a defined workflow: submitted by a named bidder, routed to a subject-matter owner, reviewed by counsel, then published. Decide at the outset whether answers are visible to all bidders or only the asker — both are defensible, but changing the rule mid-process is not.

Plan the close from the first day

At completion, both sides need a permanent record of exactly what was disclosed. A room that can produce a sealed archive — every document at its final version, the complete index, the full Q&A history and the access log — turns a week of bundle preparation into an afternoon.

Set the room's retention rule when you create it rather than when you close it. The seller's obligation to retain disclosure material typically runs to the limitation period under the warranties — a decision to make with counsel on day one.

The short version

Structure by workstream. Number permanently. Name descriptively. Tier the disclosure. Redact before upload. Thread the Q&A. Plan the archive. None of it is complicated — it is just easier to do at the start than to retrofit in week six, when forty reviewers are already working in the room.


Written by Marek Duda, VP Customer Success at Vaultline. Vaultline provides encrypted document exchange and virtual data rooms to professional services firms across the European Union. See how the platform works, or talk to our team.

Related reading

Ready to stop sending attachments?

Talk to our team about a workspace for your firm, or start with a 14-day evaluation on the Team plan.