How to structure a virtual data room for due diligence
Most data rooms are organised the way the seller's documents happen to be filed. The good ones are organised the way the buyer's questions arrive. Here is a structure that holds up.
Every firm we speak to knows email is the wrong tool for confidential documents. Far fewer can articulate exactly why — which makes the habit hard to break. Here are the five failures, named.
Ask a managing partner whether they would email a client's unredacted medical records to opposing counsel, and the answer is immediate and correct. Ask the same firm how last Tuesday's disclosure bundle went out, and the answer is frequently an attachment.
The gap between what firms know and what firms do is not carelessness. Email is right there, and the habit persists partly because the failure modes are rarely named. "It's not secure" is too vague to act on. So here they are, specifically.
This is the fundamental one, and everything else follows from it. An attachment is a copy. The moment it leaves your outbound mail server it exists on infrastructure you do not control, in a mailbox governed by someone else's retention policy, synced to a phone you have never seen, and possibly forwarded to a colleague you were never told about.
There is no recall. The "recall message" function works only inside your own organisation, and even then it announces the mistake. For a document sent to a counterparty it does nothing at all.
Compare this to the alternative posture: instead of transferring a copy, grant a right to view. The document stays where you put it. Access is a decision you keep making, and can stop making, rather than one you made irrevocably at 17:40 on a Friday.
The most common confidentiality incident at professional services firms is not a sophisticated attack. It is autocomplete. Two clients whose contact names begin with the same three letters, a hurried Tuesday, and a bundle of privileged material lands with the wrong recipient.
Training and delay-send rules help at the margins, but the design is the problem: email gives you one chance to get the address right and no way to correct it. A permission-based system fails differently — a misaddressed invitation produces an access request from someone you do not recognise, which is recoverable rather than a disclosure.
When a client asks whether the other side has seen the third schedule, most firms are guessing. Read receipts are unreliable, widely suppressed, and tell you only that a message was opened — not that a document was read, by whom, for how long, or how many times.
This matters beyond curiosity. When something goes wrong, the difference between "we believe only the deal team had it" and a timestamped access log is the difference between a difficult conversation and a defensible position.
Most corporate mail systems cap attachments somewhere between ten and thirty-five megabytes. A moderately sized bundle of scanned exhibits clears that on its own. A set of construction drawings is not close.
What happens next is the actual risk. People do not stop sending the documents; they route around the obstacle. A personal cloud account. A consumer file transfer service with a link that never expires. A USB stick in the post. A ZIP file split into four parts, with the password sent in a follow-up email — which, being in the same channel, protects against nothing.
Each workaround moves the document further outside the firm's control and its records system. The mail server's size limit did not prevent a risky transfer; it selected for the riskiest available one.
A firm may have an excellent retention schedule: litigation files destroyed seven years after matter close. That schedule governs the document management system. It does not govern the eleven mailboxes holding the same documents as attachments, the counterparty's mailbox, or the archive of an associate who left in 2021.
Under the storage limitation principle in Article 5(1)(e) of the GDPR, personal data must not be kept longer than necessary. A retention policy that reaches only your primary system while working copies live in eleven mailboxes is not a policy, it is an intention — and it surfaces again during every subject access request.
These are not five problems requiring five solutions. They are one architectural choice showing up in five places: email transfers copies, and copies cannot be governed.
Move to granting access instead of sending copies and the whole set resolves. Access can be revoked, so mistakes are recoverable. Invitations are addressed to a person rather than a string, so misdirection is visible. Every view is an event, so you know who read what. Size stops being relevant, because nothing traverses a mailbox. And when the matter closes, there is one place to apply the retention rule.
None of this requires the counterparty to adopt your software, install anything, or learn a system. They receive a link, they prove they are the person you invited, and they read the document. The experience is barely different from an attachment. The control position is not remotely the same.
The habit is worth breaking. Not because email is insecure in some abstract sense, but because for confidential documents it removes your ability to make decisions about your clients' material after the moment you press send — and that ability is, in the end, most of what professional confidentiality means in practice.
Written by Katrin Mägi, Co-founder & CEO at Vaultline. Vaultline provides encrypted document exchange and virtual data rooms to professional services firms across the European Union. See how the platform works, or talk to our team.
Most data rooms are organised the way the seller's documents happen to be filed. The good ones are organised the way the buyer's questions arrive. Here is a structure that holds up.
Everyone knows they should delete documents eventually. Almost nobody can say on what basis, on what trigger, or with what evidence. Here is how to build a schedule that holds up.
A log becomes a control when it is complete, attributable, immutable, accurately timed, retained long enough and actually reviewed. Most fail at two or three of these.
Talk to our team about a workspace for your firm, or start with a 14-day evaluation on the Team plan.