A data room index is the numbered list of folders and sub-folders that tells both sides what the room contains and where to find it. For a UK M&A deal, the index also determines the order in which documents are reviewed, the permissions granted at each phase and, if the disclosure letter refers to it, its legal weight.

What a data room index is and why it matters for UK deals

The index is not the room. It is a structured list of every folder and document the room contains, numbered so that both sides can reference items by number rather than by description, and kept stable once buyers have access. A reference in a question log or an adviser's report that says “see item 4.3.2” becomes meaningless the moment that item is renamed or moved.

For UK deals it matters more than it might appear. If the sale and purchase agreement treats the data room as part of the disclosure exercise, the index is, in effect, a list of what has been fairly disclosed. A document that is uploaded but does not appear in the index, or that sits in the wrong folder, may not constitute fair disclosure under the SPA. Agree the disclosure mechanism with your solicitors before you open the room.

The index also controls speed. On a competitive process, multiple bidder teams may be working simultaneously. A clear, numbered index is the difference between diligence running in three weeks and diligence running in six. Most buy-side advisers work from a template diligence request list, and those templates are organised by workstream. If your index matches their workstream headings, questions about missing documents drop to nearly zero.

For choosing a platform that supports proper index management, the scored league table of UK data room providers sets out which ones combine granular permissions, stable folder structures and exportable audit logs.

A worked example

Thornbrook Engineering Ltd, a Sheffield-based precision manufacturer with revenue of around fourteen million pounds and fifty-three employees, received three binding offers in September 2025. The sell-side solicitors had set up a data room two weeks earlier and loaded documents into folders named roughly after the eleven due diligence workstreams. By the time the first binding offer arrived, the buyer advisers were raising questions that had already been answered in the room. The folder names did not match the structure those advisers were working from, and the index had never been shared.

The fix was straightforward once the problem was identified: share the index on day one, number the folders to match the buyer's request list, and fix the structure before bidders enter. Thornbrook's deal completed, but a fortnight was lost to avoidable back-and-forth.

Those two weeks of remediation also revealed a gap that is common on UK deals. TUPE employee liability information had not been gathered, because the transaction was originally structured as a share sale and the team had not considered an asset sale scenario. Once the index was built with a dedicated Employment folder that flagged both documents, the solicitors were able to confirm which items would be needed in a change of structure and load them in advance. The UK M&A data room checklist covers the full document set that goes into each workstream.

A further issue Thornbrook encountered was permissions. The detailed employment schedule, including individually identifiable salaries and notice periods, had been made visible to all three bidders from day one. That is both a commercial risk (a bidder may be a trade competitor) and a data protection question under UK GDPR. The right approach is staged release: anonymised numbers in phase one, identifiable terms to a shortlisted buyer in phase two.

Standard folder structure for UK M&A

The standard structure for a UK M&A data room runs twelve top-level folders, numbered and named to match the workstreams a buyer's adviser will recognise. Within each top-level folder, use sub-folders sparingly. Three levels is usually enough; deeper hierarchies make documents harder to find, not easier. Number the folders from the outset and do not renumber once bidders are inside. The following descriptions summarise what belongs in each workstream.

01. Financial. Statutory accounts for the last three financial years, management accounts to the most recent month end, current budget and forecast, detailed trial balance, aged debtor and creditor listings, and bank facilities. The financial workstream is almost always the one buyers open first, so completeness here saves time everywhere else.

02. Legal and Corporate.Certificate of incorporation, any name change certificates, current articles of association, statutory registers (members, directors, PSC, charges), board and shareholder minutes for the last three to six years, the Companies House filing history reconciled against the registers, and any shareholders' agreement or side letters.

03. Commercial. Contracts with the largest customers by revenue (typically the top ten to twenty), key supplier agreements, and distribution or agency arrangements. A separate sub-folder for any contract containing a change of control provision is worth creating before the room opens: buyers will find them eventually, and finding them in a labelled folder is better than finding them in a bundle.

04. Employees and HR.Anonymised employee list with role, start date, salary band, notice period and location; standard employment contracts; directors' service agreements; the employee handbook and policies; IR35 determinations for contractors; and any live or threatened employment tribunal claims. TUPE employee liability information belongs here and is specific to UK transactions.

05. Assets and Property. Land Registry official copies for freeholds, leases and licences to occupy, schedules of condition, dilapidations correspondence, energy performance certificates, asbestos surveys and fire risk assessments.

06. Regulatory and Compliance. Licences and permits required to operate, FCA or PRA permissions for any regulated entity, and documentation of whether the transaction triggers a mandatory notification under the National Security and Investment Act 2021. The NSI Act covers seventeen sensitive sectors and the notification obligation falls on the buyer, but sellers are expected to have considered it.

07. Environmental. Environmental permits, monitoring records and results, Phase I and Phase II site reports where relevant, and any historic remediation correspondence.

08. Tax. Corporation tax computations and returns for the last three years, VAT returns, PAYE compliance history, any HMRC correspondence including open enquiries, and EMI scheme valuations and notifications where applicable.

09. Insurance. Current policies, schedules and claims history, pension arrangements including auto-enrolment compliance, and details of any warranty and indemnity insurance under consideration.

10. Technology and IP. Registered trade marks, patents and designs with renewal dates, domain name registrations, IP assignments from employees and contractors, software licences, SaaS subscriptions and any open source usage disclosures.

11. Customer Contracts. Where the top customer contracts are too numerous to sit comfortably in the Commercial folder, a dedicated folder with one sub-folder per major customer allows buyers to work through them without loading the main commercial bundle.

12. Conditions Precedent. Once the deal reaches heads of terms, a CP tracker and the outstanding items sit here. Many sell-side teams add this folder later in the process rather than at the outset, which is fine provided the numbering is reserved from the start.

UK-specific documents that change the index

Generic data room templates written for a European or US audience routinely omit the items that are specific to English and Scottish law. These are not edge cases: they arise on the majority of UK private company transactions and their absence is visible to any experienced buy-side adviser.

TUPE employee liability information. On an asset purchase, the Transfer of Undertakings (Protection of Employment) Regulations 2006 require the transferor to provide employee liability information to the transferee. This is a specific statutory document, not just the general employment schedule. If the transaction might be restructured as an asset sale (as many share sale negotiations are), the information should be gathered early. See the complete guide to what should be in a UK data room for the full employment workstream.

Land Registry official copies.English and Welsh property title documents are issued by HM Land Registry as official copies, not as historic title deeds. Scottish properties require a different set of extracts from the Registers of Scotland. Make sure the folder contains the current official copy rather than a historic deed: they are not the same thing and a buyer's solicitor will ask for both if there is any doubt.

Companies House filing history.Every UK company has a public filing history at Companies House, and a buyer's solicitor will check it independently. Including a printed or exported copy in the data room, alongside confirmation that it reconciles with the statutory registers, removes a common question and demonstrates that the seller has done the work in advance.

NSI Act screening documentation.The National Security and Investment Act 2021 introduced mandatory notification for acquisitions in seventeen sensitive sectors, with retrospective unwinding of uncleaned deals. The obligation falls on the acquirer, but a seller that has considered the question and documented it speeds the process considerably. Include a brief note in the Regulatory folder setting out whether the target's activities engage any of the seventeen sectors.

Cyber Essentials certificate. Where the buyer is a UK public sector body or a regulated firm with supply chain requirements, the seller may need to demonstrate its own Cyber Essentials or Cyber Essentials Plus certification as a condition of continuing as a supplier post-acquisition. If the company holds the certification, include it. If it does not, note the absence and be prepared for the buyer to raise it.

Permissions and access control by buyer phase

On a competitive process, not every document should be visible to every bidder at every stage. Staged release is standard practice on UK M&A transactions and it requires the index to be built with phases in mind from the outset.

Phase one (indicative bids, all bidders). Corporate and constitutional documents, financial accounts and management information, a commercial overview and the non-sensitive customer summary, and a high-level property and assets schedule. The goal is to give bidders enough to form a view on price and structure without exposing commercially sensitive operational detail to parties who may not proceed.

Phase two (binding bids, shortlisted buyers). Detailed customer contracts (including change of control provisions), the full employment schedule with individually identifiable terms, live and threatened litigation, detailed tax history and any HMRC correspondence. These categories are sensitive for commercial reasons (contracts) or data protection reasons (employee data) and should not be released until exclusivity or a shortlist is in place.

Phase three (preferred bidder).Conditions precedent documents, sensitive IP assignments, and any items flagged by the buyer's solicitors as outstanding from their request list. This phase is often managed as a running update rather than a single release.

Set permissions at the folder level in the data room rather than per document, because per-document permissioning under time pressure is where mistakes happen. A folder that does not exist for a given user group is more reliable than a folder that exists but has a document visible when it should not be. Consult the UK data residency and restricted transfer guidance if any bidder is based outside the UK, because granting overseas access to a UK-hosted room is itself a restricted transfer under UK GDPR.

Best tool for UK M&A deal rooms: Papermark

For UK M&A deals that need clear access analytics, staged folder release and an audit trail that satisfies solicitor requirements, Papermark is the strongest self-serve option on this assessment. It is best for teams running their own sell-side process without a dedicated project manager from the provider.

The platform is EU-hosted by default in Frankfurt, with SOC 2 Type II and ISO 27001 certification and a signable data processing agreement covering the GDPR regime that also applies to UK buyers under UK adequacy. Pricing is published on their website with no sales call required: the Data Rooms plan at EUR 99 per month includes three team members, unlimited data rooms, granular folder and user group permissions, dynamic watermarking and an append-only audit log. Pricing is in euros only, with no sterling option, so UK buyers carry the currency conversion risk. Enterprise plans add managed UK-resident hosting through region selection.

The permissions model supports exactly the staged release structure described above. Folders can be assigned to named user groups, so a phase-two folder is simply not visible to a phase-one group rather than visible but locked. The audit log records every view, every download attempt and every action, exported as a certified archive on close. That is the record a UK solicitor is likely to ask for when the disclosure letter refers to the data room.

The comparison of all data room costs for UK buyers covers the full pricing picture across the market, including providers that quote in pounds sterling.

Common indexing mistakes

Building the index after uploading the documents. Documents dropped into a room and indexed later produce duplicate files, inconsistent naming and a folder structure that was built around what was easy to find rather than what a buyer's adviser expects to see. Agree the top-level structure and the numbering scheme before the first document is uploaded. An afternoon spent on the index in advance saves days of reorganisation under deal pressure.

Using deep folder hierarchies. Three levels is usually enough: top-level workstream, category within that workstream, and individual documents. Folders nested five or six levels deep make documents difficult to find by navigation and produce unwieldy reference numbers in question logs. Flatten the structure and use clear, consistent file names instead.

Not sharing the index with the buyer on day one. This is the most common avoidable mistake. The index should be in the data room before access is granted, not circulated by email a week after bidders are already working. A buyer whose advisers have already started mapping the room themselves will do so in a way that suits them, not in a way that matches your structure, and correcting that mapping is harder than providing it in the first place.

Renaming or reorganising folders once bidders are inside. Any change to the index after buyers have access invalidates question log references and forces the buyer's team to remap their own notes. If a document genuinely needs to move, note the move in the Q&A module and keep the old folder visible, even if empty, with a note redirecting to the new location.

Releasing all documents to all buyers simultaneously. Releasing the detailed employment schedule to a trade bidder who is also a direct competitor, before exclusivity is agreed, is a real commercial risk on UK sell-sides. Build the staged release structure into the index before the room opens, and confirm with your solicitors which categories are phase one and which are phase two.

The UK virtual data room market analysis for 2026 sets out how the providers serving UK M&A actually differ in their approach to folder structure, permissions and audit trails.