Eighteen virtual data room providers sell into the United Kingdom, and 9 of them publish no price at all. Only 9 offer UK data residency, only 5 quote in sterling, and only 6 are actually British. Set against ONS transaction data, the supply side of this market is calibrated for deals considerably larger than the ones the UK mostly does.

The shape of UK deal flow

The Office for National Statistics publishes the only authoritative count, and it is narrower than most market commentary implies. ONS records mergers and acquisitions worth £1m or more that result in a change of ultimate control, which excludes both minority investments and the long tail of very small business sales.

On that basis, the first quarter of 2026 produced 352 completed transactions involving a change in majority share ownership, down from 495 in the final quarter of 2025. Inward acquisitions, meaning foreign companies buying British ones, totalled £14.2bn against £33.0bn the previous quarter. Outward was £4.7bn against £3.0bn, and domestic £1.5bn against £1.9bn. ONS flags these as provisional and notes that revisions run upwards more often than down.

Two things follow. The quarter-on-quarter volatility in value is dominated by a small number of very large inward deals, and the count of transactions is far more stable than the value. Which means the typical UK transaction is not the one that moves the headline figure.

What the market supplies

Against that demand profile, here is what the supply side looks like across the 18 providers we assess:

CharacteristicCountShare
Publish a price on their own site9 of 1850 percent
Quote in pounds sterling5 of 1828 percent
Offer UK data residency9 of 1850 percent
Headquartered or registered in the UK6 of 1833 percent
Claim Cyber Essentials5 of 1828 percent
Offer a free tier or trial9 of 1850 percent

The pricing figure is the one worth sitting with. Half the market will not tell a prospective buyer what it costs without a sales conversation. In most software categories that would be remarkable. Here it is normal enough that comparison sites treat it as unremarkable, which is precisely why we score it.

The mismatch

The providers with the deepest certification stacks, the most developed deal workflow and the strongest support are, with few exceptions, the ones that publish nothing about price. They are built for large, adviser-led processes where a procurement function absorbs the sales cycle and the data room cost is immaterial against fees.

That is a coherent business, and for a nine-figure sell-side it is the right answer. It is simply not the shape of most British transactions. A company being sold for six or seven million pounds has no procurement function, no appetite for a fortnight of demos, and a finance director who needs a number before signing anything.

The providers serving that buyer do exist, and they cluster at the opposite end on certification depth. The market has a gap in the middle: few vendors combine published, sterling pricing with the certification stack a cautious buy-side adviser will interrogate. Where a provider does bridge it, that combination is worth more than a marginally better feature list. The full ranking is largely an expression of that judgement: Papermark leads on 92 of 100 because it publishes everything and still holds SOC 2 Type II and ISO/IEC 27001, not because it has the most features.

The residency divide

Since Brexit the UK operates its own data protection regime, and the market has not fully adjusted. Only 9 of 18 providers offer the United Kingdom as a named, selectable storage location.

More striking is how many providers hold UK-facing credentials without UK hosting. One vendor operates offices in London and Glasgow, holds Cyber Essentials Plus, sells through G-Cloud, and stores every document in Norway and EU Azure regions. None of that is improper. It is simply not what a buyer reading the phrase "UK offices" on a comparison page tends to assume.

The underlying legal position is also more subtle than the marketing suggests. UK law does not require UK residency at all. What it regulates is the restricted transfer, and by the ICO's test, making data accessible to an overseas bidder is itself a restricted transfer even when the documents never leave the country. Buyers frequently purchase UK hosting to solve a problem UK hosting does not solve. We set out the actual test in our guide to UK data residency.

How British is this market?

Less than it appears, and the discrepancy is instructive. Verified against Companies House, 6 of the providers we assess are headquartered or registered in the UK. Several widely described as British are not.

Imprima is the clearest case. It is routinely presented as a London-headquartered provider offering UK data hosting. Its own company page gives Amsterdam as its headquarters with London as one of five offices, and its own security page states that all data, primary and backup, sits in EU locations. Two further providers listed as active by multiple comparison sites no longer trade: Ruby Datum, whose UK entities were dissolved in December 2023 and December 2024, and EthosData, whose UK entity was dissolved on 19 May 2026 after acquisition by Ideals.

The genuinely British suppliers tend to be small, and they cluster around sovereignty and public sector work rather than competing on deal workflow. That is a rational position given the incumbents, and it means the British end of this market is best understood as a distinct segment rather than as challengers to the large platforms. Our list of UK-based providers covers who they are.

The information problem

Researching this market surfaces a quality problem that shapes buyer behaviour. The sites ranking highest for UK data room searches are largely affiliate networks, and in a single research pass they produced one provider misdescribed on both headquarters and hosting, and two presented as available that no longer trade.

Vendor material is not uniformly better. Among the providers assessed we found a compliance page misdescribing ISO/IEC 27001 as an AI governance standard, a vendor claiming EU-US Privacy Shield certification six years after that framework was invalidated, two vendors citing different versions of ISO 27001 on different pages of their own sites, one giving two different postcodes for the same London office, and one advertising a company registration that has been dissolved.

None of that means the underlying products are bad. It does mean a buyer cannot safely take published claims at face value, which is why every provider assessment we publish carries a section listing what we could not verify.

What to expect

Three things look likely over the next several quarters, offered as reasoning rather than prediction.

Pricing opacity will erode from the bottom.Buyers who can see a price on one vendor's site increasingly ask why another will not show one. That pressure runs upward from the mid-market rather than downward from enterprise.

UK residency will become a product feature rather than an enterprise negotiation. Region selection is currently gated to the top tier at several vendors. As UK-specific procurement requirements harden, particularly around PPN 014, the vendors that expose region choice on ordinary plans will have a straightforward advantage.

The Data (Use and Access) Act 2025 will raise the evidential bar. The data protection test introduced by new Articles 45A and 45B requires that protection in a destination is not materially lower than UK standards, assessed taken as a whole, and the same test now applies to exporters relying on standard contractual clauses. Vendors whose compliance pages are already years out of date will find that increasingly difficult to sustain in buy-side security reviews.