A UK M&A data room needs to answer eleven workstreams: corporate, financial, commercial, employment, property, intellectual property and IT, data protection, regulatory, litigation, tax, and insurance and pensions. The structure matters as much as the contents, because the buyer's advisers will work from their own request list and any category they cannot find quickly becomes a question, and every question costs time.

What follows is the document set a British buyer's legal and financial advisers will realistically ask for on a private company acquisition. It is written for sellers preparing a room rather than for lawyers running diligence, and it flags the items that are specific to the UK, which is where most generic checklists are least useful.

1. Corporate and constitutional

Start here, because this is where preparation most often uncovers problems that take weeks rather than hours to fix. The buyer needs to establish that the company exists in the form you say it does and that the seller can actually convey title to the shares.

  • Certificate of incorporation, any certificates on change of name, and current articles of association
  • Statutory registers: members, directors, secretaries, persons with significant control, charges
  • Board and shareholder minutes and written resolutions, typically for the last three to six years
  • Filing history at Companies House, and confirmation that filings reconcile with the statutory books
  • Share capital history, option schemes including EMI documentation, warrants, and any convertible instruments
  • Shareholders' agreement, investment agreements and any side letters
  • Group structure chart and details of any dormant subsidiaries

The reconciliation point deserves emphasis. It is common for a company's statutory registers to diverge from what has actually been filed, particularly where share transfers, option exercises or director changes were handled informally. A buyer's solicitor will find the discrepancy, and rectification under deal pressure is both slower and more expensive than doing it in advance.

2. Financial

  • Statutory accounts for the last three financial years, plus management accounts to the most recent month end
  • Current year budget, forecast, and the assumptions underpinning them
  • Detailed trial balance and aged debtor and creditor listings
  • Banking facilities, loan agreements, debentures, guarantees and any intercompany balances
  • Details of grants, R&D tax credit claims and any government support received
  • Capital expenditure history and committed future spend

On smaller UK deals the financial workstream frequently becomes the critical path, because management accounts are prepared for internal use rather than external scrutiny and the buyer's accountants want a bridge between them and the statutory accounts. Preparing that bridge yourself, in advance, is one of the highest-value things a seller can do.

3. Commercial contracts

  • Contracts with the largest customers by revenue, usually the top ten to twenty
  • Key supplier agreements and any sole-source dependencies
  • Distribution, agency, reseller and partnership agreements
  • Standard terms of business, and a note of where customers have contracted on their own terms instead
  • Any contract containing a change of control provision, listed separately

The change of control list is the item most often missing and most likely to affect price. If material customer contracts terminate or require consent on a share sale, the buyer needs to know early, and the answer shapes deal structure. Pull these out into their own folder rather than leaving the buyer to find them.

4. Employment and TUPE

  • Anonymised employee list with role, start date, salary, notice period and location
  • Standard employment contracts and any individually negotiated terms
  • Directors' service agreements and consultancy arrangements
  • Employee handbook, policies, and any collective agreements
  • Details of self-employed contractors and the basis on which their status was assessed, including IR35 determinations
  • Live or threatened employment tribunal claims and any settlement agreements

Two UK-specific points. On an asset purchase the Transfer of Undertakings (Protection of Employment) Regulations will usually apply, which brings information and consultation obligations and makes the employee data set more sensitive and more scrutinised than on a share sale. And contractor status is a recurring area of buyer concern given IR35, so the documentation behind status determinations matters as much as the contracts themselves.

5. Property

  • Title documents and Land Registry official copies for freehold properties
  • Leases, licences to occupy, rent deposit deeds and any licences for alterations
  • Schedules of condition, dilapidations correspondence and service charge accounts
  • Energy performance certificates, asbestos surveys and fire risk assessments
  • Stamp Duty Land Tax returns and evidence of payment

6. Intellectual property and IT

  • Registered trade marks, patents and designs, with renewal dates
  • Domain names and their registrant details, which surprisingly often sit in a founder's personal account
  • Assignments confirming that IP created by employees and contractors belongs to the company
  • Software licences, SaaS subscriptions and any open source usage
  • IT systems overview, hosting arrangements and disaster recovery documentation

The contractor IP assignment gap is a classic finding on UK technology deals. Work created by an employee in the course of employment vests in the employer by default, but work created by a contractor does not unless it has been assigned. If early development was outsourced, find the assignments before the buyer asks for them.

7. Data protection

  • ICO registration and the record of processing activities required under UK GDPR
  • Privacy notices, cookie policy and consent mechanisms
  • Data processing agreements with processors, and the sub-processor list
  • International transfer documentation, including any International Data Transfer Agreement or UK Addendum and the associated transfer risk assessments
  • Breach log, and details of any notification made to the ICO

This workstream has grown considerably in importance and is now routinely scoped into UK diligence rather than treated as a formality. If your business transfers personal data outside the UK, the transfer mechanism documentation is part of the data set. Our guide to UK data residency and restricted transfers covers what that documentation has to establish.

8. Regulatory and consents

  • Licences and permits required to operate
  • For regulated firms, FCA or PRA permissions and any change in control approval requirements
  • Correspondence with regulators, including any enforcement or supervisory matters
  • An assessment of whether the transaction triggers mandatory notification under the National Security and Investment Act 2021, which covers seventeen sensitive sectors

9. Litigation and disputes

  • Current, threatened and recently concluded litigation
  • Correspondence from solicitors on contentious matters
  • Settlement agreements and any ongoing obligations under them
  • Regulatory investigations

10. Tax

  • Corporation tax computations and returns for the last three years
  • VAT returns, and details of any group registration
  • PAYE and National Insurance compliance history
  • Correspondence with HMRC, including any enquiries, clearances or settlements
  • Share scheme tax treatment, particularly EMI valuations and notifications

11. Insurance and pensions

  • Current policies, schedules and claims history
  • Pension arrangements, including auto-enrolment compliance and any defined benefit exposure
  • Details of any warranty and indemnity insurance being contemplated for the transaction

How to structure the room

Number the top-level folders to match the eleven workstreams above and keep the numbering stable once bidders have access, because advisers will reference documents by index number in their reports and questions. Within each workstream, use a shallow structure. Three levels is usually enough and deeper hierarchies make documents harder to find, not easier.

Set permissions by workstream rather than by document wherever you can, because per-document permissioning is where mistakes happen under time pressure. Reserve the most sensitive categories, typically detailed customer contracts, the employee data set and any live litigation, for a second phase released to a shortlist.

Finally, agree the disclosure mechanism with your solicitors before you upload anything. If the sale and purchase agreement will treat matters fairly disclosed in the data room as qualifying the warranties, then the room is a legal instrument and needs version control, a fixed index and a certified archive on close. Several providers offer exactly that. The ranked comparison of UK data rooms sets out which ones do.

A worked example

Consider Brackenfield Instruments, a fictional Sheffield manufacturer with revenue around eleven million pounds, forty-two employees and a single freehold site. The founders accept an indicative offer from a trade buyer and have six weeks before diligence begins in earnest.

They open the corporate workstream first and immediately find that two share transfers from 2019 were never recorded in the register of members and that the PSC register has not been updated since a founder reduced their holding. Their solicitors rectify both, which takes three weeks because one transferee has since moved abroad. Had they started that work when diligence opened, it would have sat on the critical path.

In parallel they build the customer contract folder and discover that their second largest customer, representing nineteen percent of revenue, contracted on the customer's own terms containing a change of control termination right. They flag it to their advisers early, which gives the buyer time to seek comfort from the customer rather than pricing the risk into the offer at the last minute. The employee data set is prepared but held back to phase two, so that anonymised numbers go into the first release and individually identifiable terms follow only once exclusivity is agreed.

Common mistakes

Uploading before indexing. Documents dropped into a room and organised later produce duplicate files, inconsistent naming and an index that has to be rebuilt once bidders are already inside. Agree the structure first, then populate it.

Treating the room as a filing cabinet. If the disclosure letter refers to the data room, its contents carry legal weight. That makes uncontrolled uploading by multiple people a genuine risk, and it is why permissions and an audit trail matter more than storage capacity.

Releasing employee data too early. Individually identifiable salary and performance information is both commercially sensitive and personal data. Stage it, and be able to explain the lawful basis on which it is shared.

Ignoring change of control provisions until diligence. By then the buyer has found them and the seller has lost the initiative. Read the top twenty contracts before the room opens.

Underestimating storage. A manufacturer with property documents, technical drawings and years of contracts will exceed the entry tier of most providers. Estimate the volume in gigabytes before choosing a platform, because per-megabyte overage is where a quoted monthly price becomes an unexpected invoice. Our breakdown of what UK providers charge shows where those charges sit.