A data room for a UK business sale or fundraising round should contain the documents that answer the question every buyer's adviser is paid to ask: is what we are paying for actually there, and are there any liabilities we do not know about? This guide sets out the complete document list by workstream, with the UK-specific statutory items that catch sellers out.
The starting point is the UK M&A data room checklist, which covers the full due diligence request list. This article organises the same territory by workstream and explains what goes in each section, why it matters under UK law, and where the common document gaps appear. For a ranked comparison of the platforms that host UK data rooms, see the main guide.
Corporate and constitutional
The corporate section is the one buyers' solicitors open first. It establishes what the seller actually owns, who is authorised to sell it, and whether there are any encumbrances on the shares or assets being transferred. A seller who cannot produce up-to-date statutory books at the start of diligence signals broader record-keeping problems, and those problems compound quickly once a buyer's lawyer starts cross-referencing dates.
The statutory books are the most commonly incomplete item in a UK data room. The register of members, register of directors and secretaries, and register of charges must reflect the current position. If they have not been maintained since incorporation, restoring them is a solicitor-led process that adds time to the preparation phase, not something that can be done overnight. Begin the statutory book review before any other preparation.
Section 190 of the Companies Act 2006 requires shareholder approval for substantial property transactions between a director and the company. Where a director has sold or purchased an asset from the company without a board resolution and general meeting approval, the transaction is voidable. A buyer's lawyer will trace every director transaction and ask for the section 190 paperwork. If it does not exist, the transaction needs to be ratified before exchange.
- Certificate of incorporation and any change-of-name certificates
- Current Articles of Association
- Register of members (up to date)
- Register of directors and secretaries (up to date)
- Register of charges (with any satisfied charges noted)
- Register of persons with significant control (PSC register)
- Board minutes for the past three years
- Shareholder resolutions and written resolutions
- Shareholders' agreements and any pre-emption rights waivers
- Section 190 board minutes and shareholder approvals where applicable
- Share certificates and any option or warrant documentation
- Companies House confirmation statements for the past three years
- Group structure chart showing all subsidiaries and their ownership
- Constitutional documents of any subsidiaries
Financial
Buyers will model the business from the financial documents in the data room. The quality of those documents determines how quickly they can reach a view on valuation. Audited accounts carry most weight; management accounts fill in the period between the last audit and the current date. Where the business has not been audited, a quality of earnings report commissioned by the seller is the standard substitute.
Working capital is a common sticking point in UK deal negotiations. The financial documents should be sufficient for the buyer to form a view on a normalised working capital figure before the price adjustment mechanism is agreed. That means month-by-month management accounts for the most recent 12 months, not just the year-end position.
- Audited statutory accounts for the past three years (or since incorporation)
- Management accounts for the current year to date, including comparative period
- Monthly management accounts for the past 12 months
- Most recent annual budget and multi-year forecasts
- Aged debtors and creditors schedules
- Cash flow forecasts
- Details of any inter-company loans or balances
- Fixed asset register
- Bank facility letters and any covenant compliance certificates
- Hire purchase and finance lease schedules
- Pension scheme accounts and actuarial reports where applicable
- Insurance schedules and renewal confirmations
Commercial contracts
The commercial contracts section reveals the revenue quality of the business. A buyer's adviser will review the termination provisions, change-of-control clauses, and any minimum commitment or exclusivity terms. Change-of-control provisions are the most important item to identify early: a contract that terminates or requires consent on a change of ownership can affect the valuation or require third-party consent before the transaction completes.
Concentration risk matters as much as any individual contract term. Where more than 20 percent of revenue comes from a single customer, the buyer will want that relationship documented in full, including correspondence that gives confidence the customer will remain after the transaction. If there is a side letter, comfort letter or verbal understanding with a key customer, it belongs in the data room or in the disclosure letter.
- Top ten customer contracts (by revenue), with any side letters
- Standard terms and conditions used with customers
- Key supplier contracts and framework agreements
- Distribution, agency and reseller agreements
- Joint venture, partnership and collaboration agreements
- Non-compete and exclusivity agreements
- Licence agreements (inbound and outbound)
- Finance agreements with customers (hire purchase, rentals)
- Any contracts subject to change-of-control consent requirements (flagged)
Employment and TUPE
Employment is the workstream that carries the most UK-specific legal exposure. The Transfer of Undertakings (Protection of Employment) Regulations 2006 (TUPE) apply to most business asset sales and to some share sales where the economic entity transfers. Where TUPE applies, the seller must provide employee liability information (ELI) to the buyer not less than 28 days before the transfer takes effect. The penalty for failing to provide ELI is a Tribunal award of not less than 13 weeks' pay per affected employee, with no upper cap.
Section 188 of the Trade Union and Labour Relations (Consolidation) Act 1992 requires collective consultation where 20 or more employees are being made redundant within 90 days. Even where there are no redundancies planned as part of the transaction, the information and consultation obligations under TUPE regulation 13 still apply. The seller must inform affected employees or their representatives of the fact of the transfer, the reasons for it, and the legal, economic and social implications. If there is a recognised trade union or elected employee representatives, the obligation to consult, not just inform, is triggered.
The TUPE schedule should be prepared with solicitor input and should reflect the position not more than 28 days before the intended transfer date. It should not be uploaded to the data room until the NDA has been executed and ideally until the buyer has been granted access under a formal process letter. Personal data in the TUPE schedule must be handled in accordance with UK GDPR before disclosure.
- Employee liability information (ELI) under TUPE regulation 11
- Schedule of transferring employees with roles, salaries, start dates and terms
- Employment contracts for directors and senior employees
- Standard employment contract templates
- Handbook, policies and procedures
- Details of any recognised trade unions or employee representatives
- Collective agreements and any relevant works council arrangements
- Section 188 consultation records where applicable
- Details of any outstanding Tribunal claims or settlement agreements
- Redundancy and dismissal records for the past three years
- Pension scheme enrolment details and any enhanced contribution commitments
- Bonus, commission and incentive scheme documentation
- Share scheme documentation (EMI, CSOP, SIP) and HMRC approval letters
- Key person life insurance and any related restrictive covenant agreements
Property
The property section applies whether the business owns, leases or merely occupies property. For an owner-occupier, the buyer will want to see title to all freehold and leasehold interests and any enquiries raised during the original purchase. For a leaseholder, the key documents are the leases themselves, any licences to alter, and the landlord's consent position on assignment.
Environmental disclosure is a practical requirement for any property with an industrial or commercial history. A Phase I environmental assessment (desktop review) is the minimum. Where Phase I identifies a risk, a Phase II assessment (intrusive investigation) should be in the data room or the seller should explain why it has not been commissioned. If an assessment was carried out on the original acquisition of the property, it belongs in the data room regardless of age.
- Freehold title documents and Land Registry entries for all owned properties
- Leases for all occupied premises, with any side letters or licences to alter
- Landlord consents to assignment and any outstanding dilapidations
- Service charge accounts and any disputes
- Planning permissions, building regulations approvals and completion certificates
- Environmental assessments (Phase I and Phase II where applicable)
- Contaminated land or remediation records
- Business rates correspondence and any reliefs claimed
- Property insurance schedules
- Licences for any shared or third-party-occupied space
IP and IT
For technology businesses and consumer brands, the IP section is often the most valuable part of the data room. Buyers will want to verify that the key intellectual property is owned by the company, not by a founder personally, a third party or an overseas holding vehicle. Assignments of IP from founders or consultants should have been documented at the time; if they were not, they need to be executed before disclosure.
For the IT section, cybersecurity posture has become a standard diligence item in UK M&A. Buyers in regulated sectors or with a mature information security programme will look for evidence of penetration testing, vulnerability management and incident response capability. Where the business holds personal data on customers or employees, the technical and organisational measures supporting that holding are part of the data protection section but should also appear here in summary.
- Trade mark registrations and pending applications (UK and international)
- Patent registrations and pending applications
- Registered design rights
- IP assignment agreements from founders, employees and contractors
- Software licences (inbound) and licence agreements (outbound)
- Domain name registrations and transfer records
- Source code ownership confirmation and any escrow arrangements
- Open source software inventory and licence obligations
- Penetration test reports (most recent two years)
- IT infrastructure summary and any cloud service provider contracts
- Cybersecurity policies and incident response records
- Any material IT outages, breaches or vulnerabilities in the past three years
Data protection (UK GDPR)
UK GDPR affects the data room in two distinct ways. First, the data room itself contains personal data about employees, customers and suppliers that must be handled lawfully before disclosure to a prospective buyer. Second, the buyer will conduct diligence on the target's own compliance with UK GDPR as part of assessing its regulatory exposure.
On the first point: personal data in the TUPE schedule, customer contracts and employee records should be redacted or anonymised before the data room is opened to any buyer who has not executed a strict confidentiality agreement naming them. The Information Commissioner's Office has published guidance on personal data in M&A that confirms disclosure to a prospective buyer can be lawful under the legitimate interests basis, but the buyer must be subject to equivalent obligations. In practice, use a data room NDA gate and redact personal data until the buyer is at a stage where the detail is necessary for due diligence.
On the second point, the record of processing activities (ROPA) required under Article 30 UK GDPR, any data protection impact assessments (DPIAs) and any ICO correspondence go into the data protection section. A buyer with a compliance team will check that the target has a current ROPA, that the lawful bases claimed are appropriate, and that the retention and deletion policies have actually been followed. For more on how UK data residency interacts with data room hosting requirements, see the dedicated guide.
- Record of processing activities (ROPA) under Article 30 UK GDPR
- Privacy policy (website and internal employee-facing version)
- Data protection impact assessments for high-risk processing
- Data processing agreements with key data processors
- International data transfer mechanisms (UK International Data Transfer Agreements or standard clauses)
- Subject access request log and response records for the past 12 months
- Any ICO correspondence, enforcement notices or audits
- Cookie consent implementation and records
- Data retention and deletion policy and evidence of operation
- Cyber insurance policy
- Any personal data breach notifications to the ICO or affected individuals
Regulatory and licences
The regulatory section depends heavily on the industry. A financial services business will need to produce its FCA authorisation records, approved person register and any supervisory correspondence. A food business will need its local authority registration, hygiene ratings and any enforcement notices. An education provider will need its Ofsted or equivalent inspection reports.
Even for businesses outside formally regulated sectors, certain licences are universal: health and safety at work compliance, employer's liability insurance, and (where applicable) licences for alcohol, credit, or regulated activity. A buyer will ask for evidence that every required licence is current and in the name of the trading entity, not a predecessor or individual.
- FCA authorisation and approved persons register (financial services businesses)
- Sector-specific regulatory licences and renewals
- Health and safety policy, risk assessments and inspection records
- Employer's liability and public liability insurance certificates
- Alcohol, gaming, credit or other regulated activity licences
- Export control and sanctions compliance records where applicable
- Competition law compliance programme documentation
- Any regulatory investigations, enforcement notices or warning letters in the past five years
- Anti-bribery and anti-money laundering policies and procedures
Tax
The tax section covers both compliance and planning. A buyer will want to see that every filing obligation has been met, that there are no open enquiries from HMRC, and that any tax planning in the business has been properly documented and is not at risk of challenge. The level of scrutiny depends on whether the deal is a share sale or an asset sale: in a share sale, the buyer inherits all historical tax positions, so the review is correspondingly more detailed.
EMI option schemes require HMRC registration and valuation approval. Where the company operates an EMI scheme, the approval letter and the valuation underlying it belong in the data room. If the valuation has not been refreshed in the past three years or following a material event, the buyer's tax advisers will note the risk.
- Corporation tax returns and computations for the past six years
- VAT returns and HMRC correspondence for the past four years
- PAYE and National Insurance records and any HMRC PAYE audits
- R&D tax credit claims and HMRC approval or enquiry correspondence
- Any HMRC enquiries, investigations or settlement agreements
- Transfer pricing documentation where applicable
- EMI valuation approval letters and scheme rules
- Stamp duty land tax returns for any property transactions
- Any tax indemnities or warranties given on previous acquisitions
- Details of any tax planning arrangements (DOTAS disclosure made or not made)
How to structure and organise a UK data room
The folder structure of a UK data room should follow the workstreams set out above, with leading numerals to keep the order stable regardless of the platform's default sort. A buyer's due diligence process is normally organised by the same workstreams, so a data room that mirrors that structure allows the buyer's lawyers, accountants and sector specialists to go directly to the section they are reviewing.
A standard top-level structure for a UK M&A data room is:
- 01 Corporate
- 02 Financial
- 03 Commercial
- 04 Employment
- 05 Property
- 06 IP and IT
- 07 Data Protection
- 08 Regulatory
- 09 Tax
Within each folder, sub-folders follow the buyer's request list. The request list arrives from the buyer's solicitors once an NDA is in place and a preferred bidder or process structure has been agreed. Uploading documents to match the request list, rather than in a structure the seller has invented, reduces the friction in the diligence process and reduces the number of questions about where documents can be found.
Naming conventions matter. A file named "Contract (3) FINAL v2" tells a reviewer nothing. A file named "Customer Supply Agreement Acme Ltd 2023-05-14" tells them the counterparty, the document type and the date, which is enough to match it against the request list without opening it. Set a naming convention at the start and apply it consistently.
For the pricing comparison across data room platforms, see the cost guide. Access permissions should be set at folder level where possible: give financial advisers access to the financial section without opening the employment section, and give legal advisers access to the legal sections without financial data, until a later stage of diligence when the process narrows.
Tools for UK data rooms
Papermark is best for UK M&A and fundraising data rooms where the team needs EU data residency, published pricing and a room live on the same day. The Data Rooms plan at EUR 99 per month covers unlimited rooms on one subscription, so the working-group room, the live bidder room and a management room can all run in parallel without additional fees. Hosting defaults to Frankfurt under AWS eu-central-1. For UK teams that need data to stay in the EU rather than in the United States, that is the confirmed answer. See the Papermark assessment for the full scoring breakdown.
Papermark pricing: Free at EUR 0, Pro at EUR 24 per month, Business at EUR 59 per month, and Data Rooms at EUR 99 per month (three team members included, unlimited data rooms). Annual billing saves up to 35 percent. Enterprise is on request and adds UK-resident hosting through region selection. All tiers are priced in euros only, with no sterling billing option.
For features required in a UK deal context: dynamic watermarking, NDA gates, page-by-page view analytics and granular folder-level permissions are all on the Data Rooms plan. Q&A functionality for structured diligence is not a native feature of the self-serve tiers, which is worth considering for a process with a large buy-side team and high question volume. For the full ranked comparison of UK data room providers, including security, residency and support scores, see the main guide.
A worked example: Midland Components Ltd
Midland Components Ltd is a fictional Midlands-based engineering business with 80 employees, selling to a private equity house. The deal is a full share sale. The sellers have engaged a corporate finance adviser and a solicitor. The target completion timeline is four months from the start of preparation.
The sellers' FD starts building the data room four weeks before the planned launch date. On the first pass through the corporate section, the solicitor notes that the statutory books have not been updated since 2021. The register of members does not reflect a share transfer that was made when a minority shareholder left the business in 2023, and the register of charges still shows a debenture that was discharged in 2022. Restoring the statutory books to the current position takes the solicitor one full week, working with the company secretary and the bank.
Simultaneously, the TUPE schedule needs to be prepared for all 80 employees. The ELI must be ready at least 28 days before the anticipated transfer date, but the solicitor recommends having it in the data room at launch so the buyer has it from the start of formal diligence. The schedule takes three days to prepare from the HR system, check against the employment contracts and anonymise the personal data fields before the room opens to all bidders.
The data room platform itself, Papermark, goes live within the day the FD sets it up. The folder structure is created and the naming convention agreed in under an hour. The platform is not the delay. The document preparation is the delay. The statutory book gap adds three weeks to the preparation phase. The lesson: begin the statutory book review before the data room setup, not after.
The FD also discovers that three customer contracts contain change-of-control provisions that require consent from the counterparty before the shares can be transferred. The solicitor flags these for the corporate finance adviser in week two of preparation. The consent process runs alongside the data room preparation rather than after it, saving four to six weeks versus a sequenced approach.
Common mistakes in UK data room preparation
Starting with the data room before the document gap review. The platform is not the constraint. The document set is. A seller who opens a data room before auditing what they actually hold will spend the first week of formal diligence answering questions about missing documents rather than managing the process. The document gap review comes first. The data room setup takes an afternoon.
Including personal data without redaction. Employee names, salaries and personal contact details should not be visible to all bidders at the start of the process. UK GDPR requires a lawful basis for disclosure. The legitimate interests basis can support disclosure of personal data to a prospective buyer, but only under equivalent confidentiality obligations. Set the NDA gate before the employment section is accessible, and redact personal data in the TUPE schedule until the buyer is at a stage of diligence where the full detail is necessary.
Uploading TUPE documents after the statutory 28-day window. Under TUPE regulation 11, the ELI must be provided to the buyer not less than 28 days before the transfer. Sellers who treat the ELI as an afterthought and upload it at the end of the process face a Tribunal claim with no upper cap. The ELI should be prepared before the data room launches, checked by the solicitor, and disclosed under the NDA at the start of formal diligence.
Conflating what is in the business with what goes in the data room.Operational documents, internal communications and management presentations that formed the basis of the investment decision belong in the disclosure process, not in the data room. The data room is the disclosure set: the documents a buyer's adviser needs to conduct due diligence and form a view on the warranties and indemnities. Marketing materials, board packs prepared for internal use and correspondence between the seller and its advisers do not go in.
Missing the section 190 board minutes for director transactions.Where a director has bought from or sold to the company during the period covered by the diligence, the Companies Act 2006 procedure needs to have been followed: board approval, shareholder approval (if the value is above the threshold), and documentation. A buyer's lawyer will review every director transaction in the statutory books and trace the corresponding approval. Transactions that were not properly documented at the time need to be ratified before the data room opens. Attempting to ratify them during diligence when a buyer is already in the room creates avoidable questions.