Process
Closing a data room properly, and what to keep afterwards
The last week of a deal is when records get lost. A short procedure for shutting a room down without losing the evidence.
Vault Index desk / 7 August 2026 / 6 min read
The closing pack
Three artefacts matter after completion. The document index, showing every file and version that was made available. The access log, showing which verified viewer opened what and when. The question and answer log, showing what each party was told.
Produce all three while the room is live and store them with the executed documents. Retrieving them after a subscription lapses ranges from awkward to impossible.
Revoking in the right order
On the day the process ends, revoke every external viewer from unsuccessful parties, then advisers whose engagement is over, then internal users who no longer need access. Leave a small administrator group until the closing pack is exported and checked.
Test one revoked link yourself. A closed room that still serves a cached document is a bad thing to discover later.
Retention and deletion
Ask the vendor to state in writing how long documents and logs are retained after closure, whether deletion is available on request, and what confirmation you receive. Where personal data is involved, that answer feeds directly into your own retention record under UK GDPR.
Then diarise the review. The most common failure is not deleting too early, it is a room nobody closed still holding a full diligence set three years on.
Sources and further reading
- Information Commissioner's Office, storage limitation
- 99 Data Rooms, how to revoke access to a document already shared
Vendor figures rechecked 1 September 2026
Vault Index