Process

Closing a data room properly, and what to keep afterwards

The last week of a deal is when records get lost. A short procedure for shutting a room down without losing the evidence.

Vault Index desk / 7 August 2026 / 6 min read

The closing pack

Three artefacts matter after completion. The document index, showing every file and version that was made available. The access log, showing which verified viewer opened what and when. The question and answer log, showing what each party was told.

Produce all three while the room is live and store them with the executed documents. Retrieving them after a subscription lapses ranges from awkward to impossible.

Revoking in the right order

On the day the process ends, revoke every external viewer from unsuccessful parties, then advisers whose engagement is over, then internal users who no longer need access. Leave a small administrator group until the closing pack is exported and checked.

Test one revoked link yourself. A closed room that still serves a cached document is a bad thing to discover later.

Retention and deletion

Ask the vendor to state in writing how long documents and logs are retained after closure, whether deletion is available on request, and what confirmation you receive. Where personal data is involved, that answer feeds directly into your own retention record under UK GDPR.

Then diarise the review. The most common failure is not deleting too early, it is a room nobody closed still holding a full diligence set three years on.

Sources and further reading

Vendor figures rechecked 1 September 2026