Process
How to set up a data room, step by step
The sequence that avoids the most common launch delay: uploading documents before the folder structure and permission groups exist.
Vault Index desk / 9 August 2026 / 8 min read
The short answer
Setting up a data room properly takes five ordered steps: choose a platform against the deal's actual requirements, build the folder index before uploading anything, define permission groups before inviting anyone, upload and tag documents against that index, then run a controlled test with a real external login before the process goes live. Doing these out of order, especially uploading before the structure exists, is the single most common cause of a slow, messy launch.
The whole exercise usually takes a project lead between two days and two weeks depending on deal size, most of it spent gathering and checking documents rather than configuring the software itself.
Step 1: choose the platform against the deal, not the brand
A single founder raising a seed round has different needs from an investment bank running a competitive auction with forty bidders. Match the platform to the process: lighter tools such as SecureDocs, Onehub or 99 Data Rooms suit smaller raises and mid market sales, while Datasite Diligence, Intralinks VDRPro or DFIN Venue suit large, multi advisor, cross border M&A. Ansarada and Drooms are worth a look specifically where the process needs strong built in workflow templates for M&A or real estate.
Confirm security certifications, ISO 27001 and SOC 2 are the baseline to check, and confirm where data is hosted if the deal involves EU or UK personal data, since that affects GDPR compliance.
Step 2: build the folder index before uploading
Draft the folder structure on paper or in a spreadsheet first. A typical top level structure runs: 1) Corporate and governance, 2) Financial statements and models, 3) Commercial contracts, 4) Intellectual property, 5) Employment and HR, 6) Litigation and compliance, 7) Real estate and assets, 8) Tax, 9) Insurance, and 10) Q&A and correspondence. Sub folders should mirror whatever due diligence request list the buyer or auditor has issued, so that a reviewer can move from the request list to the folder without translation.
Numbering folders and files consistently, rather than relying on the platform's search, matters more than it sounds, because auditors and lawyers frequently cite documents by index number in later correspondence and in the eventual disclosure schedule.
Step 3: define permission groups before inviting anyone
Set up viewer groups, for example bidder A, bidder B, internal deal team, and external counsel, before sending a single invitation. Decide per group whether documents can be viewed only, viewed and printed, or downloaded, and whether watermarking applies. In a competitive auction, keep bidder groups strictly separated so that one bidding team can never see another's Q&A thread or activity.
Assign a document owner for every top level folder, usually the internal person best placed to answer questions about that material, so that when a buyer question comes in through the room's Q&A workflow it routes to someone who can actually answer it rather than sitting unanswered.
Step 4: upload, tag and stage the release
Upload documents against the pre built index rather than dumping files and sorting later. Most platforms let files sit in a staged, unpublished state while they are checked, which is worth using, since it lets the internal team catch a misfiled or unredacted document before any external viewer can see it. Redact personal data and commercially sensitive figures that are not relevant to the specific process, since UK GDPR and equivalent regimes elsewhere require a lawful basis for exposing personal data even to a prospective buyer.
Where a process happens in phases, initial teaser documents, then full financials after signing a letter of intent, then the most sensitive material only for the final bidder, stage the release so each tranche opens at the right point rather than exposing everything from day one.
Step 5: test before going live
Log in as a test external viewer, using a genuinely separate account rather than an internal admin login, and confirm that permissions behave as designed: that a restricted viewer cannot download what they should only view, that watermarks render correctly, and that the Q&A routing reaches the right owner. This catches configuration mistakes before a real bidder does.
Only after that test should invitations go out to real external parties, accompanied by a short guidance note on how to use the room and who to contact for access problems, since the first week of a live process is when access issues, not document quality, generate the most support tickets.
Closing note
For a side by side comparison of the platforms mentioned here, see the full ranking at /rankings, our scoring method at /methodology, and current published pricing at /pricing.
Sources and further reading
- Ansarada, data room setup guidance
- ICO, guide to the UK GDPR
- Drooms, data room best practice
- 99 Data Rooms blog
Vendor figures rechecked 1 September 2026
Vault Index