Skip to content
By profession6 min read

Due diligence data rooms: what to redact before you upload documents

Selling or buying a company? Here is what to redact in a due diligence data room, from payroll to price lists, at each stage before you grant access.

By Alexis de ONYRI

A data room is a shared folder where a seller uploads contracts, payroll files and customer lists so a buyer can check the company before signing. Two things need to come out first: personal data about named people, and business secrets a competitor could use, like unpublished prices. Redact those, then let reviewers see the rest.

Why do data rooms create two separate risks?

Jane Example runs the sale process for a mid-size logistics firm. Her lawyers ask for payroll, supplier contracts and five years of invoices before the buyer's team even meets management. Two problems sit inside that folder. First, payroll and invoices name real employees and customers, so GDPR rules apply. Second, if the buyer is a competitor, prices and client lists can hand over a strategic advantage before the deal even closes.

What does GDPR require before you share personal data?

Under EU law, processing personal data needs a legal basis. Article 5 of the GDPR also limits it to what the purpose requires: the minimisation principle. In September 2024, Germany's data protection conference, the DSK, ruled that in an asset sale, sending personal data to a buyer during due diligence is generally not allowed before a contract is signed. It found narrow exceptions: employees or customers can give free consent, or a legitimate interest under Article 6(1)(f) can cover a few key contract partners or managers in advanced talks.

France's data authority, the CNIL, sets a parallel rule for customer files: only active customers belong in them, records past the retention period must be dropped, and the buyer must tell each person about the transfer within one month. The European Data Protection Board reminds merger parties to run a full, transparent assessment of their obligations before they even notify the deal.

What can you not share with a competing buyer?

Due diligence between competitors is also competition law territory. The European Commission's 2023 guidelines on cooperation between companies describe a common safeguard: the clean team, a small group who are not involved in day-to-day sales or pricing decisions and who sign strict confidentiality rules before they see sensitive files. Old, aggregated figures are far safer to share than live prices or named customer volumes.

France's competition authority makes the boundary concrete with a hotel example. Exchanging published rates is fine. Exchanging sector averages is fine too, if no single company's numbers can be worked out. But exchanging future price lists is a banned practice on its own, whether or not the deal ever closes. The same logic applies to a data room: a spreadsheet of next year's prices per client needs a lawyer's review before it goes online, not just a redaction pass.

What should you redact at each stage of the deal?

Not every document needs the same treatment. A first-round teaser can stay abstract. A signed sale agreement can show almost everything. The table below is a starting point for common data-room files.

DocumentStageRedact before upload
Payroll registerTeaser or early accessThe whole file: do not upload it yet
Payroll registerExclusivity, clean team formedNames, bank details and exact pay masked, job titles and totals kept
Customer contractsTeaser or early accessClient names and prices: share aggregated revenue only
Customer contractsClean team reviewClient names masked unless the reviewer sits outside sales
Supplier price listsAny stage before signingUnit prices and volumes replaced by category totals
HR files (contracts, reviews)Any stage before signingNames, addresses, health notes and disciplinary history

Why do aggregated numbers work better than named lists?

An aggregate replaces ten named rows with one number: total payroll, not each salary, average contract value, not each client's price. Germany's cartel office gives a rough figure for this in its own guidance for buying groups: pooling data from around five or more companies has held up as safe in past cases, because no single company's numbers could be picked back out. A data room can use the same idea for a target company's own customers or suppliers, without waiting for a clean team to be set up.

Before you upload a batch of PDFs or Word files, ONYRI Sanitize can mask names, IBANs, amounts with a currency and company identifiers directly in the browser, so the file never leaves your computer. It works detector by detector, so it cannot judge which clause counts as commercially sensitive: a lawyer still needs to check prices and strategic terms by hand.

Do watermarks and no-download settings count as redaction?

Most data-room platforms add a watermark with the viewer's name and log every page view. Those features stop casual leaks and show who opened what. They do nothing to the text itself: a screenshot or a photo of the screen still carries the client's name, the salary, the price. Only removing or blacking out the value before upload keeps it out of a screenshot.

What is a quick checklist before opening access?

  • List every document type going in: payroll, contracts, price lists, HR files, board minutes.
  • Mark who reads what: general access, clean team only, or lawyers only.
  • Replace named data with totals wherever a number, not a name, answers the question.
  • Get consent or confirm a legal basis for the personal data that must stay.
  • Re-check the file after export: watermarks do not change what a screenshot shows.

Frequently asked questions

Does anonymising a data room make a deal GDPR-compliant?
No. Redaction reduces exposure, but a lawful basis, minimisation and information to the people concerned are still required. Masking documents is one safeguard among several, not a compliance certificate on its own.
Can I share customer names with a competitor's clean team?
Only inside the safeguards a clean team is built for: strict confidentiality rules, a limited group cut off from live sales and pricing decisions, and aggregated figures wherever a total answers the question instead of a named list.
What happens if unmasked payroll data is uploaded by mistake?
Tell your data protection contact and the buyer right away, and log when access was revoked. Under GDPR, this kind of exposure can count as a personal data breach that may need reporting, depending on the risk to the people involved.
Is a signed NDA enough before opening a data room?
An NDA covers confidentiality, not the separate rules on personal data and competitively sensitive information. Even with an NDA in place, payroll, client prices and supplier terms still need staged access and redaction.
Should due diligence documents ever include health or union data?
Rarely, and only with explicit consent. These count as special category data under GDPR. Leave them out of a data room unless a named lawyer has confirmed a specific legal basis for that document.

Sources & references

On this siteAnonymize invoices and financial documents

Mask a document without uploading it

ONYRI Sanitize finds names, identifiers, bank details and secrets in a PDF, a Word file or a scan, and masks them in your browser. You check the preview, then download a flattened copy.

Read next