Legal matters and litigation involve sharing documents with parties who sit on different sides: opposing counsel, co-counsel, expert witnesses, clients and sometimes regulators. Productions often contain personal data about employees, customers or patients, and privileged material must never reach the wrong group. When a dispute turns on who saw what and when, you also need a reliable record of access.
This guide walks through the Papermark data room controls that matter most for legal matters, in the order you would set them up. It covers how to configure Papermark, not legal advice: what you produce, how you redact it and what your agreements say are decisions for counsel.
These are the controls that do most of the work in a legal or litigation room. The rest of this guide shows how to set each one up.
A legal room often holds privileged strategy documents that only the matter team should see.

Emails, HR files, medical records and customer data often contain personal details that are not relevant to the matter. Use AI redaction to detect names, email addresses, phone numbers and account numbers, review each suggestion and black out what should not be shared before the document goes into the room. Counsel decides what to redact; the tool helps you apply it consistently. This also supports your GDPR compliance.


Structure the room so privileged material and produced material never share a folder, for example:
Create a group for each party (opposing counsel, co-counsel, each expert, the client, a regulator) and use granular file permissions to set which folders each group can see and whether they can download. Set default permissions for new documents so new uploads stay hidden from every group until you share them on purpose.

@opposingfirm.com or @agency.gov.When someone is denied access, Papermark notifies you, so you see attempted access instead of guessing.

Turn on email verification on every link. Visitors receive a one-time code by email before the room opens, so each view in your audit log is tied to a verified person. This makes the access record far more useful than one based on typed-in addresses.

Use agreements to show a confidentiality agreement, or the terms of a protective order, before viewing. The agreement text is whatever counsel provides; Papermark displays it and records each acceptance with the visitor's verified email and a timestamp. See how to require an NDA before viewing.

Enable a dynamic watermark on every link. Papermark stamps each page as it is viewed with the details you choose, for example Confidential {{email}} {{date}} {{ipAddress}}. If a document appears where it should not, the watermark shows whose copy it was.

For material designated confidential, or anything you do not want copied outside the room:
If you allow bulk downloads of a production, OTP-verified bulk downloads send a one-time password to the visitor's verified email before the ZIP is built.

Give links to experts, regulators and other temporary parties an expiration date that matches their role in the matter. When an expert's engagement ends or a party withdraws, disable their link right away. Access ends without you having to delete documents.

Audit logs record each view, download, email verification and agreement acceptance, with the visitor's email and a timestamp. Use them to show which party had access to which production and when. Export data room visits to CSV for the matter file, and exclude internal visits so your own team's activity does not mix with outside parties. Page-level data room analytics show how long each visitor spent on each document.


If the matter involves EU personal data or a client requires data residency, pick your storage region before you upload anything.
When the matter settles, a production phase ends or the case closes, freeze the data room. Freezing permanently ends all visitor access, archives every link and generates an archive of the documents, the full audit log and all Q&A, with a SHA-256 hash so you can show later that the record has not been changed. Creditor disputes inside a corporate restructuring need a different setup, with one group per creditor class.
| Phase | Who gets access | Settings |
|---|---|---|
| Case preparation | Matter team, co-counsel, client | Data Room Member role, privileged folder for internal groups only, default permissions hidden |
| Production | Opposing counsel | AI redaction before upload, produced folder only, allow list by firm domain, email verification, agreement, watermark |
| Expert and regulator review | Experts, regulators | One group each, view only, printing disabled, expiry date per engagement |
| Resolution | Matter team only | Disable remaining links, export audit logs, freeze the room |
Some controls depend on your plan. See pricing for what each plan includes. To see how Papermark compares with other providers, look at the best data rooms for legal teams.
| Feature | How to set it up |
|---|---|
| Team roles and Data Room Member | Manage team roles |
| SAML SSO and SCIM | Set up SSO and SCIM |
| AI redaction | AI redaction |
| Groups and granular permissions | Groups and granular permissions |
| Default permissions for new documents | Set default permissions |
| Allow list | Create an allow list |
| Block list and global block list | Create a global block list |
| Email verification | Require email verification |
| Agreements and NDA | Add agreements |
| Dynamic watermark | Add a dynamic watermark |
| Download permissions | Allow downloads from a data room |
| Disable printing | Disable printing |
| Screenshot protection | Screenshot protection |
| OTP-verified bulk downloads | Bulk downloads with OTP |
| Link expiration | Set an expiration date |
| Audit logs | Audit logs |
| Export visits | Export data room visits |
| Storage region | Choose your storage region |
| Freeze data room | Freeze a data room |