Help CenterHow to secure a data room for a corporate development transaction

How to secure a data room for a corporate development transaction

Corporate development deals put your most sensitive material in front of outside parties: acquisitions, divestitures, carve-outs, joint ventures and strategic investments. The counterparty is often a competitor, several bidders may be in the process at once, and advisors on every side need different slices of the room. A leaked customer list or pricing model can hurt the business even if the deal never closes.

This guide walks through the Papermark data room controls that matter most for corporate development, in the order you would set them up.

Quick recap

  1. Limit who on your team can open the room with roles and the Data Room Member role
  2. Verify every visitor's email before they see anything
  3. Restrict access by domain with allow lists, and keep competitors out with block lists
  4. Require an NDA before the first page loads
  5. Give each bidder and workstream its own permissions with groups
  6. Watermark every page with the viewer's email, date and IP address
  7. Stop screenshots and printing on the most sensitive documents
  8. Control downloads, and require a one-time password for bulk downloads
  9. Set expiry dates so access ends when a phase ends
  10. Redact personal data before you upload
  11. Keep questions inside the room with Q&A
  12. Watch activity with page-level analytics and audit logs
  13. Choose where files are stored for data residency
  14. Freeze the room at close and keep a tamper-proof archive

Papermark features used in this guide

FeatureHow to set it up
Team roles and Data Room MemberManage team roles
SAML SSO and SCIMSet up SSO and SCIM
Email verificationRequire email verification
Allow listCreate an allow list
Block list and global block listCreate a global block list
NDA agreementRequire an NDA before viewing
Groups and granular permissionsGroups and granular permissions
Default permissions for new documentsSet default permissions
Dynamic watermarkAdd a dynamic watermark
Screenshot protection and confidential viewScreenshot protection
Disable printingDisable printing
Download permissionsAllow downloads from a data room
OTP-verified bulk downloadsBulk downloads with OTP
Link expirationSet an expiration date
AI redactionAI redaction
Q&A conversationsQ&A conversations
Request listUse the request list
Data room analyticsDetailed data room analytics
Audit logsAudit logs
Storage regionChoose your storage region
Freeze data roomFreeze a data room

1. Limit who on your team can open the room

Corporate development rooms often hold material that most of your own company should not see, such as target valuations, synergy models or a planned divestiture.

  • Use team roles so only the deal team can create links, change permissions or see analytics.
  • Invite integration leads, finance or legal colleagues as Data Room Member. They can work inside the rooms they are assigned to and see nothing else in your workspace. See how to invite team members.
  • If your company uses an identity provider, connect SAML SSO and SCIM so access ends automatically when someone leaves.

2. Verify every visitor's email

Turn on email verification on every link. Visitors receive a one-time code by email before the room opens, so a forwarded link is useless to anyone without access to that inbox. Every view in your analytics and audit log is then tied to a verified person, not just a typed-in address.

3. Restrict access by domain

  • Add an allow list with the counterparty's and its advisors' email domains, for example @acquirer.com and @theirbank.com, so nobody outside those firms can get in even with the link.
  • Add direct competitors and parties you have ruled out to a block list, or to a global block list so they are blocked on every link in your workspace.

When someone is denied access, Papermark notifies you, so you see attempted access instead of guessing.

4. Require an NDA before the first page loads

Attach your confidentiality agreement to the link with NDA agreements. Each visitor must accept it before viewing, and the acceptance is recorded with their verified email and a timestamp. This matters when bidders join at different stages and you need proof of who agreed to what. See also how to add agreements and one-click NDA.

5. Give each bidder and workstream its own permissions

Never share one link with every party. Create a group for each bidder, and one for each workstream on their side (legal, financial, commercial, technical). Then use granular file permissions to decide, folder by folder:

  • which folders each group can see
  • whether each group can view only, or also download

A typical setup shares the teaser and management presentation in the first round, adds financials and contracts for the shortlist, and opens the most sensitive folders (customer contracts, employee data, IP) only to the final bidder's named advisors. Set default permissions for new documents so files you add later stay hidden until you share them on purpose. Read more on granular permissions.

6. Watermark every page

Enable a dynamic watermark on every link. Papermark stamps each page as it is viewed with the details you choose: the viewer's email, the date and time, the link, or their IP address, for example Confidential {{email}} {{date}}. If a page leaks, the watermark shows whose copy it was. See dynamic watermarking.

7. Stop screenshots and printing

For the documents a competitor would value most, such as customer lists, pricing and product roadmaps:

These settings make bulk capture harder, and the watermark still identifies anyone who photographs the screen.

8. Control downloads

Keep downloads off by default, and allow them only for the groups that need offline copies, usually the final bidder's legal and financial advisors. See how to allow downloads from a data room.

If you allow bulk downloads, OTP-verified bulk downloads send a one-time password to the visitor's verified email before the ZIP is built. A forwarded link cannot be used to pull the whole room.

9. Set expiry dates

Give each link an expiration date that matches the phase of the process, for example the end of the first-round bid deadline. Bidders who drop out lose access automatically, without you having to remember to revoke it. You can also disable a link at any time.

10. Redact personal data before you upload

Employee files, customer contracts and HR records carry names, emails and account numbers that the counterparty rarely needs before signing. Use AI redaction to find and black out personal data before documents go into the room. This reduces GDPR exposure and lowers the stakes if anything leaks. See also GDPR compliance.

11. Keep questions inside the room

Use Q&A conversations so bidders ask questions next to the document they are about, instead of over email. Questions and answers stay inside the room's access controls, and you have a complete record when the deal closes. To collect documents from the other side, use the request list.

12. Watch activity

  • Page-level analytics show which bidder read which documents, and for how long. A sudden spike on customer contracts, or a bidder that never opens the financials, tells you a lot about their intent.
  • Audit logs record views, downloads, email verifications and NDA acceptances, which you need for the deal file and for any later dispute.
  • Export data room visits to CSV for your records.
  • Exclude internal visits so your own team does not distort the numbers.

13. Choose where files are stored

If the transaction involves EU entities or your legal team requires data residency, pick your storage region before you upload anything.

14. Freeze the room at close

When the deal signs, closes or is abandoned, freeze the data room. Freezing permanently ends all visitor access, archives every link and generates an archive of the documents, the full audit log and all Q&A, with a SHA-256 hash so you can prove later that the record has not been changed.

PhaseWho gets accessSettings
Teaser and NDAAll approached partiesEmail verification, NDA, watermark, no downloads, short expiry
First roundBidders who signed the NDAOne group per bidder, allow list by domain, screenshot protection on sensitive folders
Confirmatory due diligenceShortlisted bidder and advisorsWorkstream groups, downloads only for named advisors, OTP bulk downloads, Q&A
Signing and closeDeal team onlyExpire bidder links, export audit logs, freeze the room

Some controls depend on your plan. See pricing for what each plan includes.

More helpful articles