Skip to content
Find my data room
Data room terms / Security and compliance

GDPR

The short version

The EU's privacy law since 2018. It applies whenever a deal room holds information that identifies people in the EU, or is run by an organization established there, which in practice means most HR folders and many customer lists.

How it plays out on a deal

HR files, customer lists and email archives all contain personal data. If any of it concerns people in the EU, sharing it through a data room is processing under GDPR, and the room provider acts as a processor on the seller's behalf.

In practice that means a data processing agreement, clarity on where the data is stored and who can reach it, and a plan to minimize what is shared. Redacting or pseudonymizing employee data before the confirmatory stage is common and well worth the effort.

What to check in a review or demo

  1. 1Whether a GDPR-compliant data processing agreement is offered as standard.
  2. 2Where data is stored, and how transfers outside the EU are covered.
  3. 3Which sub-processors the provider uses and how changes are announced.

Read alongside

Where this comes up on Data Room Review