Getting started
Data room checklist for selling a mid-size company
By SourceX Editorial · Updated
Short answer
A data room checklist for selling a mid-size company covers corporate, financial, tax, contracts, people, IP and operations, plus a records and data-rights folder many sellers skip. That folder lists your systems, retention practices, privacy notices, vendor terms and any past data licenses or AI pilots, so data questions are answered before they slow the deal.
Key takeaways
- Organize the data room in folders that match how diligence teams work, with one owner holding the index.
- A records and data-rights folder shows what records exist, what the company may do with them and what it has already agreed.
- Past data licenses and AI pilots need the agreement, a scope summary and proof of how each ended.
- Never upload raw customer, employee or payroll exports; use summaries, redacted samples and a clean team.
- Start the folder early, because vendor terms, deletion certificates and old notices depend on outside parties.
What belongs in a mid-size company data room?#
A mid-size company data room holds the documents a buyer needs to verify what it is acquiring, organized in folders that match how diligence teams work. Clear folders with consistent file names cut down the follow-up questions that slow a process.
Standard sell-side checklists cover something close to the first eight folders below. The ninth, records and data rights, is the one sellers of operating companies most often leave thin, even though an acquirer will plan integration, system migrations and any AI projects around the records it is buying.
Access permissions belong on the checklist too. Early bidders can see summaries, the preferred buyer sees full agreements, and a clean team sees customer-level and pricing detail. Staging access this way protects sensitive information if the deal does not close.
| Folder | Typical contents | Usually prepared by |
|---|---|---|
| Corporate and governance | Formation documents, cap table, board minutes and consents | Corporate counsel |
| Financial | Audited or reviewed statements, monthly reporting, quality of earnings materials | CFO and controller |
| Tax | Income, payroll and sales tax filings, notices and nexus analysis | Tax adviser |
| Commercial contracts | Top customer and supplier agreements, standard terms, change-of-control provisions | Counsel and sales leadership |
| People | Org chart, key employment agreements, benefit plans, handbook | HR lead |
| IP and technology | Trademarks, software licenses, system architecture, security reports | CTO or IT lead |
| Operations | Locations, equipment, key processes, insurance | COO |
| Legal and compliance | Litigation, permits, regulatory correspondence | Counsel |
| Records and data rights | System inventory, retention, privacy notices, vendor terms, data deals | COO or IT lead with counsel |
Records and data-rights checklist#
The records and data-rights folder should let a buyer answer three questions without a meeting: what records exist, what the company is allowed to do with them, and what it has already agreed with others about them. The checklist covers all three.
Keep the inventory consistent with what the IT and finance folders say. A buyer that finds two different lists of systems will ask about both.
- System inventory: each system, its owner, what it holds, how many years are retained and how data can be exported.
- Retention schedule and any legal holds, with notes on records lost or archived during past migrations.
- Current and past privacy notices, with the dates each version was in effect.
- Customer contract terms on confidentiality, data use, data return and deletion.
- Software vendor terms, including any AI training permissions the company accepted or opted out of, with screenshots of admin settings such as HubSpot's AI model training switch.
- Past and current data licenses, AI pilots and design partner agreements, with deletion certificates where they apply.
- Employee policies and notices covering email, chat, call recording and system monitoring.
- Data processing agreements with service providers and a list of subprocessors.
- Security assessments, penetration test summaries and an incident log.
How to document past data deals and AI pilots#
Past data deals and AI pilots should be documented with the agreement, a short summary of scope and status, and proof of how each ended. Buyers read these closely because a license can carry continuing obligations or exclusivity that limit what they can do after closing.
| Document | What the buyer checks | Red flag |
|---|---|---|
| Data license agreements | Scope, term, exclusivity, remaining deliveries, assignment and change-of-control terms | Exclusivity that could bind the buyer's wider group |
| AI pilot and design partner agreements | Training rights, ownership of model improvements, deletion at the end | Perpetual rights to train on company records |
| Vendor AI terms and opt-outs | Whether vendors may train on company data | No record of the decision either way |
| Deletion certificates | Proof that licensed or piloted copies were deleted | A terminated deal with no certificate |
| Evidence of preparation | How personal and confidential details were removed | Raw exports with customer names in the data room |
| License revenue records | How income was booked and recognized | Revenue that does not match the contract terms |
Mistakes that slow diligence#
The mistake that causes the most trouble is uploading raw data. A customer list with contact details, an export of support tickets or a payroll file placed in the room for convenience creates a privacy problem and shows every bidder information it should not see. Share summaries and redacted samples instead, and keep competitively sensitive material for a clean team.
Other common mistakes are a system list that misses retired platforms whose archives still exist, vendor terms nobody has read since signing, and data deals described in one sentence with no agreement attached. Each one turns a document request into a follow-up call.
Illustrative: a 3PL prepares its records folder#
Illustrative: a fictional third-party logistics company is preparing for a sale. Its records sit in a warehouse management system, a McLeod TMS and NetSuite, with older shipment history in a retired WMS that IT kept on a read-only server. Some time earlier, it had run an AI routing pilot with a startup.
Building the records folder surfaces the pilot agreement, which granted the startup a right to train on shipment exceptions with no end date. Counsel asks the startup for a deletion certificate and a written amendment ending future training rights, and both go into the room with a short summary. When the buyer's counsel raises the pilot, the answer is already filed, and the question closes without a renegotiation.
When to start, and who owns the folder#
The records and data-rights folder should be started well before the first outreach to buyers, because several items depend on outside parties. Vendor terms, deletion certificates and copies of old privacy notices all wait on someone else answering.
A COO or IT lead usually owns the inventory, counsel owns the rights documents, and the CFO ties license revenue to the financial folder. One person should hold the index so every document has a home and a status.
How SourceX documentation fits a sale process#
Companies that license data through SourceX already hold much of what this folder needs. Each package goes through the SourceX five-step transaction, Supply, Rights, Preparation, Approval and Delivery, and ends with a SourceX Evidence Packet recording provenance, licensing rights, permitted use, the privacy record and release authorization.
That packet can go into the data room as it stands. A company planning a sale can also ask for licenses to be time-limited and free of exclusivity that could reach an acquirer's other businesses, which makes them simpler to review.
Frequently asked questions
Should a data room include raw customer or employee data?
Generally no. A data room needs enough to verify claims, which usually means summaries, counts, redacted samples and the governing documents. Raw exports with personal data create privacy exposure and show every bidder detail it should not see. Where a buyer needs deeper access, a clean team arrangement under a confidentiality agreement is the usual route.
Does a past data license lower the value of the company?
Not by itself. A documented, time-limited license with clear permitted use and no broad exclusivity is easy to review. Value questions come from surprises: undisclosed exclusivity, open-ended training rights, missing deletion certificates or license income booked in a way the contract does not support.
What is a clean team?
A clean team is a small group, usually outside advisers and a few designated buyer staff, allowed to see competitively sensitive information such as pricing or customer-level data under strict confidentiality terms. It lets diligence go deeper without exposing that information to the buyer's commercial staff before closing.
Do buyers really read software vendor terms?
Careful buyers do, especially for systems that hold customer and operating records. They look for data export rights, what happens on termination and whether the vendor may use the company's data to train AI. A checklist review of each major vendor answers those questions before they are asked.
Should we present our data as an asset in marketing materials?
Only with evidence behind it. Describe record families, years of retained history, the systems involved and whether rights have been reviewed, rather than attaching a value. Buyers discount claims they cannot verify, and an unsupported data story invites diligence questions the records folder then has to answer.
Sources
- HubSpot's knowledge base says customers can use an AI model training switch to control whether HubSpot uses their account's customer data to train its AI models. Source
Related resources
See if your company qualifies
A short company assessment. No data uploads are needed.