Private equity and portfolios
Data room checklist: preparing your company's data assets for a sale
By SourceX Editorial · Updated
Short answer
A data room checklist for data assets covers five folders: a records inventory, rights evidence, licensing history, retention and deletion records, and consents with the privacy record. Build it before the banker launches the process, because buyers test data claims with specialists, and an unsupported claim costs more credibility than making no claim at all.
Key takeaways
- Organize data assets into five folders a buyer's data specialist can test without a walkthrough.
- Every data claim in the CIM should point to a specific document in the data room.
- Rights evidence means contract and notice versions mapped to record sets, not a stack of PDFs.
- Disclose prior licenses, pilots and vendor training rights early, because surprises during exclusivity cost more.
- Do not delete old archives just before a sale without checking retention rules and their value.
What belongs in the data folder of a sell-side data room?#
The data folder of a sell-side data room holds five subfolders, each answering a question a buyer will ask about the company's records. Founders who build it before launch control the story; founders who assemble it in response to a diligence request list usually spend the process explaining gaps.
| Folder | Answers the question | Typical contents | Usually prepared by |
|---|---|---|---|
| Records inventory | What records exist and can they be accessed? | System list, record families, date coverage, export routes | COO or IT lead |
| Rights evidence | Does the company have the right to use them? | Customer contract versions, privacy notice history, vendor terms review | Counsel with finance |
| Licensing history | Has anyone else been granted rights? | License register, NDAs with data recipients, vendor AI settings | CFO and counsel |
| Retention and deletion | What has been kept, deleted or held? | Retention schedule, deletion logs, legal holds | Operations with counsel |
| Consents and privacy record | How is personal information handled? | Consent logs, request handling, de-identification notes, incident history | Privacy lead or counsel |
Folder one: the records inventory#
The records inventory lists each system that holds operational records and what a buyer would find inside it. Write one row per system and record family, for example ServiceTitan jobs and invoices, HubSpot deals and emails, Zendesk tickets, NetSuite orders and returns, or Jira issues and pull requests.
Established metadata standards make a useful template. The Data & Trust Alliance's Data Provenance Standards sort dataset metadata under three headings, Source, Provenance and Use, and the specification presents that metadata as what allows datasets to be selected properly for AI model training. Mirroring those groups makes the inventory familiar to technical reviewers on the buyer side.
- System name, business owner and whether the company holds admin access
- Record families and how they link, such as ticket to issue to release
- Earliest and latest dates still accessible, and any gaps from past migrations
- Approximate volumes, stated as ranges where exact counts are not available
- Export route: native export, API, database copy or vendor request
- Known restrictions from customer contracts or vendor terms
Folder two: rights evidence#
Rights evidence shows that the company can use its records for the purposes it claims, and it works best as a map rather than a pile. For each record family, link the customer contract versions, privacy notices and vendor terms that governed it during the years it covers, plus employee notices for email, chat and call recordings and IP assignments for code and documentation.
The Use group of the Data Provenance Standards is a good prompt for what reviewers check here: confidentiality classification, where consent documentation lives, privacy-enhancing technologies applied, processing and storage geographies, license to use, intended data use, and copyright, patent and trademark status. Not every field will apply, but each one you can answer removes a diligence question.
Folder three: licensing history#
Licensing history tells a buyer whether any rights in the records have already been granted to someone else. Include signed data licenses, pilots, evaluation agreements, NDAs under which samples were shared, and declined inbound offers with a short note on why each was declined.
Cover the vendor side too. If a software vendor's AI assistant gained rights to train on company records, document the setting, the dates and any opt-out confirmation. For each license, note exclusivity, field of use, term, assignment and change-of-control language, and any continuing delivery obligations the next owner would inherit.
A simple register beats a folder of contracts. Give each grant one row with the counterparty type, record families covered, date range of records, exclusivity, term, permitted use and the file name of the signed document. A buyer's counsel can read that in minutes and then check only the agreements that matter to their plans.
Folders four and five: retention, deletion and consents#
Retention and consent records show that the company keeps what it should and handles personal information as promised. Include the retention schedule, deletion logs, any legal holds and the dates of major system retirements.
Resist the instinct to clean house by deleting old archives just before a process. Deletion can breach retention obligations, interfere with a legal hold and destroy records a buyer might value. Decide deliberately with counsel and document the decision either way.
For consents, include opt-in and opt-out logs, a description of how privacy requests were handled, any de-identification methods used on internal datasets, and a summary of privacy or security incidents and how they were resolved.
Gaps buyers find most often, and the fix#
The gaps buyers find most often are documentation gaps rather than missing data. Each one below can usually be closed before launch with time and an owner.
| Gap | Why it matters | Fix before launch |
|---|---|---|
| Inventory claims years of history a migration lost | Undercuts credibility of every other data claim | Test exports and state real date coverage |
| No record of which notice governed older data | New uses of older records become uncertain | Rebuild notice history from archives and CMS records |
| Vendor AI training setting never reviewed | Prior grants may limit exclusivity | Review settings, opt out where possible, record dates |
| Licenses filed in email rather than a register | Buyers cannot see exclusivity or obligations | Create a one-page license register |
| Data claims in the CIM with no supporting document | Specialists discount unsupported claims | Link each claim to a folder and file |
Illustrative: a restoration company gets its data folder ready#
Illustrative: a fictional water and fire restoration company is preparing for a sale to a sponsor-backed platform. Its records sit in a job management system, a CRM, a shared drive of moisture logs and photo reports, and an accounting system adopted after a migration.
The founder's team builds the inventory first and discovers that job notes from before the migration exist only as PDF exports. They state that plainly, map customer agreement versions and the privacy notice history to each period, and find that the CRM vendor's AI note-taker had been running with default settings. They switch it off, record the date and add the finding to the licensing history folder. When the buyer's data specialist opens the folder, the questions are about scope rather than credibility.
How SourceX documentation maps to the data room#
A company that has licensed records through the SourceX five-step transaction already holds a SourceX Evidence Packet for each package, covering provenance, licensing rights, permitted use, the privacy record and release authorization. Those packets drop straight into the licensing history and rights folders. For companies that have licensed nothing yet, the metadata-only fit check produces an inventory a founder can reuse in folder one.
Frequently asked questions
When should we start building the data folder?
Start when the exit plan starts, well before a banker is engaged. Contract template changes, notice updates and retention fixes take time to show up in the record, and a buyer will see the dates on every document in the folder.
Should we put sample records in the data room?
Generally not at first. Buyers can assess most data claims from metadata, contracts and documentation. If a buyer needs samples later in diligence, provide a small prepared set under the confidentiality agreement, with personal and confidential details removed.
Do we need to disclose declined data offers?
It is useful context rather than a requirement in most cases. A short note showing the company received and evaluated interest can support a data story, as long as it is factual and any confidentiality terms in the offer are respected.
Who should review the data folder before launch?
Counsel should review rights and licensing documents, the CFO should confirm any license revenue and obligations, and the person who will answer the buyer's data specialist should walk through the whole folder once as a rehearsal.
How much detail does a smaller company need?
Less than a large one, but the same five folders. A founder-led company with a handful of systems can cover the inventory on one sheet and the rights evidence in a short memo with attachments. What matters is that each claim points to a document and that unknowns are labeled as unknown.
Sources
- The Data & Trust Alliance's Data Provenance Standards (version 1.0.0 specification) define dataset metadata in three groups: Source, Provenance and Use. The specification says this metadata is needed "to enable proper dataset selection for AI Model Training." Source
- The Use group of the Data & Trust Alliance Data Provenance Standards includes elements for confidentiality classification, consent documentation location, privacy-enhancing technologies applied, allowed and excluded processing and storage geographies, license to use, intended data use, and copyright, patent and trademark status. Source
Related resources
See if your company qualifies
A short company assessment. No data uploads are needed.