Skip to content

Wind-downs and transitions

Wind-down data room: what to give interested buyers and what to hold back

By SourceX Editorial · Reviewed by Noah Loul ·

Short answer

A wind-down data room for a data license should open with metadata only: systems, record families, date coverage, schemas and a rights summary. Raw records, customer names, employee messages and credentials stay out. Samples come later, privacy-prepared and under written sample terms, once a buyer has signed an NDA and stated its intended use.

Key takeaways

  • Open the data room with descriptions of the records, not the records themselves.
  • Each stage of disclosure needs a gate, such as a signed NDA, a stated use case or signed sample terms.
  • Samples should be small, privacy-prepared and governed by terms that bar training, retention and re-identification.
  • Give every qualified buyer the same core materials and keep a written Q&A log.
  • Never place system logins, full customer contracts or privileged memos in the room.

What is the metadata-only first rule?#

The metadata-only first rule means a wind-down data room starts with information about the records, not the records themselves. A buyer can judge fit from system names, record families, date ranges, field lists and a rights summary, and none of that exposes customers, employees or trade secrets.

The rule protects the company when protection matters most. Staff who once policed access may be gone, the estate may owe duties to creditors, and a leaked export cannot be pulled back. Starting with metadata also filters out parties who only want to look around.

What to share at each stage#

Disclosure in a wind-down data room works in stages, each with a gate that must be met before the next opens. The table gives a default sequence that the wind-down officer can tighten but should not loosen.

What to share at each stage
StageShareHold backGate to the next stage
Initial interestCompany overview, systems list, record families, date coverage and approximate scale in plain termsAny record content and any customer or employee namesNDA signed and the party's identity verified
Qualified interestData dictionary, field lists, schema diagrams, rights summary and the preparation planSamples and full contractsBuyer states its intended use and permitted-use needs in writing
Sample reviewA small, privacy-prepared sample under written sample termsThe full dataset and every excluded categorySample terms signed and the sample approved by the authorized officer
License signedThe prepared delivery defined in the license scopeEverything outside the scopeRelease authorization signed by the authorized officer

Data room checklist: folders to set up#

A wind-down data room checklist keeps the room organized around a buyer's questions rather than the company's old file shares. Set up the folders below and leave each one empty until its gate is met.

  • Company and authority: entity status, wind-down or proceeding documents, the board resolution or other approval, and the authorized signer.
  • Inventory: systems, record families, years covered and approximate scale, built from the company's data inventory.
  • Data dictionary: field names, definitions, code lists and how records link to one another.
  • Rights summary: categories of customer contracts, vendor terms reviewed, employee notices and known restrictions, written by counsel.
  • Privacy preparation plan: what will be removed or replaced, the tools and human review used, and how results are checked.
  • Sample terms and samples: the signed terms first, then the sample itself.
  • Q&A log: every buyer question and the written answer given.
  • Access log: who opened what and when, exported from the data room platform.

What to hold back, and what to give instead#

Holding back the wrong items is how wind-down disclosures go wrong, so pair each withheld item with a safer substitute. Buyers usually accept a substitute when the reason is stated plainly.

Secret scanning belongs in this step for any code. Open-source tools such as Gitleaks are built to detect passwords, API keys and tokens in git repositories and files, and a scan should run before any code excerpt is placed in the room.

What to hold back, and what to give instead
Hold backWhyGive instead
Raw exportsThey contain personal and confidential detailsSchema now, and a privacy-prepared sample later
Customer lists and namesConfidentiality duties and privacy rulesIndustry and segment descriptions
Employee email and chatPrivacy and possible consent questionsA description of channels, teams and date ranges
Full customer contractsConfidentiality clauses and commercial termsCounsel's rights summary by contract category
Privileged legal memosSharing them may waive privilegeCounsel's conclusions, if counsel agrees
System logins or API keysSecurity and loss of control over the dataExports prepared by the company
Source code with embedded secretsLeaked credentials and third-party codeScanned excerpts after secret scanning

How to share samples without giving the dataset away#

Samples are shared safely when they are small, prepared and bound by terms. A sample should show structure and quality, such as how a request links to a decision and an outcome, without being large enough to be useful on its own.

Automated detection is a first pass, not the last word. The open-source Presidio project, a toolkit for detecting and anonymizing personal data, states in its own documentation that because it uses automated detection there is no guarantee it will find all sensitive information, and that additional protections should be used. Plan a human review of every sample.

  • Prepare the sample with the same privacy method planned for delivery, then review it by hand.
  • Bar training, fine-tuning, evaluation beyond the agreed review, re-identification and onward sharing.
  • Require deletion of the sample and any copies, with written confirmation, if no license is signed.
  • Limit access to named reviewers and record who received it.
  • Keep the sample inside the data room with downloads switched off where the platform allows.

Illustrative: a consulting firm runs a staged room#

Illustrative: a fictional operations consulting firm is closing after its partners join other firms. Its records include proposals, staffing plans, project review notes and a library of internal playbooks, held in SharePoint, a professional services automation tool and a CRM.

The wind-down officer opened the room with only the inventory, the data dictionary and a rights summary noting that client deliverables were excluded. One interested party asked for raw proposals on the first call; the officer declined and offered a privacy-prepared sample once the party described its intended use and signed sample terms.

Another party never moved past the metadata stage, which cost the firm nothing. The party that proceeded reviewed a sample of project review notes with client names replaced by industry labels, and the license scope was later drafted around those notes and the playbooks.

Running the room after the staff are gone#

Running a data room after the staff are gone falls to the wind-down officer or a named delegate, with counsel answering rights questions. Keep the process consistent: give each qualified party the same core materials, answer questions in writing and add each answer to the shared Q&A log.

Use the platform's controls. Turn on view-only access or watermarking where available, set access to expire, and export the access log at the end. That log, with the NDAs and sample terms, shows creditors, a court or a successor how disclosure was managed.

How SourceX handles disclosure#

SourceX follows the same order. The initial fit check collects metadata, not files, and nothing is shared during that assessment. Samples move only with the supplier's approval and after privacy preparation, as part of the SourceX five-step transaction: Supply, Rights, Preparation, Approval and Delivery.

For packages that proceed, the SourceX Evidence Packet gives a buyer provenance, licensing rights, permitted use, the privacy record and release authorization in one place, which covers much of what a data room would otherwise need to hold.

Frequently asked questions

Do we need an NDA before sharing metadata?

It is good practice. Metadata rarely includes personal details, but it can reveal customer segments, systems and the scale of the business. A short NDA before the inventory and data dictionary are shared keeps the process orderly and gives the company remedies if the information is misused.

How is this different from an M&A data room?

An M&A data room supports buying the company or its assets and usually holds financials, contracts and employee information. A data licensing room is narrower: it supports a license to use specific records, so it centers on inventory, schema, rights and preparation, and keeps the records themselves out until late.

Should every interested buyer see the same materials?

Every qualified buyer should get the same core materials at each stage. In a wind-down, consistent treatment supports the duty to seek fair value for creditors and makes the process easier to defend. Answers to one party's questions can be shared with everyone at the same stage.

Can a buyer keep the sample if no license is signed?

Not if the sample terms are drafted well. The terms should require deletion of the sample and any derived copies, with written confirmation, when talks end. They should also bar using the sample to train or evaluate models beyond the agreed review.

Should the data room include exact record counts?

Approximate scale in plain terms, such as years covered and the systems involved, is usually enough at first. Exact counts can come with the data dictionary once a party is qualified, and they should be checked against the export so the eventual delivery matches what was described.

Sources

  • Presidio's own documentation warns that "because it is using automated detection mechanisms, there is no guarantee that Presidio will find all sensitive information. Consequently, additional systems and protections should be employed." Source
  • Gitleaks is an MIT-licensed tool for detecting secrets such as passwords, API keys and tokens in git repositories, files and stdin. Source

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify