Wind-downs and transitions
Wind-down data room: what to give interested buyers and what to hold back
By SourceX Editorial · Reviewed by Noah Loul ·
Short answer
A wind-down data room for a data license should open with metadata only: systems, record families, date coverage, schemas and a rights summary. Raw records, customer names, employee messages and credentials stay out. Samples come later, privacy-prepared and under written sample terms, once a buyer has signed an NDA and stated its intended use.
Key takeaways
- Open the data room with descriptions of the records, not the records themselves.
- Each stage of disclosure needs a gate, such as a signed NDA, a stated use case or signed sample terms.
- Samples should be small, privacy-prepared and governed by terms that bar training, retention and re-identification.
- Give every qualified buyer the same core materials and keep a written Q&A log.
- Never place system logins, full customer contracts or privileged memos in the room.
What is the metadata-only first rule?#
The metadata-only first rule means a wind-down data room starts with information about the records, not the records themselves. A buyer can judge fit from system names, record families, date ranges, field lists and a rights summary, and none of that exposes customers, employees or trade secrets.
The rule protects the company when protection matters most. Staff who once policed access may be gone, the estate may owe duties to creditors, and a leaked export cannot be pulled back. Starting with metadata also filters out parties who only want to look around.
What to share at each stage#
Disclosure in a wind-down data room works in stages, each with a gate that must be met before the next opens. The table gives a default sequence that the wind-down officer can tighten but should not loosen.
| Stage | Share | Hold back | Gate to the next stage |
|---|---|---|---|
| Initial interest | Company overview, systems list, record families, date coverage and approximate scale in plain terms | Any record content and any customer or employee names | NDA signed and the party's identity verified |
| Qualified interest | Data dictionary, field lists, schema diagrams, rights summary and the preparation plan | Samples and full contracts | Buyer states its intended use and permitted-use needs in writing |
| Sample review | A small, privacy-prepared sample under written sample terms | The full dataset and every excluded category | Sample terms signed and the sample approved by the authorized officer |
| License signed | The prepared delivery defined in the license scope | Everything outside the scope | Release authorization signed by the authorized officer |
Data room checklist: folders to set up#
A wind-down data room checklist keeps the room organized around a buyer's questions rather than the company's old file shares. Set up the folders below and leave each one empty until its gate is met.
- Company and authority: entity status, wind-down or proceeding documents, the board resolution or other approval, and the authorized signer.
- Inventory: systems, record families, years covered and approximate scale, built from the company's data inventory.
- Data dictionary: field names, definitions, code lists and how records link to one another.
- Rights summary: categories of customer contracts, vendor terms reviewed, employee notices and known restrictions, written by counsel.
- Privacy preparation plan: what will be removed or replaced, the tools and human review used, and how results are checked.
- Sample terms and samples: the signed terms first, then the sample itself.
- Q&A log: every buyer question and the written answer given.
- Access log: who opened what and when, exported from the data room platform.
What to hold back, and what to give instead#
Holding back the wrong items is how wind-down disclosures go wrong, so pair each withheld item with a safer substitute. Buyers usually accept a substitute when the reason is stated plainly.
Secret scanning belongs in this step for any code. Open-source tools such as Gitleaks are built to detect passwords, API keys and tokens in git repositories and files, and a scan should run before any code excerpt is placed in the room.
| Hold back | Why | Give instead |
|---|---|---|
| Raw exports | They contain personal and confidential details | Schema now, and a privacy-prepared sample later |
| Customer lists and names | Confidentiality duties and privacy rules | Industry and segment descriptions |
| Employee email and chat | Privacy and possible consent questions | A description of channels, teams and date ranges |
| Full customer contracts | Confidentiality clauses and commercial terms | Counsel's rights summary by contract category |
| Privileged legal memos | Sharing them may waive privilege | Counsel's conclusions, if counsel agrees |
| System logins or API keys | Security and loss of control over the data | Exports prepared by the company |
| Source code with embedded secrets | Leaked credentials and third-party code | Scanned excerpts after secret scanning |
How to share samples without giving the dataset away#
Samples are shared safely when they are small, prepared and bound by terms. A sample should show structure and quality, such as how a request links to a decision and an outcome, without being large enough to be useful on its own.
Automated detection is a first pass, not the last word. The open-source Presidio project, a toolkit for detecting and anonymizing personal data, states in its own documentation that because it uses automated detection there is no guarantee it will find all sensitive information, and that additional protections should be used. Plan a human review of every sample.
- Prepare the sample with the same privacy method planned for delivery, then review it by hand.
- Bar training, fine-tuning, evaluation beyond the agreed review, re-identification and onward sharing.
- Require deletion of the sample and any copies, with written confirmation, if no license is signed.
- Limit access to named reviewers and record who received it.
- Keep the sample inside the data room with downloads switched off where the platform allows.
Illustrative: a consulting firm runs a staged room#
Illustrative: a fictional operations consulting firm is closing after its partners join other firms. Its records include proposals, staffing plans, project review notes and a library of internal playbooks, held in SharePoint, a professional services automation tool and a CRM.
The wind-down officer opened the room with only the inventory, the data dictionary and a rights summary noting that client deliverables were excluded. One interested party asked for raw proposals on the first call; the officer declined and offered a privacy-prepared sample once the party described its intended use and signed sample terms.
Another party never moved past the metadata stage, which cost the firm nothing. The party that proceeded reviewed a sample of project review notes with client names replaced by industry labels, and the license scope was later drafted around those notes and the playbooks.
Running the room after the staff are gone#
Running a data room after the staff are gone falls to the wind-down officer or a named delegate, with counsel answering rights questions. Keep the process consistent: give each qualified party the same core materials, answer questions in writing and add each answer to the shared Q&A log.
Use the platform's controls. Turn on view-only access or watermarking where available, set access to expire, and export the access log at the end. That log, with the NDAs and sample terms, shows creditors, a court or a successor how disclosure was managed.
How SourceX handles disclosure#
SourceX follows the same order. The initial fit check collects metadata, not files, and nothing is shared during that assessment. Samples move only with the supplier's approval and after privacy preparation, as part of the SourceX five-step transaction: Supply, Rights, Preparation, Approval and Delivery.
For packages that proceed, the SourceX Evidence Packet gives a buyer provenance, licensing rights, permitted use, the privacy record and release authorization in one place, which covers much of what a data room would otherwise need to hold.
Frequently asked questions
Do we need an NDA before sharing metadata?
It is good practice. Metadata rarely includes personal details, but it can reveal customer segments, systems and the scale of the business. A short NDA before the inventory and data dictionary are shared keeps the process orderly and gives the company remedies if the information is misused.
How is this different from an M&A data room?
An M&A data room supports buying the company or its assets and usually holds financials, contracts and employee information. A data licensing room is narrower: it supports a license to use specific records, so it centers on inventory, schema, rights and preparation, and keeps the records themselves out until late.
Should every interested buyer see the same materials?
Every qualified buyer should get the same core materials at each stage. In a wind-down, consistent treatment supports the duty to seek fair value for creditors and makes the process easier to defend. Answers to one party's questions can be shared with everyone at the same stage.
Can a buyer keep the sample if no license is signed?
Not if the sample terms are drafted well. The terms should require deletion of the sample and any derived copies, with written confirmation, when talks end. They should also bar using the sample to train or evaluate models beyond the agreed review.
Should the data room include exact record counts?
Approximate scale in plain terms, such as years covered and the systems involved, is usually enough at first. Exact counts can come with the data dictionary once a party is qualified, and they should be checked against the export so the eventual delivery matches what was described.
Sources
- Presidio's own documentation warns that "because it is using automated detection mechanisms, there is no guarantee that Presidio will find all sensitive information. Consequently, additional systems and protections should be employed." Source
- Gitleaks is an MIT-licensed tool for detecting secrets such as passwords, API keys and tokens in git repositories, files and stdin. Source
Related resources
See if your company qualifies
A short company assessment. No data uploads are needed.