From set-up to closure – and the signs a shared folder is no longer enough.
A data room, sometimes called a Virtual Data Room or VDR, is a secure, structured online environment where confidential documents are stored, organised and made available to multiple parties. It is typically set up for a defined piece of work, such as a legal matter or any type of project work.
Many organisations are first introduced to a data room during a transaction or legal matter. This article explains what a data room is, how it operates from initial set-up through to closure, and the indicators that a standard shared folder is no longer sufficient.
What a data room is — and what it isn’t
A data room may at first resemble a conventional shared folder. The difference becomes clear once large numbers of documents are involved. In a data room:
- Documents follow a consistent index — Files and folders follow a clear numbering system, helping a large workspace stay organised so that every party can cite the same file in the same way.
- Access is granted according to responsibility — Each party, internal or external, sees only the content they have been granted. Administrators manage users, permissions and access levels.
- Activity is recorded — Document access and activity, such as checking a document out or document version changes within the data room, are logged, providing a record of who accessed each document and when.
- The workspace has a lifecycle — It is typically set up, used, and then formally closed, with a complete copy available for download at the end for long-term storage or reference.
A general-purpose shared folder, in comparison, can lack structure and control by default. The two are designed for different purposes.
When a data room is needed
Data rooms are typically used for due diligence during a sale or merger, disclosure in legal matters, and audits or regulatory reviews.
Across all of these situations, the indicators are consistent:
- More than one person or organisation needs to work on the same confidential documents.
- Access needs to differ by party, and some parties must be restricted from viewing material belonging to others.
- The document count extends into the hundreds or thousands.
- It may later be necessary to evidence who accessed which documents, and when.
- The work typically has a defined end, and a clear record needs to survive it.
If most of these apply, email attachments and a general-purpose shared drive are usually no longer sufficient. Files become harder to locate, and access becomes harder to restrict and to evidence.
How a data room works, start to finish
The lifecycle is most of the explanation:
- Set-up. Administrators establish the folder structure, the numbering system and the access rules before other participants join.
- Parties join. Internal and external participants are added, each granted access only to the content they need and with the permission level they require, i.e. read only, upload ability or editing rights.
- Active use. Documents are added, reviewed and referenced through a web browser or a dedicated desktop application, while the index keeps documents organised.
- Oversight. Administrators manage users and permissions as the work develops. The folder structure can be reorganised while requirements are still changing, or locked to maintain stability once the structure is agreed.
- Closure. At the end of the project or transaction, administrators can download a complete copy of the data room for long-term storage or reference.
Security and hosting
Because a data room exists for confidential material, the security infrastructure matters as much as the document structure. For AMS Data Rooms, that means encryption applied to data during transfer and while stored using 256-bit AES Encryption, full audit logging of document access and activity, hosting in UK Microsoft Azure data centres, and customer data held in separate storage and databases for isolation. The AMS Secure Cloud platform including AMS Data Rooms can also be branded to reflect your organisation’s branding.
Data room, file transfer, or file share?
A common follow-up question is how a data room differs from the other ways of moving and sharing sensitive files. In brief:
AMS Data Rooms allow you to create a controlled and structured environment and determine who is granted access to it, to what level and the specific content within it. They suit a defined, multi-party piece of work that needs structure, contained access and a complete downloadable copy at the end.
AMS File Transfer is typically used when a file is leaving or coming into your organisation as an encrypted transfer. It can be given a file expiry date and allows you to apply optional controls, such as Digital Rights Management.
AMS File Shares are ongoing shared spaces for collaboration, where all parties can securely share files with functionality such as version control.
Many organisations use more than one, for different tasks.
Keep reading: Keeping control of sensitive data after you hit send.
If a current piece of work shows the indicators above, the AMS Data Rooms page sets out the platform’s structure, security and access controls in more detail.
Was this article helpful?
Thanks — your feedback helps us decide what to write next.