Virtual data room security: what to demand for a New Zealand deal

A supplier forwards a draft sale agreement to a competitor. An adviser loses a laptop in the taxi queue at Auckland Airport. A password from a 2019 breach still works. A bidder who dropped out in week three still has a live login in week nine.

Four threats, four different failures. A file-sharing folder answers maybe one of them. A serious virtual data room answers all four, and it keeps the receipts.

This guide is deliberately long because the subject rewards depth. Read it top to bottom before you shortlist a provider, or jump to the table that answers your question. Every NZD figure, every law reference and every trade-off is set out for a New Zealand transaction, not a generic global one.

Which tool actually protects a New Zealand deal?

Start with the decision, not the theory. Most NZ deals come down to one question: is a purpose-built room worth it over the business file-sharing you already pay for?

On security, the gap is not subtle. General file-sharing is built for collaboration and convenience. A data room is built for controlled disclosure and proof. The matrix below is the fastest way to see where each tool class stops short.

Security capability by tool class. Entry and deal-grade rooms vary by provider; confirm specifics before you commit.
Security capabilityConsumer file-sharingEntry-level data roomDeal-grade data room
AES-256 at rest
Enforced MFA for all users
Granular per-file permissions
Dynamic watermarking
View-only with no download
Page-level, tamper-evident audit log
Document expiry and remote revoke
Disclosed data residency choice
Secure, walled Q&A
ISO 27001 or SOC 2 certified

Read the “no” cells top to bottom. Those are the exact features that bite once real diligence starts.

  • Consumer tools are not insecure in the everyday sense. They encrypt, they sync, they back up.
  • What they cannot do is prove controlled access. There is no page-level log, no watermark, no expiry.
  • Entry-level rooms close the biggest gaps: MFA, permissions, view-only, one certification.
  • Deal-grade rooms add the evidence and containment layer: audit depth, residency choice, walled Q&A.

Where is the line? There is no bright rule, but a few thresholds tend to decide it in practice.

  • A sub-$2m asset sale with one buyer and no personal data can survive on business file-sharing.
  • Once you run a competitive process with multiple bidders, walled Q&A and per-party logging stop being optional.
  • Anything with employee records, health data or a regulated counterparty pushes you to a certified room by default.
  • If a bank, an NZX-listed acquirer or an offshore private-equity buyer sits on the other side, they will often mandate a real room anyway.

If your transaction is small and low-risk you might still stretch a business file-sharing plan, and we weigh exactly when a data room is worth it for smaller deals. The same reasoning drives the Dropbox comparison and the Google Drive comparison. Everything after this section is about what “deal-grade” actually means, control by control.

What exactly is virtual data room security?

Strip the marketing and it does three jobs. Nothing more, nothing less.

  • It keeps outsiders out, through encryption, authentication and network controls.
  • It limits what insiders can do, through permissions, watermarking, view-only mode and expiry.
  • It records everything, in an audit log you can export, so access is not just restricted but provable.

A consumer file-sharing folder does the first job passably and the other two barely at all. That gap is the entire reason a data room beats Dropbox for a deal.

The word “security” gets stretched to cover uptime and privacy too, and for a transaction those do overlap. But the core is narrower. It is control and evidence. You decide precisely who can open a document, and you can later show a court, a regulator or a nervous board exactly who did.

Good data room security is defense in depth. Several independent layers, arranged so no single failure becomes a breach.

  • If a password leaks, MFA stops the login.
  • If a login succeeds, permissions limit the blast radius.
  • If a file opens, a watermark deters redistribution and the audit log records it.
  • If anyone questions the whole thing, an independent certification says the inner layers work as claimed.

A defense-in-depth diagram of a virtual data room showing four nested layers from the outside in: independent certification wrapping an audit-log and Q and A evidence layer, which wraps access control with permissions and watermarking, which wraps an encryption and multi-factor authentication perimeter at the core.

Picture the rings from the outside in. The perimeter is encrypted connections and multi-factor authentication, deciding whether you get through the door at all. Inside sits access control: which folders your group sees, and whether you can print or download. Deeper still is the evidence layer, the audit log and the Q&A workflow recording every interaction. Wrapping all of it is independent certification.

The practical upshot: you are not buying one feature called “security”. You are buying a stack, and a weak layer anywhere undermines the strong ones. A room with military-grade encryption but no MFA and no download controls is not secure. It just has a good marketing line.

Which security controls are non-negotiable for an NZ deal?

Here is the baseline. Every row belongs in a deal-grade room as standard, not sold to you as a premium extra.

Where a provider does charge more for these, fold the difference into your total data room cost rather than assuming the sticker price already includes them.

The security baseline to demand for an NZ deal. Confirm current inclusions with each provider.
ControlWhat to demandWhy it matters
EncryptionTLS 1.2+ in transit, AES-256 at restRenders intercepted or stolen data unreadable
AuthenticationEnforced MFA on every accountStops a leaked password becoming a breach
PermissionsView, print, download and expiry per group and per fileLeast privilege; buyers see only their scope
WatermarkingDynamic name, email and timestamp on each pageDeters and traces redistribution of documents
Audit logTamper-evident, exportable, page-levelProvable record of who saw what, and when
Data residencyNamed storage region disclosed in writingMeets Privacy Act obligations for offshore data
CertificationCurrent ISO 27001 and/or SOC 2 reportIndependent proof the controls are real
Access lifecycleInstant revocation and IP or time restrictionsCuts off a departed adviser or a lapsed party

If a salesperson cannot confirm every row of that table in writing, that is your answer. The differentiators between good rooms sit further up the stack, in usability, support and reporting depth. The eight controls above are simply table stakes.

The clearest way to think about them is not as a feature list but as a threat list. Each control exists to stop a specific way a deal leaks.

That mapping is worth committing to memory, because it tells you which control you cannot skip for your particular deal.

How each baseline control answers a specific deal threat.
The threatThe control that answers itWhat it looks like in practice
Stolen laptop or intercepted trafficEncryption in transit and at restTLS 1.2+ on the wire, AES-256 on disk; stolen data is unreadable
Leaked or reused passwordEnforced multi-factor authenticationA second factor blocks a valid password in the wrong hands
Over-shared buyer or adviserGranular permissions and expiryLeast privilege per group; access revoked in one click
Insider downloading on exitWatermarking and audit logEvery page traceable; every download recorded to a named user
Silent tampering after the factTamper-evident, exportable logThe record cannot be quietly edited, and it exports on demand

Encryption: the boring floor, not the differentiator

“Bank-grade” and “military-grade” are marketing words, not standards. What you actually want is specific and dull.

  • TLS 1.2 or higher for data moving between the browser and the server.
  • AES-256 for data sitting on disk.
  • Almost every credible provider clears that bar, so it is a floor to check, not a feature to celebrate.

Two follow-up questions separate the serious rooms. First, who holds the encryption keys, and are they rotated? Provider-managed keys are normal and fine for most deals; some enterprise rooms add customer-managed keys for an extra layer of control. Second, is data encrypted per customer or in one shared pool? Per-tenant separation limits what a single compromise can expose.

Encryption is rarely the weak link. The weak link is almost always a human holding a valid login, which is why authentication and permissions deserve more of your attention than the cipher suite.

Access control: least privilege, done properly

The governing principle is least privilege. Each person sees the minimum they need, and nothing more.

In practice that means permissions set per group and, ideally, per document. On a Tauranga horticulture co-op sale, the buy-side lawyers see the supply contracts, the commercial team sees grower payment data, and neither sees the folders that are not theirs yet.

A capable room gives you a spectrum of rights, not a yes-or-no switch.

  • View-only opens a document in a secure viewer with no way to save it.
  • Print and download are separate toggles you grant deliberately.
  • Fence-view or blur hides part of a page until you release it.
  • Expiry and self-destruct revoke access to a file after a set date, even one already downloaded.

Getting this right starts before access is granted, with a clean folder structure that maps neatly onto your permission groups.

Revocation matters as much as granting. When an adviser rolls off or a bidder drops out, you should cut their access in one click, across every device, at once. Rooms that only let you delete a user, losing their history, rather than suspend them, are a red flag for exactly this reason.

There is a record-keeping angle too. Under the Companies Act 1993 an NZ company must keep proper accounting and corporate records, and a deal room becomes the working copy of many of them during diligence. Suspending a departed user rather than deleting their trail keeps that record intact. On a multi-party auction, a real room lets you run staged disclosure: early bidders see the teaser and financials, the shortlist gets contracts and IP, and only the preferred party reaches the crown-jewel folders. That staging is a security control as much as a commercial one, and it maps directly onto how NZ M&A processes actually run in sectors from SaaS to agribusiness to healthcare.

Why is the audit trail the feature that decides a dispute?

Because a data room’s real product is not storage. It is evidence.

The audit log is a time-stamped record of every login, every document opened, every page viewed and every download, tied to a named user. It turns “we shared it appropriately” into something you can prove.

That evidence earns its keep in three ways.

  • During the deal, it shows which bidders are genuinely engaged, based on what they actually read.
  • At completion, an exported log becomes part of the permanent deal record.
  • In a dispute, or a data-access request, you have a defensible account of who was granted what.

New Zealand’s national cyber agency, CERT NZ, consistently frames logging and access review as core to incident response. A deal room hands you both by default.

The audit log is the one feature nobody thinks about until a deal turns sour, and then it becomes the most important thing in the room.

Dataroom New Zealand Editorial team

Three checks separate a real audit trail from a token one.

  • Look for page-level granularity, not just “opened this file”.
  • Look for tamper-evidence, so the log cannot be quietly edited.
  • Confirm you can export it, to CSV or PDF, without asking support.

Miss any one of those and the log stops being evidence. A record you cannot export is a record you cannot use in a dispute; a record that can be edited is a record no one will trust.

Compare data rooms on security, side by side

See how the providers we track handle encryption, permissions, audit trails and certification.

Compare data rooms

Where is my data stored, and what does the Privacy Act 2020 demand?

Almost every data room stores your files offshore, most often in Australia, the United States or the EU. That is not automatically a problem. Under New Zealand law it is your problem to manage, so you need the answer before you upload.

A data-residency diagram showing a New Zealand deal team uploading files, governed by Information Privacy Principle 12, to a provider data centre in Australia, the United States or the EU, with permissioned, logged and watermarked buy-side access at the far end, and a note that the deal team stays accountable for the data after it leaves the country.

IPP 12 and cross-border disclosure

The Privacy Act 2020 governs how you handle personal information, and a deal room is usually full of it: employee records, customer lists, director details.

Information Privacy Principle 12 sets conditions on sending that information to an overseas party. In short, you have to be satisfied the data will be protected by comparable safeguards. The Office of the Privacy Commissioner explains these cross-border disclosure rules in plain terms, and they apply to you as the party doing the sharing, not just to the software vendor.

The practical steps are simple.

  • Ask the provider to name the storage region in writing.
  • Prefer a room that lets you choose, or at least confirm, the region.
  • If the data is sensitive at a national level, weigh a provider that keeps it in Australia or offers a specific residency guarantee.

For most private-company deals, a reputable provider in a comparable-law jurisdiction is fine. The failure mode is not asking at all. Our companion guide on your Privacy Act 2020 obligations goes deeper.

There is a second angle NZX-listed vendors should note. If the deal touches material information about a listed entity, your continuous-disclosure and confidentiality obligations sit alongside the privacy ones, and a leaky room is a disclosure risk as much as a privacy one. The audit log is what lets you show the information stayed contained until announcement.

Your breach-notification duties

Security is not only about prevention. It also has to make a breach survivable and reportable.

The Privacy Act 2020 introduced a mandatory notifiable privacy breach scheme, and it applies to you as the party running the deal, not only to the vendor. If a breach is likely to cause serious harm, you must notify the Office of the Privacy Commissioner and the affected individuals as soon as practicable.

This is where the audit log stops being a nice-to-have. When something goes wrong, the first question is always “what was actually exposed, and to whom?”

  • A page-level, tamper-evident log lets you answer in hours rather than guess for weeks.
  • That directly shapes whether the harm reaches the “serious” threshold and what you must disclose.
  • A room without that record leaves you notifying on the assumption that everything leaked, because you cannot prove otherwise.

Build the response path before you need it.

  • Know who inside the deal can freeze access and pull the log.
  • Keep the provider’s incident-response contact in writing.
  • Keep their own breach-notification commitments in writing too, since a breach on their infrastructure can become your reporting obligation.

The government’s guidance for businesses on preparing for and responding to a cyber incident is a sensible baseline. It pairs naturally with the containment tools a deal room already gives you: instant revocation, IP restrictions and per-file expiry. Handled well, a scare stays a near miss; handled blind, it becomes a notifiable event you cannot scope.

Do ISO 27001 and SOC 2 actually prove anything?

Yes, and this is where you separate claims from evidence. Any vendor can print “enterprise security” on a web page. A current certificate means an independent auditor checked that the controls exist and are operating.

The two standards answer slightly different questions, and knowing which you are looking at matters.

ISO 27001 and SOC 2 Type II answer different questions. Many serious providers hold both.
ISO 27001SOC 2 Type II
What it certifiesA working information security management systemHow specific controls operated over a period
Question it answersIs there an ongoing security programme?Did the controls actually work, over months?
Time framePoint-in-time certification, audited on a cycleUsually a 6 to 12 month observation window
Output you should ask forThe current certificate, with scope and dateThe full report, not just the summary letter
The trap to avoidAn expired certificate, or a narrow scopeA Type I report (design only) sold as Type II

Read the table left to right and the difference is clear.

  • ISO 27001 certifies that the provider runs a proper information security management system, an ongoing programme rather than a one-off.
  • SOC 2 Type II reports how effectively specific controls operated over a period, usually six to twelve months.
  • The SOC 2 report is arguably the more revealing document, because it covers operation over time, not just design.

Ask for the actual certificate or report, note the date, and check it has not lapsed. Confirm the scope covers the product you are buying, not a sister service. We cover how to read them, and the common traps, in ISO 27001, SOC 2 and VDR certifications explained.

Certification is not a legal requirement for an NZ deal. It is the strongest independent evidence you can get that the controls above are real. For anything involving sensitive or third-party personal data, insist on at least one.

What does deal-grade security cost in New Zealand?

Security is rarely a separate line item. You pay for it bundled into the tier. The practical question is which tier includes the full control set, because entry plans sometimes omit watermarking, granular audit or residency choice.

Here is the rough shape of the market, whether you are running a Dunedin health-tech Series A or a Napier winery sale.

Indicative NZD monthly ranges by tier. Confirm current pricing and exactly which security features each tier includes.
TierIndicative NZD / monthSecurity features typically included
Entry, small deal$150 to $500Encryption, MFA, basic permissions, standard audit
Mid, active diligence$600 to $1,500Granular permissions, watermarking, full audit, secure Q&A
Deal-grade, enterprise$1,500 to $3,000+Residency choice, IP restrictions, both certifications

A stat board comparing three virtual data room tiers by indicative monthly cost in New Zealand dollars: an entry tier at roughly 150 to 500 dollars covering encryption, MFA and basic permissions; a mid tier at roughly 600 to 1,500 dollars adding watermarking, full audit and secure Q and A; and a deal-grade tier at roughly 1,500 to 3,000 dollars or more adding residency choice, IP restrictions and both certifications.

These NZD ranges are indicative only. The trap is buying on headline price and finding watermarking or the exportable audit log sits one tier up.

  • Read the security features against the tier, not the brochure.
  • Check that the certification you were shown applies to the plan you are quoted.
  • Watch for per-page or per-user overage that turns a cheap entry plan into a mid-tier bill once diligence heats up.

What actually drives the number? Three things, and none of them is the encryption everyone asks about first.

  • Data volume and page count. Some providers still price per page or per gigabyte, which punishes document-heavy diligence.
  • Number of users and guests. External-guest seats for bidders and their advisers add up fast on a competitive process.
  • Feature tier. Watermarking, page-level audit, residency choice and IP restrictions are the levers that move you up a band.

A short, single-buyer deal that wraps in six weeks costs very differently from a nine-month competitive auction, even at the same monthly rate, because the room stays open longer and carries more guests. Budget for the duration, not just the sticker.

For a full breakdown of what drives the number, see our NZ pricing guide. If budget is tight, the cheapest rooms for small deals still cover the encryption-and-MFA baseline; you are trading away watermarking, audit depth and residency choice, so make that trade knowingly.

How do I vet a provider, and what do most deals get wrong?

You do not need a security background to run a competent check. You need a short, deliberate process, and the nerve to ask for evidence instead of assurances.

A five-step security vetting process

Run every shortlisted provider through these steps before you upload a single file.

  1. 1

    Ask for the certificate, not the claim

    Request the current ISO 27001 certificate or SOC 2 Type II report, and check the date and scope. A vendor that cannot produce one on request is telling you something.

  2. 2

    Confirm the encryption and MFA specifics

    Get it in writing: TLS 1.2+ in transit, AES-256 at rest, and MFA enforced for every user including external parties. Enforced, not merely available.

  3. 3

    Test the permission model in a trial

    Set up two user groups and prove that view-only, no-download and expiry work as described. Try to break them; a free trial is the time to find the gaps.

  4. 4

    Pin down data residency in writing

    Ask which country stores your data and whether you can choose the region. Match the answer against your Privacy Act 2020 obligations for any personal information.

  5. 5

    Inspect and export the audit log

    Open a document, then confirm the log shows the view at page level, cannot be edited, and exports cleanly to CSV or PDF without contacting support.

A numbered left-to-right process flow of five steps to vet a virtual data room before uploading any file: ask for the certificate rather than the claim, confirm encryption and multi-factor authentication in writing, test the permission model in a trial, pin down data residency in writing, then open and export the audit log.

Run those five in order and you have done more diligence on the room than most vendors do on their bidders.

The controls, though, are usually fine. The habits around them are where deals actually leak. These are the mistakes we see most often on New Zealand transactions.

  • Over-broad permissions. Granting a whole folder tree to a bidder who needed three files is the most common quiet exposure on any NZ deal.
  • Stale access. An adviser who rolled off in week two still has a live login in week eight. Suspend, do not just plan to.
  • Skipping the audit-log export. The one time you need it is the one time you did not test that it works.
  • Uploading raw personal data. Employee files and customer lists that could be redacted or aggregated before they ever enter an offshore room.
  • No named incident owner. When the scare comes, nobody knows who is allowed to freeze access and pull the log.

None of these is a software flaw. Each is a process gap, and each is fixable in an afternoon before the room opens. Read our roundup of data room mistakes that slow NZ deals for the full list, because several of the worst ones are security failures dressed up as admin oversights.

Get those habits right and the eight technical controls do their job. Skip them, and the best-certified room in the market still lets a deal walk out the door.

Work out what a secure room will cost you

Size your deal against real NZD pricing tiers, including the security features that matter.

See pricing

Virtual data room security: frequently asked questions

Is a virtual data room actually secure?
A deal-grade virtual data room is far more secure than general file-sharing because it layers encryption, enforced multi-factor authentication, granular permissions, watermarking and a tamper-evident audit log. No system is unbreakable, but a certified room with least-privilege access and full logging is built precisely to control disclosure and prove it, which consumer tools are not.
What encryption should a data room use?
Look for TLS 1.2 or higher for data in transit and AES-256 for data at rest. Those are the practical standards behind marketing phrases like bank-grade or military-grade. Encryption is a baseline every credible provider meets, so spend more of your attention on authentication, permissions and the audit trail.
Where is my data stored, and does that matter under NZ law?
Most providers store data in Australia, the United States or the EU. It matters because the Privacy Act 2020 makes you responsible for personal information you send offshore, under Information Privacy Principle 12. Ask the provider to name the storage region in writing, and prefer one that lets you choose or confirm it.
Do I need ISO 27001 or SOC 2 for a New Zealand deal?
They are not legally required, but they are the strongest independent evidence that a provider's security controls are real and operating. ISO 27001 certifies an ongoing security management system; SOC 2 Type II reports how controls performed over time. For any deal involving sensitive or third-party data, insist on at least one.
What is the single most overlooked security feature?
The audit log. Everyone checks encryption and forgets logging, yet the tamper-evident, exportable record of who viewed what is your evidence if a deal is ever disputed or a data breach is alleged. Confirm it works at page level and exports without help from support.
How much does a secure data room cost in New Zealand?
Indicatively, entry plans run NZD $150 to $500 a month, mid tiers with watermarking and full audit run $600 to $1,500, and deal-grade plans with residency choice and both certifications run $1,500 to $3,000 or more. Security is bundled into the tier, so confirm which features each price actually includes.
Can I just use a business Dropbox or Google Drive plan instead?
For a very small, low-risk deal you might, since business plans cover encryption and basic sharing. But they lack watermarking, granular per-file permissions, document expiry, walled Q&A and a defensible page-level audit trail. Once real diligence begins, those gaps create genuine risk and slow the deal.