Audit Logs in Virtual Data Rooms

The audit log is the most under-appreciated part of a virtual data room. It is what defends the disclosure record after closing, what evidences GDPR access controls to a supervisory authority, and what produces the SYSC 8 / DORA / FINMA evidence regulators expect.

A modern European VDR audit log should be append-only (tamper-evident), should capture document-level and page-level events, and should be exportable in machine-readable form for archiving alongside the closing binder.

Published: May 2026. Updated: 19 September 2026.


Events the Log Should Capture

  • User added / removed / role changed.
  • Login / logout, MFA challenge, IP address, geolocation.
  • Document upload / replacement / deletion.
  • Document view (with page-level granularity), download, print attempt.
  • Q&A activity: questions asked, answers, recipients.
  • Permission change: folder, document, group.
  • Watermark / view-only enforcement events.
  • Failed access attempts.

Tamper-Evident Construction

A defensible audit log uses cryptographic hashing: each log entry is hashed with the previous entry's hash, forming a chain. Periodic anchoring of the hash chain to an external time-stamping service (eIDAS qualified time-stamps) raises evidentiary value. Most European VDR providers do at least the first; the leading ones do both.


Page-Level Granularity in Practice

Document-level logging ("bidder X opened file Y") is the common denominator. Page-level logging is what actually answers the questions that arise after closing: whether the bidder reached the page carrying the disclosed liability, and how long they spent on it. Papermark is best for deals where that distinction matters, because page-by-page analytics are the core of the product rather than an enterprise add-on: each view resolves to a named viewer, records time spent per page, and captures downloads and the watermarking and view-only enforcement applied to the session, with the record exportable for the closing binder. Combined with default hosting in ISO 27001-certified data centres in Frankfurt, that keeps the evidence inside the EEA where a European court or supervisory authority expects to find it.

Ask any provider two questions before you rely on the log: is the export machine-readable, and is the chain hash-linked or anchored to a qualified time-stamp. Page-level capture and tamper-evident construction are separate properties, and a provider may have one without the other.


Retention Policy

Audit logs should be retained at least through the contractual claim period in the SPA (typically 2-7 years), the regulatory inspection period (5-10 years), and any GDPR statute-of-limitations period. Retention beyond the strictly necessary should be aligned with the data-minimization principle.


Frequently Asked Questions

Are VDR audit logs admissible in European courts?

Generally yes when produced by an accredited provider with documented controls. Tamper-evident construction (hash chaining + qualified time-stamps) materially strengthens admissibility.

How long should I keep audit logs?

At minimum the SPA claim period plus any regulatory retention. Five to seven years is typical for European M&A; longer for regulated-industry transactions.