EU data room country directory 2026: what changes from market to market
Across the EU, the data room requirements that change by country are language, registry documents, investment screening and financial supervision. What does not change is the GDPR, the case for EU hosting, and the core workflow: NDA before access, staged release, group permissions, watermarking and an exportable audit log.
This page is a directory rather than a ranking. It sets out the selection considerations that genuinely differ from market to market, groups the European markets covered on this site into regions, and links each one to its full country guide. The country guides carry the local detail on M&A context, national regulators and the providers used locally. This page carries the layer above them: how to reason about a market you have not transacted in before, and which questions to ask before the room opens.
It is written for buyers, sellers and advisers who work across borders and therefore have to make the same decision repeatedly under different national conditions. If you already know the country, go straight to its guide. If you are choosing between markets, or building a room that spans several of them, read the framework sections first.
Published: July 2026. Updated: 30 July 2026.
How to use this directory, and what actually varies between EU markets
The single most useful thing to understand about European data rooms is how much is already common. Every EU member state applies the same General Data Protection Regulation, participates in the same merger control architecture, is subject to the Digital Operational Resilience Act where financial entities are involved, and is working through the same NIS2 cybersecurity directive. A data room that satisfies a German buyer's privacy counsel will satisfy a Portuguese one, because they are applying the same regulation. That commonality is why a single platform can serve a pan-European process, and it is why the provider decision is usually not country-specific.
What varies is everything below the EU layer. Company registries differ in what they contain and how accessible they are. Several member states require a notarial deed for a share transfer, which makes the notarial file a first-class diligence document rather than an administrative afterthought. Employment law, works council consultation and collective bargaining coverage vary enormously and change both the timetable and the sensitivity of the employment folder. Language expectations range from fully English-comfortable markets to markets where statutory and employment documents must exist in the national language as a matter of law. And every member state now operates or is building an investment screening mechanism, each with its own trigger and its own filing authority.
There is a fourth variable that gets less attention than it deserves: how documents physically arrive. In a carve-out from a listed group, the seller delivers a clean digital set from a document management system with consistent naming and reliable metadata. In a founder-led succession sale, which is the dominant deal type across large parts of Europe, the seller may deliver scanned paper, phone photographs and files named in a way that made sense to one person. The difference is not a quality judgement about the market, it is a function of what kind of company is being sold, and it determines whether the first fortnight in the room is spent indexing or reviewing. Ask the question before the room opens rather than discovering the answer in it.
This directory is organised so you can answer three questions quickly. First, what should I expect from documents and language in this market. Second, what regulatory filings might sit on top of the transaction. Third, where do I go for the detail. Every market section links to its full country guide on this site, and those guides carry the local M&A context and the providers used there. Nothing on this page repeats them.
- Common across the EU: GDPR, merger control architecture, DORA for financial entities, NIS2 in transposition, EU public procurement rules.
- Varies by country: company registry content and access, notarial requirements, employment and works council duties, language obligations, investment screening triggers and authorities.
- Usually not country-specific: the platform decision itself, provided hosting sits in the EU and the workflow supports NDA enforcement, group permissions, staged release, watermarking, Q&A and audit export.
- Always country-specific: who you ask. Local counsel in each jurisdiction, every time.
Five questions that decide the data room in any European market
Before opening a country guide, it helps to know what you are looking for. The same five questions determine the right answer in every European market, and the country layer simply changes the weight each one carries. Working through them in order takes about twenty minutes and prevents the most common failure, which is choosing a platform on features and discovering a constraint on hosting, language or timing after the room is half built.
The questions are deliberately blunt. They are not a scoring matrix, and they do not produce a single winner. What they produce is a shortlist of two or three platforms that can actually do the job, which is the point at which price, familiarity and support quality become the deciding factors rather than the opening ones.
Note the order. Hosting and compliance come first because a failure there is disqualifying and cannot be worked around. Timeline comes second because it eliminates whole categories of vendor. Only then do workflow and commercial terms matter.
- Where must the data sit, and can the vendor prove it? For any EU transaction, EU or EEA hosting removes the international transfer analysis entirely. Ask for the hosting location, the sub-processor list with locations, and a signed data processing agreement, and expect to receive them as documents rather than as assurances.
- Is a regulated financial entity involved? If a bank, insurer, investment firm, payment institution or crypto-asset service provider is a party, the room is an ICT third party arrangement under DORA, and the contract needs prescribed terms on data location, audit rights, incident notification, sub-outsourcing and exit.
- When does the room have to be live? A four-week procurement cycle is fine for a planned carve-out and fatal for a founder sale with an exclusivity deadline. Self-service availability and published pricing are decisive at the fast end and irrelevant at the slow end.
- What does the workflow actually need? Count the bidder groups, the advisory firms, the languages and the phases. Then check specifically: NDA enforcement before access, folder- and file-level permissions per group, staged release between phases, a permission-based Q&A module, dynamic watermarking, download and screenshot controls, and an audit log that exports at user and document level.
- What will this cost under your usage pattern, not the vendor's example? Model the total across the whole engagement. Per-user pricing punishes adviser-heavy auctions. Per-page or per-gigabyte pricing punishes technical and real estate rooms. Per-project pricing punishes buy-and-build programmes running several rooms a year.
Germany, Austria and Switzerland: notarial deeds, works councils and the deepest compliance expectations in Europe
The German-speaking markets share three characteristics that shape a data room more than anything else in Europe. The first is the notarial layer: a transfer of shares in a German or Austrian limited liability company requires a notarial deed, which makes the notarial file a core diligence document and means the corporate folder must contain a complete, dated chain rather than a summary. The second is co-determination and works councils, which turn the employment folder into a timetable item, because consultation obligations can gate announcement and closing. The third is a security review culture that is more document-driven and more detailed than most of Europe, particularly among Mittelstand corporates, banks and insurers.
That third point drives a specific expectation. DACH reviewers ask for artefacts: certification scope statements, penetration test summaries, sub-processor lists, incident response descriptions and exit and deletion processes. In Germany, the BSI C5 catalogue is frequently used as a reference framework for cloud service assurance even where it is not strictly required, and being asked about it is normal rather than a signal that something is wrong. Financial counterparties add BaFin's outsourcing expectations, which track the European supervisory guidelines.
Switzerland sits outside both the EU and the EEA, which changes the analysis rather than complicating it. Swiss data protection runs under the revised Federal Act on Data Protection supervised by the Federal Data Protection and Information Commissioner, and the country benefits from an EU adequacy decision, so transfers between the EU and Switzerland do not require the additional safeguards that a genuine third country would. Swiss financial counterparties bring FINMA outsourcing expectations, which are detailed and take bank secrecy seriously.
Germany
Europe's largest deal market by volume, with a pipeline dominated by industrial carve-outs, Mittelstand succession and private equity secondaries. Corporate records sit in the Handelsregister. Share transfers in a GmbH require notarial recording, so the notarial deed chain belongs in the corporate folder from day one. Works council consultation is a real timetable constraint and the employment folder is correspondingly sensitive. Foreign investment screening runs through the federal economics ministry under the foreign trade legislation, with sector-specific and cross-sector thresholds. Data protection supervision is split between the federal commissioner and the state authorities, which means the applicable regulator depends on where the controller is established.
Full detail: virtual data rooms in Germany.
Austria
A smaller market with a strong industrial and CEE-facing profile, since many Austrian groups hold Central and Southeastern European operations that come with the target. Corporate records sit in the Firmenbuch, GmbH share transfers require a notarial deed, and works council structures resemble the German model. Financial supervision runs through the FMA and data protection through the Datenschutzbehoerde. For a buyer, the practical point is that an Austrian target frequently brings a multi-country CEE subsidiary set, so plan the room for more jurisdictions than the headline suggests.
Full detail: virtual data rooms in Austria.
Switzerland
Outside the EU and the EEA, with its own data protection regime and an EU adequacy decision that keeps transfers straightforward. Strong in pharmaceuticals, medical technology, precision manufacturing, commodities trading and financial services. FINMA outsourcing expectations apply where a supervised institution is involved, and banking secrecy makes client data handling a live issue in any financial services transaction. Multilingual by construction, with German, French and Italian all in official use.
Full detail: virtual data rooms in Switzerland.
France, Belgium, the Netherlands and Luxembourg: language law, notarial transfers and a fund domicile
This grouping is heterogeneous, but it shares one theme worth understanding up front: language is a legal question here rather than a convenience question. France requires employment documentation to be available in French, and Belgium's language legislation is stricter still, with the language of employment documents determined by the region in which the employee works. A room that holds only English versions of employment material in these markets is not merely inconvenient; it may be holding documents that are not effective against the employee.
The second theme is the notarial layer again. Transfers of shares in a Dutch BV require a notarial deed executed before a Dutch civil law notary, and Luxembourg has its own formalities depending on entity type. As in Germany, this means the corporate folder needs a complete chain of executed deeds and the notary becomes a participant in the transaction rather than an administrative step at the end.
The third is Luxembourg's role as a fund and holding domicile. A very large share of European private equity and real estate structures runs through Luxembourg vehicles, which means a Luxembourg entity frequently appears in the ownership chain of a target whose operations are somewhere else entirely. For the data room, that shows up as a separate holding structure folder containing entity documentation, financing arrangements and substance evidence, and as a CSSF dimension whenever a supervised entity is involved.
France
A large, professionally intermediated market with strong activity in industrials, luxury goods, healthcare, technology and infrastructure. Corporate records run through the national business register, with the extract familiar to practitioners as the Kbis. Employee information obligations apply on the sale of smaller companies and are a genuine process constraint. Works council consultation through the social and economic committee affects timetable. Investment screening is administered by the Treasury with sector lists set by decree, and France has been among the more active European screeners. CNIL is the data protection authority and is one of Europe's more assertive; the AMF and the ACPR supervise markets and banking respectively.
Full detail: virtual data rooms in France.
Belgium
A mid-sized market with chemicals, logistics, pharmaceuticals, food and a substantial family business community. The Crossroads Bank for Enterprises is the corporate registry. The distinctive constraint is language: Dutch, French and German all have official status, and employment documents must generally follow the language of the region where the employee works, which means a Belgian employment folder can legitimately require documents in more than one language for the same group. Belgium introduced a foreign investment screening mechanism operating across its federal and regional authorities, which adds a coordination step that buyers should scope early.
Full detail: virtual data rooms in Belgium.
Netherlands
An efficient, English-comfortable market with strong technology, logistics, agrifood and energy activity, and a deep private equity community. Corporate records sit in the KVK trade register. BV share transfers require a notarial deed. The Vifo Act introduced a national security investment screening regime administered by the investment screening bureau, covering vital providers and sensitive technology, and it applies to a broader range of transactions than many buyers expect. The AP supervises data protection; the AFM and DNB supervise markets and prudential matters.
Full detail: virtual data rooms in the Netherlands.
Luxembourg
Small as an operating market and enormous as a domicile. Most European fund, holding and securitisation structures touch it, so a Luxembourg entity appears in ownership chains far more often than Luxembourg appears as a target jurisdiction. The CSSF supervises the financial sector and its outsourcing circulars are detailed and specific, which matters directly when a data room is used by a supervised entity. The CNPD is the data protection authority. Expect a dedicated holding structure folder and expect substance documentation to be requested.
Full detail: virtual data rooms in Luxembourg.
Italy, Spain, Portugal and Greece: golden power, notarial formality and longer timetables
Southern European processes tend to run longer than Northern European ones, and the reasons are structural rather than cultural. Corporate histories are often longer and more amended, real estate is more frequently held directly and carries planning and cadastral complexity, employment protections are strong and consultation obligations real, and the notarial and registry formalities add steps that cannot be compressed. A buyer used to a six-week Dutch confirmatory diligence should plan for materially more in Italy or Greece.
The regulatory feature that most affects deal structuring is investment screening, and Italy is the most consequential example in Europe. The Italian golden power regime is broad in scope, has been extended repeatedly, and is used actively across strategic sectors including energy, transport, communications, defence, finance, health and technology. Filings are common, and the analysis is not confined to non-EU buyers. Spain operates a prior authorisation regime for certain investments by investors from outside the EU and EFTA, with implementing detail set out in a 2023 royal decree, and it too is used in practice.
The document consequence is consistent across all four markets: build the regulatory section early and make it counsel-controlled, and expect the corporate folder to be deeper than a Northern European equivalent because the chain of amendments, notarial deeds and registry filings is longer.
Italy
A large market with industrial districts, luxury, food and beverage, machinery, pharmaceuticals and a substantial family business succession pipeline. Corporate records sit in the Registro delle Imprese held by the chambers of commerce. Transfers of quotas in an srl involve notarial or authorised professional formalities, and the corporate chain matters. The golden power regime is the defining regulatory feature and should be scoped in the first week rather than the last. The Garante supervises data protection and has been among Europe's more visible enforcers; CONSOB and the Bank of Italy supervise markets and banking.
Full detail: virtual data rooms in Italy.
Spain
A large market with strong renewables, infrastructure, hospitality, food, healthcare and technology activity, and a very active infrastructure and energy transaction pipeline. Corporate records sit in the Registro Mercantil, and transfers of shares in an SL are made by public deed before a notary. The foreign investment regime requires prior authorisation for certain investments by non-EU and non-EFTA investors, with implementing detail set out by royal decree. The AEPD supervises data protection and the CNMV supervises securities markets.
Full detail: virtual data rooms in Spain.
Portugal
A smaller market with growing technology, renewables, tourism and real estate activity, and increasing interest from Spanish and wider European acquirers. Corporate records run through the commercial registry. The CNPD supervises data protection and the CMVM supervises securities markets. Portuguese processes are typically well organised and English-comfortable at the adviser level, with statutory documentation in Portuguese.
Full detail: virtual data rooms in Portugal.
Greece
A market that has rebuilt substantially, with activity in energy and renewables, tourism and hospitality, shipping, logistics, banking and non-performing loan portfolios. Corporate records sit in the general commercial registry. Shipping deserves separate mention: Greek shipping transactions involve vessel documentation, classification records and financing arrangements that make the technical folder unusually large, and they frequently involve non-EU counterparties. The Hellenic Data Protection Authority supervises data protection.
Full detail: virtual data rooms in Greece.
Sweden, Denmark, Norway and Finland: four screening regimes and one EEA complication
The Nordic markets are the most operationally straightforward in Europe for an outside buyer, and the most legally fragmented relative to how similar they look. English is the working language of the transaction layer, processes are professionally run, and documentation quality is generally high. Underneath that, there are four separate data protection authorities, four separate financial supervisors and four separate investment screening regimes, and Norway is in the EEA rather than the EU.
That last point is the one that causes contract errors. A hosting clause that says European Union rather than European Economic Area either excludes Norwegian counterparties or creates an argument about breach. It also affects timing: EU regulations reach Norway only after incorporation into the EEA Agreement, so DORA and NIS2 do not arrive on the same schedule as in Sweden, Denmark and Finland.
The other Nordic characteristic worth planning for is deal norms. The locked box is the preferred purchase price mechanism, warranty and indemnity insurance is routine, and vendor due diligence is standard. Together those three shift work to the front of the process and put more weight on the completeness of the room at launch than on what gets added during diligence.
Sweden
The largest Nordic market. Screening runs through the Inspectorate of Strategic Products under legislation in force since December 2023, and unusually the filing obligation extends to Swedish and other EU investors. IMY supervises data protection and Finansinspektionen supervises financial markets. Foundation and family ownership structures make the corporate history section deeper than buyers expect.
Full detail: virtual data rooms in Sweden.
Denmark
Strong in life sciences, medtech, industrial technology and shipping. Screening runs through the Danish Business Authority under an act in force since 2021, with a mandatory authorisation track for sensitive sectors and a voluntary cross-sectoral notification track for legal certainty elsewhere. Life sciences targets bring clinical and regulatory documentation containing personal data, which makes pre-upload redaction a requirement rather than a nicety.
Full detail: virtual data rooms in Denmark.
Norway
EEA rather than EU. Energy, offshore renewables, shipping and aquaculture dominate, and those deal types produce the largest technical document sets in Europe outside heavy infrastructure. Ownership control runs through the Security Act. Test platform performance on real technical files before committing, because file size, not features, is what breaks Norwegian rooms.
Full detail: virtual data rooms in Norway.
Finland
Screening runs through the Ministry of Economic Affairs and Employment on a voting rights basis with no financial thresholds, and defence and security undertakings require mandatory pre-closing approval. A separate Ministry of Defence permit regime can apply to real property acquisitions by buyers from outside the EU and EEA. Finnish is not mutually intelligible with the other Nordic languages, so budget translation separately.
Full detail: virtual data rooms in Finland.
Poland, Czechia, Slovakia and Hungary: registry depth and translation budgets
The Visegrad markets are where the gap between the EU legal layer and the national document layer is widest. Everything above the national line is familiar: same GDPR, same merger control, same DORA. Everything below it requires local knowledge, and the biggest single line item a Western buyer underestimates is translation.
Poland is the largest M&A market in Central and Eastern Europe and the most institutionalised. Its distinctive requirements are the full historical extract from the National Court Register rather than the current extract, an unbroken chain of share transfers executed with notary-certified signatures for title in a limited liability company to pass, and the land and mortgage register for any transaction involving real property. Its investment screening regime was made permanent in July 2025 for investors from outside the EEA and OECD, with review moved to the Ministry of Finance and Economy.
The Czech Republic is the region's second market with a strong domestic capital base and a well digitised commercial register. Slovakia shares Czech legal heritage with a thinner sponsor base and heavier automotive exposure. Hungary produces smaller volumes with a more interventionist screening posture than most of the region, which makes early confirmation of the filing position more important there than in Prague or Warsaw.
Poland
The regional leader on both volume and value, with a deep advisory market, an active domestic private equity community, a functioning public equity route through the Warsaw Stock Exchange, and a substantial founder succession pipeline. Statutory documents are Polish only, and translation should be managed in three tiers: machine translation for triage, professional translation for anything relied on to price, and sworn translation only where a document goes to a Polish authority or court. UODO has become one of the region's more active data protection supervisors.
Full detail: virtual data rooms in Poland.
Czech Republic
Industrial mid-caps, automotive supply, energy, banking, gaming and software, with several large domestic investment groups acting as regional and pan-European acquirers. The commercial register is well digitised and includes filed financial statements, which speeds early verification. UOOU supervises data protection and the Czech National Bank supervises financial markets.
Full detail: virtual data rooms in the Czech Republic.
Slovakia
Smaller than Czechia with shared legal heritage, so Czech and Slovak counsel frequently cover both. Automotive supply chain exposure is proportionally large, which pushes weight onto customer concentration analysis and industrial diligence. Euro area membership removes a currency layer that persists in Poland, Czechia and Hungary.
Full detail: virtual data rooms in Slovakia.
Hungary
Concentrated in industrials, energy, pharmaceuticals and real estate, with deal values that swing sharply on individual transactions. Screening has been used more actively than in several neighbouring states, so confirm the filing position with Hungarian counsel early rather than assuming an EU buyer is automatically clear. NAIH supervises data protection and the MNB supervises financial markets. Hungarian is unrelated to the neighbouring languages and needs its own translation resource.
Full detail: virtual data rooms in Hungary.
Romania, Bulgaria, Croatia and Slovenia: longer paper trails, growing volumes
Southeastern EU markets share a characteristic that shows up immediately in a data room: corporate histories that pass through privatisation and post-privatisation restructuring, producing long document trails that are frequently paper-based and inconsistently organised. That is not a quality problem so much as a scheduling one. Budget more time for scanning, optical character recognition and indexing than an equivalent Western European process would need, and insist on OCR at upload so the historical set becomes searchable rather than merely present.
The second shared characteristic is that these markets are growing in professionalism faster than their reputation suggests. Romania in particular now sustains a maturing private equity ecosystem and a growing pool of regional strategic buyers, and processes are increasingly run to international standards. Croatia and Slovenia are both euro area members, which removes a currency variable, and Slovenia has an unusually high concentration of technically sophisticated manufacturers for its size.
For all four, the practical room design advice is the same: establish a naming convention before the first upload, index bilingually with English descriptive titles alongside original language titles, and flag explicitly which documents exist only as scans of paper originals, because that is precisely what a buyer's counsel needs to know when assessing whether a chain of title or corporate approvals can be evidenced.
Romania
Consistently third in the region by transaction count, diversifying from real estate and retail into healthcare, energy, agriculture, technology and business services. Corporate records run through the national trade register office and land records through the national cadastre. ANSPDCP supervises data protection. Expect the longest paper trails in this grouping.
Full detail: virtual data rooms in Romania.
Bulgaria
Smaller and more concentrated, with meaningful activity in energy, business services and outsourcing, technology and real estate. The commercial register is digitised and reasonably accessible, which makes early verification easier than in some neighbouring markets.
Full detail: virtual data rooms in Bulgaria.
Croatia
A euro area member with a tourism-heavy economy, meaningful real estate and hospitality transaction flow, and growing technology activity. Court register records are the corporate source and AZOP supervises data protection. Coastal real estate brings its own title and concession complexity, which belongs in a dedicated folder.
Full detail: virtual data rooms in Croatia.
Slovenia
Small, euro area, and unusually industrial for its size, with strong pharmaceutical, automotive component and precision manufacturing sectors. Business register records are accessible and the market is professionally served. Expect technically deep manufacturing diligence rather than volume-driven document sets.
Full detail: virtual data rooms in Slovenia.
Estonia, Latvia and Lithuania: the easiest documents in Europe, the smallest deals
The Baltic states are the most digitally mature markets in the EU for transaction purposes, and for an outside buyer they are usually the least friction-heavy. Corporate documentation exists natively in digital form, registries are accessible online, qualified electronic signature under the eIDAS framework is normal rather than exceptional, and English proficiency in the business and advisory community is very high. A Baltic diligence exercise that would take three weeks of document gathering in Southeastern Europe can take three days.
The counterweight is scale. Transaction sizes are small enough that heavy enterprise procurement is disproportionate, and the local advisory market is small enough that the same firms appear repeatedly. That argues strongly for platforms with published pricing and same-day availability, and against anything requiring a lengthy quote cycle for a transaction that may complete in eight weeks.
Nordic ownership is the other structural feature. Nordic banks, industrial groups and sponsors hold substantial positions across the Baltic economies, so a Baltic target frequently comes with a Nordic parent, Nordic financing or a Nordic buyer, which pulls Nordic procurement expectations into a Baltic process.
Estonia
The most digitised of the three, with e-government infrastructure that makes corporate records and electronic signature genuinely routine. Strong technology and financial technology activity relative to population. A platform that forces a print-sign-scan cycle looks dated to an Estonian counterparty.
Full detail: virtual data rooms in Estonia.
Latvia
Mid-sized among the three, with logistics, forestry, manufacturing and financial services activity. Digital maturity sits between Estonia and Lithuania, and registry access is straightforward.
Full detail: virtual data rooms in Latvia.
Lithuania
The largest of the three by recent deal activity, with a significant financial technology cluster built on an accommodating licensing regime, plus manufacturing, lasers and life sciences. Financial technology targets bring regulatory correspondence and licensing documentation that belongs in a dedicated regulatory folder.
Full detail: virtual data rooms in Lithuania.
Ireland and the United Kingdom: common law, English documents, one border
Ireland and the United Kingdom are grouped here because they share common law heritage, English-language documentation and a similar transaction style, and because most cross-border processes involving one frequently involve the other. The critical difference is EU membership: Ireland is an EU member state and the United Kingdom is not.
For a data room, that difference is entirely about personal data transfer. Ireland is inside the EU, so an EU-hosted room raises no transfer question at all. The United Kingdom is a third country from the EU's perspective and relies on adequacy decisions that are subject to periodic review and renewal. Those decisions have been extended and renewed since Brexit, and the sensible practice is to confirm the current position rather than to assume it, and to keep an EU-hosted room with UK access rather than the reverse where the choice is available.
Ireland's other distinctive feature is the concentration of multinational technology, pharmaceutical and medical device operations, which means an Irish target frequently sits inside a much larger international group. That produces intra-group agreements, transfer pricing documentation and shared services arrangements that need their own folder, and it means the data protection analysis often involves the Data Protection Commission acting as lead supervisory authority for a group operating across the EU.
Ireland
An EU member state with a disproportionate concentration of multinational technology, pharmaceutical and medical device operations, plus an active domestic mid-market. Corporate records sit with the Companies Registration Office. The Data Protection Commission is frequently the lead supervisory authority for major technology groups, which raises the profile of data protection diligence. Ireland brought a mandatory investment screening regime into operation in 2025 for transactions involving third country undertakings in sensitive areas.
Full detail: virtual data rooms in Ireland.
United Kingdom
Outside the EU, with UK GDPR supervised by the Information Commissioner's Office, the Financial Conduct Authority supervising financial services, and Companies House as the corporate registry. The National Security and Investment Act regime is mandatory for specified sensitive sectors and is used actively. For cross-border processes, keep the personal data transfer position documented and prefer EU hosting with UK access where the choice exists.
Full detail: virtual data rooms in the United Kingdom, and for the transfer mechanics see cross-border VDRs between the EU and the UK.
Data residency: where the room should sit, and why the answer is usually the same
Across every market in this directory, the hosting question has a default answer: put the room in the EU or the EEA. The reason is not that other locations are unlawful. It is that EU or EEA hosting removes an entire workstream. There is no transfer analysis to perform, no transfer impact assessment to draft, no standard contractual clauses to negotiate and attach, and no argument to have with a counterparty's privacy function about whether a foreign government access regime creates a risk. On a deal timetable, removing a workstream is worth more than winning an argument about it.
The nuance is the geographic term you use. For a process involving Norway, Iceland or Liechtenstein, the correct term is European Economic Area rather than European Union. For a process involving Switzerland, the EU adequacy decision means transfers are straightforward, but the Swiss data protection regime is its own and a Swiss counterparty may want its terms addressed explicitly. For a process involving the United Kingdom, adequacy decisions govern and are subject to review, so document the current position rather than assuming permanence.
A third point applies specifically to public sector and state-owned counterparties, which appear more often in European transactions than in some other regions because of the scale of public ownership in utilities, transport, healthcare and infrastructure. Those counterparties frequently add requirements that go beyond the GDPR analysis: questions about the jurisdiction of the contracting entity itself, about whether any non-EEA parent could be compelled to disclose data, and about where the vendor's own corporate control sits. Those questions are not answerable by pointing at a data centre location, and a vendor that has only prepared a hosting answer will struggle with them. Establish the position early if a public body or state-owned enterprise is on the counterparty list.
The second nuance is what hosting location actually means. A vendor whose primary data centre is in the EU may still have support personnel, backup infrastructure or sub-processors elsewhere. The questions that produce a useful answer are specific: where is customer content stored at rest, where are backups held, which sub-processors exist and in which countries, and can support staff outside the EEA technically access customer content. Ask those four and you will learn more than any general statement of EU hosting can tell you. See EU data residency and GDPR for data rooms for the underlying framework.
- Default: EU or EEA hosting for any European transaction, because it removes the transfer analysis entirely.
- Use EEA, not EU, where Norway, Iceland or Liechtenstein is involved.
- Switzerland: EU adequacy makes transfers straightforward, but the Swiss regime is separate and may need express treatment.
- United Kingdom: adequacy decisions govern and are periodically reviewed, so document the current position.
- Four questions that matter: storage at rest, backup location, sub-processor list with countries, and whether non-EEA support staff can access content.
Language and localisation: where English is enough and where it is not
English is the working language of European cross-border M&A at the transaction layer almost everywhere. Information memoranda, vendor due diligence reports, process letters and transaction agreements are in English on any internationally marketed deal, including in markets where English is not widely spoken outside professional circles. That commonality is real and it makes pan-European processes feasible.
The statutory layer is a different matter and divides into three tiers. In the first tier, English is genuinely comfortable across most of the deal: Ireland, the Netherlands, the Nordics and the Baltics, where even statutory documents are frequently available in English or where the reviewing community reads the local language easily. In the second tier, documents are in the national language but translation is a manageable cost: Germany, Austria, Poland, Czechia, Portugal, Slovenia. In the third tier, language carries legal weight: France and Belgium have statutory language requirements affecting employment documentation, and getting it wrong is a legal issue rather than a comprehension issue.
It is worth being precise about what each translation tier is for, because the cost difference between them is large and the failure modes are different. Machine translation inside the viewer is a triage tool: it tells a reviewer whether a document is a lease, an invoice or a court summons, and whether it needs escalating to someone who can read it properly. It should never be the basis for a disclosure position or a warranty. Professional business translation is what you commission for documents a bidder actually relies on to price the deal. Certified or sworn translation, performed by a translator registered with the relevant national authority, is required where a translated document must be produced to a court or an authority, and it is both slower and substantially more expensive than the other two. Deciding tier by tier, document by document, is tedious for an afternoon and cheaper than either extreme.
The operational answer is the same everywhere and costs nothing. Index bilingually. Every document gets an English descriptive title stating what it is and which entity it belongs to, the original-language title is retained, and the translation status is stated explicitly in the title. This one convention lets an international reviewer triage a foreign-language folder without opening anything, lets local counsel find the original by its real name, and turns the translation budget into a managed queue rather than a surprise.
Localisation of the platform itself matters more than teams expect, and for a specific reason. The deal principals are usually fluent in English. The people who suffer from an English-only viewer are local management uploading documents and local counsel answering Q&A items, and their friction shows up as slow responses and incomplete uploads that get misattributed to bad faith.
- Tier one, English-comfortable: Ireland, Netherlands, Nordics, Baltics.
- Tier two, translation is a cost: Germany, Austria, Poland, Czechia, Slovakia, Portugal, Slovenia, Croatia.
- Tier three, language carries legal weight: France and Belgium, where employment documentation is subject to statutory language requirements.
- Three translation tiers: machine translation for triage, professional translation for anything relied on to price, certified or sworn translation only where a document goes to an authority or court.
- Always: English descriptive title, original title retained, translation status stated in the title.
When a financial regulator is in the room: DORA and the national supervisors
If any party to the transaction is a bank, insurer, investment firm, asset manager, payment or e-money institution or crypto-asset service provider, the data room stops being a procurement decision and becomes a regulated outsourcing question. DORA applies directly and identically across the EU, which is genuinely helpful: a contract negotiated to DORA standards for a Dutch bank works unchanged for a Portuguese one. The room is an information and communication technology third party arrangement, the contract must contain prescribed provisions, and the arrangement must appear in the entity's register of information.
The national layer sits on top and is mostly consistent because national supervisors align with the European supervisory authorities' guidelines. BaFin in Germany, the ACPR in France, the CSSF in Luxembourg, DNB and the AFM in the Netherlands, the Bank of Italy and CONSOB, the CNMV in Spain, the KNF in Poland, the Czech National Bank, the four Nordic supervisors and the Central Bank of Ireland all expect written outsourcing agreements, documented audit rights, sub-processor transparency and a tested exit plan. FINMA in Switzerland applies its own detailed expectations, with bank secrecy adding a dimension that EU regimes do not have.
There is a second, less obvious consequence of a regulated party being in the room. Financial entities are subject to their own record-keeping and supervisory reporting duties, which means the audit log stops being merely useful and becomes evidence. A supervisor asking how confidential client information was handled during a transaction will expect a record showing who accessed what and when, at user and document level, retained for the applicable period. That is a question about export format and retention policy, not about features, and it is worth settling during the trial rather than discovering at the point a supervisor asks. See audit logs and retention and deletion for the underlying requirements.
The practical consequence for provider selection is that a vendor which cannot produce DORA-aligned contract terms is excluded from a whole category of European transactions, and that exclusion is invisible until late in a process. Establish it early. Ask directly whether the vendor has a DORA addendum, whether audit rights extend to a third party auditor acting for the customer, and what the contractual incident notification timeline is. Those three answers tell you within ten minutes whether a vendor can serve a regulated counterparty.
- Uniform: DORA applies directly and identically across all EU member states.
- Aligned but national: BaFin, ACPR, CSSF, DNB and AFM, Bank of Italy and CONSOB, CNMV, KNF, CNB, the Nordic supervisors and the Central Bank of Ireland all track the European supervisory guidelines.
- Separate regime: FINMA in Switzerland, with bank secrecy adding requirements EU regimes do not have.
- Three questions that settle it: is there a DORA addendum, do audit rights extend to a third party auditor, and what is the contractual incident notification timeline.
Investment screening now touches every EU market, and a new EU regulation is tightening it
A decade ago, foreign investment screening was a niche concern in a handful of European countries. It is now a standard workstream. Every large EU market operates a mechanism, several use them actively, and a new EU foreign investment screening regulation was adopted in 2026 to replace the 2019 framework. The new regulation is designed to require every member state to operate a screening mechanism, to align national procedures including two-phase reviews with harmonised timelines, and to extend the framework's reach.
The practical effect for a buyer is that the screening question should be asked at the same moment as the merger control question, in the first week rather than the last. The evidence a filing requires is ordinary diligence material: ownership charts, ultimate beneficial ownership documentation, group structure, and a description of the target's activities mapped against the protected categories in each relevant jurisdiction. Assembling it once, early, into a counsel-controlled section of the room is the cheapest week of work in a transaction. Assembling it under filing deadline pressure, twice, inconsistently, is how timetables slip.
One nuance that catches buyers repeatedly: several regimes look through to ultimate control rather than stopping at the immediate acquirer. An EU-domiciled acquisition vehicle controlled from outside the EU may be treated as a foreign investor. Fund structures with diverse limited partner bases need their position established before a process starts, not during it. And separately from corporate screening, several member states operate distinct permit regimes for the acquisition of real property by foreign persons, which a corporate screening analysis does not cover.
- Active and consequential: Italy's golden power regime, France's Treasury-administered regime, Spain's prior authorisation regime, and the UK's National Security and Investment Act outside the EU.
- Broad triggers: Sweden's regime extends filing obligations to Swedish and other EU investors; Finland's operates on voting rights with no financial thresholds.
- Recently changed: Poland made its regime permanent for non-EEA and non-OECD investors in July 2025 and moved review to the Ministry of Finance and Economy; Ireland brought a mandatory regime into operation in 2025.
- EU level: a new screening regulation adopted in 2026 replaces the 2019 framework and requires all member states to maintain a mechanism with aligned two-phase procedures.
- Separate from corporate screening: national permit regimes for acquisition of real property by foreign persons.
Procurement patterns: published pricing is the exception, and that shapes the shortlist
Across European markets, the data room vendor landscape divides sharply between providers that publish pricing and providers that quote on request. This division has more practical consequence than the price levels themselves, because it determines how long an evaluation takes. Published pricing means a deal team can compare options and get board approval on the same day. Quote-only pricing means the evaluation runs on the vendor's calendar, which is fine for a planned carve-out and fatal for a founder sale with an exclusivity clock.
Where a provider does not publish a price, this site says so rather than estimating one, because an invented benchmark that reaches a board paper is worse than an acknowledged gap. Of the providers profiled here, Papermark publishes a complete list and netfiles publishes an entry price. Several regionally significant providers, including Admincontrol and FORDATA, quote on request.
The second procurement pattern worth understanding is the security review. Its depth varies by market and by counterparty type rather than by deal size. Nordic and DACH corporates, and financial institutions everywhere, run detailed document-driven assessments that take two to four weeks properly. Southern European mid-market processes are often lighter. Public sector and state-owned counterparties add procurement law requirements including equal treatment of bidders, which places specific demands on the audit log. In every case, providers that publish their compliance documentation openly compress the review, because the reviewer can begin work without first negotiating a non-disclosure agreement and scheduling a sales call.
- Published pricing: decisive at the fast end of the market, largely irrelevant for planned enterprise procurement.
- Security review depth: driven by counterparty type, not deal size. Nordic and DACH corporates and financial institutions are the most thorough.
- Public sector: procurement law adds equal treatment obligations that the audit log must be able to evidence.
- Timing: allow two to four weeks for a proper vendor security review, and start it before the provider decision rather than after.
Where Papermark fits across European markets
Papermark positions itself as the leading European secure alternative, and the reason it appears in a country directory rather than only in a provider comparison is that its strengths map onto the constraints this page describes rather than onto a feature list. It is built around the M&A and due diligence workflow that European processes actually run: an NDA enforced before any document becomes visible, staged release of folders as bidders progress between phases, folder- and file-level permissions per bidder group, a permission-based question and answer module, dynamic watermarking carrying viewer identity on every page, download and screenshot controls, and an audit log that exports at user and document level and becomes the disclosure record after closing.
On hosting, data rooms default to EU hosting in ISO 27001-certified data centres in Frankfurt. For every EU market in this directory that removes the transfer analysis entirely, and for Norway and Iceland it keeps the room inside the EEA. Papermark is SOC 2 Type II certified and GDPR compliant, with a signed data processing agreement and a published sub-processor list, which is the exact document set a DACH or Nordic security review asks for and the set that lets a reviewer start work on day one rather than after a sales call.
On language, the viewer is localised for European deal teams in German, French, Spanish, Portuguese and further languages. That matters most in exactly the situation this directory describes: a cross-border process where the deal principals are comfortable in English but local management and local counsel are not, and where their friction is what actually slows the room down. Page-by-page analytics then show which bidder opened which national folder, which is the earliest signal that a bidder has under-resourced a jurisdiction.
Pricing is published in full, which is what makes it usable at the fast end of the market where quote-only vendors cannot compete on timing. Free is EUR 0. Pro is EUR 24 per month. Business is EUR 59 per month including three team members, with extra seats at EUR 20. Data Rooms is EUR 99 per month including three team members and unlimited data rooms, with extra seats at EUR 33. Enterprise is on request, and annual billing saves up to 35 percent.
- Best for cross-border European mid-market M&A where one room must serve counterparties in several countries and languages.
- Best for sell-side processes on a short clock, because self-service availability and published pricing remove the procurement cycle entirely.
- Best for buy-side and internal rooms holding financing papers, synergy models and integration plans that must never reach the seller.
- Best for serial acquirers and sponsors, because unlimited data rooms on one subscription fits running several diligence exercises at once.
- Honest limitation: it does not carry board portal functionality, so a listed company wanting one platform for board papers and deals will still need a second product.
A worked example: a fictional sponsor buys a three-country European group
Meridian Kontinental Partners is a fictional mid-market private equity firm invented for this guide, and every detail below is illustrative rather than real. It is acquiring a fictional packaging group with manufacturing in Germany, a sales company in France and a plant in Poland.
The seller's room is structured workstream-first with country sub-folders beneath, which lets Meridian's tax adviser review tax once across three jurisdictions rather than opening three national trees. Every document carries an English descriptive title alongside its original-language name and a stated translation tier.
Three national layers drive the work. In Germany, the notarial deed chain for the GmbH share transfers has to be complete, and works council consultation is a timetable item rather than a formality. In France, employment documentation must exist in French and the employee information obligations are checked early. In Poland, Meridian's counsel orders the full historical register extract rather than the current one and reconstructs the share transfer chain, finding one transfer executed without notary-certified signatures.
Screening is scoped in week one, not week eight. Meridian is EU-domiciled but has non-EU limited partners, so counsel establishes the look-through position across all three jurisdictions before bidding rather than after.
Meridian runs its own buy-side room in parallel for the financing papers, the synergy model and the integration plan. It is live the day the letter of intent is signed. The seller never sees it, and the audit log from the seller's room is exported at closing as the disclosure record.
Five mistakes cross-border European deal teams make
The first mistake is assuming the EU legal layer covers the national document layer. It does not, and the gap is where the work lives. The GDPR is identical everywhere, DORA is identical everywhere, and merger control follows a common architecture. Underneath that, company registries hold different things, several member states require notarial deeds for share transfers, works council consultation gates timetables in some markets and not others, and employment documentation must exist in the national language in France and Belgium as a matter of law. Teams that generalise from one European deal to the next find these differences at the worst possible time, which is during confirmatory diligence.
The second is writing European Union into a hosting clause that will encounter Norway, Iceland or Liechtenstein. Those three are in the European Economic Area and not in the European Union, and the GDPR applies to them through the EEA Agreement. A clause limited to the EU either excludes a counterparty that should be included, forcing a contract amendment mid-process, or creates an argument about whether the vendor is in breach. Writing European Economic Area instead costs nothing and is correct in every case.
The third is leaving investment screening to the end. Every large European market now operates a mechanism, several are used actively, some look through to ultimate control rather than stopping at the acquisition vehicle, and a new EU regulation adopted in 2026 will require every member state to maintain one. The documents a filing needs are ordinary diligence documents. Assembling them once in week one into a counsel-controlled section is cheap. Assembling them under filing pressure across three jurisdictions simultaneously is not.
The fourth is choosing a platform on features and discovering a constraint on hosting or timing afterwards. The order matters: establish hosting and compliance first because a failure there is disqualifying, establish the timeline second because it eliminates whole categories of vendor, and only then compare workflow and price. Teams that reverse this order build half a room and then start again, which in a competitive process is a real cost rather than an inconvenience.
The fifth is under-weighting the people who actually use the room. Deal principals are fluent in English and comfortable with any interface. Local management uploading documents and local counsel answering questions are neither, and their friction is what slows a room down. Check viewer language support, check that the local team can complete the three most common tasks without help, and give them a written upload guide in their own language before the process launches. It is a two-hour investment that prevents a category of problem that otherwise gets misdiagnosed as bad faith on the other side.
Glossary of European data room and jurisdiction terms
The terms below recur across European transaction correspondence and are the ones most often misread by teams working outside their home market. Where this site treats a concept in depth, it is linked.
- EEA (European Economic Area): the EU member states plus Norway, Iceland and Liechtenstein. The correct geographic term for any hosting clause that may touch those three.
- Adequacy decision: a European Commission determination that a non-EU country provides an adequate level of data protection, allowing transfers without additional safeguards. Relevant to Switzerland and the United Kingdom.
- [DORA](/compliance/dora): the Digital Operational Resilience Act, applying directly across the EU and treating a data room used by a regulated financial entity as an ICT third party arrangement.
- [NIS2](/compliance/nis2): the EU cybersecurity directive, transposed nationally on varying timetables, which is why contracting for named controls beats contracting for the directive.
- Golden power: the Italian investment screening regime, notable for its breadth and for how actively it is used.
- Notarial deed: the instrument required for share transfers in several European jurisdictions including Germany, Austria and the Netherlands. Makes the notarial file a core diligence document.
- Works council: the employee representative body whose information and consultation rights can gate announcement and closing in several European markets.
- Locked box: a purchase price mechanism fixing the price by reference to a historical balance sheet date, with leakage protection. The Nordic and increasingly the European default.
- Vendor due diligence: seller-commissioned diligence reports issued to bidders, standard in Nordic and increasingly in Western European auctions.
- Clean team: a ring-fenced group permitted to see competitively sensitive data the wider bidder team cannot, used where a trade buyer is in the process. See granular permissions.
- Look-through: the practice in investment screening and beneficial ownership rules of assessing ultimate control rather than the immediate acquiring entity.
- [Audit trail](/glossary/audit-trail): the timestamped, user-level and document-level activity record that outlives the transaction and serves as the disclosure record.
- [Dynamic watermarking](/guides/data-room-watermarking): overlaying viewer identity and timestamp on each rendered page to deter and trace leakage.
- Staged release: opening additional folders to a bidder group as it progresses from one phase of a process to the next, rather than granting all access at once.
- Sub-processor: a third party engaged by your processor to help deliver the service. The list, with countries, is one of the four questions that actually establishes where data sits.
Methodology and sources
This directory synthesises the country guides maintained on this site with published legal and regulatory sources and published market research. It is deliberately not a ranking. The country guides carry the local market context and the providers used in each jurisdiction, and this page links to them rather than restating or re-ordering them.
Regulatory points reflect primary regimes and published practitioner commentary on them, including national investment screening statutes and the authorities that administer them, the GDPR as applied nationally through each member state's supervisory authority, the direct application of DORA across the EU, and the uneven national transposition of NIS2. The adoption in 2026 of a new EU foreign investment screening regulation replacing the 2019 framework is reflected in the screening section. Where sources disagreed on a figure or a date, the figure has been omitted rather than reconciled.
Market characterisations are expressed qualitatively wherever quantitative sources conflict, which they frequently do for regional aggregates because different research houses use different country definitions and counting methodologies. Provider information reflects the profiles maintained on this site and each provider's published material. Pricing is quoted only where a provider publishes it; where a provider does not, this guide states that the price is not published rather than estimating one.
Nothing here is legal advice. Investment screening, cybersecurity and data protection rules across Europe are changing quickly, and every jurisdiction-specific point should be confirmed with counsel qualified in that jurisdiction before it is relied on.
- Country detail: the 28 country guides maintained on this site, linked from each market section above.
- Regulatory: national screening statutes, national data protection and financial supervisors, DORA, NIS2 and the 2026 EU screening regulation.
- Market: published European and regional M&A research, used qualitatively where aggregates conflict.
- Pricing: published price lists only. Unpublished prices are reported as not published.
- Last reviewed: July 2026.
Frequently Asked Questions
What actually changes between EU countries for a data room?
Language and translation obligations, company registry content and access, notarial requirements for share transfers, works council and employment consultation duties, and investment screening triggers and authorities. The GDPR, the merger control architecture, DORA and the core room workflow do not change.
Do I need a different data room provider in each European country?
No. The platform decision is rarely country-specific, provided hosting sits in the EU or EEA and the workflow supports NDA enforcement, group permissions, staged release, watermarking, a Q&A module and audit export. What is country-specific is the counsel you instruct and the document expectations you plan for.
Should the data room be hosted in the EU?
For any European transaction, yes, because EU or EEA hosting removes the international transfer analysis entirely. That saves a workstream rather than winning an argument, which on a deal timetable is worth more.
Is EU or EEA the right term for a hosting clause?
EEA, wherever Norway, Iceland or Liechtenstein might be involved. Those three apply the GDPR through the EEA Agreement but are not EU member states, so a clause limited to the European Union either excludes them or creates a breach argument.
Which European markets require a notarial deed for a share transfer?
Germany, Austria and the Netherlands are the clearest examples for limited liability companies, and Spain uses a public deed before a notary. Poland requires written transfers with signatures certified by a notary. In each case the executed chain belongs in the corporate folder from day one.
Where does language carry legal weight rather than just practical weight?
France and Belgium. France requires employment documentation to be available in French, and Belgian language legislation ties the language of employment documents to the region where the employee works, which can mean multiple languages within one group.
Which European investment screening regimes are used most actively?
Italy's golden power regime is the broadest and among the most used, France's Treasury-administered regime is active, Spain operates a prior authorisation regime for non-EU and non-EFTA investors, and outside the EU the UK's National Security and Investment Act is used actively for specified sectors.
Does EU-level investment screening law change in 2026?
A new EU foreign investment screening regulation was adopted in 2026 to replace the 2019 framework. It is designed to require every member state to maintain a screening mechanism and to align national procedures, including two-phase reviews with harmonised timelines.
When does a data room become a regulated outsourcing?
When a party is a bank, insurer, investment firm, asset manager, payment or e-money institution or crypto-asset service provider. DORA then treats the room as an ICT third party arrangement requiring prescribed contract terms and inclusion in the register of information.
How do I check where a vendor really stores my data?
Ask four specific questions: where is customer content stored at rest, where are backups held, which sub-processors exist and in which countries, and can support personnel outside the EEA technically access customer content. Those answers are more informative than any general claim of EU hosting.
How long should I allow for a European vendor security review?
Two to four weeks for a proper document-driven review, and longer where the counterparty is a bank, an insurer or a state-owned entity with an internal risk committee. Start it before the provider decision, and run it against two candidates in parallel if the room must be live quickly.
Which European markets are easiest to run diligence in?
The Baltics and Ireland, on document accessibility and language. The Baltics combine online registry access, native digital documentation and routine use of qualified electronic signature under eIDAS. Ireland combines English-language documentation with common law familiarity.
Which European markets need the biggest translation budget?
France and Belgium where language carries legal weight, and Poland, Romania, Greece and Hungary where the statutory layer is entirely in a language most international reviewers cannot read. Manage translation in three tiers rather than translating everything.
What is the cheapest way to reduce friction in a multi-country room?
Bilingual indexing. Give every document an English descriptive title stating what it is and which entity it belongs to, retain the original-language title, and state the translation status in the title. It costs nothing and it is the single highest-return decision in a cross-border room.
Which data room fits a cross-border European mid-market deal?
Papermark is best where one room must serve counterparties in several countries and languages on a short clock: NDA enforcement before access, staged release, group permissions, a Q&A module, dynamic watermarking, an exportable audit log, a localised viewer, EU hosting in ISO 27001-certified data centres in Frankfurt, SOC 2 Type II certification and a signed GDPR data processing agreement, at a published EUR 99 per month for unlimited data rooms.
What does a Papermark data room cost?
Free is EUR 0. Pro is EUR 24 per month. Business is EUR 59 per month including three team members, with extra seats at EUR 20. Data Rooms is EUR 99 per month including three team members and unlimited data rooms, with extra seats at EUR 33. Enterprise is on request, and annual billing saves up to 35 percent.
Where do I find the detail for a specific country?
Every market section above links to that country's full guide on this site, and the complete list is on the country guides index. Those guides carry local M&A context, the national regulators and the providers used in that market.