For the party who was invited

What a virtual data room records about you

If someone has sent you into a data room to review documents, it is keeping a record of what you do in there. Which files you opened. How long you had each one on screen. Which ones you never opened at all.

That is not unusual and it is not a scandal, it is most of what a data room is for. But the notice you were shown probably said something like activity is monitored and logged for security purposes, which is not the same sentence at all. So here is the plain version.

Typically recorded
  • Which documents you open, and when
  • How long each document is open for
  • Anything you download, print or copy, where the room allows it
  • The address you connect from, and the device type
  • Questions you ask, and any request you make for access
Not recorded, in ShareAndGo
  • Anything you do outside the data room
  • The contents of your own files, unless you upload them
  • Your activity in any other room, including other rooms run by the same organisation

Who sees it

The organisation that invited you. They can see the activity itself and, in most modern data rooms, a summary or engagement score built from it. That is the point of it from their side: a seller running a transaction needs to know which parties are reading the material and which have gone quiet.

It is also why an activity report is treated as commercially sensitive by both sides. What you did not open can say as much as what you did.

The part that is unusual

In ShareAndGo, you can read your own record

Every participant in a ShareAndGo room can open My activity and see exactly what has been logged about them: every action, the documents involved, and the total time recorded. Not a summary written for you, the record itself.

You are shown the full notice before you enter, and which version of it you agreed to is stored, so the wording cannot be changed underneath you. You see your own record only. No participant can see another's.

What to ask before you read anything sensitive

If you are about to go into a room holding a competitor's material, or your own client's, three questions are reasonable and easy for the other side to answer:

  1. What is recorded about my activity, in specific terms?
  2. Who inside your organisation can see it, and is it shared with advisers?
  3. Can I see my own record?

A room that answers all three plainly is a room being run properly. In our experience the third question is the one that separates them.

Common questions

Can the other side see which documents I opened in a data room?

Yes. Virtually every virtual data room records which documents each invited person opens, when, and for how long. The organisation that invited you can normally see that as a report, and often an engagement score derived from it. This is standard across the category and is a large part of what a data room is for: the seller needs to be able to prove who had access to what, and they use the same record to see which parties are seriously engaged.

Does a data room record how long I spend reading a document?

Usually, yes. Time on document is one of the most commonly recorded signals, because it is what tells a seller the difference between someone who downloaded an index and someone who read the material. In ShareAndGo, you can see exactly what has been recorded about you from the My activity page inside the room.

Can a data room tell that I never opened a document?

Yes, and it is often more revealing than what you did open. A record of documents provided but never viewed is visible to the party who invited you. It is one of the reasons a data room's activity report is treated as commercially sensitive by both sides.

Is it legal for a data room to track my activity?

In Australia, activity logging of this kind is lawful where you are notified of it. The Australian Privacy Principles require an organisation to be open about what personal information it collects and why. The practical problem is that notice is often reduced to a single line about security monitoring, which does not describe document-level reading behaviour. ShareAndGo shows the full notice before you enter a room, records which version you agreed to, and lets you read your own record at any time.

Can I see what a data room has recorded about me?

In most virtual data rooms, no. The activity report is built for the room's owner. ShareAndGo is the exception: any invited participant can open My activity inside the room and read their own record, including every action logged, the documents involved, and the total time recorded. You cannot see any other participant's activity, and the room's owner cannot see yours in any form you cannot also see.

What does ShareAndGo record about a data room visitor?

Which documents you open and when, how long each is open, anything you download, print or copy where the room permits it, the address you connect from and the device type, and questions or access requests you raise in the room. It does not record anything you do outside the data room, the contents of your own files unless you upload them, or your activity in any other room, including other rooms run by the same organisation.

Should I be worried about opening a data room invitation?

No, but you should know what is recorded before you start, which is exactly what a data room should tell you and often does not. Reading documents in a room you were invited to is the normal course of a transaction. The reasonable expectation is that you are told what is kept, that it is limited to your conduct inside that room, and that you can see it. If a room will not tell you what it records, that is worth asking about before you read anything sensitive.

Running the room yourself?

Transparency is a feature, not a cost

ShareAndGo gives you the full activity record on every party in your room, and gives each of them a view of nothing but their own. Australian-hosted in Sydney, tamper-evident audit trail, flat pricing, free tier.

See also

Explore ShareAndGo

Other comparisons

Use cases

By industry

Browse all