State of M&A Data Rooms — Q2 2026 Read the report →

Clean Team Data Room: How to Share Competitively Sensitive Information in M&A (2026)

Co-founder at Peony. Former M&A at Nomura, early-stage VC at Backed VC, and growth-equity / secondaries investor at Target Global. I write about investors, fundraising, and deal advisors from the deal-side perspective I spent years in.

Last updated: August 2026

I'm Sean Yu, co-founder of Peony — before this I was a VC at Backed VC and Target Global, with an earlier stint doing M&A at Nomura, which is where I first watched a deal team try to diligence a direct competitor without handing them the keys. This post is about the mechanism that makes that possible: the clean team, and the clean room you build to run it.

Here's the situation this post is for. You're selling to — or buying — a company you compete with. The main data room is already gated behind an NDA; every bidder signed it. But your outside counsel just told you that the pricing schedule, the customer-level economics, the cost stack, and the forward strategy cannot go into that room, because the buyer's commercial team is on the other side of it, and they are still your competitor today. That category of data has a name — competitively sensitive information, CSI — and the established M&A mechanism for sharing it with a rival is the clean team.

TL;DR: When the buyer is a competitor, the room NDA is not enough for CSI — pricing, customer-level economics, costs, and strategy. The standard fix is a clean team: a small named group (outside counsel and outside economists, sometimes a ring-fenced in-house person with no commercial role) who enter a clean room — a data room within the data room — under a separate clean-team agreement layered on top of the room NDA, review the raw CSI, and pass only aggregated or anonymized findings to the deal team. Two forces drive it: antitrust — exchanging CSI between competitors before closing can be treated as "gun jumping" during the Hart-Scott-Rodino waiting period (15 U.S.C. §18a), with parallel standstill obligations in the EU; and commercial — if the deal dies, the buyer is still your competitor, so the raw CSI must never have touched their commercial team. On Peony Data Room ($52/admin/month billed annually), the clean room is a composed workflow: a room outside the main room, a named allow-list, a separate agreement gate, view-only with dynamic watermarks, and a per-person access log. Nothing here is legal advice — confirm the protocol with your antitrust counsel.

Quick guide — match the question to your situation:

The Bidder Isolation Test — a five-point checklist for running a competitive M&A auction in one data room: group walls so each bidder sees only its own documents, staged disclosure by round, clean revocation, per-group audit logs, and walled Q&A. The same isolation controls that stand up a clean room for competitor buyers.

Above: Peony's Bidder Isolation Test — the five isolation controls (group walls, staged disclosure, clean revocation, per-group audit, walled Q&A) that let you run rivals through one room without cross-contamination. A clean team for a competitor buyer is the strictest tier of the same pattern: one named group, its own agreement gate, view-only, and a per-person log.

This is a practitioner explainer for the person who has to operationalize a clean team on a live deal clock. I run Peony, a data room company, so I'll be specific about how the mechanic maps onto our product — but the legal frame here is general, and where a real decision hangs on it, the honest answer is always "confirm with your antitrust counsel." Nothing below is legal advice.

What is a clean team in M&A?

A clean team is a small, named group of people — almost always outside counsel and outside economists or consultants, and occasionally a ring-fenced in-house person with no commercial role — who are the only individuals permitted to see the target's raw competitively sensitive information during due diligence, and who pass only aggregated or anonymized findings back to the buyer's deal team. It exists because ordinary diligence would put pricing, customer economics, and strategy in front of the buyer's commercial staff, and when the buyer is a competitor, that is exactly what must not happen.

Start with the two groups, because the whole mechanism is a wall between them:

  • The deal team is everyone running the transaction end to end — corp-dev, the bankers, the integration planners, and critically the commercial people (sales, pricing, product) who will operate the combined business after closing. They see the ordinary diligence set. They do not see raw CSI.
  • The clean team is the small group cleared to see raw CSI. They sit behind the wall. Their job is to review the sensitive data and produce a derived, sanitized output — the deal team gets "top-10 customers as a share of revenue," never the named customer list; a blended gross margin, never the per-account cost file.

The physical space the clean team works in is the clean room — often described as a "data room within the data room," because that is literally what it is: a separate, tightly gated space that sits alongside the main room and holds only the CSI. You will also hear black box for the strictest variant, where the underlying inputs stay entirely hidden and only a single modeled output (a valuation, a synergy estimate) emerges — the deal team sees the output but never opens the box. A looser white box variant lets the deal team see redacted or aggregated versions of the data itself. Where a given deal sits on that spectrum is a judgment your antitrust counsel makes, not the data room.

The CSI itself is a defined category. The FTC, in its guidance on avoiding antitrust pitfalls during pre-merger negotiations and due diligence, describes competitively sensitive information as including "current and future price information, strategic plans, and costs, as well as information regarding future product offerings, expansion plans, pricing strategy, and non-aggregate customer-specific information" (FTC, 2018; text reproduced by Hughes Hubbard & Reed). That "non-aggregate customer-specific" phrase is the tell: aggregate is usually fine for the deal team; per-customer, per-account, per-SKU is what belongs behind the clean-team wall.

One more piece of the definition matters for how you build it: the clean team enters under its own clean-team agreement, a document distinct from the room NDA everyone else signed. It names the individuals, defines what they may see, and — this is the part that does the work — constrains what they may pass back out. The room NDA governs the auction; the clean-team agreement governs the box.

Is sharing data with a competitor buyer before closing gun jumping?

It can be, and that risk is the reason the clean team exists as a legal instrument and not just a courtesy. "Gun jumping" is the antitrust term for two merging competitors coordinating — or exchanging competitively sensitive information — before they are legally cleared to combine. Sharing raw pricing, costs, and customer data with a rival's commercial team during diligence is one of the classic fact patterns regulators point to. What follows is the general frame; your antitrust counsel structures the specifics.

The US statute in the background is the Hart-Scott-Rodino Antitrust Improvements Act, codified at 15 U.S.C. §18a. For reportable deals, it requires the parties to file premerger notification and then observe a waiting period before they may complete the acquisition — the statute sets the period to "end on the thirtieth day after the date of such receipt (or in the case of a cash tender offer, the fifteenth day)," and it can be extended if the agencies request more information. The premise underneath the waiting period is simple: until it expires and the deal closes, the two companies must keep operating as independent competitors. Coordinating pricing, customers, or strategy in the meantime — or letting the buyer's commercial team absorb the target's CSI — is the conduct the rule is built to prevent.

The FTC has been explicit that diligence is a place this goes wrong, and equally explicit about the fix. Its guidance states that if competitively sensitive information must be exchanged for diligence and integration planning, "parties should employ third-party consultants, clean teams, and other safeguards that limit the dissemination and use of that information," that "outside counsel may review information before it is submitted to the clean room," and that these exchanges are "the subject of active enforcement by both the FTC and the Department of Justice (DOJ) Antitrust Division" (FTC, 2018; Hughes Hubbard & Reed).

"Active enforcement" is not abstract. In January 2025, DLA Piper reported that the FTC settled a gun-jumping matter in which crude-oil producers agreed to pay a $5.6 million fine for pre-merger coordination during the HSR waiting period. Among the conduct the FTC flagged: the seller "gave XCL and Verdun almost unfettered access to its competitively sensitive business information after signing the purchase agreement without customary protections, such as a 'clean team,'" and the shared data included "site design plans, customer contract and pricing information, and daily supply and production reports" (DLA Piper, 2025). The phrase "without customary protections, such as a 'clean team'" is doing a lot of work — it frames the clean team as the expected control, whose absence is itself part of the problem.

If your deal touches the EU, the same instinct applies under a parallel regime. Under the EU Merger Regulation, a concentration with an EU dimension is subject to a standstill obligation — the European Commission's guidance states that such concentrations "shall not be implemented either before its notification or until it has been declared compatible with the common market pursuant to a Commission decision" (European Commission). Implementing too early, including via premature information exchange, is the EU analogue to gun jumping, which is why cross-border deals routinely run a clean team — both regimes push the same way. Our cross-border M&A guide sets that context, though the antitrust specifics belong to counsel.

One honest caveat: a clean team is a well-recognized way to structure a lawful exchange, not a magic shield — regulators have pursued conduct that happened despite a nominal clean team when the discipline was not real. The value is in the enforcement, which is exactly what the build details below deliver: the named allow-list, the separate agreement, the view-only controls, and the log that proves who saw what, when.

Who goes on the clean team?

The clean team is small — usually two to six named individuals — and it is overwhelmingly made up of people with no commercial stake in the two competitors: outside counsel and outside economists or consultants. The governing principle, which your antitrust counsel applies to the facts, is that a clean-team member must not be someone who makes or influences the buyer's competitive decisions — pricing, sales, marketing, customer strategy — for any product where the buyer and target overlap.

In practice the roster looks like this:

  • Outside counsel. Antitrust and deal lawyers who are not part of the buyer's business. They set the protocol, define the aggregation rules, and often review the CSI — and the deal team's derived outputs — before anything moves. The FTC guidance specifically contemplates that "outside counsel may review information before it is submitted to the clean room, as well as before it is submitted to the broader cohort of decision-makers" (FTC, 2018).
  • Outside economists and consultants. The people who actually build the model — market analysis, synergy estimates, customer-concentration math — from the raw CSI, and who produce the aggregated output the deal team receives. Because they are third parties with no role in the buyer's competitive conduct, they can see per-customer and per-SKU detail that the buyer's own staff cannot. The FTC frames "engaging a third party to collect and aggregate" customer-level information as a standard safeguard against individual-level disclosure (Hughes Hubbard & Reed).
  • Ring-fenced in-house members (the edge case). Occasionally an in-house lawyer or analyst with genuinely no commercial role is permitted onto the clean team. This is the exception, not the rule, and it raises the bar on documentation: the ring-fence has to be real and provable, which is exactly what a per-person access log is for. Whether any in-house person can be cleared is a call for antitrust counsel, deal by deal.

Who is off the clean team is just as important. The buyer's sales, pricing, product, and corp-dev-with-commercial-responsibility people stay on the deal team and never enter the clean room. And the wall runs both ways: a deal-team member who goes fishing for the raw customer list — pressing the clean team or the seller to hand it over directly — can create the very gun-jumping exposure the structure exists to avoid. If you're the walled-off deal-team member, the safe posture is to ask only for the aggregated deliverable and let the clean team decide what is releasable.

How do you set up a clean room inside your data room, step by step?

Here is the part everyone actually came for. A clean room on a modern data room is not a single button labeled "clean room" — it is a composed workflow assembled from standard controls: a separate room, a named allow-list, an agreement gate, view-only protection, and logging. That is true of Peony and true of the enterprise incumbents; anyone selling you a one-click "clean team mode" is renaming the same primitives. What follows is the Peony build, but the shape transfers. Budget about fifteen minutes.

The one non-negotiable design rule, before the steps: the CSI must physically live outside the main data room. A hidden folder inside the main room is still represented in that room's tree — the deal team can see a locked folder exists, and worse, one careless permission change can expose it. The clean room sits in its own room; the main room gets only a labeled pointer to it.

Step 1 — Create the clean-room folder in a private workspace outside the main room

In Peony, click "New Data Room" and create a room dedicated to the CSI — separate from your main diligence room. This is the physical separation that makes the wall real. Name it for the protocol ("Project Maple — Clean Room — Outside Counsel Only") so there is no ambiguity about what it is. Because Peony gives you unlimited data rooms per admin, this second room costs nothing extra — it is not a new engagement fee, just another room on the same subscription.

Generate one access link for the clean room, distinct from every main-room link. This link is the single door to the CSI, and everything that follows — the allow-list, the agreement gate, the view-only controls — attaches to it. Keeping it separate from the main-room links is what lets you revoke the clean room independently later without touching the auction.

Step 3 — Allow-list only the named clean-team members

On that link, restrict access to the specific clean-team individuals by verified email — outside counsel, the outside economist, anyone counsel has cleared. This is where Peony's visitor groups and named-user allow-listing do the work: the link is identity-bound, so no one outside the list can open it even if the URL leaks. Turn on email verification for a high-sensitivity room. The allow-list is the clean team, expressed in the product.

This is the step that trips people up, so be precise: the document on the clean-room gate is the clean-team agreement, a different file from the room NDA the bidders already signed. Upload it to the NDA gate on the clean-room link in e-signature mode, drop signature fields onto the signature block, and save it. Now no clean-team member renders a single CSI page until they have signed that specific agreement — the one that names them and constrains what they may pass back out. The room NDA gated the auction; this gate governs the box.

Step 5 — Set the room view-only: downloads off, dynamic watermarks on, screenshot protection on, expiry aligned to the protocol

Lock the clean room down to read-only:

  • Downloads off, so the raw CSI cannot leave as a file. This is what lets you later prove the data never physically departed the room.
  • Dynamic watermarks on, so every page a clean-team member views carries their email, and a timestamp, burned into the render — per-person forensic attribution if a page ever surfaces.
  • Screenshot protection on, to deter capture on desktop and mobile.
  • Link expiry set to match the protocol's timeline, so access closes on schedule rather than lingering.

Dynamic watermarks, locked allow/block lists, and granular permissions are all on the Data Room plan ($52/admin/month). If your CSI needs whole sections blacked out rather than merely gated, advanced redaction lives on the Deal Team plan ($64/admin/month, minimum 4 admins) — that is the white-box move, where the deal team sees a redacted version of the underlying document instead of nothing at all.

Step 6 — Add a labeled pointer in the main room

Back in the main data room, add a labeled web-link item — something explicit like "Clean room — clean-team members only, separate agreement required" — that points to the clean-room link. This is the elegant part: the structure is visible to the deal team (they know a clean room exists and know it is gated), but the content is not (the CSI is in a different room they cannot enter). No hidden folders, no surprises, no accidental exposure from a permission slip.

Step 7 — Let the platform retain the agreement, identities, timestamps, and per-page logs

You do not build this part — Peony does it automatically, and it is the whole evidentiary payoff. The platform retains the signed clean-team agreement, each member's verified identity, the timestamps, and per-page access logs via page analytics — a defensible record of who opened which CSI page, when. This is the audit trail counsel wants if a regulator ever asks the question the whole structure is designed to answer: who saw what, when. For the leak-attribution side of that record, our dynamic watermarking guide goes deeper on the forensic layer.

And the outbound leg. The clean team's job ends with a deliverable back to the deal team — an aggregated, anonymized memo or model, produced and shared outside the clean room as a separate document while the raw CSI stays behind the wall. Because the clean room is download-off and fully logged, you can show the raw data never left it as a file even as the sanitized output moves through an entirely separate channel. The next section covers what that hand-back actually contains.

How does the clean team pass findings back to the deal team?

The clean team reviews the raw CSI inside the clean room and hands the deal team a derived deliverable — a memo or model containing only aggregated or anonymized outputs — produced and delivered outside the clean room. The deal team gets what it needs to price the deal and plan integration; it never gets the raw file. This is the "black box" idea made concrete: inputs stay in the box, a sanitized output comes out.

Concretely, the translation looks like this (illustrative, not real figures):

  • The named customer list becomes a concentration read — the share of revenue sitting in the largest accounts, stated as a band rather than as named customers. Concentration, not identities.
  • The per-account pricing schedule becomes a blended average selling price and a discount range.
  • The per-SKU cost file becomes a gross-margin band by product family.
  • The forward pricing strategy becomes a directional read — "management plans modest annual increases" — not the actual model.

Exactly how aggregated is aggregated enough is a legal judgment, not a product setting. Outside counsel typically reviews the deliverable before it crosses to the deal team — the FTC guidance explicitly contemplates counsel reviewing information "before it is submitted to the broader cohort of decision-makers" (Hughes Hubbard & Reed). On the tooling side, all Peony has to do is keep the two channels separate and logged: the raw CSI never leaves the download-off clean room, and the sanitized memo lives wherever the deal team works. The wall is a product fact; the aggregation standard is counsel's call.

What's the best M&A data room for managing multi-stage bids?

The best M&A data room for managing multi-stage bids is one where every round is its own gate on a single subscription — so you tighten access as bidders advance without ever rebuilding the room or paying per deal. In a competitive auction with a strategic in the mix, that staging is also what keeps the CSI where it belongs until the very last stage. On Peony, the whole ladder — teaser link, click-through CIM NDA, final-round clean room — runs on one $52/admin/month subscription, each round its own gate. Here is the full ladder, mapped to the controls that run it.

RoundAudienceWhat they seeThe gate
Round 1 — TeaserWide buyer universeBlind teaser, no confidential detailLight gate (or open link)
Round 2 — CIMSerious first-round biddersCIM, financial summary, aggregated metricsClick-through room NDA
Final round — Clean room / trade-secret annexNamed clean-team members onlyRaw CSI (clean room) and/or source code and formulas (trade-secret annex)Separate clean-team agreement, named allow-list, view-only, watermarked

Read the ladder as escalating trust. Round 1 is wide and light — the teaser goes to a broad universe, gated minimally because it holds nothing confidential. Round 2 puts the CIM behind a click-through NDA that every bidder e-signs before a page renders; our click-through NDA guide covers that mechanic end to end, including the round-by-round "Banker's NDA Stack" for tightening the NDA itself as bidders advance. When a competitor is bidding, the CIM at this stage should already be scrubbed of raw CSI — that lands in the final round, not this one.

The final round opens the clean room, and sometimes a trade-secret annex. For the last one or two bidders, the raw CSI goes into the clean room built above — named members, separate agreement, view-only. If the crown jewels are intellectual property rather than commercial data — source code, formulations, algorithms — that content goes into a dedicated trade-secret annex, gated the same way. The two are siblings: the clean room walls off commercial sensitivity from a competitor; the trade-secret annex walls off technical sensitivity from everyone until the deal is nearly certain.

Because Peony includes unlimited data rooms per admin, the teaser room, the CIM room, and the clean room are all one subscription — each with its own access log and its own revocation. You never buy a second product to run the final stage; you build another room. For the broader auction-isolation playbook — how to run several bidders through one process without cross-contamination — see best data room for multiple bidders. And when a competitor is one of those bidders, confirm the round-by-round information design with your antitrust counsel; the ladder is a tooling pattern, not a compliance opinion.

What happens if the deal falls through?

If the deal dies, you revoke the clean-room link in one action — every clean-team member loses access instantly — while the platform retains the signed clean-team agreement, the identities, and the per-page logs as your permanent record. The commercial worst case is the reason the clean team existed in the first place: the buyer is still your competitor, and now the deal is over. The saving grace is that if the structure held, the buyer's commercial team never saw the raw CSI at all — only their outside advisors did, and only as aggregates.

Here is what actually happens, mechanically:

  • Access is cut immediately. Revoking the link shuts every clean-team member out of the clean room at once. Because the clean room was a separate room with its own link, you can kill it without disturbing anything else.
  • Downloads-off means there is nothing local to claw back. The whole point of view-only was this moment: the raw CSI never left as a file, so there is no downloaded copy sitting on an economist's laptop to worry about. The access log is your proof of that.
  • The record is retained, not deleted. Peony keeps the signed clean-team agreement, each member's identity, the timestamps, and the per-page logs. If a dispute or a regulator's question comes later, that record is what shows the clean team was real and the wall held.
  • The agreement's obligations survive. A clean-team agreement's confidentiality and use restrictions are written to outlive the transaction — the clean-team members remain bound after the deal collapses. The exact survival terms, and any obligation to certify destruction of working files, are in the agreement your counsel drafted.

Be honest with yourself about the limit here: the clean team contains the damage; it does not erase it. Outside counsel and an economist did see the raw data, and they remain bound by the agreement. What you have genuinely prevented is the un-fixable version — the buyer's sales and pricing teams internalizing your customer list and margins and walking away with them. On the antitrust side, some deals also require destruction or return of shared materials on termination; the FTC guidance emphasizes ensuring "data is actually destroyed following the conclusion of due diligence" (Hughes Hubbard & Reed). Your counsel will tell you what the agreement and the regulators require; the room gives you the revocation and the log to execute and prove it.

What does a clean room cost to run?

On Peony, running a clean room costs nothing beyond your existing subscription — Peony Data Room is $52/admin/month billed annually ($75 month-to-month), and it includes unlimited data rooms per admin, so the clean room is just another room, not a second engagement fee. There is no per-deal charge, no per-page fee, and no storage-overage bill. The pricing is flat per-admin: you pay for admin seats, and everything else scales at zero marginal cost.

The two facts that matter most for a clean team:

  • Unlimited data rooms per admin. The clean room is a room you create on the same plan — the separation that makes the wall real does not cost you a separate product or a second contract. The enterprise incumbents — Datasite and Intralinks among them — price by quote, typically per deal or per engagement, which is how a single clean-team engagement turns into a five-figure line item elsewhere; neither publishes a documented folder-level second-agreement workflow.
  • Unlimited free viewers. Your clean-team members — outside counsel, the outside economist — view at no charge. You are not paying per-seat for the very people the room exists to serve. That is unusual enough in this category to be worth stating plainly.

Mapping the controls to plans, so you know what tier you actually need:

CapabilityPeony plan
Dynamic watermarks, locked allow/block lists, granular permissions, named-user gatingData Room — $52/admin/month
Advanced redaction (the white-box move)Deal Team — $64/admin/month, min 4 admins
Walled per-bidder Q&A (separate threads per bidder)Peony Enterprise

For the core clean-room build — separate room, named allow-list, separate agreement gate, view-only, dynamic watermarks, per-person log — the Data Room plan at $52/admin/month has everything you need. Step up to Deal Team only for advanced redaction (the white-box variant, where the deal team sees blacked-out documents rather than a locked room), and to Enterprise only if your auction needs fully walled per-bidder Q&A threads. On security posture: Peony is SOC 2 Type II. We do not hold ISO 27001, and I'd rather say that plainly than let it come up later — if an ISO certificate is a hard procurement requirement for your counterparty, factor that in.

This runs at real scale, not as a demo feature: 6,800+ customers use Peony for data rooms across M&A, private equity, and diligence, and the clean-room pattern above is composed from the same controls those 6,800+ customers already rely on. There is no separate SKU and no clean-team upcharge — the wall is built from primitives that ship in the plan.

When you do NOT need a clean team

Most deals do not need a clean team, and it is worth saying so directly, because a clean room adds real friction and you should only pay that cost when the deal actually calls for it. The trigger is competitive overlap between buyer and seller — remove that, and the whole apparatus is usually unnecessary.

You almost certainly do not need a clean team when:

  • The buyer is a financial buyer with no competitive overlap. A PE fund or family office that does not own a competing portfolio company is not your competitor. There is no rival commercial team to wall off and no gun-jumping-by-information-exchange concern of this kind. Standard diligence under the room NDA is the norm. (If the fund owns a competing platform and is running an add-on, that is an overlap — and then you are back to a clean team, ring-fencing the platform's operators, as covered above.)
  • Buyer and seller simply don't compete. Adjacent markets, complementary products, different geographies with no overlap — an ordinary NDA plus granular permissions handles the sensitivity. You can still gate the most sensitive folders tightly and watermark them; you just don't need a separate clean-team agreement and a walled economist.
  • The sensitivity is about confidentiality, not antitrust. Plenty of data is sensitive without being competitively sensitive in the antitrust sense. For that, the room NDA and per-folder permissions — restrict the folder, watermark it, log access — are the right tool, and the permissions guide covers how to set them.

For the overwhelming majority of non-competitor deals, the answer is the ordinary stack: room NDA, granular permissions, dynamic watermarks, and a clean access log. The clean team is a specialized instrument for the specific case where the person on the other side of the table would still be your competitor tomorrow if the deal never closed. When that is the situation, build the clean room. When it is not, don't — and either way, if a competitor is anywhere near the deal, let your antitrust counsel make the call.

Sources