The short answer on document link expiry best practice is this: a share link should stay live only as long as the recipient genuinely needs it, and no longer. For most business documents that means days or a couple of weeks, not months, and rarely "forever". A link with no expiry is a standing invitation that keeps working long after the deal, the review or the conversation has moved on, including for anyone the recipient forwarded it to. The right approach is to set an expiry that matches the purpose of the share, to use one link per recipient so you can control each independently, and to keep the ability to revoke access early if circumstances change. This guide explains how to think about link lifespan in 2026 and how 99 Data Rooms lets you set, monitor and cut off links properly. It is general information, not legal advice.
Almost everyone has left a link live too long. A pitch deck shared with an investor two rounds ago that still opens. A price list sent to a prospect who became a competitor. A contract draft that resurfaces after the terms changed. The cost of an over-long link is quiet: you rarely find out it was still open until it matters, and by then it is too late.
Why open-ended links are a hidden risk
The convenience of a link is also its weakness. Unlike a physical document, a live link keeps working indefinitely, silently, and for anyone who holds the URL. Three risks follow.
First, forwarding. A link that never expires can be passed on long after you shared it, and you have no natural checkpoint to notice. The person you trusted may be careful, but the link outlives the context in which you trusted them. Our guide on what a Dropbox link can't do digs into why a raw file link gives you so little control here.
Second, stale content. Documents change. If an old link still resolves, someone may be reading superseded terms, an out-of-date price, or a draft you never meant to be final. Expiry is a way of forcing freshness: when the link dies, the recipient has to come back to you, and you can send the current version.
Third, drift out of scope. A link shared for a specific purpose, due diligence, a single review, a one-off quote, has a natural end. Once that purpose is served, continued access serves no one but a potential leaker. Tying the link's life to the purpose closes that window.
The counter-argument is friction: expiry can inconvenience a legitimate recipient who comes back later. That is real, but it is a small, fixable friction (you reissue the link) set against an open-ended, invisible exposure. In almost every case the balance favours a sensible expiry.
How long is "right"? Matching lifespan to purpose
There is no single correct number, because the right lifespan depends on what the document is for. A useful way to decide is to ask how long the recipient legitimately needs access, then add a small margin, and set expiry there.
For a single review or approval, a few days is often plenty. For a live negotiation or a due diligence window, a couple of weeks that you extend if needed works better than an open link you forget about. For a one-time, high-sensitivity share, the strongest control is a link that works once and then closes, which is the pattern covered in our guide to one-time links. For an ongoing relationship, such as a client who needs continuing access to a portal, a link with no fixed expiry can be defensible, but only if you can see who is using it and revoke instantly, which is a different control from time-based expiry.
Two principles help across all of these. Use one link per recipient rather than a single link blasted to a group, so you can expire or revoke each independently and see exactly who did what. And treat expiry as a default you set at the point of sharing, not an afterthought, because the link you forget to expire is the one that comes back to bite you.
Expiry is not the same as revocation
A subtle but important point: setting an expiry date and being able to revoke a link are two different controls, and you want both. Expiry is a scheduled end, useful for the routine case where you know roughly how long access should last. Revocation is an immediate kill switch, useful when something changes: a deal collapses, a recipient turns out to be untrustworthy, you spot the wrong version went out, or you simply sent it to the wrong person.
Relying on expiry alone leaves a gap: between now and the expiry date, you have no way to stop access if you need to. Relying on revocation alone means you have to remember to act, and the link stays live until you do. Together they cover both the predictable and the unexpected. Our guide on how to un-send a document you already shared covers the revocation side in depth, and it is the control people wish they had far more often than they expect.
How 99 Data Rooms handles link lifespan
99 Data Rooms is built around exactly this idea: a shared document should stay under your control from the moment you send it. Instead of an attachment that forwards forever, you share a tracked link, and you decide how long it lives.
You can set an expiry on a link so it closes automatically when the purpose is served, and you issue one link per recipient so each can be managed independently. Before anyone opens it, the link is gated: the recipient must verify their email and enter a one-time code, so you know who is on the other end, and on the Business tier you can require an NDA first. You can read how that works on our gating and access control page. While the link is live, page-by-page analytics show whether the recipient actually opened the document and how long they spent, with a clear split between a raw visit and a verified viewer who passed the gate. And at any moment, whether before, during or after the expiry you set, one click revokes access, even for someone mid-scroll, which is the one-click revocation that expiry alone cannot give you.
Put together, that means you are never stuck with a link you cannot pull back. You set a sensible expiry as your default, watch who engages, and cut off access instantly if anything changes. The wider platform is in beta and improving fast, but this control over link lifespan already works today.
Set sensible link expiry, for free
You can share documents as gated, tracked, expiring, revocable links inside 99 Data Rooms. The free tier is a real tier, not a trial: three rooms, twenty-five active links, forever, no card required. Start for free, send your first controlled link, and move up only when you want unlimited links, NDA gating or watermarking. The platform is in beta and improving fast, but setting expiry, watching engagement and revoking in one click already work.
Sources
How long should a document share link stay live?
Only as long as the recipient genuinely needs it. For most business documents that is days to a couple of weeks, matched to the purpose of the share, with a small margin. Open-ended links are a hidden risk because they keep working, and keep being forwardable, long after the context has passed.
Should I ever use a link with no expiry?
Occasionally, for genuinely ongoing access such as a client portal, but only if you can see who is using the link and revoke it instantly. Time-based expiry and immediate revocation are different controls; for open-ended access, revocation is what protects you.
What is the difference between link expiry and revocation?
Expiry is a scheduled end set in advance, good for predictable timelines. Revocation is an immediate kill switch for when something changes unexpectedly. You want both: expiry as a default, revocation as insurance. Our guide on un-sending a document covers revocation.
Is a shorter link lifespan always safer?
Shorter generally reduces exposure, but too short creates friction for legitimate recipients. The goal is to match the lifespan to the purpose rather than to minimise it blindly. If you genuinely need one-shot access, a one-time link is stronger than a very short expiry.
Can I change a link's expiry after sending it?
In 99 Data Rooms you keep control after sending: you can revoke a link at any time, including before its expiry, and issue a fresh link if a recipient legitimately needs more time. That is safer than leaving a long expiry running unattended.