Rights and contracts
Consumer privacy ombudsman: when a bankruptcy data sale needs one
By SourceX Editorial · Reviewed by Noah Loul ·
Short answer
A consumer privacy ombudsman is generally needed in a bankruptcy data sale when the estate proposes to sell or lease consumers' personal information in a way the debtor's privacy policy, as it stood at filing, did not permit. Records about business customers, and records de-identified before transfer, usually sit outside that trigger, so split consumer and B2B data early.
Key takeaways
- An ombudsman is generally needed only when a privacy policy in effect at filing barred transfers to unaffiliated parties and the proposed sale or lease does not fit that policy.
- The rule protects consumers, so contact details of people at business customers are generally outside it.
- The ombudsman advises; the court decides whether the transfer is approved and on what conditions.
- A company that sold to both businesses and households should split those records before the assets are marketed.
- A license of de-identified operational records can often proceed without transferring any consumer's personal information.
The trigger test in plain terms#
The trigger test for a consumer privacy ombudsman compares what the debtor promised consumers with what the estate now proposes to do in a court-approved sale outside the ordinary course of business, often called a 363 sale. In general terms, the Bankruptcy Code calls for an ombudsman when every condition below is met.
If the policy allowed the transfer, for instance through a clause permitting transfers as part of a sale of the business, the ombudsman route is generally not needed on that ground. The sale still goes through ordinary court review, and estate counsel decides how the facts map onto the rule.
- The debtor gave individuals a privacy policy when offering them a product or service.
- The policy prohibited transferring personally identifiable information to unaffiliated persons.
- That policy was in effect on the date the case was filed.
- The proposed sale or lease of the information is not consistent with the policy.
Why B2B records usually fall outside the rule#
B2B records usually fall outside the rule because it protects consumers: people who gave information while obtaining goods or services primarily for personal, family or household purposes. A purchasing manager's email address in a distributor's CRM was given on behalf of an employer, not as a household customer.
Outside the rule does not mean unrestricted. Customer contracts, confidentiality clauses and state privacy laws that may apply can still limit what happens to business contact data, so it gets its own review. Mixed businesses need the most care, because one system often holds both kinds of customer.
| Record type | Position under the consumer trigger | Separate review still needed |
|---|---|---|
| Web store accounts of household buyers | Within scope while identifiable | Policy wording on transfers |
| Homeowner or tenant service histories | Within scope while identifiable | Names, addresses and free-text notes |
| Business customer accounts and buyer contacts | Generally outside | Customer contracts and state privacy laws |
| Order exceptions and support threads with business customers | Generally outside | Confidentiality terms in customer agreements; buyer contact details removed before licensing |
| Employee and HR files | Not a consumer record | Employment law and confidentiality |
| De-identified operational records | Often outside, as no person is identified | Re-identification risk and documentation |
Process steps from sale motion to approval#
The process runs alongside the sale itself, and knowing its order helps a trustee plan the timetable. The steps below describe the usual sequence in general terms; local rules and the judge's practice shape the details.
Budget for the role from the start. The ombudsman's fees are generally paid by the estate, subject to court approval, and the ombudsman is expected to keep the personal information it reviews confidential. Building the review into the sale timetable early avoids a postponed hearing.
- The estate describes the personal information in its sale motion and explains how the transfer fits, or does not fit, the privacy policy.
- If the transfer is inconsistent with the policy, the court orders an appointment and the United States Trustee appoints a disinterested ombudsman ahead of the sale hearing.
- The ombudsman reviews the policy, the data involved, the proposed buyer and any conditions already offered.
- The ombudsman reports on potential privacy losses or gains for consumers, costs or benefits to them, and alternatives that would reduce privacy losses, and may be heard at the sale hearing.
- The court decides whether to approve the transfer, considering whether it would violate applicable nonbankruptcy law, and may attach conditions.
Conditions that often come with approval#
Approved transfers of consumer data have often come with a recognizable set of conditions, drawn from ombudsman reports and regulator comments in earlier cases. Offering them up front can shorten the conversation with the court.
A data license can mirror several of these directly. A defined purpose, bans on re-identification and resale, and deletion when the term ends are standard license terms that answer the same concerns.
- The acquirer runs a similar business and will use the information for the same purposes.
- The acquirer adopts the debtor's privacy commitments for the transferred information.
- Consumers are told about the transfer and given a way to opt out or ask for deletion.
- Only the information the acquirer needs is transferred, and sensitive categories are dropped.
- The information is not sold on separately from the business.
Ways to structure the data in a sale or license#
The structure of the transaction decides how much of the ombudsman question arises. Keeping consumer identifiers out of any data transfer is the most direct way to avoid it, and estate counsel can then focus the privacy analysis on whatever identifiable data remains.
Raise the question before the assets are marketed. Bid procedures and the asset purchase agreement define what is being sold, and separating identifiable consumer data from de-identified operational records at that stage avoids reopening the sale later.
| Structure | Consumer personal information moves? | Ombudsman question |
|---|---|---|
| Sale of the business with its customer list | Yes | Turns on whether the policy permits transfer in a sale |
| Standalone sale of a consumer database | Yes | Often the hardest to fit within a policy |
| License of de-identified operational records | No, if the de-identification holds | Often avoided; counsel confirms |
| License of B2B records with contact details removed | No consumer data | Usually outside the consumer trigger |
Illustrative: a distributor with a consumer web store#
Illustrative: a fictional industrial supply distributor enters bankruptcy and its operating assets are put up for sale. Most of its accounts are contractors and facility managers, but a web store also sold tools to homeowners, and both channels run through the same Acumatica ERP and a shared support inbox.
Counsel separates the records by channel. The web store's household accounts, covered by a privacy policy that ruled out sharing with third parties, go to the acquirer of the operating business only after an ombudsman reviews the transfer and the court approves it with conditions. Business-channel order exceptions, return disputes and support threads, with buyer names and emails removed, form a separate package that an AI developer wants to license.
The estate seeks court approval of the license after notice to creditors, explaining that it carries no consumer information and that business contacts were removed. The ombudsman's work stays confined to the web store accounts, which keeps the license off that track entirely.
How SourceX works with estates#
SourceX supports the licensing side of an estate's records while estate counsel handles the bankruptcy process. It begins with a fit check based on metadata alone, such as system names, years of history, customer channels and the privacy policy versions on record, so no files move before the estate decides to proceed.
Within the SourceX five-step transaction, the Rights step captures the privacy promises and contract limits that apply, Preparation removes personal details, and Approval follows the court procedure counsel sets. The SourceX Evidence Packet then holds the privacy record and the release authorization, including the approval order.
Frequently asked questions
Does an assignment for the benefit of creditors need a consumer privacy ombudsman?
An assignment for the benefit of creditors is a state-law process outside the Bankruptcy Code, so the Code's ombudsman provisions do not apply to it as such. The company's privacy promises, state privacy laws and consumer protection law still apply, so the assignee faces similar questions without the same court framework.
Does a business transfer clause in the privacy policy settle the question?
It may help, but read it closely. Many policies allow transfers in a merger, acquisition or sale of assets, and some mention bankruptcy. Whether that wording covers a standalone data sale, or a license to a party that is not acquiring the business, is a question counsel answers from the exact text.
Does the rule apply to a license rather than a sale?
The trigger speaks of selling or leasing personal information, and a license of identifiable consumer data may be treated in a similar way. A license of records with consumer identifiers removed raises the question far less, which is why preparation comes before the transaction is described to the court.
Can the acquirer license the records to AI developers later?
Only within the limits it inherited. An acquirer that agreed to honor the debtor's privacy commitments, or that took the data subject to conditions in the sale order, carries those limits forward. It should check the order and the policy before licensing any records that came from the estate.
What if the company never published a privacy policy?
Without a policy that prohibited transfers, the trigger is not met in its usual form. That does not end the analysis: state privacy laws that may apply, consumer protection law and the court's own review of the sale still matter, and some courts have appointed an ombudsman out of caution where it was unclear what consumers had been promised.
Related resources
See if your company qualifies
A short company assessment. No data uploads are needed.