Skip to content

Privacy and preparation

Customer data in bankruptcy: when a consumer privacy ombudsman is appointed

By SourceX Editorial · Reviewed by Noah Loul ·

Short answer

A consumer privacy ombudsman is appointed in a US bankruptcy case when the debtor proposes to sell or lease personally identifiable information in a way its privacy policy, in effect when the case began, does not allow. Under 11 U.S.C. sections 332 and 363(b)(1), the ombudsman advises the court on privacy effects and alternatives.

Key takeaways

  • Under 11 U.S.C. section 363(b)(1), the ombudsman question turns on the privacy policy in force when the case began and what it promised about transfers.
  • The US trustee appoints the ombudsman, who advises on privacy gains and losses, costs and alternatives; the judge decides whether and on what terms the sale goes ahead.
  • The Code's definition of personally identifiable information is aimed at consumers, so business customer, vendor and employee records need a separate review.
  • Assignments for the benefit of creditors and out-of-court wind-downs have no ombudsman, but privacy promises and state law still apply.
  • Licensing de-identified operating records is a different transaction from selling a customer list, though it usually still needs court approval in a bankruptcy case.

When is a consumer privacy ombudsman appointed?#

A consumer privacy ombudsman is appointed when a debtor in a US bankruptcy case proposes to sell or lease personally identifiable information in a way its privacy policy did not permit. Under 11 U.S.C. section 363(b)(1), if the debtor disclosed a policy prohibiting transfer of that information to unaffiliated persons, and the policy was in effect when the case began, the sale can proceed only if it is consistent with the policy or the court approves it after an ombudsman is appointed and a hearing is held.

When that hearing is required, section 332(a) has the court order the United States trustee to appoint one disinterested person, other than the US trustee, as ombudsman no later than 7 days before the hearing. The court then gives due consideration to the facts, circumstances and conditions of the sale, and may approve it only if no showing is made that it would violate applicable nonbankruptcy law.

The trigger is a promise. Many consumer-facing companies told customers their information would not be sold, rented or shared with unaffiliated companies. When a buyer of the business wants the customer list, order history or account records, that promise collides with the estate's duty to get the best value for its assets.

The Code's own definition, in section 101(41A), covers items such as a first and last name, home address, email address, a telephone number for contacting the person at home, a Social Security number and a credit card account number, when the individual provided them to obtain a product or service primarily for personal, family or household purposes. A company that sold mostly to other businesses should ask counsel early whether its records fall inside that definition at all.

What does the ombudsman actually review?#

The ombudsman reviews how the proposed sale would affect the customers whose information would be transferred, and reports to the court before the sale is decided. Section 332(b) lets the ombudsman appear and be heard and present the debtor's privacy policy, the potential losses or gains of privacy to consumers, the potential costs or benefits to consumers, and potential alternatives that would mitigate privacy losses or costs. Section 332(c) bars the ombudsman from disclosing personally identifiable information obtained in the case.

In practice the ombudsman wants documents, not summaries: every version of the privacy policy with the dates each was in force, a description of each data set and how it was collected, the buyer's identity and line of business, and what the buyer plans to do with the information. Recommendations in past cases have tended to be conditions rather than a plain yes or no, such as the ones below.

  • The buyer operates in substantially the same line of business and uses the data for similar purposes.
  • The buyer agrees to be bound by the privacy policy customers relied on, as a successor to the debtor.
  • The buyer obtains customers' affirmative consent before making material changes to how their data is used.
  • Categories the buyer does not need, such as Social Security numbers, birth dates or payment card numbers, are excluded.
  • Records that are not sold are destroyed under a documented plan when the case closes.

What have past cases shown about customer data in bankruptcy?#

Past cases show that promises made to customers follow the data into insolvency, and that conditions usually narrow what transfers rather than block every sale. The consumer privacy provisions themselves were added by the Bankruptcy Abuse Prevention and Consumer Protection Act of 2005, after disputes such as Toysmart.

The cases below are public examples, not predictions. Each turned on its own privacy policy, data and buyer, and later courts are not bound to follow the same conditions.

What have past cases shown about customer data in bankruptcy?
CaseWhat happenedWhat it shows
Toysmart, 2000The FTC sued in July 2000 to block a sale of customer data collected under a policy promising it would never be shared with third parties; press reports in January 2001 said a settlement provided for the list to be destroyedA clear no-sharing promise can leave a customer list with little or no sale value
RadioShack, 2015After its February 2015 Chapter 11 filing in Delaware, the FTC's consumer protection director recommended in May 2015 that customer data go only to a buyer in substantially the same line of business, bound by the privacy policy and obtaining affirmative consent before material changes; state attorneys general led by Texas objected, and the court approved a sale of the brand and related customer data in May 2015 after a settlement narrowed the categories and age of data transferredNegotiated limits on which fields and how many years of data transfer can make a sale approvable
23andMe, 2025The company filed Chapter 11 on March 23, 2025 in the Eastern District of Missouri to run a court-supervised sale; on March 31, 2025 the FTC Chairman wrote to the US trustee that any purchaser should expressly agree to be bound by its privacy policiesRegulators still press for a buyer to honor existing promises, especially for sensitive data
Spirit Airlines, 2026Reporting in August 2026 on filings in the Southern District of New York described a sale of the airline's internal business data, such as emails, Teams messages and files, that excluded passenger profiles, loyalty records and privileged legal materials, with personal information stripped by a third party and re-identification attempts barredInternal operating records can be separated from customer data, with exclusions and no-reidentification terms written into the deal; check the docket for the final order

Which wind-down paths involve an ombudsman?#

Only bankruptcy cases involve a consumer privacy ombudsman; other wind-down paths leave the privacy policy question to the parties and their counsel. That does not make the question smaller, because transferring data against a published promise can draw attention from the Federal Trade Commission or state attorneys general whatever the procedure.

The table shows how the question usually arises in each path. Use it to frame a first conversation with counsel, not as a conclusion.

Which wind-down paths involve an ombudsman?
PathWho approves a data transferOmbudsman possible?What still applies
Chapter 11 sale of assetsBankruptcy court, on the debtor's motionYes, if the sale does not fit the privacy policyPrivacy policy, state privacy laws, contracts
Chapter 7 liquidationBankruptcy court, on the trustee's motionYes, on the same testPrivacy policy, state privacy laws, contracts
Assignment for the benefit of creditorsThe assignee under state lawNoPrivacy policy, state privacy and consumer protection law
ReceivershipThe receiver, under the appointing court's ordersNoPrivacy policy, court orders, state law
Out-of-court wind-downThe board and officersNoPrivacy policy, contracts, state privacy laws

How is licensing de-identified records different from selling a customer list?#

Licensing de-identified records differs from selling a customer list because the buyer receives a record of the work, not a way to reach the people. A customer list exists to identify and contact individuals; de-identified support tickets, job histories or order exceptions are prepared so that no individual can reasonably be identified.

That difference matters for the ombudsman analysis. If the licensed records no longer contain personally identifiable information, the privacy policy question may not arise for that package. Whether the de-identification holds is a legal judgment for counsel and, if contested, for the court. The Spirit Airlines reporting shows the pattern: internal records offered, passenger profiles and loyalty records left out.

Two points do not change. A license of estate property outside the ordinary course of business usually needs notice and court approval, like a sale. And the motion should describe the de-identification method plainly, because creditors, the US Trustee or an ombudsman already appointed for other assets may ask about it.

How is licensing de-identified records different from selling a customer list?
QuestionCustomer list saleDe-identified records license
What transfersNames, contact details, account and purchase dataOperating records with personal details removed
Ownership after the dealPasses to the buyerStays with the estate; the buyer receives a license
Privacy policy conflictOften directReduced if the de-identification holds, for counsel to confirm
OmbudsmanLikely if the policy restricts transfersDepends on whether personally identifiable information remains
Court approvalRequiredUsually required outside the ordinary course
Buyer obligationsHonor the privacy policy and court conditionsNo re-identification, permitted-use limits, deletion at term end

What should a trustee or wind-down officer do first?#

A trustee or wind-down officer should first preserve two things before systems and subscriptions are switched off: the records themselves and the evidence of what customers were promised. Without both, neither a sale nor a license can be described accurately to the court.

The order matters. Exports taken in a hurry after a vendor's termination notice often lose metadata such as collection dates and source systems, which are exactly what an ombudsman or a buyer will ask to see.

  • Collect every version of the privacy policy and terms of service, with the dates each was posted, from website archives, content management history and counsel's files.
  • Map each data set to the policy versions in force when its records were collected.
  • Separate consumer records from business customer, employee and vendor records, since each follows different rules.
  • Keep systems running, or export them under a documented chain of custody, until the sale or license process is settled.
  • Decide which assets to offer, such as the customer list, de-identified operating records or both, and describe each in the motion.
  • Raise the ombudsman question with counsel before the motion is filed, not after an objection.

Illustrative: a home services company in Chapter 11#

Illustrative: a fictional residential HVAC and plumbing company files for Chapter 11 and plans to sell its operating branches. Its records include a homeowner list with names, addresses and phone numbers, years of job histories in its field service software, and call recordings. Its website privacy policy said customer information would not be shared with unaffiliated companies except service providers.

The branch buyer wants the homeowner list and service histories so it can keep serving those households. Counsel advises that the transfer does not fit the policy as written, and the court directs the US trustee to appoint an ombudsman, who recommends that the buyer be bound by the existing policy, notify customers of the change of ownership and leave stored card data behind.

Separately, the chief restructuring officer proposes to license de-identified job records to an AI developer: equipment types, symptoms, diagnoses and repairs, with no names, addresses or recordings. The motion describes the preparation method and the license limits, the ombudsman's report addresses both transactions, and the judge approves each with conditions.

How SourceX works with trustees and wind-down officers#

SourceX works with trustees, wind-down officers and restructuring professionals on the licensing side of an estate's records, alongside the estate's own counsel. Work starts with a fit check that uses metadata only: which systems exist, how many years of records they hold and when subscriptions end. No files are shared during that assessment.

For any package that proceeds, the SourceX five-step transaction runs Supply, Rights, Preparation, Approval and Delivery, and the SourceX Evidence Packet records provenance, licensing rights, permitted use, the privacy record and release authorization. In a bankruptcy case, release authorization points to the court order and the conditions it sets.

Frequently asked questions

Who pays for the consumer privacy ombudsman?

The ombudsman's fees are generally paid by the estate, subject to court approval, in the same way as other professionals in the case. That cost is one reason debtors and buyers sometimes shape a sale so it fits the existing privacy policy. Counsel can weigh whether the likely value of the data assets justifies the added process.

Can a company change its privacy policy just before filing?

A last-minute change rarely solves the problem. The Bankruptcy Code looks at the policy in force when the case begins, but regulators look at what customers were promised when they gave their information, and applying looser terms to older records without consent can be treated as deceptive. Discuss any policy change with counsel first.

Does an ombudsman review employee or business contact records?

Usually not, because the Bankruptcy Code's definition of personally identifiable information is aimed at consumers. Employee files, vendor contacts and business customer records can still carry duties under state privacy laws, employment law and contracts, so they need their own review even when no ombudsman is involved.

What happens to customer data that no one buys?

Unsold data is typically destroyed or returned under a plan the court approves or, outside bankruptcy, one the officers document. Keep a deletion record naming the systems, dates and methods. Records needed for tax, payroll or litigation may have to be kept longer, so check retention duties before deleting anything.

Can the estate license records while the case is still open?

Often, with the right approvals. A license of estate records outside the ordinary course of business usually goes to the court on notice, and the motion should explain what is licensed, in what form and on what terms. Planning early lets a license run alongside the asset sale instead of delaying it.

Sources

  • Under 11 U.S.C. 363(b)(1), if a debtor disclosed a policy prohibiting transfer of personally identifiable information to unaffiliated persons and the policy is in effect when the case commences, the trustee may not sell or lease that information unless the sale is consistent with the policy or, after appointment of a consumer privacy ombudsman under section 332 and notice and a hearing, the court approves it after finding no showing that the sale would violate applicable nonbankruptcy law. Source
  • 11 U.S.C. 332(a) requires the court to order the United States trustee to appoint, not later than 7 days before the hearing, one disinterested person other than the US trustee as consumer privacy ombudsman; 332(b) lists what the ombudsman may present and 332(c) bars disclosure of personally identifiable information obtained in the case. Source
  • 11 U.S.C. 101(41A) defines personally identifiable information to include name, residence address, email address, a telephone number for contacting the individual at the residence, Social Security number or credit card account number, if provided in connection with obtaining a product or service primarily for personal, family or household purposes. Source
  • The Bankruptcy Code's consumer-privacy provisions for sales of personally identifiable information were added by the Bankruptcy Abuse Prevention and Consumer Protection Act of 2005, Pub. L. 109-8. Source
  • In July 2000 the FTC sued Toysmart.com to block the sale of customer data collected under a privacy policy promising it would never be shared with third parties; press reports said the customer list was to be destroyed under a settlement. Source
  • In May 2015 the FTC's Bureau of Consumer Protection director recommended to the RadioShack ombudsman that customer data be transferred only to a buyer in substantially the same line of business that agrees to be bound by the privacy policy and to obtain affirmative consent before material changes. Source
  • In May 2015 the Delaware bankruptcy court approved the sale of the RadioShack brand and related customer data after a settlement with state attorneys general narrowed the categories and age of data transferred. Source
  • On March 23, 2025, 23andMe filed voluntary Chapter 11 petitions in the Eastern District of Missouri to pursue a court-supervised sale process. Source
  • On March 31, 2025, FTC Chairman Andrew N. Ferguson wrote to the US Trustee in the 23andMe bankruptcy that any purchaser should expressly agree to be bound by and adhere to 23andMe's privacy policies. Source
  • Reporting on the Spirit Airlines internal data sale states that it excludes passenger profiles, loyalty records and privileged legal materials, that a third party would strip personally identifiable information before delivery, and that the agreement bars re-identification attempts. Source
  • SiliconANGLE reported on August 17, 2026 that, according to filings in the US Bankruptcy Court for the Southern District of New York, Spirit Airlines' internal business data was to be sold in a bankruptcy auction, with a hearing scheduled to consider the deal. Source
  • Court records cited in reporting describe the Spirit Airlines data as emails, Microsoft Teams messages, OneDrive files and SharePoint items. Source

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify