Skip to content

Wind-downs and transitions

Does a B2B company's bankruptcy data sale need a privacy ombudsman?

By SourceX Editorial · Reviewed by Noah Loul ·

Short answer

A B2B company's bankruptcy data sale needs a consumer privacy ombudsman only in limited cases: generally when the package transfers personally identifiable information about individuals that the debtor's privacy policy restricted. De-identified operational records, such as resolved tickets with names removed, may not raise the question at all. Counsel and the court decide case by case.

Key takeaways

  • The ombudsman question turns on personal information about individuals and the privacy policy that covered it, not on whether the debtor sold to businesses.
  • B2B archives often hide consumer data, such as homeowner addresses pasted into tickets or end-user emails forwarded into support threads.
  • A non-exclusive license of de-identified operational records is a different package from a sale of a customer database, and the sale motion should say so.
  • Pull every version of the privacy policy, because the promises made when records were collected shape what the estate can do with them.
  • Automated redaction needs human review; even maintainers of open-source PII tools say detection is never complete.

When does a bankruptcy data sale raise the ombudsman question?#

A bankruptcy data sale raises the ombudsman question when it would transfer personally identifiable information that the debtor's privacy policy said would not be shared with unaffiliated parties. Under 11 U.S.C. §363(b)(1), if such a policy was in effect when the case commenced, the trustee may not sell or lease that information unless the sale is consistent with the policy or, after a consumer privacy ombudsman is appointed under §332 and after notice and a hearing, the court approves it.

The ombudsman is a disinterested person appointed by the United States trustee. Under §332(b), the ombudsman may appear and be heard and may present the debtor's privacy policy, the potential privacy gains or losses to consumers, the potential costs or benefits to consumers, and alternatives that would reduce privacy losses. The appointment adds a step, a report and often negotiated conditions, so debtor counsel usually wants to know early whether the question will come up.

The trigger is the content of the records and the promises attached to them. Calling the asset a customer list, a database or a data license does not settle the analysis.

Why a B2B debtor is not automatically outside the rule#

A B2B debtor is not automatically outside the ombudsman rule, because business records still contain information about people. The Code's definition in §101(41A) covers items such as an individual's name, home address, email address, home telephone number, Social Security number or credit card number, but only where the individual provided them to the debtor in connection with obtaining a product or service primarily for personal, family or household purposes. That consumer-purpose limitation is why commentary has focused on consumer retailers and consumer apps, and why many B2B archives may fall outside §363(b)(1), although that is an analysis for counsel rather than a settled rule.

Most B2B records sit on the business side of that line: buyer contacts at customer companies, ticket requesters writing from work addresses and vendor representatives. Whether those contacts can fall within the definition is a threshold question practitioners debate, and the answer can depend on the facts and the court.

Separately, some state privacy laws may treat business contact details as personal information. Counsel should assess those laws alongside the bankruptcy analysis rather than assume a B2B label resolves both.

Why a B2B debtor is not automatically outside the rule
Record typeIndividuals insideRule of thumb for the analysis
Customer account list with buyer contactsBusiness contacts at customer companiesUsually framed as business data; confirm the policy and state law position
Support tickets from business usersRequesters, copied users, signatures, pasted detailsDepends on content; de-identification may take it out of scope
Job or service records for residential customersHomeowners and tenantsConsumer data; expect the question to be raised
Employee and HR filesCurrent and former staffUsually excluded from data packages; other laws may apply
De-identified operational recordsNone after preparation, if done wellOften outside the ombudsman analysis, subject to re-identification review
Aggregated metricsNone at record levelRarely raises the question

Where consumer data hides in business records#

Consumer data hides in business records wherever a customer's customer appears. A scheduling platform sold to contractors, a billing tool used by property managers or a logistics portal that tracks residential deliveries can all hold homeowners' names and addresses, even though the debtor never sold to a consumer.

Free text is the usual carrier. Users paste details into ticket bodies, attach screenshots and forward end-customer emails, so a review of structured fields alone misses most of it.

  • Ticket bodies and comments where users pasted end-customer names, addresses or phone numbers.
  • Attachments such as screenshots, exported reports, invoices and site photos.
  • Call recordings and transcripts from support or sales lines.
  • CRM records for sole proprietors, where the business name is a person's name.
  • Email signatures and forwarded threads inside support or sales history.
  • Product logs or database extracts that capture end-user activity.

Does licensing instead of selling change the analysis?#

Licensing instead of selling changes the shape of the transaction but not the privacy question: if personally identifiable information moves, the same promises apply. The statute speaks of selling or leasing such information, so counsel may reasonably treat a license of it the same way. What licensing can change is the content of the package, because a non-exclusive license of de-identified operational records is built to move work patterns rather than identities.

A license also lets the estate keep ownership of the archive. The going-concern buyer, or a later buyer of the remaining assets, can still acquire the records, while the estate receives license fees for a separate prepared copy. That structure needs its own court approval where it falls outside the ordinary course, and the motion should state exactly what is licensed and what is excluded.

Licenses signed before a filing raise different questions. A license agreed shortly before bankruptcy may be examined later for fair value and proper authority, so a distressed board that licenses data should document how it tested the market and who approved the terms.

How to prepare a data package counsel can defend#

A defensible data package is one where counsel can show the court what was in the records, what was removed and which promises covered them. That record matters more than any single redaction technique.

Automated tools help with de-identification but do not finish it. The documentation for Presidio, an open-source PII detection tool, warns that its automated detection cannot guarantee it finds all sensitive information and that additional protections should be used.

How to prepare a data package counsel can defend
StepWhat it producesWho reviews
Inventory systems and record familiesSources, date ranges and fields in scopeDebtor management and counsel
Collect every privacy policy versionA timeline of promises by collection periodDebtor counsel
Check customer contracts and data processing termsRestrictions on use, return or deletionDebtor counsel
De-identify and sample-checkA method description and review resultsPrivacy reviewer with human spot checks
Document the packageProvenance, rights, permitted use and release authorizationCounsel, the buyer and, where required, the court

Illustrative: a scheduling software debtor licenses its ticket archive#

Illustrative: a fictional field service scheduling software company files for Chapter 11 and markets its business. Its Zendesk instance holds years of tickets from contractor customers, linked to Jira issues and release notes, and the likely buyer of the platform has no interest in the legacy ticket archive.

Debtor counsel proposes a non-exclusive license of the archive to an AI developer. The review finds that contractors routinely pasted homeowners' names and addresses into tickets, and the company's privacy policy covered those end users. The team removes personal details from ticket bodies and comments, drops attachments and call recordings entirely, and keeps a sampling record of the review.

The sale motion describes the package as de-identified operational records, attaches the privacy policy history and explains the method. Whether an ombudsman is appointed remains the court's decision, but the question is argued on documented facts rather than assumptions about what a B2B archive contains.

How SourceX approaches data packages in a bankruptcy#

SourceX treats an estate's data package like any other supplier transaction, with the debtor or trustee as the approving party. The SourceX five-step transaction runs Supply, Rights, Preparation, Approval and Delivery, and the Rights step gathers the privacy policy history and contract restrictions counsel needs for the motion.

Each package that proceeds gets a SourceX Evidence Packet recording provenance, licensing rights, permitted use, the privacy record and release authorization. Nothing is shared during the initial fit check, and court approval, where required, sits inside the Approval step rather than after delivery.

Frequently asked questions

Do employee records raise the consumer privacy ombudsman question?

Employee records are generally not what the consumer ombudsman provision is aimed at, but employment, benefits and state privacy laws may still restrict them. In practice, HR files, payroll and performance records are usually excluded from AI data packages entirely, which removes the question rather than arguing it.

What if the privacy policy changed several times over the years?

Collect every version with its effective dates and map each one to the period when records were collected. Records gathered under a stricter version may need to be excluded or handled differently. Counsel assesses which promises govern which records, and the package description should reflect that split.

Can de-identified records be re-identified?

Sometimes, if enough detail remains. Rare job types, small towns, unusual product names or exact dates can point back to a person. Good preparation looks at combinations of fields, not just names, and includes human review of samples. The license should also prohibit the recipient from attempting re-identification.

Who raises the ombudsman issue in practice?

The issue can come from the debtor's own motion, the U.S. Trustee, creditors or the court. Debtor counsel usually addresses it directly in the sale motion by explaining whether personally identifiable information is transferred and how the privacy policy applies, which gives other parties a clear position to respond to.

Should a distressed company license data before filing instead?

Sometimes a pre-filing license preserves value that a rushed process would lose, and it happens while systems and staff are still available. It also invites later scrutiny of price, authority and timing. Boards should document the decision, involve restructuring counsel and handle proceeds consistently with their duties to creditors.

Sources

  • Under 11 U.S.C. §363(b)(1), if a debtor disclosed a policy prohibiting transfer of personally identifiable information to unaffiliated persons and the policy is in effect when the case commences, the trustee may not sell or lease that information unless consistent with the policy or approved by the court after appointment of a consumer privacy ombudsman under §332 and notice and a hearing. Source
  • Under 11 U.S.C. §332(b), the consumer privacy ombudsman may present the debtor's privacy policy, potential losses or gains of privacy to consumers, potential costs or benefits to consumers, and alternatives that would mitigate privacy losses. Source
  • 11 U.S.C. §101(41A) defines personally identifiable information as items such as name, residence address, email, residential phone, SSN or credit card number provided by an individual in connection with obtaining a product or service primarily for personal, family or household purposes. Source
  • Presidio's own documentation warns that "because it is using automated detection mechanisms, there is no guarantee that Presidio will find all sensitive information. Consequently, additional systems and protections should be employed." Source

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify