Skip to content

Wind-downs and transitions

Section 363 sales of customer data: privacy policy limits explained

By SourceX Editorial · Reviewed by Noah Loul ·

Short answer

In a Section 363 sale, the debtor's privacy policy can limit which customer data transfers. If the policy permits transfer in a sale, the data can generally move on consistent terms; if it prohibits transfer, the Bankruptcy Code generally calls for court approval after a consumer privacy ombudsman is appointed. B2B records and de-identified operating data raise different questions.

Key takeaways

  • Start with the privacy policy in effect when the case was filed, plus the earlier versions under which data was collected.
  • A policy that allows transfer in a business sale usually lets customer data move on terms consistent with that policy.
  • A policy that prohibits transfer generally brings in a consumer privacy ombudsman and specific court findings before approval.
  • The bankruptcy personal-information rule centers on individuals; B2B contact records and de-identified operating records need their own analysis.
  • Separating customer lists from prepared operational records keeps a privacy dispute from holding up the whole sale.

How does a Section 363 sale treat customer data?#

A Section 363 sale treats customer data as estate property that can be sold with court approval, with an added check when the data is personally identifiable information covered by the debtor's privacy policy. The asset purchase agreement, the sale motion and the proposed order describe what data moves and on what conditions.

For restructuring counsel and debtor CFOs, the practical question is which data sits in which category. A consumer customer list, a CRM of business contacts, a support archive and a de-identified set of operating records can each be treated differently, and a single undifferentiated data lot invites objections.

Before the sale motion is filed, build a short data schedule: each data set, the system it lives in, the personal fields it holds, the policy version that covers it and whether the buyer actually needs it. That schedule becomes the backbone of the motion, the bid procedures and any ombudsman review, and it often shows that the buyer can do without the most sensitive fields.

When does a privacy policy limit the sale?#

A privacy policy limits the sale when it told individuals that their personal information would not be transferred to unaffiliated parties. The Bankruptcy Code's sale provision includes a specific rule for that situation, and it generally looks to the policy in effect when the case was filed.

Collect every version of the policy, with dates, and map which data was collected under which version. Read the transfer, merger and sale language closely: many policies allow transfer as part of a business sale, while others promise that data will never be sold or shared.

Also check terms of service, in-app notices, signup screens and promises in marketing or sales materials. Regulators may treat statements made outside the formal policy as commitments too, so counsel usually reviews them together.

Decision tree: permits, silent or prohibits#

The decision tree turns on what the policy says about transfers, and each branch leads to a different sale path. Treat the table as a map of questions for counsel, not as a prediction of how any court will rule.

Even on the permits branch, state privacy laws and consumer protection rules may still govern how the buyer uses the data, so the sale order often records the buyer's commitments.

Decision tree: permits, silent or prohibits
Policy position at filingGeneral sale pathWhat the court and parties look for
Permits transfer in a sale or mergerSale generally proceeds on terms consistent with the policyThe exact clause, the policy version and the buyer's commitment to honor it
Silent on transfersThe specific bankruptcy privacy rule may not be triggered, but consumer protection and state privacy law still applyWhether individuals were led to expect no transfer, and how the buyer will use the data
Prohibits or limits transferSale must fit within the policy, or the court approves after a consumer privacy ombudsman is appointedConditions such as same use, same line of business, the buyer adopting the policy and consent before material changes
No personally identifiable information in scopeThe specific privacy rule may not apply at allContract confidentiality, customer data terms and whether de-identification holds up

What a consumer privacy ombudsman looks at#

A consumer privacy ombudsman gives the court an independent view of the privacy effects of a proposed sale of personal data. When a hearing is required under the privacy rule, the court orders the U.S. trustee to appoint one disinterested person as ombudsman no later than 7 days before the hearing. The ombudsman may present the debtor's privacy policy, the potential privacy losses or gains for consumers, the potential costs or benefits, and alternatives that would reduce privacy losses. In practice the review tends to work through questions like these.

Plan the sale timeline with the ombudsman step in mind. Bidders value certainty, so describing likely privacy conditions in the bid procedures can reduce surprises at the sale hearing.

  • Which privacy promises were made, in which documents, and when.
  • Which data fields are in the sale, and which could be dropped without hurting the buyer's use.
  • Whether the buyer will use the data for the same purposes and in the same line of business.
  • Whether individuals should receive notice or a chance to opt out before transfer.
  • Whether sensitive categories should be destroyed rather than transferred.

What RadioShack and 23andMe show about sale conditions#

The RadioShack and 23andMe cases show the conditions regulators typically ask for when customer data is sold out of bankruptcy. RadioShack filed Chapter 11 in Delaware in February 2015, and in May 2015 the FTC's consumer protection director wrote to the consumer privacy ombudsman recommending that customer data not be sold as a standalone asset, and that it go only to a buyer in substantially the same line of business that agreed to be bound by the privacy policy and to obtain consumers' affirmative consent before material changes.

State attorneys general led by Texas also objected, citing a widely reported privacy statement: "We do not sell our mailing list." The court approved a sale of the brand and related customer data in May 2015, reported at $26.2 million, after a settlement with the states narrowed the categories and age of the customer data transferred.

The pattern held a decade later. After 23andMe filed Chapter 11 in March 2025 to pursue a Section 363 sale, the FTC chairman wrote to the U.S. Trustee that any purchaser should expressly agree to be bound by the company's privacy policies and applicable law. Debtors should expect conditions like these and write them into the bid procedures early rather than contest them at the sale hearing.

Are B2B customer records treated the same as consumer data?#

B2B customer records are not automatically treated the same as consumer data, because the Bankruptcy Code defines personally identifiable information around consumers. The definition covers items such as an individual's name, residence address, email address, home telephone number, Social Security number or credit card number, provided to the debtor in connection with obtaining a product or service primarily for personal, family or household purposes, plus certain linked data such as birth date. Contact names and work emails at corporate customers may fall outside that definition, but the answer depends on the facts and on how the court reads them.

B2B debtors still face limits from other sources. Customer contracts often carry confidentiality and data-return clauses, employee and end-user data can sit inside business accounts, and some state privacy laws treat business contact data as personal information. A software debtor's platform can also hold consumer data that its business customers collected, which those customers control under their contracts.

De-identified operating records, such as support tickets with names and account details removed, can sit outside the personal-information question if the de-identification is sound. Objectors will ask how it was done, so document the method.

Illustrative: a field service software debtor splits its data#

Illustrative: a fictional vertical software company that sells scheduling software to plumbing and HVAC contractors files for Chapter 11 and markets its platform in a Section 363 sale. Its HubSpot CRM holds business contacts at contractor customers, its platform database holds homeowner names and addresses entered by those contractors, and Zendesk holds many years of support tickets.

Counsel separates three categories. The platform and the contractor customer contracts go to the platform buyer, with homeowner data handled under the customer contracts rather than sold as a list. The CRM transfers on terms consistent with a privacy policy that allowed transfer in a sale.

The support tickets, with personal and customer-identifying details removed, are offered as a separate non-exclusive license. The sale motion describes that license on its own, so the court and objectors can see exactly what is licensed and what stays out.

How SourceX approaches data in a sale process#

SourceX works on the licensing of prepared operational records, not on the sale of customer lists. In a court-supervised case, the SourceX five-step transaction of Supply, Rights, Preparation, Approval and Delivery runs alongside the sale process, and the court order or the estate representative's authorization serves as the release authorization.

The SourceX Evidence Packet records provenance, licensing rights, permitted use, the privacy record and release authorization, giving the court, any ombudsman and the buyer one document that shows what was removed and what was approved. SourceX does not give legal advice; debtor's counsel decides how a license is presented to the court.

Frequently asked questions

Which version of the privacy policy matters?

The policy in effect when the case was filed generally matters most, but data collected under earlier versions may carry the promises made at that time. Gather every dated version, map data to versions, and let counsel decide which commitments apply to which records.

Can a debtor change its privacy policy just before filing?

Changing a policy shortly before filing to permit a sale is risky. Regulators may see a retroactive change as deceptive, and objectors may argue it does not reach data collected earlier. Any change should go through privacy and restructuring counsel first.

Does de-identified data still count as personally identifiable information?

Properly de-identified data generally falls outside personal-information rules, but weak methods can leave records that identify people when combined with other data. Document the method, test for re-identification risk, and keep any key linking original and prepared records out of the sale.

Does the buyer have to follow the debtor's old privacy policy?

Often the sale order requires it, at least for data collected under that policy, along with limits on use and a duty to obtain consent before material changes. The exact conditions come from the sale order and any ombudsman recommendations the court adopts.

Is licensing customer data different from selling it in a 363 sale?

A license grants defined use while the estate keeps ownership, but the bankruptcy personal-information rule is generally read to reach leases of personal data as well as sales, so calling a deal a license does not avoid the privacy question. Prepared, de-identified operating records are the cleaner path.

Sources

  • Under 11 U.S.C. 363(b)(1), if a debtor's policy in effect at commencement prohibits transfer of personally identifiable information, the trustee may not sell or lease it unless consistent with the policy or approved by the court after a consumer privacy ombudsman is appointed and notice and a hearing. Source
  • 11 U.S.C. 332 requires appointment of a consumer privacy ombudsman not later than 7 days before the hearing, and the ombudsman may present the privacy policy, potential privacy losses or gains, costs or benefits, and mitigating alternatives. Source
  • 11 U.S.C. 101(41A) defines personally identifiable information by reference to information provided in connection with obtaining a product or service primarily for personal, family or household purposes. Source
  • RadioShack filed for Chapter 11 on February 5, 2015 in the U.S. Bankruptcy Court for the District of Delaware. Source
  • The FTC recommended that RadioShack customer data not be sold as a standalone asset and go only to a buyer in substantially the same line of business bound by the privacy policy and obtaining affirmative consent before material changes. Source
  • Texas objected to the RadioShack customer data sale, citing the statement "We do not sell our mailing list." Source
  • The court approved the sale of the RadioShack brand and related customer data for a reported $26.2 million after a settlement with state attorneys general narrowed the data transferred. Source
  • 23andMe filed Chapter 11 on March 23, 2025 to pursue a Section 363 sale process. Source
  • The FTC chairman wrote to the U.S. Trustee that any 23andMe purchaser should expressly agree to be bound by its privacy policies and applicable law. Source

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify