Skip to content

Definitions and comparisons

What is a consumer privacy ombudsman in bankruptcy?

By SourceX Editorial · Reviewed by Noah Loul ·

Short answer

A consumer privacy ombudsman is a neutral person appointed in a US bankruptcy case to advise the court when the estate proposes selling or leasing customers' personal information in a way its privacy policy did not allow. The ombudsman reports on privacy effects and alternatives; the court decides. De-identified business records often never reach that question.

Key takeaways

  • The ombudsman is an independent adviser to the court, not a regulator, a buyer's advocate or a representative of the debtor.
  • The question generally arises when personal information would move in a way the debtor's privacy policy at filing did not permit.
  • Reports typically weigh the privacy promises made, the buyer's intended use, possible harm to customers and conditions that reduce it.
  • Separating consumer personal data from de-identified operating records early keeps a records license out of the ombudsman's path.
  • Whether an ombudsman is needed in a given case is a question for counsel and the court.

What is a consumer privacy ombudsman?#

A consumer privacy ombudsman is a disinterested person, often a privacy lawyer or a former regulator, appointed in a bankruptcy case to give the court an independent view on a proposed sale or lease of customers' personal information. The ombudsman does not represent the debtor, the buyer or the creditors.

The role exists because a failed company's customer data can be one of its more saleable assets, while the people in that data relied on promises in the privacy policy. The ombudsman helps the court weigh the estate's interest in recovering value against those promises.

The ombudsman advises; the court decides. A report can shape the conditions attached to a sale, but approval or rejection remains with the judge.

When does an ombudsman come into the picture?#

An ombudsman generally comes into the picture when a debtor proposes to sell or lease personally identifiable information about individuals in a way that its privacy policy, as in effect when the case was filed, did not permit. The issue usually arises in a court-approved asset sale, often called a Section 363 sale.

If the transfer is consistent with the policy, the question may not arise at all. If it is not, the court generally needs the ombudsman's input before approving the sale. Whether the data and the policy raise the issue in a particular case depends on the facts, and counsel makes that call early so the sale timetable allows for the review.

What does an ombudsman's report cover?#

An ombudsman's report typically covers what the debtor promised customers, what the buyer intends to do with the data, the potential harm or benefit to customers, and alternatives or conditions that would reduce privacy risk. The table shows what an estate can have ready for each topic.

Estates that arrive with these materials organized tend to have smoother reviews. The most frequent gap is the privacy policy history: companies often changed their policy several times and kept only the current version, so the wind-down team has to reconstruct which version applied to which customers.

What does an ombudsman's report cover?
Report topicQuestion the ombudsman asksWhat the estate should have ready
Privacy promisesWhat did customers agree to when their data was collected?Every privacy policy version, with dates and the records each covered
Data inventoryWhat personal information is in the package?A field-level description by system, including sensitive fields
Buyer and useWho is buying, and will the data be used the same way?The buyer's line of business, intended use and privacy commitments
Harm and benefitCould customers be harmed, or lose a service they rely on?An assessment of risks such as unwanted marketing or exposure
AlternativesCould the sale proceed with less personal data?Options such as de-identification, field removal or opt-outs
ConditionsWhat safeguards should bind the buyer?Draft undertakings the buyer is willing to accept

Conditions ombudsmen commonly recommend#

Ombudsmen commonly recommend conditions that keep the buyer's use close to the original promise made to customers. The mix depends on the data, the buyer and the court, but several themes recur across cases.

An estate that proposes sensible conditions up front usually makes the review faster, because the report can assess a concrete plan instead of an open question.

  • The buyer agrees to honor the debtor's privacy policy for the transferred data.
  • The buyer operates in a similar line of business and uses the data for similar purposes.
  • Customers receive notice and a chance to opt out or ask for deletion.
  • Sensitive fields, such as payment card data or account passwords, are destroyed rather than transferred.
  • Data the buyer does not need is destroyed by the estate after closing.

What an ombudsman means for licensing records out of an estate#

For data licensing, the ombudsman question matters mainly when licensed records would still contain consumer personal information. A license of operational records with personal details removed, such as resolved support tickets, route exceptions or maintenance histories, often does not raise the question, although counsel should confirm.

A non-exclusive license of de-identified records can also run alongside a separate sale of the operating business, so the estate does not have to bundle every data question into one process or one buyer. The license is still a use of estate property, though. Outside the ordinary course of business it generally needs court approval on notice to creditors, even when no ombudsman is involved, so counsel builds it into the case timetable.

What an ombudsman means for licensing records out of an estate
PackagePersonal information involvedOmbudsman question likely?
Consumer customer list with contact detailsNames, emails, addresses, purchase historyLikely, if the policy limits transfer
Consumer accounts inside a product line being soldAccount data needed to keep serving customersPossible; the policy and the buyer's use decide
Business customer CRM recordsNames and contact details of people at client companiesLess likely, but individual contacts still need review
De-identified support and operations recordsPersonal details removed before transferUsually not, if the de-identification holds
Employee and payroll recordsHR, pay and benefits dataDifferent rules apply; usually excluded from any license

Illustrative: a furniture delivery company in Chapter 11#

Illustrative: a fictional regional furniture delivery and assembly company files for Chapter 11. It holds a consumer booking database from its website, route and exception records in its TMS, and years of customer service tickets in its helpdesk.

Its privacy policy said customer information would not be shared with third parties for their own use. The proposed buyer of the delivery business wants the booking database, so counsel expects an ombudsman and prepares the policy history, a field inventory and a proposal that the buyer honor the policy and destroy payment-related fields.

Separately, the chief restructuring officer asks whether route exceptions and resolved tickets could be licensed. After names, addresses and phone numbers are removed from structured fields and free text, and a sample is reviewed, counsel concludes that the de-identified records can be licensed non-exclusively without being folded into the consumer data sale, and seeks the court's approval for that license on notice to creditors.

How SourceX works with estates#

SourceX works with trustees, wind-down officers and their counsel through the SourceX five-step transaction. In the Preparation step, personal and confidential details are removed before any delivery, and in the Approval step the estate's authorized representative releases the package, subject to any court requirements counsel identifies.

Each package's SourceX Evidence Packet sets out where the records came from, the licensing rights, the permitted use, the privacy record and who authorized release. That gives counsel, and where relevant an ombudsman, one written account of what was removed and what was licensed.

Frequently asked questions

Who appoints the consumer privacy ombudsman?

The court orders the appointment, and the United States Trustee generally selects the person. The appointee must be disinterested, meaning free of conflicts with the debtor and the parties. Debtor's counsel usually raises the need early so the sale timetable allows for the review.

Who pays for the ombudsman?

The ombudsman's fees are generally paid by the estate, subject to court approval, like other professionals in the case. That cost is one reason estates try to define data packages narrowly and drop personal information that adds little value to the sale.

Does an ombudsman apply outside bankruptcy?

Not in the same way. Assignments for the benefit of creditors, state receiverships and informal wind-downs follow state processes without this federal role. Privacy policies, state privacy laws and consumer protection enforcement still apply, so the same preparation remains sensible.

What should a company do before filing if customer data may be sold?

Preserve the evidence the review will need before systems or subscriptions are shut off: every privacy policy version with its dates, the systems holding customer records, and exports of the archives themselves. Keep systems running or archived until counsel confirms what the sale process requires, because a deleted helpdesk or CRM cannot be reconstructed later.

Can an ombudsman stop a data sale or license?

An ombudsman cannot stop a transaction alone. The report advises the court, which decides whether to approve the sale and on what conditions. In practice, a critical report can lead the court to require changes or limit what transfers.

Does the ombudsman review business-to-business data?

Generally not. The Bankruptcy Code's definition of personally identifiable information centers on individuals who obtained products or services for personal, family or household purposes, so records about business customers usually sit outside it. B2B records still name individual contacts, and state privacy laws may apply, so they need a field-level review before any sale or license.

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify