Bankruptcy data sales in the AI era: what restructuring practitioners now watch

In bankruptcy, data can be sold or licensed as estate property, but the debtor's privacy promises still bind it: section 363(b)(1) limits transfers of personally identifiable information that a privacy policy prohibited, often requiring a consumer privacy ombudsman and court approval. Operational business records licensed for AI training raise narrower questions, but still need redaction and proper authority.

Why data now appears on the estate's asset list

Data has moved from the storage line of a wind-down budget to the asset schedule. Practitioners now ask early what records a debtor holds, who can export them and what the debtor promised about them, because a buyer category now exists for operational records: AI labs and data buyers looking for records of real work to train and evaluate agents.

The Bankruptcy Code's limits on transferring personal information apply to those transactions just as they applied to customer-list sales, and the 2025 ombudsman report in the 23andMe case, covered below, shows how closely they can be examined. The result is a new first-week question for trustees, debtors' counsel and financial advisers, and a new reason not to let subscriptions lapse before it is answered. Why buyers care is set out in why AI buyers want records from closed and closing companies, and the timing argument in why now is the window for company data licensing.

What the Bankruptcy Code says about selling personal information

Section 363(b)(1) restricts sales of personally identifiable information where the debtor had a privacy policy prohibiting its transfer to unaffiliated persons. If that policy was in effect when the case began, the trustee may not sell or lease the information unless the sale is consistent with the policy, or the court approves it after appointing a consumer privacy ombudsman, giving notice and holding a hearing, and finding no showing that the sale would violate applicable nonbankruptcy law. The text is at 11 U.S.C. 363.

Under 11 U.S.C. 332, when that hearing is required the court orders the US trustee to appoint one disinterested person, other than the trustee, as ombudsman no later than seven days before the hearing. The ombudsman may give the court information such as the debtor's privacy policy, and may not disclose personally identifiable information obtained in that role.

Two practical consequences follow. The privacy policy in force on the petition date becomes a key document, so collect every version rather than the one currently online. And any transaction touching personal information needs room in the sale calendar for an ombudsman, if one is required.

What recent developments signal

DevelopmentDateWhat it signals for practitioners
The consumer privacy ombudsman in 23andMe's bankruptcy recommended that transfers of customers' genetic or personally identifiable data be prohibited absent renewed opt-in consent2025Sensitive data draws close scrutiny, and fresh consent can become the condition for a transfer
FTC staff wrote that quietly and retroactively changing terms to permit uses such as AI training could be unfair or deceptiveFebruary 2024A restrictive privacy policy cannot safely be fixed by amending it after the fact; this is staff guidance, not a rule
HHS guidance on de-identifying protected health information sets out the Expert Determination and Safe Harbor methods under HIPAANovember 2012Health data is out of reach unless de-identified under the HIPAA standard or otherwise authorized

This page does not describe how the 23andMe sale concluded; the ombudsman's recommendation is the point here.

Consumer data and operational records are different assets

QuestionConsumer data (customer lists, profiles)Operational business records (tickets, code, documents)
What it isInformation about individual customersRecords of how the business did its work
Main privacy hookThe privacy policy and consumer privacy lawCustomer contracts, employee notices and the personal data embedded in records
Section 363(b)(1) relevanceCentral where the policy restricted transferCan still apply where records contain customers' personally identifiable information
Typical structureSale with the customer relationships, subject to the policyExclusive license for AI training for an agreed term, with the estate keeping ownership
RedactionOften impossible without destroying the assetAgreed before work begins; names, contact details and identifiers removed as required
AI buyer interestLow for consumer personal data without a licensing basisRecords of real work with outcomes are what AI labs and data buyers look for

Licensing operational records does not avoid the privacy analysis. It narrows it: the question becomes which personal information sits inside the records and how it will be removed, rather than whether a customer list can change hands.

What practitioners now check before a data sale or license

  • Every version of the privacy policy and terms of service, and which one was in force on the petition date
  • Customer contracts with confidentiality, data-use or deletion clauses
  • Employee handbooks and notices covering email, chat and monitoring
  • Whether any records include health, financial or children's data
  • Who holds administrator credentials, and whether exports have been taken
  • Whether the records have already been licensed for AI training
  • How a license fits the bid procedures and any asset purchase agreement
  • Whether creditors, a committee or the court must approve; see do creditors have to approve a data licensing deal
  • Where proceeds go; see who gets the money from a data license in a bankruptcy or ABC
  • Any plan or order provision requiring records to be destroyed

Where licensed business records fit

For a debtor that had 50+ full-time employees at peak (contractors excluded), several years of documented operations and records across many systems, an AI-training license runs as a separate track from the main sale. SourceX qualifies the records, the debtor or fiduciary completes an inventory, and one all-in price and the terms are agreed before AI labs and data buyers review. Nothing binds the estate until it signs, data is delivered only after an executed agreement and the estate's authorization, and payment is one-time, typically within about 60 days of invoicing once a buyer selects the data.

In chapter 7, the trustee's perspective on these assets is set out in overlooked intangible assets in chapter 7.

Limits and open questions

  • Practice is still forming. Expect the US trustee, a creditors' committee or an ombudsman, where one is appointed, to ask how personal information inside operational records will be handled.
  • State privacy laws and contract terms can apply even where section 363(b)(1) does not.
  • A debtor whose records belong mainly to its clients, or consist mainly of consumer or patient data, is usually not a fit.
  • The FTC posts cited here are staff views and can change with agency leadership.

This is general information, not legal, tax or financial advice. Confirm with your own counsel, tax adviser or professional body before acting.

What it means for referral partners

Restructuring professionals often see a case before anyone has thought about the records. A referral partner's role is narrow: introduce the debtor or the fiduciary, disclose the relationship, and leave data handling to SourceX and the estate. Partners earn 25% of the eligible platform fees SourceX actually collects from the referred company's licensing deals, capped at $100,000 per referred company, paid only after the buyer pays and SourceX receives its fee. No reward is guaranteed. Anyone employed by the estate under a court-approved retention should review those retention terms, and any disclosure the court expects, before registering.

Next step

Screen the debtor against the who qualifies baseline or the company fit checker, then register as a partner and introduce the fiduciary or debtor's counsel.

  1. Step 1Share your linkSend your personal link to a company you know.
  2. Step 2Company appliesThe company applies itself at /apply.
  3. Step 3Buyer selects and paysThe buyer selects and pays for the data and SourceX receives its fee.
  4. Step 4You get your rewardYour share of SourceX fees becomes payable.

Common questions

Is a consumer privacy ombudsman required for every data sale in bankruptcy?

No. Under section 363(b)(1) the ombudsman route arises when the debtor's privacy policy, in effect when the case began, prohibited transferring personally identifiable information to unaffiliated persons and the proposed sale is not consistent with that policy. Many operational datasets raise the question only to the extent they contain such information. Counsel should confirm whether the provision is triggered in a given case.

Does section 363(b)(1) apply in an assignment for the benefit of creditors?

Section 363 is a Bankruptcy Code provision, so it governs sales in bankruptcy cases. An ABC runs under state law outside bankruptcy. The debtor's privacy promises, customer contracts and consumer protection laws still bind it, so the underlying analysis looks similar even without an ombudsman process. Confirm the position with counsel in the relevant state.

Can a debtor license data instead of selling it to avoid the privacy limits?

No. The provision covers leases as well as sales, and a license that lets a buyer use personally identifiable information should be expected to face the same scrutiny. Structuring the deal as a license changes ownership, not the promises the debtor made. Removing personal information through agreed redaction is the route that actually narrows the issue.

What should a trustee preserve in the first week of a business case?

Administrator credentials, a list of every system and its renewal date, copies of each version of the privacy policy and terms, and customer contracts with data clauses. Ask the remaining IT staff or managed service provider to confirm exports before any cancellation. These steps cost little and keep both a sale and a license possible.

How is personal information inside operational records handled in a license?

De-identification and redaction requirements are agreed with the company or estate before any work on the data begins, and nothing is delivered until the agreement is executed and the estate authorizes delivery. Data that cannot be cleaned to the agreed standard is left out. Mainly consumer or patient data is usually not a fit at all.

Free resources

By SourceX Partnerships Team · Published 2026-10-09 · Updated 2026-10-09

Know a US company with valuable proprietary data?

Become a referral partner from anywhere we support, get your link and introduce an owner or authorized decision-maker.

Refer a company →

I own a business

Explore licensing your company's data to AI developers worldwide. Start a short assessment; no uploads needed.

Start an assessment