Business records vs personal data: what a bankruptcy estate can license

In a bankruptcy sale, a company's own operational records, such as SOPs, tickets, internal email and decision logs, are mainly a question of ownership and contracts, while consumer personal data is restricted by section 363(b)(1) when the debtor's privacy policy barred transfers. Estates whose value is mainly consumer data or PHI are a poor fit for SourceX.

The short answer: two kinds of data in one estate

A bankruptcy estate often holds two very different data assets. Operational business records, such as SOPs, runbooks, support tickets, internal email, project files and decision logs, document how the company did its work. Consumer personal data, such as customer names, contact details, purchase histories and account information, describes identifiable people. The Bankruptcy Code puts a specific brake on selling the second kind; the first kind is mainly a question of ownership, contracts and confidentiality.

Ownership of most operational records starts with the employer. Under federal copyright law, a work prepared by an employee within the scope of employment is a work made for hire, and the employer is treated as its author and owner; material from contractors may not belong to the company unless rights were assigned in a signed writing (US Copyright Office, Circular 30). Those employee-created records are the core of what AI labs and data buyers license, because they show real multi-step work and how it turned out.

What section 363(b)(1) actually restricts

The restriction is narrower than many people assume: it concerns personally identifiable information covered by a privacy policy that barred transfers.

Under 11 U.S.C. 363(b)(1), if the debtor disclosed a privacy policy prohibiting the transfer of personally identifiable information to unaffiliated persons, and that policy was in effect when the case began, the trustee may not sell or lease that information unless the sale is consistent with the policy, or the court approves it after a consumer privacy ombudsman is appointed, notice and a hearing are held, and the court finds no showing that the sale would violate applicable nonbankruptcy law.

When that hearing is required, 11 U.S.C. 332 directs the court to order the US trustee to appoint one disinterested person as ombudsman no later than 7 days before the hearing. The ombudsman may give the court information such as the debtor's privacy policy and may not disclose personally identifiable information obtained in that role.

Two details matter for licensing. The statute speaks of selling or leasing, so ask counsel how a license of records that contain personal information will be characterized. And ombudsmen can take a firm line: in 23andMe's 2025 bankruptcy, the appointed ombudsman recommended that any transfer of customers' genetic or personally identifiable data be prohibited absent renewed opt-in consent (The Record). That case involved consumer genetic data, exactly the category SourceX does not pursue.

How the two categories compare

QuestionOperational business recordsConsumer personal data
Typical examplesSOPs, tickets and resolutions, internal email, Slack or Teams threads, CRM activity, approvals, code reviewsCustomer lists, contact details, order histories, loyalty and account data
Who created itMostly employees doing their jobsMostly collected from or about consumers
Main constraintOwnership, customer and vendor contracts, confidentiality, employee noticesPrivacy policy in effect at filing, section 363(b)(1), state and sector privacy laws
Ombudsman questionDepends on whether personal information inside the records is covered; counsel confirmsLikely to arise when a policy barred transfers
What AI buyers want from itWorkflows, decisions and outcomesRarely the target of a SourceX license
Typical treatmentLicensed with agreed redaction of personal details inside the recordsExcluded, or handled only with a clear legal basis
Fit for a SourceX introductionOften a fit when rights and a signer are clearPoor fit when it is the main asset

Mixed records: where redaction comes in

Most operational records are mixed. A support ticket carries a customer's name and email address; an internal thread mentions an employee's leave. The real question is whether personal details are incidental and removable, or the point of the record.

De-identification and redaction requirements are agreed with the company, or with the fiduciary acting for the estate, before any work begins, and nothing is delivered until a license is executed and delivery is authorized. Points an estate usually wants settled in that agreement:

  • Which fields are removed or masked inside records, such as names, email addresses, phone numbers and account numbers
  • Which whole categories are excluded, such as HR files, privileged legal communications and payment card data
  • Which systems or date ranges are out of scope
  • Who approves the final dataset before it leaves the estate's control

Health information has its own standard. HHS guidance explains that health information de-identified by either Expert Determination or the Safe Harbor method, which removes 18 specified identifiers, is no longer protected health information under the HIPAA Privacy Rule (HHS de-identification guidance). Even so, an estate whose records are mainly PHI is a poor fit for SourceX unless HIPAA authorization or de-identification is already in place.

Which estates are a good fit, and which are not

Estate profile (Illustrative)Likely fitWhy
B2B software company in chapter 11 with eight years of tickets, pull requests and design docsStrong candidateEmployee-created engineering and support records with outcomes
Freight brokerage in chapter 7 with dispatch notes, carrier email and a TMS historyCandidateOperational decisions dominate; driver and contact details can be redacted
Consumer subscription retailer whose main asset is its customer listPoor fitThe value is consumer personal data governed by its privacy policy
Clinic billing group whose records are mostly claims and chartsPoor fit unless de-identified or authorizedPHI is the core of the dataset
Contact-center outsourcer whose work product belongs to its clientsPoor fit without client consentThe estate may not hold the rights
Any debtor whose email tenant and SaaS tools lapsed before filingNo fitNothing is left to license

What this means for a referral partner

For trustees, CROs, assignees and their advisors, the working rule is simple: separate the records the company made from the data it collected about consumers, and lead with the first. The trustee's guide to overlooked intangible assets shows where operational records sit alongside domain names, contracts and code on the schedules.

As a partner you give fit information only: which systems exist, how many years they cover, peak headcount and who controls the estate. You never send samples or describe the contents of confidential records. If a trustee, court or assignee controls the assets, they need to be part of the conversation from the start.

Whether the estate should license the records or sell them outright is a separate decision, covered in licensing data from a bankruptcy estate vs selling it outright. The same split between business records and personal data shows up outside bankruptcy too, in excluded assets in an asset sale. For what typically happens to systems and archives once operations stop, see what happens to company data when a business closes.

Partners earn 25% of the eligible platform fees SourceX actually collects from the referred company's licensing deals, capped at $100,000 per referred company, and the reward becomes payable only after the buyer pays and SourceX receives its fee. The reward is a share of SourceX's fee and never reduces what the estate receives.

Limits and open questions

  • Whether particular information counts as personally identifiable under the Bankruptcy Code, including business contact details in a CRM, is a question for estate counsel.
  • State privacy laws and sector rules can apply alongside the Bankruptcy Code, and requirements vary by state.
  • Court approval requirements depend on the chapter, the transaction and local practice.
  • Privacy promises made in customer contracts, not only the public privacy policy, can limit what is licensed.

This is general information, not legal, tax or financial advice. Confirm with your own counsel, tax adviser or professional body before acting.

Next step

Before the next sale motion or asset schedule, sort the estate's data into business records and consumer data. Run a preliminary check with the company fit checker, confirm the baseline on who qualifies, and register as a partner to make the introduction.

  1. Step 1Share your linkSend your personal link to a company you know.
  2. Step 2Company appliesThe company applies itself at /apply.
  3. Step 3Buyer selects and paysThe buyer selects and pays for the data and SourceX receives its fee.
  4. Step 4You get your rewardYour share of SourceX fees becomes payable.

Common questions

Is a business customer's work email address personal data in a bankruptcy sale?

It can be, depending on how counsel reads the Bankruptcy Code definition, the debtor's privacy policy and any state law that applies. Many estates avoid the question for licensing by masking contact fields inside CRM and ticket records. The operational content, such as the request, the steps taken and the outcome, usually carries the value, so removing names and addresses rarely destroys it.

Is a consumer privacy ombudsman appointed in every bankruptcy data sale?

No. The ombudsman requirement is tied to a specific situation: the debtor disclosed a privacy policy barring transfers of personally identifiable information, the policy was in effect when the case began, and the proposed sale is not consistent with it. Sales of operational records that do not involve such information are generally outside that trigger, though counsel should confirm for each estate.

Can an estate license internal email that mentions customers by name?

Often yes, if the estate owns the email, customer contracts allow it, and the redaction rules agreed before work begins remove or mask names and contact details. Email that consists mainly of consumer correspondence, or that contains health or financial account details at scale, is harder. Estate counsel and SourceX's rights review settle what is in and out of scope before anything is delivered.

Who signs a data license on behalf of a debtor?

The fiduciary in control of the estate signs, acting with whatever court approval counsel says is required. In practice that means establishing early whether the debtor remains in possession or a trustee has taken control, and involving that person before buyers review anything. A former owner or officer who no longer controls the assets cannot authorize a license on their own.

Does licensing records stop the estate from selling the business later?

Not necessarily. A license is not a sale: the estate keeps ownership and grants an agreed set of rights, typically an exclusive AI-training license for an agreed term. A later buyer of the business would need to know about the license, so its terms should be disclosed in any sale process and checked against what bidders are likely to want.

Free resources

By SourceX Partnerships Team · Published 2026-10-09 · Updated 2026-10-09

Know a US company with valuable proprietary data?

Become a referral partner from anywhere we support, get your link and introduce an owner or authorized decision-maker.

Refer a company →

I own a business

Explore licensing your company's data to AI developers worldwide. Start a short assessment; no uploads needed.

Start an assessment