Toysmart and RadioShack: what customer data sales in bankruptcy teach restructuring pros
Toysmart and RadioShack are the cases most often cited for a simple rule: customer data can be sold in bankruptcy only within the privacy promises the debtor made. The Bankruptcy Code now routes certain sales through a consumer privacy ombudsman and court review, which is one reason operational business records are the cleaner asset.
The short answer
Customer data can be sold out of a bankruptcy, but only within the promises the debtor made when it collected the data. Toysmart and RadioShack are the two cases practitioners cite most when a debtor wants to sell a customer list it promised to protect. Whether a particular sale can proceed depends on what the privacy policy said, what kind of data is involved and whether a buyer will honor the original promises.
For restructuring professionals, the practical lesson is to inventory privacy commitments as early as you inventory liens. For anyone thinking about licensing records to AI developers, the lesson is sharper: consumer data carries the heaviest baggage, and operational business records usually carry far less.
What do the Toysmart and RadioShack cases show?
Both were retail debtors that held customer information collected under privacy policies. In both, the fight was over whether the debtor could sell personal data despite what customers had been told. Commentary on bankruptcy and privacy treats Toysmart as the origin of the Code's privacy provisions and RadioShack as the large modern example. The sources in our library do not cover the dockets, so read the court filings and regulators' public statements before relying on any detail beyond that outline.
The lesson is the same either way. The privacy policy in force when the case began is the starting point, regulators and states can object, and a sale that honors the original promises or rests on consent is easier to approve.
What the Bankruptcy Code requires: the privacy limit and the ombudsman
Section 363(b)(1) of the Code says that if the debtor's privacy policy in effect when the case began prohibits transferring personally identifiable information to unaffiliated persons, the trustee cannot sell or lease that information unless the sale is consistent with the policy, or the court approves it after notice and a hearing and a finding that no showing was made that the sale would violate applicable nonbankruptcy law. That approval also requires a consumer privacy ombudsman. Under 11 U.S.C. section 332, the court orders the US trustee to appoint one disinterested person as ombudsman no later than 7 days before the hearing. The ombudsman may give the court information such as the debtor's privacy policy and may not disclose personally identifiable information obtained in that role.
Two details matter in practice. The Code has its own definition of personally identifiable information, so counsel should check whether a given data set, such as business contact data, falls inside it. And the test looks at the policy in force when the case began, so a later rewrite does not change the starting point.
How has the question changed for sensitive data and AI training?
The pattern has continued with more sensitive data. In the 23andMe bankruptcy in 2025, the consumer privacy ombudsman recommended that any transfer of customers' genetic or personally identifiable data be prohibited without renewed opt-in consent. Whatever a given case's outcome, that recommendation shows how high the bar sits for sensitive categories.
AI training adds another layer. FTC staff stated in January 2024 that companies' promises not to use customer data for undisclosed purposes, such as training or updating models, are enforceable wherever the promise was made, from privacy policies to terms of service. A buyer that acquires consumer data in a sale and then trains models on it inherits that exposure.
How the lessons apply in common situations
| Situation | What to check | Typical outcome to confirm with counsel |
|---|---|---|
| Retail or consumer debtor selling a customer list | The privacy policy text in force on the petition date | Ombudsman process likely; expect a narrowed, consent-based or policy-bound transfer |
| Policy expressly allowed transfer in a sale of the business | Whether the proposed buyer and use fit the policy's wording | May proceed without an ombudsman, but state privacy law and FTC expectations still apply |
| Sensitive data such as genetic, health or children's information | Category-specific laws and the ombudsman's view | Expect opt-in consent or exclusion |
| Buyer wants the data to train AI models | Whether the original notices covered that use | Treat it as a new purpose; expect objections without consent or de-identification |
| B2B company selling operating records such as tickets, project files and internal documents | Customer contracts, confidentiality terms, employee notices | Ombudsman less likely; court approval of any transaction outside the ordinary course is still needed |
| Mixed records with some consumer data | Whether the consumer data can be carved out | Separate it, then license or sell the rest |
For the court-approval mechanics of selling or licensing estate property, see section 363(f) sales and IP licensees. For how the same contract questions play out at a service business, the guide on an MSP going out of business separates client-owned from provider-owned records.
Why SourceX works with operational records instead
SourceX licenses records of how a business worked, not lists of who its customers were. AI developers training and evaluating agents need multi-step records with outcomes: support tickets and resolutions, project histories, engineering reviews, approvals and exceptions. SourceX looks for those records at US companies with 50+ full-time employees at peak (contractors excluded), and a company whose data is mainly consumer personal information with no licensing basis is screened out.
The structure avoids the Toysmart problem at the source. The company keeps ownership and grants a license, de-identification and redaction rules are agreed before work begins, and nothing is delivered without an executed agreement and the authorization of whoever controls the assets. In a case, that means the trustee or the debtor in possession, with court approval where required. The guide to overlooked intangible assets in chapter 7 covers how trustees find and assess these records.
Good practice for the estate
- Pull every version of the privacy policy and terms, and confirm which one was live on the petition date.
- Map each data category to the promises that cover it, including marketing opt-ins and app notices.
- Tell the US trustee early if personally identifiable information is in any sale package, and budget for an ombudsman.
- List consumer data and business records as separate assets so one does not hold up the other.
- Document what will be de-identified, by which method and who verifies it.
- Disclose any referral or finder relationship to the client and, where you are court-retained, to the court; the comparison of CRO, turnaround consultant and interim CEO roles explains why the role matters.
Questions to ask your counsel
- Which privacy policy was in effect on the petition date, and does it prohibit transfer to unaffiliated persons?
- Does any of the data meet the Code's definition of personally identifiable information?
- Do state privacy laws, earlier regulator settlements or vendor contracts restrict the data?
- Will the sale or license motion need an ombudsman, and what will that cost the estate?
- Can the operating records be offered separately from the consumer data?
- Would a license rather than a sale change the analysis before this court?
This is general information, not legal, tax or financial advice. Confirm the approach with your own counsel before acting.
Next step
If a debtor holds years of operational records rather than consumer lists, check it against who qualifies or run the company fit checker. Then register as a partner and introduce the trustee, the debtor in possession or another authorized sponsor.
- Step 1Share your linkSend your personal link to a company you know.
- Step 2Company appliesThe company applies itself at /apply.
- Step 3Buyer selects and paysThe buyer selects and pays for the data and SourceX receives its fee.
- Step 4You get your rewardYour share of SourceX fees becomes payable.
Common questions
Does section 363(b)(1) apply to business customer lists?
Usually less directly, but the answer turns on the Code's own definition of personally identifiable information, which counsel should read against the actual list. A list of business contacts may fall outside it, yet contracts, confidentiality terms, state privacy laws and the debtor's own published promises can still restrict a sale, so counsel should review the list before it joins an asset package.
When should a debtor raise the ombudsman issue with the US trustee?
As soon as personally identifiable information is part of a possible sale package. Section 363(b)(1) can require a hearing and an ombudsman appointed at least 7 days beforehand, so the timing affects the sale calendar. Counsel should also ask who bears the ombudsman's cost under the court's orders, and consider offering consumer data and business records as separate assets.
Does calling the deal a license instead of a sale avoid these rules?
Do not rely on the label. Section 363(b)(1) covers selling or leasing personally identifiable information, and a court looking at a broad license of a consumer list will focus on what the recipient can do with the data. The safer route is to keep consumer data out of scope, or to obtain consent, rather than to restructure the paperwork.
Can a debtor change its privacy policy before filing to allow a sale?
The Code looks at the privacy policy in force when the case began, so a later change does not rewrite promises already made. Any change should be prospective and clearly communicated, and for sensitive categories the realistic path is fresh consent from the people concerned. Counsel should review the policy history and any regulator or state positions before a sale is proposed.
Why are operational business records easier to license than customer lists?
They describe how work was done rather than who bought what. Tickets, project files and internal approvals are usually created by employees for the company, so ownership is clearer, and personal details inside them can be redacted under rules agreed before any work starts. They also carry the multi-step, outcome-labeled detail AI developers need to train and evaluate agents.
Related pages
- Section 363(f) free-and-clear sales and IP licensees: what survives when a licensor files
- MSP going out of business: what happens to client data and the MSP's own records
- Overlooked intangible assets in chapter 7: what trustees should look for
- CRO vs turnaround consultant vs interim CEO: mandates, duties and referral conflicts
- Which US businesses are a fit for a SourceX data licensing introduction
- Check Company Fit for Data Licensing
Free resources
- Business succession planning assessment — Ten questions on successor, transition and documentation.
- NPV calculator — Net present value with a discounted cash flow table.
- Time value of money calculator — Future and present value with optional regular payments.
- All free tools · MCP resource center
By SourceX Partnerships Team · Published 2026-10-09 · Updated 2026-10-09
Know a US company with valuable proprietary data?
Become a referral partner from anywhere we support, get your link and introduce an owner or authorized decision-maker.
Refer a company →I own a business
Explore licensing your company's data to AI developers worldwide. Start a short assessment; no uploads needed.
Start an assessment