Why User Data Is a Bankruptcy Asset
When a company files for bankruptcy, a court-supervised process identifies every asset that can be used to repay creditors. In a traditional business — a retailer, a manufacturer — assets are things like inventory, equipment, and real estate. For a technology company, one of the most valuable assets is often its user database: the accumulated personal information of everyone who signed up for, purchased, or used the service.
Names, email addresses, phone numbers, purchase histories, behavioral profiles, location data, payment information, health data, and communication records all have commercial value. A company that collected data on millions of users has an asset that advertisers, data brokers, and competitors may be willing to pay for — and in a bankruptcy, the legal obligation to maximize recovery for creditors can override the privacy promises the company made to users when they signed up.
User data collected by a company is classified as intellectual property or personal property in most bankruptcy proceedings — an asset of the estate. When the company's assets are sold to satisfy creditor claims, the data may be sold as part of a broader asset package or as a standalone asset. The new owner — who may have made no privacy promises to users — takes possession of the data. Source: Federal Trade Commission.
What Your Privacy Policy Actually Says About This
Almost every privacy policy includes language addressing what happens to user data in a corporate transaction — acquisition, merger, or bankruptcy. The language is typically buried in a section about "Business Transfers" or "Corporate Transactions," and it almost universally says some version of: your data may be transferred as part of any merger, acquisition, or sale of assets, including in bankruptcy proceedings.
The privacy policy you agreed to when you signed up — the one that said "we will never sell your personal information" — almost certainly also contains this carve-out. "We won't sell your data" and "we may transfer your data in a business transaction" coexist in the same document because they're legally considered different things: selling data to advertisers as a standalone business is different from transferring it as part of an asset sale where the acquiring entity continues operating under certain commitments.
When a privacy policy says "we do not sell your personal data," that statement applies to the current business operating under current management. A bankruptcy trustee or acquiring company is not the same legal entity and is not necessarily bound by those promises — particularly if the acquiring entity operates under a different privacy policy going forward. The statement is a current operational commitment, not a permanent unconditional guarantee. Source: Federal Trade Commission Business Guidance.
The FTC's Role — and Its Limits
The Federal Trade Commission has authority to challenge data transfers in bankruptcy when they violate material promises made to consumers. The FTC has used this authority in several notable cases — most significantly, it required data deletion rather than transfer in the RadioShack bankruptcy, and it imposed conditions on the transfer of user data in other consumer-facing bankruptcies.
However, the FTC's authority has meaningful limitations:
- The FTC must actively intervene in the bankruptcy proceeding to challenge a data transfer — this requires agency resources and prioritization
- The FTC cannot compel a company to delete data or guarantee certain outcomes — it negotiates and litigates within the bankruptcy process
- FTC intervention is more likely for high-profile cases involving large user bases or sensitive data categories — smaller bankruptcies may receive less scrutiny
- The FTC's authority primarily covers deceptive trade practices — if a company's privacy policy accurately disclosed that data could be transferred in bankruptcy, there's less basis for FTC challenge
What Actually Happens: Three Outcomes
Outcome 1: Data Transferred to an Acquirer (Most Common)
The most common outcome in a business bankruptcy is that the company's assets — including user data — are sold to an acquirer who continues operating the service or absorbs the user base into their own. The acquirer may honor the original privacy policy, may update it with new terms, or may have significantly different data practices. Users are typically notified of the change of control and given an opportunity to delete their accounts — but the notification may be easy to miss, and the window to act may be brief.
Outcome 2: Data Sold to a Data Broker or Third Party
In liquidation scenarios where no single acquirer purchases the whole business, user data may be sold as a standalone asset to whoever values it most — which could be a data broker, a competitor, or a company whose business the original users were never aware of. The FTC has challenged some of these transfers, but not all such sales are blocked.
Outcome 3: Data Deleted
In cases where the data is deemed too sensitive to transfer, where the FTC successfully intervenes, or where a privacy-protective acquisition condition is imposed, user data may be required to be deleted rather than transferred. This is the outcome that best protects users but is the least common of the three, as it eliminates the asset value that would benefit creditors.
Real Cases: What History Shows
Data That Is Better Protected
Not all personal data has equal legal protection in a bankruptcy scenario. Some categories carry stronger statutory protections:
- Health data under HIPAA: If a company is a covered entity or business associate under HIPAA, health information remains subject to HIPAA requirements even in bankruptcy. An acquirer must comply with HIPAA or the data must be deleted. However, many health apps are not HIPAA-covered entities.
- Financial data under GLBA: Financial institutions covered by the Gramm-Leach-Bliley Act have obligations to protect customer financial data that survive corporate transactions, including bankruptcy.
- Children's data under COPPA: Data collected from children under 13 under the Children's Online Privacy Protection Act has heightened protections that apply in business transfers.
- Data under state privacy laws: States like California (CCPA/CPRA) and others have enacted consumer privacy laws that impose obligations on acquirers of personal data, including in bankruptcy. The scope and enforceability in practice varies.
Many people assume that health and fitness apps — calorie trackers, period tracking apps, sleep monitors, mental health apps — are protected by HIPAA. Most are not. HIPAA applies to healthcare providers, health insurers, and their business associates — not to consumer wellness apps. Your data in a health app may have no special legal protection in a bankruptcy beyond what the general privacy law framework provides. Source: HHS HIPAA FAQ.
What You Can Do Before a Company Fails
The most effective data protection happens before a company enters financial distress — not after the bankruptcy filing, when your leverage is essentially zero.
- Minimize what you share with services you're uncertain about. A company that has only your email address and username has far less leverage over your privacy than one that has your full name, address, payment history, health data, and location history.
- Use unique email addresses for services. An email alias (through services like Apple's Hide My Email, SimpleLogin, or AnonAddy) means a data transfer exposes an address that you can disable — not your primary inbox.
- Download and then delete your data periodically. Most services offer a data export function. Download your data annually and then request deletion of the account. A company that has already deleted your data at your request cannot transfer it in bankruptcy.
- Don't store payment information on services you don't use regularly. Remove saved payment methods from accounts you're not actively using — a breach or data sale can't expose payment data that isn't stored.
- Watch for signs of financial distress. Mass layoffs, executive departures, missed product updates, and unresponsive customer support are warning signs that a company may be approaching financial difficulty. These are reasonable prompts to delete your account proactively.
What to Do If a Company You Used Goes Bankrupt
If a service you used announces bankruptcy, the window for meaningful action is narrow:
- Download any data you want to keep immediately. Once the company shuts down servers or transfers the service, access may be cut off with no warning.
- Submit a deletion request as quickly as possible. Under CCPA (if you're a California resident) and some other state laws, you have a right to request deletion of your personal data. Submit the request before the company stops responding to such requests.
- Monitor the bankruptcy docket for data transfer notices. Bankruptcy proceedings are public records. Large consumer-facing bankruptcies often generate news coverage that will surface any proposed data sales.
- Update passwords on any services where you used the same credentials. If the bankrupting company's data is sold or leaked, credential reuse is a significant risk.
- Cancel any automatic payments or subscriptions linked to the account. Access may disappear without warning; make sure you're not being charged for a service you can no longer access.
User data is a business asset, and in bankruptcy, assets are sold to satisfy creditors. The privacy promises a company made you when you signed up are operational commitments — not unconditional permanent guarantees. The FTC provides some protection but cannot intervene in every case. The most effective protection is limiting what you share, using data minimization practices before problems arise, and acting quickly when a company shows signs of distress. The data you never gave them in the first place is the only data they definitely cannot sell. Source: Federal Trade Commission Privacy and Security.