What Happens to Your Data When a Company Goes Bankrupt
Technology

What Happens to Your Data When a Company Goes Bankrupt

8seneca TeamEngineering
September 15, 20265 min read

Share

When companies go bankrupt, your personal data can be sold as an asset. Here is what actually happens to it.

data privacy bankruptcy personal data company collapse
Source: Magnific

Most people, when a company they use goes bankrupt, think about losing access to the service. Not many think about what happens to the data they left behind.

In 2025, 23andMe filed for bankruptcy. The company held the genetic data of more than 15 million people. As soon as the filing was announced, the question became unavoidable: who ends up with all of that DNA?

The answer is not reassuring. When a company goes bankrupt, personal data is often treated as a corporate asset. It can be sold, transferred, or auctioned to the highest bidder. Privacy policies promise protection. Bankruptcy courts do not always agree.

Your Data Is an Asset. That Is the Problem.

When a company goes bankrupt, a trustee takes control of everything the company owns. The goal is to pay back creditors. That means selling whatever has value.

For most modern companies, data is one of the most valuable things they hold. Customer names, email addresses, purchase histories, location data, health records. In a bankruptcy sale, all of it can go on the block.

RadioShack tried to sell 117 million customer records when it filed for bankruptcy in 2015. The FTC and 38 state attorneys general pushed back. RadioShack still walked away with $26 million from selling names, email addresses, and transaction data. The more sensitive information was destroyed, but only because regulators intervened in time.

Not every bankruptcy gets that level of scrutiny. Most do not. The legal mechanism that makes this possible is Section 363 of the US Bankruptcy Code. It allows courts to approve the sale of a debtor’s assets, including customer data, even when the original privacy policy promised otherwise. Bankruptcy courts can override those promises. Your data, in the eyes of the law, belongs to the company, not to you.

Deleting Your Account Does Not Save You

When companies start showing signs of trouble, a lot of users do the sensible thing. They log in, delete their account, and assume that is the end of it.

It is usually not.

Data does not disappear the moment you click delete. It lives in backups, archived databases, and servers that may not be cleaned up for months. When 23andMe users rushed to delete their accounts after the bankruptcy announcement, the data many of them thought they had removed was still sitting in the company’s systems, potentially in scope for any future asset sale.

Even deleted data can resurface during bankruptcy proceedings as a valuable asset. The company’s privacy policy may promise deletion within a certain timeframe, but if bankruptcy is filed before that process is complete, the trustee can freeze assets, including data scheduled for deletion, while the sale is worked out.

This is not a loophole that companies are exploiting. It is just how bankruptcy law works. The trustee’s job is to maximize value for creditors. Deleting data reduces that value. So deletion stops.

What the Law Does and Does Not Protect

The legal picture depends on where you live, what kind of data is involved, and whether regulators get involved.

In Europe, GDPR gives users stronger protections. Any company that acquires data through a bankruptcy sale must honor existing data rights. That includes the right to access, correct, and delete personal information. A new owner cannot simply start using your data in ways the original company never disclosed.

In the US, it is less clear. The FTC has stepped in to block data sales that violated original privacy promises. But that does not happen every time. The FTC’s ability to act depends on whether the original privacy policy made specific commitments about data sharing. If the policy was vague, there is less ground to stand on.

Anonymized data is not necessarily safe either. Precise location data can still reveal visits to medical facilities or religious institutions even without a name attached. Stripping names out does not eliminate the risk.

The honest answer is that protections exist but are inconsistent. Whether they apply to your specific situation depends on factors most people cannot predict in advance.

What You Can Do About It

You cannot fully control what happens to your data if a company collapses. But you can reduce your exposure.

The first step is to be selective about what you share. The less sensitive data a company holds on you, the less there is to worry about if things go wrong. For services that ask for more than they need, that is worth thinking about before signing up.

Read the privacy policy before you hand over sensitive information. Specifically, look for what it says about data transfers in the event of a sale or bankruptcy. Some policies explicitly state that data will not be sold. Others leave the door wide open. That difference matters.

If a company you use files for bankruptcy, act quickly. Submit a data deletion request immediately and document it. If your data is listed as an asset in the bankruptcy proceedings, you can submit a formal objection to the bankruptcy court. It does not guarantee anything, but it puts your objection on record.

Monitor what happens to the data after a sale. Check bankruptcy court filings for asset transfer details and look for any successor companies named in the deal. If a new owner contacts you with communications that feel inconsistent with what the original company promised, that is worth flagging to your country’s data protection authority.

Finally, treat data privacy bankruptcy as a real risk, not a hypothetical. 23andMe is not an isolated case. Every year, thousands of companies shut down. Some quietly, some loudly. The data they hold does not always go quietly with them.

Enjoyed this article?

Let’s talk about how a focused outsourcing partner can move your roadmap forward.

Book a call
8seneca Logo

Pure Play B2B IT outsourcing — European management, Vietnamese talent.

KONTAKT
ABONNIEREN SIE UNS

Durch das Abonnieren erhalten Sie Updates zu 8Senecas Produkten, Dienstleistungen und Veranstaltungen. Sie können sich jederzeit abmelden. Weitere Details finden Sie in unserer Datenschutzerklärung.

SINGAPOREHQ

8SENECA PTE. LTD.

Reg. No. 202225113N

10 Anson Road, #22-02, International Plaza, Singapore 079903

VIETNAMHo Chi Minh

CONG TY TNHH 8SENECA

Reg. No. 0317546084

Room 1428, 14th Floor, Saigon Centre Tower 1, 65 Le Loi Street, Sai Gon Ward, Ho Chi Minh City, Vietnam

[email protected]
VIETNAMHa Noi

19th Floor, Coninco Tower, 4 Ton That Tung Street, Kim Lien Ward, Hanoi, Vietnam

UNITED KINGDOMLondon

8SENECA LTD.

Reg. No. 14085322

20-22 Wenlock Road, London N1 7GU, England

SLOVAKIANitra

8SENECA s.r.o.

Reg. No. 55005446

Palánok 1, 949 01 Nitra, Slovakia

2026 8Seneca. Alle Rechte vorbehalten.

Folgen Sie uns auf TikTokAbonnieren Sie unseren SubstackFolgen Sie uns auf TwitterAbonnieren Sie unseren YouTube-KanalFolgen Sie uns auf LinkedInFolgen Sie uns auf Facebook