Bankruptcy and Customer Data: What Gets Sold

When a domain industry company enters bankruptcy, attention initially focuses on domains, cash, and contracts, but customer data often becomes one of the most sensitive and misunderstood assets in the case. Registrars, marketplaces, hosting providers, brokers, parking platforms, and affiliate networks all accumulate vast amounts of customer information over time. This data can include names, email addresses, billing histories, IP logs, transaction records, authentication details, and behavioral analytics. In bankruptcy, the question is not simply whether customer data has value, but what portions of it can legally be sold, to whom, and under what restrictions.

From the perspective of bankruptcy law, customer data is generally treated as an intangible asset of the estate, much like software or intellectual property. If the debtor collected and stored the data in the ordinary course of business, the starting assumption is that it belongs to the estate and may be monetized for the benefit of creditors. However, this assumption is immediately constrained by privacy laws, contractual commitments, and industry-specific obligations that limit how data can be transferred or used. In the domain name industry, these constraints are particularly complex because customer data is intertwined with ICANN policies, registrar accreditation requirements, and global privacy regulations.

The most straightforward category of data that may be sold is aggregated or anonymized information. Statistical data about customer behavior, geographic distribution, transaction volumes, and revenue patterns can often be transferred without violating privacy commitments, provided it is sufficiently de-identified. Buyers value this data for market analysis and strategic planning, and courts are generally comfortable approving its sale because individual customers cannot be re-identified. However, the line between anonymized and identifiable data is closely scrutinized, especially when datasets are rich enough that re-identification is theoretically possible.

Personally identifiable information is where bankruptcy sales become contentious. Names, email addresses, phone numbers, billing addresses, and payment histories are all highly sensitive and subject to privacy laws such as the GDPR, CCPA, and similar regimes worldwide. Whether this data can be sold depends heavily on the debtor’s published privacy policy and the representations made to customers at the time the data was collected. If a privacy policy promised that data would never be sold or transferred except in limited circumstances, courts may prohibit its sale or require explicit customer consent.

In many domain businesses, privacy policies include language allowing data transfer in the event of a merger, acquisition, or sale of assets. Bankruptcy often falls within this carveout, allowing customer data to be transferred to a buyer as part of a going-concern sale. Even then, courts may impose conditions. Buyers may be required to honor the existing privacy policy, limit use of the data to the original business purpose, or provide customers with notice and opt-out rights. These restrictions can reduce the economic value of the data and complicate transactions.

Registrar bankruptcies present additional layers of restriction. ICANN’s Registrar Accreditation Agreement imposes strict rules on the handling of registrant data. Registrars are custodians, not owners, of much of the data they hold. Registrant information is collected to fulfill registration and DNS management functions, not for resale. In a registrar bankruptcy, bulk transfers of registrations to a gaining registrar include the necessary registrant data, but that transfer is governed by ICANN policy, not asset sale logic. The gaining registrar cannot use that data for unrelated marketing or resale, even if it acquired the registrar’s business assets.

Marketplaces and brokers occupy a more ambiguous position. They often collect extensive data about buyers and sellers, including negotiation histories, pricing behavior, and portfolio composition. Some of this data may be considered proprietary business information rather than personal data, particularly when tied to corporate customers. However, individual domain investors are still protected by privacy commitments. Courts may allow the sale of customer lists but restrict how buyers can contact or market to those customers, especially if the original relationship was based on trust and confidentiality.

Authentication data is almost never sold. Passwords, API keys, two-factor authentication secrets, and security tokens are considered highly sensitive and dangerous to transfer. Trustees are expected to secure or destroy this data rather than monetize it. Buyers acquiring a platform typically require that authentication systems be reset and credentials regenerated, both to comply with security best practices and to limit liability. Any attempt to sell usable authentication data would likely be blocked by courts and regulators.

Payment data is similarly restricted. Credit card numbers, bank account details, and payment tokens are subject to financial regulations and contractual obligations with payment processors. In bankruptcy, this data is usually excluded from asset sales entirely. Even historical payment records may be partially redacted to remove sensitive details. Buyers may receive transaction histories without underlying payment credentials, sufficient for accounting or fraud analysis but not for re-billing customers without consent.

International considerations loom large in customer data sales. Domain businesses often serve customers across dozens or hundreds of countries. Transferring data across borders may trigger additional legal requirements, including data localization laws or restrictions on export of personal data. In some cases, trustees may be forced to segment datasets by jurisdiction, selling or transferring some portions while excluding others. This fragmentation reduces value and increases administrative complexity, sometimes making data sales impractical.

Customer expectations and reputational risk also influence outcomes. Even when legally permissible, selling customer data can provoke backlash that diminishes the value of the remaining business or deters potential buyers. Courts are increasingly sensitive to this dynamic, especially in consumer-facing businesses. In some cases, judges have denied or conditioned data sales not because they were illegal, but because they conflicted with reasonable customer expectations and threatened broader harm.

There are also situations where customer data is effectively unsellable. If a business promised strict confidentiality, operated in a regulated niche, or collected data solely for limited operational purposes, trustees may determine that attempting to sell the data would invite litigation or regulatory penalties. In such cases, data may be transferred only as necessary to fulfill existing services or may be destroyed after a wind-down. Creditors often find this outcome frustrating, as valuable-seeming assets produce no recovery.

For customers, bankruptcy disclosures can be unsettling. Privacy policies that once felt theoretical suddenly matter deeply. Customers may receive notices informing them that their data may be transferred, along with options to opt out or close accounts. The practical ability to exercise these rights varies, especially when systems are degraded or timelines are short. Customers who do not respond in time may find their data transferred by default, within the bounds of the law.

In the domain name industry, bankruptcy and customer data intersect at the boundary between asset maximization and trust preservation. Data can be valuable, but it is not freely alienable in the way domains or hardware might be. Legal constraints, contractual promises, and ethical considerations all shape what gets sold and how. When companies fail, customer data does not simply become a commodity to be auctioned off. Instead, it becomes a test of how well the industry balances financial recovery against the obligations it assumed when that data was first collected.

When a domain industry company enters bankruptcy, attention initially focuses on domains, cash, and contracts, but customer data often becomes one of the most sensitive and misunderstood assets in the case. Registrars, marketplaces, hosting providers, brokers, parking platforms, and affiliate networks all accumulate vast amounts of customer information over time. This data can include names,…

Leave a Reply

Your email address will not be published. Required fields are marked *