Data at Risk: What Happens to Your Personal Data in a Corporate Insolvency?

[By shivangi nawalkha]

The author is a student of National Law University, Jodhpur

Introduction

When Jet Airways entered its Corporate Insolvency Resolution Process (‘CIRP’) in mid-2019, the Resolution Professionals (‘RP’) came across an unexpected “intangible asset” – the airline’s entire customer database. Jet’s loyalty programme called as Jet Privilege held records of approximately 8.5 million of its members encompassing names, contact details, travel histories and payment information. Not surprisingly, prospective bidders evaluated this data trove almost as highly as the aircraft and route licences, viewing it as a revenue-generating asset that could be monetised post-acquisition.

Although Jet privilege ultimately remained with Etihad and was excluded from the sale, this episode starkly illustrated a dangerous conflict at the intersection of insolvency and privacy which is that the airlines routinely hold gargantuan volumes of sensitive personal and financial data, yet neither the Insolvency and Bankruptcy Code, 2016  (‘IBC’) nor its regulations prescribe any data-privacy safeguards.

Since May 2025, this tension has only intensified with the Insolvency and Bankruptcy Board of India (‘IBBI’) revamping its e-CIRP portal and expanding the online auction framework which requires the Resolution Professional’s (‘RP’) to upload and share the assets through web-based data rooms. Without clear statutory guardrails, personal data could be treated like any other asset risking mass privacy breaches, loss of consent and non-compliance with the newly enacted Digital Personal Data Protection Act, 2023 (‘DPDP’).

Jet Airways’ CIRP stands as a cautionary tale to warn us that in the drive to maximise value, we cannot afford to overlook the protection of individual privacy rights.

This Article critically examines the unaddressed intersection of data privacy and insolvency under India’s IBC, beginning with an analysis of why personal data demands the same rigour as tangible financial assets. It then maps the existing legal vacuum examining the IBC’s silence with the DPDP’s stringent requirements and explores our key legal tensions that RPs and CoCs must navigate. Lastly, it reviews how the EU’s GDPR and USA’s consumer-privacy ombudsman model address these challenges and concludes with five policy overhauls to embed global best practices into India’s digital CIRP and online auction processes.

Importance of Privacy in Corporate Insolvencies

Insolvency of an entity invariably entails transferring a company’s entire records – its financials, contracts and the operational data into the hands of unfamiliar stakeholders. In today’s digital economy, these “books” also contain vast troves of personal information. These could be passenger profiles and payment credentials in airlines, patient records in healthcare, customer usage data in telecom and employee details technically across every sector.

A sudden CIRP can expose this personal data trove into the data rooms of bidders, creditors and even the competitors – none of whom the original data principals originally consented to engage with.

This exposure carries serious risks because the personal data exposed during an insolvency process may be leaked for unsolicited marketing, financial fraud or re-identification attacks. Concurrently, sensitive health data and financial details such as medical histories and credit card information respectively could be exploited for identity theft, insurance fraud or targeted scams. In the wrong hands, this data could be sold on the dark web or used to profile individuals without their knowledge or consent.

Crucially, unlike physical assets such as machinery or aircraft, personal data cannot lawfully change hands without informed consent, purpose limitation, and clear notice. Had bidders acquired Jet Airways’ customer files without privacy safeguards, each of its 8.5 million members would have lost control over their information with a potential of being misused.

In short, insolvency dramatically escalates the privacy stakes – the larger the data pool, the greater the potential fallout from any misuse requiring the RPs treat data protection with the same rigour and care as they do financial assets.

Yet, despite these heightened risks, India’s insolvency framework under the IBC remains silent on how such personal data should be handled leaving the RP’s without statutory guidance and exposing stakeholders to significant compliance and liability gaps.

The Legal Landscape in India: Insolvency Law Meets (or not) Data Privacy

India’s insolvency framework currently operates in a legal blind spot when it comes to personal data. The IBC and its accompanying regulations are entirely silent on how sensitive personal information should be handled during a CIRP or liquidation. There are no provisions that limit what personal data, a RP is allowed to share with the bidders nor any guidance on how long such data may be retained.

Section 30(2)(e) of the IBC simply mandates that a resolution plan must not contravene any existing law and should maximise the value of “all assets” of the debtor – it does not contain any provision for the protection of personal data. This is problematic because unlike physical assets, personal data implicates individual privacy rights and are subject to completely different legal obligations i.e. DPDP. However, the section being non-exhaustive leaves enough space to carve out a provision in the IBC for the protection of the personal data. In similar spirit, regulation 36 of the CIRP Regulations has no provisions for protection of “intangible assets” like personal data.

Meanwhile, the DPDP marks India’s first comprehensive attempt to regulate the collection and use of personal data. It was enacted to give effect to fundamental rights under Article 21 and is modelled on principles akin to the GDPR. It contains the provisions that would bind any entity processing personal data called a “data fiduciary.” Since a RP assumes possession and control of the corporate debtor’s personal data during a CIRP or liquidation, it may be deemed as a “data fiduciary” under DPDP.

Section 6 of the same mandates consent as the default basis for processing any kind of personal data unless one of the specific “legitimate uses” under Section 7 applies. Two such exceptions could arguably apply in an insolvency for the use of personal data, first; section 7(c) which allows for processing of personal data without consent for “performance of any function under the law.” This could be a possible fit for statutory CIRP duties of the RP or the Committee of Creditors (‘CoC’) and can allow the RP to process the personal data without consent when it is strictly necessary to asses and quantify creditors’ and employees’ financial claims during a CIRP or liquidation.

Additionally, these are the other obligations a data fiduciary under the DPDP must follow :-

  1. Section 7(a) which delineates that personal data may only be processed for a specific and lawful purpose and must be used limited to what is necessary.
  2. Section 8(7) makes it mandatory for the data to be erased as soon as its purpose is fulfilled and must be stored securely with the appropriate safeguards.
  3. Section 27 which say that the breaches must be reported to the Data Protection Board and the affected individuals

However, none of these provisions are insolvency specific and the DPDP does not contain any harmonising clause to reconcile its provisions with the IBC leaving a legal vacuum.

The vacuum gives rise to at-least three other legal questions namely:-

  1. Can personal data collected pre-insolvency be used for resolution purposes?
  2. What are the limits of retention of the personal data and its disposal requirements after the CIRP ends?
  3. Does the IBC moratorium under section 14 protect against DPDP penalties?

Lawful basis for using Pre-Insolvency Data for resolution under IBC

In a CIRP, the RP must share financial and operational data including customer datasets with potential resolution applicants. However, most such data would have been collected pre-insolvency for the limited purpose of providing goods or services (for example flight bookings in the case of Jet Airways. Under section 5 of DPDP, repurposing this data (to market the corporate debtor to the resolution applicants) would require fresh consent unless the legitimate used as mentioned above under section 7 applies. Moreover, courts and tribunals may still insist on granular justifications for the use of personal data, de-identification or anonymisation before data-sharing and notice to affected data principals, especially where use of sensitive data (for example Aadhar-linked KYC, health records) is involved.

A pragmatic fix would be to amend the IBC or add a schedule to recognise RP processing of personal data for CIRP as legitimate use under DPDP subject to necessity, proportionality and a limited safe harbour for good faith RP’s.

Retention and Disposal of Personal Data after the resolution under IBC ends

Section 8(7) of the DPDP mandates that personal data be erased once the purpose is no longer served. In insolvency, if the use of personal data is allowed, it purpose will be deemed to be fulfilled either when the resolution plan is approved and implemented or the company has proceeded for liquidation.

Yet current CIRP regulations have no provisions for data retention limits or disposal protocols. This means resolution applicants and RPs may retain or even duplicate large volumes of sensitive personal information long after the process ends.  A practical fix is to require a short and specified retention schedule and mandatory deletion protocols for any personal data accessed during CIRP.

IBC Moratorium v. DPDP Penalties

Section 14 of the IBC imposes a moratorium on all legal proceedings against the corporate debtor once CIRP begins. However, DPDP’s penalties under Sections 33-34 are public law sanctions not civil claims and so would fall outside the moratorium shield.

This is reinforced by a recent Supreme Court authority of Saranga Anilkumar Aggarwal v. Bhavesh Dhirajlal Sheth & Ors which has held that the moratoria under the IBC do not enjoin execution of consumer protection penalties, thereby distinguishing public law enforcement from debt recovery.

NCLAT has reached a similar, if more nuanced result in the tax context in the case of Commissioner of State Tax Department v. Ramchandra Dallaram Chaudhary, which affirms that fiscal authorities may issue assessment orders and have claims admitted in the insolvency process even though their direct enforcement is restrained by the moratorium.

This would mean that:

  1. RPs, CoCs or the resolution applicants could be held liable if they cause or allow a breach.
  2. Regulatory fines may be imposed independently of creditor processes.
  3. An RP who discloses sensitive data without a lawful basis may be personally exposed to fines or even prosecution.

To reconcile this mis-match, it is recommended that the Parliament should provide with a narrowly drawn safe-harbour provision for the RP’s so that they can work efficiently during a CIRP albeit in good faith and with procedural safeguards in place.

All of these questions require urgent policy resolution by the legislature, especially given the increased use of digital portals like the IBBI’s e-CIRP system and online auction platforms (which now often host raw data, including employee, vendor, and customer files).

The Legal Landscape in Eu and Usa: : Insolvency Law Meets Data Privacy

As India’s insolvency framework grapples with data’s growing value, both the European Union (‘EU’) and United States of America (‘USA’) have developed mechanisms to ensure personal information is treated with care even amidst asset-maximization drives. It is detailed ahead ow the General Data Protection Regulation (‘GDPR’) and the U.S. Bankruptcy Code respectively balance privacy safeguards with the practicalities of restructuring and sales.

EU and GDPR

In the EU, data privacy in insolvency is handled by the GDPR. It imposes strict obligations on any controller or processor of personal data including the appointed insolvency office-holders. The insolvency office holders often act controllers for debtor, creditor, employee and customer data and must uphold the core principles i.e. lawfulness, fairness and transparency of the GDPR.

The UK Information Commissioner has advised that when a failing entity’s customer list is transferred (e.g. sold in liquidation), the practitioner must carry out full GDPR-style due diligence – identifying the data’s original purposes, lawful basis for sharing, and informing data subjects, just as would happen in a merger or acquisition.

The violations to GDPR can draw heavy fines and strict enforcement action. The UK Information Commissioner’s Office and European Data Protection Authorities have recently warned that any sale of sensitive customer data such as genetic or health data in a bankruptcy must comply fully with the rigours of GDPR

So, the EU has no special insolvency-privacy statute, instead personal data in any insolvency are governed by the standard GDPR framework, with professional guidance and data-protection authority oversight ensuring that IPs handle data lawfully.

US and Bankruptcy Code

In the US, privacy in bankruptcy is handled by specific bankruptcy law provisions rather than a single privacy code. Under the 2005 BAPCPA amendments, Congress created the position of a  “consumer privacy ombudsman” which would forbid a corporate debtor from selling its personal data in conflict with its privacy policy unless this  independent ombudsman approves the sale.

The Federal Trade Commission (‘FTC’), a regulatory body in the US has intervened in the many bankruptcies  such as that of Toysmart where the FTC sued to block the sale of a bankrupt website’s customer database and the parties agreed to destroy the data rather than sell it. Congress then responded in the Bankruptcy Abuse Prevention and Consumer Protection Act 2005 by creating the consumer-privacy ombudsman to advise courts when personally identifiable information is proposed to be sold. The FTC has since intervened in other retail bankruptcies including RadioShack and Borders to limit transfers that would violate pre-bankruptcy privacy promises. These actions illustrate the risks of treating personal data as a vanilla estate asset.

Overall, the US model uses targeted bankruptcy-code rules and case by case regulator actions to protect consumer data in insolvency, rather than relying on a sweeping general privacy law.

These international approaches underscore the need for India’s insolvency regime to embed similarly robust privacy safeguards which have been delineated in the next section.

Policy Recommendations

To ensure that digital CIRP and online auction processes under the IBC respect fundamental privacy rights, the following policy changes could be implemented.

  1. Treating the RP as a “data fiduciary” – the RP if due to an ongoing CIRP or liquidation comes into possession of the corporate debtor’s personal data, he will be for the purposes of DPDP be treated as a data fiduciary under Section 2(i) of the same. Naturally then he must comply with DPDP’s core duties such as purpose limitation under Section 7, data limitation under Section 8 and ensure that the data processing is supported by consent of the data holders or a certain DPDP legitimate use under Section 6 and Section 7.
  2. Mandatory Data Mapping and Impact Assessment – the RP must at the outset of CIRP conduct a comprehensive inventory of all personal data held by the corporate debtor including customer records, employee files and creditor KYC documents. This will make it easy for the RP and the CoC to map the data flow from initial collection to sharing it with the resolution applicants.

Thereafter, the RP should commission a full Data Protection Impact Assessment identifying high risk processing activities and prescribing mitigation measures. This step is modelled on the GDPR guidance for insolvency practitioners and is essential to satisfy the accountability principle under Section 5 and Section 8 of the DPDP Act.

  1. Enforceable Non-Disclosure Agreements and Access Controls – Prior to granting any party access to debtor data, the RP must require execution of a robust non-disclosure agreement that (a) limits use for only the purpose of CIRP (b) prohibits onward transfers or marketing (c) mandates secure deletion or return of data upon request and (d) makes it compulsory for all data access must occur within encrypted, watermark‑protected virtual data rooms with time‑limited credentials. These protocols have been inspired from GDPR practice of preliminary pseudonymisation and tiered data access.
  2. Contractual Privacy Warranties and Indemnities – Every resolution plan or a request for a resolution plan must include express warranties from bidders that they will (a) process personal data only for authorised CIRP objectives (b) comply fully with DPDP’s security and data-subject rights obligations and (c) indemnify the corporate estate against any privacy breach. This approach integrates GDPR’s requirement for data‑processing agreements.
  3. Encrypted vaulting and Post-CIRP Disposal – throughout the CIRP, all personal data must be stored in an encrypted vault with strict access log in. As a condition of the resolution order, the RP must require certified erasure or anonymisation of all non‑essential data upon completion of the resolution or liquidation, in accordance with Section 8(7) of the DPDP. To ensure that these obligations are fulfilled, the RP should document a formal transfer impact assessment consistent with GDPR Article 28 and consider a neutral third-party escrow arrangement for data held pending final judicial approval.
  4. Independent Audits and Ombudsman Oversight – The RP should appoint an independent privacy auditor to verify compliance with NDA’s and security protocols. Additionally, he should also appoint a “Privacy Ombudsman” drawing on the U.S. Consumer Privacy Ombudsman model to handle complaints, liaise with the Data Protection Board and ensure ongoing compliance with the DPDP and global standards. This could either be created as an empanelled professional under the IBBI similar to registered valuers or function as a specialised officer within the Data Protection Board with jurisdiction over insolvency proceedings. Either arrangement would give the Ombudsman statutory recognition, a defined mandate to review data handling during CIRP or liquidation and the power to liaise with the RP.

By adopting these measures grounded in Indian law and informed by GDPR and U.S. bankruptcy‑privacy regimes, RP’s and CoC’s can balance asset maximisation with robust safeguards for personal data.

Conclusion

The intersection of India’s digital insolvency regime and its nascent privacy framework presents a pressing policy imperative with the IBBI’s renewed insistence on the e-CIRP portal and online auctions exposing corporate databases to external bidders.

At the same time, DPDP imposes rigorous obligations such as purpose limitation (Section 5), secure retention and erasure (Section 8(7)) and heavy penalties (Section 33-34) but offers no guidance on their during CIRP. This regulatory mismatch leaves RP’s and CoC’s navigating uncharted waters where the drive to maximise asset value risks trampling fundamental privacy rights.

Drawing on EU where insolvency practitioners undertake full GDPR style Data Protection Impact Assessments and in the USA, where a Consumer Privacy Ombudsman under the Bankruptcy Code is appointed, the article suggests five important policy changes to fill the vacuum till legislative reforms are brought. These are (a) mandatory data mapping and impact assessment (b) enforceable NDAs and tiered access (c) contractual warranties and indemnities (d) encrypted vaulting with post‑CIRP disposal and (e) independent audits coupled with ombudsman oversight.

The Ministry of Corporate Affairs and the IBBI are urged to  amend the IBC regulations to incorporate clear data-privacy protocols and issue joint guidance on DPDP compliance in corporate insolvencies.

With these changes in place, India can ensure that its insolvency ecosystem does not sacrifice individual rights on the altar of asset realisation and that the lessons of Jet Airways and global best practices translate into concrete safeguards for all stakeholders.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top