When a company fails, the lawyers make a list of everything it owns. Office furniture, delivery vans, patents, the domain name, the brand. Somewhere on that list, usually near the top by value, sits the customer database. Names, emails, addresses, purchase history, and whatever else the company collected over the years. A bankruptcy court exists to turn assets into money for creditors, and data is an asset. That is the part most people never think about when they hand over an email address.

The pattern was set in 2000 by an online toy retailer called Toysmart. The company had promised in its privacy policy that it would never share customer information with third parties. When it went under, it tried to sell that information anyway. The Federal Trade Commission sued, arguing that selling the data broke the promise the company had made, and the case settled with tight limits on any transfer. The case became the reference point for every data sale in bankruptcy that followed. It also revealed how thin the protections were. Twenty five years later it is still the leading case.

Congress responded in 2005 by amending the bankruptcy code. When a company that made privacy promises tries to sell personally identifiable information, the court can appoint a consumer privacy ombudsman. That person is independent of the company and the buyer. The job is to review the proposed sale, weigh the losses and gains to customers, look at what the privacy policy actually said, and report back to the judge before the sale is approved. The ombudsman does not have veto power, but the recommendation carries weight and creates a public record. The report lands on the docket for anyone to read.

The 23andMe bankruptcy in March 2025 turned that quiet procedure into a national conversation. A genetics company holds something more permanent than a mailing list. You can change an email address, but you cannot change your genome, and the information partly describes relatives who never signed anything. The court appointed a consumer privacy ombudsman, several state attorneys general filed objections, and the chair of the FTC wrote publicly about the privacy stakes in the sale. It was the clearest demonstration yet that a privacy policy is a promise made by a company that may not survive. The case is still shaping how courts treat this.

The practical lesson is that a privacy policy is only as durable as the entity behind it. Most policies now include a line reserving the right to transfer data in a merger, acquisition, or sale of assets. That single sentence is doing enormous work. It means the company is telling you, in advance, that the promises in the rest of the document travel with the business to whoever buys it. Read that clause before you decide how much to hand over. It is usually near the end under a heading about business transfers.

There are steps worth taking while a company is still healthy. Delete accounts you no longer use rather than letting them sit dormant, because a dormant account is still a record in the database. Use a unique email alias for services you are unsure about so you can trace where a leak came from later. Give the minimum information a service actually needs to function, and skip optional profile fields entirely. For services that hold sensitive material such as health records, genetic results, or financial history, check whether the company offers a real deletion process rather than deactivation. Deletion requests take time, so do not wait for bad news. Do it while the site still works.

State law is doing more of this work than federal law. California, Colorado, Connecticut, Virginia, and a growing list of other states give residents a right to request deletion of personal information, with defined response windows. Those rights generally survive a bankruptcy, since the buyer inherits the obligations that attach to the data. Sensitive categories such as genetic and biometric information often carry extra consent requirements. If you live in a state with one of these laws, the deletion request is not a favor you are asking for. It is a legal request with a deadline attached. Send it in writing and keep a copy.

None of this makes bankruptcy the biggest privacy risk anyone faces, and breaches at healthy companies remain far more common. What the bankruptcy cases expose is a structural gap. Privacy is treated as a policy the company writes and can revise, rather than as a right that follows the person. Until that changes, the reasonable approach is to assume that anything you give a company can outlive the company itself. Decide what you share with that assumption in place, not after the filing hits the news. Assume the data can outlive the logo on the box.