•  
  •  
 

Abstract

The increasing reliance of modern businesses on personal data has created novel legal challenges when data-intensive companies enter insolvency. Under Indian law, the Insolvency and Bankruptcy Code, 2016 seeks to maximise the value of a corporate debtor’s assets for the benefit of creditors, while the Digital Personal Data Protection Act, 2023 as operationalised through the DPDP Rules, 2025, protects personal data through a rigorous consent-based framework grounded in the constitutional right to privacy recognised in Justice K.S. Puttaswamy (Retd.) v Union of India (2017). This paper examines whether personal data can be treated as an insolvency asset, and whether it can be sold or transferred during insolvency proceedings without violating data protection law. Using a doctrinal and comparative methodology, the paper analyses the scope of ‘property’ and ‘assets’ under the IBC, the consent and purpose-limitation framework of the DPDP Act, and relevant judicial interpretations from the Supreme Court, NCLT, and NCLAT, alongside practices in the European Union and the United States. The analysis reveals that personal data may fall within the broad category of intangible assets under the IBC, but that its transfer during insolvency constitutes fresh processing and ordinarily requires renewed consent under the DPDP Act. The paper further finds that the ‘commercial wisdom’ of the Committee of Creditors and the overriding clause under Section 238 of the IBC cannot lawfully nullify statutory privacy obligations, which operate in a distinct constitutional domain. The paper concludes with six novel suggestions, including a Data-Insolvency Compliance Protocol, mandatory appointment of a Data Protection Ombudsman, purpose-bound data channels, retrospective notice obligations, and legislative amendments to bridge the regulatory gap.

Digital Object Identifier (DOI)

10.55496/HNBX4894

Share

COinS