top of page

Data as an Insolvency Asset: The IBC-DPDPA Disconnect

  • Prachi Pravasini, Sneh Kumkum Kaushik
  • 1 day ago
  • 6 min read

[Prachi and Sneh are students at National Law University Odisha.]


The Supreme Court in State Bank of India v. The Consortium of Mr Murari Lal Jalan and Mr Florian Fritsch (JetAirways) directed liquidation of JetAirways (India) Limited, which offers a preview at a growing legal concern. The passenger data (digital data) under the JetPrivilege loyalty program was treated as a commercially significant asset, heavily contested during resolution due to its post-acquisition profitability. This was not an isolated episode. From area demographics to digital health records, every digital interaction now generates economically significant data. With low capital requirements and expanding internet infrastructure, businesses rapidly scale into global digital marketplaces, making customer data, behavioural insights, and digital records central commercial assets.


India sits at the forefront of this transformation, boasting 881 million internet users and an e-commerce sector projected to reach USD 325 billion by 2030. However, there is no legislation that explicitly deals with this new asset class. The Insolvency and Bankruptcy Code 2016 (IBC) provides no guidance on the classification, valuation or transfer of data in the corporate insolvency resolution process (CIRP). The Digital Personal Data Protection Act 2023 (DPDPA) while establishing a framework for lawful processing of personal data, contains no insolvency-specific provisions. The result is a regulatory void of legal uncertainty, arbitrary valuations and a struggle between asset recovery and data principal's privacy rights.


Fragmented Frameworks: Navigating Data Assets in Indian Insolvency Proceedings


Data as an intangible asset under IBC


Section 18(f)(iv) of the IBC lists “intangible assets” as part of the liquidation estate. While "digital data" is not explicitly mentioned, it reasonably falls within this category where the corporate debtor owns or lawfully has control over the data, which can then be used by the creditor to satisfy the claims of the creditors under Section 36(3)(d).


Judicial precedents support this reading. Ebix Singapore v. Educomp Solutions (CoC) treated digital records as integral to assessing the enterprises component to determine enterprise viability. In Edelweiss Asset Reconstruction Company v. Net 4 India Limited, the NCLT emphasized preserving customer databases for continuity. The Supreme Court in Binani Industries v. Bank of Baroda and Committee of Creditors of Essar Steel v. Satish Kumar Gupta further established that the Committee of Creditors’ commercial judgment must remain balanced and oriented towards maximising value for all stakeholders.


Despite this evolving jurisprudence, no provision specifically addresses data assets valuation methodology, privacy-compliance obligations during CIRP, or the legal consequences of non-compliance- leaving a critical legislative gap.


The DPDPA's insolvency blindspot


The DPDPA establishes consent-based data processing, imposes accountability on Data fiduciaries and Data processors, and grants Data principals rights of correction, erasure, and purpose-limited use. However, it contains no provision governing the treatment of  personal data when a corporate entity undergoes CIRP where such data may be the very asset undergoing valuation and transfer.


The consent conundrum


A key ambiguity lies in Section 17(1)(e), which removes the requirement for consent for data processing for "the purpose of implementing a scheme" as recommended by the court. This might be extended to CIRP, which is a process under the statutory supervision of the courts, with the resolution plan being the “scheme”. In this interpretation, data valuation may proceed without seeking fresh consent.


However, a more restrictive but equally justifiable approach would force RPs to ask for new consent to process personal data for valuation purposes because Section 6 of the DPDPA focuses on the purpose for which consent is requested. This would also create conflict with IBC's 330-day outer timeframe as provided in Section 12(3). Getting consent from possibly millions of data principals again and then parsing out those who have opted-out and re-compiling the eligible sets is operationally incompatible with this timeline.


Compounding this, the data principals may exercise post-resolution rights of data portability, consent withdrawal, and erasure under Section 12 of the DPDPA. Applied at scale, these rights could materially erode the commercial value of a data asset. Meanwhile, the IBC’s moratorium under Section 14 while temporarily barring legal proceedings during CIRP, merely defers this problem. Potentially exposing the resolution applicants to regulatory and contingent liabilities post-resolution.


Jurisdictional overlap and institutional confusion


A parallel institutional conflict arises from the concurrent jurisdiction of the NCLT under Section 60(5)(a) of the IBC and the Data Protection Board under Section 39 of the DPDPA. Neither statute specifies which authority governs data breaches occurring mid-CIRP.  This ambiguity heightens transactional risk for prospective bidders and suppresses asset valuations.


Taken together, these structural incompatibilities produce three compounding problems. First, the consent impasse delays valuation, raises the risk of privacy violations, and exposes acquires to mass-opt-outs and regulatory penalties. Second, unresolved jurisdictional overlap between the NCLT and the Data Protection Board generates regulatory uncertainty that discourages investor participation. Third, post-resolution objections from data-principals create contingent liabilities that depress the commercial value of data assets. Each of these undermines the IBC’s foundational objective of maximising value through the resolution process.


Valuation of Data under IBC and DPDPA


Currently, there is no standardised or formal methodology adopted for the purpose of data valuation. As already established, it is crucial to capture the true potential of data assets as they are proving to be a significant portion of the assets, as seen in the insolvency sale of 23andMe’s genetic database. 


Although there exist approaches to evaluate intangible assets like the market approach or the cost approach, there is no trace of the same in the Indian legislation due to an additional problem i.e. lack of classification.


Section 20 of the IBC essentially mandates the RP to manage the corporate debtor’s assets as a going concern with asset maximization as its priority. Without comprehensive laws on evaluation of intangible assets such as customer databases, the professional is unable to conduct fair and informed valuation of data. 


The DPDPA treats “personal data” as a single block of data. This broad ambit increases the possibility of including “inferred data” or “anonymised data” in the gamut of personal data. Such data is usually data observed from user purchase history or search patterns by Big Data organisations, removing the identifiable nature of data. Since the laws remain unclear, challenges arise during the insolvency proceedings. 


Firstly, data valuation without sieving out inferred databases from personal data leads to undervaluation or complete abandonment of “personal data” as an asset. Secondly, the risk of data breach heightens making the CD vulnerable to a hefty penalty of 250 crores under Section 33(1) of the DPDPA. Although there is no direct link between the IBC and DPDPA as of now, Section 29(2) of IBC does mandate a confidentiality undertaking. This does not address the concerns related to data privacy, misuse or compliance with the DPDPA. 


Necessary Reforms 


Firstly, a mechanism for data classification for the purpose of applying varying degrees of privacy protection based on the nature of personal data. A legal distinction between data assets which are “inferred data” and “personal data” will allow for asset maximisation during insolvency and carve out a fair valuation. The General Protection of Data Regulations profiles personal data into categories based on the level of risk involved. For instance, highly sensitive data is categorised differently from data which is anonymised. A similar law could be introduced to help asset maximisation during insolvency proceedings in India. Consequently, incorporation of a standardised method to value data and intangible assets based on the use cases and context will help classify data and facilitate a fair valuation of assets. This would minimize the problem of data maximisation and the risk of privacy violation.  


Lastly, alternatives such as pseudonymisation (masked data, re-identifiable through a coded key) or data aggregation can reduce dependency on individual consent when datasets of millions of users are involved. A clear and comprehensive guidelines on the requirements and obligations of the RP in data-intensive insolvency proceedings is necessary for balancing the data privacy concerns and asset maximisation


Conclusion


The JetAirways proceedings illustrated a legal vacuum which is yet to be addressed. The IBC was designed for tangible assets such as machinery and plants which form a significant portion of assets during insolvency proceedings. However, with the advent of technological era, post-industrialisation, datasets are the new currency. With the rising number of users and their right to privacy, DPDP Act was introduced to safeguard consent and data protection. However, it is far more complicated to deal with data assets without clarity on consent, jurisdiction and classification during an CIRP. For the dual purposes of asset maximisation and data minimisation, it is crucial for comprehensive laws to be introduced for harmonisation of the statutes. A data classification framework, a standardised valuation methodology and clarity on jurisdiction and timelines are some workable solutions which can represent the minimum reforms required to close the gap. 


Related Posts

See All

Comments


Sign up to receive updates on our latest posts.

Thank you for subscribing to IRCCL!

©2025 by The Indian Review of Corporate and Commercial Laws.

bottom of page