Insolvency
Insolvency proceedings

Customer data in an insolvency asset sale: privacy and contract transfer

Customer data in an insolvency sale: review inventory, purpose, GDPR basis, notice, objections and secure handover.

BRANDAUER Rechtsanwälte
Your insolvency law team

BRANDAUER Rechtsanwälte

Insolvency law, Salzburg and throughout Austria

We review the procedural status, contracts, payment records and security, then explain which legal question needs to be addressed next.

3 August 2026, Mag. Bernhard Brandauer, Rechtsanwalt

When a business unit is sold from an insolvency estate, customer data does not pass like a machine as a freely transferable asset. Each data set requires review of purpose, affected groups, data types, existing legal basis, intended buyer use and safeguards.

Approval of a sale under section 117 IO does not itself answer the data protection question. An economically sensible asset deal still needs a legal basis under the GDPR for disclosure and further processing, must respect purpose limitation and data minimisation and must satisfy information duties.

The general acquisition path is explained in the article on buying a business unit from the estate. This article focuses on data sets, contract connection, transfer basis and secure handover.

Before data release

Which question belongs to which data set?

Active contracts, prospects, marketing lists and archives should not be transferred as one undifferentiated pool.

Review areas for customer data in an insolvency acquisition
Data set Review Possible measure
Active customers Contract status, required data, buyer role and basis for performance or transfer. Assign data and contract separately and exclude unnecessary fields.
Open orders Performance stage, claims, complaints, contacts and handover information. Provide only data necessary for the specific administration purpose.
Prospects Original collection purpose, consent or legitimate interest and expected new use. Review compatibility and notice before new contact.
Marketing lists Consent, objections, suppression lists, advertising purpose and channel. Carry objections across and do not activate unclear records.
Archives and sensitive data Retention, legal claims, special categories, deletion periods and access. Keep archives separate, limit access and review additional conditions.

Review is record and purpose specific. Technical export capability proves neither necessity nor lawfulness.

Choose the handover path

Is the customer data set ready for transfer?

The check separates transaction role, inventory, purpose, legal basis and notice.

Discuss the specific matter with the firm.

01 Question 1

From which role is the data transfer being prepared?

Your answers

Review the documents

01

Complete the inventory at field and purpose level

Record system, table, fields, group of individuals, volume, original purpose, retention basis, access roles and intended use. Only then decide what belongs in the data room or handover.

02

Replace a full export with the necessary data set

Article 5 GDPR requires data minimisation. Define a separate export for each legitimate buyer purpose. Test accounts, duplicates, internal notes, stale contacts and unnecessary free text should not pass without review.

03

Review marketing separately

A transaction does not create blanket advertising permission. Review original purpose, consent, legitimate interests, communications law and objections. Under Article 21 GDPR, an objection ends processing for direct marketing.

04

Define buyer purposes before disclosure

Without a defined purpose, necessity and legal basis cannot be assessed. Separate contract performance, claims administration, customer notice, service and marketing. Give each purpose its own data scope and owner.

05

Document the GDPR basis beside the purchase agreement

The asset purchase agreement governs the transaction between the parties but does not replace Article 6 GDPR. Justify disclosure and later processing separately and apply Article 6(4) where the new purpose relies neither on consent nor a specific legal rule.

06

Prepare notice under Article 13 or 14 GDPR

Determine whether data came directly from the individual or from the acquired pool. Article 14 generally requires notice within a reasonable period and at the latest within one month, with earlier points for first communication or disclosure. Review content and exceptions specifically.

07

Carry out a controlled and logged handover

Limit the export to approved fields, encrypt transport and storage, grant role-based access and log transfer, import and deletion of intermediate copies. Suppression and objection flags must remain operational.

Review data transfer and contract transfer separately

A customer contract, an open claim and the related data set are connected but not identical assets. Whether a contract transfers depends on transaction structure, contract and applicable rules. This does not automatically permit transfer of every historic customer record.

The article on an ongoing contract in insolvency explains reciprocal performance and the choice under section 21 IO. The data set requires a separate GDPR review.

Create three lists: contracts transferred or continued, legacy positions only to be wound down and persons without an active contract. Assign purpose, data scope and legal basis separately.

Evidence legal basis and compatible purpose for each use

Article 6 GDPR requires at least one legal basis for each processing operation. Depending on purpose, contract performance, legal obligation or legitimate interests may be relevant. None applies automatically to the entire acquired database.

If the buyer intends a different purpose, Article 6(4) GDPR requires a compatibility assessment absent consent or specific legislation. Connections between purposes, context, data nature, consequences and safeguards are among the factors.

Special categories under Article 9 GDPR need an additional exception. Health, biometric or other sensitive information should not remain hidden in a general customer export.

Apply data minimisation in the data room

Article 5 GDPR requires purpose limitation, minimisation, accuracy, storage limitation, integrity and confidentiality. These principles apply before completion. The due diligence data room should contain only what the specific review needs.

Where possible, potential buyers should first receive aggregated, pseudonymised or redacted material. Names, private contact details and free-form notes are often unnecessary in full for economic evaluation.

The acquisition from insolvency hub places the data room, acquisition perimeter and approval chain in context.

Inform individuals transparently and on time

Where the buyer obtains data from the acquired pool rather than directly from the individual, Article 14 GDPR generally applies. Information includes controller, purposes, basis, categories, recipients, retention, rights and data source.

Notice is generally given within a reasonable period and at the latest within one month. Earlier timing can apply before first communication or disclosure. Article 14(5) exceptions require a specific assessment.

Data collected directly by the new controller follows Article 13 GDPR. New purposes need notice before the corresponding further processing unless an exception applies.

Transfer objections, deletion markers and security

A customer record includes more than contact details. Objections, consent status, suppression flags, deletion dates and source information are essential for lawful use and must not be lost in export.

Article 21 GDPR is clear for direct marketing. After an objection, data cannot be processed for that purpose. The buyer needs effective suppression lists and must highlight the right to object no later than the first communication.

Article 32 GDPR requires risk-appropriate security. Encryption, role-based access, logging, secure key delivery, recovery and deletion of intermediate copies belong in the handover plan.

Do not treat insolvency approval as GDPR clearance

Section 117 IO can require approval by the creditors committee and insolvency court for the sale of the business, all movable fixed and current assets or an operationally necessary part. The intended sale must be publicly announced.

That approval concerns the insolvency transaction. It does not identify data controllers or replace legal basis, notice and security. Both workstreams must meet before data access.

The insolvency estate describes the asset framework. Personal data remains regulated information when the underlying business is realised.

No blanket CRM transfer: Do not export the entire database first and review it later. Purpose, legal basis, required fields, notice, objections and security should determine the export.
FAQ

Common questions about customer data in an insolvency sale

Can the buyer acquire the whole customer database? +

Not as a blanket rule. Each category and use requires review of purpose, necessity, legal basis, transparency and security. Data minimisation may require a much smaller export.

Is insolvency court approval a GDPR legal basis? +

No. Approval of the transaction does not replace the lawfulness assessment under Article 6 GDPR or other data protection duties.

Does customer data automatically follow the customer contract? +

No. Contract transfer and data processing are separate questions. Even with a continuing relationship, the data scope must be necessary and processing lawful.

When must customers be informed about the buyer? +

For indirectly obtained data, Article 14 generally provides a reasonable period of at most one month, with possible earlier timing for first communication or disclosure. Exceptions require specific review.

May the buyer use the data for marketing? +

Only after separate review of purpose, legal basis and communications law. Existing objections must be respected, and an Article 21 objection bars direct marketing with the data.

Topics
Customer dataGDPRAsset dealInsolvency estateContract transfer

Would you like us to review a claim, owned goods or a decision in a business crisis?

Tell us your role, the business concerned and the procedural status. We respond within one business day.

Direct line to the firm.

Address

BRANDAUER Rechtsanwälte GmbH Giselakai 51 5020 Salzburg