Introduction

"Data" has emerged as one of the most valuable, yet the least capitalized asset. Customer databases, metadata, analytics, proprietary algorithms, transaction histories, loyalty-program records, and KYC-linked financial profiles — though not capitalized — still exceed land, plant, and machinery in commercial value. Realization of "Data" creates a tussle between the Insolvency and Bankruptcy Code, 2016 (hereinafter "IBC"), which mandates value maximization of the assets of Corporate Debtor, and the Digital Personal Data Protection Act, 2023 (hereinafter "DPDP Act"), which vests individuals ("Data Principals") with enforceable rights over their personal data irrespective of its commercial worth.

Through this blog, I will try to examine how current laws deal with this aspect and what could be the possible challenges in the process of realisation of this intangible asset — Data.

Data as "Property" Under the IBC

Though "Data" is not explicitly mentioned under the definition of "Property" under Section 3(27) of IBC, it is defined expansively to include money, goods, actionable claims, land, and every description of property situated in or outside India. A formulation that the courts have already invoked brings cryptocurrency within the insolvency estate on the reasoning that "property" signifies every possible interest a person can hold. The same logic extends to structured data holdings.

At the liquidation stage, Section 36(3)(d) of IBC expressly includes intangible assets such as intellectual property, securities, and contractual rights within the liquidation estate, and its open phrase "including but not limited to" extends this to "Data". This is reinforced by Section 25 of IBC, which requires the resolution professional (hereinafter "RP") to preserve and maximize the value of all assets, tangible or intangible, and by Section 18(f), which allows the RP to take control and custody of both tangible and intangible assets, unless excluded under statutory exemptions such as property held in trust. Section 29 of IBC and Regulation 36 of the CIRP Regulations further require the information memorandum to contain all "relevant information" — a category broad enough to include customer databases and employee records. In practice, RPs routinely compile data rooms containing identifiable personal data for disclosure to resolution applicants, often without anonymization, and well before any resolution plan is approved.

Thus, data is, in principle, properly capable of forming part of the insolvency or liquidation estate. The question which remains is what may lawfully be done with it, and how it should be valued.

The DPDP Act Collision

Insolvency proceedings tend to render the greatest possible value obtainable from the debtor's assets. Accounting of personal data — such as customer records, behavioural analytics, and usage patterns — has developed into an intangible asset with potentially enormous monetary value. Creditors and resolution professionals hope to financially benefit from these datasets in asset maximization strategies. However, the DPDP Act proposes a stringent system of consent-based processing, data minimization, and purpose limitation for the protection of personal data. This leads to a tension between the protection of the right to privacy and maximum realization of assets.

A second issue concerns consent withdrawal by a Data Principal during CIRP, resulting in varied realization of Data Assets. Specifically, Section 6(4) of the DPDP Act entitles a Data Principal to withdraw consent at any time, with a withdrawal mechanism as easy to use as the consent itself. Once withdrawn, the data must generally be erased once its specified purpose ceases to be served. Applied to an ongoing CIRP, this creates the possibility that a resolution applicant's principal asset depreciates or dissolves mid-process through the cumulative exercise of individual rights — a risk the IBC's asset-maximization architecture has no mechanism to anticipate or price.

When we consider the non obstante clause, Section 238 of the IBC provides that the Act's provisions override any inconsistent law, thereby establishing supremacy — reaffirmed by the Supreme Court in Innoventive Industries Ltd. v. ICICI Bank and Committee of Creditors of Essar Steel India Ltd. v. Satish Kumar Gupta. However, Section 38 of the DPDP Act states that its provisions are in addition to, and not in derogation of, other laws, yet the DPDP Act's provisions would prevail in the event of a conflict. Further complexity arises from Justice K.S. Puttaswamy (Retd.) v. Union of India, which recognised informational privacy as an incident of the fundamental right to life and personal liberty under Article 21. Because Article 21 sits above ordinary legislation, an unqualified "IBC overrides DPDP Act" argument may not survive constitutional scrutiny notwithstanding Section 238's text.

The DPDP Act permits a financial institution to process a defaulter's personal data without fresh consent solely to ascertain that person's financial information, assets, and liabilities; its explanatory note expressly borrows the definitions of "default" and "financial institution" from Sections 3(12) and 3(14) of the IBC. This confirms legislative awareness of the IBC–DPDP interface, but the exemption is confined to ascertaining financial position for recovery — it does not extend to the wholesale sale of a customer database to a third party as a standalone commercial asset, which remains governed by ordinary consent and purpose-limitation rules. This gap between the narrow statutory exemption and prevailing resolution practice is where the legal risk resides.

The Valuation Gap

Assuming the question of data as estate property is settled, another issue arises: a reliable mechanism for pricing it. The IBBI (Valuation) Rules, 2017 recognise only three asset classes — land and building, plant and machinery, and securities or financial assets — leaving intangibles such as data and intellectual property without a dedicated methodology or a recognised class of valuers. Where such assets surface in liquidation, they are frequently classified as "not readily realizable assets" under Regulation 37A of the IBBI (Liquidation Process) Regulations, 2016 — a category that, by definition, requires specialized valuation approaches which the current framework does not supply. This results in undervaluation, absent market infrastructure, and a shortage of qualified professionals.

A dataset's realizable value depends heavily on the legal security of its use — through consent robustness, erasure exposure, and confidentiality — yet no valuation methodology currently prices that risk explicitly, leaving bidders to price it informally.

Conclusion

Considering the threshold question, data clearly qualifies as estate property under the IBC. The expansive definition of "property," when read with Sections 18(f), 25, and 36(3)(d), leaves little room to exclude structured data holdings from the resolution professional's custody or the liquidation estate. The harder question — and the one Indian law has not yet answered — is what may lawfully be done with that data once inside the estate.

Three gaps remain unresolved and would require specific legislation. First, the conflict between Section 238 of the IBC and Section 38 of the DPDP Act cannot be settled by comparing non-obstante clauses alone, since informational privacy under Article 21 sits above ordinary legislation and demands constitutional, not merely statutory, reconciliation. Second, the DPDP Act's consent-withdrawal and erasure rights operate on a rolling, individual basis that the IBC's time-bound framework has no mechanism to anticipate or price, so a dataset's value can shrink mid-CIRP through no fault of the resolution applicant. Third, the IBBI Valuation Rules and Regulation 37A offer no methodology for pricing data or its associated legal risk.