Technology & Society

What Actually Happens to
Your Data When a Company
Goes Bust

You've signed up to dozens of apps and services over the years. You've ticked the privacy policy boxes, handed over your email, your location, your purchase history, maybe your health data. And then the company behind one of them quietly folds. So — where does all that information go?

It's a question most people don't think about until something makes them think about it. And increasingly, something is making them think about it. The technology startup landscape produces a steady stream of companies that raise money, gather users, accumulate data, and then — when the funding runs dry or the product doesn't find its market — shut down, get acquired, or enter administration. Each of those outcomes has a different implication for the data those companies held, and almost none of them work out the way most users assume.

The short answer is: your data doesn't disappear when a company does. The slightly longer answer is that what happens to it depends on a complicated mix of how the company wound down, what jurisdiction you're in, what the privacy policy actually said, and how much the people handling the insolvency care about data protection obligations — which, in the author's observation, is often not very much.

The three most common scenarios — and what each means

The company gets acquired
This is the most common outcome for a struggling tech company with valuable data — and the one that should concern users most. When a company is acquired, its data is frequently one of the primary assets being purchased. The buyer may have a completely different privacy policy, a different business model, and a different view of what they're entitled to do with the information you handed over to someone else entirely. The original privacy policy you agreed to may or may not transfer with the data — this varies by jurisdiction and by the specific terms of the acquisition.
What typically happens
Your data moves to the acquiring company. You may receive an email notifying you of the change. The new privacy policy may contain significantly different terms. In many jurisdictions, including Australia, you have a right to request deletion — but that right requires you to exercise it, which most people don't.
The company enters administration or liquidation
When a company goes into formal insolvency, an administrator or liquidator takes control of its assets — and data is an asset. The administrator's primary obligation is to creditors, not to users. In practice, this means data can be sold to recover debts, transferred to third parties as part of a broader asset sale, or simply left in cloud storage environments that continue to be billed until someone notices. The data protection obligations that the original company had don't automatically disappear, but enforcing them against an entity that no longer functionally exists is genuinely difficult.
What typically happens
User data may be included in asset sales without specific notification. Regulators in some jurisdictions have intervened to prevent this — the Australian Privacy Act has provisions relevant here — but enforcement is inconsistent and often comes too late to protect affected users.
The company simply shuts down
Sometimes companies just stop — servers go dark, teams disperse, the website returns a 404. In these cases, what happens to data depends entirely on what cloud infrastructure the company was using and whether anyone remembered to delete the databases before the credit card stopped being charged. Data can linger in cloud storage for months or years after a company ceases operations, accessible to whoever still has the credentials — which may be a handful of former employees scattered across different cities.
What typically happens
Data may persist in cloud storage indefinitely, eventually deleted only when the hosting costs are cut off. In the absence of a formal wind-down process, there is often no one with both the authority and the motivation to ensure user data is properly handled.
The uncomfortable reality is that the privacy policy you agreed to when you signed up described the company's obligations while it was operating normally. It was not designed to protect you in the event of the company's failure — and in most cases, it doesn't.

What you can actually do about it

Some of this is structural and requires regulatory change — and that change is slowly happening, with the Australian Privacy Act under review and jurisdictions like the EU setting standards that other markets follow. But there are also practical things that individuals and businesses can do right now, without waiting for regulators.

Request deletion while companies are alive
Most privacy laws give you a right to request deletion of your data. Exercise it for services you no longer use while the company is still operating — this is far more likely to be honoured than a request made after insolvency. Make it a periodic habit, like clearing out subscriptions.
Use unique email addresses for services
Services like email aliasing let you create a unique address for each service you sign up to. If that address starts appearing in spam or breach notifications, you know exactly which company lost your data. It also makes deletion requests easier to track.
Be selective about what you share
The data that companies can sell when they fold is the data you gave them in the first place. Being thoughtful about which services genuinely need your real name, your real address, your payment history, or your health information reduces your exposure when companies don't survive.
For businesses: check your vendor data practices
If your business uses SaaS tools that hold customer or employee data, your privacy obligations extend to what your vendors do with that data — including in the event of their insolvency. Data processing agreements should address this explicitly, and most off-the-shelf ones don't adequately cover wind-down scenarios.

The broader point here is one that Abel Prasad comes back to often in thinking about technology and society: the gap between what we assume is happening to our information and what is actually happening is significant, and it tends to only become visible at exactly the moment when it's too late to do much about it. The company that folded, the acquisition that transferred your data to someone you never chose, the cloud database that kept running on autopilot — these aren't edge cases. They happen quietly, and to most people they're entirely invisible.

Invisible problems don't generate pressure for solutions. The more people understand what actually happens to their data when companies fail, the better equipped they are to make choices that reduce their exposure — and the more pressure exists on regulators and companies to build systems that handle wind-down with the same care they're supposed to handle normal operations.

Frequently asked questions

What happens to my personal data when a company goes bankrupt?
When a company enters administration or liquidation, its data is treated as an asset and may be sold to recover debts, transferred to third parties, or simply left in cloud storage. Your privacy rights don't disappear — in Australia, the Privacy Act provides some protections — but enforcing them against an entity in insolvency is practically difficult. Administrators are primarily obligated to creditors, not to users, and data sales can happen without specific user notification.
Can a company sell my data when it gets acquired?
Yes — user data is frequently one of the primary assets being purchased in a company acquisition. The acquiring company may have a different privacy policy, different data practices, and different intentions for how they use that data. In many jurisdictions including Australia, you have a legal right to request deletion of your data following an acquisition, but this right requires you to actively exercise it. Most users receive a notification email about the change and take no further action.
Does my data get deleted when a startup shuts down?
Not automatically. When companies shut down without a formal wind-down process, data often persists in cloud storage environments for months or years — running on autopilot until the hosting bills are cut off. There is typically no person with both the authority and the motivation to ensure proper data deletion. This is one of the least-discussed data privacy risks, and it's more common than most users assume.
How can I protect my data from companies that might fail?
The most effective steps are: requesting deletion from services you no longer actively use while the company is still operating (far more likely to be honoured than post-insolvency requests); using unique email addresses per service so you can track data exposure; being selective about what personal information you share with smaller or higher-risk services; and for businesses, ensuring vendor contracts include explicit data handling provisions for wind-down scenarios. Proactive data minimisation is significantly more effective than reactive remediation after a company fails.
A
Written by
Abel Prasad
Abel Prasad is a financial adviser and business consultant based in Adelaide, South Australia. He writes on technology, society, and the structural forces shaping how individuals and businesses manage information, risk, and trust in a digital environment. His analysis has been featured alongside reporting by ABC News and other outlets covering technology policy and its effects on Australian businesses and consumers.

Leave a Reply

Discover more from Abel Prasad

Subscribe now to keep reading and get access to the full archive.

Continue reading