Verdict 7/10: Very Concerning for the future
What the Spirit Airlines and those Making Deals for the Data Reveals About Employee Data Rights
When a company shuts its doors, most of us think about severance, COBRA, and the scramble to find a new job, few of us think about our old work emails. Currently there’s a fight playing out in a New York bankruptcy court and is a reminder that when a business fails, its digital collateral, including years of emails, chat logs, spreadsheets, and internal records available for purchase and they just don’t disappear. I don’t think many of us realize what an asset this is to organizations that work with data, especially training AI. As data becomes less assessable to train off, we should all realize that increasingly, these assets will be sold to the highest bidder to do just that.
Spirit Airlines’ Digital Afterlife
Spirit Airlines shut down operations on May 2, 2026, after a second Chapter 11 filing in two years left roughly 17,000 people out of work and the airline carrying about $8.1 billion in debt. As part of its wind-down, Spirit auctioned off its internal business data, which Google won, agreeing to pay $10 million for a dataset that reportedly includes around 100 million employee emails, roughly 500 million Microsoft Teams messages, 30 million lines of software code, and years of records covering revenue, aircraft operations, and employee productivity. Google beat out a $7.5 million bid from Mercor, an AI training data company.
Google at no time hid its goal which is to improve their products and train their AI models on a rare, high-fidelity snapshot of how a real company operated day to day. That’s exactly what makes this data so valuable and exactly what’s making people nervous.
Then the Union Pushed Back
A hearing to approve the sale, originally scheduled for August 19, was delayed to September 9 after the Association of Flight Attendants-CWA (AFA), which represents about 5,500 of Spirit’s former flight attendants, filed a formal objection. The union’s argument is quite clear and worth all our understanding, because it points to a real gap in, we may perceive data privacy.
Google’s agreement requires a court-appointed “deidentification agent” to strip the data of anything that could be linked to Spirit’s customers, which fulfills a requirement modeled on California’s consumer privacy framework. But the AFA argues that framework was built to protect consumers, not employees, and that no comparable screen has been applied to the employment records the sale actually conveys. Those records include payroll history, disciplinary files, and internal communications and I personally would be concerned if that data was breached, let alone capable of being sold once you leave the company. As the union’s attorney put it in the court filing, the privacy protections built into this transaction are consumer-facing, even though most of what’s actually changing hands is employee-facing.
The union also raised the more technical concern about the sale agreement reportedly preserving “referential integrity” across datasets. This means all records stay linked to each other even after names are stripped out. For any of us that work in data anonymization, we know that in a workforce this size, patterns of behavior, job titles, and references to specific events can make these records re-identifiable anyway. Sara Nelson, the AFA’s international president, called the deal “outrageous,” saying it exposes payroll records, emails, and internal files that “has no business being sold.”
The Bidding War Just Makes it All The More Excruciating
Just as the privacy objection was gaining attention, a second complication emerged: Micro1, an AI training data startup, submitted a $12.5 million offer to Spirit’s legal team. This new bid was well above Google’s winning $10 million bid, and it was made after the auction had already closed. Legal experts are split on whether a judge would actually reopen a completed, court-supervised auction over a late higher bid; one bankruptcy law professor noted that courts are generally reluctant to undo a “duly noticed, well-run auction,” while another pointed out the bankruptcy code doesn’t clearly foreclose it, leaving it to judicial discretion. Whatever happens, the episode underscores just how much a defunct company’s internal data is now worth to AI developers hungry for real-world, “messy” training material that scraped public web text can’t replicate.
For the people whose emails, chats, and performance records make up this dataset, the reaction has been been as you would expect. I find this part of a broader, more uncomfortable trend where AI firms increasingly start acquiring the digital remains of failed companies, which would include Slack archives, email threads, internal drives and such, to fill gaps in their training data as public internet text runs dry. What makes the Spirit case different is the scale and that this is the first time I’ve witnessed this in public playing out. This isn’t a handful of executives’ inboxes, it’s the accumulated work product of an entire airline’s workforce, none of whom ever agreed that their internal working data might one day train a commercial AI model.
So What Are Employees Owed in Data Protection?
Here’s the part that troubles me the most because it’s not a matter of interpretation, but a genuine, largely unaddressed hole in U.S. law. It’s tempting to assume there’s a contract somewhere protecting employees from this scenario, but there really isn’t. For the vast majority of workers, there’s no individually negotiated agreement governing what happens to their data after employment ends. There is a boilerplate IT/acceptable-use policy, clicked through at onboarding, stating that anything on company systems is company property. It’s a one-sided policy the employer wrote, and it’s the closest thing to a “contract” most employees have ever agreed to about what happens to their data internal to the company.
What Does Exist
- The right to inspect your own personnel file. California (Labor Code § 1198.5) and a handful of other states guarantee current and former employees the right to see and copy their own file. That’s the extent of it, but you do have a right to look, not a right to be consulted, notified, or asked for consent before that file is sold in bulk to a third party.
- CCPA rights, since the employee exemption expired January 1, 2023. California employees technically gained the same access, deletion, correction, and sale opt-out rights as consumers. It sounds like it should matter here, but as the next section shows, it likely doesn’t.
- A bankruptcy-code privacy safeguard, but there isn’t one built for employees. Federal bankruptcy law allows a court to appoint a “consumer privacy ombudsman” to scrutinize a data sale. As the name states, that mechanism was built around customer data, not employee data. It’s the structural gap the AFA is describing that protects people’s data in a bankruptcy sale which has customers in mind, yet employees were essentially an afterthought.
- A handful of narrow, sector-specific laws. HIPAA for health information, GINA for genetic data, FCRA for background-check-sourced records. These cover thin slices of a personnel file. None of them meaningfully touch the bulk of what’s in this sale, which happens to be years of ordinary email and chat traffic. If you think about what and how you interact day-to-day with your coworkers and company, you can see how this is concerning.
What’s Missing
The Biggest Gap: If you look at theCCPA’s sales opt-out right it contains a carve-out that likely swallows whole exactly this situation. Under the CCPA, personal information transferred to a third party as part of a bankruptcy, merger, or acquisition generally doesn’t count as “sale” at all, provided it’s used consistently with what was previously disclosed. In other words, the very transaction type at the center of this case is the type of the law explicitly exempts from its main consumer protection. That’s very likely why the AFA isn’t fighting this as a straightforward CCPA violation. They realize they couldn’t win, so they’re arguing about something narrower and more procedural because the deal’s privacy safeguards were modeled entirely on consumer protections and were never extended to cover employee-specific records like payroll history and disciplinary files.
“De-identification” is doing a lot of heavy legal lifting. Both this case and the broader AI-data market lean on the assumption that stripping direct identifiers makes data safe to sell. But de-identification isn’t the same as anonymization. With enough contextual detail, such as job titles, dates, department references, the small cast of characters in any given team, then the individuals in a dataset can often be re-identified, especially in a workforce small and distinctive enough that patterns give people away.
Asymmetry: Companies famously restrict job references to “dates of employment only” and this is not as a courtesy to employees, but as a defensive legal move to protect themselves from defamation liability if a bad reference torpedoes someone’s career. That instinct only exists because the company has an ongoing interest in not getting sued. Once a company is dissolving in bankruptcy, that self-protective incentive disappears entirely. The safeguard employees have quietly relied on that of a company protecting itself, which incidentally protects them, suddenly evaporates now the risk of former employees is highest while they’re looking for new employment.
What are employees legally owed here? The right to inspect their own file, and whatever thing, sector-specific protections apply to select categories of data. Currently, legally, nothing more. There is no general legal requirement that an employer obtains consent, provides individual notice, or offers any way to object before years of work communications are sold as a bankruptcy asset. I checked around and that’s the plain structure of the law, and this case is one of the first times that structure is being tested publicly and on this scale.
Going Forward
Whatever the bankruptcy court decides on September 9, the Spirit Airlines case is likely to become a reference point. It tests real time, whether existing privacy and bankruptcy frameworks, which were built for a world where “company data” mostly meant financial records and customer lists, can adequately handle a world where a company’s most valuable remaining asset might be the accumulated digital trace of its own employees. And as the gap above makes clear, the honest answer right now is that those frameworks weren’t built to handle the demand for data to feed AI.
If there’s a practical takeaway for anyone watching this unfold, we’re the product. Many of you already know this and that you should read your employer’s data and IT policies before you need to. Understand what “company property” covers. And if you’re in California, know that your CCPA rights over your own employment data are newer, and far narrower in a bankruptcy sale, than most people realize.
If you haven’t been keeping up on this story, feel free to check out the links below:
References:
- Reuters, via NY Daily Record: “US court delays hearing on Google’s purchase of Spirit Airlines data as union objects”
- Gizmodo: “Former Spirit Employees Aren’t Happy About Its AI Deal With Google”
- SiliconANGLE: “Google’s attempt to buy Spirit Airlines’ data might come unstuck”
- Bloomberg Law: “Spirit Data Sale to Google Prompts Flight Attendants’ Objection”
- Forbes: “Google’s ‘Outrageous’ Plan To Train AI Using Spirit Airlines’ Data Blasted By Flight Attendant Union”
- Holland & Knight: “California Employee Data Exemption expires on January 1”
- Farella Braun + Martel: “Privacy During Bankruptcy Proceedings: Why It Matters”
- Jackson Lewis: “Navigating the California Consumer Privacy Act: 30+ Essential FAQs for Covered Businesses”