Former Airline Employees Concerned About Personal Data After Google’s Purchase: The Risks Nobody Priced In

Table of Contents

Spirit Airlines stopped flying in May 2026, its second bankruptcy filing in two years finally catching up with it after roughly 17,000 employees lost their jobs and the carrier’s debts climbed past $8 billion. What’s happening now, months later, is in some ways a more interesting story than the shutdown itself. A bankruptcy court in New York is deciding whether Google gets to buy what’s left of Spirit’s digital life, and the fight over that sale has turned into a genuinely useful case study in where privacy law does, and does not, actually protect people.

What Google is actually trying to buy

In mid August, Google won a court supervised auction for a large chunk of Spirit’s internal records, beating out a $7.5 million offer from the AI recruiting startup Mercor.io with a $10 million bid of its own. According to court filings, the dataset is enormous. It includes roughly 100 million company emails, some 500 million Microsoft Teams messages and collaboration records, around 80,000 email accounts, and about 30 million lines of software code and development metadata. It also includes over 175,000 employee records stretching back to 1986, covering payroll, timekeeping, training, disciplinary matters, and internal communications. Google has said the goal is straightforward: use the material to help improve its products and AI models. According to the company, passenger data, including Spirit’s roughly 97.5 million passenger profiles and its Free Spirit loyalty program records, was excluded from the deal entirely. A Google spokesperson told reporters the company “will not receive any personal information from this dataset,” and that a third party would strip out identifying details before Google ever touches the material.

The de-identification promise, and its limits

As part of getting the sale approved, Google agreed to a process overseen by a court appointed privacy ombudsman, whose job is to make sure the data is scrubbed of anything that could be linked back to an individual before it changes hands. Google also committed to never intentionally trying to re-identify anyone in the dataset once that process is complete. On paper, that looks like a reasonable, fairly standard privacy safeguard for a bankruptcy asset sale. The problem, according to the union representing Spirit’s former flight attendants, is what that safeguard was actually built to protect against. The Association of Flight Attendants, CWA filed a formal objection in the bankruptcy court arguing that the de-identification standard being used here traces back to the California Consumer Privacy Act, a law written to protect customers, not employees. As the union’s attorney put it in the filing, that framework “was built for customers, and no comparable screen has been applied to the employment record that this transaction actually conveys.” That’s a sharper distinction than it might first sound. Stripping a customer record of personally identifying information is generally meant to answer one question: can this data still be tied back to a specific shopper or passenger? Employment records raise a second question that consumer privacy frameworks were never designed to answer: even with a name removed, does the surviving content still reveal something confidential about a person’s work life, their discipline history, their union activity, or their health and accommodation needs?

Why removing a name isn’t the same as protecting the record

The union’s objection lays out exactly why this gap matters in practice, and it’s worth sitting with their argument rather than summarizing it away. A dataset that has had names stripped out can still show, in the union’s words, which crew bases generated the most grievances, how a specific group of flight attendants performed on recurrent training, which employees were under investigation, what pay adjustments followed which incidents, and what workers said to each other about management, staffing, or their union. None of that requires a name attached to be sensitive. A small crew base, a narrow date range, or an unusual disciplinary pattern can make an “anonymized” record re-identifiable in practice, even if it technically passes a formal de-identification test. Adam Schwartz, privacy litigation director at the Electronic Frontier Foundation, raised a related point to Ars Technica: using employee data for a purpose far removed from why it was originally collected, in this case training AI models rather than running an airline, raises its own separate consent question, one that a de-identification process doesn’t really answer either way. Nobody who filled out a leave request or sent a message about a scheduling conflict was agreeing, even implicitly, to have that record become training material for a technology company’s AI system years later. There’s also a structural irony the union has been blunt about. Passenger data, the information belonging to people who were never Spirit’s employees and had no ongoing relationship with the company beyond buying a ticket, was carved out of the sale entirely and protected by a well established legal framework. Employee data, generated by people who spent years working for the airline and whose personnel files contain far more sensitive material, ended up with weaker protection simply because the sale’s privacy architecture was modeled on consumer law rather than employment law. As the union’s filing states, the transaction’s privacy protections are “consumer-facing,” while its actual content is “disproportionately employee-facing.”

An unsettled area of law

Part of what makes this dispute worth watching is that there’s no clear rulebook for how it should come out. Lindsey Simon, an associate law professor at Emory University, told reporters that the outcome could genuinely go either way, largely because these calls tend to fall to the presiding judge’s discretion. The bankruptcy code itself doesn’t spell out how employee confidentiality should be handled when a company’s data becomes an asset for sale, which leaves judges essentially building the standard case by case as these disputes come up. That gap is exactly what the union is trying to get the court to close in Spirit’s case specifically. Its objection asks the court to reject the sale unless flight attendant data, including training records, time cards, payroll information, and any Microsoft 365 content involving flight attendants, is excluded outright, or unless a genuine, independent screen for employee confidentiality is added to the deal. A hearing on the sale, originally set for August 19, was pushed back to September 9 after the union’s objection was filed, and the court has not yet ruled on either the sale itself or the adequacy of Google’s privacy commitments.

Why this matters well beyond one airline

Spirit is not the only company whose internal records are attracting interest from AI developers hunting for training data. As more businesses fail, restructure, or simply look for new sources of revenue, bankruptcy sales and data licensing deals are becoming a real pipeline for the kind of large, messy, real world datasets that AI companies want and that are otherwise hard to come by. That makes the outcome of Spirit’s case more than a one off dispute. It’s shaping up as an early test of a question that’s going to keep coming up: when a company’s data becomes a sellable asset, whose privacy interests actually get built into the sale terms, and whose get left out because nobody wrote a law with them specifically in mind. For compliance and privacy teams, there are a few practical takeaways worth pulling out of this dispute even before the court rules:
  • Consumer privacy frameworks and employment confidentiality are not interchangeable. A de-identification process built around a law like the CCPA answers a narrower question than “is this record actually safe to hand over.” Businesses evaluating any data sale, licensing deal, or AI training arrangement involving workforce data need a separate, explicit review for employment specific sensitivities, not an assumption that consumer grade anonymization automatically covers it.
  • Removing a name is often not enough on its own. Small population sizes, narrow date ranges, and unusual patterns in disciplinary or performance data can make records re-identifiable even after formal identifiers are stripped, particularly within a defined workplace like a single crew base or department.
  • Purpose matters, not just identity. Data collected for running payroll or handling a leave request was never collected with an eye toward AI model training. Any organization considering a secondary use this different from the original purpose should expect that gap to draw scrutiny, whether from a union, a regulator, or a court.
  • Bankruptcy doesn’t erase privacy obligations, it just changes who’s asking the questions. A company heading toward insolvency should treat its employee data governance as seriously as its customer data governance well before a sale process starts, since the terms negotiated in a rushed asset sale may end up being the only protection that data ever gets.
Whatever the bankruptcy court decides on September 9, the underlying tension here isn’t going away. AI developers are going to keep looking for large, realistic datasets, and distressed companies are going to keep having internal records sitting on their books that look, to a buyer, a lot like an asset. The Spirit Airlines case is simply the moment that tension became visible enough, and specific enough, for a judge to have to weigh in on where the line actually sits.

Written by: 

Online Privacy Compliance Made Easy

Captain Compliance makes it easy to develop, oversee, and expand your privacy program. Book a demo or start a trial now.