Editor’s Note: A defunct airline’s corporate correspondence is up for sale, and the fight over it reads like a discovery dispute. Spirit Airlines proposes to sell Google enterprise data for $10 million to train AI, and the asset schedule it filed in August listed about 100 million emails and 500 million Microsoft Teams items alongside employee records. A bankruptcy hearing is set for Oct. 14. A letter from 121 members of Congress, along with objections from flight attendant and pilot unions, argues that stripping names may not be enough to protect workers’ confidential information. The court record shows why that matters to practitioners: exclusions the flight attendants’ union says track systems rather than content, search terms the union says it had not seen as of late September, a contractual privilege clawback and third parties warning that their confidential material may sit inside the corpus.
Cybersecurity, data privacy, regulatory compliance and eDiscovery professionals should watch whether the court conditions approval on a content review, how de-identification is certified and what the outcome signals for other failed companies’ data.
Content Assessment: Lawmakers press Google and Spirit on employee data before a hearing on a $10 million AI training data sale
Information - 94%
Insight - 95%
Relevance - 93%
Objectivity - 92%
Authority - 93%
93%
Excellent
A short percentage-based assessment of the qualitative benefit expressed as a percentage of positive reception of the recent article from ComplexDiscovery OÜ titled, "Lawmakers press Google and Spirit on employee data before a hearing on a $10 million AI training data sale."
News Analysis – Data Privacy and Protection Beat
Lawmakers press Google and Spirit on employee data before a hearing on a $10 million AI training data sale
ComplexDiscovery OÜ Staff
Spirit Airlines’ proposed $10 million sale of corporate email, Microsoft Teams messages and personnel records to Google for AI training faces a bankruptcy hearing Oct. 14, and 121 lawmakers want worker data held until safeguards exist.
Strip away the AI framing and the asset looks familiar to anyone who has scoped a review: about 100 million emails, 80,000 email accounts and 500 million Teams items, according to the asset schedule Spirit filed with the court in August.
What the lawmakers asked Google and Spirit to do
The letter, dated Oct. 8 and addressed to Google Chief Executive Sundar Pichai and Spirit Chief Executive Dave Davis, was led by Rep. Steven Horsford, D-Nev., and Sen. Elizabeth Warren, D-Mass. The copy posted by the Association of Flight Attendants-CWA (AFA) carries 121 signature blocks, 13 of them for senators, and Horsford’s office said the two led 119 colleagues. The Record, the cybersecurity news site published by Recorded Future, reported 114; neither the letter nor the two releases accounts for the difference.
The signers did not ask the companies to abandon the deal. They urged six steps before any worker data moves: keep employee information out of the deal as far as possible; build a de-identification protocol “agreed upon by the affected workers” and shaped by their input; keep heightened protection on disciplinary, medical, accommodation and compensation records even after de-identification; commission an “independent employee confidentiality review” with enforceable limits on downstream use; adopt formal review procedures for labor records and bar profiling of identifiable groups of workers; and exclude records from voluntary aviation safety programs.
“Removing names, email addresses, or other direct identifiers does not necessarily make a dataset anonymous,” the letter said, citing the National Institute of Standards and Technology’s acknowledgment that data stripped of identifiers can, in some circumstances, be traced back to people.
Horsford put the stakes in local terms. “In Las Vegas alone, nearly 1,000 people were laid off from Spirit,” he said in a statement. “They should not have to worry about their payroll records, disciplinary files, and private messages being used by a company they never worked for.”
Google has said it is not buying personal information. A company spokesperson told The Record that Google is “not looking to buy any personal information from Spirit,” adding that the information “will either be completely excluded or will be deidentified by an independent third party before Google receives any data.” The Record said it could not locate a press contact for Spirit, which shut down in May. A spokesperson for the Spirit estate told the South Florida Sun Sentinel that management “is working closely with the AFA and other unions on their concerns,” and that “updated sale documentation” would be filed with the court.
A consumer privacy framework applied to a workforce archive
The letter describes its inventory as drawn from “publicly available court findings.” The counts trace to the asset schedule attached to Spirit’s Aug. 14 notice of auction results in the U.S. Bankruptcy Court for the Southern District of New York. That notice named Google the successful bidder at $10 million and Mercor.io Corp. the alternate at $7.5 million.
The schedule, as filed, marked customer profiles for 97.5 million passengers “Not Included” while listing as included payroll records (3,426,618 from June 2016), employee records (175,658 from August 1986), employee tax forms, training records, 17,082,644 OneDrive items and 20,577,677 SharePoint items. That schedule describes the August proposal, and the letter’s inventory mirrors it rather than the narrower terms the parties describe in later filings. Google said in a Sept. 9 filing that it had agreed to drop the timecard, passenger transaction, refund, inflight purchase and Wi-Fi sales datasets. AFA reported Sept. 24 that flight attendant time records were also out, but that flight attendant tax forms, which Google had not agreed to drop, still faced only de-identification.
The Bankruptcy Code’s privacy machinery was built for customers. Section 363(b)(1) applies when a debtor, in offering a product or service, disclosed to an individual a policy against transferring “personally identifiable information” to unaffiliated parties, and that policy was in effect when the case began. Such a debtor may not sell that information unless the sale is consistent with the policy. The other route runs through a consumer privacy ombudsman, whom the U.S. trustee appoints on the court’s order, and a hearing at which the court may approve the sale after giving due consideration to its facts, circumstances and conditions, and after finding no showing that it would violate nonbankruptcy law.
Section 101(41A) ties the defined term to information an individual provides while obtaining a product or service from the debtor primarily for personal, family or household purposes. The list covers names, home addresses, email addresses, residential phone numbers, Social Security numbers and credit card numbers, plus birth details and other information that, tied to those items, would allow a person to be contacted or identified.
Lucy L. Thomson, whom the U.S. trustee appointed in July and the court approved, filed a supplemental report Oct. 5 recommending that, “from a privacy perspective, approval of the sale of the deidentified data would be appropriate.” Her footnotes draw the boundary plainly. The ombudsman “did not investigate or reach any conclusion about whether the data offered for sale or the deidentification process to be followed presents any risks to affected employees or third parties.” Google argued in a Sept. 9 filing that the ombudsman’s statutory role reaches only consumer data, and that this sale “is not, and never has been, a sale of Consumer Data.”
The sale agreement, in the form filed in August, follows the same consumer-facing design. Its de-identification test asks whether data can be “associated with, reasonably used to infer information about, or otherwise linked to, a particular consumer.” Certification runs to applicable law, including the California Consumer Privacy Act standard applied “to the extent applicable to U.S. consumers” and “regardless of whether such statute does, or does not, apply to the Assets,” the HIPAA rule for consumer health data and “prevailing industry standards for data deidentification.” And the work must be done “while preserving referential integrity across the data set.”
AFA’s Aug. 18 objection framed the gap in two sentences. “Deidentification addresses whether a record can be traced to a named individual. It does not address whether the contents of the record are confidential,” the union said. The Air Line Pilots Association, International (ALPA) argued in a Sept. 25 filing that the referential-integrity requirement heightens the risk, because preserved linkages “would facilitate reidentification of specific employees or groups of employees.”
An exclusion process the union says tracks systems, not content
Here the dispute turns into an eDiscovery problem. AFA’s Sept. 24 supplemental objection reports that the debtors agreed to exclude medical and disability data, accommodations, leave, drug and alcohol testing records and union records, but by naming the system where each category normally lives. A medical discussion in an email does not take the email system out of scope, according to the union, though AFA said debtors’ counsel told it that excluded material found in free-form fields would be removed “to the extent possible.”
The removal runs in at least two stages, as AFA describes it. Spirit runs a search-term pass of its own design, and the de-identification agent, which the Oct. 5 ombudsman report identifies as Tonic.ai, follows with a second screen before applying its own methods to whatever survives. AFA said that as of Sept. 24 the debtors had not disclosed the search terms they used. It said debtors’ counsel had advised that the debtors did not then plan to offer evidence at the hearing and that no Rule 30(b)(6) witness would be produced for deposition ahead of it.
Practitioners will recognize every piece of that. The standard fault lines of a discovery dispute are all present: search terms the other side has not seen, an exclusion method the objecting union has asked to verify, and a process the debtors, by AFA’s account, did not plan in September to back with evidence or a witness. The remedy AFA proposed is equally familiar: defined content categories, a database-wide search that flags them in unstructured data, and a recognized protocol that certifies the de-identification. Counsel advising any party whose information sits inside a debtor’s data estate can ask for items such as the term list, hit reports, a sampling plan and an error rate.
Privilege, third-party secrets and a clawback inside a bill of sale
Privilege is the second familiar problem in the record. Section 1(b)(i) of the filed agreement resembles a protective order’s clawback provision, though it is a contract term rather than a court order. It excludes privileged communications and work product, provides that an inadvertent transfer “shall not result in the loss of any attorney-client privilege, work product or other similar protection,” and obliges Google to return or destroy flagged material at Spirit’s election.
The asset schedule, as filed, lists “Litigation Case Files” and legal memos, including product and IP counsel reviews, as included. Both provisions can hold at once, since the schedule names repositories and Section 1(b)(i) carves privileged content out of them, but the carve-out depends on that material being identified, before transfer or, under the clawback, after it. Section 3(e), a closing condition, mentions privilege only as a ground for removing “de minimis amounts of data.” AFA argued that the agreement’s structure, including that clause and Google’s say over the de-identification agent, “leaves no room for the Debtors to withhold confidential employee information even if they wished to.” Google said in its Sept. 9 filing that the agent, though paid for by Google, “will be an independent party selected by the Debtors,” and the ombudsman’s report says the debtors made the hire.
Third parties raised the same issue from the other side. International Aero Engines objected Aug. 27 and cross-moved to enforce confidentiality agreements, arguing that because its proprietary information may have been copied into internal communications, “deidentification is insufficient to ensure that the IAE Proprietary Information has been removed.” Navitaire, Spirit’s reservation-systems vendor for 19 years, joined that objection with Amadeus. Any company that shared confidential material with a failed counterparty should check whether that counterparty’s data sale schedule sweeps it in.
Retained copies, onward transfer and the questions that outlive the airline
What the estate keeps matters as much as what it sells, and two clauses deserve litigators’ attention. Section 1(b)(ii) lets Spirit retain copies of the data “solely for purposes of winding down the Seller’s business or complying with applicable law or statutory requirements in connection therewith.” That is where any party expecting discovery from the estate should look. Section 1(c) lets Google transfer de-identified data to third parties that contractually accept its commitments against re-identification, a chain that, in AFA’s account, leaves the flight attendants no practical way to police compliance.
Information governance teams should read the schedule’s dates as closely as its counts. The August schedule listed employee records dating to August 1986 among the assets proposed for sale. In a proposed amicus brief supporting AFA, the Electronic Privacy Information Center (EPIC) and law professor Seema N. Patel argued that “proceeding with the sale as proposed would create perverse incentives for employers to over-collect employee data.” Records kept for decades can become assets a bankruptcy estate tries to sell, which gives retention decisions consequences that reach well past the operating company.
Confidential material and AI training are already colliding in ordinary litigation, where courts are writing AI-use limits into protective orders. In Morgan v. V2X, Magistrate Judge Maritza Dominguez Braswell of the U.S. District Court for the District of Colorado ordered March 30 that the protective order be amended to keep confidential information out of AI platforms unless the provider is contractually barred from “storing or using inputs to train or improve its model.” The provider must also be barred from disclosing inputs except to third parties essential to delivering the service, and those third parties must be bound by protections at least as strict. Deletion on request must be available under contract as well. In Spirit’s case, the training is the point of the transaction.
What to watch at the Oct. 14 hearing
The next step for that transaction is the hearing, adjourned four times since August and now set for 11 a.m. Oct. 14 before Judge Sean H. Lane in White Plains, New York. Replies were due at noon Oct. 9, and Google said in September that it would answer the objections before the hearing. EPIC and Patel moved Oct. 1 to participate as amici curiae. Separately, micro1 filed notice in September that it intends to submit a competing bid of $12.5 million, which it called a 25 percent premium over Google’s. Thomson asked for a chance to research further if the court considers Mercor or micro1 instead of Google, noting that Mercor “experienced a supply chain security incident” in early 2026 and that micro1 proposed to de-identify the data itself rather than use an independent party.
Security belongs on the checklist too. The ombudsman’s report says the winning bidder owes reasonable, appropriate security to the de-identified data it takes in, and ALPA has tied confidentiality directly to aviation safety. “Our safety system works because pilots and other airline workers trust that when they speak up, it stays confidential,” Capt. Jason Ambrosi, ALPA’s president, said in a statement released with the letter.
Spirit’s latest notice says the debtors are working to resolve the objections consensually, and its estate spokesperson said updated sale documentation is coming. The employee questions could still be settled by agreement before Lane rules. If they are not, the court may have to weigh whether a de-identification certificate can stand in for the content review that a discovery protocol would demand. When a company’s entire correspondence becomes a sellable asset, who should certify that the confidential parts stayed behind?

News sources
- House Sign-on Letter: Spirit Airlines & Google Need Guardrails for Sensitive Employee Data Transfer (Transportation Trades Department, AFL-CIO)
- Letter to Spirit Airlines and Google Re: Sale of Employee Data (Oct. 8, 2026) (Association of Flight Attendants-CWA)
- Spirit Airlines to Sell Employee Data to Train Google AI, Horsford and Warren Lead Call for Worker Privacy Protections (Office of Rep. Steven Horsford)
- Spirit Aviation Holdings, Inc., et al. Dockets Case: 25-11897 (Epiq Corporate Restructuring; includes Docs. 1332, 1350 and 1380 on the ombudsman appointment)
- Notice of Auction Results and Scheduled Hearing for the Deidentified Data, Doc. 1463 (U.S. Bankruptcy Court, S.D.N.Y., via Epiq)
- Limited Objection of the Association of Flight Attendants-CWA, AFL-CIO to the Proposed Sale of the Deidentified Data, Doc. 1489 (U.S. Bankruptcy Court, S.D.N.Y., via Epiq)
- Limited Objection of International Aero Engines LLC and IAE International Aero Engines AG to the Debtors’ Proposed Sale of the Deidentified Data and Cross-Motion for Enforcement of Confidentiality Agreements, Doc. 1538 (U.S. Bankruptcy Court, S.D.N.Y., via Epiq)
- Google LLC’s Preliminary Response to Consumer Privacy Ombudsman’s Report in Support of the Proposed Sale of the Deidentified Data, Doc. 1594 (U.S. Bankruptcy Court, S.D.N.Y., via Epiq)
- Navitaire and Amadeus’ Limited Objection to Deidentified Sale and Joinder in Objections, Doc. 1602 (U.S. Bankruptcy Court, S.D.N.Y., via Epiq)
- Supplemental Limited Objection of the Association of Flight Attendants-CWA, AFL-CIO to the Proposed Sale of the Deidentified Data, Doc. 1656 (U.S. Bankruptcy Court, S.D.N.Y., via Epiq)
- Supplement to Limited Objection of Air Line Pilots Association, International to the Debtors’ Proposed Sale of Deidentified Data, Doc. 1658 (U.S. Bankruptcy Court, S.D.N.Y., via Epiq)
- Notice of Adjournment of Hearing on the Sale of the Deidentified Data, Doc. 1663 (U.S. Bankruptcy Court, S.D.N.Y., via Epiq)
- Consumer Privacy Ombudsman Supplemental Report to the Court on the Sale of Deidentified Data, Doc. 1684 (U.S. Bankruptcy Court, S.D.N.Y., via Epiq)
- Notice of micro1 Inc.’s Intent to Submit a Competing and Superior Bid for the Deidentified Data, Doc. 1556 (U.S. Bankruptcy Court, S.D.N.Y., via Epiq)
- Motion by the Electronic Privacy Information Center & Seema N. Patel for Leave to Participate as Amici Curiae, with Proposed Amicus Curiae Brief, Doc. 1677 (U.S. Bankruptcy Court, S.D.N.Y., via Epiq)
- Order, Morgan v. V2X, Inc., No. 1:25-cv-01991-SKC-MDB, Doc. 65 (U.S. District Court for the District of Colorado via CourtListener)
- 11 U.S. Code § 332: Consumer privacy ombudsman (Legal Information Institute, Cornell Law School)
- 11 U.S. Code § 363: Use, sale, or lease of property (Legal Information Institute, Cornell Law School)
- 11 U.S. Code § 101: Definitions (Legal Information Institute, Cornell Law School)
- Congressional Leaders Send Joint Letter to Spirit & Google CEOs Objecting to Data Sale in Watershed Moment for Workers’ Fight for Data & AI Protections (Association of Flight Attendants-CWA)
- Spirit Bankruptcy: Objection to Sale of Your Data (Association of Flight Attendants-CWA)
- Lawmakers warn Google could expose Spirit Airlines data in $10 million AI training deal (The Record from Recorded Future News)
- Is data secure when Spirit sells to Google? US lawmakers seek privacy safeguards for ex-workers (South Florida Sun Sentinel)
- Spirit Airlines Shuts Down Operations After White House Rescue Deal Falls Through (Frequent Business Traveler)
Assisted by GAI and LLM Technologies
Additional reading
- Italy’s privacy regulator rejects IQVIA’s anonymization claim and fines it 7 million euros
- Europe’s draft cloud rule would put vendor ownership in the audit file
- The eight-hour clock starts today: EU e-evidence orders now land on covered U.S. providers’ EU addressees
- California’s AI Transparency Act arrives alongside Europe’s Article 50
- Federal magistrate judge treats LinkedIn’s Relativity aiR workflow as TAR
- One benchmark, three directions: 2026 legal rates rise, flatten and fall at once
- Confidence cools, commitment holds: full results from the 1H 2026 eDiscovery Business Confidence Survey
- Complete look: ComplexDiscovery OÜ’s 2025 to 2030 eDiscovery market size mashup
- The workstream of eDiscovery: Considering processes and tasks
Source: ComplexDiscovery OÜ

ComplexDiscovery’s mission is to enable clarity for complex decisions by providing independent, data‑driven reporting, research, and commentary that make digital risk, legal technology, and regulatory change more understandable for practitioners, policymakers, and business leaders.



























