When a Company Dies, Your Data Goes to the Highest Bidder
Somewhere in the terms of service you clicked through without reading, there is a sentence that goes something like this: “In the event of a merger, acquisition, or sale of assets, your personal information may be transferred.” On an ordinary Tuesday, that line means nothing. The moment the company files for Chapter 11, it means everything. Your name, your email, your travel history, your payment records — all of it becomes inventory in a court-supervised auction.
First, the facts of this particular story
Here is what is going around: Spirit Airlines went bankrupt, its customer database hit the asset auction block, and Google bought it to train AI models.
Straight up — I could not find verified community discussion or credible primary reporting on this. No Reddit threads, no trade-press confirmation. So I am not going to treat the Google-bought-it part as established fact. When a rumor names a specific company and a specific transaction, verification comes before commentary.
But stopping there would miss the point. The reason this story spread so fast, and the reason your gut reaction was probably “yeah, that tracks,” is that the underlying mechanism is entirely real. Customer data getting sold in bankruptcy is not a hypothetical. It has happened repeatedly, in public, with court records. The interesting question is not whether this specific deal occurred. It is why the rumor sounds so plausible.
Bankruptcy law treats your data as property
US bankruptcy law is refreshingly blunt about this. Everything a failed company owns is an asset to be liquidated for creditors. The planes are assets. The gate slots are assets. The brand is an asset. The customer database is an asset.
The problem is that the entity you consented to share data with is not the entity that wins the auction. Handing your travel history to a budget airline and handing it to an ad-tech company are two completely different acts. Bankruptcy proceedings are not built to distinguish between them. The data just moves down the schedule of assets like everything else.
The precedents are well documented. When RadioShack collapsed in 2015, it tried to sell roughly 65 million customer records — emails, purchase histories, in some cases phone numbers. A coalition of state attorneys general intervened, and the sale was ultimately narrowed by settlement. Which is another way of saying: absent that intervention, it would have gone through. The same fight played out back in 2000, when the toy retailer Toysmart promised customers it would never share their data with third parties, then filed for bankruptcy and listed the customer database for sale anyway.
The pattern is hard to miss. A privacy promise is only enforceable against a company that still exists.
Why airline data is especially valuable
You might reasonably ask why an airline database in particular would be worth bidding on. The answer is that airline data sits near the top of the value hierarchy in the data market.
It is not just names and emails. A flight booking record contains where you went and when, who you booked with, what fare class you chose, what you paid. Often it includes passport numbers and dates of birth. Layer a frequent-flyer program on top and you get years of a person’s movement patterns and spending behavior in a single structured file.
That is categorically different from a mailing list. From repeat bookings on the same itinerary, you can infer relationships. From quarterly trips to a specific city, you can infer someone’s job. It works for ad targeting. It works for model training. And joined against other datasets — credit, location, retail — it produces profiles far sharper than any single source could.
The AI era makes this considerably worse
Historically, the reason to buy a customer list at a bankruptcy auction was straightforward: send marketing email. Narrow purpose, bounded harm.
That has changed. As demand for AI training data has exploded, the entire basis for pricing a dataset shifted. The old question was “what can I sell to these people?” The new question is “how much better does this make my model?” The ceiling on that second question is dramatically higher, which is exactly why data that was once worth pennies per record now attracts serious bidders.
The deeper problem is that training is effectively irreversible. You can ask a marketing database to delete your record, and there is a reasonably clear technical path to compliance. Asking a company to extract your data from a set of trained model weights is a different category of problem — one nobody has solved at production scale. This is the point where the right to deletion, whether it comes from GDPR Article 17 or CCPA, quietly stops working.
Which is why “an AI company bought a bankrupt firm’s customer data at auction” lands as immediately credible. The motive is obvious and the economics check out.
The regulatory picture is uneven
The EU has the strongest position here on paper. Under GDPR, transferring personal data in an asset sale still requires a lawful basis, and the original purpose limitation follows the data to the acquirer. A buyer cannot simply repurpose a customer database for AI training because it paid for the file. South Korea’s Personal Information Protection Act is similarly explicit: transfers via business sale or merger require notice to the data subjects, the recipient is bound to the original purpose, and users who receive that notice can withdraw consent.
The US has none of this at the federal level. What it has instead is a procedural workaround: under 11 U.S.C. § 332, a bankruptcy court can appoint a consumer privacy ombudsman to review a proposed data sale when the debtor’s own privacy policy prohibited it. That is a real mechanism and it has been used. It is also discretionary, case-by-case, and depends on someone noticing.
Even where the rules are strong, enforcement after dissolution is the weak link. Who audits the acquirer’s compliance when the original company no longer exists, its officers have moved on, and there is no entity left to fine? The statute survives. The defendant does not.
What you can actually do
Honestly, not much at the individual level. But a few things are worth the effort.
Delete accounts on services you no longer use, rather than letting them sit dormant. A live account means your record stays on the asset schedule. Use per-service email aliases — Apple’s Hide My Email, SimpleLogin, or a catch-all domain — so that when your address surfaces somewhere unexpected, you know exactly which breach or sale it came from. And think twice before handing passport numbers or dates of birth to a company whose financials look shaky.
The real fix is structural. Bankruptcy courts should not treat personal data as fungible with warehouse inventory. Mandatory user notice and enforceable purpose limitation on any data sale, applied by default rather than only when an ombudsman gets appointed, would close most of the gap. The tooling exists. The political will mostly does not.
The Google-Spirit story is unverified, and you should treat it that way. But the fact that it sounded plausible to nearly everyone who heard it is the more useful signal. We already live in a world where personal data is a liquidatable asset. Most of us know this, and we click accept anyway.
Count the services you signed up for over the last decade that no longer exist. Now ask who owns what you left behind. I cannot answer that question about my own data with any confidence, and neither, probably, can you.
Deepen your perspective
Comments
Loading comments...