Flight attendants freaked out that Google is buying tons of Spirit employee data
Bankrupt Spirit accused of selling out workers in massive data sale to Google.
Last Friday, Google won an auction to acquire a huge amount of Spirit Airlines data.
The data doesn’t include personal information or customer data, but instead nearly covers the airline’s entire employment and workplace record.
To ensure that no individual can be identified in the dataset, Google agreed to use a court-appointed ombudsman to oversee a process to strip any personally identifying information (PII) from the data before it’s transferred to Google. Under the deal, Google agreed to maintain the data in this de-identified form and to never intentionally re-identify the data. And if Google sells access to the data, third parties would supposedly be bound by the same terms.
It may sound like a solid plan if you ever flew on Spirit Airlines and interacted with an employee by email or chat. However, Google’s privacy commitments protecting Spirit customers don’t seem to extend to former Spirit workers. Panicked by the deal, former flight attendants are now rushing to object, worried that Google has not agreed to strip confidential information that workers fear could possibly be used by Google or a third party to link them to scrubbed data.
In a court filing Tuesday, the Association of Flight Attendants (AFA), a collective bargaining unit that represents Spirit workers, argued that Google relied on consumer protection laws to guarantee the data wouldn’t contain personally identifying information (PII). However, those laws do not cover worker confidentiality, and that allegedly leaves a huge privacy loophole in Google’s deal, especially when you consider that the tech giant is buying worker data, not consumer data.
“The privacy architecture of this transaction is consumer-facing; its payload is disproportionately employee-facing,” the AFA argued. “Hence, the employee data is far more confidential than the customer data, yet receives far less protection than the customer data.”
The sale comes after Spirit Airlines went bankrupt and decided to auction off a massive dataset to the highest bidder. A privacy litigation director for a digital rights nonprofit called the Electronic Frontier Foundation, Adam Schwartz, told Ars that the sale alarmed privacy advocates.
“EFF opposes using a person’s data for a new purpose without first getting their consent, which does not happen when a bankrupt company sells its employees’ emails to become AI training data,” Schwartz said.
Google wins the auction
At the auction, Spirit debtors seemingly prioritized choosing a buyer with a plan that would least frustrate the customers it lost when the airline abruptly shuttered on May 2.
The virtual auction was described beat for beat in a court filing supporting the data sale to Google from Dylan Friesner, the vice president of PJT Partners LP, which is Spirit Airlines’ investment banker.
Held on August 14, Google placed the opening bid at $5 million, while promising from the start to cover the cost of a third party scrubbing the data. Competing bids raised next were rejected after requesting additional consumer data, including a certain customer list that Spirit wouldn’t sell. But any bid seeking to include PII in the sale was cast aside after the first round.
Included in the dataset were Spirit computer programs, applications, and code, as well as worker data spanning decades, including approximately 100 million employee emails, HR information, payroll data, and data measuring employee behaviors, activity, and productivity.
A court document showed that Google spent two and a half hours fighting off other bidders. Mercor Corporation was its fiercest rival for the data, but Mercor tried to avoid terms that would require a third party to scrub the data. Instead, Mercor floated rejected bids repeatedly offering to scrub the data itself.
Ultimately, Google won by offering the highest price, $10 million, as well as by going the extra step of covering the costs of hiring a third-party service to scrub the data to comply with consumer privacy laws. An alternative bid with similar terms for $7.5 million was accepted from Mercor, should Google fail to follow through on the purchase.
In the flight attendants’ objection—which is “limited” and does not seek to disrupt the sale—the AFA argued that Spirit debtors should have protected workers as strongly as they did consumers. “The Sale Agreement nowhere requires that anyone screen for, segregate, or restrict the use of confidential employee information” that employees deem sensitive. Specifically, they argued:
“Deidentification addresses whether a record can be traced to a named individual. It does not address whether the contents of the record are confidential. A flight attendant’s disciplinary correspondence, a crew training deficiency, a leave or accommodation request, an internal Teams exchange about staffing or scheduling grievances, and a payroll adjustment history each remain sensitive employment information whether or not the employee’s name has been stripped from it.”
Further, they’re concerned that despite Google’s agreement to never intentionally re-identify anyone in the data, the company could possibly combine the worker data with other Google datasets to re-associate them with their Spirit data.
Google says it won’t re-identify data
In a statement to Ars, a Google spokesperson suggested that the company isn’t interested in using the data to identify people connected to Spirit Airlines. Google purchased the data to improve its AI and other products.
“We acquired part of an enterprise dataset from Spirit Airlines, which can be helpful in improving our products and AI models,” the spokesperson said. “We will not receive any personal information from this dataset. Any data we receive will be rigorously scrubbed of any personally identifiable information by a third party before receipt.”
Although the AFA doesn’t make a “technical claim that any particular record can be re-identified,” they feel that they don’t need to because the risk is not speculative. For years, “increasingly powerful computer hardware” has made it easier to combine publicly available data—like you might find in Google searches—with scrubbed data to de-anonymize it, a Georgia Law researcher noted back in 2017. If Google is using the data for AI training, then it will inevitably be combined with other data.
It’s also troubling to flight attendants that Google’s deal only limits intentional efforts to identify individuals in the data. That overlooks concerns that confidential data can expose information particular groups of Spirit workers might not want public.
“Where a small, highly structured population is described across linked operational and communications datasets spanning more than a decade, the risk that information about identifiable individuals or small identifiable groups can be inferred is not speculative, and the Buyer’s covenant reaches only intentional association,” the AFA wrote.
They argued that Google’s public commitments against re-association “are real and were not obviously required,” but “a pseudonymized dataset can still disclose which crew bases generated grievances, how a small subset of flight attendants performed on recurrent training, which employees were subject to investigation, what compensation adjustments followed which events, and what employees said to one another about management, staffing, or their union.” Although Google won’t have names, “the consequence is that information whose sensitivity has nothing to do with names will pass through untouched.”
Flight attendants warned that so far, only Google has a voice in how de-identification works. They argued that the court should acknowledge that’s a problem since Google’s process allegedly ignores “legitimate concerns of parties who are not at the negotiating table.”
To protect workers, the AFA asked the court to deny approval of the sale until Google agrees to exclude all flight attendant information from the purchase and to notify workers when Google allows a third party to access the data.
Ars could not immediately reach the AFA’s lawyer for comment, but the filing is dated one day after the court’s deadline to object to the sale. It’s currently unclear if the court will weigh the AFA’s objection, but the AFA’s filing suggested a representative would be at a hearing scheduled in September where the court will possibly approve the sale.
“If the Court does permit the sale to move forward, it should only approve the sale until at a minimum the same protections extended to consumers are extended to former Spirit flight attendants,” the AFA argued. That should include directly prohibiting Google from using worker data to “analyze, profile, evaluate, score, or draw conclusions regarding any individual Spirit flight attendant or any identifiable group or subgroup of Spirit flight attendants, and from attempting to re-associate the Deidentified Data with any Spirit employee,” their filing said.
Sale requires public trust in Google
Although flight attendants seemingly feel that workers are most vulnerable to privacy risks from the data sale, consumers who understand how easy it is to re-identify scrubbed data may share their concerns.
Google is still reviewing the AFA’s objection, while maintaining that data privacy is at the heart of the deal.
A source close to the sale, who was granted anonymity to discuss the technical risk of Google re-identifying the de-identified data, told Ars that Google’s vendors will apply certified de-identification industry standards to ensure that all PII is removed from the dataset. Google won’t receive the data until it’s scrubbed and will never gain access to the original identifiers, the source said.
Additionally, Google has made binding commitments in court to never intentionally re-identify the data.
However, as the flight attendants’ association pointed out, the data sale seems to require that both consumers and workers put a lot of trust in Google.
Meanwhile, skeptics, which to some extent includes the AFA, know that Google has been accused of shady data practices linked to privacy violations in the past. In 2024, Google settled a class action lawsuit raised by Incognito users and agreed to delete billions of data records reflecting users’ private browsing activities that it surreptitiously collected. Then last year, Google agreed to pay Texas $1.4 billion to settle a lawsuit claiming Google unlawfully tracked and collected users’ private data regarding geolocation, incognito searches, and biometric data. In a press release, Texas Attorney General Ken Paxton bragged that it was “the highest recovery nationwide against Google for any attorney general’s enforcement of state privacy laws.”
Consumers will also have to trust that Google’s third party does a thorough job sanitizing the data. Flight attendants are concerned that Google’s process seems to rely on removing identifiers from structured fields, like names associated with email addresses or chat sessions. That seems like a “poor instrument” to try to strip confidential info, even if the court agrees to order the conditions they have requested to drop their objection to the sale.
Left as is, Google’s deal omits consumer data while seemingly retaining records that any worker would consider confidential, the AFA argued.
“Nearly every consumer-facing category, including Customer Profiles, loyalty and Free Spirit data, active email addresses, chat sessions, call recordings, telephone numbers, website analytics, DOT complaints, is designated ‘Not Included,’” the AFA wrote in its objection. “Nearly every category under the heading ‘Team Member,’ time card information, employee data and employee records, employee business travel records, corporate and crew training records, payroll records, employee tax forms, and employee documents, is designated ‘Included.’”
What's Your Reaction?
Like
0
Dislike
0
Love
0
Funny
0
Wow
0
Sad
0
Angry
0

Comments (0)