Skip to Content

Data for Sale to Train AI: Lessons From the Spirit Case

Emails, internal chats and payroll records carry market value and legal risk. Here is how to keep your company's data organized and protected.
October 9, 2026 by
Data for Sale to Train AI: Lessons From the Spirit Case

A $10 million deal that raised red flags

According to a report by The Record, U.S. lawmakers have raised concerns about a proposed $10 million deal to sell internal Spirit Airlines data to Google for use in training artificial intelligence. According to a statement from Representative Steven Horsford cited by the publication, the package would include roughly 100 million emails and 500 million messages exchanged on a corporate chat platform.

The list goes beyond conversations and includes employment contracts, employee and timekeeping records, as well as payroll and tax information. The lawmakers say the transaction could expose personal and sensitive data belonging to employees and to third parties who communicated with the company, and the case is still ongoing.

For business and technology decision-makers, the episode raises a question worth thinking through carefully: if your company changed ownership, entered bankruptcy protection, or shut down an operation, what would happen to the years of emails, conversations, and HR records stored in your systems?

What the case reveals about your company's data

The first lesson is that emails, internal chats, contracts, and payroll make up an asset with market value. With growing demand for real-world data to train AI models, this body of records now attracts buyers who previously wouldn't have given it a second look.

The second lesson balances the first, because that same body of records is also a legal and reputational liability. A corporate mailbox typically holds identification documents, banking details, health information forwarded to HR, customer conversations, and supplier negotiations. Privacy laws such as the LGPD (Lei Geral de Proteção de Dados, Brazil's General Data Protection Law) and the GDPR (General Data Protection Regulation, the European data protection regulation), as well as state and local regulations across the Americas, apply principles of purpose limitation and necessity to personal data.

How to get your house in order, step by step

The process starts with data inventory and classification. A data inventory maps what information the company stores, in which systems, and for what purpose, while classification assigns levels such as public, internal, confidential, and sensitive so that each category receives the appropriate level of care.

Next come retention and disposal policies. A retention policy defines how long each type of data must be kept, whether for legal, tax, or business reasons, and what happens when that period ends. Aligning these rules with the LGPD, the GDPR, and local regulations is part of sound governance and compliance, and it reduces the volume of exposed information in any scenario.

Finally, managed backup with defined retention ensures that what is critical can be recovered, without keeping everything forever simply because there are no rules. Continuous proactive monitoring completes the picture by flagging unusual access and large-scale data extraction, such as bulk mailbox downloads, before they turn into a bigger problem.

If your company were sold, could you say which data would be in the package?

For most decision-makers, the most honest answer is "partly," and that is a great starting point. A managed IT partner can act as backup for your team to map where data lives, apply patch management (the organized updating of systems to close known vulnerabilities), configure EDR (Endpoint Detection and Response, detection and response on workstations and servers), and maintain continuous proactive monitoring of the most sensitive accounts.

Combined with backup under a clear retention policy and training people on what should and should not be shared in emails and chats, this set of measures turns a disorganized body of records into an organized asset. Companies that approach an audit, due diligence (a detailed review conducted before a corporate transaction), or a compliance process in this state spend less, take on less risk, and make decisions with greater confidence.

The Spirit case is still ongoing, but the lesson already applies to any company: data that is known, well stored, and disposed of at the right time is a sign of maturity, and that maturity is within reach of teams of any size through simple, consistent steps.

Frequently asked questions

Why are corporate emails and chats considered sensitive data?

Corporate emails and chats often contain personal information about employees, customers, and suppliers, such as documents, banking details, and health information, as well as confidential negotiations. That is why privacy laws such as the LGPD and the GDPR require care with this content. Knowing what is in these mailboxes is the first step toward protecting it.

What is a data retention policy?

A data retention policy defines how long each type of information should be kept and how it should be disposed of at the end of that period. It takes into account legal, tax, and business requirements. With it, a company avoids storing data unnecessarily and reduces legal and reputational risks.

How can a small company start organizing its data?

The most practical approach is to inventory your systems and the information each one stores, enable MFA on critical accounts, and set retention periods for emails and HR records. A managed IT partner can support the in-house team through these steps. Small, consistent steps already significantly reduce exposure.

References

Want to know how your company's data is organized? Schedule a no-obligation Strategic IT Assessment.

Data for Sale to Train AI: Lessons From the Spirit Case
October 9, 2026
Share this post
Tags
Archive