Toysmart, 2000
- In the lot
- ~250,000 customer records
- The safeguard
- The office did not yet exist
- What it produced
- Its 60% shareholder paid $50,000 to take it off the market
When a company dies, everything its staff wrote at work becomes an asset on the schedule. In August 2026 Google was the winning bidder for one such archive at $10 million, or about £7.4 million. A judge in New York decides on 9 September whether it goes through. Nobody inside the archive was asked, and there is no reported case anywhere in Britain or the EU of an employee stopping a sale like it.
You have spent years writing things at work. Emails you would not want read aloud. A message to a colleague about a manager. A support ticket describing a problem you caused. A commit comment written at eleven at night. You assume this material is boring, private, and destined for deletion.
It is none of those things. It is inventory. And the moment your employer stops trading, it goes on a schedule, gets a lot number, and is sold to whoever bids highest.
There is a name for the industry that buys it. Data as a service is the business of selling access to information about people and companies who are not your customers and have never heard of you, delivered as a live feed rather than a file. You are already deep inside that market. What follows is the story of the day it reached into the one place you assumed it could not.
Spirit Airlines stopped flying on 2 May 2026, having failed to emerge from its second attempt at Chapter 11. It had flown under that name for 34 years, though the personnel records in its archive reach back further than the name does. Chapter 11 is the American procedure in which a company keeps trading while it restructures, as opposed to Chapter 7, in which it simply stops. Spirit tried the first, twice, and ended at the second. Roughly 17,000 people lost their jobs. The company owed about $8.1 billion.
What was left became an estate. That word is not a metaphor. When a company fails, its assets pass into the hands of an officer whose legal duty is to convert them into money for creditors, exactly as an executor converts a dead person's belongings. Everything the company owned becomes a lot.
On 14 August 2026, in the US Bankruptcy Court for the Southern District of New York, one of those lots went to auction. Google LLC won it at $10,000,000. Mercor.io Corporation, an AI data company, came second at $7,500,000. Those two figures are on the face of the court's Notice of Auction Results, and they are the only bids the public file discloses.
The legal instrument is a section 363 sale, and its mechanics explain why anyone bothers. Section 363 of the US Bankruptcy Code lets a failing company sell assets quickly, outside the ordinary course of business, without waiting for a full restructuring plan. Crucially, under section 363(f) the sale can pass the asset to the buyer free and clear of most competing claims against it, though the clearing has never been absolute and courts have carved out categories of liability it does not reach. Those claimants are left with a claim against the sale proceeds instead of against the thing itself. That is what a bankruptcy buyer is really paying for: not a discount, but a title that is unusually hard to chase.
Whether free and clear reaches the rights of the people described inside a dataset is a question no court has answered. Nobody has held that it does. Nobody has held that it does not. Every reported fight about a data sale has turned on a different provision, the one that summons the privacy office, and the office is where this story goes next.
Here is what $10 million bought, as itemised in the sale documents:
| Asset | Volume |
|---|---|
| Corporate emails | 100 million, across 80,000 accounts |
| Microsoft Teams messages | 500 million |
| Source code | ~30 million lines, across 516 repositories |
| OneDrive items | ~17.1 million |
| Revenue transactions | 7,510,221,520, back to May 2008 |
| Payroll records | 3,426,618 |
| Personnel records | 175,658, back to August 1986 |
| Flights flown | ~763,000, since April 2023 |
| Passenger name records | 190 million, de-identified, included |
Source: Notice of Auction Results, In re Spirit Aviation Holdings, Inc., Case No. 25-11897 (Bankr. S.D.N.Y.); Bloomberg Law
Read the last line again. The framing repeated almost everywhere is that customer data was excluded. Customer data of a particular kind was excluded: 97.5 million customer profiles, 50.2 million Free Spirit loyalty accounts, 740,000 co-branded cardholder records, 30.87 million call recordings, 13.7 million marketing email addresses. But 190 million passenger name records went with the sale, with the names taken off. And Reuters reports the estate kept the right to sell customer spending data separately, to travel and hospitality buyers. Excluded means excluded from Google's lot. It does not mean withheld from the market.
Google's statement was narrow and carefully drawn: "We acquired part of an enterprise dataset from Spirit Airlines, which can be helpful in improving our products and AI models." A spokesperson added that the data would be "rigorously scrubbed of any personally identifiable information by a third party before receipt" and that "We will not receive any personal information from this dataset."
Neither sentence is untrue. Both are narrower than they sound. Hold on to that phrase, personally identifiable information, because in an American bankruptcy it is not a description. It is a statutory term with a narrow definition, and the whole transaction turns on it.
Why buy any of this. In June 2024 the research group Epoch AI put the effective stock of public human text at around 300 trillion tokens, a token being roughly three quarters of an English word. Its 90% range is wide, from 100 trillion to 1,000 trillion. Training datasets have been growing at about 2.4 times a year, which on the central estimate exhausts the supply around 2028. Epoch has been wrong before, and wrong in the direction that flatters this article's argument: its 2022 paper put exhaustion of high-quality text several years earlier, then revised the stock upward. Treat the date as soft and the direction as fixed. Everything that can be scraped has a floor, and every frontier lab can now see roughly where it is.
"Actually quite low."
Ansari's company sent Spirit's lawyers an offer of $12,500,000 on 19 August, five days after the auction closed and on the morning of the approval hearing. His argument, as reported, is that the mess is the point: a tidy dataset teaches a model nothing about working in real conditions. That offer is still live before the court. So is an objection from the flight attendants' union. Judge Sean H. Lane adjourned the hearing by three weeks and will hear it on 9 September 2026. As this piece goes out, nothing has been approved. One detail matters for what happens after that date. Under section 363(m), an objector who fails to obtain a stay and then watches the sale close to a good faith purchaser will struggle to unwind it on appeal. The Supreme Court held in MOAC Mall Holdings v Transform Holdco in 2023 that this limits the relief a court can give rather than stripping it of jurisdiction, which sounds like a softening and is not much of one. Once the money moves and the data moves, an appeal has very little left to undo. In practice the hearing is not one stage in a long argument. It is close to the whole of it.
Could this happen in Britain. Yes, and with less friction. The mechanism has three parts and Britain has all of them. A company enters administration or liquidation under the Insolvency Act 1986. An office holder takes control with a statutory duty to realise value for creditors. Databases and code are property of the estate, held through copyright and database rights, and they are saleable. What Britain does not have is the American safeguard you are about to meet, because no equivalent office exists here at all. Set against that, no publicly reported British sale of an internal corporate archive to an AI buyer has yet happened, and there is a reason to think one would be harder: British data protection law travels with the data and does not fall away on a sale. We come back to all of this. First, the safeguard.
American bankruptcy law has a privacy office. It exists because of a children's toy shop.
In 2000 Toysmart.com went under holding a database of roughly 250,000 customers, having promised in its privacy policy that personal information would "never" be shared with a third party. It tried to sell the list. The Federal Trade Commission sued. Thirty-nine states opposed the sale at a hearing in July 2000, and by 4 August forty-four had signed a joint objection to the FTC's proposed settlement. Judge Carol Kenner declined to approve it as premature. In January 2001 Buena Vista Internet Group, a Walt Disney subsidiary that already owned around 60% of Toysmart, agreed to pay $50,000 for the list so that it could be destroyed. Kenner ordered it held by Toysmart's lawyers until the remaining claims were settled, and destroyed after that. Contemporaneous reporting does not record the destruction being carried out, and nobody appears to have gone back to check.
Five years later Congress wrote the case into the statute book. Senator Patrick Leahy, sponsoring the amendment, put it simply: "Once somebody tells you we are going to keep your kids' information confidential, it will be." The 2005 reforms added a definition of personally identifiable information at 11 U.S.C. § 101(41A), a trigger at § 363(b)(1), and an office at § 332: the Consumer Privacy Ombudsman.
Two things about that office, before anything else. It is not what a British reader will assume. Our ombudsmen take complaints from the public; this one does not. And it cannot stop a sale. It investigates, files a report to the judge, and recommends conditions. The judge decides. The ombudsman has no veto.
It also has to be summoned, and the summoning has three gates. All three must open.
In the Spirit transaction, the court appointed no consumer privacy ombudsman. Bloomberg Law reports that it is relying on the parties instead. The material governed by the ombudsman regime sits on the excluded schedule; the material outside it sits on the included schedule. Nothing in the filings suggests the split was designed that way, and the effect is the same either way. The safeguard operated exactly as drafted and never touched the thing being sold.
Even where the office does open, it mostly does not bite. Professor Christopher Bradley of the University of Kentucky searched every US bankruptcy docket, meaning the public court file, from the statute's enactment in 2005 to mid-2020. He found 141 cases in which an ombudsman was appointed, filed a written report, and consumer data was to be sold. His paper is called Privacy Theater in the Bankruptcy Courts, 74 Hastings L.J. 607 (2023), and the title is the argument.
The most instructive case is the one where the office worked. RadioShack collected personal information from more than 117 million customers and, in 2015, tried to sell it. An ombudsman was appointed, Elise Frejka of Frejka PLLC. Apple and AT&T objected on their own account. A coalition that ran to thirty-eight states settled the matter in a mediation run by a retired bankruptcy judge, Leif M. Clark, and Judge Brendan Shannon approved the result. Around 67 million name-and-address files went to the buyer, of which some 8.3 million carried an email address. Roughly 50 million records were destroyed, and the destruction was certified to the court. Of the more than 170 fields RadioShack held on a customer, seven survived alongside the name and address. No card numbers, no social security numbers, no dates of birth. That is what a functioning safeguard looks like. Not prevention, but a very deep cut.
Now the cases where it never engaged. Sports Authority sold roughly 114 million customer files to Dick's Sporting Goods in 2016, and the court's own sale order found no ombudsman necessary because the privacy policy had been complied with. That policy had reserved the right to transfer personal information "in the event of a corporate sale, merger, acquisition, dissolution or similar event." Bradley then ran the wording of that finding through a database of bankruptcy dockets. It "yielded eighty results in which language stated that no ombud needed to be appointed". One court's convenient sentence, and eighty places where it turns up. Caesars Entertainment moved its Total Rewards loyalty database out through a restructuring plan rather than a standalone asset sale, and no ombudsman was appointed. Bradley records the absence. The explanation usually offered for it, that the trigger in § 363(b)(1) reaches asset sales rather than plan transfers, is a practitioners' reading rather than a settled point of law. ConnectEDU put around 20 million student records into its estate, grades and disability accommodations included, and the FTC asked for an ombudsman and did not get one, reportedly because the company had no employees left by the filing date.
One sentence in a privacy policy, written years earlier by someone not thinking about liquidation, disarms the protection. The protection was designed for a company that made a promise. It has nothing to say about a company that never made one.
| Case | In the lot | The safeguard | What it produced |
|---|---|---|---|
| NOT SOLD | |||
| Toysmart, 2000 | ~250,000 customer records | The office did not yet exist | Its 60% shareholder paid $50,000 to take it off the market |
| XY Magazine, 2010 | ~100,000 subscribers, plus 500,000 to 1m online profiles of young gay men | FTC staff letter, no ombudsman | Consent order requiring permanent destruction |
| CUT DOWN | |||
| RadioShack, 2015 | Personal information on 117m customers | Ombudsman, plus Apple, AT&T and 38 states | 67m records transferred, seven of 170+ fields survived |
| Borders, 2011 | Records for nearly 48m customers | Ombudsman urged opt-in, was overruled | 15-day opt-out. The notice went out over a weekend |
| 23andMe, 2025 | Genetic and health data on ~15m people | Ombudsman urged opt-in consent, was refused | Auction reopened. $305m, to the founder's own non-profit |
| NEVER ENGAGED | |||
| ConnectEDU, 2014 | ~20m student records, grades and disability accommodations | FTC asked for an ombudsman. Did not get one | Notice arrived after the sale. Under 1% asked for deletion |
| Caesars, 2015 to 2017 | Total Rewards loyalty database | Moved by restructuring plan, not asset sale | No ombudsman, no separate price |
| Sports Authority, 2016 | ~114m customer files | Court found none necessary | The policy already allowed transfer on a sale. $15m |
| Debenhams, 2021 (UK) | Brand, websites and, on law-firm accounts, the customer data | No such office exists here | £55m to Boohoo. No privacy step on the public record |
| SimpleClosure, 2026 | ~100 wind-downs: Slack, Workspace, code repositories | Not a court process at all | $10,000 to $100,000 each, as a service |
| Spirit Airlines, 2026 | 100m emails, 175,658 personnel records | Employee data sits outside the definition | Pending. Hearing 9 September |
Sales of personal or operational data out of insolvent estates, 2000 to 2026, ordered by outcome. Sources: FTC press releases and staff letters; state attorney general settlement announcements; bankruptcy court filings; Bradley, 74 Hastings L.J. 607 (2023)
Read it downwards. It begins with a database taken off the market in 2000 and ends with a wind-down service selling archives by the hundred as a product. Only the top band ever produced a refusal, and the last time that happened, the office you have just read about did not exist yet.
The law protects what you told a shop. It has nothing to say about what you told your boss.
Buried in the Spirit sale documents is a phrase that decides everything. The estate must deliver the archive de-identified, to the standard of the California Consumer Privacy Act or the American health-data rules at 45 C.F.R. § 164.514, and must certify that it has done so. Then comes the qualifier:
"...while preserving referential integrity across the data set."
Referential integrity is a term borrowed from database engineering, and it means the links survive. Names are replaced with tokens, but the same person's token is the same token everywhere. One individual's chain therefore stays intact: the email raising a problem, the ticket it became, the code commit that fixed it, the flight that departed on time afterwards.
That distinction has a name in law, and it is the difference between two words that sound interchangeable. Anonymised data cannot be traced back to a person by any means reasonably likely to be used, and it falls outside data protection law altogether. Pseudonymised data has had the identifiers swapped for tokens but remains relinkable, and in Britain it is still personal data, still fully regulated. A file that preserves referential integrity is, by construction, the second thing.
The chain is also the entire reason the archive is worth $10 million. A frontier AI lab training a model to do work does not want more prose. It has read the internet. What it lacks is the recorded shape of a decision: the state of the world, the action taken, the result. That triple is what the labs call a trajectory, and it is the scarce input. Public text captures outcomes. An internal archive captures the causal graph of labour. Strip the links and you have a pile of disconnected sentences. Keep the links and you have a training set.
You also have a person.
They take your name off it. They keep everything that made it yours.
The Association of Flight Attendants-CWA filed a limited objection on 18 August. It does not ask the court to stop the sale. It asks for the crew records to come out, or for review protocols to go in. The argument is precise:
"The privacy architecture of this transaction is consumer-facing; its payload is disproportionately employee-facing."
On mechanism, the union argues that a tokenised set can still disclose which crew bases generated grievances, how a small group performed in recurrent training, which is the mandatory periodic recertification cabin crew must pass, and which employees were under investigation. Cross-reference a tokenised chain against public flight schedules and known incident dates, and at an individual crew base the numbers are small enough to do the rest. Sara Nelson, the union's president, made the commercial point more bluntly. Spirit flight attendants, she says, have still not been paid their accrued holiday and sick leave, and selling their data on top of that is "adding insult to injury", as she told Fortune.
The academic literature is not on the buyer's side, though it is more contested than the headline numbers suggest. Latanya Sweeney showed in 2000 that 87% of Americans could be uniquely identified by three details: sex, date of birth and ZIP code, an area averaging some eight thousand people, against a British postcode covering roughly fifteen properties. Philippe Golle re-ran the same test on newer census data six years later and got 63%, which is the figure the field now argues about. Yves-Alexandre de Montjoye and colleagues showed that four points of time and place identify 95% of people in a mobile phone dataset covering 1.5 million subscribers in one European country. Rocher, Hendrickx and de Montjoye, publishing in Nature Communications in 2019, modelled that 99.98% of Americans would be correctly re-identified in any dataset using fifteen demographic attributes. That last figure is a statistical projection rather than an executed re-identification, which is worth knowing before you repeat it.
Against that, the British regulator's threshold is not zero risk. The Information Commissioner's Office finalised its anonymisation guidance on 28 March 2025 and applies a motivated intruder test: a hypothetical person who is "reasonably competent", "has access to appropriate resources (eg the internet, libraries, public documents)" and "uses investigative techniques". You must reduce the risk of identification to "sufficiently remote".
Nobody independent checks any of this, and the buyer has a say in who does. The sale agreement requires delivery to a de-identification agent "acceptable to or designated by Buyer", which gives Google at minimum a veto over who checks the file and may give it the choice outright. The agreement points at two possible standards, the California statute or the American health-data rules at 45 C.F.R. § 164.514, and the second of those contains two quite different methods: strip eighteen listed identifiers mechanically, or have an expert certify that the risk of re-identification is very small. Which one applies decides how much the certificate is worth. The filings do not say. There is no ombudsman in this deal, no statutory audit, and no route by which anyone in the archive can test the result. Google has separately committed not to intentionally re-associate the data with individuals or households, which is a promise about intent rather than a property of the file.
The Spirit auction is newsworthy because a famous buyer paid a round number for a dead airline. The transaction underneath it is ordinary, and it is happening constantly.
SimpleClosure, an American startup wind-down service, launched a product called Asset Hub on 16 April 2026. It sells the leftover digital assets of failed companies: the Slack archives, the Google Workspace exports, the code repositories. Forbes reported it had run around 100 such deals at between $10,000 and $100,000 per company. Spirit is not the beginning of this market. It is the first lot big enough to reach a court file you can read.
And insolvency is the visible case, not the common one. This piece is about bankruptcy because bankruptcy leaves a paper trail. Your realistic exposure is a solvent sale: your employer gets bought, you transfer across, and the mail archive goes with the business. There is no court, no auction, no docket, no union and no journalist reading filings.
In that version, your data goes with the company and is almost never priced as data. The accounting standards have no line for it. Under IFRS 3 and IAS 38 in Britain, and ASC 805 in America, an acquired dataset is recognised separately only if it is identifiable and separable, and most corporate data is neither. So it gets absorbed: into "customer relationships", into "developed technology", or into the residual, which is goodwill. Microsoft's accounts for the LinkedIn purchase put the total at $27,009 million and send $16,803 million of it straight to goodwill. The $7,887 million of identifiable intangibles is split into customer relationships, trade names, technology and contracts. There is no line called data, and LinkedIn's entire professional graph is the reason anyone paid. Roche bought Flatiron Health for $1,616 million and booked $1,174 million of that as goodwill. The oncology records that were the thesis of the deal appear nowhere by name.
Then there is the structure, which decides whether anyone tells you. Buy the shares and the controller does not change: the same legal entity holds the same data under the same lawful basis, and nobody has to be notified of anything. Buy the assets and it is a transfer between two controllers, which needs its own legal basis and, under Article 14 of the UK GDPR, notice to the people described in the data within one month. That duty has an escape hatch, for cases where notifying everyone would involve disproportionate effort, and the argument about how wide the hatch opens is one Britain has already had. We come to it in section five. The commercial outcome is identical. Whether anyone has to tell you depends on which document the lawyers reached for.
Regulators do occasionally treat the data as the substance of a deal rather than its residue. Google was allowed to buy Fitbit only after committing to ten-year data silos. Experian abandoned its purchase of ClearScore after the Competition and Markets Authority's provisional findings. The Committee on Foreign Investment in the United States forced Grindr's Chinese owner to sell it, on the ground that the data itself was a national security matter. And the European Commission cleared Apple's purchase of Shazam by finding the opposite: the data was not unique, so owning it conferred nothing.
In an insolvency the data is sold in public and priced badly. In an acquisition it is transferred in private and not priced at all.
Above both sits the older trade, and you are already inside it without having agreed to anything in particular. Experian, Equifax and TransUnion hold a file on you and license it out. LiveRamp goes further: it stitches your app activity, your browser session and your in-store purchase into a single persistent identifier, so a buyer who has never met you can address all three as one person. Data marketplaces run by Snowflake, Amazon Web Services and Databricks then let those brokers deliver the result as a live query against their own systems rather than as a file anyone hands over, which is why nobody can tell you where a copy of you currently sits.
The money underneath is real. Retail media, meaning advertising sold by shops against their own customer data, grew 18% in 2025 to £3.8 billion of the UK's £40.5 billion digital advertising market, on IAB UK's audited Digital Adspend study. Most of it rides on loyalty schemes. Tesco's Clubcard reaches more than 20 million households on independent reporting. The Office for National Statistics counts 29.0 million households in the country.
And here the industry's critics have the story backwards, and so does the industry.
| What was tested | Accuracy achieved | Baseline |
|---|---|---|
| Third-party gender segments | 42.3% average (range 25.7% to 62.7%) | 50% by coin toss |
| Third-party "male, 25 to 54" | 24.4% | 26.5% in the population |
| Third-party probabilistic segments, B2B | 9.4% to 11.0% | 16.0% random prospecting |
| Third-party deterministic segments, B2B | 16.1% to 18.2% | 16.0% random prospecting |
| Publisher first-party, business content interest | 41.8% | 16.0% random prospecting |
Sources: Neumann, Tucker & Whitfield, Marketing Science 38(6), 2019; Neumann, Tucker, Subramanyam & Marshall, Quantitative Marketing and Economics 21(4), 2023
Two distinctions run through that table. First-party data is collected by the company you actually dealt with. Third-party data is assembled by a broker who has never met you. Within the third-party trade, deterministic segments are built from something you demonstrably did; probabilistic segments are inferred from proxies, and they cost more.
Nico Neumann, Catherine Tucker and colleagues ran field experiments across nineteen brokers and more than ninety audience segments. Bought third-party data identified gender correctly 42.3% of the time, which is not roughly random but worse than guessing. In the same 2019 study, reaching an audience through third-party targeting cost about two and a half times what untargeted display advertising cost. In a separate study four years later, inferred business segments performed below a random baseline. First-party publisher data, in that second study, beat the baseline by a factor of two and a half.
So the axis is not consumer data against operational data. It is inference against record. The third-party trade is enormous, cheap and frequently useless because it is guessing at attributes from proxies. First-party data works, which is why Clubcard is a business. And an internal corporate archive is the purest form of record there is, because it is not describing anybody. It is what they did.
That also resolves something the last section left hanging. A buyer training an AI agent does not want to know who you are; it wants to know how the work went. Which is precisely why nobody is guarding your identity in the file, and precisely why it remains recoverable by someone who does want it.
So is $10 million cheap. Here is the only honest way to test it, and the workings matter because neither corpus has a published token count. Take the Spirit lot at somewhere around 25 to 30 billion tokens, on the rough basis that 100 million emails and 500 million short messages dominate the volume. That puts Google's purchase at roughly $0.35 per million tokens. Reddit's licensing arrangements, disclosed in its flotation prospectus at $203.0 million of contracted value over two to three years, work out somewhere between three and eight times that per token, depending on what you believe Reddit's licensable corpus contains. This is Undercurrent's own estimate with the assumptions on the table, and the honest summary is that Spirit went for less per token than a live social network, not that it went for a hundredth.
Cheap, then, on any comparison available. But cheap is not the same as valuable. Spirit collapsed under $8.1 billion of debt after years of operational difficulty, and a record of how Spirit ran is a record of how a failing airline ran. Train a model by rewarding it for copying what Spirit did and you reward the delays and the workarounds alongside the good calls. Forty years of archive also means dead file formats, undocumented schemas and heavy duplication, and nobody has published what it costs to make a corpus of that shape trainable. Nor will anyone settle it: frontier labs never publish the experiment that would, which is to train the model twice, once with the archive and once without, and show the difference.
There is a harder version of that objection, and it is standing in this article already. Mercor and Micro1 are in this story as the underbidder and the late bidder, and their actual business is commissioning trajectories to order: paying experts to generate the recorded reasoning the labs want. If that can be manufactured at scale, a dead airline's archive is a cheap substitute rather than a scarce input, and $10 million is the right price for a nice-to-have.
Which leaves one reading of the price. Ten million dollars was never a valuation. It was a cheap option: it denies the corpus to a competitor, hedges against a future in which scraping becomes legally harder, and supports an enterprise cloud sales story. Micro1 offering $12.5 million five days late does not prove the asset is worth more than $10 million. It proves that three organisations wanted it, that two numbers were tested at the auction, and that whether a judge can reopen a closed auction to take a third is now itself part of what is being decided.
If a British company you worked for went into administration tomorrow, three things would be true, and none of them is what you would guess.
There is no privacy office. The Consumer Privacy Ombudsman is a creature of the US Bankruptcy Code. Administration and liquidation under the Insolvency Act 1986 have no analogue: no statutory appointee, no court-appointed privacy examiner, no mandatory report. What exists instead is the insolvency practitioner's own duty, as the party legally responsible for the data, to comply with UK GDPR, supervised by the ICO in the ordinary way. That is weaker in one respect and stronger in another. Weaker because nobody is appointed to look. Stronger because, unlike an American section 363 sale, British data protection law does not sell free and clear. Your rights travel with the file into the buyer's hands.
The rule everyone cites does not exist. Something narrower does. The Insolvency Service's live operational guidance for Official Receivers, at its own Chapter 39, updated on 20 April 2026, says a purchaser may use a database only for the purposes for which the information was originally collected and within "the reasonable expectations of the individuals concerned". Its worked example is a dental practice: the patient list should go to "another dentist providing similar dental treatments". Paragraph 39.123 adds that "if a database is sold affected individuals must be told who now has their information". That is restrictive, and it is also narrow: Chapter 39 is operational guidance for Official Receivers, who act in compulsory liquidations and bankruptcies. It does not bind an administrator running a private administration, which is the scenario this section opened with. The often-cited rule that data must stay within the same trade traces to an ICO good practice note from 2006 that is no longer published. The ICO's current data sharing guidance, updated on 9 September 2025, treats a database sale as ordinary data sharing and does not mention insolvency at all.
You do not own your work emails. Neither does your employer. English law has spent a decade circling this and declining to land. The old rule was that personal property came in two kinds: things you can physically hold, and things you can only enforce through a court, such as a debt or a share. Digital records fit neither. In Your Response Ltd v Datateam Business Media Ltd [2014] EWCA Civ 281 the Court of Appeal held that an electronic database is not something you can possess, so a supplier could not hold one hostage against unpaid fees. In Fairstar Heavy Transport NV v Adkins [2013] EWCA Civ 886 the same court gave a company the right to inspect business emails held by a former chief executive, but grounded that right in the law of agency and expressly declined to decide whether information can be property at all. In Capita plc v Darch [2017] EWHC 1248 (Ch) an employer's property claim in its own emails failed.
There is a further twist about who is even responsible. When a company goes under, the insolvency practitioner does not become the guardian of your data. In Re Southern Pacific Personal Loans Ltd [2013] EWHC 2485 (Ch), decided under the previous data protection regime and never revisited since, the court held that officeholders are not personally responsible for data protection compliance in respect of data processed by the company. They act as its agents; the company, which by then is a corpse, remains the controller. The Information Commissioner argued for the opposite result in that case, wanting the practitioner on the hook personally, and lost.
So your employer has custody, not title. You have neither. And once your employer is dead, the thing legally answerable for your file is the dead company. And the Property (Digital Assets etc) Act 2025, in force since 2 December 2025, has just removed the categorical objection that kept this tidy: a thing is no longer barred from being property merely because it is neither of the two old kinds. The Act was written for crypto-tokens. Whether it reaches a corporate email archive is an open question nobody has litigated.
There is no reported case, anywhere in Britain or the EU, of an employee successfully blocking the transfer of workplace communications in a sale or an insolvency. Not an injunction, not an ICO enforcement notice, not a tribunal ruling. The levers exist on paper: objection under Article 21, erasure under Article 17, breach of confidence, misuse of private information. None has been deployed successfully against a transfer. Nor does TUPE help, which is the first thing most people reach for. The Transfer of Undertakings regulations move your contract to the buyer and require your employer to hand over employee liability information about you. TUPE is a mechanism for transferring your data, not for withholding it.
What does work, modestly, is the subject access request: a written demand that an organisation tell you what personal data it holds about you and give you a copy. It applies to the buyer once the buyer holds your file. And paragraph 39.123 above means that in an Official Receiver case you are entitled to be told who now has your information, which is a live and under-used entitlement.
And it does happen here, quietly. When Debenhams collapsed, its administrators at FRP Advisory sold the global rights to the brands and the websites to Boohoo for £55 million in January 2021. FRP's own announcement mentions brands and websites; law firms writing up the deal say the intellectual property included customer data. Which is the British pattern in one sentence: the thing you would most want to know is the thing the public record does not say.
Sometimes the answer is that nothing was sold. Wonga's administrators at Grant Thornton said plainly that the remaining loan book would not be sold to a debt collector. When Carillion was wound up in January 2018 it employed around 18,200 people in Britain; 11,739 of those jobs moved to new suppliers and 2,340 were made redundant. What became of the personnel records is not discussed in the National Audit Office report, the Official Receiver's updates, or anywhere else on the public record. Not because it was hidden. Because in Britain nobody has to say.
The nearest British parallel cuts against that, and it is worth being precise about why. The Information Commissioner's Office executed a warrant at Cambridge Analytica in March 2018 and carried out 42 laptops and computers, 31 servers and around 700 terabytes. That was six weeks before SCL Elections collapsed into insolvency, so it is not a case of a regulator reaching into an estate. What happened next is the interesting part. The enforcement notice was not about the voter profiles or the psychographic models. It was about a single subject access request, made by an American academic, David Carroll, who wanted to see his own file. SCL ignored it, and the company was prosecuted and fined £15,000 while already in administration. So a dead company can be answerable after all. It cost one man years, and the answer was £15,000.
One of the two levers above has been quietly narrowed. The Data (Use and Access) Act 2025 brought most of its data protection provisions into force on 5 February 2026, with a further tranche in June, and it moved in one direction. It named a short list of "recognised legitimate interests", mostly public-interest purposes such as crime prevention and safeguarding, that a controller can rely on without weighing your interests against its own. It set out categories of further processing that are treated as compatible with the purpose data was first collected for. And it capped subject access: the search need only be "reasonable and proportionate", which is the organisation's judgement of proportionate, not yours. That last provision is deemed to have been in force since 1 January 2024, eighteen months before the Act was passed. Every subject access request sent in 2024 was retrospectively governed by a standard that did not exist when it was sent.
Meanwhile the ICO's flagship attempt to discipline the data broking industry ended in defeat. Its 2020 enforcement notice against Experian was cut down by the First-tier Tribunal in February 2023, and on 22 April 2024 the Upper Tribunal dismissed the Commissioner's appeal on all five grounds. The ICO announced a month later that it would not appeal further. The tribunals did find that Experian had breached its transparency duty, and rejected the argument that cost alone excuses notifying people. But they declined to order retrospective notification of the 5.3 million people affected, and imposed no penalty.
Britain also has no register of data brokers and no single deletion route. California has both: a public registry, and a Delete Request and Opt-Out Platform live since January 2026, through which one request reaches every registered broker. From August 2026 those brokers must check it every 45 days or pay $200 per request per day. A British resident wanting the same outcome must first work out which companies hold your data, from no public list, and then write to each one.
Four of the cases in that register are worth more than a row, because each one tests a different thing you probably believe.
XY Magazine, 2010. The only case where somebody fought for the people in the file. XY was a magazine for gay teenagers, posted out in opaque black shrink wrap to about 100,000 subscribers, many of them closeted and living with their parents. Its website held between 500,000 and a million more profiles. When the founder went bankrupt, creditors wanted the list. The Federal Trade Commission's consumer protection director wrote to them directly, pointing out that XY had told subscribers their information would not be given to anybody, and that selling it would be a deceptive practice. The matter ended in a consent order, approved by Judge Michael Kaplan on 3 August 2010, requiring permanent destruction of every subscriber record. Paragraph 4 of that order is the most careful piece of drafting in this entire register. It let the publisher keep customers' last names and the titles of the back issues they had ordered, roughly 400 unfulfilled orders from 2008 and 2009, purely so he could verify who they were if they got in touch. It expressly forbade him from using any of it to contact or locate anyone.
Borders, 2011. What a working safeguard actually delivers. This is the only case in the register where every part of the machine was present at once. An ombudsman was appointed, Michael St Patrick Baxter of Covington & Burling. He recommended opt-in consent, meaning nothing transfers unless you say yes. Judge Martin Glenn overruled him and ordered opt-out, meaning everything transfers unless you say no, inside a fifteen-day window, with notice in USA Today. The estate then sent the notice email over a weekend against a 15 October deadline, so if you had ever shopped at Borders you had eleven days to find it, read it and act. Records for nearly 48 million customers went to Barnes & Noble inside a $13.9 million package. That is the best outcome the register contains.
ConnectEDU, 2014. What happens when people are told. Around 20 million student records, grades and disability accommodations included, went into an estate. The FTC asked for an ombudsman and did not get one, on the reported ground that the company had no employees left to run the process. Judge Shelley Chapman ordered that students be told and given a chance to delete. The acquirers sent that notice, after the sale had completed. Of the students one buyer notified, fewer than one in a hundred asked for their records to be destroyed.
23andMe, 2025. The file the ombudsman said was the most sensitive he had seen. Fifteen million people's genetic code entered a bankruptcy estate. This time every part of the office engaged. Professor Neil Richards was appointed ombudsman and reported that the collection was "one of the most, if not the most, sensitive collections of data about identified people ever sought to be discharged in bankruptcy". He recommended separate, affirmative consent before any sale. Regeneron won the first auction at $256 million. More than two dozen states sued, the auction was reopened, and that deal was never completed. A second auction went at $305 million to a non-profit founded by Anne Wojcicki, who had run the company. The judge approving it observed that the structure "involves a sale of customer data only in a technical sense", because the data stayed under the same policies and the same management. By the time he said it, roughly two million customers had already asked for deletion, a wave that began with the company's 2023 data breach and did not stop.
Put the last two side by side, because they are the only place in this piece where the argument is tested against what people actually do. At ConnectEDU, told their records had been sold, fewer than one per cent acted. At 23andMe, roughly one in eight did. The law was the same. The difference is whether you think the file is you.
The best outcome in twenty-six years was a fifteen-day window, and the letter arrived on a Saturday.
The most useful case in the register is the one where a regulator decided the data was worth nothing. In 2018 the European Commission examined whether owning Shazam's music-recognition data would let Apple squeeze rivals, and concluded it would not: competitors could obtain equivalent signals elsewhere, so acquiring it conferred no real power. Hold that against everything else here. Data is not automatically valuable, most of it is replaceable, and a regulator that looked properly said so. What makes the Spirit archive different is not that it is data. It is that the only copy of what you did there is the copy that just sold.
Your instinct on reading about the Spirit sale is that a rule was broken. No rule was broken. Every actor behaved correctly.
The estate had a duty to realise value for creditors, and it realised value. The buyer bought a lawfully marketed asset under a court-supervised process and agreed to de-identification terms it was not required to agree to. The court applied a statute that does what it says. The union filed the objection open to it. The privacy office that exists was not triggered, because the material being sold was never the material it was written to protect.
And notice who was in the room. Seventeen thousand people lost their jobs when Spirit stopped flying. The lot holds 175,658 personnel records reaching back to 1986, and the filings do not say whether that is a count of people or of files, so the honest position is that the population inside the archive is somewhere between seventeen thousand and something much larger. Not one of them was a party to the sale, and neither, until the moment of the bid, was the buyer. The archive changed hands between two parties who had no part in making it: an estate that no longer employed the authors, and a company that never had.
The gap is not a failure of enforcement. It is a definition. American bankruptcy law protects information you handed over as a customer, because in 2000 a toy shop broke a promise to parents. It has nothing to say about information you generated as a worker, because nobody in 2005 imagined that the residue of a job could be worth more than the customer list. British law has no such office at all, and arrives at the same place by a different road: your employer holds your working life without owning it, you hold rights over it without title to it, and nobody has ever successfully used those rights to stop a transfer.
The asymmetry is not about value. It is about promises. A customer list is protected, where it is protected at all, because at some point somebody wrote a sentence to a customer about what would happen to it. The work record was never protected because nobody has ever written that sentence to a worker. Twenty-six years of case law turn on a promise, and employees have never been on the receiving end of one.
What has changed is who is buying. The record of people doing the work is the one input that cannot be scraped and cannot yet be convincingly invented, and it reaches the open market at exactly one moment: when the organisation that generated it stops existing.
There is a version of this that reads as a scandal. It is not one. It is something more durable than a scandal, which is a market discovering a supply.
Nobody owns what you wrote at work. That has never once stopped it being sold.
You’ve looked beneath the surface.
Both investigate who controls the infrastructure or information that other people depend on.
Both examine how a familiar relationship can create an ownership claim that is easy to miss.
A connection through “Who really owns it?”: Follow the ownership and control behind infrastructure, money, and information.
From the foundations of AI to the ownership of information.