8 Total
1 High severity
6 Medium severity
1 Low severity
Summary

Slack's Privacy Policy establishes the categories of personal information Slack collects during platform use, including messages, files, usage patterns, device information, and inferred location data. The policy designates workspace administrators—typically employed by the organization using Slack—as the primary controller of message content and account data for users within that organization, with Slack's data handling obligations running to the organization rather than individual users. California residents are afforded opt-out rights through mechanisms identified in Slack's website footer.

Technical / Legal Breakdown

This document is Slack's global Privacy Policy, governing the collection, use, and disclosure of personal data across Slack's services, with Slack Technologies, LLC (a Salesforce company) serving as the primary data controller for most users and Slack Technologies Limited acting as controller for users in the EEA, UK, and Switzerland. The policy states that Slack collects data across three categories: information users provide directly (name, email, payment info, content), information collected automatically (usage data, device identifiers, log files, cookies, location inferred from IP), and information from third parties (identity providers, connected apps, partners); the terms authorize use of this data for service operation, marketing, analytics, safety, and 'developing and improving' Slack's products. Notably, the policy draws a structural distinction between 'Customer Data' (content controlled by workspace administrators, including messages and files) and other personal data Slack controls directly, meaning individual users within an organization may have limited direct rights against Slack for their own message content, with those rights mediated through the employing or administering organization. The policy engages GDPR and UK GDPR (citing Standard Contractual Clauses and adequacy decisions for international transfers), CCPA/CPRA for California residents (with explicit opt-out rights for certain data uses and a 'Do Not Sell or Share My Personal Information' link), and references COPPA by stating the service is not directed at children under 13 (or 16 in certain jurisdictions). Compliance teams operating Slack in regulated industries (healthcare, financial services, education) should note that the policy's broad data use authorizations for 'improving services' and sharing with Salesforce affiliates may require evaluation under HIPAA, GLBA, and FERPA depending on the nature of Customer Data processed.

Institutional Analysis

Institutional analysis available with Professional

Regulatory exposure by statute, material risk assessment, vendor due diligence action items, and enforcement precedent. Available on Professional.

Start Professional free trial
High — 1 provision
Medium — 6 provisions
Low — 1 provision

Monitoring

Slack has updated this document before.

Watcher includes same-day alerts, structured change summaries, and monitoring for up to 10 platforms.

Start Watcher free trial Or create a free account →

Professional Governance Intelligence

Need provision-level monitoring and regulatory mapping?

Professional includes governance timelines, compliance memos, audit-ready analysis, and full provision tracking.

Start Professional free trial

Cross-platform context

See how other platforms handle AI and Machine Learning Data Use and similar clauses.

Compare across platforms →

Mapped Governance Frameworks

CCPA/CPRA
California, USA
View official text ↗
Connecticut Data Privacy Act Amendments
US-CT
View official text ↗
CAN-SPAM
United States Federal
View official text ↗
FTC Act Section 5
United States Federal
View official text ↗
GDPR
European Union
View official text ↗
Indiana Consumer Data Protection Act
US-IN
View official text ↗
Kentucky Consumer Data Protection Act
US-KY
View official text ↗
UK GDPR
United Kingdom
View official text ↗
Universal Opt-Out Mechanism Expansion 2026
US
View official text ↗
VPPA
United States Federal
View official text ↗
Archival ProvenanceSource & Archival Record
Last Captured April 19, 2026 06:14 UTC
Capture Method Automated scheduled archival capture
Document ID CA-D-000192
Version ID CA-V-000733
SHA-256 f92538879ef8296e9742fbbb953fb626cd5264e9e0ceefd980b0bcc326ae4051
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Hash verified

Governance Monitoring

Monitor governance changes across the platforms you rely on.

Structured alerts for policy changes, governance events, and provision updates across 318+ platforms.

Create free account Compare plans