StackLégal

Collaboration

GDPR Slack

In an indie stack, Slack is used for Team messaging. Entity cited: Slack Technologies, LLC for workspaces in the United States and Canada; Slack Technologies Limited for workspaces outside the United States and Canada. The sections repeat what the vendor publishes, without filling a gap. Last update of the facts: October 4, 2026. Verified on October 4, 2026.

Translation of the French sheet. The facts do not change. The date is the date the official pages were read.

DPA Slack

Yes. Data Processing Addendum that supplements the customer terms.

Read the DPA

Stated role

The customer is the controller of Customer Data. Slack is the processor of Customer Data and the controller of Other Information.

Personal data

Messages, files, and other customer content, workspace and account information, usage information, device type, system, settings, and device identifiers, cookie information, contact details, profile, IP address.

Sub-processors of Slack

Public list.

List published by the vendor

Transfers outside the EU

Hosting / location

The services operate globally. Transfers outside the EEA are indicated, including to Australia, Canada, Japan, India, South Korea, and the United States. Customers may be able to choose a processing region.

EU–United States Data Privacy Framework

Salesforce is registered, EU-U.S. Data Privacy Framework status: Active. Slack Technologies, LLC is listed as a covered entity.

Data Privacy Framework sheet

Cookies

First-party session and persistent cookies, third-party cookies including Google Analytics, pixels, and web beacons, for login, preferences, analytics, and security.

Typical use, written by StackLégal and not by the vendor: Team messaging.

History

Last update: October 4, 2026.

  1. First publication. The facts come from the official pages cited in the sources. Anything not stated there remains "not disclosed".

Clause to paste

Place it in the sub-processor section of your privacy policy. Review it: a “not disclosed” field must be completed before publication.

Sub-processor clause

Add this vendor to your free sub-processors widget

Sources

Verified on October 4, 2026.

Frequently asked questions

Is Slack a processor within the meaning of the GDPR?

The customer is the controller of Customer Data. Slack is the processor of Customer Data and the controller of Other Information.

What DPA does Slack publish?

Yes. Data Processing Addendum that supplements the customer terms. https://slack.com/terms-of-service/data-processing

Which further sub-processors does Slack publish?

Public list. https://slack.com/slack-subprocessors

Where does Slack state that it processes data, including outside the EU?

The services operate globally. Transfers outside the EEA are indicated, including to Australia, Canada, Japan, India, South Korea, and the United States. Customers may be able to choose a processing region.

Is Slack registered under the EU–United States Data Privacy Framework?

Salesforce is registered, EU-U.S. Data Privacy Framework status: Active. Slack Technologies, LLC is listed as a covered entity. https://www.dataprivacyframework.gov/participant/5959

Which personal data does Slack mention?

Messages, files, and other customer content, workspace and account information, usage information, device type, system, settings, and device identifiers, cookie information, contact details, profile, IP address.

Often in the same stack

These sheets come up in searches for a Next.js SaaS. Next.js itself is not a processor: GDPR Next.js.

Related tools

All the sheets collaboration

Full pack, from 39 € incl. VAT

The clause above covers only one tool. StackLégal generates the legal notices, terms of use, terms of sale, privacy policy, Article 28 DPA, and the public list, naming only the boxes that are checked. One-time payment via Gumroad. This is not legal advice.