š ADULT: Trust/compliance/gdpr - HD Photos!
Slack's GDPR Commitment
Our Commitment to You and the Protection of Your Data
Weāre committed to helping Slack customers and users understand, and where applicable, comply with the General Data Protection Regulation (GDPR). The GDPR is the most comprehensive EU data privacy law in decades, and went into effect on May 25, 2018.
Besides strengthening and standardizing user data privacy across the EU nations, it introduces new or additional obligations on all organizations that handle EU citizensā personal data, regardless of where the organizations are located. On this page, we explain how we help our customers comply with the GDPR.
- GDPR Compliance
- Security Infrastructure Standards and Certifications
- International Data Transfers
- Updates
GDPR Compliance
The GDPRās updated requirements are significant and our global team has adapted Slackās product offerings, operations and contractual commitments to help our customer comply with the regulation. Measures Slack (who processes data on our customerās behalf) has implemented include:
- Investments in our security infrastructure and certifications
- Updates to relevant contractual terms
- Support for international data transfers by executing Standard Contractual Clauses through our updated Data Processing Addendum, which is available to all customers regardless of the Slack plan they are using.
- Offering data portability and data management tools including:
- Import and export tools. Businesses and organizations may access, import, and export their Customer Data using Slackās tools.
- Profile deletion tool. Help customers respond to user requests to delete personal information, such as names and email addresses, from a Slack account.
- Workspace settings center. See your workspaceās plan and settings, or contact an admin who controls the workspace.
- Data Residency for Slack. Data residency for Slack allows global teams to choose the region where certain types of data at rest are stored.
- Slack Enterprise Key Management. Complete control and visibility of access to your data in Slack using your own encryption keys.
We also monitor the guidance around GDPR compliance from privacy-related regulatory bodies, and update our product features and contractual commitments accordingly. Weāll provide you with regular updates so that youāre always current.
Our Security Infrastructure and Certifications
Protecting our customersā information and their usersā privacy is extremely important to us. As a cloud-based company entrusted with some of our customersā most valuable data, weāve set high standards for security. Weāve received several security certifications from the American Institute of Certified Public Accountants such as SOC 2 and SOC 3. Slack has received internationally recognized security certifications for ISO 27001 (information security management system), ISO 27017 (security controls for the provision and use of cloud services) and ISO 27018 (for protecting personal data in the cloud).
Slack has invested heavily in building a robust security team, one that can handle a variety of issues ā everything from threat detection to building new tools. In accordance with GDPR requirements around security incident notifications, Slack will continue to meet its obligations and offer contractual assurances.
If youād like to learn more about Slackās security policies and procedures, please see our security page. It provides detailed information on how we approach security, and includes a white paper on how Slack ensures user data security in particular, including our technical and organizational measures(TOMs) as well as our encryption standards.
International Data Transfers
To comply with European Union data protection laws around international data transfer mechanisms, we offer European Union Model Clauses, also known as Standard Contractual Clauses, to meet adequacy and security requirements for our customers who operate in the European Union and the United Kingdom. A copy of our standard data processing addendum, incorporating Model Clauses, is available here.
Data transfers between Europe and the U.S. may also be covered by the EU-U.S. Data Privacy Framework. Through Salesforce, Slack participates in the EU-U.S. Data Privacy Framework (DPF), UK Extension to the EU-U.S. DPF, and Swiss-U.S. DPF, as detailed here. More information about the DPF can be found at https://www.dataprivacyframework.gov/Program-Overview
Updates
At Slack, we are committed to the security and privacy of your data. So weāre glad to comply and help you comply with the GDPR. If you have any questions about your rights under the GDPR as a user or how Slack can help you with compliance as a Customer, we hope youāll reach out to us at [email protected]. Please also visit our Trust Center to learn more about our privacy, security and compliance programs.



