

Slack
Based exclusively on public evidence • 20 criteria (Privacy + AI)
Last review: 13 Feb 2026

AI Trust Summary
Safer Alternatives
Higher-rated software in the same category
Attention Points in AI (2)
AI criteria that require attention. Buy the Premium Analysis to see all 2 criteria.
AI data retention (prompts and responses) is not disclosed
AI decision contestation mechanism not available
Source: vendor public documents
Compliances in AI (3)
AI criteria the company meets. Buy the Premium Analysis to see all 3 criteria.
Policy on data use for AI training clearly stated
AI training opt-out control available
Use of artificial intelligence clearly disclosed in policies
Source: vendor public documents
Highlights in Privacy (3)
Most relevant criteria for this category. Buy the Premium Analysis to see all 3 criteria.
Sensitive data processing without additional documented safeguards
Data controller and processor roles clearly defined
Data controller identity and contact clearly disclosed
Source: vendor public documents
Conformance analysis (20)
AI data retention (prompts and responses) is not disclosed
Reference: ISO/IEC 42001 (8.2) + ISO/IEC 27701 (7.4.6)
Policy on data use for AI training clearly stated
Reference: ISO/IEC 42001 (8.2) + ISO/IEC 23894 + EU AI Act
AI training opt-out control available
Reference: ISO/IEC 42001 (8.3) + ISO/IEC 29100 + EU AI Act
Source: vendor public documents
Follow this company and access all 20 criteria
Track score changes, get alerts on policy updates, and view the full conformance analysis
Don't miss any update
Sign up to follow this company and track changes in privacy and AI scores
Why trust the AITS Index: Open Community Audit
Public transparency, peer review and open evidence trails — all verifiable by the community
Trust guarantees
Peer review
users, professionals and experts confirm or contest items online.
Public history
vendor and index changes are versioned and accessible.
Participate
Evidence, confirmations and contestations
participate in the collaborative validation of AITS criteria
Understanding Slack's Privacy and AI Governance: Strengths and Weaknesses
Clear Data Processing Purposes
Slack excels in transparency regarding the purposes of data processing. Each category of data has clearly defined objectives, which means users can understand how their information is being utilized. This clarity is essential for compliance with regulations like the GDPR and LGPD, as it empowers users to make informed decisions about their data. With an AITS Privacy Score of 86%, Slack demonstrates a strong commitment to user privacy, ensuring that individuals are aware of how their data contributes to the platform's functionality.
Defined Roles of Data Controller and Processor
Another strength of Slack is its clear delineation of roles between data controllers and processors. This is crucial for users, as it establishes accountability and responsibility for data handling. Knowing who is responsible for what can help users feel more secure about their data. This clarity supports compliance with ISO 27701 standards, which emphasize the importance of governance in data management. Users can trust that Slack has a structured approach to data governance, enhancing their confidence in the platform.
Undefined Retention Periods for AI Messages
Despite its strengths, Slack does have notable weaknesses. One significant concern is the undefined retention periods for AI-generated messages and calls. Without clear guidelines on how long this data is stored, users may face uncertainty regarding their privacy. This lack of specificity can be problematic, especially for organizations that must comply with strict data retention policies under GDPR and LGPD. Users should regularly review their data retention settings and consider implementing internal policies to manage data lifecycle effectively.
Absence of Contestation Mechanism for AI Decisions
Another weakness is the absence of a documented mechanism for contesting automated decisions made by AI. This limitation can hinder users' ability to challenge or seek clarification on AI-generated outcomes, which is particularly concerning for those relying on AI for critical business decisions. Users should be aware of this gap and consider supplementing their use of Slack with additional tools or processes that allow for human oversight of AI-generated decisions, ensuring that they maintain control over important outcomes.
Lack of Safeguards for Sensitive Data Processing
Slack also lacks documented safeguards for the processing of sensitive data. This is a critical area for users, especially those in industries that handle personal or sensitive information. The absence of additional protections can expose users to risks, including potential data breaches or non-compliance with privacy regulations. Users should take proactive measures by limiting the sharing of sensitive information on the platform and regularly auditing their data sharing practices to ensure compliance with relevant laws.
Practical Guidance for Users
To mitigate the risks associated with Slack's weaknesses, users should take several practical steps. First, regularly review the platform's privacy settings and ensure that only necessary data is shared. Enable features that enhance data security, such as two-factor authentication and message encryption. Additionally, consider establishing internal policies for data retention and processing, particularly for sensitive information. By being proactive and informed, users can better navigate the complexities of data privacy and governance while using Slack.
Other Communication and Collaboration software
Dive into in-depth research and analysis of each player
Source: vendor public documents
Related articles about Slack
Analyzed Sources
Public documents used in the audit of Slack:
Evidence, confirmations and contestations
participate in the collaborative validation of AITS criteria
Scope & Limitations
TrustThis/AITS assessments are based exclusively on publicly available information, duly cited with date and URL, following the AITS methodology (privacy & AI transparency).
The content is indicative in nature, intended for screening and comparison, not replacing internal audits.
TrustThis/AITS does not perform invasive tests, does not access vendor technology environments and does not process customer personal data. Conclusions reflect only the vendor's public communication at the date of collection.
Source: vendor public documents







