728 words, 42 clausesno date on the pageread 25/09/2026source
·Do you need help finding the information that you need to complete your security or privacy questionnaire? We've organised our compliance resources so that you can demonstrate Slack's ability to meet your organisation's requirements.
·ISO/IEC 27001
·Information Security Management System (ISMS) ISO/IEC 27017
·Security Controls for the Provision and Use of Cloud Services ISO/IEC 27018
·Protection of Personally Identifiable Information (PII) ISO/IEC 27701
·Privacy information management system (PIMS) ISO/IEC 42001
·Information technology - Artificial intelligence - Management system SOC 2 (Type II)Trust Services Principles SOC 3 Service organisation controls GovSlack SOC 2 (Type II)Trust Services Principles GovSlack SOC 3 Service organisation control Global PRP Certification*
·Global privacy recognition for processors minimum requirements Global CBPR Certification*
·Global cross-border privacy rules minimum requirements CSA Cloud Security Alliance
·Health Insurance Portability and Accountability Act (HIPAA)
·Slack can be configured for HIPAA compliance, including electronically protected health information (e-PHI). Request requirements for HIPAA entities
·Financial Industry Regulatory Authority (FINRA)
·Slack is FINRA 17a-4 configurable so your team can collaborate and still meet your compliance requirements.
·Federal Risk and Authorization Management Program (FedRAMP)
·Slack is FedRAMP Moderate authorised to meet the compliance needs of organisations in the public sector with an Enterprise or Enterprise+ Slack subscription and properly configured in accordance with the Secure Configuration Guide.
·GovSlack is FedRAMP JAB High authorised and is also pursing DoD CC SRG IL4 compliance. View our Moderate authorisation View our JAB High authorisation
·Federal Education Rights and Privacy Act (FERPA)
·Slack supports its educational customers and their unique compliance responsibilities. View our policy
·Trusted Information Security Assessment Exchange
·Scope-ID SHYV0T Assessment-ID AMHN37 TISAX and TISAX results are not intended for the general public. Request our results
·Information Security Registered Assessors Program (IRAP)
·Slack has been assessed by an independent IRAP assessor against the requirements of the Australian Information Security Manual (ISM). Customers can contact their Slack account team to request a copy of our IRAP report. IRAP assessment letter
·Information System Security Management and Assessment Program (ISMAP)
·Slack was assessed for the Information System Security Management and Assessment Program (ISMAP), a Japanese government programme evaluating the security posture of cloud service providers. Slack's registration can be viewed on the ISMAP list of registered services. View our registration
·Cloud Computing Compliance Criteria Catalogue (C5)
·Slack completed its attestation for the Cloud Computing Compliance Criteria Catalogue (C5), a standard created by the Federal Office for Information Security (BSI) in Germany. Customers can contact their Slack account team to request a copy of the C5 report.
·South Korea Cloud Service Providers (CSP) Safety Assessment
·Slack completed its evaluation for the Cloud Service Providers (CSP) Safety Assessment, a programme performed by the Korean Financial Security Institute (K-FSI) to ensure that CSPs comply with a defined set of cybersecurity standards managed by the Regulation on Supervision of Electronic Financial Transactions (RSEFT) programme. Request our results
·Spain Esquema Nacional de Seguridad (ENS)
·The ENS (Esquema Nacional de Seguridad) is a set of security controls and standards that are required to be implemented by service providers to allow the processing of data for Spanish public services (such as governments and public organisations). Slack has achieved ENS High, which is the highest achievable level of accreditation possible. View our certificate
·We are committed to helping our customers and users to understand and, where applicable, comply with the General Data Protection Regulation (GDPR). For more information, please see our commitment page.
·The GDPR does not require EU data to reside in the European Union. Slack's Data processing agreement and the EU Model Clauses will continue to ensure compliance for EU personal data transfers outside of the EU.
·We're committed to helping Slack customers and users to understand and exercise their rights under the California Consumer Privacy Act (CCPA). On this page, we clarify Slack's role and obligations under the CCPA and provide additional information to help our customers to meet their compliance needs.
·Slack offers data processing addenda that supplement the customer terms of service or any MSA.
·This page provides important information about the identity, location and role of Slack Subprocessors.
·Slack's Modern Slavery Statement can be found here
·Yes, you can make this request using our Privacy and security form
·We do! Please see our Security white paper or visit our Security page for more information.