Skip to content

Wind-downs and transitions

Do former employees have to consent before a closed company licenses their messages?

By SourceX Editorial · Reviewed by Noah Loul ·

Short answer

Former employees usually do not have to consent as owners, because the company generally owns messages written on its systems, but notice or consent may still be needed for the personal information inside them. Separate three questions: who owns the records, what privacy laws and staff notices allow, and what third parties shared in confidence.

Key takeaways

  • Ownership, personal data and third-party confidentiality are separate questions with separate answers.
  • Company ownership of workplace messages does not by itself permit every use of the personal information inside them.
  • What the handbook, IT policy and privacy notice told staff shapes what a closed company can do now.
  • Direct messages, HR channels and legal threads raise all three questions at once and are usually excluded.
  • Notice or consent can be a sound choice even where counsel concludes it is not required.

Question one: who owns the messages?#

Ownership of workplace messages usually sits with the company, because the messages were created on company systems, in the course of work, under employment agreements and IT policies. Former employees typically have no property claim to them.

Ownership answers less than founders hope. Owning a Slack workspace means the company controls the records; it does not settle whether a new use of the personal information inside them is allowed. That is why the next two questions carry most of the weight.

Pull the documents that support ownership: employment agreements and invention assignments, the IT or acceptable use policy, and the service terms for the chat and email tools. Contractors need their own check, because their agreements may differ from the employee templates.

Question two: what about personal data in the messages?#

Personal data in workplace messages includes names, handles and contact details, but also what people wrote about themselves: health, family, performance and opinions about colleagues. Whether licensing that information needs notice or consent depends on which laws may apply and what employees were told.

In the United States, some state privacy laws, such as California's CCPA, may apply to employee personal information. For staff in the EU or UK, GDPR may apply, with its own rules on purpose and legal basis. What the employee privacy notice and handbook said about monitoring and use of communications also matters, and each of these is assessed deal by deal with counsel.

Preparation changes the picture. Replacing names and identifiers with consistent placeholders and removing personal disclosures reduces how much personal information remains. In small teams, though, people may still be recognizable from roles and context, so de-identification needs human review, not just a tool run.

Question three: what did others share in confidence?#

Third-party confidentiality covers what customers, partners, candidates and advisors shared with the company under contracts, NDAs or privilege. Former employees cannot waive it and are not the ones who would consent to it, but it can block a license just as firmly as a privacy problem.

Look for customer details pasted into support or engineering channels, Slack Connect channels shared with other companies, candidate information in recruiting channels, and conversations with lawyers. Attorney-client privilege belongs to the company, and licensing privileged material risks waiving it, so legal threads are typically excluded outright.

How the three questions apply to common message types#

The three questions apply differently to each message type, which is why decisions are made channel by channel rather than for a workspace as a whole. The table shows the usual pattern; a specific company's documents can move any row.

How the three questions apply to common message types
Message typeOwnershipPersonal dataThird-party confidentialityTypical handling
Public engineering channelsCompanyLow once names are replacedPasted customer data possibleCandidate for license after review
Incident and on-call channelsCompanyLow to moderateCustomer identifiers often presentCandidate after redaction
Direct messagesCompanyHigh and personalVariesUsually excluded
HR, people and recruiting channelsCompanyHigh, often sensitiveCandidate informationExcluded
Customer escalation threadsCompanyModerateContract terms usually applyExcluded unless contracts allow
Legal threadsCompanyModeratePrivilege at stakeExcluded

Notice or consent makes sense even when counsel concludes it is not legally required, because former employees can recognize their own words and founders still have reputations to keep. A short notice also gives people a way to raise concerns before records leave the company.

Reaching former staff is the practical hurdle. Last known personal email addresses from payroll or the HR system usually work for recent departures; older ones may need a public notice or may justify excluding their messages entirely.

  • Notice with an opt-out: tell former staff which record families are in scope and how personal details are removed, and exclude messages written by anyone who objects.
  • Targeted consent: ask named individuals whose material is central and hard to de-identify, such as long design threads by a small team.
  • Exclusion: leave out channels where notice is impractical and the content is personal.
  • Documentation: record what was sent, to whom and how each response was handled.

Who makes the call after an ABC or a bankruptcy filing?#

After an assignment for the benefit of creditors or a bankruptcy filing, the assignee or trustee makes the call on employee messages, not the former founders. The three questions stay the same, but the decision-maker now acts as a fiduciary for creditors and answers to them, and in bankruptcy often to the court.

That shift tends to make decision-makers more cautious with employee communications. An assignee or trustee usually lacks the context to judge which threads are sensitive, so a clear record of what the handbook, IT policy and privacy notice said, and which channels the founders already flagged for exclusion, saves time and reduces the chance of an objection.

If the company is heading toward either process, document the three-question analysis before the handover. A short memo with the channel list, the governing documents and the recommended exclusions gives the successor a starting point instead of a blank workspace.

Illustrative: a fictional developer tools company, once home to more than fifty employees, closes, and its outside counsel acts as wind-down counsel. The board wants to know whether engineering Slack channels can be licensed without asking every former employee for consent.

Ownership is clear from the IT policy and offer letters. The employee privacy notice described monitoring for security but said nothing about other uses, and two former engineers now live in Germany, where GDPR may apply. Counsel also flags a long-running design channel with only three active members: replacing their names would not stop them, or colleagues, from recognizing the threads.

Counsel recommends notice with an opt-out for everyone in scope, targeted consent from the three design-channel members, and exclusion of messages from contractors supplied through an agency whose agreement had different terms. Notices go to last known personal email addresses from payroll. One designer declines, so the design channel is dropped; two other people opt out and their messages are removed before preparation finishes. The board approves the remaining scope with the record of the process.

How SourceX approaches employee communications#

SourceX approaches employee communications as a high-sensitivity record family within the SourceX five-step transaction. The Rights step addresses ownership and third-party terms, and the Preparation step removes personal and confidential details before anything leaves the supplier.

The SourceX Evidence Packet records the privacy record, including any notice or consent process, and the release authorization. The supplier, guided by its own counsel, decides the scope and can exclude any channel at any step.

Frequently asked questions

Can a former employee demand deletion of their messages?

It depends on where the person lives, which laws may apply and what records are involved. Some privacy laws give individuals deletion or objection rights that can reach employee data, with exceptions. Route any request through counsel and record the outcome, even while the company is closing.

Does a handbook clause allowing monitoring cover licensing?

Not necessarily. A clause saying the company may monitor or access communications for security or compliance describes one purpose. Licensing for model training is a different use, so counsel should read the clause, the privacy notice and the applicable law together before relying on it.

Are contractors treated the same as employees?

Not always. Contractor agreements may not include the same IT policies or notices, and some contractors were employed by an agency. Check each agreement for confidentiality, ownership and notice terms, and treat contractor messages as their own category in the review.

If messages are de-identified, is consent still needed?

Sometimes not, but the de-identification has to be real. Replacing names may not be enough when a small team's roles, projects and writing style make people recognizable. Counsel weighs how identifiable the prepared records remain and which laws may apply.

Does it matter that the company has closed?

The obligations generally continue while the entity winds up. Closing changes practical things, such as who has authority and whether former staff can be reached, but it does not erase privacy notices, contracts or legal duties attached to the records.

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify