Skip to content

Software companies

Is it legal for a shut-down startup to sell employee Slack messages?

By SourceX Editorial · Reviewed by Noah Loul ·

Short answer

Whether a shut-down startup can legally sell or license employee Slack messages turns less on ownership than on notice, policy and privacy law. The workspace usually belongs to the company, but personal details, direct messages and what employees were told still constrain reuse, so most deals exclude direct messages and de-identify work channels after counsel review.

Key takeaways

  • Company ownership of a Slack workspace does not by itself settle whether employee messages can be licensed.
  • Handbooks, privacy notices, the Slack agreement and privacy laws that may apply all shape the answer.
  • Direct messages and personal channels are usually excluded; work channels may qualify after de-identification.
  • Automated detection tools miss things in chat text, so human review stays part of preparation.
  • A shutdown does not erase obligations to the employees, customers and partners whose words appear in the archive.

Who owns Slack messages written by employees?#

Slack messages written by employees on a company workspace are usually treated as company records, created on company systems as part of the job. Employment agreements, IP assignment terms and acceptable use policies often say so directly.

Ownership of the records is not the end of the analysis. The same messages contain personal information about employees, customers and third parties, and the law treats that information differently from the company's code or documents. A company can own an archive and still be limited in what it does with the people inside it.

Which rules may apply to licensing employee messages?#

Several layers of rules may apply to licensing employee Slack messages, and they are assessed deal by deal with counsel. Each layer can narrow the scope on its own.

No single row decides the question. A permissive handbook does not cure a privacy notice that promised narrower use, and a narrow notice may block reuse even where the company plainly owns the records.

Which rules may apply to licensing employee messages?
SourceWhat it can affectWhat to check
Employee handbook and acceptable use policyWhether staff were told work messages belong to the company and may be reviewedExact wording on monitoring, ownership and secondary use
Privacy notices to employeesWhich purposes were disclosed for personal informationWhether sharing with third parties or AI training was covered
State privacy lawsRights some employees may have over their personal information; California's law reaches employee data, while several other state laws have exempted employment-context dataWhere employees lived and worked, whether any law's thresholds were met, and whether each statute covers employees
GDPR and similar lawsMessages from staff or contractors based outside the USLawful basis, purpose limits and transfer rules
Slack customer agreementHow workspace data may be exported and usedExport and use terms for your plan
Customer and partner NDAsConfidential information discussed in channelsWhether confidentiality survives the shutdown
Attorney-client privilegeChannels or threads involving counselExclusion before any outside review

Why is de-identifying chat text harder than it looks?#

De-identifying Slack text is harder than removing names because chat is informal, contextual and full of indirect identifiers. People use nicknames, refer to a colleague's leave, mention a child's illness, or describe a manager's reaction in ways only insiders could decode.

Detection software narrows the review; it does not complete it. Presidio, an open-source SDK for finding and anonymizing PII, is candid about this in its own documentation: automated detection cannot promise to catch every sensitive item, so other safeguards belong alongside it. That is why human review of samples stays in any serious preparation plan.

Pseudonymization, which swaps names for consistent tokens, keeps threads readable but can leave people identifiable to anyone who knew the team. Whether that is enough depends on the law that may apply, on who will see the data, and on what else the licensee could combine it with.

  • Nicknames, initials and handles that differ from legal names.
  • References to life events such as medical leave, family news or relocation.
  • Compensation, performance and disciplinary discussions.
  • Customer names inside pasted emails, screenshots or logs.
  • Small-team context that points to one person even after names are removed.

Why public scrutiny raises the stakes#

Public scrutiny raises the stakes because reporting on shut-down startups selling workspace archives has drawn criticism from privacy advocates, including doubts about whether chat text can be meaningfully anonymized. In an April 2026 Forbes report, Marc Rotenberg of the Center for AI and Digital Policy called the privacy issues from selling anonymized workplace messages substantial, given how heavily employees rely on tools like Slack. Former employees, customers and journalists can all read about a deal after it closes.

That makes the defensible deal the narrow one: limited channels, documented notices, de-identified content and a clear record of who authorized the release. A broad archive sale may be hard to explain even where counsel finds a legal path, and the founders' names stay attached to it.

Reputational review belongs in the same meeting as legal review. A useful test is whether the founders would be comfortable explaining the scope, the notice and the de-identification method to a former colleague who asked about it directly.

Checklist before any Slack archive is offered#

Before any Slack archive is offered to a licensee, the company or its wind-down officer should work through these checks with counsel and keep a written record of each answer.

The checklist is deliberately conservative. Each exclusion can be revisited if counsel finds a basis for it, but nothing can be recalled once delivered.

  • Confirm who has authority to act for the company after shutdown.
  • Collect every version of the handbook, acceptable use policy and employee privacy notice in force while messages were written.
  • Read the Slack customer agreement for export and use terms.
  • Exclude direct messages, group messages and personal channels by default.
  • Exclude shared channels with customers, vendors or partners.
  • Exclude HR, legal, finance and board channels.
  • Identify staff and contractors outside the US and the laws that may apply to them.
  • Decide whether and how to notify former employees.
  • Run automated detection, then human review of samples.
  • Document the scope, the reasoning and the approval in writing.

Illustrative: a closed analytics startup narrows its archive#

Illustrative: a fictional B2B analytics startup has shut down, and its wind-down officer receives an inquiry about the full Slack workspace. Counsel reviews the handbook, which says work communications belong to the company, and the employee privacy notice, which lists only operating purposes.

The officer declines to offer the full workspace. The scope that remains covers engineering and incident channels, where threads reference Jira issues and pull requests. Direct messages, the people-team channel and a shared channel with a design agency are excluded.

Former employees receive a short notice describing the scope and the de-identification approach. After automated detection and human review of samples, the officer approves a narrow license of engineering discussions tied to engineering records, and nothing else.

How SourceX approaches employee communications#

SourceX treats employee communications as the most sensitive record family in a software archive. In the Rights step of the SourceX five-step transaction, notices, policies and signing authority are reviewed before scope is set, and direct messages are typically excluded.

Where work channels proceed, Preparation removes personal and confidential details, and the SourceX Evidence Packet records the privacy record and release authorization. SourceX can decline communications that the company's notices and policies do not support.

Frequently asked questions

Does anonymizing the messages make the sale legal?

Not automatically. De-identification reduces risk but does not cure a notice that promised narrower use, and chat text often keeps indirect identifiers. Some laws define de-identified data with conditions beyond removing names. Counsel should assess the method and the result, not just the intent.

Can former employees object to their messages being licensed?

They may have rights under privacy laws that apply to them, and they can raise concerns publicly regardless. Clear notice of the scope, exclusion of personal channels and a documented de-identification method reduce both legal and reputational exposure.

What about contractors and customers who posted in the workspace?

Their messages need separate treatment. Contractors may not be covered by the employee handbook, and customers in shared channels belong to another organization. Most companies exclude shared channels entirely and review contractor-heavy channels before including any of them.

Is the answer different in a bankruptcy or an assignment for the benefit of creditors?

The person with authority changes, and a court or assignee may oversee asset sales, but privacy obligations generally travel with the records. In a US bankruptcy, Section 363(b)(1) of the Bankruptcy Code may restrict selling personally identifiable information where the debtor's disclosed privacy policy prohibited such transfers, unless the sale is consistent with the policy or a court approves it after a consumer privacy ombudsman is appointed. The trustee's or assignee's counsel should assess whether and how that applies.

Can investor approval stand in for employee notice?

No. Investors may need to consent to asset dispositions, but their consent does not replace employee notice or privacy obligations. Board or officer approval covers corporate authority; it does not answer what employees were promised about their messages.

Does the Slack plan the company used matter?

It can. Plans differ in what owners can export and in whether admins could ever reach direct messages. If employees were told their direct messages were private and the plan's export did not cover them, reaching into them now would contradict both. Check the plan's export scope against what staff were told.

Sources

  • Presidio's documentation warns that because it uses automated detection mechanisms there is no guarantee it will find all sensitive information, and additional systems and protections should be employed. Source
  • Marc Rotenberg of the Center for AI and Digital Policy told Forbes that the privacy issues from selling anonymized workplace messages are substantial, noting how heavily employees rely on internal tools like Slack. Source
  • Other comprehensive state privacy laws then enacted (Colorado, Connecticut, Utah and Virginia) do not apply to employment-context data, making California the first state to apply comprehensive restrictions to employee information. Source
  • Under 11 U.S.C. 363(b)(1), if a debtor disclosed a policy prohibiting transfer of personally identifiable information, the trustee may not sell it unless consistent with the policy or approved by the court after appointment of a consumer privacy ombudsman. Source

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify