Privacy and preparation
Slack DMs and private channels: include or exclude from a data export?
By SourceX Editorial · Reviewed by Noah Loul ·
Short answer
Slack DMs and private channels should be excluded from a data export by default. Employees use them with a stronger expectation of privacy, and they mix work with HR, legal and personal topics. A narrow inclusion can be defensible for work-only private channels, such as incident rooms, after channel-by-channel review, a policy check and counsel's sign-off.
Key takeaways
- Exclude direct messages and group DMs from any licensing dataset by default.
- Review private channels one by one; only work-only channels with a documented business purpose are candidates.
- Slack Connect channels involve another company's people and usually need that company's agreement or exclusion.
- Record the channel list, the reason for each inclusion and the workspace policy in force when the messages were written.
- What an admin can export depends on the Slack plan and workspace settings, so confirm scope before promising anything.
Why exclude DMs and private channels by default?#
DMs and private channels are excluded by default because they carry the highest expectation of privacy in a workspace and the densest mix of off-topic and sensitive content. Even in a disciplined engineering culture, direct messages include performance conversations, health and family matters, pay questions and candid remarks about customers.
Legal exposure compounds quickly. Messages with in-house or outside counsel can be privileged, HR channels can hold investigation notes, and employee notice, monitoring and privacy rules may apply differently from state to state. Unlike public channels, there is usually no shared understanding among employees that this content forms part of the company's working record.
Public channels, by contrast, are where much of the valuable work already happens: incident response, release coordination, support escalations and design discussion. Starting there gives a buyer the workflow without the private layer.
What is actually in each type of conversation?#
Each conversation type in Slack has a typical content profile, and that profile, more than the privacy setting, should drive the default. Use the table as a starting position, then adjust after reading samples from your own workspace.
Channel names are a weak guide. A channel called random may hold years of useful troubleshooting, while a team channel may drift into salary and hiring talk. Sample before deciding, and treat archived channels like active ones, since old channels often predate the current workspace policy.
| Conversation type | Typical content | Default for a licensing export |
|---|---|---|
| Public channels | Incidents, releases, support escalations, design threads | Candidates after review |
| Private project channels | Work on a customer account or an unreleased feature | Review one by one |
| Private leadership channels | Strategy, financing, personnel decisions | Exclude |
| Private HR, legal and finance channels | Investigations, privileged advice, compensation | Exclude |
| Group DMs | Ad hoc coordination mixed with personal chat | Exclude |
| One-to-one DMs | Personal and work topics intertwined | Exclude |
| Slack Connect channels | Conversations with customers or vendors | Exclude unless the other party agrees |
| Bot and alert channels | Monitoring alerts, deploy notices | Candidates; scan for secrets first |
When is a narrow inclusion of private channels defensible?#
A narrow inclusion is defensible when a private channel works as an ordinary work room that happens to be restricted, such as an incident channel kept private because it discusses a customer outage. The test is purpose and content, not the privacy flag.
Direct messages rarely pass this test. Even when a team used DMs for real work, the content is too mixed to separate reliably, and the expectation of privacy under which it was written is stronger. A private channel should meet every condition below before it is included.
- The channel has a documented business purpose and a named owner.
- A reviewer has read a sample and found no HR, legal, medical or personal threads, or those threads can be removed cleanly.
- The workspace policy in force at the time told employees that workspace content belongs to the company.
- Names and contact details will be replaced, and credentials scanned out.
- Counsel has reviewed notice and consent questions for the states where employees work.
- The channel owner or department head approves the inclusion in writing.
Who should decide, and what should be recorded?#
The general counsel or privacy lead should decide, with the CTO supplying the channel inventory and department heads confirming each channel's purpose. The decision belongs to the company that owns the workspace, and it should be made before any export runs.
Record the channel list by channel ID, the reason each included channel passed review, the version of the acceptable use or workspace policy, any employee notice given and who approved. A record like this answers later questions from a buyer, an employee or an acquirer without reconstructing the decision from memory.
How to run an export that matches the decision#
An export matches the decision when it is built from an approved channel list rather than from the whole workspace. Slack's plan rules shape what is possible: Owners and Admins on every plan can export public channel messages and file links as JSON, but exports that include private channels and DMs are offered only on Business+ and Enterprise plans, and Owners must apply to Slack to use them. Export by conversation type or member is listed only for Enterprise, so on other plans a full export may arrive before you can filter it.
Filter by channel ID, keep thread structure and timestamps, and decide separately about files: the export contains links to files rather than the files themselves, and attachments often carry more personal data than the messages around them. Replace user IDs with consistent placeholders across channels so a person who appears in several incident rooms keeps one label, and run a secrets scan before release.
Use the workspace's own admin export, not a third-party app pulling through the API: Slack's API terms bar outside app providers from bulk exporting message data or using it to train a large language model. If the export can only produce everything, filter it in a controlled environment and delete the unfiltered copy once the filtered one is verified. Note the deletion in the decision record.
Check retention settings and legal holds before exporting. Admins may have set custom deletion periods, which permanently remove older messages, so confirm how much history exists. Channels under a litigation hold or tied to an internal investigation are usually best excluded whatever their content, subject to counsel's advice, and the export job should not change retention settings in the workspace.
Illustrative: a fleet software company draws the line#
Illustrative: a fictional fleet telematics software company prepares engineering and support records for a licensing review. Its Slack workspace has public channels for releases and support escalations, a private incident channel for each customer outage, a leadership channel, an HR channel and years of DMs.
The privacy lead excludes all DMs, group DMs, the leadership channel and the HR channel without further review. The incident channels are sampled: most threads are pure troubleshooting, but some contain a customer's internal contact details and one includes a discussion of an engineer's medical leave.
The team includes the incident channels after removing those threads, replaces names with placeholders and excludes the Slack Connect channels shared with customers. The CTO exports only the approved channel IDs, and the approval file lists every included channel with the reason it passed.
How SourceX approaches chat records#
SourceX reviews chat records in the Rights step of the SourceX five-step transaction, before any preparation work, because whether a channel may be licensed comes before how to clean it. The fit check needs only a description of the workspace, the channel types and the years of history, not an export.
The SourceX Evidence Packet records permitted use, the channel scope and the privacy record for the final package. The supplier approves the channel list and the release authorization, and nothing outside that list is included.
Frequently asked questions
Do employees need to consent before Slack messages are licensed?
It depends on the laws in the states where employees work, your workspace policy and what employees were told. Some state privacy laws cover employee data, and other employment rules may apply. Treat this as a question for counsel, settled before export, rather than an assumption.
Does our acceptable use policy settle the question?
It helps but rarely settles it. A policy saying workspace content belongs to the company supports including public channels, but it may not mention licensing to third parties, and it does not change the sensitive content inside DMs. Read the version in force when the messages were written.
What about messages from former employees?
Former employees' messages in public and approved private channels are usually handled like current employees' messages: names replaced, content reviewed. Their DMs stay excluded. Check whether separation agreements include confidentiality terms that affect specific threads.
Can we include DMs if we anonymize them?
Replacing names does not change much here. DMs often describe health, family, pay or performance in ways that remain sensitive and can identify someone from context, and anonymizing does not change the expectation of privacy under which they were written. The safer course is to leave DMs out entirely.
Should Slack Connect channels be treated differently?
Yes. Those channels include another company's employees, and their messages may be covered by your contract with that company. Exclude them unless the other organization agrees in writing, and even then remove its people's identities.
Should bot and integration messages be included?
Often, after a check. Alert, deploy and ticket-sync channels show how systems and people interact during incidents, which is useful context. They also tend to carry hostnames, customer identifiers and occasionally credentials in payloads, so scan them for secrets and replace identifiers like any other channel.
Sources
- Slack Workspace Owners and Admins on all plans can export public channel messages and file links as JSON; exports including private channels and DMs are available only on Business+ and Enterprise and require an application; exports contain links to files rather than the files. Source
- Slack's API Terms bar providers of applications used outside their own organization from training a large language model on API Data or bulk exporting message and file data except where an additional agreement allows it. Source
- Slack retains messages and files for the lifetime of the workspace by default, admins can set custom deletion periods, and deletion is permanent. Source
Related resources
See if your company qualifies
A short company assessment. No data uploads are needed.