Example — not a live audit
This is a static illustration of a SovereigntyScore compliance audit. It demonstrates the format, scoring methodology, and output structure that Pro users receive for every analysis. Live audits are generated in real time using current data.
Slack
Sovereignty Assessment
Slack presents significant sovereignty risk for European organisations. US ownership, default US data processing, and structural exposure to US surveillance legislation make it a high-priority candidate for migration assessment.
Assessment context: SaaS vendor analysis for EU-based organisation, August 2026
Slack processes and stores data primarily in the United States. EU data residency is available via Slack Enterprise Grid but requires specific configuration and is not the default. Data may be subject to US government access under the CLOUD Act.
Slack is owned by Salesforce, Inc., a US-publicly-traded corporation. Corporate governance, investor base, and strategic decisions are entirely US-anchored. No European entity exercises meaningful operational control.
Slack operates under a Data Processing Agreement referencing Standard Contractual Clauses. However, as a US entity, it remains subject to FISA 702 and the CLOUD Act, creating a structural conflict with GDPR requirements.
Slack publishes a transparency report and government request disclosures. However, detailed audit access and independent sovereignty assessments are not publicly available.
Verdict: Slack presents high sovereignty risk for EU-regulated organisations due to jurisdictional exposure and potential CLOUD Act applicability. Use only with documented risk acceptance and mitigating controls.
San Francisco, California, United States
United States (default). EU data residency available on Enterprise Grid with explicit configuration.
Salesforce, Inc. (NYSE: CRM) — US publicly traded corporation. Acquired Slack Technologies in 2021.
GDPR-compliant via Standard Contractual Clauses. Structural CLOUD Act conflict remains unresolved.
Key Sovereignty Concerns
- •US CLOUD Act exposure: Salesforce is compellable to produce data regardless of storage location
- •Default data residency is US-based; EU residency requires Enterprise Grid (premium tier)
- •No meaningful European operational control or governance structure
- •Transparency reporting is limited and does not cover national security requests in detail
- •Vendor lock-in risk: deep integration with Salesforce ecosystem creates switching costs
Jurisdictional Context
This section provides legal and geopolitical context only and does not influence the Sovereignty Score.
San Francisco, California, United States
Mixed
This tool may be subject to legal frameworks outside the EU. While this does not indicate non-compliance, it may be relevant for regulated or sovereignty-sensitive workloads.
European Alternatives
Open-source, self-hosted team messaging platform. EU hosting possible with full data control.
End-to-end encrypted messaging built on the open Matrix protocol. EU-hosted options available.
Open-source communication platform with self-hosting and EU cloud deployment options.
Migration Considerations
Migration from Slack requires careful planning around channel history, integrations, and workflow automations. Mattermost and Element offer Slack-compatible import tools. The primary challenge is user adoption and third-party integration parity, not data portability. A phased migration starting with internal teams is advisable.
Audit your technology stack
One-off €99. Your entire technology stack scored as one system, a prioritised fix-first roadmap, and a board-ready PDF. Free per-tool guides live in our Info Hub.