Subject Access Requests and eDiscovery: Finding the Data in Teams and Slack
A subject access request or a legal request still covers everything an organisation holds about a person, including the conversations that now happen in Microsoft Teams and Slack. That data feels ephemeral, but it persists, it is scattered, and finding all of it by the deadline is genuinely hard. Here is why the obligation reaches collaboration tools, why they are so awkward to search, and what makes it manageable.
For years the answer to a subject access request lived in two places, email and a handful of shared drives. That is no longer true. A large part of the working day now happens in Teams and Slack, in channels, threads and direct messages, and that is where decisions get made, opinions get shared and personal data gets discussed. The obligation to find and produce that data has not changed at all. What has changed is that the data has moved somewhere far harder to search, and most organisations have not caught up.
A subject access request and an eDiscovery request both reach collaboration data, not just email. Teams and Slack feel throwaway, but the messages persist, scattered across channels and direct messages, edited and deleted over time, with no unified way to search one person's whole footprint. The native export tools are slow and limited. Meeting the deadline reliably means capturing that data into a searchable, immutable store you can actually query, preserve and defensibly delete.
The data has moved, the obligation has not
Under UK GDPR, an individual has a right of access to the personal data you hold about them. That right does not stop at the inbox. If someone has been discussed by name in a Teams channel, mentioned in a Slack thread, or is the subject of a direct message between two managers, that is personal data within scope, and you are expected to find it and produce it. The same is true when a regulator or a court asks. The channel the conversation happened in is irrelevant to the obligation. The only thing that changes is how hard it is to comply.
This is where many organisations quietly carry a risk they have never tested. They can search email in minutes. Ask them to produce every message about one named person across two years of Teams and Slack activity, and the honest answer is often that they are not sure they can, certainly not quickly, and certainly not with confidence that nothing was missed.
What a subject access request actually demands
A subject access request is not a polite enquiry you can answer at leisure. It carries a statutory clock and a duty to be thorough.
- A right of access to their personal data. The individual can ask for the personal data you hold about them, and you must provide it, wherever within your systems it sits, including collaboration tools.
- A one month deadline. You must respond without undue delay and within one month of receiving the request. That can be extended by up to two further months where the request is complex or where you have received a number of requests from the same person, but the extension has to be justified.
- A duty of reasonable effort. You are expected to carry out a reasonable and proportionate search. Not knowing where the data is, or not having the tools to find it, is not an excuse the process makes room for.
The clock does not stop because the data is inconvenient to reach. If it takes your team two weeks of manual effort to trawl channels and exports, that is two weeks gone from a one month window, on a single request.
Why Teams and Slack are so hard to search
Collaboration platforms were built for fast conversation, not for records management, and it shows the moment you need to produce something.
- It feels ephemeral, but it persists. A chat feels like a passing remark, yet the message is stored and discoverable. People speak more casually in Teams than they ever would in an email, which makes the content more sensitive, not less.
- Messages get edited and deleted. A message can be changed or removed after the fact, so a simple export taken today may not reflect what was actually said. Establishing the true record means capturing the full context, including edits and deletions, as they happen.
- The data is scattered. One person's footprint is spread across public channels, private channels, group chats and direct messages, in more than one workspace, and often across both Teams and Slack at once.
- Native tools are limited. The built in export and eDiscovery features can be slow, awkward to scope to a single person, and inconsistent across platforms. There is rarely one unified search that spans a named individual's entire activity.
eDiscovery and legal hold, the same problem with higher stakes
Everything above applies just as much when the request comes from litigation or a regulatory investigation. In eDiscovery you must not only find the relevant collaboration data, you must preserve it against change or deletion the moment a matter is anticipated, then review and produce it. A legal hold that only covers email while the real conversation happened in Slack is a hold with a hole in it. The ability to place an immutable hold across collaboration channels, with an audit trail, is what turns a nervous manual scramble into a defensible process.
Regulated sectors have a further duty
For firms in regulated sectors, the requirement goes beyond responding to requests. Obligations to capture and retain business communications, and in some cases to supervise them, increasingly extend to the collaboration channels where business is now actually conducted. If staff are agreeing things in Teams and Slack, those channels fall within the same record keeping and oversight expectations that once applied only to email and phone, and a gap in capture is a gap in compliance.
These are two different problems that people often conflate. Stopping threats inside collaboration tools, malicious links, impersonation and risky sharing, is a security question, and we cover it in securing collaboration tools. Finding, preserving and producing the data for a subject access request or a court is a compliance and records question. You can be strong on one and exposed on the other. This guide is about the second.
What good looks like
A collaboration estate you can actually answer for shares a few characteristics, and none of them depend on hoping the native exports are enough on the day.
- Full context capture. Messages from Teams, Slack and similar tools are collected as they happen, including edits and deletions, so the record reflects what was really said.
- Search across a person, not a channel. You can pull one named individual's entire footprint across every workspace, channel and direct message in a single query, rather than stitching together partial exports.
- Retention with defensible deletion. Data is classified and kept for as long as policy and regulation require, then removed on a clear schedule, so you are neither hoarding nor destroying prematurely.
- Immutable holds and audit trails. When a matter arises, relevant data can be preserved beyond change or deletion, with a record of who did what and when.
- The ability to erase. When a valid right to erasure applies, you can remove a person's data reliably, which is the other side of the same coin as finding it.
Where Mimecast Aware fits
This is the specific gap Mimecast Aware is built for. It collects, processes and preserves collaboration data at scale from Microsoft Teams, Slack and Zoom, using native API and webhook integrations, and it captures the full conversation context including edits, deletions and emojis, so the record is complete rather than a snapshot. It gives legal, compliance, HR and security teams granular search across that data, classifies it by type, sensitivity and retention need, applies retention policies, supports immutable holds for investigations with audit trails, and can carry out automated removal of a user's data when that is required. In other words, it turns the scattered, awkward reality of collaboration into something you can query and produce against. Worth noting that Mimecast Cloud Archive also captures Teams data as part of a wider archive, which we cover in the archiving, retention and eDiscovery guide. We are a strategic Mimecast partner and recommend Aware where the collaboration compliance and discovery burden genuinely justifies it, rather than as a default, because a small organisation with light collaboration use may not need it.
Not sure whether you could answer a subject access request that reaches your collaboration tools? Our free, interactive Email Security Assessment covers the collaboration and compliance dimensions alongside the rest of your email and collaboration posture, and returns an instant, personalised view of where the gaps are. It is a quick, honest place to start.
Could you produce every Teams and Slack message about one person, on deadline?
C4C helps organisations get collaboration data under control, so a subject access request, an eDiscovery order or a regulatory ask becomes a search rather than a scramble. Vendor neutral, with no quota to fill.
Prefer email? Reach us directly at hello@c4cgroup.co.uk.
Frequently asked questions
Does a subject access request cover Microsoft Teams and Slack?
Yes. A subject access request covers all the personal data you hold about an individual, wherever it lives, and that includes messages in Microsoft Teams and Slack. If someone is named or discussed in a channel, thread or direct message, that content is in scope, and you are expected to find and produce it just as you would an email.
How long do you have to respond to a subject access request?
Under UK GDPR you must respond without undue delay and within one month of receiving the request. That period can be extended by up to two further months where the request is complex or where the same person has made a number of requests, but you have to justify the extension. The clock does not stop because the data is hard to reach.
Why is it hard to find Teams and Slack data for a DSAR?
Because the data is scattered across public channels, private channels, group chats and direct messages, often in more than one workspace, and messages get edited and deleted over time. The native export tools are slow and awkward to scope to a single person, and there is rarely one unified search across a named individual's entire footprint, so a thorough manual search eats into your one month deadline.
What is the difference between securing Teams and capturing Teams data?
Securing Teams is a security question, stopping threats inside collaboration tools such as malicious links, impersonation and risky sharing. Capturing Teams data is a compliance and records question, being able to find, preserve and produce the data for a subject access request, eDiscovery or a regulator. They are different problems, and an organisation can be strong on one while exposed on the other.
Can you put a legal hold on Teams and Slack messages?
You can, but only if you have the means to preserve that data against change or deletion the moment a matter is anticipated. A legal hold that covers email while the real conversation happened in Slack leaves a gap. The ability to place an immutable hold across collaboration channels, with an audit trail of who did what and when, is what makes the process defensible.
How does Mimecast Aware help with subject access requests?
Mimecast Aware captures collaboration data from Microsoft Teams, Slack and Zoom, including edits and deletions, into a searchable store. It gives legal, compliance, HR and security teams granular search across that data, classifies it, applies retention policies, supports immutable holds for investigations with audit trails, and can automatically remove a user's data when required. That turns a scattered manual scramble into a search you can run and trust.