The Practice

The HR function uses AI-assisted design tools to create visual communications — birthday greetings and performance recognition creatives — for circulation within the organisation. These creatives incorporate the employee's name, photograph, and department.

 

Questions Raised for Compliance Review

1. Is this practice permissible under the Digital Personal Data Protection Act, 2023?

2. What are the potential data breach risks across the AI tool, the generated output, and its internal circulation?

3. What is the recommended approach for continuing this practice in a manner fully compliant with DPDP obligations?

 

Is This Permitted Under DPDP?

Permissible — but only if a valid consent basis exists for this specific use. The employee's name, photograph, and department are personal data under DPDP. Most employment contracts and onboarding forms collect employee data for payroll, performance, and compliance — not for AI-generated communications. That gap, absent a specific consent or disclosed purpose, makes the current practice non-compliant by default.

 

Where the Breach Risks Sit

  • The AI platform — When an employee's photograph is uploaded to a generative design tool such as Canva AI or Adobe Firefly, it is transmitted to a third-party server. Depending on the platform's data retention and training policies, the image may be stored beyond the session or used to improve the model. The employee did not consent to their photograph being processed by an external AI vendor.
  • The output and its circulation — A creative containing the employee's name, photo, and department, once shared on WhatsApp groups, Teams channels, or email lists, moves outside any controlled environment. If the group includes contractors, vendors, or former employees not yet removed, personal data has been disclosed to unauthorised parties.
  • Performance creatives specifically — A performance recognition creative — naming an individual, their team, and their achievement — reveals performance standing and organisational positioning. If screenshotted and shared externally, or if the employee has a contested relationship with the recognition, the organisation faces both a data exposure and a potential HR grievance.

 

The Ideal Compliant Approach

1. Obtain explicit consent at onboarding. Add a clear clause to the employee onboarding or HR data consent form: the employee's name, photograph, and department may be used by the HR team to create internal celebration and recognition communications using AI-assisted design tools. One clause resolves the consent gap entirely.

2. Use enterprise-tier tools only. Canva for Teams, Adobe Express for Enterprise, and Microsoft Designer operate under enterprise data agreements that prohibit training on uploaded content and restrict retention. Consumer or free-tier versions of the same platforms frequently do not. This distinction is material under DPDP's processor obligations.

3. Make performance creatives opt-in. Birthday communications are generally expected and welcome. Performance recognition is a different category — some employees are private about their achievements. Offering a one-time opt-out preference during onboarding eliminates both the consent gap and the risk of HR friction.

 

DPDP Risk Summary

ElementStatusRecommended Action
Employee photo uploaded to AI toolNeeds consent basisAdd specific clause to onboarding consent form
Use of name, photo, dept in creativePurpose not declaredUpdate HR data use policy to include this purpose
Enterprise tool with DPA in placeCompliantConfirm tool tier — consumer vs enterprise terms differ
Circulation on controlled internal channelsGenerally acceptableAudit group membership — remove ex-employees and vendors
Performance recognition creativesSensitive — higher riskMake opt-in at onboarding; treat separately from birthday comms
Retention of generated creativesNo policy definedDefine retention period and communicate to HR team