The Practice |
The HR function uses AI-assisted design tools to create visual communications — birthday greetings and performance recognition creatives — for circulation within the organisation. These creatives incorporate the employee's name, photograph, and department.
Questions Raised for Compliance Review |
1. Is this practice permissible under the Digital Personal Data Protection Act, 2023?
2. What are the potential data breach risks across the AI tool, the generated output, and its internal circulation?
3. What is the recommended approach for continuing this practice in a manner fully compliant with DPDP obligations?
Is This Permitted Under DPDP? |
Permissible — but only if a valid consent basis exists for this specific use. The employee's name, photograph, and department are personal data under DPDP. Most employment contracts and onboarding forms collect employee data for payroll, performance, and compliance — not for AI-generated communications. That gap, absent a specific consent or disclosed purpose, makes the current practice non-compliant by default.
Where the Breach Risks Sit |
- The AI platform — When an employee's photograph is uploaded to a generative design tool such as Canva AI or Adobe Firefly, it is transmitted to a third-party server. Depending on the platform's data retention and training policies, the image may be stored beyond the session or used to improve the model. The employee did not consent to their photograph being processed by an external AI vendor.
- The output and its circulation — A creative containing the employee's name, photo, and department, once shared on WhatsApp groups, Teams channels, or email lists, moves outside any controlled environment. If the group includes contractors, vendors, or former employees not yet removed, personal data has been disclosed to unauthorised parties.
- Performance creatives specifically — A performance recognition creative — naming an individual, their team, and their achievement — reveals performance standing and organisational positioning. If screenshotted and shared externally, or if the employee has a contested relationship with the recognition, the organisation faces both a data exposure and a potential HR grievance.
The Ideal Compliant Approach |
1. Obtain explicit consent at onboarding. Add a clear clause to the employee onboarding or HR data consent form: the employee's name, photograph, and department may be used by the HR team to create internal celebration and recognition communications using AI-assisted design tools. One clause resolves the consent gap entirely.
2. Use enterprise-tier tools only. Canva for Teams, Adobe Express for Enterprise, and Microsoft Designer operate under enterprise data agreements that prohibit training on uploaded content and restrict retention. Consumer or free-tier versions of the same platforms frequently do not. This distinction is material under DPDP's processor obligations.
3. Make performance creatives opt-in. Birthday communications are generally expected and welcome. Performance recognition is a different category — some employees are private about their achievements. Offering a one-time opt-out preference during onboarding eliminates both the consent gap and the risk of HR friction.
DPDP Risk Summary |
| Element | Status | Recommended Action |
|---|---|---|
| Employee photo uploaded to AI tool | ⚠ Needs consent basis | Add specific clause to onboarding consent form |
| Use of name, photo, dept in creative | ⚠ Purpose not declared | Update HR data use policy to include this purpose |
| Enterprise tool with DPA in place | ✓ Compliant | Confirm tool tier — consumer vs enterprise terms differ |
| Circulation on controlled internal channels | ✓ Generally acceptable | Audit group membership — remove ex-employees and vendors |
| Performance recognition creatives | ⚠ Sensitive — higher risk | Make opt-in at onboarding; treat separately from birthday comms |
| Retention of generated creatives | ⚠ No policy defined | Define retention period and communicate to HR team |