The Practice

During a company town hall or all-hands meeting, HR or senior leadership presents slides identifying top-performing employees by name, team productivity metrics tied to individuals, or attendance and leave trends broken down by department. The presentation deck is subsequently shared on the company intranet or distributed via email to all staff.

 

Questions Raised for Compliance Review

  1. Does the broadcast of named individual performance data within an organisation constitute a processing activity under DPDP?
  2. What specific risks arise from the post-event distribution of such presentation materials?
  3. What is the compliant approach to recognising performance and sharing productivity data organisation-wide?
     

Is This Permitted Under DPDP?

Yes — it is a processing activity, and in its current form, likely non-compliant. An individual's performance rating, attendance record, and team-level output are personal data under DPDP. Their disclosure to an audience beyond what is operationally necessary — and without the individual's prior knowledge or consent to that specific broadcast — is a processing activity that most organisations have not examined through a compliance lens.

 

Where the Breach Risks Sit

  • Disclosure without consent — Employees provided their personal data to the organisation for employment purposes — payroll, appraisal, and management. Having their performance standings announced organisation-wide, and subsequently distributed as a document, extends the use of that data far beyond what was agreed. Some employees may welcome recognition; others may find it unwelcome, embarrassing, or professionally sensitive.
  • Post-event document distribution — A slide deck shared on the intranet or by email becomes a persistent record. It can be downloaded, forwarded, or screenshotted. Once distributed, the organisation loses control of who accesses the named performance data and in what context.
  • Comparative performance data — Naming the top performers implicitly identifies — to a perceptive audience — those who did not appear on the list. In smaller teams or departments, this inference is immediate. The non-disclosure of some employees' performance data through their omission is itself a form of data use.
  • Sensitivity in specific contexts — Attendance and leave data may reflect medical conditions, caregiving responsibilities, or personal circumstances. Its broadcast, even at a team level, risks exposing information the employee considers private.
     

The Ideal Compliant Approach

  1. Obtain prior consent for named recognition. Employees whose names or individual metrics will feature in organisation-wide communications should be informed in advance and given the opportunity to decline. This can be managed through a standing preference captured at onboarding or during the appraisal cycle.
  2. Use aggregate data for organisation-wide sharing. Productivity trends, departmental performance, and attendance patterns can be shared meaningfully at an organisational level without naming individuals. Team-level data — where no individual is identifiable — is typically sufficient for the communication's purpose.
  3. Restrict post-event distribution. If a presentation contains named individual data, it should not be posted to the intranet or distributed by email without review. A separate, anonymised summary can serve the internal communication purpose without creating a persistent, shareable personal data record.

 

DPDP Risk Summary

ElementStatusRecommended Action
Named performance data broadcast to all staffConsent gap for this specific useObtain prior opt-in for named recognition communications
Presentation deck distributed post-eventCreates persistent, shareable personal data recordDistribute anonymised summary only; restrict named version
Attendance and leave data presented by nameMay reveal sensitive personal circumstancesUse aggregate or anonymised data for all-staff presentations
Employees not informed of planned disclosureTransparency obligation not metNotify individuals before featuring them in org-wide comms
No opt-out mechanism for recognitionShould be availableAdd recognition preference to onboarding or appraisal process