The Practice

A marketing or business development professional uses a generative AI tool — such as ChatGPT or Claude — to draft a client case study, proposal, or thought leadership piece. To produce contextually accurate and compelling output, they input the client's company name, the name and designation of the client contact, specific project outcomes, and commercially sensitive details into the AI prompt.

 

Questions Raised for Compliance Review

  1. Does entering client-related personal and commercially sensitive information into a third-party generative AI tool constitute a DPDP compliance and contractual risk?
  2. What breach risks arise from this practice at the individual, organisational, and client relationship level?
  3. What is the compliant approach to using generative AI tools for client-facing content creation?

Is This Permitted Under DPDP?

Yes — on both counts. The client contact's name and designation are personal data under DPDP. Their entry into a third-party AI platform without the individual's knowledge or consent, and without a processing agreement between the organisation and the AI vendor covering this use, constitutes unauthorised processing. Separately, the inclusion of commercially sensitive project details likely breaches the confidentiality obligations in the client engagement agreement — a simultaneous DPDP and contractual exposure.

 

Where the Breach Risks Sit

  • Personal data entered without consent — The named client contact did not agree to have their personal information processed by a third-party AI platform. The organisation's agreement with its AI tool vendor — if any exists — governs data handling, but the client contact is not a party to that agreement and has no knowledge of or control over how their information is handled.
  • Vendor data retention and training risk — Many generative AI platforms, particularly consumer-tier versions, retain user inputs. There is a documented risk that content entered into prompts — including named individuals and sensitive project details — may surface in outputs generated for other users, or be used to train future model iterations.
  • Confidentiality and NDA breach — Most client engagement contracts include explicit confidentiality provisions. Entering project-specific outcomes, financial metrics, or strategic details into any external platform — AI or otherwise — likely breaches those provisions. The client may have legal recourse independent of any DPDP consideration.
  • Reputational and relationship risk — If a client discovers that their contact's personal information and confidential project details were processed through a public AI tool, the damage to the relationship may be irreparable — regardless of whether a formal breach is pursued.
     

The Ideal Compliant Approach

1. Implement a client data classification policy. Before any content generation activity, staff must classify the information involved. Client contact names, project specifics, financial outcomes, and strategic details should be classified as restricted — meaning they cannot be entered into external AI tools without DPO and legal clearance.

2. Use enterprise AI tools with appropriate DPAs. Where AI-assisted content generation is a legitimate business activity, the organisation should deploy enterprise versions of AI tools — such as Microsoft Copilot with enterprise data protection, or API-based implementations with appropriate data handling terms — that contractually prohibit training on inputs and ensure data isolation.

3. Anonymise inputs where possible. For drafting purposes, AI tools rarely need the specific client name or contact's identity to produce effective content. Staff should be trained to use placeholders — 'a mid-size logistics company in Mumbai' rather than the client's name — and populate specifics only after the draft is removed from the AI environment.

4. Obtain client consent for case study development. Before any client case study is developed — through AI or otherwise — the client should provide written consent covering what information may be used, in what format, and for which audiences.

 

DPDP Risk Summary

ElementStatusRecommended Action
Client contact name entered into public AI toolPersonal data processed without consentUse placeholders in prompts; personalise outside AI environment
Commercially sensitive details in AI promptLikely NDA breach; confidentiality riskClassify client data as restricted; prohibit entry into external AI
Consumer-tier AI tool usedNo data isolation, potential retentionMandate enterprise-tier tools with appropriate DPAs for client work
No client consent for case study useRequired before developmentObtain written consent; define permitted scope of use
Staff unaware of riskTraining gapInclude AI prompt hygiene in mandatory compliance training