Hub Learning Pathway Use Cases Policy & Guidelines What's New Brand Hub ↗

Documents

Policy Documents

Download and read our AI governance documents. These apply to all Miroma Group employees using AI tools.

Decision Guide

Data Handling Decision Guide

Not sure whether you can use AI with a particular dataset? Work top to bottom: identify your data, find its risk level, then follow that column down to the controls you need to apply.

Planning to use an AI tool with data?
Identify your data type from the lists below
What is the risk level?

🔴 High risk

Data types

  • Personnel
  • Customer
  • Client
  • Social media
  • Financial
  • Proprietary business data

Is a DPIA required?

Check the list — Personal data: yes, Customer data: yes. All others: review with Legal.

Send the DPIA form to your AI Division Head + Legal
Wait for legal approval

Implement HIGH controls

  • Role-based access
  • Encryption required
  • Audit logs enabled
  • DPA with vendor
  • Regular access reviews

🟡 Medium risk

Data types

  • PR / media relations
  • Creative assets
  • Media buying
  • Influencer data
  • Sales / revenue
  • Marketing / campaign

Does this involve client data or competitive info?

If yes: review client contracts for restrictions first.

Implement MEDIUM controls

  • Access limited by team / client
  • Confidentiality enforced
  • Client approval where needed
  • Standard access controls

🟢 Low risk

Data types

  • Brand monitoring
  • Development / code
  • Production / vendor
  • Technical / system

Implement LOW controls

  • Standard access controls
  • Remove PII from data
  • Basic security terms
  • Vendor due diligence
Document it in the data inventory
✅ Ready to launch
Quarterly compliance review
🔄 Continue monitoring

Prefer the original diagram? Open the flowchart image ↗

At a Glance

The Golden Rules

A quick reference for using AI tools responsibly at Miroma. Always read the full policy documents above.

01

Never input confidential client data

Do not enter personally identifiable information, client financial data, or proprietary business data into any AI tool without completing a DPIA first.

02

Always review AI output

AI-generated content must be reviewed, fact-checked and edited by a human before being shared with clients or published externally. You are responsible for the final output.

03

Be transparent about AI use

Where AI has been used to create client-facing work, this should be disclosed appropriately. Check client contracts for any specific restrictions.

04

Protect intellectual property

Do not input Miroma Group's, or any client's, proprietary strategies, creative IP, or trade secrets into external AI tools. Use only approved platforms.

05

Assess your data risk level

Use the data handling flowchart above before using AI with any dataset. High-risk data requires a DPIA and legal sign-off before proceeding.

06

When in doubt, ask the AI team

If you're unsure whether a particular use of AI is permitted, reach out to the AI team before proceeding. Better to check than to create a compliance issue.

Questions about AI compliance or data handling?

Contact the AI team at aiteam@miroma.com — we'll help you navigate the right approach.