Home → Compliance

Compliance & guidelines

The data-protection laws and advertising rules that shape how Oye Creators, brands and creators work — and what we do about each. Plain-language summaries in our own words; the official texts are linked in every section.

This page explains how we align with each framework. It is not a certification — no regulator issues one for these laws — and it is not legal advice. Brands and creators remain responsible for their own compliance; our platform is built to make that easier.

1. DPDP Act, 2023 (India)

What it is. India’s Digital Personal Data Protection Act sets the rules for processing digital personal data of people in India: consent-based processing for a stated purpose, rights for individuals, duties on the organisation that decides how data is used (the “data fiduciary”), and a grievance route that ends at the Data Protection Board.

Why it matters here. Oye Creators holds personal data of creators (identity, contact, payout and tax details, social-account data) and of brand users. Brands running campaigns may also receive limited creator data through the platform.

What we do.

  • Collect personal data for stated purposes only — running the marketplace, paying creators, meeting tax and legal duties — and ask for consent where the Act requires it, in clear language.
  • Give creators and brand users the ability to access, correct and erase their data from the app, and to withdraw consent for optional processing (for example, Auto-DM).
  • Publish a named grievance officer and respond within the timelines on our Grievance page.
  • Keep data only as long as the purpose or a legal obligation requires — see Data Retention and Data Deletion.
  • Protect data with the safeguards in our Security Policy, and notify affected users and authorities of breaches as the Act requires.
  • Do not knowingly process data of children; the platform is for users 18 and over — see Age Restriction & Child Safety.

Official source: Ministry of Electronics & IT (MeitY) — Digital Personal Data Protection Act, 2023 and rules.

2. GDPR (European Union and United Kingdom)

What it is. The General Data Protection Regulation governs personal data of people in the EU, with a near-identical UK version. It requires a lawful basis for every use of data, transparency, data-subject rights, protection by design, and controls on transferring data outside the region.

Why it matters here. Oye Creators is an Indian platform for Indian creators and brands. GDPR applies where we handle data of people in the EU/UK — for example a brand team based there, or a creator who is a resident. Our Data Processing Agreement covers the case where we process data on a brand’s behalf.

What we do.

  • Identify a lawful basis for each processing purpose and state it in our Privacy Policy.
  • Honour access, rectification, erasure, restriction, portability and objection requests through the same channels as DPDP rights.
  • Act as processor under a DPA where brands are controllers, with sub-processors listed on the Vendors page.
  • Apply appropriate safeguards for international transfers and keep records of processing.
  • Report qualifying breaches within the regulation’s timelines.

Official source: Regulation (EU) 2016/679 on EUR-Lex.

3. CCPA / CPRA (California, USA)

What it is. The California Consumer Privacy Act, as amended by the CPRA, gives California residents rights over their personal information: to know what is collected, to delete it, to correct it, to opt out of its sale or sharing, and not to be discriminated against for exercising those rights.

Why it matters here. It applies if we handle personal information of California residents and meet the law’s thresholds — for instance a US brand team or a creator based there. We treat the rights as available to those users regardless.

What we do.

  • We do not sell personal information, and we do not share it for cross-context behavioural advertising.
  • Requests to know, delete or correct can be made from the app or by email; see Data Deletion and the Privacy Policy.
  • No user is treated differently for exercising a privacy right.

Official source: California Attorney General — CCPA.

4. ASCI guidelines for influencer advertising (India)

What they are. The Advertising Standards Council of India’s guidelines require that paid or barter promotions by creators are clearly disclosed, that disclosures are prominent and in the same language as the content, and that creators do their own due diligence on claims. Health and finance content has stricter rules, including qualifications for anyone presenting as an expert.

Why it matters here. Every campaign on Oye is a brand-creator collaboration that the guidelines cover. Both the brand and the creator are responsible for disclosure; the platform is where the brief and the rules meet.

What we do.

  • Every brief carries the required disclosure label (for example #ad, #collab or #sponsored) and asks that it appear upfront, not buried in hashtags — and in the language of the post.
  • Barter campaigns are disclosed exactly like paid ones.
  • Health, wellness and financial briefs are reviewed for permitted claims before they go out; creators presenting as experts must hold and show the relevant qualification. See our Healthcare and Fintech industry pages.
  • Brands warrant that claims in the brief are substantiated (Enterprise Client Terms); creators warrant that content is original and compliant (Creators Agreement).
  • Automated replies sent through Auto-DM are identified as automated — see the Meta Platform Policy.

Official source: Advertising Standards Council of India — Guidelines for Influencer Advertising in Digital Media.

5. Questions and requests

Data-protection requests and complaints: the Grievance Redressal page has the officer’s contact and the escalation route. General questions: Support@ttlmedia.in.