India's Digital Personal Data Protection Act, 2023 (DPDPA) received presidential assent in August 2023 and its rules are now being finalised, making this the most consequential shift in how brands can legally collect, store, and republish consumer-generated content since the internet arrived in India. If your brand already runs UGC programmes at scale, you are not starting from zero; you are retrofitting.
The playbook below is written for teams that already have creator briefs, repurposing workflows, and paid amplification in place. It covers the specific pressure points where DPDPA, IT Rules 2021, ASCI's influencer guidelines, and platform terms-of-service intersect with UGC collection, and what you need to change operationally, not just legally.
What the DPDPA Actually Means for UGC Programmes
The DPDPA classifies personal data as any data that can identify an individual. A video of a creator reviewing your skincare product, showing their face, name, location, and voice, is personal data. A photo tagged with #MyMyntraLook that includes someone's reflection in a mirror is personal data. The moment you collect, store, process, or republish that content for commercial purposes, you become a Data Fiduciary under the Act.
Key obligations that directly affect UGC workflows:
- Purpose limitation: Consent must be collected for a specific stated purpose. "We may use your content for marketing" is no longer adequate. You need: "We will use this video in paid Meta and Google ads for 12 months."
- Consent dashboards: Users must be able to withdraw consent. If a creator who posted an Instagram Reel tagging your brand later asks you to stop running it as an ad, you must be able to honour that request, and have a process to pull it from running creatives within a defined SLA.
- Data minimisation: You cannot retain a creator's phone number, location, or full name indefinitely just because they once submitted a review. Purge policies need to exist.
- Children's data: Anyone under 18 is classified as a child. Given that a significant portion of Instagram and YouTube Shorts creators in Tier-cities across India like Coimbatore, Patna, and Bareilly are minors, this is a live exposure, not a theoretical one.
The penalties are graded up to Rs. 250 crore per breach instance. For brands running UGC campaigns across thousands of creators, the aggregate exposure from poorly managed consent records is substantial.
Auditing Your Current Consent Stack
Most brands running mature UGC programmes in India have consent scattered across three disconnected layers: a hashtag campaign terms page that nobody reads, a creator brief PDF that has a one-line usage clause, and a verbal agreement on a WhatsApp message. None of these constitutes valid, verifiable, specific consent under DPDPA.
A practical audit starts with these questions:
- Can you produce a timestamped consent record for every piece of UGC currently in your ad account or website?
- Does your consent language specify the platforms, ad formats, and duration of use?
- Do you have a documented withdrawal process and can you actually execute it within 72 hours?
- Are minors filtered out at collection, or do you rely on platform age gates (which are routinely circumvented)?
In our production work, we moved all creator onboarding to a digital consent form, not a PDF, but a form with a unique submission ID tied to the brief. That ID travels through editing, approval, and upload, so any ad manager can trace the consent record in under two minutes. Building this cost roughly Rs. 40,000 in developer time.
ASCI Influencer Guidelines and the Consent Overlap
ASCI's influencer guidelines (updated 2021, enforced actively since 2022) require creators to label paid partnerships with #Ad or #Sponsored. But there is a less-discussed dimension: when a brand repurposes an organic UGC post as a paid dark post on Meta, the disclosure obligation shifts. The original post may have carried no disclosure because the creator was not paid, but running it as a paid ad without the creator's knowledge, and without adding the disclosure label, violates both ASCI rules and Meta's ad policies simultaneously.
This creates a consent and compliance coupling that most brands have not thought through. The solution is explicit repurposing clauses: when you seek consent to run organic UGC as paid media, the consent form must specify that the repurposed version will carry a "Paid Partnership" or "Sponsored" label, and the creator must acknowledge this. It also prevents creator backlash, a Bengaluru-based food creator discovering their unpaid review is funding a Rs. 5 lakh ad campaign is a reputational problem, not just a legal one.
Platform-Level Rules That Add Further Constraints
India's dominant UGC surfaces, Instagram, YouTube Shorts, and Moj, each have terms-of-service provisions that affect how brands can collect and use content, independently of DPDPA:
- Instagram: Meta's rights and permissions policies require explicit written permission from the creator to use their content in paid advertising, even if they tagged your brand. A tag is not a content licence. Meta's own Branded Content tool and the Partnership Ads flow (formerly known as whitelisting) are the only compliant routes for paid amplification, and both require the creator to actively grant access.
- YouTube: Google's content policies similarly require creator permission for any commercial use outside the standard Creative Commons designations. Downloading a YouTube Short and cutting it into a pre-roll without a written licence is a copyright violation, full stop.
- Moj and Josh: Sharechat's platforms are popular among Hindi, Tamil, and Telugu-speaking creators in Tier-2 and Tier-3 markets. Their creator agreements vest original content rights in the creator; brand repurposing requires a separate licensing agreement, which most brands skip entirely.
The practical implication: every UGC asset in your library should have a documented source, a platform-specific rights status, and a consent record. "We found it on Instagram" is not a rights record.
Rebuilding Your Collection Workflow for Compliance
Rather than bolt consent onto existing workflows, brands running serious UGC programmes should redesign collection from the brief stage. Here is what a compliant, operationally efficient structure looks like:
- Brief + consent in one step: The creator brief document (or onboarding link) contains the usage clause in plain language, platform, duration, format, whether it will be used in paid ads. Acceptance of the brief constitutes documented consent. Use a form tool like Tally or a custom PHP form (not a PDF) so submissions are timestamped and stored.
- Separate clauses for organic vs. paid: A creator may consent to their video appearing on your website but not in paid ads. Build the form to capture this granularly rather than using a blanket clause.
- Retention and deletion schedule: Define how long you keep creator personal data (name, phone, address) versus the content itself. A 24-month retention for content, 12-month for personal data unless an active contract exists, is a reasonable starting point.
- Minor screening: For hashtag campaigns where you are pulling submissions from public posts, build a screening step that verifies account age signals, profile creation date, follower demographics, stated age in bio. Flag any account where signals suggest the creator may be under 18 for manual review before use.
- Consent withdrawal SLA: Document a 72-hour SLA for honouring withdrawal requests. Assign a named owner (not just "the marketing team") to manage these requests, and include the step of pausing or removing the relevant ad creatives.
Localisation, Language, and the Consent UX Problem
India has 22 scheduled languages and a UGC creator base that spans Tamil Nadu to Rajasthan. A consent form in English that a creator in Tirunelveli or Gorakhpur cannot fully understand is arguably not informed consent under the spirit of the DPDPA, which requires consent to be "freely, specifically, informedly, and unambiguously" given. Consent materials should be available in at least Hindi and the primary language of the creator segment you are briefing. Translation costs for a standard brief run Rs. 3,000–8,000 per language variant, a rounding error relative to the cost of a non-compliant campaign.
Data Storage, Vendor Risk, and Cross-Border Issues
The DPDPA's data localisation provisions are still being finalised in the rules, but the direction is clear: significant data fiduciaries will face restrictions on cross-border transfers of personal data to certain countries. If your UGC asset management is handled by a US-based DAM (digital asset management) platform, and that platform stores Indian creators' personal data on US servers, you may be building a compliance liability into your infrastructure.
Brands should audit their vendor stack: Where are creator submissions actually stored? Does your DAM or CRM vendor have a Data Processing Agreement covering Indian data subjects? Switching sensitive creator records to India-hosted storage, AWS Mumbai, Google Cloud Mumbai, or domestic vendors like Zoho, is a low-disruption risk reduction step that most brands can implement in a sprint.
Building a compliant UGC programme in 2025–26 is not a legal team project, it is a production operations project. If you want to review your current consent stack, repurposing workflow, or creator brief structure against these requirements, book a consultation with our team and we can walk through your specific programme together.