Seven Rights Gates Before Buyer Delivery

GateRequired evidenceRelease decision
Project disclosureTask, location, capture, purpose, reviewers, exclusions, and reward basis shown before recordingBlock if the intended use exceeds the project disclosure
Participation and compensationProgram terms plus a record that distinguishes business payment from individual worker compensationBlock unsupported contributor-pay claims
Privacy and capture scopeApproved site, participants, devices, task, and excluded people or informationReject or remediate out-of-scope capture
Acceptance recordSubmission status, material rejection reason, reward basis, and remediation historyOnly accepted records proceed
Permitted useModel training, commercial use, public display, vendors, redistribution, retention, and geographyApprove only the uses explicitly supported
Rights requestsRequest route and documented source, distribution, retention, and trained-model limitsNever promise deletion beyond enforceable control
Legacy reviewPinned source agreement, intended use, contributor category, buyer terms, and surviving restrictionsNo new license without a release-specific decision

This Is a Prospective Minimum, Not Retroactive Consent

Source-backed context[1] GIG Rewards AI data information[2] GIG Rewards collection partner program[3] GIG Rewards privacy policy

The standard applies to newly scoped EGXO collection from July 25, 2026 and to any legacy asset newly approved for licensing. It does not rewrite historical agreements. A legacy dataset must pass a fresh, release-specific review before buyer delivery.

That boundary matters. Saying a company owns or licenses media is not enough to prove every new training, commercial, public-display, vendor, or redistribution use. The release decision must pin the agreement and the intended use.

Disclosure Must Be Project-Specific

Source-backed context[1] GIG Rewards AI data information

Before recording, the project brief should state what is captured, where, for which task, for what AI or robotics purpose, who may review it, how acceptance and reward work, and what must stay out of frame. Participation in one task cannot silently authorize another.

GIG’s public AI-data guidance already tells contributors to follow the current quest, limit the recording to the task, avoid unrelated people and sensitive information, review the recording, and understand that approval depends on acceptance.

Business Payment and Worker Compensation Are Different Claims

Source-backed context[2] GIG Rewards collection partner program

In a collection-partner program, EGXO or GIG may contract and pay a business. The business may then compensate participating workers under its employment arrangements and applicable law. A public business rate is not proof of the amount an individual worker received.

The release record should preserve that distinction. Reporter, buyer, and marketing materials must never collapse a business payment into an unsupported contributor-pay claim.

Privacy Exclusions Belong in the Capture Brief

Source-backed context[1] GIG Rewards AI data information[2] GIG Rewards collection partner program[3] GIG Rewards privacy policy

Approved locations, participants, devices, and tasks must be defined before collection. Unrelated people, private spaces, screens, documents, customer information, and sensitive content are excluded unless the brief expressly permits them and the necessary authorization exists.

Privacy review is not merely a blur pass at the end. The first control is to avoid collecting what the project does not need.

Rights Eligibility Is Independent of Technical Quality

Implementation guidanceEGXO guidance for translating the research into a project specification.

A record can pass focus, codec, synchronization, and annotation checks and still fail licensing. The dataset ledger must keep a rights status separate from technical QA and include collection authority, commercial and model-training permission, public-display status, vendor access, redistribution, retention, and restrictions.

The buyer sees a rights matrix, review date, agreement version, approval status, and provenance chain. Private identity documents, contact data, consent records, and confidential commercial terms remain controlled.

Rights Requests Need Honest Downstream Limits

Source-backed context[3] GIG Rewards privacy policy[4] Philippines National Privacy Commission — Know Your Rights[5] South Africa Information Regulator — POPIA

The program must provide a privacy or rights-request route. The response should explain what can be removed or restricted in source systems and what may already be governed by legal retention, a buyer agreement, a distributed copy, or a trained-model limitation.

Blanket deletion promises are worse than precise limits because they create an expectation the system cannot enforce. The operational record should say what happened, when, under which authority, and which downstream parties were notified where required.

The Buyer Release Gate

Implementation guidanceEGXO guidance for translating the research into a project specification.

No record enters a commercial buyer release until the seven gates above resolve for that specific release. The decision is versioned so later changes to purpose, geography, buyer, model use, or public display trigger a new review instead of inheriting an old yes.

  • Rights-cleared is a release status, not a permanent adjective
  • Legacy media receives a new decision before a new use
  • Rejected and restricted records remain outside delivery
  • Technical QA and rights QA report separately
  • Private contributor evidence stays private

Primary Sources and Further Reading

  1. [1] GIG Rewards AI data information ↗
  2. [2] GIG Rewards collection partner program ↗
  3. [3] GIG Rewards privacy policy ↗
  4. [4] Philippines National Privacy Commission — Know Your Rights ↗
  5. [5] South Africa Information Regulator — POPIA ↗

These sources inform the category-level guidance above. Project-specific requirements are defined with the buyer.