A public instrument of the OYA movement

The OYA Standard (OYA-S)

OYA-S is the draft standard being developed for any organization that collects personal information and creates a profile, inference, score, recommendation, ranking, personalization, or eligibility decision from it. In scope: AI products that build profiles, scores, or recommendations; dating and social platforms; coaching and wellness products; marketplaces; education products; and financial products and eligibility tools.

Founding status. OYA-S is a draft. It has not been ratified by an independent board, and OYA does not yet operate as a certifying body — no company has been certified against it. Full detail: Status & disclosures.

The control domains

Nine control domains.

Each domain names a specific control OYA-S asks a member to build and keep evidence for.

OYA-1

Data Map

A member-readable map of what is collected, inferred, retained, and why.

OYA-2

Algorithmic Representation

Understandable descriptions of what a profile or inference means, and how a member can contest it.

OYA-3

Purpose Boundaries

Documented permitted and prohibited uses for each data category — for example, never selling private reflection data undisclosed.

OYA-4

Sensitive Information Safeguards

Proportionate controls for sensitive data: encryption, least-privilege access, minimization, and retention rules.

OYA-5

Member Controls

Access, correction, deletion, export, and the ability to limit how sensitive data is used.

OYA-6

No Coercive Disclosure

No social, relationship, or employment pressure mechanisms that force disclosure of private records to another person.

OYA-7

Derived-Data Lineage

Tracking how derived data was produced, so a correction or deletion can propagate downstream.

OYA-8

Research and Model Improvement

Separating account-linked data from de-identified aggregate research data, with re-identification-risk controls.

OYA-9

Accountability and Redress

A named accountable role, a dispute and incident process, and a public change log.

The adoption ladder

Six tiers. One ladder.

Each tier is being designed to earn one specific public claim — no more.

1 · OYA Supporter

"We support the principles."

2 · OYA Participant

"We are working toward the standard."

3 · OYA Declared

"We have declared our conformance."

4 · OYA Assessed

"Our declared conformance has been assessed."

5 · OYA Verified

"Our conformance has been independently verified."

6 · OYA Gold

"Verified OYA Gold [version]."

The top tier

What OYA Gold requires.

The short list, as currently drafted.

  • A member-visible data map.
  • Functional correction and deletion controls.
  • Sensitive-data classification with a restricted processing environment.
  • No targeted ads or pricing manipulation drawn from sensitive data.
  • No default peer or partner access to private records.
  • Independent annual assessment.

Founding implementer

AlignHeart is building toward Gold.

AlignHeart — a separate, independent company and OYA's founding implementer — has stated it is building its own product toward this Gold tier. That is a fact about AlignHeart's own roadmap, not a claim about OYA's existence or operation: no company, including AlignHeart, has been certified against OYA-S, because OYA does not yet operate as a certifying body. A full worked draft of one of these standards — OYA-S 2000, covering sensitive data, encryption, member-key control, and erasure — is published in full, with every requirement in normative form, so the standard can be read rather than taken on faith.

Read the governance model