{
  "id": "BRD-168",
  "slug": "brd-168",
  "title": "Consent must name the seller whose messages are delivered",
  "statement": "Where a reseller or agency sends, the consent must authorise messages delivered, or caused to be delivered, by the named seller.",
  "rationale": "Consent runs to a named party, and the FCC's definition covers messages a seller causes to be delivered as well as ones it sends itself — so consent naming the agency does not authorise the brand, and consent naming the brand does authorise its vendor. Getting this backwards is how a compliant-looking programme ends up with consent that covers nobody who is actually texting.",
  "layer": "BRAND",
  "layerSlug": "brand",
  "object": "the consent text vs the sending entity",
  "severity": "HIGH",
  "detectability": [
    "AI_FORM"
  ],
  "failureClass": "TERMINAL_WEBSITE",
  "authorities": [
    "FCC"
  ],
  "applicabilityText": "Applies to every 10DLC registration.",
  "universal": true,
  "remediation": "Word the opt-in so it names the business the customer knows — the seller — and covers messages sent on its behalf: \"…to receive texts from Acme Coffee or its service providers.\" Done when the name in the consent is the brand on the registration.",
  "notes": "Applies where an agency or ISV sends on the brand's behalf. The condition lives in the criteria rather than in a tag, because no fact on the registration says who operates the sending — and the criteria open with the PASS boundary for the ordinary case where the brand sends for itself.",
  "phase": "approval",
  "automated": true,
  "url": "https://ekas.io/rules/10dlc/brand/brd-168/",
  "markdown": "https://ekas.io/rules/10dlc/brand/brd-168.md",
  "registry": "https://ekas.io/rules/10dlc/",
  "updated": "2026-07-25",
  "licence": "CC BY 4.0 — https://creativecommons.org/licenses/by/4.0/"
}
