{
  "id": "CMP-050",
  "slug": "cmp-050",
  "title": "The description must not contain personal data",
  "statement": "The campaign description must not contain individual names, account numbers or other personal data.",
  "rationale": "The description is stored and read across several organisations — the CSP, the registry, the carriers — and none of them is the right custodian for a customer's name or account number. It gets there through a well-meant example: someone illustrates the programme with a real message they sent, and the illustration carries a real person in it.",
  "layer": "CAMPAIGN",
  "layerSlug": "campaign",
  "object": "campaign.description",
  "severity": "MEDIUM",
  "detectability": [
    "AI_FORM"
  ],
  "failureClass": "RETRY_FIELD",
  "authorities": [
    "Twilio"
  ],
  "codes": [
    {
      "provider": "Twilio",
      "code": "30886",
      "remediable": true
    }
  ],
  "applicabilityText": "Applies to every 10DLC registration.",
  "universal": true,
  "remediation": "Replace any real person, account number or order reference with a category or a bracketed placeholder. Done when nothing in the field identifies an individual.",
  "example": "Acme Coffee texts customers their order status — not \"we text customers like Maria Alvarez about order 4471 on card ending 8891\".",
  "phase": "approval",
  "automated": true,
  "url": "https://ekas.io/rules/10dlc/campaign/cmp-050/",
  "markdown": "https://ekas.io/rules/10dlc/campaign/cmp-050.md",
  "registry": "https://ekas.io/rules/10dlc/",
  "updated": "2026-07-25",
  "licence": "CC BY 4.0 — https://creativecommons.org/licenses/by/4.0/"
}
