{
  "id": "CMP-129",
  "slug": "cmp-129",
  "title": "Evidence must come from one company, not several",
  "statement": "A campaign's opt-in evidence must all come from the registered brand, not from subsidiaries, franchises or client brands.",
  "rationale": "A bundle showing three businesses tells a reviewer that consent was pooled across them, and pooled consent is not transferable to whichever entity happens to be sending. Agencies and franchisors hit this honestly by attaching the best examples they have rather than the ones belonging to the registrant, and the submission is refused for a reason that reads as pedantic until you notice it is the whole question.",
  "layer": "CAMPAIGN",
  "layerSlug": "campaign",
  "object": "opt-in evidence across the bundle",
  "severity": "BLOCKING",
  "detectability": [
    "AI_FORM"
  ],
  "failureClass": "TERMINAL_EVIDENCE",
  "authorities": [
    "Twilio"
  ],
  "codes": [
    {
      "provider": "Twilio",
      "code": "30926",
      "remediable": true
    }
  ],
  "applicabilityText": "Applies to every 10DLC registration.",
  "universal": true,
  "remediation": "Attach only artifacts captured from this brand's own consent surfaces, and register a separate campaign for each other entity. Where the programme genuinely spans franchisees, the AGENTS_FRANCHISES use case is the route that lets sub-entities be disclosed rather than hidden.",
  "example": "Every screenshot shows acmecoffee.com — not one from acmecoffee.com and one from a sister brand that happens to run the same form.",
  "phase": "approval",
  "automated": true,
  "url": "https://ekas.io/rules/10dlc/campaign/cmp-129/",
  "markdown": "https://ekas.io/rules/10dlc/campaign/cmp-129.md",
  "registry": "https://ekas.io/rules/10dlc/",
  "updated": "2026-07-25",
  "licence": "CC BY 4.0 — https://creativecommons.org/licenses/by/4.0/"
}
