{
  "id": "CON-036",
  "slug": "con-036",
  "title": "Platform-hosted evidence must show the end business, not the platform",
  "statement": "Where consent is collected on a platform, agency, or franchisee surface, the evidence must identify the end business the consumer is agreeing to hear from.",
  "rationale": "A consumer looking at a form carrying only the marketing platform's branding cannot tell whose messages they just agreed to, so the consent names nobody and the brand that later sends is not the brand they said yes to. This is the honest version of the consent-transfer problem: the form genuinely is the platform's, so screenshotting it as-is feels like screenshotting the opt-in, and nothing on screen tells you it is not.",
  "layer": "CONSENT_FLOW",
  "layerSlug": "consent-flow",
  "object": "consent artifact branding",
  "severity": "BLOCKING",
  "detectability": [
    "VISION"
  ],
  "failureClass": "TERMINAL_EVIDENCE",
  "authorities": [
    "Twilio",
    "AT&T"
  ],
  "codes": [
    {
      "provider": "Twilio",
      "code": "30506",
      "remediable": true
    }
  ],
  "applicability": {
    "consentMethods": [
      "third_party",
      "imported",
      "franchise_agent",
      "chat"
    ]
  },
  "applicabilityText": "Applies when consent was collected by third party, imported list, franchise or agent and chat.",
  "universal": false,
  "remediation": "Re-capture the evidence with the end business's name or logo inside the same frame as the consent control — usually by setting the platform form's header or logo field, or by capturing the branded page the widget is embedded in rather than the bare widget. Done when somebody who has never heard of your platform can name the business from the image alone.",
  "pitfalls": [
    "Naming the brand in the campaign record does not fix the artifact — the reviewer is judging the picture, not the field beside it.",
    "A franchisee form that names only the franchisor fails the same way as an ISV form: the entity on the artifact must be the entity registered."
  ],
  "phase": "approval",
  "automated": true,
  "url": "https://ekas.io/rules/10dlc/consent-flow/con-036/",
  "markdown": "https://ekas.io/rules/10dlc/consent-flow/con-036.md",
  "registry": "https://ekas.io/rules/10dlc/",
  "updated": "2026-07-25",
  "licence": "CC BY 4.0 — https://creativecommons.org/licenses/by/4.0/"
}
