{
  "id": "CON-096",
  "slug": "con-096",
  "title": "Nothing in the flow may contradict the no-sharing promise",
  "statement": "No part of the opt-in surface or its linked policy may indicate that opt-in data is shared with third parties.",
  "rationale": "A policy routinely carries the required no-sharing sentence in its SMS section while a general data-sharing clause elsewhere says the opposite, and reviewers read the whole document and treat the permissive clause as controlling. A checker that only looks for the good sentence therefore passes a policy that will be rejected — which is worse than not checking, because the brand submits believing it is covered.",
  "layer": "CONSENT_FLOW",
  "layerSlug": "consent-flow",
  "object": "opt-in surface + linked privacy policy",
  "severity": "BLOCKING",
  "detectability": [
    "CRAWL"
  ],
  "failureClass": "TERMINAL_POLICY",
  "artifact": "privacy_policy",
  "authorities": [
    "AWS",
    "Twilio",
    "GoHighLevel"
  ],
  "applicabilityText": "Applies to every 10DLC registration.",
  "universal": true,
  "dependsOn": [
    "CON-095"
  ],
  "remediation": "Find the permissive clause and carve mobile data out of it explicitly, rather than adding a second sentence that contradicts it. Done when the sharing section itself says mobile information is excluded — a reviewer reading only that section reaches the right answer.",
  "example": "We may share aggregated, non-identifying data with partners. This sharing expressly excludes mobile phone numbers and SMS opt-in data, which are never shared with third parties for marketing purposes.",
  "pitfalls": [
    "A cookie or advertising-partner section is where this usually hides — the SMS section is clean and the marketing section three headings earlier is not."
  ],
  "notes": "The inverse trap, on the consent surface rather than the policy page. Depends on CON-095: until the no-sharing statement is located, there is nothing for a contradiction to contradict. POL-064 states the same trap for the policy document read on its own.",
  "phase": "approval",
  "automated": true,
  "url": "https://ekas.io/rules/10dlc/consent-flow/con-096/",
  "markdown": "https://ekas.io/rules/10dlc/consent-flow/con-096.md",
  "registry": "https://ekas.io/rules/10dlc/",
  "updated": "2026-07-25",
  "licence": "CC BY 4.0 — https://creativecommons.org/licenses/by/4.0/"
}
