{
  "id": "CON-124",
  "slug": "con-124",
  "title": "The sending entities must be named before consent is captured",
  "statement": "The authorised sending entities must be disclosed before the consumer acts, not on the confirmation screen or in the first message.",
  "rationale": "Consent is given at the moment of the act, so a name disclosed afterwards was not part of what was agreed to. Brands get this wrong in a specific and understandable way: the confirmation page is where they put the full legal detail, because that is the page nobody has to be persuaded by.",
  "layer": "CONSENT_FLOW",
  "layerSlug": "consent-flow",
  "object": "disclosure ordering on the opt-in surface",
  "severity": "BLOCKING",
  "detectability": [
    "CRAWL"
  ],
  "failureClass": "TERMINAL_WEBSITE",
  "authorities": [
    "AT&T"
  ],
  "applicabilityText": "Applies to every 10DLC registration.",
  "universal": true,
  "dependsOn": [
    "CON-123"
  ],
  "remediation": "Move the entity names above the consent control, inside the sentence the consumer is agreeing to. Keep them on the confirmation as well if you like — the requirement is that they appear before the act, not that they appear only there. Done when the names are on screen at the moment the box is ticked.",
  "example": "☐ Text me offers from Acme Coffee and my local Acme Coffee franchise location.\n\n[Join] — the names appear above this button, not on the page it leads to.",
  "notes": "Depends on CON-123: where no entity is named at all, that is CON-123's finding and this rule has no ordering to judge.",
  "phase": "approval",
  "automated": true,
  "url": "https://ekas.io/rules/10dlc/consent-flow/con-124/",
  "markdown": "https://ekas.io/rules/10dlc/consent-flow/con-124.md",
  "registry": "https://ekas.io/rules/10dlc/",
  "updated": "2026-07-25",
  "licence": "CC BY 4.0 — https://creativecommons.org/licenses/by/4.0/"
}
