{
  "id": "CON-130",
  "slug": "con-130",
  "title": "Each messaging programme needs its own opt-in control",
  "statement": "A single opt-in control must not enrol the consumer into several messaging programmes or use cases at once.",
  "rationale": "One tick enrolling somebody into offers, delivery alerts and service notices gives them no way to keep the one they wanted and drop the two they did not — so the only exit is STOP, and the brand loses the whole relationship over a programme the consumer never asked for. It also makes the consent unprovable per programme, which is what a reviewer is checking.",
  "layer": "CONSENT_FLOW",
  "layerSlug": "consent-flow",
  "object": "opt-in surface control set",
  "severity": "BLOCKING",
  "detectability": [
    "CRAWL"
  ],
  "failureClass": "TERMINAL_WEBSITE",
  "authorities": [
    "Infobip",
    "Bandwidth",
    "CTIA"
  ],
  "applicability": {
    "consentMethods": [
      "web_form",
      "checkout",
      "account_settings",
      "third_party",
      "pos"
    ]
  },
  "applicabilityText": "Applies when consent was collected by web form, checkout, account settings, third party and point of sale.",
  "universal": false,
  "remediation": "Give each programme its own checkbox with its own description, and register each as its own campaign. Done when a consumer can join the rewards texts without joining the service alerts.",
  "example": "☐ Acme Coffee Rewards: offers and rewards balance updates.\n☐ Acme Coffee order updates: delivery and pickup notifications.",
  "pitfalls": [
    "Splitting the controls but sending both programmes from one campaign puts the split back where it started — the campaign registration has to match the control set."
  ],
  "notes": "The surface half of the scope rule. CON-SCOPE-SPLIT covers the specific and most common instance — promotional bundled with transactional — while this rule covers a control that spans several programmes of any kind. Where the only bundling is marketing-plus-transactional, report it there rather than twice.",
  "phase": "approval",
  "automated": true,
  "url": "https://ekas.io/rules/10dlc/consent-flow/con-130/",
  "markdown": "https://ekas.io/rules/10dlc/consent-flow/con-130.md",
  "registry": "https://ekas.io/rules/10dlc/",
  "updated": "2026-07-25",
  "licence": "CC BY 4.0 — https://creativecommons.org/licenses/by/4.0/"
}
