{
  "id": "CON-132",
  "slug": "con-132",
  "title": "Email or voice consent does not become SMS consent",
  "statement": "Consent collected for email or phone calls must not be treated as consent to text, and an email list must not be migrated to SMS without a fresh opt-in.",
  "rationale": "Consent runs to a channel, and the consumer who gave an address for a newsletter made no decision about their phone. Migrating a list is the single most common way a careful brand acquires numbers it has no consent for, because the numbers were genuinely volunteered and the brand genuinely has a relationship — everything about it feels legitimate except the part that matters.",
  "layer": "CONSENT_FLOW",
  "layerSlug": "consent-flow",
  "object": "consent scope; list provenance",
  "severity": "BLOCKING",
  "detectability": [
    "AI_FORM"
  ],
  "failureClass": "HARD_STOP",
  "authorities": [
    "Bandwidth",
    "T-Mobile",
    "Twilio",
    "CTIA"
  ],
  "applicabilityText": "Applies to every 10DLC registration.",
  "universal": true,
  "remediation": "Numbers whose only consent was for another channel cannot be messaged under any use case. Re-permission them first: email the list asking them to opt in to texts, and send only to those who complete the SMS opt-in. The email invitation is not the consent — the landing page they submit is.",
  "notes": "HARD_STOP because there is no field that fixes it: the defect is which numbers are on the list, not how the campaign is described. The remediation is a real path, but it happens before registration rather than inside it.",
  "catalogIds": [
    "CON-136"
  ],
  "phase": "approval",
  "automated": true,
  "url": "https://ekas.io/rules/10dlc/consent-flow/con-132/",
  "markdown": "https://ekas.io/rules/10dlc/consent-flow/con-132.md",
  "registry": "https://ekas.io/rules/10dlc/",
  "updated": "2026-07-25",
  "licence": "CC BY 4.0 — https://creativecommons.org/licenses/by/4.0/"
}
