{
  "id": "CON-137",
  "slug": "con-137",
  "title": "The consent record must capture the number it authorises",
  "statement": "The consent record must store the specific telephone number the consumer authorised messages to be sent to.",
  "rationale": "The federal definition of written consent turns on the number the signatory authorised, so a record proving somebody consented without recording which number they consented for cannot be matched to the message that was sent. It is the failure that surfaces late and badly: the brand has thousands of consent records and cannot tie any of them to the number in the complaint.",
  "layer": "CONSENT_FLOW",
  "layerSlug": "consent-flow",
  "object": "consent artifact phone field",
  "severity": "BLOCKING",
  "detectability": [
    "CRAWL"
  ],
  "failureClass": "TERMINAL_EVIDENCE",
  "authorities": [
    "FCC",
    "SIP.US"
  ],
  "applicabilityText": "Applies to every 10DLC registration.",
  "universal": true,
  "remediation": "Store the number on the consent record itself, in the form it was given, next to the timestamp and the disclosure version. Done when you can take any number from your sending list and produce the record that authorised it.",
  "example": "Each consent record stores: phone number, timestamp, collection surface, disclosure version shown, and the session or agent identity.",
  "pitfalls": [
    "Storing consent against a customer account rather than a number breaks the moment somebody changes their number, and the old number stays on the sending list with a record that no longer describes it."
  ],
  "notes": "Judged from what the flow and the artifact say about the record, since the record itself is the brand's own system. OPS-205 states the same field requirement on the retained record.",
  "catalogIds": [
    "OPS-205"
  ],
  "phase": "approval",
  "automated": true,
  "url": "https://ekas.io/rules/10dlc/consent-flow/con-137/",
  "markdown": "https://ekas.io/rules/10dlc/consent-flow/con-137.md",
  "registry": "https://ekas.io/rules/10dlc/",
  "updated": "2026-07-25",
  "licence": "CC BY 4.0 — https://creativecommons.org/licenses/by/4.0/"
}
