The consent record must capture the number it authorises
The requirementstatement
The consent record must store the specific telephone number the consumer authorised messages to be sent to.
- Severityseverity
- BlockingBLOCKINGBreaking this rule gets the submission rejected. There is no partial credit.
- When it bitesphase
- Gates approvalapprovalGet this wrong and the brand or campaign is refused at registration.
- What is checkedobject
- consent artifact phone field
- Where it liveslayer
- Consent flowCONSENT_FLOW
- How Ekas settles itdetectability
- AI · crawlCRAWL
- Needs your live site or policy page fetched and read. Ekas crawls it the way a reviewer would.
- What the fix involvesfailureClass
- Supply evidenceTERMINAL_EVIDENCE
- Needs proof only you hold: a screenshot, a recording, a scan of the form people signed.
- Who requires itauthorities
- FCCSIP.US
- When it appliesapplicabilityText
- Applies to every 10DLC registration.
Why this rule existsrationale
How to fix itremediation
Store the number on the consent record itself, in the form it was given, next to the timestamp and the disclosure version. Done when you can take any number from your sending list and produce the record that authorised it.
A compliant exampleexample
Each consent record stores: phone number, timestamp, collection surface, disclosure version shown, and the session or agent identity.
Common mistakespitfalls
- Storing consent against a customer account rather than a number breaks the moment somebody changes their number, and the old number stays on the sending list with a record that no longer describes it.
Notesnotes
Rules you will hit next
Other consent flow rules at the same severity. A registration is judged as a whole, not rule by rule.
CON-137 is one of 101 consent flow rules in the 915-rule 10DLC registry. Free to cite under CC BY 4.0.