{
  "id": "CON-AGE-GATE",
  "slug": "con-age-gate",
  "title": "Age-gated programs require real age verification at opt-in",
  "statement": "A campaign declaring age-gated content must verify age at the point of consent, not merely ask for self-attestation.",
  "rationale": "Robust age verification means electronic confirmation of age and identity, which in practice means collecting a full date of birth. The carrier discretion to waive age gating was removed in SCMH v1.8, so a self-attest tick box that used to be tolerated now fails, and the underlying content categories carry per-message violation fees.",
  "layer": "CONSENT_FLOW",
  "layerSlug": "consent-flow",
  "object": "consent surface",
  "severity": "BLOCKING",
  "detectability": [
    "CRAWL",
    "VISION"
  ],
  "failureClass": "TERMINAL_WEBSITE",
  "authorities": [
    "CTIA",
    "T-Mobile",
    "TCR"
  ],
  "applicability": {
    "attributes": {
      "ageGated": true
    }
  },
  "applicabilityText": "Applies when `ageGated` is true.",
  "universal": false,
  "remediation": "Collect a full date of birth (MM/DD/YYYY) at opt-in and reject under-age submissions server-side. Replace any \"I am 21 or older\" checkbox — self-attestation is not robust verification and is no longer waivable.",
  "catalogIds": [
    "WEB-108",
    "WEB-113"
  ],
  "phase": "approval",
  "automated": true,
  "url": "https://ekas.io/rules/10dlc/consent-flow/con-age-gate/",
  "markdown": "https://ekas.io/rules/10dlc/consent-flow/con-age-gate.md",
  "registry": "https://ekas.io/rules/10dlc/",
  "updated": "2026-07-25",
  "licence": "CC BY 4.0 — https://creativecommons.org/licenses/by/4.0/"
}
