{
  "id": "CON-DOUBLE-OPTIN-CART",
  "slug": "con-double-optin-cart",
  "title": "Abandoned-cart programs require double opt-in",
  "statement": "Abandoned-cart messaging requires a confirmed double opt-in and must not treat cart placement as consent.",
  "rationale": "Putting an item in a cart is explicitly not consent to be texted about it, and the number is usually linked to the cart by a cookie the consumer never saw. T-Mobile therefore mandates a confirmed double opt-in for this pattern specifically — one of the very few places double opt-in is required rather than optional.",
  "layer": "CONSENT_FLOW",
  "layerSlug": "consent-flow",
  "object": "campaign.message_flow",
  "severity": "BLOCKING",
  "detectability": [
    "AI_FORM"
  ],
  "failureClass": "TERMINAL_WEBSITE",
  "authorities": [
    "T-Mobile",
    "CTIA"
  ],
  "applicabilityText": "Applies to every 10DLC registration.",
  "universal": true,
  "remediation": "Add a confirmation step so the consumer opts in twice, disclose in your terms how the phone number is linked to the cart, send at most one notification per shopping event within 48 hours, and never allow order completion by text reply.",
  "notes": "Double opt-in is OPTIONAL under CTIA generally. Do not generalise this rule into a universal double-opt-in requirement.",
  "catalogIds": [
    "MSG-070"
  ],
  "phase": "approval",
  "automated": true,
  "url": "https://ekas.io/rules/10dlc/consent-flow/con-double-optin-cart/",
  "markdown": "https://ekas.io/rules/10dlc/consent-flow/con-double-optin-cart.md",
  "registry": "https://ekas.io/rules/10dlc/",
  "updated": "2026-07-25",
  "licence": "CC BY 4.0 — https://creativecommons.org/licenses/by/4.0/"
}
