{
  "id": "CON-IMPORTED-LIST",
  "slug": "con-imported-list",
  "title": "Imported or legacy lists must evidence original consent",
  "statement": "A campaign messaging a pre-existing list must describe when and how that consent was originally obtained.",
  "rationale": "An existing customer relationship is not by itself consent to send marketing texts. Where the original opt-in cannot be described, there is nothing to audit, and the practical risk is that the list predates any SMS disclosure at all.",
  "layer": "CONSENT_FLOW",
  "layerSlug": "consent-flow",
  "object": "campaign.message_flow",
  "severity": "HIGH",
  "detectability": [
    "AI_FORM"
  ],
  "failureClass": "TERMINAL_EVIDENCE",
  "authorities": [
    "CTIA",
    "TCR",
    "FCC"
  ],
  "applicability": {
    "consentMethods": [
      "imported"
    ]
  },
  "applicabilityText": "Applies when consent was collected by imported list.",
  "universal": false,
  "remediation": "Describe the original collection surface and approximate date, and attach evidence of the disclosure used then. Where you cannot, re-permission the list with a fresh opt-in before messaging it.",
  "example": "Numbers were collected between 2023 and 2026 at checkout on acmecoffee.com using the disclosure shown in the attached screenshot; the consent date is stored per record.",
  "catalogIds": [
    "CON-140"
  ],
  "phase": "approval",
  "automated": true,
  "url": "https://ekas.io/rules/10dlc/consent-flow/con-imported-list/",
  "markdown": "https://ekas.io/rules/10dlc/consent-flow/con-imported-list.md",
  "registry": "https://ekas.io/rules/10dlc/",
  "updated": "2026-07-25",
  "licence": "CC BY 4.0 — https://creativecommons.org/licenses/by/4.0/"
}
