# CON-IMPORTED-LIST — Imported or legacy lists must evidence original consent

> A campaign messaging a pre-existing list must describe when and how that consent was originally obtained.

- **Rule ID:** CON-IMPORTED-LIST
- **Layer:** Consent flow (`CONSENT_FLOW`)
- **Checks:** `campaign.message_flow`
- **Severity:** HIGH — Rejected by at least one carrier or provider, and a common cause of failure at the rest.
- **When it bites:** Gates approval — get this wrong and registration is refused
- **How it is detected:** AI judgement over the submitted form
- **Fix type:** Supply evidence only you hold
- **Required by:** CTIA, TCR, FCC
- **Applies:** Applies when consent was collected by imported list.
- **Canonical URL:** https://ekas.io/rules/10dlc/consent-flow/con-imported-list/

## Why this rule exists

An existing customer relationship is not by itself consent to send marketing texts. Where the original opt-in cannot be described, there is nothing to audit, and the practical risk is that the list predates any SMS disclosure at all.

## How to fix it

Describe the original collection surface and approximate date, and attach evidence of the disclosure used then. Where you cannot, re-permission the list with a fresh opt-in before messaging it.

## Example of a compliant value

```text
Numbers were collected between 2023 and 2026 at checkout on acmecoffee.com using the disclosure shown in the attached screenshot; the consent date is stored per record.
```
