{
  "id": "CON-QR-DEST",
  "slug": "con-qr-dest",
  "title": "QR opt-in must resolve to a compliant surface",
  "statement": "A QR code used for opt-in must land on a page carrying the full consent disclosure, or the disclosure must be printed beside the code.",
  "rationale": "A QR code carries no information a consumer can evaluate — it is an opaque instruction to trust wherever it goes. The disclosure therefore has to exist either next to the code or on the page it opens, and a QR that fires a pre-filled SMS bypasses both.",
  "layer": "CONSENT_FLOW",
  "layerSlug": "consent-flow",
  "object": "consent surface",
  "severity": "BLOCKING",
  "detectability": [
    "AI_FORM"
  ],
  "failureClass": "TERMINAL_ARTIFACT",
  "artifact": "qr_landing_copy",
  "authorities": [
    "CTIA",
    "TCR"
  ],
  "applicability": {
    "consentMethods": [
      "qr"
    ]
  },
  "applicabilityText": "Applies when consent was collected by QR code.",
  "universal": false,
  "remediation": "Point the QR at a hosted opt-in page carrying the full disclosure and a real checkbox, and supply that URL or a capture of it. If the code appears on print where you also control the surrounding space, print the disclosure beside it as well.",
  "pitfalls": [
    "A QR that opens a pre-filled \"text JOIN to 55512\" message collects no disclosed consent at all — the consumer never saw terms."
  ],
  "catalogIds": [
    "WEB-102"
  ],
  "phase": "approval",
  "automated": true,
  "url": "https://ekas.io/rules/10dlc/consent-flow/con-qr-dest/",
  "markdown": "https://ekas.io/rules/10dlc/consent-flow/con-qr-dest.md",
  "registry": "https://ekas.io/rules/10dlc/",
  "updated": "2026-07-25",
  "licence": "CC BY 4.0 — https://creativecommons.org/licenses/by/4.0/"
}
