{
  "id": "MSG-175",
  "slug": "msg-175",
  "title": "Content must not invade privacy, defame, or otherwise cause harm",
  "statement": "Message content must not invade privacy, create a safety risk, or be unlawful, abusive, malicious, misleading, excessively violent, obscene or defamatory.",
  "rationale": "CTIA's residual harm clause is what catches the damage nobody wrote a category for — a message that names a third party's debt, address or medical appointment to somebody else, or that asserts something ruinous about a named business. The recipient of a privacy leak is not the person harmed by it, which is why no complaint-driven check finds these and why the clause is written as a sweep. Businesses reach it innocently through personalisation: a template that renders the wrong record, or a referral message that tells the recipient why their friend needs the service.",
  "layer": "MESSAGE_CONTENT",
  "layerSlug": "message-content",
  "object": "campaign.sample[] + campaign.description",
  "severity": "BLOCKING",
  "detectability": [
    "AI_FORM"
  ],
  "failureClass": "HARD_STOP",
  "authorities": [
    "CTIA"
  ],
  "applicabilityText": "Applies to every 10DLC registration.",
  "universal": true,
  "remediation": "Strip any third-party detail out of the message body and address the recipient about their own relationship with you only. Where personalisation pulls in another person's data — a referrer, a dependent, a co-signer — replace it with a reference the recipient already holds, and remove any assertion about a named business you cannot document.",
  "pitfalls": [
    "A message that is accurate can still fail this: disclosing a true fact about someone who is not the recipient is the violation, not getting it wrong."
  ],
  "notes": "This is CTIA MPBP §5.3.1, which is written as a catch-all covering several harms that have dedicated rules elsewhere. It is kept whole rather than split so the limbs nobody else owns — privacy invasion, safety risk and defamation — are not lost between rules; the criteria route the overlapping limbs so a single defect is reported once.",
  "phase": "approval",
  "automated": true,
  "url": "https://ekas.io/rules/10dlc/message-content/msg-175/",
  "markdown": "https://ekas.io/rules/10dlc/message-content/msg-175.md",
  "registry": "https://ekas.io/rules/10dlc/",
  "updated": "2026-07-25",
  "licence": "CC BY 4.0 — https://creativecommons.org/licenses/by/4.0/"
}
