No sender whose business is buying, selling or sharing consumer information

The requirementstatement

Campaign content must not promote the buying, selling or sharing of consumer information as a business model.

Severityseverity
BlockingBLOCKINGBreaking this rule gets the submission rejected. There is no partial credit.
When it bitesphase
Gates approvalapprovalGet this wrong and the brand or campaign is refused at registration.
What is checkedobject
campaign.description + campaign.sample[] + campaign.message_flow
How Ekas settles itdetectability
AI · formAI_FORM
A semantic question about what you wrote: whether a description matches a use case, whether a name looks like a filed entity. Judged by a model against written criteria.
What the fix involvesfailureClass
Hard stopHARD_STOP
Not remediable. Resubmitting will not help, and anyone offering to fix it is selling you a rejection.
Who requires itauthorities
Twilio
When it appliesapplicabilityText
Applies to every 10DLC registration.

Why this rule existsrationale

Every consent in the framework is held by one business for one relationship, so a sender whose business is moving consumer records between parties cannot hold the consent it is relying on — the person agreed to hear from somebody else. Twilio applies this to the sender rather than to the message, and explicitly to non-profits and political committees as well, because list-swapping is how their traffic is built too. That is the surprise: an organisation can have impeccable message copy and still be refused on what it does for a living.

How to fix itremediation

This is settled on the business model, so the fix is not in the message copy: stop selling or sharing consumer data for other parties' marketing, and make the privacy policy say so in the standard form — mobile information is never sold, rented, traded or shared with third parties or affiliates for their own marketing. Where a vendor genuinely only delivers the messages, name it as a processor rather than as a partner. Done when the policy, the website and the description all describe one business holding one relationship.

Common mistakespitfalls

  • The website and the privacy policy are read alongside the campaign, so a permissive data-sharing clause left in a generated policy fails this even when the business does not actually sell anything.

Provider rejection codescodes

The code you get back when this rule is what failed, and whether that provider lets you resubmit.

ProviderCodeResubmit
Twiliogen230951No
Twilio30468No

Rules you will hit next

6 other rules read campaign.description + campaign.sample[] + campaign.message_flow. Fixing one field to satisfy a single rule is how a resubmission trades one rejection for another, so read these before you change anything.

All message content rules

MSG-262 is one of 122 message content rules in the 915-rule 10DLC registry. Free to cite under CC BY 4.0.

Reading the rules is the easy part.

Ekas runs every rule that gates approval, 823 of these 915, against your registration before it reaches the carrier. It reads your site, your policy pages and your opt-in the way a reviewer would, and hands you the fix, not just the verdict.