{
  "id": "OPS-063",
  "slug": "ops-063",
  "title": "Opt-out records must not be shared onward",
  "statement": "The published policy must not permit sharing or forwarding opt-out records to unaffiliated parties without the consumer's prior express permission.",
  "rationale": "A suppression list is a list of people who asked a specific sender to stop, and passing it on turns a refusal into a marketing asset — the consumer discovers that saying no put them on a new list. Policies allow it by accident: a general \"we may share data with partners\" clause written for analytics also covers the suppression file, because nobody carved it out.",
  "layer": "OPERATIONAL",
  "layerSlug": "operational",
  "object": "privacy policy + SMS terms",
  "severity": "MEDIUM",
  "detectability": [
    "CRAWL"
  ],
  "failureClass": "TERMINAL_POLICY",
  "artifact": "privacy_policy",
  "authorities": [
    "FCC",
    "CTIA"
  ],
  "applicabilityText": "Applies to every 10DLC registration.",
  "universal": true,
  "remediation": "Add a sentence to the SMS section stating that opt-out and suppression records are used only to stop messages and are never sold, rented or shared. Done when a general sharing clause elsewhere in the policy no longer reads as covering them.",
  "example": "Opt-out requests are recorded and used solely to suppress further messages. We do not sell, rent or share opt-out records with any third party.",
  "pitfalls": [
    "A carve-out in the SMS section does not help if a broader sharing clause earlier in the policy is unqualified — reviewers read the permissive clause as controlling."
  ],
  "phase": "approval",
  "automated": true,
  "url": "https://ekas.io/rules/10dlc/operational/ops-063/",
  "markdown": "https://ekas.io/rules/10dlc/operational/ops-063.md",
  "registry": "https://ekas.io/rules/10dlc/",
  "updated": "2026-07-25",
  "licence": "CC BY 4.0 — https://creativecommons.org/licenses/by/4.0/"
}
