# OPS-063 — Opt-out records must not be shared onward

> The published policy must not permit sharing or forwarding opt-out records to unaffiliated parties without the consumer's prior express permission.

- **Rule ID:** OPS-063
- **Layer:** Operational (`OPERATIONAL`)
- **Checks:** `privacy policy + SMS terms`
- **Severity:** MEDIUM — Usually survives review, but lowers your trust score or invites manual review.
- **When it bites:** Gates approval — get this wrong and registration is refused
- **How it is detected:** AI judgement over the crawled website or policy page
- **Fix type:** Fix the privacy policy or SMS terms
- **Required by:** FCC, CTIA
- **Applies:** Applies to every 10DLC registration.
- **Canonical URL:** https://ekas.io/rules/10dlc/operational/ops-063/

## Why this rule exists

A suppression list is a list of people who asked a specific sender to stop, and passing it on turns a refusal into a marketing asset — the consumer discovers that saying no put them on a new list. Policies allow it by accident: a general "we may share data with partners" clause written for analytics also covers the suppression file, because nobody carved it out.

## How to fix it

Add a sentence to the SMS section stating that opt-out and suppression records are used only to stop messages and are never sold, rented or shared. Done when a general sharing clause elsewhere in the policy no longer reads as covering them.

## Example of a compliant value

```text
Opt-out requests are recorded and used solely to suppress further messages. We do not sell, rent or share opt-out records with any third party.
```

## Common mistakes

- A carve-out in the SMS section does not help if a broader sharing clause earlier in the policy is unqualified — reviewers read the permissive clause as controlling.
