{
  "id": "OPS-113",
  "slug": "ops-113",
  "title": "A state may impose its own opt-out and identification duties",
  "statement": "Where a state requires it, opt-out replies must be honoured and accurate sender identification maintained under that state's own rules.",
  "rationale": "Virginia and states like it restate obligations the federal rules already impose, which sounds redundant and is not: the state version comes with its own enforcement route and its own penalties, so a failure is actionable twice. It matters most for sender identification, where the federal framing is a carrier expectation and the state framing is a statute.",
  "layer": "OPERATIONAL",
  "layerSlug": "operational",
  "object": "opt-out handling and sender identification, per state",
  "severity": "HIGH",
  "detectability": [
    "HUMAN"
  ],
  "failureClass": "TERMINAL_EXTERNAL",
  "authorities": [
    "state law (VA)"
  ],
  "applicabilityText": "Applies to every 10DLC registration.",
  "universal": true,
  "remediation": "Identify the brand in every message and honour every opt-out immediately, which satisfies the state rules and the federal ones together. Done when no message leaves without the brand name in it.",
  "notes": "State law applied to traffic we cannot see. What the user has to do is treat the strictest state as the standard rather than maintaining per-state behaviour — the identification and opt-out duties are cheap to satisfy universally and expensive to get wrong once.",
  "phase": "post",
  "automated": false,
  "attestation": {
    "question": "Does every message leaving your programme carry the brand name, and is every opt-out honoured immediately?",
    "howToCheck": [
      "Treat the strictest state as the standard rather than maintaining per-state behaviour: identification and immediate opt-out are cheap universally.",
      "Read a real delivered message and confirm the brand is identifiable in it."
    ],
    "failureLooksLike": "Virginia and states like it restate federal duties with their own enforcement route and penalties, so one failure is actionable twice."
  },
  "url": "https://ekas.io/rules/10dlc/operational/ops-113/",
  "markdown": "https://ekas.io/rules/10dlc/operational/ops-113.md",
  "registry": "https://ekas.io/rules/10dlc/",
  "updated": "2026-07-25",
  "licence": "CC BY 4.0 — https://creativecommons.org/licenses/by/4.0/"
}
