{
  "id": "OPS-209",
  "slug": "ops-209",
  "title": "The consent record must say which act gave consent",
  "statement": "Every consent record must carry the confirmation method used — a ticked box, a click, or a replied keyword.",
  "rationale": "Two records can agree on number, timestamp and campaign and still describe completely different events: one consumer ticked an unchecked box, another replied YES to a text, a third was added by an agent. Those are not equally strong evidence, and a record that does not say which act happened cannot be graded — which is exactly the moment, months later, when it needs to be.",
  "layer": "OPERATIONAL",
  "layerSlug": "operational",
  "object": "campaign.message_flow + privacy policy",
  "severity": "MEDIUM",
  "detectability": [
    "AI_FORM"
  ],
  "failureClass": "RETRY_FIELD",
  "authorities": [
    "CTIA",
    "mytcrplus"
  ],
  "applicabilityText": "Applies to every 10DLC registration.",
  "universal": true,
  "remediation": "Store the specific act on each record — checkbox, button click, SMS reply, keypress, agent entry — rather than a boolean. Done when reading one record tells you what the consumer physically did.",
  "example": "Each opt-in stores confirmation_method: checkbox_ticked (or sms_reply_yes for double opt-ins).",
  "notes": "Registration-side twin: we judge whether the programme describes storing the field, never whether the stored record exists.",
  "phase": "approval",
  "automated": true,
  "url": "https://ekas.io/rules/10dlc/operational/ops-209/",
  "markdown": "https://ekas.io/rules/10dlc/operational/ops-209.md",
  "registry": "https://ekas.io/rules/10dlc/",
  "updated": "2026-07-25",
  "licence": "CC BY 4.0 — https://creativecommons.org/licenses/by/4.0/"
}
