{
  "id": "OPS-217",
  "slug": "ops-217",
  "title": "Consent must be tracked per consumer, not per list",
  "statement": "Consent must be recorded against the individual consumer rather than at list level.",
  "rationale": "List-level consent cannot answer whether a specific person agreed, which is the only question that matters in a complaint. It is also structurally how purchased lists get laundered into a programme — a list marked \"consented\" with no per-number provenance.",
  "layer": "OPERATIONAL",
  "layerSlug": "operational",
  "object": "campaign.message_flow",
  "severity": "HIGH",
  "detectability": [
    "AI_FORM"
  ],
  "failureClass": "RETRY_FIELD",
  "authorities": [
    "CTIA",
    "FCC",
    "TCR"
  ],
  "applicabilityText": "Applies to every 10DLC registration.",
  "universal": true,
  "remediation": "Record consent per phone number with its own timestamp and source, never as a property of a list or segment.",
  "example": "Each number carries its own consent timestamp, medium and disclosure version.",
  "phase": "approval",
  "automated": true,
  "url": "https://ekas.io/rules/10dlc/operational/ops-217/",
  "markdown": "https://ekas.io/rules/10dlc/operational/ops-217.md",
  "registry": "https://ekas.io/rules/10dlc/",
  "updated": "2026-07-25",
  "licence": "CC BY 4.0 — https://creativecommons.org/licenses/by/4.0/"
}
