{
  "id": "OPS-219",
  "slug": "ops-219",
  "title": "Opt-out records must be retained alongside opt-ins",
  "statement": "Revocation requests must be retained for the same period as opt-ins, with the channel recorded.",
  "rationale": "Proving someone opted in is only half the defence — the other half is proving you stopped when they asked, and when. Revocations arrive by text, call and email, so the channel matters: a revocation taken by a phone agent must reach the same suppression list as a texted STOP.",
  "layer": "OPERATIONAL",
  "layerSlug": "operational",
  "object": "campaign.message_flow + privacy policy",
  "severity": "HIGH",
  "detectability": [
    "AI_FORM"
  ],
  "failureClass": "RETRY_FIELD",
  "authorities": [
    "CTIA",
    "FCC"
  ],
  "applicabilityText": "Applies to every 10DLC registration.",
  "universal": true,
  "remediation": "Retain revocations for the same period as consents, record the channel each arrived on, and route revocations captured by agents or IVR into the same suppression list as texted opt-outs.",
  "example": "Opt-outs are stored with the number, timestamp, and channel (SMS, phone, email), retained for four years alongside consent records.",
  "phase": "approval",
  "automated": true,
  "url": "https://ekas.io/rules/10dlc/operational/ops-219/",
  "markdown": "https://ekas.io/rules/10dlc/operational/ops-219.md",
  "registry": "https://ekas.io/rules/10dlc/",
  "updated": "2026-07-25",
  "licence": "CC BY 4.0 — https://creativecommons.org/licenses/by/4.0/"
}
