{
  "id": "OPS-240",
  "slug": "ops-240",
  "title": "Recordings must outlive the consent records they evidence",
  "statement": "Call recordings must be retained at least as long as the consent records they are the evidence for.",
  "rationale": "Recording retention is usually set by the telephony platform for quality-monitoring reasons — thirty or ninety days is a common default — while consent records are kept for years. The result is a consent record that points at a recording which was deleted long before anyone asked for it, and nobody notices because both systems are behaving exactly as configured.",
  "layer": "OPERATIONAL",
  "layerSlug": "operational",
  "object": "campaign.message_flow + privacy policy",
  "severity": "HIGH",
  "detectability": [
    "AI_FORM"
  ],
  "failureClass": "RETRY_FIELD",
  "authorities": [
    "FTC",
    "CTIA",
    "practice"
  ],
  "applicability": {
    "consentMethods": [
      "verbal_live",
      "verbal_ivr"
    ]
  },
  "applicabilityText": "Applies when consent was collected by live verbal and IVR.",
  "universal": false,
  "remediation": "Raise the recording retention on the telephony platform to match the consent retention window, or export the consent calls into the consent store. Done when the recording retention setting is at least as long as the period stated for consent records.",
  "example": "Consent-call recordings are retained for four years, matching the consent-record retention period.",
  "pitfalls": [
    "A blanket increase across every call is expensive and usually unnecessary — tag the consent calls and retain those, rather than the whole queue."
  ],
  "phase": "approval",
  "automated": true,
  "url": "https://ekas.io/rules/10dlc/operational/ops-240/",
  "markdown": "https://ekas.io/rules/10dlc/operational/ops-240.md",
  "registry": "https://ekas.io/rules/10dlc/",
  "updated": "2026-07-25",
  "licence": "CC BY 4.0 — https://creativecommons.org/licenses/by/4.0/"
}
