{
  "id": "OPS-251",
  "slug": "ops-251",
  "title": "Consent left unused for a month must be reconfirmed",
  "statement": "Where no message is sent within 30 days of collecting consent, the programme must reconfirm by double opt-in before its first send.",
  "rationale": "A consumer who signed up and heard nothing for a month has usually forgotten, changed number, or moved on, and the first message they eventually get reads as unsolicited — which is how it gets reported. The 30-day rule exists because that first message is also the one most likely to arrive at a reassigned number. Programmes hit it by launching a signup form months before the messaging goes live, which is the ordinary way to build a list and the exact shape the rule is about.",
  "layer": "OPERATIONAL",
  "layerSlug": "operational",
  "object": "campaign.message_flow",
  "severity": "BLOCKING",
  "detectability": [
    "AI_FORM"
  ],
  "failureClass": "RETRY_FIELD",
  "authorities": [
    "T-Mobile",
    "CTIA"
  ],
  "applicabilityText": "Applies to every 10DLC registration.",
  "universal": true,
  "remediation": "Describe the reconfirmation: numbers with no message inside 30 days of opt-in receive a single confirmation asking them to reply YES, and are not messaged further until they do. Done when the flow says what happens to a signup that goes unmessaged for a month.",
  "example": "Numbers not messaged within 30 days of opt-in are sent one reconfirmation (\"Reply YES to confirm you still want Acme Coffee texts\") and receive nothing further unless they reply.",
  "pitfalls": [
    "Sending the delayed first message with an opt-out line attached is not reconfirmation — the consumer is being messaged on stale consent, and the opt-out arrives after the message they did not expect."
  ],
  "notes": "Registration-side twin: whether the 30-day clock is honoured is runtime behaviour. What is decidable now is whether the programme has a rule for the case, which matters most for a list built before launch.",
  "phase": "approval",
  "automated": true,
  "url": "https://ekas.io/rules/10dlc/operational/ops-251/",
  "markdown": "https://ekas.io/rules/10dlc/operational/ops-251.md",
  "registry": "https://ekas.io/rules/10dlc/",
  "updated": "2026-07-25",
  "licence": "CC BY 4.0 — https://creativecommons.org/licenses/by/4.0/"
}
