{
  "id": "OPS-252",
  "slug": "ops-252",
  "title": "Consent collected away from the handset should be confirmed on it",
  "statement": "Where consent is collected outside the SMS channel — web, phone, point of sale or paper — the programme should send a double opt-in confirmation before recurring messages.",
  "rationale": "Off-channel opt-ins are the ones where the number can be wrong: mistyped on a form, misheard on a call, or written illegibly on a card. A confirmation text is the only step that proves the number reached the person who agreed, and it converts a typo from a stranger receiving your marketing into a message nobody answers. It is also what a carrier looks for when a programme built from paper forms starts generating complaints.",
  "layer": "OPERATIONAL",
  "layerSlug": "operational",
  "object": "campaign.message_flow + campaign.optin_message",
  "severity": "HIGH",
  "detectability": [
    "AI_FORM"
  ],
  "failureClass": "RETRY_FIELD",
  "authorities": [
    "T-Mobile",
    "CTIA"
  ],
  "applicability": {
    "excludeConsentMethods": [
      "keyword"
    ]
  },
  "applicabilityText": "Applies when consent was NOT collected by text-to-join keyword.",
  "universal": false,
  "remediation": "Send one confirmation to the number as collected, asking for a reply to activate, and enrol only on that reply. Where a full double opt-in is not workable, at minimum send a single confirmation that names the brand and how to stop before any other message. Done when the flow says what the number receives first.",
  "example": "After a checkout opt-in we text: \"Acme Coffee: reply YES to confirm you want offers and order updates. Msg&data rates may apply. Reply STOP to cancel.\" Numbers are enrolled only on YES.",
  "notes": "Not tagged away from paper, point-of-sale or verbal methods — those are the cases it exists for. It is excluded only where consent arrived on the handset itself, as an SMS keyword, since the number is already proven there.",
  "phase": "approval",
  "automated": true,
  "url": "https://ekas.io/rules/10dlc/operational/ops-252/",
  "markdown": "https://ekas.io/rules/10dlc/operational/ops-252.md",
  "registry": "https://ekas.io/rules/10dlc/",
  "updated": "2026-07-25",
  "licence": "CC BY 4.0 — https://creativecommons.org/licenses/by/4.0/"
}
