# OPS-261 — Only the charity may use the numbers a charity collects

> A charitable programme must let no entity other than the charity use the collected subscriber data, and only for the campaign it was collected for.

- **Rule ID:** OPS-261
- **Layer:** Operational (`OPERATIONAL`)
- **Checks:** `campaign.message_flow + privacy policy`
- **Severity:** BLOCKING — Breaking this rule gets the submission rejected outright.
- **When it bites:** Gates approval — get this wrong and registration is refused
- **How it is detected:** AI judgement over the submitted form
- **Fix type:** Fix the field — a better value in the form clears it
- **Required by:** T-Mobile, CTIA
- **Applies:** Applies when the use case is CHARITY.
- **Canonical URL:** https://ekas.io/rules/10dlc/operational/ops-261/

## Why this rule exists

Charitable messaging gets favourable treatment because donors are giving to a cause, not entering a marketing relationship — and the data is unusually valuable precisely because it identifies people who give. The restriction is absolute for that reason: no agency, no fundraising partner, no affiliated foundation. It is broken innocently when the campaign is run by an agency whose own platform holds the list.

## How to fix it

State that subscriber data collected by the programme is used only by the charity and only for this campaign, and that no partner, agency or affiliate uses any part of it. Where an agency operates the sending, say it processes the data for the charity and holds no independent right to it. Done when the flow and the policy agree that the charity is the only user.

## Example of a compliant value

```text
Numbers collected by Riverside Shelter's text programme are used only by Riverside Shelter and only for this campaign; our messaging agency processes them on our behalf and may not use them for anything else.
```

## Common mistakes

- Naming an agency as a joint controller, or a parent foundation as a permitted recipient, breaks the restriction even where both are non-profits.
