# OPS-RETENTION-STATED — Consent record retention period should be stated

> The programme should state how long consent and opt-out records are retained.

- **Rule ID:** OPS-RETENTION-STATED
- **Layer:** Operational (`OPERATIONAL`)
- **Checks:** `campaign.message_flow + privacy policy`
- **Severity:** MEDIUM — Usually survives review, but lowers your trust score or invites manual review.
- **When it bites:** Gates approval — get this wrong and registration is refused
- **How it is detected:** AI judgement over the submitted form
- **Fix type:** Fix the field — a better value in the form clears it
- **Required by:** CTIA, FCC
- **Applies:** Applies to every 10DLC registration.
- **Canonical URL:** https://ekas.io/rules/10dlc/operational/ops-retention-stated/

## Why this rule exists

Retention is what lets you answer a complaint eighteen months later, and CTIA sets a floor of six months after opt-out while TCPA exposure runs to four years. A programme that never says how long it keeps records usually has not decided, which is the same as not retaining.

## How to fix it

State a retention period covering both consent and opt-out records. Four years matches the TCPA statute of limitations and comfortably exceeds the CTIA floor.

## Example of a compliant value

```text
We retain consent and opt-out records for four years from the date of collection or revocation.
```
