A2P 10DLC rule registry
Policy checks catch inverse traps as often as omissions: a policy that contains the required sentence and, four paragraphs later, a clause that contradicts it. These rules cover both documents, their URLs, their sharing language, and the specific sentences carriers require to be present and absent.
Every campaign registration must carry a non-empty privacy policy URL.
Every campaign registration must carry a non-empty terms and conditions URL.
Where a policy is uploaded rather than linked, the file must be a PDF, PNG or JPEG within the tightest provider size cap.
The campaign's terms-and-conditions attestation flag must be set to true, alongside supplying the URL.
The privacy policy and terms URLs must resolve in DNS and return a successful response to an anonymous fetch — no session, no cookie, no member wall.
The host serving the policy pages must present a valid TLS chain, checked independently of the brand website host.
The privacy policy URL must resolve to a real privacy policy — not the homepage, a stub, a placeholder, or a generic landing page.
The policy pages must be fetchable by an automated vetter — no robots.txt disallow, no noindex, no JS-only render, no geofence.
A reseller's, platform's, ISV's or generic vendor privacy policy must not be submitted in place of the brand's own.
Where consent is collected offline, the site hosting the policy pages must still be a live, authentic site rather than a shell built to hold them.
Verbal, IVR, keyword and email opt-in copy must state where the privacy policy can be found, or carry the disclosures inline.
A printed, QR or point-of-sale call to action must show a spelled-out, typeable URL for the terms and the privacy policy.
A QR opt-in landing page must link both a compliant privacy policy and compliant message-programme terms.
The policy pages must satisfy the full content requirements even where opt-in never happens on the web.
The privacy policy must explicitly state that mobile information and SMS consent are not shared or sold to third parties or affiliates for marketing.
The privacy policy must contain no exception, carve-out or "except where" clause that permits SMS opt-in data to be shared.
A policy permitting personal data to be shared with other companies is rejected whether or not it mentions SMS.
A privacy policy stating affirmatively that mobile opt-in data or consent is shared with third parties or affiliates is rejected.
The whole policy — not just the SMS section — must contain no clause permitting sale, rental, or sharing of personal data for third-party marketing.
The terms of service, the cookie policy and any separate data-sharing page must not contradict the SMS non-sharing clause in the privacy policy.
Neither the privacy policy nor the terms may reserve a right to sell, rent or share the consumer's consent.
The policy and the SMS terms must not describe messaging consent as transferable or assignable between businesses.
The policy must carry an explicit sentence excluding SMS opt-in data and consent from any sharing, whether or not it discloses sharing elsewhere.
The third-party data-sharing prohibition applies to a political brand's policy exactly as it does to a commercial one.
A charity or donation programme's policy must state that no entity other than the charity itself may use the subscriber data.
The privacy policy must identify the business: legal name, any DBA, postal address, email address and phone number.
The registered brand name or DBA must appear in the privacy policy the campaign links to.
Where the programme sends shopping-cart reminders, the policy must state explicitly how cart abandonment is detected.
Where the service is directed at children, the policy must carry the COPPA online-notice elements, including the categories of third parties that receive children's data and the purpose.
No policy, terms or message copy may state that a single named method is the only way to opt out.
The SMS terms must be published as a distinct, directly accessible document rather than only as a clause inside the general website terms.
The terms of service must contain a section covering the messaging programme, or a dedicated SMS terms page must exist.
The SMS terms must carry a description of the programme — what the messages are about.
The SMS terms must state how to stop the messages — "Reply STOP to cancel" or a clear equivalent.
The programme description in the SMS terms must relate to the use case the campaign is registered under.
The SMS terms must not indicate that consumer data or opt-in information is shared with third parties.
The SMS terms must contain no affiliate-marketing or lead-generation language anywhere.
Opt-out information must appear in the call to action, in the terms and conditions, and in the opt-in confirmation message.
The programme name or product description must appear both on the call to action and in the terms and conditions.
The legal entity named in the privacy policy, in the terms, and on the TCR brand record must be the same name.
A generated document must assert no fact about the business — retention periods, encryption, sub-processors, certifications, jurisdictions — that has not been sourced or confirmed by the user.
A URL submitted for a policy page must resolve directly rather than returning a 30x redirect.
A social-media profile or post must not be submitted as the privacy policy or terms URL where the brand has a website.
The brand domain must present a single discoverable privacy policy, not several copies or versions.
Where a policy document is uploaded with the registration and a policy also exists on the site, the two must not conflict.
The privacy policy and the terms must be linked from the footer of every page on the brand site.
The non-sharing statement must separately state that data is not shared — "we do not sell your data" alone is insufficient.
The prohibition must be unconditional — an "unless you consent" or "except where you have authorised" escape clause fails.
Generic policy-generator output such as "we may share with trusted partners" must be removed or narrowed to service providers.
Where the policy carries a CCPA "categories of personal information sold or shared" table, it must explicitly exclude phone numbers and SMS consent data.
Where the brand publishes a "Do Not Sell or Share My Personal Information" link, the policy must make clear that the SMS exclusion applies regardless.
The policy should state explicitly that the SMS non-sharing clause prevails over any other sharing language in the document.
Where the policy contains both a general sharing disclosure and an SMS-specific non-sharing clause, the two must be reconciled rather than left to contradict.
The policy or SMS terms should state affirmatively that the brand does not message rented, sold or shared opt-in lists.
A political organisation soliciting donations by text must communicate its privacy policy to donors and enforce it.
The privacy policy must describe what data the messaging programme collects.
The privacy policy must describe how phone numbers are obtained, consistently with the registered message flow.
The privacy policy must describe the purpose of the texting, consistently with the registered use case.
Where the campaign is not registered for marketing, the policy must not describe promotional or marketing texting.
The privacy policy must describe how the sender collects, uses and shares consumer information.
The privacy policy must describe how consumers can contact the sender about their information.
The privacy policy must give opt-out instructions inside the policy itself.
The privacy policy must disclose how often the programme sends messages.
The privacy policy must carry the "message and data rates may apply" disclosure.
The privacy policy must be consistent with the privacy law that applies to the business.
The practices described in the policy must match what the site and the programme actually do.
Where the programme sends shopping-cart reminders, the SMS terms must describe them.
The privacy policy must describe how location data is collected and why, where messaging is triggered by location.
The privacy policy must carry a children's-data section with a parental-consent route and a deletion route.
The privacy policy must publish a written data-retention policy for children's data, with the purpose, the justification and the deletion timeframe.
The business must maintain a written internal do-not-call policy and make it available on demand.
The privacy policy must list the categories of personal information collected, using the statutory category names.
The privacy policy must state the business or commercial purpose for each category of information, in terms a consumer can understand.
The privacy policy must list the categories of third parties personal information is disclosed, sold or shared to, and why.
The privacy policy must state whether personal information was sold or shared in the preceding twelve months, or affirmatively that it was not.
The privacy policy must enumerate the CCPA and CPRA consumer rights.
The privacy policy must give instructions for exercising consumer rights, including submission methods, verification and authorised agents.
Where the business sells or shares personal information, the "Do Not Sell or Share My Personal Information" link must be published on the site.
The privacy policy and the terms must each display the date they were last updated.
The SMS terms must cover the messaging programme specifically rather than restating general website terms.
The SMS terms must be near the top of the document or reachable by their own anchor, not buried inside terms about other services.
The live privacy policy and terms must contain no {curly brace} or {{PLACEHOLDER}} tokens left from a template.
The terms and the privacy policy must give up-to-date, accurate information about the programme's details and functionality.
The SMS terms section must disclose message frequency and that message and data rates may apply.
The SMS terms must state that a single confirmation message follows an opt-out and that nothing further is sent.
The SMS terms must contain the statement that consent is not a condition of any purchase.
The SMS terms must describe every way people join the programme, consistently with the registered message flow.
The SMS terms must name the keywords the programme honours for opting out and getting help.
Where the programme sends both transactional and promotional messages, the terms must distinguish them and describe the separate consent.
The SMS terms must state that the opt-in applies only to this brand's programme and is not transferable or assignable.
A Sweepstakes campaign's terms must contain the sweepstakes terms, or a link to them.
The terms of service must identify the legal entity the consumer is contracting with, and its address.
The terms of service must carry a contact block naming the entity, its address, an email address and a phone number.
The brand or DBA used in the message samples must match the brand name in the SMS terms and the name shown in the opt-in disclosure.
The message types described in the SMS terms, the registered use case and the sample messages must all agree.
The support email or phone number in the SMS terms must be one the HELP auto-reply also gives.
The opt-out keywords listed in the published SMS terms must be the same set declared on the campaign registration.
Every opt-in surface found by crawling the site must be represented in the list of opt-in methods in the SMS terms.
A generated policy or terms document must contain facts specific to this brand — real product names, the actual opt-in surfaces, the actual vendors.
Every unverified variable in a generated draft must be visibly marked, and export must be blocked until each is resolved.
Where the brand already publishes a policy, a generated replacement must be diffed against it and the removed clauses surfaced for review.
A generated policy or terms document must be exported with a visible disclaimer that it is not legal advice and should be reviewed by counsel.
Neither the product nor its output may claim that a generated policy makes the brand compliant or approved.
Where the brand is in a regulated vertical, the generated documents must be accompanied by a warning that sector rules apply on top of them.
A generated policy must not describe practices the brand does not actually perform.
Policy pages must be produced for a sole-proprietor brand on the same terms as for any other entity type.
Where the site is published in another language, an English version of the policy pages must exist.
The registered privacy policy and terms URLs must remain reachable after the campaign is approved.
Both policy pages should be captured at submission so the exact version that was reviewed can be produced later.
The policy should permit disclosure to the vendors that actually deliver the messages, while prohibiting everything else.
The privacy policy must describe how data is handled rather than marketing the messaging programme.
The privacy policy must state how message content is stored, for how long, who can read it, and whether it is used for analytics or AI.
The privacy policy must describe the safeguards protecting the information, at least at a high level.
The privacy policy must state how long data is kept and how consumers can access or delete it.
Where joining the programme earns a discount or other reward, the policy must carry a CCPA Notice of Financial Incentive that does not contradict the messaging clause.
The privacy policy must list the sources of the personal information it collects.
The privacy policy must state whether the business has actual knowledge that it sells or shares the personal information of consumers under 16.
The privacy policy must state whether sensitive personal information is used beyond the permitted purposes.
The privacy policy must name or categorise the third-party processors that handle personal information.
The privacy policy must disclose the cookies, pixels, SDKs and tracking it uses, and how to opt out of them.
The privacy policy must describe how it honours browser opt-out preference signals such as Global Privacy Control.
The privacy policy must carry a GDPR addendum naming the controller, the legal bases, transfers, withdrawal of consent and the right to complain.
The privacy policy must carry a section describing how changes to it are communicated.
The SMS terms should describe how someone can rejoin the programme after opting out.
The SMS terms must state that wireless carriers are not liable for delayed or undelivered messages.
The SMS terms should state the eligibility and minimum age for the programme, consistently with the privacy policy.
The SMS terms should state that the subscriber warrants the number is their own and will tell the brand if it changes or is deactivated.
The SMS terms should state that the brand may change or terminate the programme, and how notice will be given.
The SMS terms must link to the privacy policy, and the privacy policy should link back to the SMS terms.
The SMS terms must provide a support email or phone number a consumer can actually reach.
The terms of service must include an acceptance clause saying that using the service constitutes agreement.
The terms of service must include an eligibility clause stating who may use the service and any minimum age.
The services or products described in the terms must be consistent with what the campaign description says the business does.
The terms of service must include a commerce section covering orders, pricing, payment, taxes, subscriptions and auto-renewal.
The terms of service must include an acceptable-use or prohibited-conduct clause.
The terms of service must include a disclaimer of warranties, a limitation of liability and an indemnity.
Arbitration, class-action-waiver and governing-law language must be reviewed by counsel rather than generated.
The terms of service must include a governing-law and venue clause.
The minimum age in the terms' eligibility clause must not conflict with the age threshold in the privacy policy's children's section.
The last-updated dates on the privacy policy and the terms must be no older than the last material change to the messaging programme.
Where joining the programme earns a discount or reward, both the SMS terms and the privacy policy's financial-incentive notice must describe it.
Policy and terms text recognisable as generator boilerplate must be flagged, because reviewers reject it as evidence the business is not real.
The business should record who approved each published policy or terms document, and when.
The product should disclose that the SMS non-sharing language is a carrier and TCR requirement rather than a CTIA one.
The privacy policy must state its scope — which sites, apps and offline channels it applies to.
Where the business meets the applicability threshold of another US state privacy statute, the policy must carry that state's addendum.
The privacy policy must carry an accessibility statement or a route to an alternative format.
The privacy policy should be available in a form a consumer can print or save.
The STOP and HELP instructions must be legible in the rendered terms; bold typeface is no longer required.
The terms of service must include a clause covering accounts, registration and credential security.
The terms of service must include a section covering shipping, returns, refunds and cancellations, or links to those pages.
The terms of service must include a user-content clause covering licence, takedown and a DMCA agent.
The terms of service must include a clause stating who owns the site content and the marks.
The terms of service must include a third-party links and services disclaimer.
Marketing terms for email and other channels must be kept separate from the SMS consent terms.
The terms of service must include a termination and suspension clause.
The terms of service must include the standard boilerplate: severability, assignment, entire agreement, waiver, force majeure and notices.
Ekas runs every rule that gates approval, 823 of these 915, against your registration before it reaches the carrier. It reads your site, your policy pages and your opt-in the way a reviewer would, and hands you the fix, not just the verdict.