{
  "id": "POL-041",
  "slug": "pol-041",
  "title": "Offline and keyword opt-in copy must carry the route to the policy",
  "statement": "Verbal, IVR, keyword and email opt-in copy must state where the privacy policy can be found, or carry the disclosures inline.",
  "rationale": "None of these surfaces has a link: a caller cannot click, and a keyword instruction on a poster is read rather than tapped. So the route has to be spoken or printed — a typeable address — or the disclosures have to be said out loud, and a script that mentions neither collects consent from someone who was never told where the terms are.",
  "layer": "POLICY_PAGE",
  "layerSlug": "policy-page",
  "object": "verbal script, IVR prompt, keyword CTA or opt-in email body",
  "severity": "BLOCKING",
  "detectability": [
    "AI_FORM"
  ],
  "failureClass": "TERMINAL_ARTIFACT",
  "artifact": "consent_disclosure",
  "authorities": [
    "Bandwidth",
    "AWS"
  ],
  "codes": [
    {
      "provider": "Bandwidth/DCA",
      "code": "7107",
      "remediable": true
    }
  ],
  "applicability": {
    "consentMethods": [
      "verbal_live",
      "verbal_ivr",
      "keyword",
      "email"
    ]
  },
  "applicabilityText": "Applies when consent was collected by live verbal, IVR, text-to-join keyword and email.",
  "universal": false,
  "remediation": "Add one sentence to the script or the opt-in copy naming where the terms and privacy policy live, spoken as a typeable address. Done when someone who only heard or read the opt-in knows where to find the policy.",
  "pitfalls": [
    "Naming the policy in the confirmation text is too late — the consumer has already consented. It has to be in the copy that asks."
  ],
  "notes": "Absorbs POL-042, which states the same requirement for keyword and email opt-in. A spoken or printed reference does not substitute for a compliant page: the policy it points at still has to satisfy the rest of this layer.",
  "catalogIds": [
    "POL-042"
  ],
  "phase": "approval",
  "automated": true,
  "url": "https://ekas.io/rules/10dlc/policy-page/pol-041/",
  "markdown": "https://ekas.io/rules/10dlc/policy-page/pol-041.md",
  "registry": "https://ekas.io/rules/10dlc/",
  "updated": "2026-07-25",
  "licence": "CC BY 4.0 — https://creativecommons.org/licenses/by/4.0/"
}
