{
  "id": "POL-044",
  "slug": "pol-044",
  "title": "The QR landing page must link a compliant policy and message-programme terms",
  "statement": "A QR opt-in landing page must link both a compliant privacy policy and compliant message-programme terms.",
  "rationale": "The landing page is the entire disclosure surface for a QR opt-in — there is no checkout, no footer the consumer arrived through, and nothing behind them. If the two documents are not linked there, the consumer consents having seen neither, and the printed piece cannot carry them because it has no links.",
  "layer": "POLICY_PAGE",
  "layerSlug": "policy-page",
  "object": "QR landing page link set",
  "severity": "BLOCKING",
  "detectability": [
    "CRAWL"
  ],
  "failureClass": "TERMINAL_WEBSITE",
  "authorities": [
    "Aerialink",
    "CTIA"
  ],
  "codes": [
    {
      "provider": "Bandwidth/DCA",
      "code": "852",
      "remediable": true
    }
  ],
  "applicability": {
    "consentMethods": [
      "qr"
    ]
  },
  "applicabilityText": "Applies when consent was collected by QR code.",
  "universal": false,
  "remediation": "Put both links next to the consent control on the landing page, not in a footer below the fold. Done when the page that collects the number also shows the way to both documents.",
  "notes": "The linked documents still have to satisfy the rest of this layer — a link to a non-compliant policy discharges this rule and fails POL-050 onward.",
  "phase": "approval",
  "automated": true,
  "url": "https://ekas.io/rules/10dlc/policy-page/pol-044/",
  "markdown": "https://ekas.io/rules/10dlc/policy-page/pol-044.md",
  "registry": "https://ekas.io/rules/10dlc/",
  "updated": "2026-07-25",
  "licence": "CC BY 4.0 — https://creativecommons.org/licenses/by/4.0/"
}
