{
  "id": "POL-073",
  "slug": "pol-073",
  "title": "The policy should say the brand does not use rented or purchased lists",
  "statement": "The policy or SMS terms should state affirmatively that the brand does not message rented, sold or shared opt-in lists.",
  "rationale": "CTIA asks senders not to use such lists, and the affirmative statement is what a reviewer can actually check — the absence of purchased numbers is not visible in any document. It also matters to the consumer question underneath: someone receiving a message wants to know how the sender got their number, and this is the sentence that answers it.",
  "layer": "POLICY_PAGE",
  "layerSlug": "policy-page",
  "object": "privacy policy or SMS terms body",
  "severity": "HIGH",
  "detectability": [
    "AI_FORM"
  ],
  "failureClass": "TERMINAL_POLICY",
  "artifact": "sms_terms",
  "authorities": [
    "CTIA"
  ],
  "codes": [
    {
      "provider": "Bandwidth",
      "code": "7108",
      "remediable": true
    }
  ],
  "applicabilityText": "Applies to every 10DLC registration.",
  "universal": true,
  "remediation": "Add a sentence to the messaging section stating that every number was collected directly from the person it belongs to and that no rented, purchased or shared lists are used. Done when the document says where the numbers come from.",
  "example": "Every number in the Acme Coffee text programme was given to us directly by its owner. We do not rent, buy or use lists of numbers collected by anyone else.",
  "phase": "approval",
  "automated": true,
  "url": "https://ekas.io/rules/10dlc/policy-page/pol-073/",
  "markdown": "https://ekas.io/rules/10dlc/policy-page/pol-073.md",
  "registry": "https://ekas.io/rules/10dlc/",
  "updated": "2026-07-25",
  "licence": "CC BY 4.0 — https://creativecommons.org/licenses/by/4.0/"
}
