# POL-191 — The terms must say the opt-in applies to this programme only

> The SMS terms must state that the opt-in applies only to this brand's programme and is not transferable or assignable.

- **Rule ID:** POL-191
- **Layer:** Policy pages (`POLICY_PAGE`)
- **Checks:** `SMS terms body`
- **Severity:** HIGH — Rejected by at least one carrier or provider, and a common cause of failure at the rest.
- **When it bites:** Gates approval — get this wrong and registration is refused
- **How it is detected:** AI judgement over the crawled website or policy page
- **Fix type:** Fix the privacy policy or SMS terms
- **Required by:** CTIA, Twilio, Bandwidth
- **Applies:** Applies to every 10DLC registration.
- **Canonical URL:** https://ekas.io/rules/10dlc/policy-page/pol-191/

## Why this rule exists

CTIA states that an opt-in should not be transferable, and putting it in the terms is what turns the principle into something the subscriber has been told. Its absence is what a reviewer reads when they are deciding whether a brand understands that consent names a sender — the whole affiliate-marketing prohibition rests on the same idea.

## How to fix it

Add the sentence to the terms, naming the brand rather than saying "us". Done when the document states that the consent covers this programme and travels nowhere.

## Example of a compliant value

```text
Your consent covers the Acme Coffee Rewards programme only. We do not transfer or assign it to any other business, including any company that might acquire us.
```

## Provider rejection codes

| Provider | Code | Resubmission allowed |
| --- | --- | --- |
| Twilio (gen2) | `30932` | yes |

## Notes

The positive form of POL-072, which fails a document that describes consent as assignable. This one fails a document that says nothing.
