{
  "id": "POL-196",
  "slug": "pol-196",
  "title": "Opt-out information must appear in all three places",
  "statement": "Opt-out information must appear in the call to action, in the terms and conditions, and in the opt-in confirmation message.",
  "rationale": "CTIA asks for all three because they reach the subscriber at three different moments — before consenting, when checking later, and in the first message they receive — and the exit has to be visible at each. Satisfying one of them is the normal state of a programme that has never had this checked, and it is not a partial pass.",
  "layer": "POLICY_PAGE",
  "layerSlug": "policy-page",
  "object": "T&C body + call to action + opt-in confirmation",
  "severity": "BLOCKING",
  "detectability": [
    "AI_FORM"
  ],
  "failureClass": "TERMINAL_POLICY",
  "artifact": "sms_terms",
  "authorities": [
    "CTIA"
  ],
  "applicabilityText": "Applies to every 10DLC registration.",
  "universal": true,
  "remediation": "Put the STOP instruction in the opt-in disclosure, in the terms, and in the confirmation message. Done when all three carry it in the same words.",
  "example": "All three say: \"Reply STOP to opt out.\"",
  "notes": "A three-surface conjunction. The confirmation-message half is also checked from the message side; this rule is the one that reports the set as incomplete rather than reporting one surface.",
  "phase": "approval",
  "automated": true,
  "url": "https://ekas.io/rules/10dlc/policy-page/pol-196/",
  "markdown": "https://ekas.io/rules/10dlc/policy-page/pol-196.md",
  "registry": "https://ekas.io/rules/10dlc/",
  "updated": "2026-07-25",
  "licence": "CC BY 4.0 — https://creativecommons.org/licenses/by/4.0/"
}
