{
  "id": "POL-232",
  "slug": "pol-232",
  "title": "Every opt-in surface on the site must appear in the terms",
  "statement": "Every opt-in surface found by crawling the site must be represented in the list of opt-in methods in the SMS terms.",
  "rationale": "This is the same question as POL-181 asked from the other side, and it catches the case the declared flow cannot: a sign-up form somebody built for a campaign months ago, still live, feeding the same programme. A subscriber who joined through it reads terms that do not describe how they got there.",
  "layer": "POLICY_PAGE",
  "layerSlug": "policy-page",
  "object": "crawled opt-in surfaces vs SMS terms opt-in list",
  "severity": "HIGH",
  "detectability": [
    "CRAWL"
  ],
  "failureClass": "TERMINAL_POLICY",
  "artifact": "sms_terms",
  "authorities": [
    "Twilio"
  ],
  "codes": [
    {
      "provider": "Twilio",
      "code": "30909",
      "remediable": true,
      "generation": "gen2"
    }
  ],
  "applicabilityText": "Applies to every 10DLC registration.",
  "universal": true,
  "remediation": "Inventory every form on the site that collects a mobile number for messaging, then either list it in the terms or take it down. Done when the terms describe every live route into the programme.",
  "notes": "Decided from the crawl rather than the declared flow, which is why it is separate from POL-181 — the two disagree independently, and this is the one that finds the surface nobody remembered.",
  "phase": "approval",
  "automated": true,
  "url": "https://ekas.io/rules/10dlc/policy-page/pol-232/",
  "markdown": "https://ekas.io/rules/10dlc/policy-page/pol-232.md",
  "registry": "https://ekas.io/rules/10dlc/",
  "updated": "2026-07-25",
  "licence": "CC BY 4.0 — https://creativecommons.org/licenses/by/4.0/"
}
