{
  "id": "CMP-URL-DISTINCT",
  "slug": "cmp-url-distinct",
  "title": "Privacy policy and terms URLs must be different pages",
  "statement": "The privacy policy URL and the terms of service URL must not be the same page.",
  "rationale": "The privacy policy and the terms answer different questions — how data is handled versus what the program is — and reviewers check them separately. Brands routinely paste the same combined-legal-page URL into both fields, and a presence-only check passes it while a reviewer opening both links does not.",
  "layer": "CAMPAIGN",
  "layerSlug": "campaign",
  "object": "campaign.privacy_url + campaign.terms_url",
  "severity": "HIGH",
  "detectability": [
    "DETERMINISTIC"
  ],
  "failureClass": "RETRY_FIELD",
  "authorities": [
    "TCR",
    "Twilio"
  ],
  "applicabilityText": "Applies to every 10DLC registration.",
  "universal": true,
  "remediation": "Link the privacy policy and the terms of service separately. If you only have one combined page, publish a distinct SMS terms page.",
  "example": "Privacy: https://acmecoffee.com/privacy · Terms: https://acmecoffee.com/terms",
  "notes": "Catalog POL-017. Brands paste the same URL twice constantly and \"both fields present\" passes today.",
  "catalogIds": [
    "POL-017"
  ],
  "phase": "approval",
  "automated": true,
  "url": "https://ekas.io/rules/10dlc/campaign/cmp-url-distinct/",
  "markdown": "https://ekas.io/rules/10dlc/campaign/cmp-url-distinct.md",
  "registry": "https://ekas.io/rules/10dlc/",
  "updated": "2026-07-25",
  "licence": "CC BY 4.0 — https://creativecommons.org/licenses/by/4.0/"
}
