{
  "id": "POL-016",
  "slug": "pol-016",
  "title": "The privacy policy URL must open an actual privacy policy",
  "statement": "The privacy policy URL must resolve to a real privacy policy — not the homepage, a stub, a placeholder, or a generic landing page.",
  "rationale": "A URL that opens something other than a policy is read as a policy that failed review, so the rejection blames the document rather than the link. It happens through ordinary site maintenance: the policy path is retired in a redesign and the server helpfully serves the home page instead of a 404, which is worse than the 404 because nothing looks broken.",
  "layer": "POLICY_PAGE",
  "layerSlug": "policy-page",
  "object": "privacy policy body (document classification)",
  "severity": "BLOCKING",
  "detectability": [
    "AI_FORM"
  ],
  "failureClass": "TERMINAL_POLICY",
  "artifact": "privacy_policy",
  "authorities": [
    "Bandwidth",
    "Telnyx",
    "AWS",
    "Ringover"
  ],
  "codes": [
    {
      "provider": "Bandwidth",
      "code": "7102",
      "remediable": true
    }
  ],
  "applicabilityText": "Applies to every 10DLC registration.",
  "universal": true,
  "remediation": "Point the field at the page whose content is the policy, and confirm what it opens rather than trusting the path. Done when the URL loads a document headed as a privacy policy and containing its sections.",
  "phase": "approval",
  "automated": true,
  "url": "https://ekas.io/rules/10dlc/policy-page/pol-016/",
  "markdown": "https://ekas.io/rules/10dlc/policy-page/pol-016.md",
  "registry": "https://ekas.io/rules/10dlc/",
  "updated": "2026-07-25",
  "licence": "CC BY 4.0 — https://creativecommons.org/licenses/by/4.0/"
}
