{
  "id": "POL-025",
  "slug": "pol-025",
  "title": "Exactly one privacy policy must be discoverable",
  "statement": "The brand domain must present a single discoverable privacy policy, not several copies or versions.",
  "rationale": "Two policies mean a reviewer has to guess which one governs, and Twilio treats that ambiguity as preventing review rather than as a tidiness problem. The usual cause is a platform default left in place beside a custom one — a Shopify or Wix policy page still reachable at its original path while the real one lives somewhere else — so both are live and neither is wrong.",
  "layer": "POLICY_PAGE",
  "layerSlug": "policy-page",
  "object": "all discoverable privacy policies on the brand domain",
  "severity": "HIGH",
  "detectability": [
    "CRAWL"
  ],
  "failureClass": "TERMINAL_POLICY",
  "artifact": "privacy_policy",
  "authorities": [
    "Twilio",
    "AWS"
  ],
  "codes": [
    {
      "provider": "Twilio",
      "code": "30908",
      "remediable": true,
      "generation": "gen1"
    }
  ],
  "applicabilityText": "Applies to every 10DLC registration.",
  "universal": true,
  "remediation": "Delete or redirect every policy page except the canonical one, including the platform default at its original path, and point every link at the survivor. Done when searching your own site for \"privacy\" returns one document.",
  "notes": "Needs a multi-page crawl to settle. Against a single-page fetch the judge can only report what it saw, so it must say which pages it read rather than treating one policy found as one policy existing.",
  "phase": "approval",
  "automated": true,
  "url": "https://ekas.io/rules/10dlc/policy-page/pol-025/",
  "markdown": "https://ekas.io/rules/10dlc/policy-page/pol-025.md",
  "registry": "https://ekas.io/rules/10dlc/",
  "updated": "2026-07-25",
  "licence": "CC BY 4.0 — https://creativecommons.org/licenses/by/4.0/"
}
