# POL-050 — Privacy policy must state mobile opt-in data is not shared or sold

> The privacy policy must explicitly state that mobile information and SMS consent are not shared or sold to third parties or affiliates for marketing.

- **Rule ID:** POL-050
- **Layer:** Policy pages (`POLICY_PAGE`)
- **Checks:** `privacy policy body`
- **Severity:** BLOCKING — Breaking this rule gets the submission rejected outright.
- **When it bites:** Gates approval — get this wrong and registration is refused
- **How it is detected:** AI judgement over the crawled website or policy page
- **Fix type:** Fix the privacy policy or SMS terms
- **Required by:** TCR, Twilio, T-Mobile, Bandwidth, AWS, Telnyx
- **Applies:** Applies to every 10DLC registration.
- **Canonical URL:** https://ekas.io/rules/10dlc/policy-page/pol-050/

## Why this rule exists

This is the single most frequently cited cause of 10DLC rejection in the entire corpus. Carriers require it because SMS consent is non-transferable: the clause is the written promise that the number you collected will not become someone else's marketing list. Note it is a carrier and TCR requirement, not a CTIA one — CTIA never asks for this sentence, so guidance attributing it there is wrong and leads people to skip it.

## How to fix it

Add an explicit mobile-data clause to the privacy policy. Paste the language below verbatim — reviewers look for this specific formulation, and paraphrases that soften "will not be shared" routinely fail.

## Example of a compliant value

```text
No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. All the above categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.
```

## Provider rejection codes

| Provider | Code | Resubmission allowed |
| --- | --- | --- |
| Twilio (gen1) | `30908` | yes |
| Twilio (gen2) | `30932` | yes |
