{
  "id": "POL-058",
  "slug": "pol-058",
  "title": "A service-provider carve-back is required, not prohibited",
  "statement": "The policy should permit disclosure to the vendors that actually deliver the messages, while prohibiting everything else.",
  "rationale": "An absolute \"we never disclose your number to anyone\" is factually false — your platform, aggregator and the carriers all handle it — and a reviewer who spots the impossibility distrusts the rest of the policy. The correct shape is a narrow carve-back for message delivery.",
  "layer": "POLICY_PAGE",
  "layerSlug": "policy-page",
  "object": "privacy policy body",
  "severity": "MEDIUM",
  "detectability": [
    "CRAWL"
  ],
  "failureClass": "TERMINAL_POLICY",
  "artifact": "privacy_policy",
  "authorities": [
    "TCR",
    "Twilio"
  ],
  "applicabilityText": "Applies to every 10DLC registration.",
  "universal": true,
  "remediation": "Add a narrow carve-back naming the delivery chain, immediately after the non-sharing sentence.",
  "example": "We share your mobile number only with the service providers who deliver our messages (our messaging platform, aggregators, and wireless carriers), and for no other purpose.",
  "phase": "approval",
  "automated": true,
  "url": "https://ekas.io/rules/10dlc/policy-page/pol-058/",
  "markdown": "https://ekas.io/rules/10dlc/policy-page/pol-058.md",
  "registry": "https://ekas.io/rules/10dlc/",
  "updated": "2026-07-25",
  "licence": "CC BY 4.0 — https://creativecommons.org/licenses/by/4.0/"
}
