{
  "id": "POL-060",
  "slug": "pol-060",
  "title": "No exception may permit sharing SMS opt-in data",
  "statement": "The privacy policy must contain no exception, carve-out or \"except where\" clause that permits SMS opt-in data to be shared.",
  "rationale": "Bandwidth's reviewer reads the prohibition as admitting no exception at all, so a policy that promises not to share and then lists the circumstances in which it will is read on the list rather than on the promise. The exceptions are almost always drafted for good reasons — a merger, a partner integration, an analytics vendor — and each one reopens exactly the door the clause was written to close.",
  "layer": "POLICY_PAGE",
  "layerSlug": "policy-page",
  "object": "privacy policy body (whole document)",
  "severity": "BLOCKING",
  "detectability": [
    "AI_FORM"
  ],
  "failureClass": "TERMINAL_POLICY",
  "artifact": "privacy_policy",
  "authorities": [
    "Bandwidth",
    "AWS"
  ],
  "codes": [
    {
      "provider": "Bandwidth/DCA",
      "code": "7109",
      "remediable": true
    }
  ],
  "applicabilityText": "Applies to every 10DLC registration.",
  "universal": true,
  "remediation": "Delete every exception attached to the messaging non-sharing clause, keeping only the narrow service-provider carve-back for the vendors that deliver the messages. Done when the clause has no \"except\", \"unless\" or \"other than\" hanging off it besides that one.",
  "example": "No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. We disclose it only to the service providers who deliver our messages, and to no one else.",
  "pitfalls": [
    "A merger or acquisition clause counts as an exception here, even though it is standard in every other part of a privacy policy. Exclude messaging data from it explicitly rather than relying on it being obviously different."
  ],
  "notes": "Genuine implementation divergence, recorded rather than resolved: Bandwidth 7109 as written admits no exception, while Infobip, Telnyx and Alive5 require the service-provider carve-back that POL-058 asks for. The product has to draft that carve-back narrowly enough to survive a 7109 reviewer, and a policy carrying both patterns is worth a human look. Absorbs POL-059, which names the common shape — an exception for partners, advertisers or lead buyers.",
  "catalogIds": [
    "POL-059"
  ],
  "phase": "approval",
  "automated": true,
  "url": "https://ekas.io/rules/10dlc/policy-page/pol-060/",
  "markdown": "https://ekas.io/rules/10dlc/policy-page/pol-060.md",
  "registry": "https://ekas.io/rules/10dlc/",
  "updated": "2026-07-25",
  "licence": "CC BY 4.0 — https://creativecommons.org/licenses/by/4.0/"
}
