# POL-060 — No exception may permit sharing SMS opt-in data

> The privacy policy must contain no exception, carve-out or "except where" clause that permits SMS opt-in data to be shared.

- **Rule ID:** POL-060
- **Layer:** Policy pages (`POLICY_PAGE`)
- **Checks:** `privacy policy body (whole document)`
- **Severity:** BLOCKING — Breaking this rule gets the submission rejected outright.
- **When it bites:** Gates approval — get this wrong and registration is refused
- **How it is detected:** AI judgement over the submitted form
- **Fix type:** Fix the privacy policy or SMS terms
- **Required by:** Bandwidth, AWS
- **Applies:** Applies to every 10DLC registration.
- **Canonical URL:** https://ekas.io/rules/10dlc/policy-page/pol-060/

## Why this rule exists

Bandwidth's reviewer reads the prohibition as admitting no exception at all, so a policy that promises not to share and then lists the circumstances in which it will is read on the list rather than on the promise. The exceptions are almost always drafted for good reasons — a merger, a partner integration, an analytics vendor — and each one reopens exactly the door the clause was written to close.

## How to fix it

Delete every exception attached to the messaging non-sharing clause, keeping only the narrow service-provider carve-back for the vendors that deliver the messages. Done when the clause has no "except", "unless" or "other than" hanging off it besides that one.

## Example of a compliant value

```text
No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. We disclose it only to the service providers who deliver our messages, and to no one else.
```

## Common mistakes

- A merger or acquisition clause counts as an exception here, even though it is standard in every other part of a privacy policy. Exclude messaging data from it explicitly rather than relying on it being obviously different.

## Provider rejection codes

| Provider | Code | Resubmission allowed |
| --- | --- | --- |
| Bandwidth/DCA | `7109` | yes |

## Notes

Genuine implementation divergence, recorded rather than resolved: Bandwidth 7109 as written admits no exception, while Infobip, Telnyx and Alive5 require the service-provider carve-back that POL-058 asks for. The product has to draft that carve-back narrowly enough to survive a 7109 reviewer, and a policy carrying both patterns is worth a human look. Absorbs POL-059, which names the common shape — an exception for partners, advertisers or lead buyers.
