No exception may permit sharing SMS opt-in data

The requirementstatement

The privacy policy must contain no exception, carve-out or "except where" clause that permits SMS opt-in data to be shared.

Severityseverity
BlockingBLOCKINGBreaking this rule gets the submission rejected. There is no partial credit.
When it bitesphase
Gates approvalapprovalGet this wrong and the brand or campaign is refused at registration.
What is checkedobject
privacy policy body (whole document)
Where it liveslayer
Policy pagesPOLICY_PAGE
How Ekas settles itdetectability
AI · formAI_FORM
A semantic question about what you wrote: whether a description matches a use case, whether a name looks like a filed entity. Judged by a model against written criteria.
What the fix involvesfailureClass
Fix the policyTERMINAL_POLICY
The fix lives in your privacy policy or SMS terms. Ekas can generate the missing clauses.
Who requires itauthorities
BandwidthAWS
When it appliesapplicabilityText
Applies to every 10DLC registration.

Why this rule existsrationale

Bandwidth's reviewer reads the prohibition as admitting no exception at all, so a policy that promises not to share and then lists the circumstances in which it will is read on the list rather than on the promise. The exceptions are almost always drafted for good reasons — a merger, a partner integration, an analytics vendor — and each one reopens exactly the door the clause was written to close.

How to fix itremediation

Delete every exception attached to the messaging non-sharing clause, keeping only the narrow service-provider carve-back for the vendors that deliver the messages. Done when the clause has no "except", "unless" or "other than" hanging off it besides that one.

A compliant exampleexample

No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. We disclose it only to the service providers who deliver our messages, and to no one else.

Common mistakespitfalls

  • A merger or acquisition clause counts as an exception here, even though it is standard in every other part of a privacy policy. Exclude messaging data from it explicitly rather than relying on it being obviously different.

Provider rejection codescodes

The code you get back when this rule is what failed, and whether that provider lets you resubmit.

ProviderCodeResubmit
Bandwidth/DCA7109Yes

Notesnotes

Genuine implementation divergence, recorded rather than resolved: Bandwidth 7109 as written admits no exception, while Infobip, Telnyx and Alive5 require the service-provider carve-back that POL-058 asks for. The product has to draft that carve-back narrowly enough to survive a 7109 reviewer, and a policy carrying both patterns is worth a human look. Absorbs POL-059, which names the common shape — an exception for partners, advertisers or lead buyers.

Rules you will hit next

2 other rules read privacy policy body (whole document). Fixing one field to satisfy a single rule is how a resubmission trades one rejection for another, so read these before you change anything.

All policy pages rules

POL-060 is one of 157 policy pages rules in the 915-rule 10DLC registry. Free to cite under CC BY 4.0.

Reading the rules is the easy part.

Ekas runs every rule that gates approval, 823 of these 915, against your registration before it reaches the carrier. It reads your site, your policy pages and your opt-in the way a reviewer would, and hands you the fix, not just the verdict.