# POL-063 — A policy that says mobile opt-in data is shared is refused outright

> A privacy policy stating affirmatively that mobile opt-in data or consent is shared with third parties or affiliates is rejected.

- **Rule ID:** POL-063
- **Layer:** Policy pages (`POLICY_PAGE`)
- **Checks:** `privacy policy body`
- **Severity:** BLOCKING — Breaking this rule gets the submission rejected outright.
- **When it bites:** Gates approval — get this wrong and registration is refused
- **How it is detected:** AI judgement over the submitted form
- **Fix type:** Fix the privacy policy or SMS terms
- **Required by:** Sinch, AWS, Twilio
- **Applies:** Applies to every 10DLC registration.
- **Canonical URL:** https://ekas.io/rules/10dlc/policy-page/pol-063/

## Why this rule exists

This is the loudest version of the defect and it is treated as evidence about the business rather than as bad drafting — AWS maps it to a spam-association reason, not to a document problem. It is what a lead-generation operation's policy says when it is being honest, so a legitimate business with an over-broad template inherits that reading without having done anything.

## How to fix it

Delete the sentence and replace it with the non-sharing clause, then check the business actually operates that way before publishing it. Done when nothing in the document says mobile data goes to anyone but the delivery vendors.

## Example of a compliant value

```text
Mobile information, including your number and your consent to receive text messages, is never sold, rented, traded or shared with third parties or affiliates for their own marketing or promotional purposes.
```

## Common mistakes

- Do not fix this by deleting the sentence while the practice continues. The rule that follows is POL-108, and a policy that misdescribes what the business does is a worse position than an accurate one.

## Provider rejection codes

| Provider | Code | Resubmission allowed |
| --- | --- | --- |
| Twilio (gen2) | `30932` | yes |
