{
  "id": "POL-065",
  "slug": "pol-065",
  "title": "Boilerplate \"trusted partners\" language must be removed or narrowed",
  "statement": "Generic policy-generator output such as \"we may share with trusted partners\" must be removed or narrowed to service providers.",
  "rationale": "Ranked #4 most-missed. Free privacy-policy generators emit permissive sharing language by default, and the business pasting it in has no idea it contradicts their messaging programme. It is the most common source of the inverse trap because nobody wrote the sentence deliberately.",
  "layer": "POLICY_PAGE",
  "layerSlug": "policy-page",
  "object": "privacy policy body",
  "severity": "HIGH",
  "detectability": [
    "AI_FORM"
  ],
  "failureClass": "TERMINAL_POLICY",
  "artifact": "privacy_policy",
  "authorities": [
    "TCR",
    "Twilio",
    "AWS"
  ],
  "applicabilityText": "Applies to every 10DLC registration.",
  "universal": true,
  "remediation": "Replace vague partner language with a specific, closed list of processor categories, and state that messaging data is excluded from all of them.",
  "example": "We share personal information only with service providers who perform functions on our behalf (payment processing, order fulfilment, and message delivery). We do not share personal information with third parties for their own marketing purposes.",
  "phase": "approval",
  "automated": true,
  "url": "https://ekas.io/rules/10dlc/policy-page/pol-065/",
  "markdown": "https://ekas.io/rules/10dlc/policy-page/pol-065.md",
  "registry": "https://ekas.io/rules/10dlc/",
  "updated": "2026-07-25",
  "licence": "CC BY 4.0 — https://creativecommons.org/licenses/by/4.0/"
}
