{
  "id": "POL-066",
  "slug": "pol-066",
  "title": "CCPA sold/shared disclosure must exclude phone numbers and SMS consent",
  "statement": "Where the policy carries a CCPA \"categories of personal information sold or shared\" table, it must explicitly exclude phone numbers and SMS consent data.",
  "rationale": "Ranked #5 most-missed. A CCPA table listing \"identifiers\" as sold or shared directly contradicts the non-sharing promise, because a phone number is an identifier. Businesses complying carefully with California law thereby create a 10DLC rejection, and the fix is a carve-out rather than a removal.",
  "layer": "POLICY_PAGE",
  "layerSlug": "policy-page",
  "object": "privacy policy CCPA disclosure",
  "severity": "HIGH",
  "detectability": [
    "AI_FORM"
  ],
  "failureClass": "TERMINAL_POLICY",
  "artifact": "privacy_policy",
  "authorities": [
    "TCR",
    "Twilio"
  ],
  "applicabilityText": "Applies to every 10DLC registration.",
  "universal": true,
  "remediation": "Add an explicit exclusion beneath the CCPA table so the two disclosures do not contradict each other.",
  "example": "All the above categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.",
  "phase": "approval",
  "automated": true,
  "url": "https://ekas.io/rules/10dlc/policy-page/pol-066/",
  "markdown": "https://ekas.io/rules/10dlc/policy-page/pol-066.md",
  "registry": "https://ekas.io/rules/10dlc/",
  "updated": "2026-07-25",
  "licence": "CC BY 4.0 — https://creativecommons.org/licenses/by/4.0/"
}
