CCPA sold/shared disclosure must exclude phone numbers and SMS consent
The requirementstatement
Where the policy carries a CCPA "categories of personal information sold or shared" table, it must explicitly exclude phone numbers and SMS consent data.
- Severityseverity
- HighHIGHRejected by at least one carrier or provider, and a common cause of failure at the rest.
- When it bitesphase
- Gates approvalapprovalGet this wrong and the brand or campaign is refused at registration.
- What is checkedobject
- privacy policy CCPA disclosure
- Where it liveslayer
- Policy pagesPOLICY_PAGE
- How Ekas settles itdetectability
- AI · formAI_FORM
- A semantic question about what you wrote: whether a description matches a use case, whether a name looks like a filed entity. Judged by a model against written criteria.
- What the fix involvesfailureClass
- Fix the policyTERMINAL_POLICY
- The fix lives in your privacy policy or SMS terms. Ekas can generate the missing clauses.
- Who requires itauthorities
- TCRTwilio
- When it appliesapplicabilityText
- Applies to every 10DLC registration.
Why this rule existsrationale
How to fix itremediation
Add an explicit exclusion beneath the CCPA table so the two disclosures do not contradict each other.
A compliant exampleexample
All the above categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.
Rules you will hit next
Other policy pages rules at the same severity. A registration is judged as a whole, not rule by rule.
POL-066 is one of 157 policy pages rules in the 915-rule 10DLC registry. Free to cite under CC BY 4.0.