{
  "id": "POL-076",
  "slug": "pol-076",
  "title": "The privacy policy must describe data handling, not sell the programme",
  "statement": "The privacy policy must describe how data is handled rather than marketing the messaging programme.",
  "rationale": "A policy written as promotional copy — how great the offers are, why to sign up — answers none of the questions a policy exists to answer, so a reviewer looking for the data-handling terms finds none and rejects the document. It happens when the page is written by whoever writes the rest of the site, from a brief that said \"explain the text programme\".",
  "layer": "POLICY_PAGE",
  "layerSlug": "policy-page",
  "object": "privacy policy body (document purpose)",
  "severity": "MEDIUM",
  "detectability": [
    "AI_FORM"
  ],
  "failureClass": "TERMINAL_POLICY",
  "artifact": "privacy_policy",
  "authorities": [
    "AWS"
  ],
  "applicabilityText": "Applies to every 10DLC registration.",
  "universal": true,
  "remediation": "Rewrite the page around what is collected, why, who it goes to and how to get it removed, and move the programme pitch to a marketing page. Done when the document reads as a description of data handling rather than an invitation to join.",
  "example": "When you join the Acme Coffee text programme we collect your mobile number, the date and source of your consent, and the delivery status of the messages we send. We use them only to send the messages you asked for.",
  "phase": "approval",
  "automated": true,
  "url": "https://ekas.io/rules/10dlc/policy-page/pol-076/",
  "markdown": "https://ekas.io/rules/10dlc/policy-page/pol-076.md",
  "registry": "https://ekas.io/rules/10dlc/",
  "updated": "2026-07-25",
  "licence": "CC BY 4.0 — https://creativecommons.org/licenses/by/4.0/"
}
