# POL-076 — The privacy policy must describe data handling, not sell the programme

> The privacy policy must describe how data is handled rather than marketing the messaging programme.

- **Rule ID:** POL-076
- **Layer:** Policy pages (`POLICY_PAGE`)
- **Checks:** `privacy policy body (document purpose)`
- **Severity:** MEDIUM — Usually survives review, but lowers your trust score or invites manual review.
- **When it bites:** Gates approval — get this wrong and registration is refused
- **How it is detected:** AI judgement over the submitted form
- **Fix type:** Fix the privacy policy or SMS terms
- **Required by:** AWS
- **Applies:** Applies to every 10DLC registration.
- **Canonical URL:** https://ekas.io/rules/10dlc/policy-page/pol-076/

## Why this rule exists

A policy written as promotional copy — how great the offers are, why to sign up — answers none of the questions a policy exists to answer, so a reviewer looking for the data-handling terms finds none and rejects the document. It happens when the page is written by whoever writes the rest of the site, from a brief that said "explain the text programme".

## How to fix it

Rewrite the page around what is collected, why, who it goes to and how to get it removed, and move the programme pitch to a marketing page. Done when the document reads as a description of data handling rather than an invitation to join.

## Example of a compliant value

```text
When you join the Acme Coffee text programme we collect your mobile number, the date and source of your consent, and the delivery status of the messages we send. We use them only to send the messages you asked for.
```
