The privacy policy must describe data handling, not sell the programme
The requirementstatement
The privacy policy must describe how data is handled rather than marketing the messaging programme.
- Severityseverity
- MediumMEDIUMUsually survives review, but lowers your trust score or invites a manual look you would rather avoid.
- When it bitesphase
- Gates approvalapprovalGet this wrong and the brand or campaign is refused at registration.
- What is checkedobject
- privacy policy body (document purpose)
- Where it liveslayer
- Policy pagesPOLICY_PAGE
- How Ekas settles itdetectability
- AI · formAI_FORM
- A semantic question about what you wrote: whether a description matches a use case, whether a name looks like a filed entity. Judged by a model against written criteria.
- What the fix involvesfailureClass
- Fix the policyTERMINAL_POLICY
- The fix lives in your privacy policy or SMS terms. Ekas can generate the missing clauses.
- Who requires itauthorities
- AWS
- When it appliesapplicabilityText
- Applies to every 10DLC registration.
Why this rule existsrationale
How to fix itremediation
Rewrite the page around what is collected, why, who it goes to and how to get it removed, and move the programme pitch to a marketing page. Done when the document reads as a description of data handling rather than an invitation to join.
A compliant exampleexample
When you join the Acme Coffee text programme we collect your mobile number, the date and source of your consent, and the delivery status of the messages we send. We use them only to send the messages you asked for.
Rules you will hit next
Other policy pages rules at the same severity. A registration is judged as a whole, not rule by rule.
POL-076 is one of 157 policy pages rules in the 915-rule 10DLC registry. Free to cite under CC BY 4.0.