# POL-078 — A political brand is held to the same data-sharing ban

> The third-party data-sharing prohibition applies to a political brand's policy exactly as it does to a commercial one.

- **Rule ID:** POL-078
- **Layer:** Policy pages (`POLICY_PAGE`)
- **Checks:** `privacy policy body`
- **Severity:** BLOCKING — Breaking this rule gets the submission rejected outright.
- **When it bites:** Gates approval — get this wrong and registration is refused
- **How it is detected:** AI judgement over the crawled website or policy page
- **Fix type:** Fix the privacy policy or SMS terms
- **Required by:** Twilio
- **Applies:** Applies when the use case is POLITICAL.
- **Canonical URL:** https://ekas.io/rules/10dlc/policy-page/pol-078/

## Why this rule exists

Political organisations routinely share supporter lists with allied committees and vendors, and treat it as normal practice rather than as data sharing — Twilio names political campaigns that buy, sell or share consumer information specifically. The consumer protection is identical: someone who consented to hear from one committee did not consent to hear from every committee it works with.

## How to fix it

Exclude mobile numbers and messaging consent from every list-exchange, coalition or vendor-sharing clause in the policy, and stop the practice for the numbers in this programme. Done when the policy says supporter mobile data is not shared with allied organisations.

## Provider rejection codes

| Provider | Code | Resubmission allowed |
| --- | --- | --- |
| Twilio (gen2) | `30951` | no |

## Notes

An anti-exemption rule. It exists because the sector reads the general prohibition as aimed at commercial marketing, so stating it for political brands separately is what makes it land.
