{
  "id": "POL-090",
  "slug": "pol-090",
  "title": "The policy must say what messaging data is collected",
  "statement": "The privacy policy must describe what data the messaging programme collects.",
  "rationale": "A consumer handing over a number is entitled to know that the consent timestamp, the source, the delivery status and in many programmes the message content are kept alongside it — none of which is obvious from typing a phone number into a box. Twilio asks directly for \"what customer data you collect\", and a policy that names only \"contact information\" answers a different question.",
  "layer": "POLICY_PAGE",
  "layerSlug": "policy-page",
  "object": "privacy policy body",
  "severity": "HIGH",
  "detectability": [
    "AI_FORM"
  ],
  "failureClass": "TERMINAL_POLICY",
  "artifact": "privacy_policy",
  "authorities": [
    "Twilio",
    "Bandwidth",
    "TCR"
  ],
  "codes": [
    {
      "provider": "Twilio",
      "code": "30908",
      "remediable": true,
      "generation": "gen1"
    }
  ],
  "applicabilityText": "Applies to every 10DLC registration.",
  "universal": true,
  "remediation": "Add a short list to the data-collection section naming the messaging fields specifically. Done when a reader can see that consent metadata is kept, not just the number.",
  "example": "For the Acme Coffee text programme we collect your mobile number, the date and time you consented, the page or call it happened on, and the delivery status of each message we send.",
  "phase": "approval",
  "automated": true,
  "url": "https://ekas.io/rules/10dlc/policy-page/pol-090/",
  "markdown": "https://ekas.io/rules/10dlc/policy-page/pol-090.md",
  "registry": "https://ekas.io/rules/10dlc/",
  "updated": "2026-07-25",
  "licence": "CC BY 4.0 — https://creativecommons.org/licenses/by/4.0/"
}
