{
  "id": "POL-091",
  "slug": "pol-091",
  "title": "The policy must say how the number was obtained",
  "statement": "The privacy policy must describe how phone numbers are obtained, consistently with the registered message flow.",
  "rationale": "This is the sentence a reviewer compares against the message flow, and a disagreement between them reads as two different programmes — the registration says checkout, the policy says \"when you contact us\". It is also the answer to the first question anyone asks about an unexpected text, which is how did you get my number.",
  "layer": "POLICY_PAGE",
  "layerSlug": "policy-page",
  "object": "privacy policy body",
  "severity": "HIGH",
  "detectability": [
    "AI_FORM"
  ],
  "failureClass": "TERMINAL_POLICY",
  "artifact": "privacy_policy",
  "authorities": [
    "Twilio",
    "AWS"
  ],
  "codes": [
    {
      "provider": "Twilio",
      "code": "30909",
      "remediable": true,
      "generation": "gen2"
    }
  ],
  "applicabilityText": "Applies to every 10DLC registration.",
  "universal": true,
  "remediation": "Name every collection surface the registration declares, using the same words the message flow uses. Done when the policy and the message flow describe the same opt-in.",
  "example": "We collect your mobile number when you tick the text-messaging box at checkout on acmecoffee.com. That is the only way we add a number to the programme.",
  "notes": "The SMS-terms twin is POL-181, which asks the terms to describe every method, and POL-232 asks the same of the surfaces found by crawling. All three can disagree independently, which is why they are separate.",
  "phase": "approval",
  "automated": true,
  "url": "https://ekas.io/rules/10dlc/policy-page/pol-091/",
  "markdown": "https://ekas.io/rules/10dlc/policy-page/pol-091.md",
  "registry": "https://ekas.io/rules/10dlc/",
  "updated": "2026-07-25",
  "licence": "CC BY 4.0 — https://creativecommons.org/licenses/by/4.0/"
}
