{
  "id": "POL-092",
  "slug": "pol-092",
  "title": "The policy must say what the messages are for",
  "statement": "The privacy policy must describe the purpose of the texting, consistently with the registered use case.",
  "rationale": "The use case sets the consent standard the campaign is held to, so a policy describing promotions behind a transactional registration tells the reviewer the wrong standard was applied. From the consumer's side it is the difference between agreeing to delivery updates and agreeing to weekly marketing, which is the whole substance of what they consented to.",
  "layer": "POLICY_PAGE",
  "layerSlug": "policy-page",
  "object": "privacy policy body",
  "severity": "HIGH",
  "detectability": [
    "AI_FORM"
  ],
  "failureClass": "TERMINAL_POLICY",
  "artifact": "privacy_policy",
  "authorities": [
    "AWS",
    "TCR",
    "Twilio",
    "Klaviyo"
  ],
  "codes": [
    {
      "provider": "Twilio",
      "code": "30908",
      "remediable": true,
      "generation": "gen1"
    }
  ],
  "applicabilityText": "Applies to every 10DLC registration.",
  "universal": true,
  "remediation": "Name the message categories in the policy and check them against the registered use case before submitting. Done when the two describe the same programme.",
  "example": "We use your number to send Acme Coffee promotional offers and rewards balance updates — the programme you joined at checkout — and for nothing else.",
  "phase": "approval",
  "automated": true,
  "url": "https://ekas.io/rules/10dlc/policy-page/pol-092/",
  "markdown": "https://ekas.io/rules/10dlc/policy-page/pol-092.md",
  "registry": "https://ekas.io/rules/10dlc/",
  "updated": "2026-07-25",
  "licence": "CC BY 4.0 — https://creativecommons.org/licenses/by/4.0/"
}
