{
  "id": "POL-094",
  "slug": "pol-094",
  "title": "The policy must describe how information is collected, used and shared",
  "statement": "The privacy policy must describe how the sender collects, uses and shares consumer information.",
  "rationale": "This is CTIA's actual privacy requirement, and it is far weaker than the carrier non-sharing overlay everyone argues about — which is why it gets skipped: businesses focused on the non-sharing sentence forget the document also has to describe ordinary handling. A policy that promises not to share and never says what it does with the data has answered only half the question.",
  "layer": "POLICY_PAGE",
  "layerSlug": "policy-page",
  "object": "privacy policy body",
  "severity": "HIGH",
  "detectability": [
    "AI_FORM"
  ],
  "failureClass": "TERMINAL_POLICY",
  "artifact": "privacy_policy",
  "authorities": [
    "CTIA",
    "Bandwidth",
    "Klaviyo"
  ],
  "codes": [
    {
      "provider": "Bandwidth",
      "code": "7102",
      "remediable": true
    }
  ],
  "applicabilityText": "Applies to every 10DLC registration.",
  "universal": true,
  "remediation": "Give the document the three ordinary sections — collection, use, disclosure — around whatever it already says about messaging. Done when a reader can follow the data from where it is collected to who ends up handling it.",
  "example": "We collect your number at checkout, use it to send the messages you asked for, and disclose it only to the messaging vendor that delivers them.",
  "phase": "approval",
  "automated": true,
  "url": "https://ekas.io/rules/10dlc/policy-page/pol-094/",
  "markdown": "https://ekas.io/rules/10dlc/policy-page/pol-094.md",
  "registry": "https://ekas.io/rules/10dlc/",
  "updated": "2026-07-25",
  "licence": "CC BY 4.0 — https://creativecommons.org/licenses/by/4.0/"
}
