The policy must describe how information is collected, used and shared

The requirementstatement

The privacy policy must describe how the sender collects, uses and shares consumer information.

Severityseverity
HighHIGHRejected by at least one carrier or provider, and a common cause of failure at the rest.
When it bitesphase
Gates approvalapprovalGet this wrong and the brand or campaign is refused at registration.
What is checkedobject
privacy policy body
Where it liveslayer
Policy pagesPOLICY_PAGE
How Ekas settles itdetectability
AI · formAI_FORM
A semantic question about what you wrote: whether a description matches a use case, whether a name looks like a filed entity. Judged by a model against written criteria.
What the fix involvesfailureClass
Fix the policyTERMINAL_POLICY
The fix lives in your privacy policy or SMS terms. Ekas can generate the missing clauses.
Who requires itauthorities
CTIABandwidthKlaviyo
When it appliesapplicabilityText
Applies to every 10DLC registration.

Why this rule existsrationale

This is CTIA's actual privacy requirement, and it is far weaker than the carrier non-sharing overlay everyone argues about — which is why it gets skipped: businesses focused on the non-sharing sentence forget the document also has to describe ordinary handling. A policy that promises not to share and never says what it does with the data has answered only half the question.

How to fix itremediation

Give the document the three ordinary sections — collection, use, disclosure — around whatever it already says about messaging. Done when a reader can follow the data from where it is collected to who ends up handling it.

A compliant exampleexample

We collect your number at checkout, use it to send the messages you asked for, and disclose it only to the messaging vendor that delivers them.

Provider rejection codescodes

The code you get back when this rule is what failed, and whether that provider lets you resubmit.

ProviderCodeResubmit
Bandwidth7102Yes

Rules you will hit next

6 other rules read privacy policy body. Fixing one field to satisfy a single rule is how a resubmission trades one rejection for another, so read these before you change anything.

All policy pages rules

POL-094 is one of 157 policy pages rules in the 915-rule 10DLC registry. Free to cite under CC BY 4.0.

Reading the rules is the easy part.

Ekas runs every rule that gates approval, 823 of these 915, against your registration before it reaches the carrier. It reads your site, your policy pages and your opt-in the way a reviewer would, and hands you the fix, not just the verdict.