{
  "id": "POL-095",
  "slug": "pol-095",
  "title": "The policy must say how to contact the sender",
  "statement": "The privacy policy must describe how consumers can contact the sender about their information.",
  "rationale": "Every right the policy grants — access, deletion, opting out — depends on there being someone to ask, so a document with no contact route grants nothing it can deliver. The address is also what a reviewer uses to corroborate the brand, which is why a bare web form fails where an email address on the brand domain passes.",
  "layer": "POLICY_PAGE",
  "layerSlug": "policy-page",
  "object": "privacy policy body",
  "severity": "HIGH",
  "detectability": [
    "CRAWL"
  ],
  "failureClass": "TERMINAL_POLICY",
  "artifact": "privacy_policy",
  "authorities": [
    "Bandwidth",
    "Sakari",
    "MessageDesk"
  ],
  "codes": [
    {
      "provider": "Bandwidth",
      "code": "7102",
      "remediable": true
    }
  ],
  "applicabilityText": "Applies to every 10DLC registration.",
  "universal": true,
  "remediation": "Add a privacy contact block with an email address on the brand domain and the business postal address. Done when a reader can write to a person without using a form.",
  "example": "Privacy questions: privacy@acmecoffee.com, or Acme Coffee Co, LLC, 1240 Mission St, Suite 400, San Francisco, CA 94103.",
  "phase": "approval",
  "automated": true,
  "url": "https://ekas.io/rules/10dlc/policy-page/pol-095/",
  "markdown": "https://ekas.io/rules/10dlc/policy-page/pol-095.md",
  "registry": "https://ekas.io/rules/10dlc/",
  "updated": "2026-07-25",
  "licence": "CC BY 4.0 — https://creativecommons.org/licenses/by/4.0/"
}
