{
  "id": "POL-099",
  "slug": "pol-099",
  "title": "The policy must carry the message-and-data-rates disclosure",
  "statement": "The privacy policy must carry the \"message and data rates may apply\" disclosure.",
  "rationale": "The disclosure exists so nobody is billed by their carrier for something they did not know they were agreeing to, and it is required in the policy as well as the terms for the same reason frequency is: the two standards disagree about where it lives, so it has to be in both. It is one sentence and it is the single most mechanically-screened string in the framework.",
  "layer": "POLICY_PAGE",
  "layerSlug": "policy-page",
  "object": "privacy policy body",
  "severity": "HIGH",
  "detectability": [
    "AI_FORM"
  ],
  "failureClass": "TERMINAL_POLICY",
  "artifact": "privacy_policy",
  "authorities": [
    "Twilio"
  ],
  "codes": [
    {
      "provider": "Twilio",
      "code": "30924",
      "remediable": true,
      "generation": "gen1"
    }
  ],
  "applicabilityText": "Applies to every 10DLC registration.",
  "universal": true,
  "remediation": "Add the sentence to the messaging section of the policy. Done when the phrase appears in the policy as well as in the SMS terms.",
  "example": "Privacy policy, \"Text messaging\" section: \"Acme Coffee Rewards is a recurring programme. Message and data rates may apply.\"",
  "notes": "The catalog exempts Free-To-End-User programmes, where the consumer is not billed. We hold no FTEU fact, so the rule fires universally; an FTEU programme should record the exemption rather than treating the finding as wrong.",
  "phase": "approval",
  "automated": true,
  "url": "https://ekas.io/rules/10dlc/policy-page/pol-099/",
  "markdown": "https://ekas.io/rules/10dlc/policy-page/pol-099.md",
  "registry": "https://ekas.io/rules/10dlc/",
  "updated": "2026-07-25",
  "licence": "CC BY 4.0 — https://creativecommons.org/licenses/by/4.0/"
}
