{
  "id": "POL-106",
  "slug": "pol-106",
  "title": "The policy must state retention and consumer rights",
  "statement": "The privacy policy must state how long data is kept and how consumers can access or delete it.",
  "rationale": "Retention and deletion are what a consumer actually wants after they have unsubscribed — the number is out of the programme, and they want to know whether it is gone. Several statutes require the disclosure independently, and the COPPA amendments make a published retention policy mandatory wherever children's data is in scope.",
  "layer": "POLICY_PAGE",
  "layerSlug": "policy-page",
  "object": "privacy policy body",
  "severity": "MEDIUM",
  "detectability": [
    "AI_FORM"
  ],
  "failureClass": "TERMINAL_POLICY",
  "artifact": "privacy_policy",
  "authorities": [
    "Sakari",
    "GDPR",
    "FTC"
  ],
  "codes": [
    {
      "provider": "Twilio",
      "code": "30908",
      "remediable": true,
      "generation": "gen1"
    }
  ],
  "applicabilityText": "Applies to every 10DLC registration.",
  "universal": true,
  "remediation": "State a period or a rule for messaging data, and give the route for access and deletion requests. Done when a reader knows how long you keep their number and how to ask you to delete it.",
  "example": "We keep opt-in records for four years after you unsubscribe, because we may need to show that consent existed. Email privacy@acmecoffee.com to see or delete what we hold.",
  "pitfalls": [
    "Consent records are usually the one thing that should outlive a deletion request, because they are the evidence that the messages were lawful. Say so, rather than promising a deletion you will not perform."
  ],
  "phase": "approval",
  "automated": true,
  "url": "https://ekas.io/rules/10dlc/policy-page/pol-106/",
  "markdown": "https://ekas.io/rules/10dlc/policy-page/pol-106.md",
  "registry": "https://ekas.io/rules/10dlc/",
  "updated": "2026-07-25",
  "licence": "CC BY 4.0 — https://creativecommons.org/licenses/by/4.0/"
}
