# POL-106 — The policy must state retention and consumer rights

> The privacy policy must state how long data is kept and how consumers can access or delete it.

- **Rule ID:** POL-106
- **Layer:** Policy pages (`POLICY_PAGE`)
- **Checks:** `privacy policy body`
- **Severity:** MEDIUM — Usually survives review, but lowers your trust score or invites manual review.
- **When it bites:** Gates approval — get this wrong and registration is refused
- **How it is detected:** AI judgement over the submitted form
- **Fix type:** Fix the privacy policy or SMS terms
- **Required by:** Sakari, GDPR, FTC
- **Applies:** Applies to every 10DLC registration.
- **Canonical URL:** https://ekas.io/rules/10dlc/policy-page/pol-106/

## Why this rule exists

Retention and deletion are what a consumer actually wants after they have unsubscribed — the number is out of the programme, and they want to know whether it is gone. Several statutes require the disclosure independently, and the COPPA amendments make a published retention policy mandatory wherever children's data is in scope.

## How to fix it

State a period or a rule for messaging data, and give the route for access and deletion requests. Done when a reader knows how long you keep their number and how to ask you to delete it.

## Example of a compliant value

```text
We keep opt-in records for four years after you unsubscribe, because we may need to show that consent existed. Email privacy@acmecoffee.com to see or delete what we hold.
```

## Common mistakes

- Consent records are usually the one thing that should outlive a deletion request, because they are the evidence that the messages were lawful. Say so, rather than promising a deletion you will not perform.

## Provider rejection codes

| Provider | Code | Resubmission allowed |
| --- | --- | --- |
| Twilio (gen1) | `30908` | yes |
