The policy must state retention and consumer rights
The requirementstatement
The privacy policy must state how long data is kept and how consumers can access or delete it.
- Severityseverity
- MediumMEDIUMUsually survives review, but lowers your trust score or invites a manual look you would rather avoid.
- When it bitesphase
- Gates approvalapprovalGet this wrong and the brand or campaign is refused at registration.
- What is checkedobject
- privacy policy body
- Where it liveslayer
- Policy pagesPOLICY_PAGE
- How Ekas settles itdetectability
- AI · formAI_FORM
- A semantic question about what you wrote: whether a description matches a use case, whether a name looks like a filed entity. Judged by a model against written criteria.
- What the fix involvesfailureClass
- Fix the policyTERMINAL_POLICY
- The fix lives in your privacy policy or SMS terms. Ekas can generate the missing clauses.
- Who requires itauthorities
- SakariGDPRFTC
- When it appliesapplicabilityText
- Applies to every 10DLC registration.
Why this rule existsrationale
How to fix itremediation
State a period or a rule for messaging data, and give the route for access and deletion requests. Done when a reader knows how long you keep their number and how to ask you to delete it.
A compliant exampleexample
We keep opt-in records for four years after you unsubscribe, because we may need to show that consent existed. Email privacy@acmecoffee.com to see or delete what we hold.
Common mistakespitfalls
- Consent records are usually the one thing that should outlive a deletion request, because they are the evidence that the messages were lawful. Say so, rather than promising a deletion you will not perform.
Provider rejection codescodes
The code you get back when this rule is what failed, and whether that provider lets you resubmit.
| Provider | Code | Resubmit |
|---|---|---|
| Twiliogen1 | 30908 | Yes |
Rules you will hit next
6 other rules read privacy policy body. Fixing one field to satisfy a single rule is how a resubmission trades one rejection for another, so read these before you change anything.
POL-106 is one of 157 policy pages rules in the 915-rule 10DLC registry. Free to cite under CC BY 4.0.