# POL-107 — The policy must be consistent with applicable privacy law

> The privacy policy must be consistent with the privacy law that applies to the business.

- **Rule ID:** POL-107
- **Layer:** Policy pages (`POLICY_PAGE`)
- **Checks:** `privacy policy body`
- **Severity:** HIGH — Rejected by at least one carrier or provider, and a common cause of failure at the rest.
- **When it bites:** Gates approval — get this wrong and registration is refused
- **How it is detected:** Human check — only someone holding the document can settle it
- **Fix type:** Fix the privacy policy or SMS terms
- **Required by:** CTIA
- **Applies:** Applies to every 10DLC registration.
- **Canonical URL:** https://ekas.io/rules/10dlc/policy-page/pol-107/

## Why this rule exists

CTIA requires it, and which law applies turns on where the customers are, what is collected and how large the business is — none of which a document check can establish. The consequence of getting it wrong is a regulator rather than a carrier, so it is the one requirement in this layer where passing the registration is not the point.

## How to fix it

Have the policy reviewed by someone who knows which statutes apply to your business, before publishing rather than after a complaint. Done when a reviewer has confirmed the applicable regimes are covered.

## Check this yourself

**Has someone who knows which privacy statutes apply to this business read the policy?**

1. Establish which regimes are in play: where the customers are, what is collected, and how large the business is.
2. Route the document to counsel or a qualified privacy adviser before publishing, not after a complaint.
3. Treat the CCPA, GDPR and COPPA sections this registry checks as a floor, not a legal opinion.

*What wrong looks like:* The document passes every automated check and misses the regime the business is actually in. The consequence here is a regulator rather than a carrier, so approval of the registration is not the point.

## Notes

Not machine-decidable and not something the registry should pretend to settle. The individual statutory elements this layer does check — the CCPA sections, the GDPR addendum, the COPPA sections — are a floor rather than a legal opinion, and the user has to route the document to counsel for the rest.
