The policy must be consistent with applicable privacy law

The requirementstatement

The privacy policy must be consistent with the privacy law that applies to the business.

Severityseverity
HighHIGHRejected by at least one carrier or provider, and a common cause of failure at the rest.
When it bitesphase
Gates approvalapprovalGet this wrong and the brand or campaign is refused at registration.
What is checkedobject
privacy policy body
Where it liveslayer
Policy pagesPOLICY_PAGE
How Ekas settles itdetectability
Human checkHUMAN
Only someone holding the document or making the call can settle it. Ekas tells you exactly what to look at.
What the fix involvesfailureClass
Fix the policyTERMINAL_POLICY
The fix lives in your privacy policy or SMS terms. Ekas can generate the missing clauses.
Who requires itauthorities
CTIA
When it appliesapplicabilityText
Applies to every 10DLC registration.

Why this rule existsrationale

CTIA requires it, and which law applies turns on where the customers are, what is collected and how large the business is — none of which a document check can establish. The consequence of getting it wrong is a regulator rather than a carrier, so it is the one requirement in this layer where passing the registration is not the point.

How to fix itremediation

Have the policy reviewed by someone who knows which statutes apply to your business, before publishing rather than after a complaint. Done when a reviewer has confirmed the applicable regimes are covered.

Check this yourselfattestation

No tool can settle this one for you. Here is the check, and what wrong looks like.

Has someone who knows which privacy statutes apply to this business read the policy?

  1. 1Establish which regimes are in play: where the customers are, what is collected, and how large the business is.
  2. 2Route the document to counsel or a qualified privacy adviser before publishing, not after a complaint.
  3. 3Treat the CCPA, GDPR and COPPA sections this registry checks as a floor, not a legal opinion.

What wrong looks like: The document passes every automated check and misses the regime the business is actually in. The consequence here is a regulator rather than a carrier, so approval of the registration is not the point.

Notesnotes

Not machine-decidable and not something the registry should pretend to settle. The individual statutory elements this layer does check — the CCPA sections, the GDPR addendum, the COPPA sections — are a floor rather than a legal opinion, and the user has to route the document to counsel for the rest.

Rules you will hit next

6 other rules read privacy policy body. Fixing one field to satisfy a single rule is how a resubmission trades one rejection for another, so read these before you change anything.

All policy pages rules

POL-107 is one of 157 policy pages rules in the 915-rule 10DLC registry. Free to cite under CC BY 4.0.

Reading the rules is the easy part.

Ekas runs every rule that gates approval, 823 of these 915, against your registration before it reaches the carrier. It reads your site, your policy pages and your opt-in the way a reviewer would, and hands you the fix, not just the verdict.