{
  "id": "POL-108",
  "slug": "pol-108",
  "title": "The policy must describe what the business actually does",
  "statement": "The practices described in the policy must match what the site and the programme actually do.",
  "rationale": "A policy that misdescribes the business is worse than a thin one: it is a public statement that is not true, which is an FTC deception question as well as a carrier one. The machine-checkable half of it is easy — a policy that says \"we do not use cookies\" while an analytics tag loads on every page — and that half is usually a generated document nobody reconciled with the site.",
  "layer": "POLICY_PAGE",
  "layerSlug": "policy-page",
  "object": "privacy policy body vs observed site behaviour",
  "severity": "HIGH",
  "detectability": [
    "CRAWL"
  ],
  "failureClass": "TERMINAL_POLICY",
  "artifact": "privacy_policy",
  "authorities": [
    "CTIA"
  ],
  "applicabilityText": "Applies to every 10DLC registration.",
  "universal": true,
  "remediation": "Read the policy against what the site loads and what the programme does, and correct whichever is wrong. Done when every practice the document describes is one you can point at.",
  "notes": "Only partly decidable: a crawl can catch a cookie claim contradicted by a tracker, and nothing we fetch can confirm a retention period or an access control. The generation-side twin is POL-250; full verification is POL-107, which is a human question.",
  "phase": "approval",
  "automated": true,
  "url": "https://ekas.io/rules/10dlc/policy-page/pol-108/",
  "markdown": "https://ekas.io/rules/10dlc/policy-page/pol-108.md",
  "registry": "https://ekas.io/rules/10dlc/",
  "updated": "2026-07-25",
  "licence": "CC BY 4.0 — https://creativecommons.org/licenses/by/4.0/"
}
