{
  "id": "POL-112",
  "slug": "pol-112",
  "title": "Location-triggered messaging must be described in the policy",
  "statement": "The privacy policy must describe how location data is collected and why, where messaging is triggered by location.",
  "rationale": "A message that arrives because someone walked past a shop is the kind of thing consumers find startling, and the policy is the only place they can find out it was going to happen. Location tracking is usually switched on inside a marketing platform rather than built deliberately, so the practice exists long before anyone thinks to document it.",
  "layer": "POLICY_PAGE",
  "layerSlug": "policy-page",
  "object": "privacy policy body",
  "severity": "HIGH",
  "detectability": [
    "AI_FORM"
  ],
  "failureClass": "TERMINAL_POLICY",
  "artifact": "privacy_policy",
  "authorities": [
    "Klaviyo"
  ],
  "applicabilityText": "Applies to every 10DLC registration.",
  "universal": true,
  "remediation": "Describe the collection method, the messaging use and the opt-out in the messaging section. Done when someone who receives a location-triggered message can find out why in the policy.",
  "example": "If you enable location in the Acme Coffee app we use it to text you when you are near a store with an offer on. Turn location off in the app to stop those texts without leaving the programme.",
  "notes": "Conditional on the programme being location-triggered, which no applicability dimension expresses; the criteria pass immediately where nothing in the registration indicates location triggering.",
  "phase": "approval",
  "automated": true,
  "url": "https://ekas.io/rules/10dlc/policy-page/pol-112/",
  "markdown": "https://ekas.io/rules/10dlc/policy-page/pol-112.md",
  "registry": "https://ekas.io/rules/10dlc/",
  "updated": "2026-07-25",
  "licence": "CC BY 4.0 — https://creativecommons.org/licenses/by/4.0/"
}
