{
  "id": "POL-113",
  "slug": "pol-113",
  "title": "The policy needs a children's-data section",
  "statement": "The privacy policy must carry a children's-data section with a parental-consent route and a deletion route.",
  "rationale": "A messaging programme cannot tell how old the person holding the phone is, so the policy has to say what happens when a child ends up in it — and the FTC's amended rule raises the bar on what that section must contain. Ordinary businesses are in scope more often than they expect, because the question is whether children are reachable rather than whether they are the audience.",
  "layer": "POLICY_PAGE",
  "layerSlug": "policy-page",
  "object": "privacy policy body",
  "severity": "HIGH",
  "detectability": [
    "AI_FORM"
  ],
  "failureClass": "TERMINAL_POLICY",
  "artifact": "privacy_policy",
  "authorities": [
    "FTC",
    "CTIA"
  ],
  "applicabilityText": "Applies to every 10DLC registration.",
  "universal": true,
  "remediation": "Add a children's section giving the age position, the parental route and the deletion commitment. Done when a parent reading it knows exactly who to contact and what will happen.",
  "example": "The Acme Coffee text programme is not directed at children under 13 and we do not knowingly collect their information. A parent can email privacy@acmecoffee.com to see what we hold about a child and we will delete it.",
  "notes": "The FTC amended rule took effect on 2025-06-23 with full compliance required from 2026-04-22, so this is live rather than forthcoming.",
  "phase": "approval",
  "automated": true,
  "url": "https://ekas.io/rules/10dlc/policy-page/pol-113/",
  "markdown": "https://ekas.io/rules/10dlc/policy-page/pol-113.md",
  "registry": "https://ekas.io/rules/10dlc/",
  "updated": "2026-07-25",
  "licence": "CC BY 4.0 — https://creativecommons.org/licenses/by/4.0/"
}
