# POL-113 — The policy needs a children's-data section

> The privacy policy must carry a children's-data section with a parental-consent route and a deletion route.

- **Rule ID:** POL-113
- **Layer:** Policy pages (`POLICY_PAGE`)
- **Checks:** `privacy policy body`
- **Severity:** HIGH — Rejected by at least one carrier or provider, and a common cause of failure at the rest.
- **When it bites:** Gates approval — get this wrong and registration is refused
- **How it is detected:** AI judgement over the submitted form
- **Fix type:** Fix the privacy policy or SMS terms
- **Required by:** FTC, CTIA
- **Applies:** Applies to every 10DLC registration.
- **Canonical URL:** https://ekas.io/rules/10dlc/policy-page/pol-113/

## Why this rule exists

A messaging programme cannot tell how old the person holding the phone is, so the policy has to say what happens when a child ends up in it — and the FTC's amended rule raises the bar on what that section must contain. Ordinary businesses are in scope more often than they expect, because the question is whether children are reachable rather than whether they are the audience.

## How to fix it

Add a children's section giving the age position, the parental route and the deletion commitment. Done when a parent reading it knows exactly who to contact and what will happen.

## Example of a compliant value

```text
The Acme Coffee text programme is not directed at children under 13 and we do not knowingly collect their information. A parent can email privacy@acmecoffee.com to see what we hold about a child and we will delete it.
```

## Notes

The FTC amended rule took effect on 2025-06-23 with full compliance required from 2026-04-22, so this is live rather than forthcoming.
