# POL-114 — A child-directed service owes the full COPPA notice

> Where the service is directed at children, the policy must carry the COPPA online-notice elements, including the categories of third parties that receive children's data and the purpose.

- **Rule ID:** POL-114
- **Layer:** Policy pages (`POLICY_PAGE`)
- **Checks:** `privacy policy children's section`
- **Severity:** BLOCKING — Breaking this rule gets the submission rejected outright.
- **When it bites:** Gates approval — get this wrong and registration is refused
- **How it is detected:** AI judgement over the submitted form
- **Fix type:** Fix the privacy policy or SMS terms
- **Required by:** FTC
- **Applies:** Applies to every 10DLC registration.
- **Canonical URL:** https://ekas.io/rules/10dlc/policy-page/pol-114/

## Why this rule exists

A general "we do not target children" section is not a COPPA notice, and a service that is child-directed needs the full one — including the third-party disclosure, which is precisely what the messaging non-sharing clause has to be reconciled with. The FTC enforces this directly, so it is the one place in this layer where the regulator rather than the carrier is the risk.

## How to fix it

Publish the COPPA online notice: what is collected from children, how it is used, every category of third party that receives it and why, the parental-consent mechanism, and the parental review and deletion routes. Done when each element is present and specific.

## Common mistakes

- The third-party categories element and the SMS non-sharing clause have to agree. If the notice lists recipients of children's data, exclude messaging opt-in data from that list explicitly, or the two contradict.

## Notes

Conditional on the service being child-directed, which no applicability dimension expresses. The criteria pass immediately where nothing in the registration indicates a child-directed service, and record the condition rather than leaving the rule looking universal.
