# POL-115 — Children's data needs a published retention policy

> The privacy policy must publish a written data-retention policy for children's data, with the purpose, the justification and the deletion timeframe.

- **Rule ID:** POL-115
- **Layer:** Policy pages (`POLICY_PAGE`)
- **Checks:** `privacy policy body`
- **Severity:** HIGH — Rejected by at least one carrier or provider, and a common cause of failure at the rest.
- **When it bites:** Gates approval — get this wrong and registration is refused
- **How it is detected:** AI judgement over the submitted form
- **Fix type:** Fix the privacy policy or SMS terms
- **Required by:** FTC
- **Applies:** Applies to every 10DLC registration.
- **Canonical URL:** https://ekas.io/rules/10dlc/policy-page/pol-115/

## Why this rule exists

The 2025 COPPA amendments require the retention policy to be published rather than merely held, which is a change most businesses have not noticed. The substance matters as much as the publication: a retention rule with no deletion timeframe is a commitment to keep a child's data indefinitely, stated in public.

## How to fix it

Add the retention rule to the children's section: what is kept, why, and for how long. Done when the section states a period rather than a condition.

## Example of a compliant value

```text
Where we learn that a subscriber is under 13 we delete the number and its consent record within 30 days, keeping only the fact of the deletion.
```

## Notes

Conditional on children's data being in scope, which no applicability dimension expresses; the criteria pass immediately where it is not.
