{
  "id": "POL-121",
  "slug": "pol-121",
  "title": "The policy must say what it covers",
  "statement": "The privacy policy must state its scope — which sites, apps and offline channels it applies to.",
  "rationale": "A policy scoped to \"this app\" while the opt-in happens on the website is the wrong document for the programme being registered, and a reviewer reads the scope line before anything else. Businesses inherit the mismatch from whichever product the policy was first written for.",
  "layer": "POLICY_PAGE",
  "layerSlug": "policy-page",
  "object": "privacy policy body",
  "severity": "LOW",
  "detectability": [
    "AI_FORM"
  ],
  "failureClass": "TERMINAL_POLICY",
  "artifact": "privacy_policy",
  "authorities": [
    "TCR"
  ],
  "applicabilityText": "Applies to every 10DLC registration.",
  "universal": true,
  "remediation": "Open the policy with a scope sentence naming every surface it covers, including the messaging programme. Done when the document plainly covers the surface where consent is collected.",
  "example": "This policy covers acmecoffee.com, the Acme Coffee mobile app, our stores, and the Acme Coffee text messaging programme.",
  "phase": "approval",
  "automated": true,
  "url": "https://ekas.io/rules/10dlc/policy-page/pol-121/",
  "markdown": "https://ekas.io/rules/10dlc/policy-page/pol-121.md",
  "registry": "https://ekas.io/rules/10dlc/",
  "updated": "2026-07-25",
  "licence": "CC BY 4.0 — https://creativecommons.org/licenses/by/4.0/"
}
