The policy must say what it covers
The requirementstatement
The privacy policy must state its scope — which sites, apps and offline channels it applies to.
- Severityseverity
- LowLOWBest practice. Worth fixing, rarely fatal on its own.
- When it bitesphase
- Gates approvalapprovalGet this wrong and the brand or campaign is refused at registration.
- What is checkedobject
- privacy policy body
- Where it liveslayer
- Policy pagesPOLICY_PAGE
- How Ekas settles itdetectability
- AI · formAI_FORM
- A semantic question about what you wrote: whether a description matches a use case, whether a name looks like a filed entity. Judged by a model against written criteria.
- What the fix involvesfailureClass
- Fix the policyTERMINAL_POLICY
- The fix lives in your privacy policy or SMS terms. Ekas can generate the missing clauses.
- Who requires itauthorities
- TCR
- When it appliesapplicabilityText
- Applies to every 10DLC registration.
Why this rule existsrationale
How to fix itremediation
Open the policy with a scope sentence naming every surface it covers, including the messaging programme. Done when the document plainly covers the surface where consent is collected.
A compliant exampleexample
This policy covers acmecoffee.com, the Acme Coffee mobile app, our stores, and the Acme Coffee text messaging programme.
Rules you will hit next
6 other rules read privacy policy body. Fixing one field to satisfy a single rule is how a resubmission trades one rejection for another, so read these before you change anything.
POL-121 is one of 157 policy pages rules in the 915-rule 10DLC registry. Free to cite under CC BY 4.0.