{
  "id": "POL-122",
  "slug": "pol-122",
  "title": "The policy must list the categories of personal information collected",
  "statement": "The privacy policy must list the categories of personal information collected, using the statutory category names.",
  "rationale": "California requires the statutory names rather than a plain-English list, and the same section answers Twilio's demand to know what customer data is collected — so it is one of the few CCPA elements that carries direct 10DLC weight. It is also the section that most often contradicts the messaging clause, because \"identifiers\" includes the phone number.",
  "layer": "POLICY_PAGE",
  "layerSlug": "policy-page",
  "object": "privacy policy body",
  "severity": "HIGH",
  "detectability": [
    "AI_FORM"
  ],
  "failureClass": "TERMINAL_POLICY",
  "artifact": "privacy_policy",
  "authorities": [
    "CCPA",
    "Twilio"
  ],
  "codes": [
    {
      "provider": "Twilio",
      "code": "30908",
      "remediable": true,
      "generation": "gen1"
    }
  ],
  "applicabilityText": "Applies to every 10DLC registration.",
  "universal": true,
  "remediation": "List the statutory categories that apply and give an example of each in plain words alongside. Done when a reader sees both the legal category and what it means for them.",
  "example": "Identifiers — including your name, email address and mobile phone number.",
  "pitfalls": [
    "This list feeds the sold-or-shared table two sections later. Whatever appears here must be excluded there for messaging data, or POL-066 fires on the contradiction."
  ],
  "phase": "approval",
  "automated": true,
  "url": "https://ekas.io/rules/10dlc/policy-page/pol-122/",
  "markdown": "https://ekas.io/rules/10dlc/policy-page/pol-122.md",
  "registry": "https://ekas.io/rules/10dlc/",
  "updated": "2026-07-25",
  "licence": "CC BY 4.0 — https://creativecommons.org/licenses/by/4.0/"
}
