# POL-123 — The policy must list where the information came from

> The privacy policy must list the sources of the personal information it collects.

- **Rule ID:** POL-123
- **Layer:** Policy pages (`POLICY_PAGE`)
- **Checks:** `privacy policy body`
- **Severity:** MEDIUM — Usually survives review, but lowers your trust score or invites manual review.
- **When it bites:** Gates approval — get this wrong and registration is refused
- **How it is detected:** AI judgement over the submitted form
- **Fix type:** Fix the privacy policy or SMS terms
- **Required by:** CCPA
- **Applies:** Applies to every 10DLC registration.
- **Canonical URL:** https://ekas.io/rules/10dlc/policy-page/pol-123/

## Why this rule exists

The sources list is where a policy either confirms or quietly contradicts the claim that every number was given directly by its owner — a list naming data brokers or partners tells a reviewer the opposite of what the messaging section promises. That makes a nominally low-relevance CCPA element load-bearing for a messaging registration.

## How to fix it

List the sources honestly and make sure none of them contradicts the messaging section. Done when the sources list and the opt-in description tell the same story.

## Example of a compliant value

```text
We collect personal information directly from you — at checkout, in your account, and when you contact us.
```
