{
  "id": "POL-124",
  "slug": "pol-124",
  "title": "The policy must state the purpose of each category",
  "statement": "The privacy policy must state the business or commercial purpose for each category of information, in terms a consumer can understand.",
  "rationale": "The statute asks for a meaningful understanding rather than a list, which is a deliberate rejection of the \"to improve our services\" formulation that says nothing. For a messaging programme it is also the section where the purpose of holding the number is either stated plainly or lost in a generic paragraph.",
  "layer": "POLICY_PAGE",
  "layerSlug": "policy-page",
  "object": "privacy policy body",
  "severity": "HIGH",
  "detectability": [
    "AI_FORM"
  ],
  "failureClass": "TERMINAL_POLICY",
  "artifact": "privacy_policy",
  "authorities": [
    "CCPA"
  ],
  "applicabilityText": "Applies to every 10DLC registration.",
  "universal": true,
  "remediation": "Give each category its own purpose, in the words a customer would use. Done when a reader can tell why you hold each thing you listed.",
  "example": "Identifiers — to fulfil your orders, to answer support requests, and to send the text messages you asked for.",
  "phase": "approval",
  "automated": true,
  "url": "https://ekas.io/rules/10dlc/policy-page/pol-124/",
  "markdown": "https://ekas.io/rules/10dlc/policy-page/pol-124.md",
  "registry": "https://ekas.io/rules/10dlc/",
  "updated": "2026-07-25",
  "licence": "CC BY 4.0 — https://creativecommons.org/licenses/by/4.0/"
}
