# POL-124 — The policy must state the purpose of each category

> The privacy policy must state the business or commercial purpose for each category of information, in terms a consumer can understand.

- **Rule ID:** POL-124
- **Layer:** Policy pages (`POLICY_PAGE`)
- **Checks:** `privacy policy body`
- **Severity:** HIGH — Rejected by at least one carrier or provider, and a common cause of failure at the rest.
- **When it bites:** Gates approval — get this wrong and registration is refused
- **How it is detected:** AI judgement over the submitted form
- **Fix type:** Fix the privacy policy or SMS terms
- **Required by:** CCPA
- **Applies:** Applies to every 10DLC registration.
- **Canonical URL:** https://ekas.io/rules/10dlc/policy-page/pol-124/

## Why this rule exists

The statute asks for a meaningful understanding rather than a list, which is a deliberate rejection of the "to improve our services" formulation that says nothing. For a messaging programme it is also the section where the purpose of holding the number is either stated plainly or lost in a generic paragraph.

## How to fix it

Give each category its own purpose, in the words a customer would use. Done when a reader can tell why you hold each thing you listed.

## Example of a compliant value

```text
Identifiers — to fulfil your orders, to answer support requests, and to send the text messages you asked for.
```
