# POL-125 — The policy must list who the information is disclosed to

> The privacy policy must list the categories of third parties personal information is disclosed, sold or shared to, and why.

- **Rule ID:** POL-125
- **Layer:** Policy pages (`POLICY_PAGE`)
- **Checks:** `privacy policy body`
- **Severity:** HIGH — Rejected by at least one carrier or provider, and a common cause of failure at the rest.
- **When it bites:** Gates approval — get this wrong and registration is refused
- **How it is detected:** AI judgement over the submitted form
- **Fix type:** Fix the privacy policy or SMS terms
- **Required by:** CCPA, Bandwidth
- **Applies:** Applies to every 10DLC registration.
- **Canonical URL:** https://ekas.io/rules/10dlc/policy-page/pol-125/

## Why this rule exists

This is the section carrier reviewers grep hardest, because it is where a policy admits what actually happens to the data — the research calls it the section that trips Bandwidth 7103. A careful CCPA disclosure and a compliant messaging clause pull in opposite directions here, and reconciling them is the whole job.

## How to fix it

List the recipient categories accurately and add the messaging exclusion immediately after the list. Done when the section is both a truthful CCPA disclosure and consistent with the non-sharing clause.

## Example of a compliant value

```text
We disclose personal information to our payment processor, our fulfilment partner and our messaging vendor, each acting on our behalf. All of the above exclude text messaging originator opt-in data and consent.
```

## Provider rejection codes

| Provider | Code | Resubmission allowed |
| --- | --- | --- |
| Bandwidth | `7103` | yes |
