The policy must say whether data was sold or shared in the last 12 months
The requirementstatement
The privacy policy must state whether personal information was sold or shared in the preceding twelve months, or affirmatively that it was not.
- Severityseverity
- HighHIGHRejected by at least one carrier or provider, and a common cause of failure at the rest.
- When it bitesphase
- Gates approvalapprovalGet this wrong and the brand or campaign is refused at registration.
- What is checkedobject
- privacy policy body
- Where it liveslayer
- Policy pagesPOLICY_PAGE
- How Ekas settles itdetectability
- AI · formAI_FORM
- A semantic question about what you wrote: whether a description matches a use case, whether a name looks like a filed entity. Judged by a model against written criteria.
- What the fix involvesfailureClass
- Fix the policyTERMINAL_POLICY
- The fix lives in your privacy policy or SMS terms. Ekas can generate the missing clauses.
- Who requires itauthorities
- CCPA
- When it appliesapplicabilityText
- Applies to every 10DLC registration.
Why this rule existsrationale
How to fix itremediation
State the answer plainly and, where it is yes, exclude messaging opt-in data from it in the same paragraph. Done when the twelve-month statement cannot be read as covering the text programme.
A compliant exampleexample
In the last 12 months we have not sold or shared personal information. Text messaging opt-in data and consent are never sold or shared in any case.
Provider rejection codescodes
The code you get back when this rule is what failed, and whether that provider lets you resubmit.
| Provider | Code | Resubmit |
|---|---|---|
| Bandwidth | 7103 | Yes |
Notesnotes
Rules you will hit next
6 other rules read privacy policy body. Fixing one field to satisfy a single rule is how a resubmission trades one rejection for another, so read these before you change anything.
POL-126 is one of 157 policy pages rules in the 915-rule 10DLC registry. Free to cite under CC BY 4.0.