# POL-128 — The policy must state its position on sensitive personal information

> The privacy policy must state whether sensitive personal information is used beyond the permitted purposes.

- **Rule ID:** POL-128
- **Layer:** Policy pages (`POLICY_PAGE`)
- **Checks:** `privacy policy body`
- **Severity:** MEDIUM — Usually survives review, but lowers your trust score or invites manual review.
- **When it bites:** Gates approval — get this wrong and registration is refused
- **How it is detected:** AI judgement over the submitted form
- **Fix type:** Fix the privacy policy or SMS terms
- **Required by:** CCPA
- **Applies:** Applies to every 10DLC registration.
- **Canonical URL:** https://ekas.io/rules/10dlc/policy-page/pol-128/

## Why this rule exists

The statement decides whether the business owes a Limit-the-Use link, so getting it wrong adds an obligation or drops one. Messaging programmes rarely touch sensitive information at all, which makes the honest answer short — and its absence a gap a reviewer has to fill by guessing.

## How to fix it

Add the sentence, and where the answer is no, say so plainly rather than omitting the section. Done when the document states the position either way.

## Example of a compliant value

```text
We do not use or disclose sensitive personal information beyond the purposes permitted under California law.
```
