{
  "id": "POL-129",
  "slug": "pol-129",
  "title": "The policy must name or categorise its processors",
  "statement": "The privacy policy must name or categorise the third-party processors that handle personal information.",
  "rationale": "The service-provider carve-back the messaging clause depends on is only meaningful if the reader can tell who the service providers are — otherwise \"vendors acting on our behalf\" is an open door with a friendly label. Naming the messaging platform and the carriers is also the sentence that makes the carve-back obviously narrow rather than obviously convenient.",
  "layer": "POLICY_PAGE",
  "layerSlug": "policy-page",
  "object": "privacy policy body",
  "severity": "MEDIUM",
  "detectability": [
    "CRAWL"
  ],
  "failureClass": "TERMINAL_POLICY",
  "artifact": "privacy_policy",
  "authorities": [
    "TCR"
  ],
  "codes": [
    {
      "provider": "Bandwidth/DCA",
      "code": "7109",
      "remediable": true
    }
  ],
  "applicabilityText": "Applies to every 10DLC registration.",
  "universal": true,
  "remediation": "List the processor categories, naming the messaging vendor explicitly. Done when the carve-back in the messaging clause points at a list a reader can actually see.",
  "example": "Our processors are: our messaging platform and the wireless carriers that deliver the texts, our hosting provider, our payment processor, and our analytics provider.",
  "phase": "approval",
  "automated": true,
  "url": "https://ekas.io/rules/10dlc/policy-page/pol-129/",
  "markdown": "https://ekas.io/rules/10dlc/policy-page/pol-129.md",
  "registry": "https://ekas.io/rules/10dlc/",
  "updated": "2026-07-25",
  "licence": "CC BY 4.0 — https://creativecommons.org/licenses/by/4.0/"
}
