The policy must name or categorise its processors
The requirementstatement
The privacy policy must name or categorise the third-party processors that handle personal information.
- Severityseverity
- MediumMEDIUMUsually survives review, but lowers your trust score or invites a manual look you would rather avoid.
- When it bitesphase
- Gates approvalapprovalGet this wrong and the brand or campaign is refused at registration.
- What is checkedobject
- privacy policy body
- Where it liveslayer
- Policy pagesPOLICY_PAGE
- How Ekas settles itdetectability
- AI · crawlCRAWL
- Needs your live site or policy page fetched and read. Ekas crawls it the way a reviewer would.
- What the fix involvesfailureClass
- Fix the policyTERMINAL_POLICY
- The fix lives in your privacy policy or SMS terms. Ekas can generate the missing clauses.
- Who requires itauthorities
- TCR
- When it appliesapplicabilityText
- Applies to every 10DLC registration.
Why this rule existsrationale
How to fix itremediation
List the processor categories, naming the messaging vendor explicitly. Done when the carve-back in the messaging clause points at a list a reader can actually see.
A compliant exampleexample
Our processors are: our messaging platform and the wireless carriers that deliver the texts, our hosting provider, our payment processor, and our analytics provider.
Provider rejection codescodes
The code you get back when this rule is what failed, and whether that provider lets you resubmit.
| Provider | Code | Resubmit |
|---|---|---|
| Bandwidth/DCA | 7109 | Yes |
Rules you will hit next
6 other rules read privacy policy body. Fixing one field to satisfy a single rule is how a resubmission trades one rejection for another, so read these before you change anything.
POL-129 is one of 157 policy pages rules in the 915-rule 10DLC registry. Free to cite under CC BY 4.0.