{
  "id": "POL-130",
  "slug": "pol-130",
  "title": "The policy must disclose cookies, pixels and tracking",
  "statement": "The privacy policy must disclose the cookies, pixels, SDKs and tracking it uses, and how to opt out of them.",
  "rationale": "For most brands this is ordinary privacy law with no messaging consequence — except where cart reminders are in scope, when the cookie section is what explains how the message was triggered at all. It is also the section most often contradicted by the site itself, which is what POL-108 catches.",
  "layer": "POLICY_PAGE",
  "layerSlug": "policy-page",
  "object": "privacy policy body",
  "severity": "MEDIUM",
  "detectability": [
    "CRAWL"
  ],
  "failureClass": "TERMINAL_POLICY",
  "artifact": "privacy_policy",
  "authorities": [
    "CCPA"
  ],
  "applicabilityText": "Applies to every 10DLC registration.",
  "universal": true,
  "remediation": "Describe the tracking the site actually loads and give the route to turn it off. Done when the section matches what a browser sees on the home page.",
  "example": "We use cookies to keep your basket, to measure how the site is used, and — if you have joined the text programme — to tell when a basket was left unfinished. You can manage them from the cookie settings link in the footer.",
  "phase": "approval",
  "automated": true,
  "url": "https://ekas.io/rules/10dlc/policy-page/pol-130/",
  "markdown": "https://ekas.io/rules/10dlc/policy-page/pol-130.md",
  "registry": "https://ekas.io/rules/10dlc/",
  "updated": "2026-07-25",
  "licence": "CC BY 4.0 — https://creativecommons.org/licenses/by/4.0/"
}
