A brand handling EU or UK data needs a GDPR addendum
The requirementstatement
The privacy policy must carry a GDPR addendum naming the controller, the legal bases, transfers, withdrawal of consent and the right to complain.
- Severityseverity
- MediumMEDIUMUsually survives review, but lowers your trust score or invites a manual look you would rather avoid.
- When it bitesphase
- Gates approvalapprovalGet this wrong and the brand or campaign is refused at registration.
- What is checkedobject
- privacy policy body
- Where it liveslayer
- Policy pagesPOLICY_PAGE
- How Ekas settles itdetectability
- AI · formAI_FORM
- A semantic question about what you wrote: whether a description matches a use case, whether a name looks like a filed entity. Judged by a model against written criteria.
- What the fix involvesfailureClass
- Fix the policyTERMINAL_POLICY
- The fix lives in your privacy policy or SMS terms. Ekas can generate the missing clauses.
- Who requires itauthorities
- GDPR
- When it appliesapplicabilityText
- Applies to every 10DLC registration.
Why this rule existsrationale
How to fix itremediation
Add the addendum as its own section rather than weaving it through the document, and make its consent-withdrawal route the same one the SMS terms give. Done when each element is present and the two documents agree.
A compliant exampleexample
For visitors in the EU and UK: the controller is Acme Coffee Co, LLC. We rely on your consent to send marketing texts; you can withdraw it at any time by replying STOP or emailing privacy@acmecoffee.com, and you may complain to your local supervisory authority.
Notesnotes
Rules you will hit next
6 other rules read privacy policy body. Fixing one field to satisfy a single rule is how a resubmission trades one rejection for another, so read these before you change anything.
POL-133 is one of 157 policy pages rules in the 915-rule 10DLC registry. Free to cite under CC BY 4.0.