# POL-136 — A business that sells or shares must publish the Do-Not-Sell link

> Where the business sells or shares personal information, the "Do Not Sell or Share My Personal Information" link must be published on the site.

- **Rule ID:** POL-136
- **Layer:** Policy pages (`POLICY_PAGE`)
- **Checks:** `site-wide Do-Not-Sell link`
- **Severity:** HIGH — Rejected by at least one carrier or provider, and a common cause of failure at the rest.
- **When it bites:** Gates approval — get this wrong and registration is refused
- **How it is detected:** AI judgement over the crawled website or policy page
- **Fix type:** Fix the website — no form edit clears it
- **Required by:** CCPA
- **Applies:** Applies to every 10DLC registration.
- **Canonical URL:** https://ekas.io/rules/10dlc/policy-page/pol-136/

## Why this rule exists

California requires the link wherever the business does either, and its absence is a compliance failure in its own right. It is worth pairing with the messaging carve-out deliberately rather than by accident: publishing the link invites a reviewer to ask whether the messaging data is inside the request, which is the question POL-067 exists to answer in advance.

## How to fix it

Publish the link in the site footer and state next to it that messaging opt-in data is excluded from sale or sharing in any case. Done when the link is present and the exclusion is unambiguous.

## Provider rejection codes

| Provider | Code | Resubmission allowed |
| --- | --- | --- |
| Bandwidth | `7103` | yes |

## Notes

Conditional on the business selling or sharing personal information, which no applicability dimension expresses; the criteria pass immediately where the policy discloses neither. Pair with POL-067 — publishing the link without the carve-out statement is the trap.
