{
  "id": "POL-140",
  "slug": "pol-140",
  "title": "Both documents must say how changes are communicated",
  "statement": "The privacy policy must carry a section describing how changes to it are communicated.",
  "rationale": "A policy that can change silently is a promise with an expiry date nobody is told about, and the section is what lets a consumer know a change has happened without re-reading the document. It matters more for a messaging programme than for most, because a material change to the programme is supposed to be reflected in these documents and dated.",
  "layer": "POLICY_PAGE",
  "layerSlug": "policy-page",
  "object": "privacy policy body",
  "severity": "MEDIUM",
  "detectability": [
    "CRAWL"
  ],
  "failureClass": "TERMINAL_POLICY",
  "artifact": "privacy_policy",
  "authorities": [
    "TCR"
  ],
  "applicabilityText": "Applies to every 10DLC registration.",
  "universal": true,
  "remediation": "Add a \"Changes to this policy\" section to both the privacy policy and the terms, saying how notice is given and when a change takes effect. Done when both documents carry it.",
  "example": "We may update this policy. We will change the Last updated date above and, where the change is material, post a notice on acmecoffee.com for 30 days before it takes effect.",
  "notes": "Absorbs POL-218, the same clause required of the terms — one requirement across both documents rather than two.",
  "catalogIds": [
    "POL-218"
  ],
  "phase": "approval",
  "automated": true,
  "url": "https://ekas.io/rules/10dlc/policy-page/pol-140/",
  "markdown": "https://ekas.io/rules/10dlc/policy-page/pol-140.md",
  "registry": "https://ekas.io/rules/10dlc/",
  "updated": "2026-07-25",
  "licence": "CC BY 4.0 — https://creativecommons.org/licenses/by/4.0/"
}
