# POL-140 — Both documents must say how changes are communicated

> The privacy policy must carry a section describing how changes to it are communicated.

- **Rule ID:** POL-140
- **Layer:** Policy pages (`POLICY_PAGE`)
- **Checks:** `privacy policy body`
- **Severity:** MEDIUM — Usually survives review, but lowers your trust score or invites manual review.
- **When it bites:** Gates approval — get this wrong and registration is refused
- **How it is detected:** AI judgement over the crawled website or policy page
- **Fix type:** Fix the privacy policy or SMS terms
- **Required by:** TCR
- **Applies:** Applies to every 10DLC registration.
- **Canonical URL:** https://ekas.io/rules/10dlc/policy-page/pol-140/

## Why this rule exists

A policy that can change silently is a promise with an expiry date nobody is told about, and the section is what lets a consumer know a change has happened without re-reading the document. It matters more for a messaging programme than for most, because a material change to the programme is supposed to be reflected in these documents and dated.

## How to fix it

Add a "Changes to this policy" section to both the privacy policy and the terms, saying how notice is given and when a change takes effect. Done when both documents carry it.

## Example of a compliant value

```text
We may update this policy. We will change the Last updated date above and, where the change is material, post a notice on acmecoffee.com for 30 days before it takes effect.
```

## Notes

Absorbs POL-218, the same clause required of the terms — one requirement across both documents rather than two.
