{
  "id": "POL-157",
  "slug": "pol-157",
  "title": "The documents must describe the programme as it runs today",
  "statement": "The terms and the privacy policy must give up-to-date, accurate information about the programme's details and functionality.",
  "rationale": "CTIA asks for accuracy rather than mere presence, and a document describing a programme that has since changed is worse than a missing one — a consumer relying on a frequency cap that no longer holds has been misled by a compliance document. Programmes drift constantly: a new message category, a different keyword set, a platform migration, and the terms are rarely part of the change.",
  "layer": "POLICY_PAGE",
  "layerSlug": "policy-page",
  "object": "privacy policy + SMS terms body",
  "severity": "HIGH",
  "detectability": [
    "AI_FORM"
  ],
  "failureClass": "TERMINAL_POLICY",
  "artifact": "sms_terms",
  "authorities": [
    "CTIA",
    "AWS"
  ],
  "applicabilityText": "Applies to every 10DLC registration.",
  "universal": true,
  "remediation": "Read both documents against the campaign as registered and correct anything that has moved on — categories, frequency, keywords, contact routes. Done when every factual claim in either document is true of the programme today.",
  "example": "Terms updated alongside the campaign: \"up to 6 messages per month\" replaced by \"message frequency varies\" when the weekly send was added.",
  "notes": "Whether the documents carry a date is POL-141; whether the date is recent enough for the programme is POL-233. This rule is about the substance rather than the dating.",
  "phase": "approval",
  "automated": true,
  "url": "https://ekas.io/rules/10dlc/policy-page/pol-157/",
  "markdown": "https://ekas.io/rules/10dlc/policy-page/pol-157.md",
  "registry": "https://ekas.io/rules/10dlc/",
  "updated": "2026-07-25",
  "licence": "CC BY 4.0 — https://creativecommons.org/licenses/by/4.0/"
}
