{
  "id": "POL-203",
  "slug": "pol-203",
  "title": "The terms should cover accounts and credentials",
  "statement": "The terms of service must include a clause covering accounts, registration and credential security.",
  "rationale": "Where the service has logins, the account clause is what puts the duty to keep a password safe on the person who holds it — without it the business carries the whole risk of a compromised account. For a messaging programme it also matters that account settings are often where a subscriber manages their preferences.",
  "layer": "POLICY_PAGE",
  "layerSlug": "policy-page",
  "object": "terms of service body",
  "severity": "LOW",
  "detectability": [
    "AI_FORM"
  ],
  "failureClass": "TERMINAL_POLICY",
  "artifact": "sms_terms",
  "authorities": [
    "TCR"
  ],
  "applicability": {
    "excludeUseCases": [
      "M2M"
    ]
  },
  "applicabilityText": "Applies when the use case is NOT M2M.",
  "universal": false,
  "remediation": "Add the accounts clause where the service has user accounts. Done when the document says who is responsible for a login and what happens when it is misused.",
  "example": "You are responsible for keeping your Acme Coffee account password secure and for anything done using your account. Tell us at once if you think someone else has used it.",
  "notes": "Conditional on the service having user accounts, which no applicability dimension expresses; the excludeUseCases tag only keeps it away from machine-to-machine programmes, and the criteria carry the real condition.",
  "phase": "approval",
  "automated": true,
  "url": "https://ekas.io/rules/10dlc/policy-page/pol-203/",
  "markdown": "https://ekas.io/rules/10dlc/policy-page/pol-203.md",
  "registry": "https://ekas.io/rules/10dlc/",
  "updated": "2026-07-25",
  "licence": "CC BY 4.0 — https://creativecommons.org/licenses/by/4.0/"
}
