Never assert a fact about the business nobody has confirmed

The requirementstatement

A generated document must assert no fact about the business — retention periods, encryption, sub-processors, certifications, jurisdictions — that has not been sourced or confirmed by the user.

Severityseverity
BlockingBLOCKINGBreaking this rule gets the submission rejected. There is no partial credit.
When it bitesphase
Gates approvalapprovalGet this wrong and the brand or campaign is refused at registration.
What is checkedobject
generated policy factual assertions
Where it liveslayer
Policy pagesPOLICY_PAGE
How Ekas settles itdetectability
Human checkHUMAN
Only someone holding the document or making the call can settle it. Ekas tells you exactly what to look at.
What the fix involvesfailureClass
Supply evidenceTERMINAL_EVIDENCE
Needs proof only you hold: a screenshot, a recording, a scan of the form people signed.
Who requires itauthorities
FTCTCR
When it appliesapplicabilityText
Applies to every 10DLC registration.

Why this rule existsrationale

Every invented fact in a privacy policy is a public representation the business will be held to, and the ones a generator reaches for are exactly the ones nobody checks: a thirty-day retention period, AES-256 at rest, a SOC 2 report that does not exist. The FTC treats a false privacy claim as a deceptive practice, so this is the one obligation in the layer where the consequence is an enforcement action rather than a rejection.

How to fix itremediation

Confirm each factual claim with the person who would know — retention with whoever runs the database, encryption with whoever runs the infrastructure, certifications with whoever holds the audit report — and delete the ones nobody can confirm. Done when every specific in the document traces to somebody who said it.

Check this yourselfattestation

No tool can settle this one for you. Here is the check, and what wrong looks like.

Can you name a person who confirmed each specific claim in this document — retention periods, encryption, sub-processors, certifications?

  1. 1Read the document as a list of assertions about your own business.
  2. 2For each specific, ask the person who would know: retention with whoever runs the database, encryption with whoever runs the infrastructure, certifications with whoever holds the audit report.
  3. 3Delete every claim nobody can source. Invented SOC 2, ISO 27001 and HIPAA claims are the named ones.

What wrong looks like: A thirty-day retention period and AES-256 at rest arrive in the draft because they are plausible. The FTC treats a false privacy claim as a deceptive practice, so the consequence is an enforcement action rather than a rejection.

Notesnotes

Nothing in a registration reveals whether a claim was confirmed, which is why this cannot be settled here. The user has to read the generated document as a set of assertions about their own business and strike out everything they cannot personally source. Invented SOC 2, ISO 27001 and HIPAA claims are the specific ones the research names.

Rules you will hit next

Other policy pages rules at the same severity. A registration is judged as a whole, not rule by rule.

All policy pages rules

POL-242 is one of 157 policy pages rules in the 915-rule 10DLC registry. Free to cite under CC BY 4.0.

Reading the rules is the easy part.

Ekas runs every rule that gates approval, 823 of these 915, against your registration before it reaches the carrier. It reads your site, your policy pages and your opt-in the way a reviewer would, and hands you the fix, not just the verdict.