{
  "id": "POL-250",
  "slug": "pol-250",
  "title": "A generated policy must not describe practices the site does not perform",
  "statement": "A generated policy must not describe practices the brand does not actually perform.",
  "rationale": "Generation makes this failure easy in a way that drafting does not: a template section about cookies goes into a document for a site that has none, or a \"we do not use tracking\" line goes into a document for a site loading three analytics tags. The result is a public statement that is false, which is an FTC deception question rather than a carrier one.",
  "layer": "POLICY_PAGE",
  "layerSlug": "policy-page",
  "object": "generated policy body vs the site's observed behaviour",
  "severity": "HIGH",
  "detectability": [
    "CRAWL"
  ],
  "failureClass": "TERMINAL_POLICY",
  "artifact": "privacy_policy",
  "authorities": [
    "CTIA"
  ],
  "applicabilityText": "Applies to every 10DLC registration.",
  "universal": true,
  "remediation": "Check every practice claim against the live site before publishing, and delete the sections that describe things the business does not do. Done when each claim in the document can be pointed at on the site.",
  "notes": "The machine-checkable half of POL-108, which asks the same question of a policy the brand already published. This one is the generation-time gate, so it is the one that can stop the false statement being made at all.",
  "phase": "approval",
  "automated": true,
  "url": "https://ekas.io/rules/10dlc/policy-page/pol-250/",
  "markdown": "https://ekas.io/rules/10dlc/policy-page/pol-250.md",
  "registry": "https://ekas.io/rules/10dlc/",
  "updated": "2026-07-25",
  "licence": "CC BY 4.0 — https://creativecommons.org/licenses/by/4.0/"
}
