10DLC Privacy Policy Requirements: What Carriers Actually Check (+ Template)

No single document rejects more 10DLC campaigns than the privacy policy. Not because the requirements are hard (they amount to a few specific sentences) but because almost nobody knows which sentences reviewers are scanning for. This guide lists them exactly, with adaptable template language.

Why your privacy policy is part of SMS registration at all

When a DCA reviewer evaluates your campaign, they verify that the consent story you told in the form exists in reality. The privacy policy is where your data practices are legally stated, so the reviewer opens your website, finds the policy, and checks that it covers the phone numbers you are collecting. Missing, unreachable, or silent-on-SMS policies fail the campaign.

The checklist reviewers apply

  1. The policy exists on the same website you registered and is reachable from an obvious place (footer link).
  2. It discloses that you collect phone numbers / SMS opt-in data and what you use them for (sending the messages the user signed up for).
  3. It contains the non-sharing statement, saying that SMS consent data is not shared with third parties for marketing. This is the sentence whose absence causes the most rejections.
  4. It doesn’t contradict itself. A policy that elsewhere says "we share your personal information with marketing partners" without carving out SMS data reads as a violation.
  5. It mentions how to opt out of messaging (STOP), often alongside the SMS section.

Template language

Adapt the following into your existing policy (this is a starting point, not legal advice):

SMS/Text Messaging. If you opt in to receive text messages from [Business Name], we collect your phone number and your consent record (date, time, and source of opt-in). We use this information solely to send you the messages you signed up for, such as [appointment reminders / order updates / promotional offers]. Message frequency varies and message & data rates may apply. You can opt out at any time by replying STOP, or get help by replying HELP.
No Third-Party Marketing. Text messaging originator opt-in data and consent are not shared with, sold to, or rented to any third parties for marketing or promotional purposes. We may share this data only with our service providers who send messages on our behalf (such as our messaging platform), and only for that purpose.

Will your website pass carrier review?

Paste your URL into our free AI scanner and get an instant PASS / WARN / FAIL compliance report. No signup needed.

Run a free compliance scan

Placement rules

  • Footer link on every page. Reviewers look there first.
  • Linked at the point of opt-in. The consent checkbox language should reference "Privacy Policy" as a working link.
  • On the registered domain. A policy hosted on a different domain than the one in your brand registration raises mismatch flags.
  • Actually live. Staging links, login-walled pages, and PDFs that 404 are all equivalent to "no policy" for review purposes.

Common failure modes

  • The generic template. A boilerplate policy about cookies and analytics that never mentions phone numbers or texting. Very common, always insufficient.
  • The contradiction. SMS section says "not shared"; the general sharing section says "we share personal information with partners for their marketing." Reviewers read both.
  • The orphan policy. Exists at /privacy but no page links to it.
  • The wrong entity. Policy names a different company than the registered brand (common after rebrands and white-label setups).

This is the single highest-ROI fix in all of 10DLC: two paragraphs of policy text prevent the most common multi-week rejection. Our free scanner reads your policy the way a reviewer does, including the non-sharing statement check, before you submit. For the broader consent rules the policy supports, see SMS opt-in requirements.

Frequently asked questions

Do I need a separate SMS terms page?

Not strictly; the required disclosures can live inside your privacy policy and terms of service. Many programs add a dedicated /sms-terms page (program name, frequency, STOP/HELP, support contact); it is good practice and makes reviews smoother, but the privacy policy statements described here are the hard requirement.

Does the non-sharing clause forbid using Twilio or my messaging platform?

No. Service providers acting on your behalf to deliver messages are not "third parties for marketing purposes." The clause targets selling/renting opt-in lists to other marketers. State the service-provider carve-out explicitly, as in the template.

My privacy policy is on my main site but I registered a different product domain. Problem?

Potentially yes, because reviewers check the registered website. Either host/link the policy on the registered domain or ensure the registered site clearly links to the canonical policy covering it.

Check your compliance before you submit

Most 10DLC rejections trace back to the sender's website: a missing SMS clause in the privacy policy, no visible opt-in language, mismatched business details. Our free AI scanner reads your site the way a carrier reviewer does and tells you what to fix.

Scan my website free No signup required  ·  Results in ~30 seconds

Related to this topic: