Skip to main content
Category: Legal Basis and Consent

Notice and Choice

Also known as: Notice-and-Choice, Notice and Consent
Simply put

Notice and Choice is a longstanding approach to privacy protection, associated primarily with the United States, in which organizations inform individuals about how their data will be collected and used and then give those individuals some ability to accept or decline. The idea is that once people are told what will happen to their data, their continued use of a service reflects an acceptable choice. This model has been widely criticized as inadequate for genuinely protecting individuals.

Formal definition

Notice and Choice is a foundational model in U.S. online privacy regulation and self-regulation under which data-collecting entities provide users with notice of their data practices, typically via a privacy policy, and offer users a mechanism to exercise choice over aspects of that processing. Historically it underpinned a self-regulatory approach in which regulators relied on disclosure and user consent rather than substantive limits on data use. Commentators have critiqued the model on grounds that privacy policies function poorly as instruments of meaningful consent and that the framework leaves individuals without effective protection, prompting proposals to supplement or replace it with unfairness-based or collective-governance approaches. This entry describes the model conceptually and its critique; it does not address specific statutory consent requirements, lawful bases for processing under regimes such as the EU or UK GDPR, enforcement mechanics, or cross-border transfer rules, which are governed by their respective instruments and differ from this U.S.-centered framework.

Why it matters

Notice and Choice has shaped the practical experience of online privacy in the United States for decades, functioning as the default framework under which regulators relied on disclosure and user consent rather than substantive limits on how data may be used. For compliance and privacy professionals, understanding this model is essential because it explains why so many U.S. data practices are structured around privacy policies and opt-in or opt-out mechanisms, and why simply publishing a notice has often been treated as sufficient to legitimize collection. The model rests on the premise that once individuals are told what will happen to their data, their continued use of a service reflects an acceptable choice.

The significance of the term today lies largely in its sustained critique. Commentators have argued that privacy policies function poorly as instruments of meaningful consent and that the framework leaves individuals without effective protection, in part because the burden of understanding and acting on complex disclosures falls on individuals who face deep and often unresolvable differences in expectations and capacities. This critique has prompted proposals to supplement or replace Notice and Choice with unfairness-based or collective-governance approaches, meaning practitioners should not treat notice-and-consent as a self-sufficient compliance strategy.

Professionals working across jurisdictions must also recognize the limits of this model's reach. Notice and Choice is a U.S.-centered concept; it is not equivalent to the lawful-basis structure of the EU or UK GDPR, and it does not by itself satisfy statutory consent requirements found in other regimes. Treating a privacy notice as though it universally establishes a valid basis for processing is a common and consequential error, particularly given that consent is only one possible lawful basis and that different instruments impose different obligations.

Who it's relevant to

U.S. privacy and compliance officers
Professionals structuring data practices under U.S. frameworks need to understand Notice and Choice because it has historically underpinned disclosure-and-consent approaches. They should recognize its criticized limitations and avoid treating a published privacy policy alone as demonstrable evidence of adequate privacy protection.
Data protection officers operating across jurisdictions
DPOs working with both U.S. and non-U.S. regimes should not conflate Notice and Choice with the lawful-basis structure of the EU or UK GDPR. Consent is only one possible lawful basis under those instruments, and a U.S.-style notice does not by itself satisfy their statutory requirements.
Privacy engineers and product teams
Those designing notice mechanisms and consent flows should be aware that the model has been critiqued on grounds that privacy policies function poorly as instruments of meaningful consent. Design choices that rely on disclosure alone may not deliver effective protection for individuals.
Legal counsel and policy specialists
Lawyers advising on privacy strategy should understand both the historical role of Notice and Choice as a self-regulatory framework and the proposals to supplement or replace it with unfairness-based or collective-governance approaches, which signal shifting expectations about what constitutes adequate protection.

Inside Notice and Choice

Notice
The disclosure component, through which an organization informs individuals about its data practices, typically including what personal data is collected, the purposes of processing, and how the data is used, shared, or retained. Notice is generally delivered through a privacy notice or policy, though the specific content requirements vary by regime and are not addressed exhaustively here.
Choice
The mechanism through which individuals can exercise some control over the processing of their personal data, such as opting in or opting out of certain uses. The scope and enforceability of choice differ significantly across frameworks; for example, opt-out models feature prominently in the CCPA and CPRA, while the EU and UK GDPR generally rely on lawful bases rather than a standalone notice-and-choice construct.
Origin and framing
Notice and choice is a framing most closely associated with US and self-regulatory privacy approaches, including fair information practice principles. It is not a term of art with a fixed statutory definition across all jurisdictions, and its treatment differs between US state laws and the GDPR-based regimes.
Relationship to lawful basis
In GDPR-based regimes, notice is an accountability and transparency obligation borne generally by the data controller, and choice in the form of consent is only one of several lawful bases for processing. Notice and choice should not be read as establishing consent as the default or sole lawful basis.
Accountability dimension
Providing notice and offering choice are governance activities that, under accountability-oriented frameworks, must typically be supported by demonstrable evidence such as documented notices, records of choices exercised, and mechanisms to honor those choices, rather than stated intent alone.

Common questions

Answers to the questions practitioners most commonly ask about Notice and Choice.

Does providing notice and choice by itself make our processing lawful?
Not necessarily. Notice and choice is a transparency-and-control model that surfaces information to individuals and offers them options, but it should not be conflated with establishing a lawful basis for processing. Under the EU GDPR and UK GDPR, consent is only one of several lawful bases, and choice presented to a data subject is not the same as satisfying the conditions for valid consent or for another basis such as legitimate interests or contractual necessity. Whether processing is lawful depends on jurisdiction, the applicable regime, and how the mechanism is implemented, so notice and choice alone does not guarantee compliance.
Is the choice we offer users the same thing as GDPR consent?
Generally no. Notice and choice as a model is most closely associated with certain frameworks and with US approaches such as those reflected in CCPA and CPRA, where opt-out choices feature prominently. Consent under the EU GDPR and UK GDPR has specific qualifying conditions and differs in treatment. A choice mechanism, particularly an opt-out, may not meet the standard required where consent is the applicable lawful basis, and the two concepts should be kept distinct rather than treated as interchangeable.
Where should the notice be presented relative to when a choice is offered?
Typically the notice should be available to the individual before or at the point the relevant choice is exercised, so the person can make an informed decision. The specific timing and placement expectations vary by regime and context, and this entry does not prescribe cross-border or sector-specific requirements. Implementation should be validated against the applicable framework rather than assumed to be uniform across jurisdictions.
How do we demonstrate that notice was given and choice was honored?
Under accountability-oriented governance frameworks, demonstrable evidence is generally expected rather than stated intent alone. In practice this can mean retaining records of the notice content and version presented, the choices offered, and how a given individual's selection was captured and applied downstream. The precise evidentiary expectations depend on the applicable regime and are outside the scope of this entry to enumerate exhaustively.
Which team owns the notice-and-choice mechanism, governance or security?
Responsibility usually spans both without collapsing the distinction. Data governance functions typically address the accuracy, ownership, and lifecycle of the notice content and the policies behind the choices offered, while information security functions typically address the confidentiality, integrity, and availability of the systems that capture and enforce those choices. Clear allocation of these roles supports accountability, but the specific ownership model depends on organizational structure.
Does a choice mechanism need to reflect changes when our processing purposes change?
Generally the notice and the associated choices should remain aligned with the actual processing, so material changes in purpose typically warrant reviewing and, where appropriate, updating both. This entry does not address retention rules, cross-border transfer mechanics, or enforcement consequences, and the applicable requirements for handling changes depend on the relevant regime and implementation context.

Common misconceptions

Providing notice and obtaining a choice guarantees compliance with applicable privacy law.
No single mechanism guarantees compliance. Compliance depends on jurisdiction, context, and implementation. In GDPR-based regimes, choice in the form of consent is only one of several lawful bases, and even a valid notice does not by itself satisfy all obligations. In some contexts a lawful basis other than consent may apply, so treating choice as universally required or sufficient is generally incorrect.
Notice and choice works the same way across the EU GDPR, UK GDPR, and the CCPA/CPRA.
These regimes are not interchangeable. The CCPA and CPRA emphasize opt-out rights for certain activities, while the EU and UK GDPR are structured around lawful bases and transparency obligations rather than a notice-and-choice model. The specific rights, defaults, and disclosures differ, and this entry does not detail those differences in full.
Choice and consent are the same thing.
Choice is a broader concept that may include opt-in, opt-out, or preference settings, whereas consent is a specific, legally defined lawful basis in GDPR-based regimes with particular validity conditions. Conflating the two can lead practitioners to over-rely on consent where another lawful basis is more appropriate or where an opt-out model applies.

Best practices

Identify the applicable regime or regimes before designing notice and choice, and tailor disclosures and control mechanisms to each rather than assuming a single uniform approach satisfies all jurisdictions.
In GDPR-based regimes, determine and document the appropriate lawful basis for each processing activity rather than defaulting to consent, and reserve consent-based choice for situations where it is genuinely the correct basis.
Ensure the data controller retains and can produce demonstrable evidence that notice was provided and that choices were captured and honored, since accountability generally requires evidence rather than stated intent.
Keep privacy notices accurate and aligned with actual processing practices, updating them when purposes, sharing, or retention practices change.
Implement operational mechanisms to give effect to choices, such as opt-out handling, so that offered choices are reliably enforced across systems.
Use qualified, jurisdiction-specific language in internal guidance and avoid representing notice and choice as a complete compliance solution or as making data non-personal.