Notice and Choice
Notice and Choice is a longstanding approach to privacy protection, associated primarily with the United States, in which organizations inform individuals about how their data will be collected and used and then give those individuals some ability to accept or decline. The idea is that once people are told what will happen to their data, their continued use of a service reflects an acceptable choice. This model has been widely criticized as inadequate for genuinely protecting individuals.
Notice and Choice is a foundational model in U.S. online privacy regulation and self-regulation under which data-collecting entities provide users with notice of their data practices, typically via a privacy policy, and offer users a mechanism to exercise choice over aspects of that processing. Historically it underpinned a self-regulatory approach in which regulators relied on disclosure and user consent rather than substantive limits on data use. Commentators have critiqued the model on grounds that privacy policies function poorly as instruments of meaningful consent and that the framework leaves individuals without effective protection, prompting proposals to supplement or replace it with unfairness-based or collective-governance approaches. This entry describes the model conceptually and its critique; it does not address specific statutory consent requirements, lawful bases for processing under regimes such as the EU or UK GDPR, enforcement mechanics, or cross-border transfer rules, which are governed by their respective instruments and differ from this U.S.-centered framework.
Why it matters
Notice and Choice has shaped the practical experience of online privacy in the United States for decades, functioning as the default framework under which regulators relied on disclosure and user consent rather than substantive limits on how data may be used. For compliance and privacy professionals, understanding this model is essential because it explains why so many U.S. data practices are structured around privacy policies and opt-in or opt-out mechanisms, and why simply publishing a notice has often been treated as sufficient to legitimize collection. The model rests on the premise that once individuals are told what will happen to their data, their continued use of a service reflects an acceptable choice.
The significance of the term today lies largely in its sustained critique. Commentators have argued that privacy policies function poorly as instruments of meaningful consent and that the framework leaves individuals without effective protection, in part because the burden of understanding and acting on complex disclosures falls on individuals who face deep and often unresolvable differences in expectations and capacities. This critique has prompted proposals to supplement or replace Notice and Choice with unfairness-based or collective-governance approaches, meaning practitioners should not treat notice-and-consent as a self-sufficient compliance strategy.
Professionals working across jurisdictions must also recognize the limits of this model's reach. Notice and Choice is a U.S.-centered concept; it is not equivalent to the lawful-basis structure of the EU or UK GDPR, and it does not by itself satisfy statutory consent requirements found in other regimes. Treating a privacy notice as though it universally establishes a valid basis for processing is a common and consequential error, particularly given that consent is only one possible lawful basis and that different instruments impose different obligations.
Who it's relevant to
Inside Notice and Choice
Common questions
Answers to the questions practitioners most commonly ask about Notice and Choice.