Leadership and readiness
Notice vs consent: what's the difference for business records?
By SourceX Editorial · Reviewed by Noah Loul ·
Short answer
Notice tells people how their information will be used; consent asks for their permission, which they can refuse or later withdraw. For business records, the difference decides whether a new use, such as licensing records for AI training, needs an updated notice, an opt-out, opt-in consent or exclusion of the records. Counsel decides which applies, record family by record family.
Key takeaways
- A notice informs people; consent is an affirmative, specific and revocable permission, and one cannot stand in for the other.
- Many comprehensive US state privacy laws rely mainly on notice and opt-out rights, and several require opt-in consent for sensitive data.
- A use not described in the notice in effect at collection is the most common trigger for a fresh notice or consent.
- Removing personal details before licensing can change the analysis, but de-identification standards differ by law.
- Customer, employee, candidate and business contact records may each fall under different rules and promises.
What is the difference between notice and consent?#
Notice is a disclosure: a privacy policy, a collection notice on a form, an employee handbook section or a clause in customer terms that tells people what the company does with their information. The person does not have to do anything for a notice to work.
Consent is permission. The person takes an affirmative step, such as ticking an unticked box or signing a separate form, that agrees to a specific use. Valid consent generally has to be informed and specific, and it can usually be withdrawn.
Opt-out sits between the two. The company gives notice and proceeds, but the person has a right to object and stop the use. Opt-out is a right exercised after notice, not a form of consent.
Notice, opt-out and opt-in compared#
The three mechanisms differ in who has to act and what the default is. That difference determines what records a company must keep to show it complied.
The record-keeping row is where companies most often fall short. Many can produce today's privacy policy but not the version in effect when a ticket was opened long ago. Archiving every version of each notice with its effective dates makes later questions far easier to answer.
| Dimension | Notice only | Notice plus opt-out | Opt-in consent |
|---|---|---|---|
| What the person does | Nothing; they are informed | Can act to stop the use | Must agree before the use |
| Default | Use proceeds | Use proceeds unless they object | No use without agreement |
| Typical form | Privacy policy, handbook, collection notice | Preference center, settings link, request form | Checkbox, signed form, separate agreement |
| Withdrawal | Not applicable | By opting out | Yes, and the use should stop going forward |
| Record to keep | Notice version and the dates it was in effect | Opt-out requests and proof they were honored | Who agreed, when and to what wording |
| Where it commonly appears | Routine business uses | Sale, sharing or targeted advertising under several US state laws | Sensitive data and some EU processing |
When is consent required instead of notice?#
Consent tends to be required when the law, the data or the company's own promises raise the bar. Under GDPR, consent is one of several legal bases for processing, and a company that relies on it must meet strict conditions. Under many US state laws, opt-in consent applies to sensitive data categories, while most other uses run on notice and opt-out rights.
Promises matter as much as statutes. A privacy policy that said customer information would never be shared outside the company, or a customer contract that requires approval before any reuse, can create a consent requirement where no law would.
Timing matters too. Rewriting a privacy policy today does not automatically reach records collected under an older version, and changing promises after the fact can create its own risk. Counsel should review which notice applied when each record was collected.
How the question plays out by record family#
The notice-and-consent question plays out differently for each record family, because each brings its own people, notices and promises. Scope differs by state too: the Colorado Attorney General states that the Colorado Privacy Act does not cover personal data of individuals acting in a commercial or employment context, while other laws, including GDPR, cover business contacts and employees. The table below is a starting map for counsel, not a conclusion about any company's obligations.
Email threads deserve extra care because they carry people who never dealt with the company directly, such as a customer's subcontractor copied on a message. Those people received no notice at all, which is one reason internal communications are usually redacted more heavily than structured records.
| Record family | Whose information | Notice usually relevant | Consent questions to check |
|---|---|---|---|
| Support tickets | Customer staff or consumers | Privacy policy and terms of service | Promises about sharing; sensitive details in free text |
| CRM histories | Business contacts | Privacy policy and marketing notices | Whether state laws cover business contacts; customer contract terms |
| Email and chat | Employees and outside contacts | Employee handbook and acceptable use policy | Employee notice rules in some states; third parties in threads |
| Job and dispatch records | Homeowners and occupants | Service agreements and privacy policy | Addresses, photos of homes and call recordings |
| Applicant tracking records | Candidates | Candidate privacy notice | Usually sensitive and often excluded |
| Code and engineering records | Developers, sometimes customers | Employee notices and customer terms | Customer data pasted into issues or tickets |
A decision rule for a new use of old records#
The decision rule is a sequence of checks that ends with counsel choosing among no action, an updated notice, an opt-out, opt-in consent or excluding the records. Run it for each record family, because answers often differ inside one company.
Stated briefly: when records keep personal data and the use is new, assume more than notice is needed until counsel concludes otherwise. When personal data is removed to the applicable standard, the question often shifts from privacy consent to contract rights and public promises.
- Decide whether the records will still contain personal data after planned preparation.
- Find the notice in effect when the records were collected, not only today's version.
- Compare the new use with the purposes described in that notice.
- Check contracts and promises: customer agreements, data processing addenda and public statements.
- Flag sensitive content such as health, financial, biometric or children's information, and call recordings, which raise separate recording-consent laws in some states.
- Choose the mechanism with counsel and record the decision with the notice versions relied on.
Illustrative: two companies, two different answers#
Illustrative: a fictional staffing firm reviews its Bullhorn records. Candidate notices described use for placement and nothing else, and the records are full of resumes, compensation details and interview notes. Counsel recommends excluding candidate records entirely, and the firm agrees.
A fictional B2B software company reviews its Intercom conversations with business customers. Its privacy policy covered improving services but not licensing, and its customer agreements restrict sharing customer information. Counsel recommends removing personal and customer-identifying details, informing customers through their account managers and excluding conversations from customers who object. The two outcomes differ because the people, notices and promises differ, not because one company is more cautious.
How SourceX documents notice and consent#
Notice and consent are reviewed in the Rights step of the SourceX five-step transaction, alongside contracts and other restrictions. The result is written into the SourceX Evidence Packet as part of the permitted use and the privacy record, and the supplier approves the final scope.
Buyers may ask to see this documentation in a consistent form. The Data & Trust Alliance's Data Provenance Standards, for example, include a metadata element for where consent documentation is located, alongside confidentiality classification and intended data use.
Frequently asked questions
Is accepting a privacy policy the same as giving consent?
Generally not. A privacy policy is notice, and continued use of a service after reading it is weak evidence of consent under many laws. Where consent is required, laws such as GDPR expect a clear affirmative action tied to a specific purpose, separate from general terms.
Does an opt-out count as consent?
No. An opt-out gives people the right to stop a use that proceeds by default. Under GDPR, consent must be an affirmative act, so silence or a pre-ticked box does not qualify. Under US state laws, opt-out rights typically apply to specific uses named in the statute.
Do we need employee consent to license internal email or chat?
It depends on the laws that may apply and on what employees were told. Consent in employment can be hard to rely on because of the power imbalance, so companies often look at updated notices and thorough de-identification instead. Counsel should assess this before any internal communications are in scope.
Can we rely on consent collected years ago?
Only if the wording covered the use you now plan, and you can show who agreed and to what. Broad or vague consent language is often read narrowly. Keep the original wording and records, and treat gaps as a reason to update notice or exclude records.
If we remove all personal data, do notice and consent still matter?
Privacy notice and consent rules may matter less if the records meet the applicable de-identification standard. Contract terms, confidentiality obligations and public promises still apply, and customers and employees may still expect to be told. Counsel should confirm the standard has been met.
Sources
- The Use group of the Data & Trust Alliance Data Provenance Standards includes elements for confidentiality classification, consent documentation location, privacy-enhancing technologies applied, allowed and excluded processing and storage geographies, license to use, intended data use, and copyright, patent and trademark status. Source
- The Colorado Attorney General states that the Colorado Privacy Act protects personal data of Colorado residents acting in an individual or household context, does not cover individuals acting in a commercial or employment context, and does not apply to data maintained for employment records purposes. Source
Related resources
See if your company qualifies
A short company assessment. No data uploads are needed.