Skip to content

Leadership and readiness

Notice vs consent: what's the difference for business records?

By SourceX Editorial · Reviewed by Noah Loul ·

Short answer

Notice tells people how their information will be used; consent asks for their permission, which they can refuse or later withdraw. For business records, the difference decides whether a new use, such as licensing records for AI training, needs an updated notice, an opt-out, opt-in consent or exclusion of the records. Counsel decides which applies, record family by record family.

Key takeaways

  • A notice informs people; consent is an affirmative, specific and revocable permission, and one cannot stand in for the other.
  • Many comprehensive US state privacy laws rely mainly on notice and opt-out rights, and several require opt-in consent for sensitive data.
  • A use not described in the notice in effect at collection is the most common trigger for a fresh notice or consent.
  • Removing personal details before licensing can change the analysis, but de-identification standards differ by law.
  • Customer, employee, candidate and business contact records may each fall under different rules and promises.

Notice is a disclosure: a privacy policy, a collection notice on a form, an employee handbook section or a clause in customer terms that tells people what the company does with their information. The person does not have to do anything for a notice to work.

Consent is permission. The person takes an affirmative step, such as ticking an unticked box or signing a separate form, that agrees to a specific use. Valid consent generally has to be informed and specific, and it can usually be withdrawn.

Opt-out sits between the two. The company gives notice and proceeds, but the person has a right to object and stop the use. Opt-out is a right exercised after notice, not a form of consent.

Notice, opt-out and opt-in compared#

The three mechanisms differ in who has to act and what the default is. That difference determines what records a company must keep to show it complied.

The record-keeping row is where companies most often fall short. Many can produce today's privacy policy but not the version in effect when a ticket was opened long ago. Archiving every version of each notice with its effective dates makes later questions far easier to answer.

Notice, opt-out and opt-in compared
DimensionNotice onlyNotice plus opt-outOpt-in consent
What the person doesNothing; they are informedCan act to stop the useMust agree before the use
DefaultUse proceedsUse proceeds unless they objectNo use without agreement
Typical formPrivacy policy, handbook, collection noticePreference center, settings link, request formCheckbox, signed form, separate agreement
WithdrawalNot applicableBy opting outYes, and the use should stop going forward
Record to keepNotice version and the dates it was in effectOpt-out requests and proof they were honoredWho agreed, when and to what wording
Where it commonly appearsRoutine business usesSale, sharing or targeted advertising under several US state lawsSensitive data and some EU processing

Consent tends to be required when the law, the data or the company's own promises raise the bar. Under GDPR, consent is one of several legal bases for processing, and a company that relies on it must meet strict conditions. Under many US state laws, opt-in consent applies to sensitive data categories, while most other uses run on notice and opt-out rights.

Promises matter as much as statutes. A privacy policy that said customer information would never be shared outside the company, or a customer contract that requires approval before any reuse, can create a consent requirement where no law would.

Timing matters too. Rewriting a privacy policy today does not automatically reach records collected under an older version, and changing promises after the fact can create its own risk. Counsel should review which notice applied when each record was collected.

How the question plays out by record family#

The notice-and-consent question plays out differently for each record family, because each brings its own people, notices and promises. Scope differs by state too: the Colorado Attorney General states that the Colorado Privacy Act does not cover personal data of individuals acting in a commercial or employment context, while other laws, including GDPR, cover business contacts and employees. The table below is a starting map for counsel, not a conclusion about any company's obligations.

Email threads deserve extra care because they carry people who never dealt with the company directly, such as a customer's subcontractor copied on a message. Those people received no notice at all, which is one reason internal communications are usually redacted more heavily than structured records.

How the question plays out by record family
Record familyWhose informationNotice usually relevantConsent questions to check
Support ticketsCustomer staff or consumersPrivacy policy and terms of servicePromises about sharing; sensitive details in free text
CRM historiesBusiness contactsPrivacy policy and marketing noticesWhether state laws cover business contacts; customer contract terms
Email and chatEmployees and outside contactsEmployee handbook and acceptable use policyEmployee notice rules in some states; third parties in threads
Job and dispatch recordsHomeowners and occupantsService agreements and privacy policyAddresses, photos of homes and call recordings
Applicant tracking recordsCandidatesCandidate privacy noticeUsually sensitive and often excluded
Code and engineering recordsDevelopers, sometimes customersEmployee notices and customer termsCustomer data pasted into issues or tickets

A decision rule for a new use of old records#

The decision rule is a sequence of checks that ends with counsel choosing among no action, an updated notice, an opt-out, opt-in consent or excluding the records. Run it for each record family, because answers often differ inside one company.

Stated briefly: when records keep personal data and the use is new, assume more than notice is needed until counsel concludes otherwise. When personal data is removed to the applicable standard, the question often shifts from privacy consent to contract rights and public promises.

  • Decide whether the records will still contain personal data after planned preparation.
  • Find the notice in effect when the records were collected, not only today's version.
  • Compare the new use with the purposes described in that notice.
  • Check contracts and promises: customer agreements, data processing addenda and public statements.
  • Flag sensitive content such as health, financial, biometric or children's information, and call recordings, which raise separate recording-consent laws in some states.
  • Choose the mechanism with counsel and record the decision with the notice versions relied on.

Illustrative: two companies, two different answers#

Illustrative: a fictional staffing firm reviews its Bullhorn records. Candidate notices described use for placement and nothing else, and the records are full of resumes, compensation details and interview notes. Counsel recommends excluding candidate records entirely, and the firm agrees.

A fictional B2B software company reviews its Intercom conversations with business customers. Its privacy policy covered improving services but not licensing, and its customer agreements restrict sharing customer information. Counsel recommends removing personal and customer-identifying details, informing customers through their account managers and excluding conversations from customers who object. The two outcomes differ because the people, notices and promises differ, not because one company is more cautious.

Notice and consent are reviewed in the Rights step of the SourceX five-step transaction, alongside contracts and other restrictions. The result is written into the SourceX Evidence Packet as part of the permitted use and the privacy record, and the supplier approves the final scope.

Buyers may ask to see this documentation in a consistent form. The Data & Trust Alliance's Data Provenance Standards, for example, include a metadata element for where consent documentation is located, alongside confidentiality classification and intended data use.

Frequently asked questions

Is accepting a privacy policy the same as giving consent?

Generally not. A privacy policy is notice, and continued use of a service after reading it is weak evidence of consent under many laws. Where consent is required, laws such as GDPR expect a clear affirmative action tied to a specific purpose, separate from general terms.

Does an opt-out count as consent?

No. An opt-out gives people the right to stop a use that proceeds by default. Under GDPR, consent must be an affirmative act, so silence or a pre-ticked box does not qualify. Under US state laws, opt-out rights typically apply to specific uses named in the statute.

Do we need employee consent to license internal email or chat?

It depends on the laws that may apply and on what employees were told. Consent in employment can be hard to rely on because of the power imbalance, so companies often look at updated notices and thorough de-identification instead. Counsel should assess this before any internal communications are in scope.

Can we rely on consent collected years ago?

Only if the wording covered the use you now plan, and you can show who agreed and to what. Broad or vague consent language is often read narrowly. Keep the original wording and records, and treat gaps as a reason to update notice or exclude records.

If we remove all personal data, do notice and consent still matter?

Privacy notice and consent rules may matter less if the records meet the applicable de-identification standard. Contract terms, confidentiality obligations and public promises still apply, and customers and employees may still expect to be told. Counsel should confirm the standard has been met.

Sources

  • The Use group of the Data & Trust Alliance Data Provenance Standards includes elements for confidentiality classification, consent documentation location, privacy-enhancing technologies applied, allowed and excluded processing and storage geographies, license to use, intended data use, and copyright, patent and trademark status. Source
  • The Colorado Attorney General states that the Colorado Privacy Act protects personal data of Colorado residents acting in an individual or household context, does not cover individuals acting in a commercial or employment context, and does not apply to data maintained for employment records purposes. Source

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify