WorkNest

Blog

Notice & consent compliance in US, China & Canada

The first blog of our series on international data protection looks at notice & consent compliance in USA, China & canada

Background Image

In the United States, the Federal Trade Commission (FTC) has taken a leading role in this area, using Section 5(a) of the FTC Act to address deceptive and unfair practices towards data subjects in online governance. This foundational approach sets a benchmark for other jurisdictions grappling with similar issues in their pursuit of effective data regulation. It invites a closer examination of how regulatory bodies worldwide, from the bustling marketplaces of Canada, to the tech hubs of China curb the abuse of online consumer personal data. In this article, we explore how businesses can effectively adhere to the regulations in these countries, focusing on notice and consent, drawing from recent enforcement actions as instructive examples.


The FTC has been at the forefront of addressing consumer data protection issues. Section 5(a) of the FTC Act promotes notice and consent by requiring companies to clearly inform consumers about data collection, usage, and sharing practices. The FTC provides guidelines for effective notice and meaningful consent, emphasising plain language and consumer choice, in its report titled "Protecting Consumer Privacy in an Era of Rapid Change" which provided recommendations for businesses and policymakers on how to improve consumer privacy. It also emphasises the importance of privacy by design, simplified consumer choice, and transparency in privacy notices. It encourages companies to give consumers clear and simple choices about their data collection and use practices (FTC Privacy Report (2012).

The FTC enforces these principles by taking action against companies that fail to provide proper notice or obtain adequate consumer consent, as documented in the case of USA v. Facebook, where the FTC and the Department of Justice imposed a historic $5 billion penalty on Facebook for failing to provide clear and transparent privacy notices to users about the extent of data sharing with third-party apps. This highlights the FTC's commitment to holding companies accountable for failure to protect users’ privacy.


In Canada, Personal Information Protection and Electronic Documents Act (PIPEDA) and provincial laws such as PIPA-AB and PIPA-BC, establish requirements for obtaining consent and ensuring appropriate and reasonable use of personal information.

Canada establishes stringent consent requirements and guidelines for the reasonable use of personal information. High-profile cases like the investigations into ‘Tim Hortons’ and ‘Home Depot’ by Canadian privacy regulators, demonstrates a proactive stance against deceptive practices and the failure to obtain valid consent, reflecting a commitment to upholding consumer privacy and rights.

In the Tim Hortons case, Canadian privacy regulators from different provinces jointly investigated the company's location tracking practices. They found that ‘Tim Hortons’ did not obtain meaningful or valid consent due to misleading statements and lack of clear communication regarding the collection of granular location data, leading to global abuse. The investigation concluded that ‘Tim Hortons’ contravened multiple privacy regulations, including PIPEDA, Quebec's Private Sector Act, PIPA-AB, and PIPA-BC.

Similarly, in the Home Depot case, the Privacy Commissioner of Canada investigated the company's practice of sharing customer data with ‘Meta’ without obtaining valid consent. The investigation found that ‘Home Depot's’ reliance on its Privacy Statement and ‘Meta's’ Privacy Notice was insufficient to support meaningful consent for disclosing customers' personal information to ‘Meta’ and were in contravention of PIPEDA.

These demonstrate that Canadian privacy regulators are actively addressing instances of deception and unfairness in relation to consumer data protection.


In China, the focus on regulating the collection and use of personal information through Software Development Kits (SDKs) plays a significant role provided by companies like TikTok, Alibaba, and other tech giants are widely used by app developers to integrate various functionalities, such as social media logins, analytics, and advertising, into their apps. While SDKs are essential for building well-functioning apps, they can also be used to collect and share user data, raising privacy concerns.

China relies on similar regulatory concepts for deception and unfairness in consumer data protection as the U.S. FTC to tackle such issues, as evidenced by various notices, methods, and rectification actions undertaken by the Chinese authorities.

The "Method for Identifying the Illegal Collection and Use of Personal Information by Apps” prohibits misleading users into agreeing to collect personal information through fraud, deception, or other improper means. An official notice by China’s Ministry of Industry and Information Technology outlines rectification objectives, objects, and tasks to strengthen the protection of users' personal information. The notice addresses issues like the unauthorised collection of users' personal information, the collection of personal information beyond the scope, and unauthorised use of personal information for purposes other than providing services without informing users, which can be considered "unfair" practices. The Personal Information Protection Law (PIPL), in Articles 5 & 17, states that personal information handlers shall, before handling personal information, explicitly notify individuals.

China's interventionist approach to consumer data protection emphasises clear definitions of data collection and processing activities, ensuring they are reasonably necessary for providing a service. Companies must identify additional purposes beyond this scope and give individuals the choice to consent. This approach uses consumer notice and choice as a regulatory device, requiring more consent and offering consumers signposts and choices if activities fall outside the defined scope.

The case of Didi Global Inc., highlights the enforcement of these regulations wherein Cyberspace Administration of China imposed an administrative penalty on Didi Global Inc. for violating the Cybersecurity Law, the Data Security Law, and the PIPL in several aspects, such as illegal collection of personal information, excessive collection of various types of information, and failure to explain the processing purposes of personal information.

In conclusion, by adopting these comprehensive measures, companies can ensure compliance with data protection regulations, build trust with consumers, and protect user privacy effectively in the United States, China and Canada. These steps are essential for regulatory compliance and fostering a secure and trustworthy digital environment for consumers globally.

Talk to an expert

Share your challenge with us and we’ll help you find the right level of support for your business.

Your certified partner

Proven standards, trusted expertise, complete peace of mind

Award logo 1
Award logo 2
Award logo 3
Award logo 4
Award logo 5
Award logo 6
Award logo 7
Worknest logo
© 2020-2026 WorkNest. All rights reserved. (888) 243-3110