We are also exposed to the risk of employees, independent contractors, principal investigators, consultants, commercial partners or vendors engaging in fraud or other misconduct. Misconduct by employees, independent contractors, principal investigators, consultants, commercial partners and vendors could include intentional failures to comply with United Kingdom ("UK") or European Union ("EU") regulations, to provide accurate information to the UK, EMA or EU Member States authorities or to comply with manufacturing or quality standards we have or will have established. In particular, sales, marketing and business arrangements in the healthcare industry are subject to extensive laws and regulations intended to prevent fraud, misconduct, kickbacks, self-dealing and other abusive practices such as promotion of products by medical practitioners. Of general application are the European Anti-Fraud Office Regulation 883/2013, and the UK Bribery Act 2010. Under the latter, a commercial organization can be guilty of the offence if the bribery is carried out by an employee, agent, subsidiary, or another third-party, and the location of the third-party is irrelevant to the prosecution. The advertising of medicinal products in the EU is regulated by Title VIII of European Directive 2001/83/EC. The corresponding UK legislation is Part 14 of the Human Medicines Regulations 2012 (S.I. 2012/1916 as amended). Such laws and regulations may restrict or prohibit a wide range of pricing, discounting, marketing and promotion, sales commission, customer incentive programs and other business arrangements. Misconduct could also involve the improper use of information obtained in the course of clinical studies, which could result in regulatory sanctions and serious and irreparable harm to our reputation.
This could also apply with respect to data privacy. In the EU, the General Data Protection Regulation (EU) 2016/679 ("GDPR") lays down the legal framework for data protection and privacy. The GDPR applies directly in EU Member States and applies to companies with an establishment in the EEA and to certain other companies not in the EEA that offer or provide goods or services to individuals located in the EEA or monitor the behavior of individuals located in the EEA. Since January 1, 2021, the UK is not part of the EU. In the UK, the GDPR has been converted into UK domestic law, pursuant to the Data Protection, Privacy and Electronic Communications (Amendments etc.) (EU Exit) Regulations 2019 (as amended), which makes some minor technical amendments to ensure the GDPR is operable in the UK ("UK GDPR"). The UK GDPR is also supplemented by the Data Protection Act 2018. UK and EU data protection law is therefore aligned. The GDPR and UK GDPR implement stringent operational requirements for controllers of personal data, including, for example, expanded disclosures about how personal information is to be used, limitations on retention of information, increased requirements pertaining to health data and pseudonymized (i.e., key-coded) data, increased cyber security requirements, mandatory data breach notification requirements and higher standards for controllers to demonstrate that they have obtained a valid legal basis for certain data processing activities. The activities of data processors are being regulated for the first time, and require companies undertaking processing activities to offer certain guarantees in relation to the security of such processing and the handling of personal data. Contracts with data processors will also need to be updated to include certain terms prescribed by the GDPR, and negotiating such updates may not be fully successful in all cases. The GDPR provides that EU Member States may make their own further laws and regulations in relation to the processing of genetic, biometric or health data, which could result in differences between Member States, limit our ability to use and share personal data or could cause our costs to increase, and harm our business and financial condition. We are also subject to evolving and strict rules on the transfer of personal data out of the EU and UK to the United States, under both the GDPR and the UK GDPR. Under the GDPR personal data cannot be transferred to a third country (i.e. outside of the EEA or UK, as applicable) unless certain safeguards are in place. These include, for example, where the transfer is to a country that the EU Commission has deemed "adequate" or where EU standard contractual clauses have been implemented. Further prospective revision of the Directive on privacy and electronic communications (Directive 2002/58/EC) ("ePrivacy Directive") may affect our marketing communications. Failure to comply with EU laws, including failure under the GDPR and UK GDPR, Data Protection Act 2018, ePrivacy Directive and other laws relating to the security of personal data may result in fines up to €20,000,000 (or £17,500,000 under the UK GDPR) or up to 4% of the total worldwide annual turnover of the preceding financial year, if greater, and other administrative penalties including criminal liability, which may be onerous and adversely affect our business, financial condition, results of operations and prospects. Failure to comply with the GDPR and related laws may also give risk to increase risk of private actions from data subjects and consumer not-for-profit organizations, including a new form of class action that is available under the GDPR. Compliance with the GDPR and UK GDPR requires a rigorous and time-intensive process that may increase our cost of doing business or require us to change our business practices, and despite those efforts, there is a risk that we may be subject to the aforementioned fines and penalties, litigation, and reputational harm in connection with any European activities.
The UK is treated as a third country (for the purposes of data transfers). On June 28, 2021, the EU Commission published two adequacy decisions in respect of transfers under EU GDPR and the Law Enforcement Directive stating that the UK provides adequate protection for personal data transferred from the EU to the UK under EU GDPR. The adequacy decision is expected to last until June 27, 2025 but may end earlier, for example if an EU data subject or EU data protection authority challenges the adequacy decisions. In such a case, the Court of Justice of the European Union would need to determine whether the UK provides essentially equivalent protection.
The UK government has confirmed that the EEA is adequate, and so all transfers of personal data from the UK to the EEA will continue to be unrestricted after July 1, 2021.
The UK has issued a consultation with respect to future changes to data protection law. There is risk that in the event UK and EU data protection law diverges, that the adequacy decisions may come to an end. If this occurs, there will be cost implication due to dual compliance requirements and costs with respect to international data transfers.
It is not always possible to identify and deter misconduct by employees or other parties. The precautions we take to detect and prevent this activity may not protect us from legal or regulatory action resulting from a failure to comply with applicable laws or regulations. Misconduct by our employees, principal investigators, consultants, commercial partners or vendors could result in significant financial penalties, criminal sanctions and thus have a material adverse effect on our business, including through the imposition of significant fines or other sanctions, and our reputation.