By reason of our Direct-to-Consumer business in particular, we collect personal data.
In 2016, the European Union ("EU") adopted a comprehensive overhaul of its data protection regime from the current national legislative approach to a single European Economic Area Privacy Regulation, the General Data Protection Regulation ("GDPR"), which went into effect in May 2018. The EU data protection regime expands the scope of the EU data protection law to all foreign companies processing personal data of EU residents, imposes a strict data protection compliance regime with severe penalties of up to the greater of 4% of worldwide turnover or €20 million, and includes new rights such as the "portability" of personal data. Although the GDPR will apply across the EU without a need for local implementing legislation, EU member states have the ability to interpret the GDPR opening clauses, which permit region-specific data protection legislation and have the potential to create inconsistencies on a country-by-country basis.
The Company has an office in Vienna, Austria that provides marketing support services for our international (including EU) customers. Although our international operations are currently modest compared to our business in the United States, our international business could grow over time. We have evaluated the new regulation and its requirements, and believe we are currently in compliance with the GDPR in all material respects. Going forward, however, the expansion of our international operations could require us to change our business practices and may increase the costs and complexity of compliance. Also, a violation by the Company of the new regulation could expose us to penalties and sanctions under the regulation.
On June 28, 2018, California passed the California Consumer Privacy Act of 2018 ("CCPA"), effective on January 1, 2020. The new law provides California consumers with a greater level of transparency and broader rights and choices with respect to their personal information than those contained in any existing state and federal laws in the U.S. The "personal information" regulated by CCPA is broadly defined to include identification or association with a California consumer or household, including demographics, usage, transactions and inquiries, preferences, inferences drawn to create a profile about a consumer, and education information. Compliance with CCPA requires the implementation of a series of operational measures such as preparing data maps, inventory, or other records of all personal information pertaining to California residents, households and devices, as well as information sources, usage, storage, and sharing, maintaining and updating detailed disclosures in privacy policies, establishing mechanisms (including, at a minimum, a toll-free telephone number and an online channel) to respond to consumers' data access, deletion, portability, and opt-out requests, providing a clear and conspicuous "Do Not Sell My Personal Information" link on the home page of the business' website, etc. CCPA prohibits businesses from discriminating against consumers who have opted out of the sale of their personal information, subject to a narrow exception. It allows companies to provide financial incentives to California consumers in order to obtain their consent to the collection and use of their personal information. Violations of CCPA will result in civil penalties up to $7,500 per violation. CCPA further allows consumers to file lawsuits against a business if a data breach has occurred and the California Attorney General does not prosecute the business.
In addition, on May 29, 2019, Nevada's governor approved a bill (the "Amendment Bill"), effective on October 1, 2019. The Amendment Bill provides amendments to an existing law that requires operators of websites and online services to post a notice on their websites regarding their privacy practices. The Amendment Bill requires operators of internet websites or online services to establish a designated request address through which a consumer may submit a verified request directing such operators not to make any sale of covered information collected about the consumer. The "covered information" regulated by the Amendment Bill is defined to include an enumerated list of items of personally identifiable information (including names, addresses, email addresses, phone numbers, social security numbers and identifiers that allow a specific person to be contacted).
The changes introduced by the CCPA and the Amendment Bill, and other similar regulations enacted by other jurisdictions, will subject the Company to additional costs and complexity of compliance, by requiring, among other things, changes to the Company's security systems, policies, procedures and practices. In addition, a violation by the Company of the new regulations could expose us to penalties and sanctions.