Most healthcare providers are subject to privacy and security regulations promulgated under HIPAA, as amended by HITECH. We are not currently classified as a covered entity or business associate under HIPAA and thus are not subject to its requirements or penalties. However, any person may be prosecuted under HIPAA's criminal provisions either directly or under aiding-and-abetting or conspiracy principles. Consequently, depending on the facts and circumstances, we could face substantial criminal penalties if we knowingly receive individually identifiable health information from a HIPAA-covered healthcare provider or research institution that has not satisfied HIPAA's requirements for disclosure of individually identifiable health information. In addition, if we receive sensitive personally identifiable information, including health information, we may be subject to state laws requiring notification of affected individuals and state regulators if a breach of personal information occurs, which is a broader class of information than the health information protected by HIPAA.
We cannot assure you that we, our CROs, our clinical trial sites, and our clinical trial principal investigators with access to personally identifiable and other sensitive or confidential information relating to the patients in our clinical trials will not breach contractual obligations, or that we or they will not experience data security breaches or attempts thereof. This could have a corresponding effect on our business, including putting us in breach of our obligations under privacy laws and regulations as discussed above, which could in turn adversely affect our business, financial condition, results of operations, and prospects. We cannot assure you that our contractual measures and our own privacy and security-related safeguards will protect us from the risks associated with the third-party processing, storage, and transmission of such information.
Compliance with global privacy and data security requirements could result in additional costs and liabilities to us or inhibit our ability to collect and process data globally, and the failure to comply with such requirements could subject us to significant fines and penalties, which could have a material adverse effect on our business, financial condition, results of operations, or prospects.
The regulatory framework for the collection, use, safeguarding, sharing, transfer, and other processing of information worldwide is rapidly evolving and is likely to remain uncertain for the foreseeable future. Globally, many jurisdictions have established their own data security and privacy frameworks. In the United States, there are a broad variety of data protection laws that are either currently in place or under way and a wide range of enforcement agencies at both the state and federal levels have the authority to review companies for privacy and data security concerns based on general consumer protection laws. The Federal Trade Commission ("FTC"), and state Attorneys General have been aggressive in reviewing privacy and data security protections for consumers. New laws also are being considered at both the state and federal levels. For example, the California Consumer Privacy Act (the "CCPA"), which went into effect on January 1, 2020, provides for civil penalties for violations, as well as a private right of action for data breaches that is expected to increase data breach litigation. Many other states are considering similar legislation. A broad range of legislative measures also have been introduced at the federal level. There also is the threat of consumer class actions related to these laws and the overall protection of personal data.
Additionally, the CCPA was amended by the California Privacy Rights Act, which significantly amends the CCPA and imposes additional data protection obligations on covered businesses, including additional consumer rights processes, limitations on data uses, new audit requirements for higher risk data, and opt outs for certain uses of sensitive data. It will also create a new California data protection agency authorized to issue substantive regulations, which could result in increased privacy and information security enforcement. The majority of the provisions went into effect on January 1, 2023, and additional compliance investment and potential business process changes may be required. Similar laws have passed in, or are being considered by, other states. The enactment of such laws in other states could result in potentially conflicting requirements, which would make compliance challenging and costly.
The FTC and many state attorneys general continue to enforce federal and state consumer protection laws against companies for online collection, use, dissemination and security practices that appear to be unfair or deceptive. For example, according to the FTC, failing to take appropriate steps to keep consumers' personal information secure can constitute unfair acts or practices in or affecting commerce in violation of Section 5(a) of the Federal Trade Commission
Act. The FTC expects a company's data security measures to be reasonable and appropriate in light of the sensitivity and volume of consumer information it holds, the size and complexity of its business, and the cost of available tools to improve security and reduce vulnerabilities. We may also be subject to new state laws governing the privacy of consumer health data, including information concerning individual health conditions and treatment.
The data privacy laws in the European Union (the "EU") have also been significantly reformed. The collection, use, disclosure, transfer, or other processing of personal data regarding individuals in the EU, including personal health data, is subject to the General Data Protection Regulation, (EU) 2016/679 (the "GDPR"). The GDPR is wide-ranging in scope and imposes numerous requirements on companies that process personal data, including requirements relating to processing health and other sensitive data, obtaining consent of the individuals to whom the personal data relates, providing information to individuals regarding data processing activities, implementing safeguards to protect the security and confidentiality of personal data, providing notification of data breaches, and taking certain measures when engaging third-party processors. The GDPR has expanded the definition of personal data to include coded data and requiring changes to informed consent practices and more detailed notices for clinical trial patients and investigators. In addition, the GDPR also imposes strict rules on the transfer of personal data to countries outside the EU, including the United States and, as a result, increases the scrutiny that clinical trial sites located in the European Economic Area should apply to transfers of personal data from such sites to countries that are considered to lack an adequate level of data protection, such as the United States. The GDPR also permits data protection authorities to require destruction of improperly gathered or used personal information or impose substantial fines for violations of the GDPR, which can be up to 4% of global revenues or €20 million, whichever is greater, and it also confers a private right of action on data subjects and consumer associations to lodge complaints with supervisory authorities, seek judicial remedies, and obtain compensation for damages resulting from violations of the GDPR. In addition, the GDPR provides that EU member states may make their own additional laws and regulations limiting the processing of personal data, including genetic, biometric, or health data.
Furthermore, since the United Kingdom is no longer part of the EU, its data protection regulatory regime will be independent of the EU. From January 1, 2021, companies have had to comply with the GDPR and also the United Kingdom GDPR, which, together with the amended United Kingdom Data Protection Act 2018, retains the GDPR in UK national law. The relationship between the United Kingdom and the EU in relation to certain aspects of data protection law remains unclear. In addition, the longer term economic, legal, political, regulatory, and social framework to be put in place between the United Kingdom and the EU has had, and may continue to have, a material and adverse effect on global economic conditions and the stability of global financial markets and may significantly reduce global market liquidity and restrict the ability of key market participants to operate in certain financial markets. Any of these factors could depress economic activity and restrict our access to capital, which could materially and adversely affect our business, financial condition, and results of operations.