We are subject to various privacy, information security and data protection laws, including requirements concerning security breach notification, and we could be negatively impacted by these laws. For example, our business is subject to the Gramm-Leach-Bliley Act which, among other things: (i) imposes certain limitations on our ability to share non-public personal information about our customers with non-affiliated third parties; (ii) requires that we provide certain disclosures to customers about our information collection, sharing and security practices and afford customers the right to "opt out" of any information sharing by us with non-affiliated third parties (with certain exceptions) and (iii) requires we develop, implement and maintain a written comprehensive information security program containing safeguards appropriate based on our size and complexity, the nature and scope of our activities and the sensitivity of customer information we process, as well as plans for responding to data security breaches. Various state and federal banking regulators and states have also enacted data security breach notification requirements with varying levels of individual, consumer, regulatory or law enforcement notification in certain circumstances in the event of a security breach. Moreover, legislators and regulators in the United States are increasingly adopting or revising privacy, information security and data protection laws that potentially could have a significant impact on our current and planned privacy, data protection and information security-related practices, our collection, use, sharing, retention and safeguarding of consumer or employee information, and some of our current or planned business activities. Bank are required to notify their regulators within 36 hours of a "computer-security incident" that rises to the level of a "notification incident." This could increase our costs of compliance and business operations and could reduce income from certain business initiatives. This includes increased privacy-related enforcement activity at the federal level by the Federal Trade Commission, as well as at the state level.
We rely on third parties, and in some cases subcontractors, to provide information technology and data services. Although we provide for appropriate protections through our contracts and perform information security risk assessments of its third-party service providers and business associates, we still have limited control over their actions and practices. In addition, despite the security measures that we have in place to ensure compliance with applicable laws and rules, our facilities and systems, and those of our third-party providers may be vulnerable to security breaches, acts of vandalism or theft, computer viruses, misplaced or lost data, programming and/or human errors or other similar events. In such cases, notification to affected individuals, state and federal regulators, state attorneys general and media may be required, depending upon the number of affected individuals and whether personal information including financial data was subject to unauthorized access.
Compliance with current or future privacy, data protection and information security laws (including those regarding security breach notification) affecting customer or employee data to which we are subject could result in higher compliance and technology costs and could restrict our ability to provide certain products and services, which could have a material adverse effect on our business, financial conditions or results of operations. Our failure to comply with privacy, data protection and information security laws could result in potentially significant regulatory or governmental investigations or actions, litigation, fines, sanctions and damage to our reputation, which could have a material adverse effect on our business, financial condition or results of operations.