As a global software and service provider, we collect and process personal data and other data from our users and prospective users. We use this information to provide solutions and applications to our accounts, to validate user identity, to fulfill contractual duties and administer billing and support, to expand and improve our business, and to communicate and recommend products and services through our marketing and advertising efforts. We may also share accounts' personal data with certain third parties as described in the privacy policy provided to each account. We may also share accounts' personal data with certain third parties as described in the privacy policy provided to each account. Further, we collect and otherwise process personal data of our global employees and contractors.
Governments, regulators, privacy advocates, plaintiffs' attorneys, and our users and accounts are increasingly focused on how companies collect, process, use, store, share, and transmit personal data. Regulation relating to the provision of our solutions and applications, is evolving, as federal, state, and foreign governments continue to adopt new, or modify existing, laws and regulations addressing privacy, data protection, data sovereignty, information security and the collection, processing, storage, sharing, transmission, and use of data generally. This evolving regulatory landscape may be subject to differing interpretations, jurisdiction specific inconsistencies, or may conflict with other rules. We expect the regulatory landscape to remain uncertain for the foreseeable future. Further, our expectation is that there will continue to be new laws, regulations, and industry standards applicable to our collection, processing, storage, sharing, transmission, and use of data generally.
Globally, laws such as the GDPR in the European Economic Area, the LGPD in Brazil, and the PIPL in China, impose obligations directly on us as both a data controller and a data processor, as well as on many of our users. In addition, new and emerging state laws in the U.S. governing privacy, data protection, and information security, such as the California Consumer Privacy Act ("CCPA"), the California Privacy Rights Act, the Virginia Consumer Data Protection Act, the Colorado Privacy Act, the Utah Consumer Privacy Act, and Connecticut's Act Concerning
Personal Data Privacy and Online Monitoring have been enacted. These laws and regulations, as well as industry self-regulatory codes, create new compliance obligations and substantially expand the scope of potential liability and provide greater penalties for non-compliance. For example, the GDPR provides for penalties of up to €20 million or 4% of a company's annual global revenue, whichever is greater, the PIPL provides for penalties of up to 50 million renminbi or 5% of a company's annual revenue and disgorgement of all illegal gains, whichever is greater, and the CCPA provides for penalties of up to $7,500 per violation.
Although, we monitor the regulatory environment and have invested in addressing these developments, operating in an increasingly complex regulatory landscape may impact our innovation and business drivers in developing new and emerging technologies (e.g., artificial intelligence and machine learning). Globally, these and other requirements are causing increased scrutiny amongst users, particularly in the public sector and highly regulated industries, which could restrict the use and adoption of our solutions and applications (in particular cloud services). Further, these developments may require us to take on more onerous obligations in our contracts, restrict our ability to store, transfer and process data or, in some cases, impact our ability or our users' ability to offer our services in certain locations, to deploy our solutions, or to derive insights from user data globally.
Around the world, there is continued uncertainty in relation to the legal mechanisms supporting cross-border data flows which are subject to evolving guidance, active litigation, and enforcement proceedings in a number of jurisdictions. A number of countries including China, Australia, New Zealand, Brazil, and Japan have established specific requirements for cross-border data transfers. Further, a number of countries and states have adopted or are considering adopting data localization policies which would further restrict cross-border data transfers and may require data to be localized in the country of origin (potentially at a state level) which could substantially impact our operations.
Our failure to comply with applicable laws and regulations, or to protect data, could result in enforcement action against us, including fines and public censure, claims for damages by users, accounts, and other affected individuals, damage to our reputation and loss of goodwill (both in relation to existing accounts and prospective accounts), any of which could harm our business, financial condition, and results of operations.
Around the world, there are numerous lawsuits in process against various technology companies that process personal data. If those lawsuits are successful, it could increase the likelihood that we may be exposed to liability for our own policies and practices concerning the processing of personal data and could hurt our business.
Our accounts expect us to meet voluntary certification or other standards established by third parties or imposed by the accounts themselves. If we are unable to maintain these certifications or meet these standards, it could adversely affect our ability to provide our solutions to certain accounts and could harm our business. Further, if we were to experience a breach of systems compromising our accounts' sensitive data, our brand and reputation could be adversely affected, use of our software solutions and services could decrease, and we could be exposed to a risk of loss, litigation, and regulatory proceedings.
The costs of compliance with and other burdens imposed by laws, regulations, and standards may limit the use and adoption of our services and reduce overall demand for them, or lead to significant fines, penalties, or liabilities for any noncompliance.
Furthermore, concerns regarding privacy, data protection, and information security may cause our accounts' customers to resist providing the data necessary to allow our accounts to use our services effectively. Even the perception that the privacy of data is not satisfactorily protected or does not meet regulatory requirements could inhibit sales of our software solutions or services, and could limit adoption of our cloud-based solutions.