We rely on encryption and authentication technology in an effort to securely transmit and store data about our customers, merchants, suppliers, advertisers, and others, including personally identifiable information, as well as other confidential and proprietary information but such measures cannot provide absolute security and may fail to operate as intended or be circumvented. Data loss, breaches, theft, misuse, unauthorized access, or other security incidents or vulnerabilities affecting our or our vendors' or customers' technology, products, and systems have in the past, and could in the future, result in the inadvertent or unauthorized use or disclosure of information or otherwise enable third parties to gain unauthorized access to this information. For instance, we have experienced data incidents in the past, including the Incident, and the inadvertent exposure of limited customer information within our app that occurred during an upgrade in 2021. For more information about the Incident, see the risk factor titled "We have experienced, and may again experience, data incidents involving the unauthorized or improper access to proprietary, confidential, or customer data, and may experience cybersecurity or data incidents involving unauthorized or improper use of, disclosure of, alteration of, or destruction of, proprietary, confidential, or customer data, any of which could cause loss of revenue, harm to our brand, business disruption, and significant liabilities." In addition, our apps, websites, networks, and systems are subject to security threats, including hacking of our systems, denial-of-service attacks, viruses, malicious software, ransomware, break-ins, phishing attacks, social engineering, security breaches, or other attacks and similar disruptions that may jeopardize the security of information stored in or transmitted by our apps, websites, networks, and systems, or that we otherwise maintain. It may be difficult to determine the best way to investigate, mitigate, contain, and remediate the harm caused by a data incident. Such efforts may not be successful, and we may make errors or fail to take necessary actions. Such risks extend not only to our own apps, websites, networks, and systems, but also to those of third-party service providers and our customers, contractors, business partners, vendors, and other third parties. There can be no assurance that future incidents will not have material adverse effects on our business, financial condition, and results of operations.
Moreover, techniques used to obtain unauthorized access to or sabotage systems change frequently and are becoming increasingly sophisticated and may not be known until launched against us or our third-party service providers, increasing the difficulty of detecting and defending against such threats. We have observed an increase in the frequency of the security threats we and our third-party service providers face, and we expect these activities to continue to increase. Geopolitical tensions or conflicts, such as the conflict between Russia and Ukraine, and the increased adoption of AI technologies, may further heighten the risk of cybersecurity incidents. In addition, security breaches can also occur as a result of non-technical issues, including intentional or inadvertent breaches by our employees or former employees (such as was the case in the Incident) or by persons with whom we have commercial relationships. As a result of any security breach, our reputation and brand could be damaged, our business could suffer, we could be required to expend significant capital and other resources to alleviate problems caused by such breaches, and we could be exposed to a risk of loss, litigation, or regulatory action (including under laws related to privacy, data use, data protection, data security, network security, and consumer protection) and possible liability. Actual or anticipated attacks may cause us to incur increasing costs, including costs to deploy additional personnel and protection technologies, train employees, and engage third-party experts and consultants. Any compromise or breach of our security measures, or those of our third-party service providers, could violate applicable privacy, data security, and other laws, cause significant legal and financial exposure, cause adverse publicity, interfere with customers' ability to use our apps, websites, networks, and systems, interfere with customer transactions and order fulfillment, and a create a loss of confidence in our security measures, which could have an adverse effect on our business, financial condition, and results of operations.
Inadequate account security or organizational security practices, including those of companies we have acquired or those of the third-parties we utilize, may result in unauthorized access to our systems and data, including customer systems and data. For example, passwords may not be rotated and employee access may not be updated or removed on a timely basis. Employees or third parties may intentionally compromise our security or systems or reveal confidential information.
We are also subject to regulations relating to privacy and use of confidential, sensitive, and personal information of our consumers, including, among others, Korea's Personal Information Protection Act ("PIPA"), Korea's Act on the Promotion of Information, Korea's Communications Network Utilization and Protection of Information Act, Korea's Credit Information Act and China's Personal Information Protection Act. PIPA requires consent by the consumer with respect to the use of his or her data and requires the persons responsible for management of personal data to take the necessary technological and managerial measures to prevent data breaches and, among other duties, to notify the Personal Information Protection Commission of any data breach incidents within 24 hours. Failure to comply with PIPA in any manner may subject the individuals responsible to personal liability for not obtaining such consent in an appropriate manner or for such breaches, including even negligent breaches, and violators face varying penalties ranging from monetary penalties to imprisonment. We are also subject to regulations regarding privacy and use of confidential, sensitive, and personal information of our employees and service providers. We strive to take the necessary technological and managerial measures to comply with applicable laws, including the implementation of privacy policies concerning the collection, use, and disclosure of subscriber data on our apps and websites, and we regularly review and update our policies and practices. Despite these efforts to comply with applicable laws, these rules are complex and evolving, subject to interpretation by government regulators which may change over time and therefore we are subject to the risk of claims by regulators of failure to comply. Any failure, or perceived failure, by us to comply with such policies, laws, regulations, and other legal obligations and regulatory guidance could adversely affect our reputation, brand, and business, and may result in claims, proceedings, or actions, including criminal proceedings, against us and certain of our executive officers by governmental entities or others or other liabilities. Any such claim, proceeding, or action could hurt our reputation, brand, and business, force us to incur significant expenses in defense of such proceedings, distract our management, increase our costs of doing business, result in a loss of employees, customers, or merchants, and could have an adverse effect on our business, financial condition, and results of operations.
Moreover, we are also subject to other data privacy and protection laws regulating the collection, use, retention, disclosure, transfer, and processing of personal information, such as the California Consumer Privacy Act, the California Privacy Rights Act, similar laws in other states in the United States, the United Kingdom's General Data Protection Regulation, and the European Union's General Data Protection Regulation. The potential effects of these laws are far-reaching, continue to evolve, and may require us to modify our data processing practices and policies and to incur substantial costs and expenses to comply with the obligations imposed by the governments of the jurisdictions in which we do business or seek to do business and we may be required to make significant changes in our business operations, all of which may adversely impact our business. These and other privacy and cybersecurity laws may carry significant potential penalties for noncompliance.
We may also be contractually liable to indemnify and hold harmless third parties from the costs or consequences of non-compliance with any laws, regulations or other legal obligations relating to privacy or consumer protection or any inadvertent or unauthorized use or disclosure of data that we store or handle as part of operating our business. In addition, legislative and regulatory bodies, or self-regulatory organizations, may expand or change their interpretations of current laws or regulations, or enact new laws or regulations or issue revised rules or guidance regarding privacy, data protection, and consumer protection. Any such changes may force us to incur substantial costs or require us to change our business practices. This could compromise our ability to pursue our growth strategy effectively and may harm our ability to attract new customers or retain existing customers, or otherwise adversely affect our business, financial condition, and results of operations.
Additionally, some providers of consumer devices and web browsers have implemented, or announced plans to implement, means to make it easier for Internet users to prevent the placement of cookies or to block other tracking technologies, which could, if widely adopted, result in the use of third-party cookies and other methods of online tracking becoming significantly less effective. The regulation of the use of these cookies and other current online tracking and advertising practices or a loss in our ability to make effective use of services that employ such practices could adversely affect our business, financial condition, and results of operations.