Our business employs websites, networks, and systems through which we collect, maintain, transmit, and store data about our customers, merchants, suppliers, advertisers, and others, including personally identifiable information, as well as other confidential and proprietary information. We rely on encryption and authentication technology in an effort to securely transmit confidential and sensitive information. However, security breaches or other security incidents have in the past and could in the future result in the inadvertent or unauthorized use or disclosure of confidential and sensitive information we collect, store, or transmit, or otherwise enable third parties to gain unauthorized access to this information such as our inadvertent exposure of limited customer information within our App that occurred during an upgrade in 2021 and was remediated within an hour. In addition, our apps,websites, networks, and systems are subject to security threats, including hacking of our systems, denial-of-service attacks, viruses, malicious software, ransomware, break-ins, phishing attacks, social engineering, security breaches, or other attacks and similar disruptions that may jeopardize the security of information stored in or transmitted by our apps, websites, networks, and systems, or that we otherwise maintain. Such risks extend not only to our own apps, websites, networks, and systems, but also to those of third-party services providers and our customers, contractors, business partners, vendors, and other third parties. Moreover, techniques used to obtain unauthorized access to or sabotage systems change frequently and are becoming increasingly sophisticated and may not be known until launched against us or our third-party service providers, increasing the difficulty of detecting and defending against such threats. We have observed an increase in the frequency of the security threats we and our third-party service providers face, and we expect these activities to continue to increase. Geopolitical tensions or conflicts, such as the conflict between Russia and Ukraine, and the increased adoption of artificial intelligence technologies, may further heighten the risk of cyber security incidents. In addition, security breaches can also occur as a result of non-technical issues, including intentional or inadvertent breaches by our employees or by persons with whom we have commercial relationships. As a result of any security breach, our reputation and brand could be damaged, our business could suffer, we could be required to expend significant capital and other resources to alleviate problems caused by such breaches, and we could be exposed to a risk of loss, litigation, or regulatory action and possible liability. Actual or anticipated attacks may cause us to incur increasing costs, including costs to deploy additional personnel and protection technologies, train employees, and engage third-party experts and consultants. Any compromise or breach of our security measures, or those of our third-party service providers, could violate applicable privacy, data security, and other laws, and cause significant legal and financial exposure, adverse publicity, and a loss of confidence in our security measures, which could have an adverse effect on our business, financial condition, and results of operations.
We are also subject to regulations relating to privacy and use of confidential information of our users, including, among others, Korea's Personal Information Protection Act and related legislation, regulations and orders (the "PIPA"), China's Personal Information Protection Act, the Act on the Promotion of Information and Communications Network Utilization and Protection of Information Act (Korea), and the Credit Information Act in Korea that specifically regulates certain sensitive personal information. PIPA requires consent by the consumer with respect to the use of his or her data and requires the persons responsible for management of personal data to take the necessary technological and managerial measures to prevent data breaches and, among other duties, to notify the Personal Information Protection Commission of any data breach incidents within 24 hours. Failure to comply with PIPA in any manner may subject these persons responsible to personal liability for not obtaining such consent in an appropriate manner or for such breaches, including even negligent breaches, and violators face varying penalties ranging from monetary penalties to imprisonment. We strive to take the necessary technological and managerial measures to comply with PIPA, including the implementation of privacy policies concerning the collection, use, and disclosure of subscriber data on our apps and websites, and we regularly review and update our policies and practices. Despite these efforts to comply with PIPA, these rules are complex and evolving, subject to interpretation by government regulators which may change over time and therefore we are subject to the risk of claims by regulators of failure to comply with PIPA. Any failure, or perceived failure, by us to comply with such policies, laws, regulations, and other legal obligations and regulatory guidance could adversely affect our reputation, brand, and business, and may result in claims, proceedings, or actions, including criminal proceedings, against us and certain of our executive officers by governmental entities or others or other liabilities. Any such claim, proceeding, or action, could hurt our reputation, brand, and business, force us to incur significant expenses in defense of such proceedings, distract our management, increase our costs of doing business, result in a loss of customers and merchants, and could have an adverse effect on our business, financial condition, and results of operations.
Moreover, we are also subject to other data privacy and protection laws regulating the collection, use, retention, disclosure, transfer, and processing of personal information, such as the California Consumer Privacy Act, which was significantly modified by the California Privacy Rights Act, similar laws in other states in the US, and the European Union's General Data Protection Regulation. The potential effects of these laws are far-reaching, continue to evolve, and may require us to modify our data processing practices and policies and to incur substantial costs and expenses to comply with the obligations imposed by the governments of the foreign jurisdictions in which we do business or seek to do business and we may be required to make significant changes in our business operations, all of which may adversely impact our business. These and other privacy and cybersecurity laws may carry significant potential penalties for noncompliance.
We may also be contractually liable to indemnify and hold harmless third parties from the costs or consequences of non-compliance with any laws, regulations or other legal obligations relating to privacy or consumer protection or any inadvertent or unauthorized use or disclosure of data that we store or handle as part of operating our business. In addition, legislative and regulatory bodies, or self-regulatory organizations, may expand or change their interpretations of current laws or regulations, or enact new laws or regulations or issue revised rules or guidance regarding privacy, data protection, and consumer protection. Any such changes may force us to incur substantial costs or require us to change our business practices. This could compromise our ability to pursue our growth strategy effectively and may harm our ability to attract new customers or retain existing customers, or otherwise adversely affect our business, financial condition, and results of operations.
Additionally, some providers of consumer devices and web browsers have implemented, or announced plans to implement, means to make it easier for Internet users to prevent the placement of cookies or to block other tracking technologies, which could, if widely adopted, result in the use of third-party cookies and other methods of online tracking becoming significantly less effective. The regulation of the use of these cookies and other current online tracking and advertising practices or a loss in our ability to make effective use of services that employ such practices could adversely affect our business, financial condition, and results of operations.