We rely on a variety of marketing and advertising techniques, including email communications, affiliate partnerships, social media interactions, influencer partnerships, digital marketing, direct mailers and public relations initiatives, and we are subject to various laws, regulations and industry standards that govern such marketing and advertising practices. Increasingly complex and rigorous, and sometimes conflicting laws, regulatory standards, industry standards, external and internal privacy and security policies, contracts and other obligations govern the collection, use, retention, sharing and security of consumer data, particularly in the context of digital marketing, which we rely upon to attract new customers.
Laws, regulations and industry standards (including, for example, the Payment Card Industry Data Security Standard, or PCI-DSS) relating to privacy, data protection, marketing and advertising and consumer protection are evolving and subject to potentially differing interpretations. These requirements may be interpreted and applied in a manner that is inconsistent from one jurisdiction to another or may conflict with other rules or our practices. As a result, our practices may not have complied or may not comply in the future with all such laws, regulations, standards, requirements and obligations. Any failure, or perceived failure, by us to comply with our posted privacy policies or with any federal or state privacy or consumer protection-related laws, regulations, industry self-regulatory principles, industry standards or codes of conduct, regulatory guidance, orders to which we may be subject or other obligations relating to privacy or consumer protection could adversely affect our reputation, brand and business, and may result in claims, proceedings or actions against us by governmental entities, customers, suppliers or others or other liabilities or may require us to change our operations and/or cease using certain data sets. Any such claims, proceedings or actions may also hurt our reputation, brand and business, force us to incur significant expenses in defense of such proceedings or actions, distract our management, increase our costs of doing business, result in a loss of customers, suppliers or vendors and result in the imposition of monetary penalties. We may also be contractually required to indemnify and hold harmless third parties from the costs or consequences of non-compliance with any laws, regulations or other legal obligations relating to privacy or consumer protection or any inadvertent or unauthorized use or disclosure of data that we store or handle as part of operating our business.
Federal and state governmental authorities continue to evaluate the privacy implications inherent in the use of third-party "cookie" and other methods of online tracking for behavioral advertising and other purposes. The U.S. government has enacted, has considered or is considering legislation or regulations that could significantly restrict the ability of companies and individuals to engage in these activities, such as by regulating the level of consumer notice and consent required before a company can employ cookies or other electronic tracking tools or the use of data gathered with such tools. Additionally, some providers of consumer devices and web browsers have implemented, or announced plans to implement, means to make it easier for Internet users to prevent the placement of cookies or to block other tracking technologies, which could if widely adopted result in the use of third-party cookies and other methods of online tracking becoming significantly less effective. The regulation of the use of these cookies and other current online tracking and advertising practices or a loss in our ability to make effective use of services that employ such technologies could increase our costs of operations and limit our ability to acquire new customers on cost-effective terms and, consequently, materially and adversely affect our business, financial condition, and results of operations.
In addition, various federal and state legislative and regulatory bodies, or self-regulatory organizations, may expand current laws or regulations, enact new laws or regulations or issue revised rules or guidance regarding privacy, data protection, consumer protection, and advertising. For example, on January 1, 2023, the CPRA amendments to the CCPA came into force. Among other operational requirements for covered companies, the CCPA mandates that covered companies provide new disclosures to California consumers and afford such consumers data privacy rights that include, among other things, the right to request a copy from a covered company of the personal information collected about them, the right to request correction or deletion of such personal information, and the right to request to opt-out of certain sales, or disclosures for the purposes of cross-context behavioral advertising, of such personal information. The California Attorney General and a standalone California data privacy agency can enforce the CCPA, including seeking an injunction and civil penalties for violations. The CCPA also provides a private right of action for certain data breaches that is expected to increase data breach litigation. Four additional states (Virginia, Colorado, Utah and Connecticut) have enacted data privacy and security laws that have, or will in the near future, come into effect and other states may follow. This legislation may add additional complexity, variation in requirements, restrictions and potential legal risk, require additional investment in resources to compliance programs, and could impact strategies and availability of previously useful data and could result in increased compliance costs and/or changes in business practices and policies. Additionally, the FTC and many state attorneys general are interpreting existing federal and state consumer protection laws to impose expanded standards for the online collection, use, dissemination and security of data.
Foreign privacy laws are also undergoing a period of rapid change, have become more stringent in recent years and may increase the costs and complexity of offering our products and services in new geographies. In Canada, where we operate, the Personal Information Protection and Electronic Documents Act ("PIPEDA") and various provincial laws require that companies give detailed privacy notices to consumers; obtain consent to use personal information, with limited exceptions; allow individuals to access and correct their personal information; and report certain data breaches. In addition, Canada's Anti-Spam Legislation ("CASL") prohibits email marketing without the recipient's consent, with limited exceptions. Failure to comply with PIPEDA, CASL or provincial privacy or data protection laws could result in significant fines and penalties or possible damage awards.
In addition, the data protection landscape in the EU, EEA and UK is continually evolving and in some cases, laws or regulations in one country may be inconsistent with, or contrary to, those of another country. Tracking existing data privacy laws and regulations, new data privacy laws and regulations, and changes to the same over time, together with implementing compliance measures may result in possible significant operational costs for internal compliance and risks to our business. Compliance with the GDPR may require adhering to stringent legal and operational obligations and therefore the dedication of substantial time and financial resources by the business, which may increase over time (in particular in relation to any transfers of any personal data to third parties located in certain jurisdictions). Failure to comply with the GDPR may lead to the business incurring fines and/or facing other enforcement action or reputational damage. For example, failure to comply with the GDPR, depending on the nature and severity of the breach (and with a requirement on regulators to ensure any enforcement action taken is proportionate), could (in the worst case) attract regulatory penalties of up to the greater of (i) €20 million / £17.5 million (as applicable); and (ii) 4% of an entire group's total annual worldwide turnover, as well as the possibility of other enforcement actions (such as suspension of processing activities and audits), and liabilities from third-party claims.
Further, we are subject to the Payment Card Industry, or PCI, Data Security Standard, which is a multifaceted security standard that is designed to protect credit card account data as mandated by payment card industry entities. We rely on vendors to handle PCI matters and to ensure PCI compliance. Despite our compliance efforts, we may become subject to claims that we have violated the PCI Data Security Standard, based on past, present, and future business practices, which could have an adverse impact on our business and reputation.
Each of these privacy, security, and data protection laws and regulations, and any other such changes or new laws or regulations, could impose significant limitations, require changes to our business, or restrict our use or storage of personal information, which may increase our compliance expenses and make our business more costly or less efficient to conduct. In addition, any such changes could compromise our ability to develop an adequate marketing strategy and pursue our growth strategy effectively, which, in turn, could adversely affect our business, financial condition and results of operations. Finally, any actual or perceived failure to comply with these laws could result in a costly investigation or litigation resulting in potentially significant liability and a material and adverse impact on our reputation and business.