We receive, collect, store, and process certain personally identifiable information about individuals and other data relating to users of the application. We have legal and contractual obligations regarding the protection of confidentiality and appropriate use of certain data, including personally identifiable and other potentially sensitive information about individuals. We may be subject to numerous federal, state, local, and international laws, directives, and regulations regarding privacy, data protection, and data security and the collection, storing, sharing, use, processing, transfer, disclosure, disposal and protection of information about individuals and other data, the scope of which are changing, subject to differing interpretations, and may be inconsistent among jurisdictions or conflict with other legal and regulatory requirements. We strive to comply with our applicable data privacy and security policies, regulations, contractual obligations, and other legal obligations relating to privacy, data protection, and data security. However, the regulatory framework for privacy, data protection and data security worldwide is, and is likely to remain for the foreseeable future, uncertain and complex, and it is possible that these or other actual or alleged obligations may be interpreted and applied in a manner that we do not anticipate or that is inconsistent from one jurisdiction to another and may conflict with other legal obligations or our practices. Further, any significant change to applicable laws, regulations or industry practices regarding the collection, use, retention, security, processing, transfer or disclosure of data, or their interpretation, or any changes regarding the manner in which the consent of users or other data subjects for the collection, use, retention, security, processing, transfer or disclosure of such data must be obtained, could increase our costs and require us to modify our services and features, possibly in a material manner, which we may be unable to complete, and may limit our ability to receive, collect, store, process, transfer, and otherwise use user data or develop new services and features.
If we are found in violation of any applicable laws or regulations relating to privacy, data protection, or security, our business may be materially and adversely affected and we would likely have to change our business practices and potentially the services and features, integrations or other capabilities of the application. In addition, these laws and regulations could impose significant costs on us and could constrain our ability to use and process data in a commercially desirable manner. In addition, if a breach of data security were to occur or be alleged to have occurred, if any violation of laws and regulations relating to privacy, data protection or data security were to be alleged, or if we were to discover any actual or alleged defect in our safeguards or practices relating to privacy, data protection, or data security, the application may be perceived as less desirable and our business, financial condition, results of operations and growth prospects could be materially and adversely affected.
We also expect that there will continue to be new laws, regulations, and industry standards concerning privacy, data protection, and information security proposed and enacted in various jurisdictions. For example, the California Consumer Privacy Act ("CCPA"), which came into force in 2020, provides new data privacy rights for California consumers and new operational requirements for covered companies. Specifically, the CCPA mandates that covered companies provide new disclosures to California consumers and afford such consumers new data privacy rights that include, among other things, the right to request a copy from a covered company of the personal information collected about them, the right to request deletion of such personal information, and the right to request to opt-out of certain sales of such personal information. The California Attorney General can enforce the CCPA, including seeking an injunction and civil penalties for violations. The CCPA also provides a private right of action for certain data breaches that is expected to increase data breach litigation. Additionally, a new privacy law, the California Privacy Rights Act ("CPRA"), was approved by California voters in the November 3, 2020 election. The CPRA generally takes effect on January 1, 2023 and significantly modifies the CCPA, including by expanding consumers' rights with respect to certain personal information and creating a new state agency to oversee implementation and enforcement efforts, potentially resulting in further uncertainty and requiring us to incur additional costs and expenses in an effort to comply. Some observers have noted the CCPA and CPRA could mark the beginning of a trend toward more stringent privacy legislation in the United States, which could also increase our potential liability and adversely affect our business. For example, the CCPA has encouraged "copycat" or other similar laws to be considered and proposed in other states across the country, such as in Virginia, New Hampshire, Illinois and Nebraska. This legislation may add additional complexity, variation in requirements, restrictions and potential legal risk, require additional investment in resources to compliance programs, could impact strategies and availability of previously useful data and could result in increased compliance costs and/or changes in business practices and policies.
Various U.S. federal privacy laws are potentially relevant to our business, including the Federal Trade Commission Act, Controlling the Assault of Non-Solicited Pornography and Marketing Act, the Family Educational Rights and Privacy Act, the Children's Online Privacy Protection Act, and the Telephone Consumer Protection Act. Any actual or perceived failure to comply with these laws could result in a costly investigation or litigation resulting in potentially significant liability, injunctions and other consequences, loss of trust by our users, and a material and adverse impact on our reputation and business.
In addition, the data protection landscape in the EU is continually evolving, resulting in possible significant operational costs for internal compliance and risks to our business. The EU adopted the General Data Protection Regulation ("GDPR"), which became effective in May 2018, and contains numerous requirements and changes from previously existing EU laws, including more robust obligations on data processors and heavier documentation requirements for data protection compliance programs by companies.
Among other requirements, the GDPR regulates the transfer of personal data subject to the GDPR to third countries that have not been found to provide adequate protection to such personal data, including the United States. Recent legal developments in Europe have created complexity and uncertainty regarding such transfers. For instance, on July 16, 2020, the Court of Justice of the European Union (the "CJEU") invalidated the EU-U.S. Privacy Shield Framework (the "Privacy Shield") under which personal data could be transferred from the European Economic Area to U.S. entities who had self-certified under the Privacy Shield scheme. While the CJEU upheld the adequacy of the standard contractual clauses (a standard form of contract approved by the European Commission as an adequate personal data transfer mechanism and potential alternative to the Privacy Shield), it made clear that reliance on such clauses alone may not necessarily be sufficient in all circumstances. Use of the standard contractual clauses must now be assessed on a case-by-case basis taking into account the legal regime applicable in the destination country, including, in particular, applicable surveillance laws and rights of individuals, and additional measures and/or contractual provisions may need to be put in place; however, the nature of these additional measures is currently uncertain. The CJEU also states that if a competent supervisory authority believes that the standard contractual clauses cannot be complied with in the destination country and that the required level of protection cannot be secured by other means, such supervisory authority is under an obligation to suspend or prohibit that transfer.
Additionally, the GDPR greatly increased the European Commission's jurisdictional reach of its laws and added a broad array of requirements for handling personal data. EU member states are tasked under the GDPR to enact, and have enacted, certain implementing legislation that adds to and/or further interprets the GDPR requirements and potentially extends our obligations and potential liability for failing to meet such obligations. The GDPR, together with national legislation, regulations and guidelines of the EU member states a governing the processing of personal data, impose strict obligations and restrictions on the ability to collect, use, retain, protect, disclose, transfer and otherwise process personal data. In particular, the GDPR includes obligations and restrictions concerning the consent and rights of individuals to whom the personal data relates, security breach notifications and the security and confidentiality of personal data.
Failure to comply with the GDPR could result in penalties for noncompliance (including possible fines of up to the greater of €20 million and 4% of our global annual turnover for the preceding financial year for the most serious violations, as well as the right to compensation for financial or non-financial damages claimed by individuals under Article 82 of the GDPR).
In addition to the GDPR, the European Commission has another draft regulation in the approval process that focuses on a person's right to conduct a private life. The proposed legislation, known as the Regulation of Privacy and Electronic Communications ("ePrivacy Regulation"), would replace the current ePrivacy Directive. While the text of the ePrivacy Regulation is still under development, a recent European court decision and regulators' recent guidance are driving increased attention to cookies and tracking technologies. If regulators start to enforce the strict approach in recent guidance, this could lead to substantial costs, require significant systems changes, limit the effectiveness of our marketing activities, divert the attention of our technology personnel, adversely affect our margins, increase costs and subject us to additional liabilities. Regulation of cookies and similar technologies may lead to broader restrictions on our marketing and personalization activities and may negatively impact our efforts to understand users.
Further, in March 2017, the United Kingdom formally notified the European Council of its intention to leave the EU pursuant to Article 50 of the Treaty on European Union ("Brexit"). The United Kingdom ceased to be an EU Member State on January 31, 2020, but enacted a Data Protection Act substantially implementing the GDPR ("U.K. GDPR"), effective in May 2018, which was further amended to align more substantially with the GDPR following Brexit. It is unclear how U.K. data protection laws or regulations will develop in the medium to longer term and how data transfers to and from the United Kingdom will be regulated. Some countries also are considering or have enacted legislation requiring local storage and processing of data that could increase the cost and complexity of delivering our services. Beginning in 2021 when the transitional period following Brexit expired, we are required to comply with both the GDPR and the U.K. GDPR, with each regime having the ability to fine up to the greater of €20 million (in the case of the GDPR) or £17 million (in the case of the U.K. GDPR) and 4% of total annual revenue. The relationship between the United Kingdom and the EU in relation to certain aspects of data protection law remains unclear, including, for example, how data transfers between EU member states and the United Kingdom will be treated and the role of the United Kingdom's Information Commissioner's Office following the end of the transitional period. These changes could lead to additional costs and increase our overall risk exposure.
Any failure or perceived failure by us to comply with our posted privacy policies, our privacy-related obligations to users, or any other legal obligations or regulatory requirements relating to privacy, data protection, or data security, may result in governmental investigations or enforcement actions, litigation, claims, or public statements against us by consumer advocacy groups, or others and could result in significant liability, cause our users to lose trust in us, and otherwise materially and adversely affect our reputation and business. Furthermore, the costs of compliance with, and other burdens imposed by, the laws, regulations, other obligations, and policies that are applicable to the businesses of our users may limit the adoption and use of, and reduce the overall demand for, the application. Further, public scrutiny of, or complaints about, technology companies or their data handling or data protection practices, even if unrelated to our business, industry or operations, may lead to increased scrutiny of technology companies, including us, and may cause government agencies to enact additional regulatory requirements, or to modify their enforcement or investigation activities, which may increase our costs and risks. Any of the foregoing could materially and adversely affect our business, financial condition and results of operations.