As part of our normal operations, we collect, process, transmit and where appropriate, retain certain sensitive and confidential employee and customer information, including credit card information. There is significant concern by consumers and employees over the security of personal information, consumer identity theft and user privacy. Despite the security measures we have implemented, our facilities and systems, and those of our third-party service providers, are vulnerable to cybersecurity incidents, including security breaches, acts of vandalism, computer viruses, misplaced or lost data, programming and/or human errors, or other similar events. We (or third parties we rely on) may not be able to fully, continuously, and effectively implement cybersecurity controls as intended. We utilize a risk-based approach to determine which security controls to implement and it is possible that we may not implement appropriate controls if we do not recognize, or we underestimate, a particular cybersecurity risk. In addition, cybersecurity controls, no matter how well designed or implemented, may only mitigate, and not fully eliminate, risks. Events, when detected by security tools or third parties, may not always be immediately understood or acted upon. Additionally, external events, like the ongoing wars in Ukraine and Gaza and the Red Sea crisis, can increase the likelihood of cybersecurity incidents. As security breaches at prominent retailers and other large institutions have become more common, the media and public scrutiny of information security and privacy has become more intense and the regulatory environment has become more stringent. Any security breach involving the misappropriation, loss or other unauthorized disclosure of confidential customer or employee information, whether by us, our vendors, or another party with access to our information systems, could result in significant legal and remediation expenses, severely damage our reputation and our customer relationships, harm sales, expose us to risks of litigation and liability and result in a material adverse effect on our business, financial condition and results of operations. Additionally, changing privacy laws in the United States, Europe and elsewhere, including the California Consumer Privacy Act, which created an array of consumer privacy rights and business obligations with regard to the collection and sale of personal information, and other similar state laws, and the General Data Protection Regulation ("GDPR"), adopted in the European Union, which created individual privacy rights and imposed increased obligations on companies handling personal data. Consequently, we may incur significant costs related to complying with laws regarding the protection and unauthorized disclosure of personal information. A failure to comply with the stringent rules of the GDPR or state privacy laws could result in material fines.