Personal privacy, data protection and information security are significant issues in the United States and the other jurisdictions where we offer our products and services. The regulatory framework for privacy and security issues worldwide is rapidly evolving and is likely to remain uncertain for the foreseeable future. Our handling of data is subject to a variety of laws and regulations, including regulation by various government agencies, including the United States Federal Trade Commission (FTC) and various state, local and foreign regulators, and agencies. Our agreements with certain customers and business partners may also subject us to certain requirements related to our processing of personal information, including obligations to use industry-standard or reasonable security measures to safeguard personal information.
The United States and various state and foreign governments have adopted or proposed limitations on the collection, distribution, use and storage of personal information of individuals, including end-customers and employees. In the United States, the FTC and many state attorneys general are applying federal and state consumer protection laws to the online collection, use, processing, storage, deletion, and dissemination of personal information. Further, all states have enacted laws requiring companies to notify individuals, regulatory authorities and others of security breaches involving personal information.
We also expect that there will continue to be new proposed laws, regulations and industry standards concerning privacy, data protection and information security in the United States, the EU and other jurisdictions, and we cannot always predict the impact of such future laws, regulations, and standards may have on our business. We expect that existing laws, regulations, and standards may even be interpreted differently or inconsistently relative to each other in the future. California initiated the first wave of state consumer privacy laws by enacting the California Consumer Privacy Act (the CCPA), as amended by the California Privacy Rights Act (the CPRA). Following California's lead, several other states have enacted privacy laws. Failure to comply with these new state regulations may result in significant civil penalties, injunctive relief, or statutory or actual damages. Complying with this new privacy legislation may result in additional costs and expenses.
Additionally, many foreign countries and governmental bodies, including Australia, the EU, the U.K., India, Japan, and numerous other jurisdictions in which we operate or conduct our business, have laws and regulations concerning the collection, use, processing, storage, and deletion of personal information obtained from their residents or by businesses operating within their jurisdiction. These laws and regulations often are more restrictive than those in the United States.
For example, in the EU and the U.K., the respective EU or U.K. General Data Protection Regulation (GDPR) imposes more stringent data protection requirements, provides an enforcement authority, and imposes large penalties for noncompliance. If we fail to comply with the respective GDPR or if regulators assert that we have failed to comply with the GDPR, we may be subject to fines of up to 4% of our worldwide annual revenue under EU GDPR requirements and up to 4% of our worldwide annual turnover under the UK's implementation of GDPR.
Among other requirements, both the EU and U.K. GDPR regulates transfers of personal data outside of the EU to countries that have not been found to provide adequate protection to personal data, including the United States, requiring that certain steps are taken to legitimize those transfers. We have undertaken certain efforts to conform transfers of personal data from the EU to the United States and other jurisdictions based on our understanding of current regulatory obligations and the guidance of regulators and data protection authorities. Despite this, we may be unsuccessful in establishing or maintaining conforming means of transferring such data from the European Economic Area or the U.K. particularly as a result of continued legal and legislative activity that has challenged or called into question the legal basis for existing means of data transfers to countries that have not been found to provide adequate protection for personal data. We continue to monitor these regulatory and legal developments.
In addition to government regulation, privacy advocates and industry groups may propose new and different self-regulatory standards. These and other industry standards may legally or contractually apply to us, or we may elect to comply with such standards. It is possible that if our practices are not consistent, or are viewed as not consistent, with legal and regulatory requirements, including changes in laws, regulations and standards or new interpretations or applications of existing laws, regulations and standards, we may become subject to audits, inquiries, whistleblower complaints, adverse media coverage, investigations, loss of export privileges, fines, awards, penalties, injunctions, judgments, or criminal or civil sanctions, all of which may have a material adverse effect on our business, operating results, reputation, and financial condition.
Future laws, regulations, standards and other obligations, as well as changes in the interpretation of existing laws, regulations, standards and other obligations could impair our ability to collect, use or disclose information relating to individuals, which could decrease demand for our products, require us to restrict our business operations, increase our costs, and impair our ability to maintain and grow our customer base and increase our revenue.