We are, and may increasingly become, subject to various laws and regulations, as well as contractual obligations, relating to data privacy and security in the jurisdictions in which we operate. The regulatory environment related to data privacy and security is increasingly rigorous, with new and constantly changing requirements applicable to our business, and enforcement practices are likely to remain uncertain for the foreseeable future. These laws and regulations may be interpreted and applied differently over time and from jurisdiction to jurisdiction, and it is possible that they will be interpreted and applied in ways that may have a material adverse effect on our business, financial condition, results of operations or prospects.
In the US, various federal and state regulators, including governmental agencies like the Consumer Financial Protection Bureau and the Federal Trade Commission, have adopted, or are considering adopting, laws and regulations concerning personal information and data security. In particular, regulations promulgated pursuant to the Health Insurance Portability and Accountability Act of 1996 ("HIPAA") establish privacy and security standards that limit the use and disclosure of protected health information and require the implementation of safeguards to protect the privacy, integrity and availability of protected health information. Determining whether protected health information has been handled in compliance with applicable privacy standards and our contractual obligations can be complex and may be subject to changing interpretation. If we fail to comply with applicable HIPAA privacy and security standards, we could face civil and criminal penalties. In addition, state attorneys general are authorized to bring civil actions seeking either injunctions or damages in response to violations that threaten the privacy of state residents. We cannot be sure how these regulations will be interpreted, enforced or applied to our operations.
Certain state laws may be more stringent or broader in scope, or offer greater individual rights, with respect to personal information than federal, international, or other state laws, and such laws may differ from each other, all of which may complicate compliance efforts. For example, the California Consumer Privacy Act ("CCPA"), which increases privacy rights for California residents and imposes obligations on companies that process their personal information, came into effect on January 1, 2020. Among other things, the CCPA requires covered companies to provide new disclosures to California consumers and provide such consumers new data protection and privacy rights, including the ability to opt-out of certain sales of personal information. The CCPA provides for civil penalties for violations, as well as a private right of action for certain data breaches that result in the loss of personal information. This private right of action may increase the likelihood of, and risks associated with, data breach litigation.
Internationally, laws, regulations and standards in many jurisdictions apply broadly to the collection, use, retention, security, disclosure, transfer and other processing of personal information. For example, the E.U. General Data Protection Regulation ("GDPR"), which became effective in May 2018, greatly increased the European Commission's jurisdictional reach of its laws and adds a broad array of requirements for handling personal data. EU member states are tasked under the GDPR to enact, and have enacted, certain implementing legislation that adds to and/or further interprets the GDPR requirements and potentially extends our obligations and potential liability for failing to meet such obligations. The GDPR, together with national legislation, regulations and guidelines of the EU member states governing the processing of personal data, impose strict obligations and restrictions on the ability to collect, use, retain, protect, disclose, transfer and otherwise process personal data. In particular, the GDPR includes obligations and restrictions concerning the consent and rights of individuals to whom the personal data relates, the transfer of personal data out of the European Economic Area, security breach notifications and the security and confidentiality of personal data. The GDPR authorizes fines for certain violations of up to 4% of global annual revenue or €20 million, whichever is greater.
All of these evolving compliance and operational requirements impose significant costs, such as costs related to organizational changes, implementing additional protection technologies, training associates and engaging consultants, which are likely to increase over time. In addition, such requirements may require us to modify our data processing practices and policies, distract management or divert resources from other initiatives and projects, all of which could have a material adverse effect on our results of operations, financial condition and cash flows. Any failure or perceived failure by us to comply with any applicable federal, state or similar foreign laws and regulations relating to data privacy and security could result in damage to our reputation and our relationship with our customers, as well as proceedings or litigation by governmental agencies or customers, including class action privacy litigation in certain jurisdictions, which would subject us to significant fines, sanctions, awards, penalties or judgments, all of which could have a material adverse effect on our business, financial condition, results of operations or prospects.