We are, and may increasingly become, subject to various laws, directives, industry standards and regulations, as well as contractual obligations, relating to data privacy and security in the jurisdictions in which we operate. The regulatory environment related to data privacy and security is increasingly rigorous, with new and constantly changing requirements applicable to our business, and enforcement practices are likely to remain uncertain for the foreseeable future. These laws and regulations may be interpreted and applied differently over time and from jurisdiction to jurisdiction, and it is possible that they will be interpreted and applied in ways that may have a material adverse effect on our results of operations, financial condition and cash flows. In the U.S., various federal and state regulators, including governmental agencies like the Consumer Financial Protection Bureau and the Federal Trade Commission, have adopted, or are considering adopting, laws and regulations concerning personal information and data security and have prioritized privacy and information security violations for enforcement actions. Certain state laws may be more stringent or broader in scope, or offer greater individual rights, with respect to personal information than federal, international or other state laws, and such laws may differ from each other, all of which may complicate compliance efforts. For example, the California Consumer Privacy Act (“CCPA”), which increases privacy rights for California residents and imposes obligations on companies that process their personal information, went into effect on January 1, 2020. Among other things, the CCPA requires covered companies to provide new disclosures to California consumers and provide such consumers new data protection and privacy rights, including the ability to opt-out of certain data sharing arrangements of personal information, and the ability to access and delete personal information. The CCPA provides for civil penalties for violations, as well as a private right of action for certain data breaches that result in the loss of personal information. This private right of action may increase the likelihood of, and risks associated with, data breach litigation. Furthermore, in November 2020, California voters passed the California Privacy Rights Act of 2020 (“CPRA”). Effective beginning January 1, 2023, the CPRA imposes additional obligations on companies covered by the legislation and will significantly modify the CCPA, including by expanding California residents’ rights with respect to certain sensitive personal information. The CPRA also creates a new state agency that will be vested with authority to implement and enforce the CCPA and CPRA. Other states (such as Virginia) also plan to pass data privacy laws that are similar to the CCPA, CPRA, and GDPR (described below), further complicating the legal landscape. In addition, laws in all 50 U.S. states require businesses to provide notice to consumers (and, in some cases, to regulators) whose personal information has been accessed or acquired as a result of a data breach. State laws are changing rapidly and there is discussion in Congress of a new comprehensive federal data privacy law to which we would become subject if it is enacted, which may add additional complexity, variation in requirements, restrictions and potential legal risk, require additional investment of resources in compliance programs, impact strategies and the availability of previously useful data and could result in increased compliance costs or changes in business practices and policies. We are also subject to international laws, regulations and standards in many jurisdictions, which apply broadly to the collection, use, retention, security, disclosure, transfer and other processing of personal information. For example, the E.U. General Data Protection Regulation (“GDPR”), which became effective in May 2018, greatly increased the European Commission’s jurisdictional reach of its laws and adds a broad array of requirements for handling personal data. EU member states are tasked under the GDPR to enact, and have enacted, certain implementing legislation that adds to and/or further interprets the GDPR requirements and potentially extends our obligations and potential liability for failing to meet such obligations. The GDPR, together with national legislation, regulations and guidelines of the EU member states and the United Kingdom governing the processing of personal data, impose strict obligations and restrictions on the ability to collect, use, retain, protect, disclose, transfer and otherwise process personal data. In particular, the GDPR includes obligations and restrictions concerning data transparency and consent, the overall rights of individuals to whom the personal data relates, the transfer of personal data out of the European Economic Area ("EEA") or the United Kingdom, security breach notifications and the security and confidentiality of personal data. The GDPR authorizes fines for certain violations of up to 4% of global annual revenue or €20 million, whichever is greater. Recent legal developments in Europe have created further complexity and uncertainty regarding transfers of personal data from the EEA and the United Kingdom to the United States. Most recently, in July 2020, the Court of Justice the European Union (“CJEU”) invalidated the EU-U.S. Privacy Shield Framework (“Privacy Shield”) under which personal data could be transferred from the EEA to the United States. While the CJEU upheld the adequacy of standard contractual clauses, a standard form of contract approved by the European Commission as an adequate personal data transfer mechanism and potential alternative to the Privacy Shield, it made clear that reliance on them alone may not necessarily be sufficient in all circumstances. Further, the United Kingdom’s decision to leave the EU has created uncertainty with regard to data protection regulation in the United Kingdom. As of January 1, 2021, we are also subject to the UK GDPR and UK Data Protection Act of 2018, which retains the GDPR in the United Kingdom’s national law. These recent developments will require us to review and amend the legal mechanisms by which we make and/or receive personal data transfers. As supervisory authorities issue further guidance on personal data export mechanisms, including circumstances where the standard contractual clauses and other mechanisms cannot be used, and/or start taking enforcement action, we could suffer additional costs, complaints and/or regulatory investigations or fines, or if we are otherwise unable to transfer personal data between and among countries and regions in which we operate, it could affect the manner in which we do business, the geographical location or segregation of our relevant operations, and could adversely affect our financial results. All of these evolving compliance and operational requirements impose significant costs, such as costs related to organizational changes, implementing additional protection technologies, training associates and engaging consultants, which are likely to increase over time. In addition, such requirements may require us to modify our data processing practices and policies, distract management or divert resources from other initiatives and projects, all of which could have a material adverse effect on our results of operations, financial condition and cash flows. Any failure or perceived failure by us to comply with any applicable federal, state or similar foreign laws and regulations relating to data privacy and security could result in damage to our reputation and our relationship with our customers, as well as proceedings or litigation by governmental agencies or customers, including class action privacy litigation in certain jurisdictions, which could subject us to significant fines, sanctions, awards, penalties or judgments, any of which could have a material adverse effect on our results of operations, financial condition and cash flows.