We and our customers that use our products may be subject to privacy and data protection-related laws and regulations that impose obligations in connection with the collection, processing and use of personal data, financial data, health or other similar data. The U.S. federal and various state and foreign governments have adopted or proposed limitations on, or requirements regarding, the collection, distribution, use, security and storage of personally identifiable information of individuals. The U.S. Federal Trade Commission and numerous state attorneys general are applying federal and state consumer protection laws to impose standards on the online collection, use and dissemination of data, and to the security measures applied to such data.
Similarly, many foreign countries and governmental bodies, including the European Union, or the EU, member states, have laws and regulations concerning the collection and use of personally identifiable information obtained from individuals located in the EU or by businesses operating within their jurisdiction, which are often more restrictive than those in the United States. Laws and regulations in these jurisdictions apply broadly to the collection, use, storage, disclosure and security of personally identifiable information that identifies or may be used to identify an individual, such as names, telephone numbers, email addresses and, in some jurisdictions, IP addresses and other online identifiers.
For example, the General Data Protection Regulation, or GDPR, took effect in the EU on May 25, 2018. The GDPR enhances data protection obligations for businesses and requires service providers (data processors) processing personal data on behalf of customers to cooperate with European data protection authorities, implement security measures and keep records of personal data processing activities. Noncompliance with the GDPR can trigger fines equal to or greater of €20 million or 4% of global annual revenues. There are also additional EU laws and regulations (and member states implementations thereof) which govern the protection of consumers and of electronic communications. If our efforts to comply with GDPR or other applicable EU laws and regulations are not successful, we may be subject to penalties and fines that would adversely impact our business and results of operations, and our ability to conduct business in the EU could be significantly impaired.
As well, we continue to see jurisdictions imposing data localization laws, which require personal information, or certain subcategories of personal information to be stored in the jurisdiction of origin. These regulations may inhibit our ability to expand into those markets or prohibit us from continuing to offer services in those markets without significant additional costs.
The uncertainty and changes in the requirements of multiple jurisdictions may increase the cost of compliance, delay or reduce demand for our services, restrict our ability to offer services in certain locations, impact our customers' ability to deploy our solutions in certain jurisdictions, or subject us to sanctions, by national data protection regulators, all of which could harm our business, financial condition and results of operations.
Additionally, although we endeavor to have our products and platform comply with applicable laws and regulations, these and other obligations may be modified, they may be interpreted and applied in an inconsistent manner from one jurisdiction to another, and they may conflict with one another, other regulatory requirements, contractual commitments or our internal practices.
We also may be bound by contractual obligations relating to our collection, use and disclosure of personal, financial and other data or may find it necessary or desirable to join industry or other self-regulatory bodies or other privacy or data protection-related organizations that require compliance with their rules pertaining to privacy and data protection.
We expect that there will continue to be new proposed laws, rules of self-regulatory bodies, regulations and industry standards concerning privacy, data protection and information security in the U.S., the EU and other jurisdictions, and we cannot yet determine the impact such future laws, rules, regulations and standards may have on our business. Moreover, existing U.S. federal and various state and foreign privacy and data protection-related laws and regulations are evolving and subject to potentially differing interpretations, and various legislative and regulatory bodies may expand current or enact new laws and regulations regarding privacy and data protection-related matters. Because global laws, regulations and industry standards concerning privacy and data security have continued to develop and evolve rapidly, it is possible that we or our products or platform may not be, or may not have been, compliant with each such applicable law, regulation and industry standard and compliance with such new laws or to changes to existing laws may impact our business and practices, require us to expend significant resources to adapt to these changes, or to stop offering our products in certain countries. These developments could adversely affect our business, results of operations and financial condition.
Any failure or perceived failure by us, our products or our platform to comply with new or existing U.S., EU or other foreign privacy or data security laws, regulations, policies, industry standards or legal obligations, or any security incident that results in the unauthorized access to, or acquisition, release or transfer of, personally identifiable information or other customer data may result in governmental investigations, inquiries, enforcement actions and prosecutions, private litigation, fines and penalties, adverse publicity or potential loss of business.